All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 28,990
- 1,208
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 1,033–1,056 of 28,990 skills
- Browser Account Settings Change PreviewUse when a task involves previewing a browser account setting change before saving it to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perform external writes witho...Votes: 0GitHub stars: 2
- Browser Accessibility Snapshot Diff EvaluationUse when a task involves comparing browser accessibility-tree snapshots after a UI change to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perform external writes w...Votes: 0GitHub stars: 2
- Browser Accessibility Locator Fallback PolicyUse when a task involves choosing a safe fallback when an interactive element lacks a reliable accessible locator to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or p...Votes: 0GitHub stars: 2
- Web Server DevelopmentUse when implementing an HTTP server, routing layer, reverse proxy, or web-serving runtime to define supported protocol behavior, concurrency and resource limits, and trust boundaries before exposing a listener; test malformed requests and filesystem access in a local harness. Trigger for request parsing, routing, middleware, static files, or server lifecycle work.Votes: 0GitHub stars: 2
- Fastapi Router PatternsUse when a task involves organizing FastAPI routes around validated request models, dependency boundaries, and testable service logic to identify the intended outcome, relevant inputs, platform or version, sensitive data, and permission boundary before acting. Use current primary documentation for version-sensitive behavior, produce a reviewable artifact, and verify it against stated criteria. Trigger for planning, implementation, evaluation, or troubleshooting in this focused domain; do not ...Votes: 0GitHub stars: 2
- Browser Api Replay Write Safety ReviewUse when a task involves reviewing whether a browser-captured API request can be replayed without unintended side effects to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication sta...Votes: 0GitHub stars: 2
- Api Contract DesignUse when designing or changing an HTTP API contract consumed by another service, client, or team to specify resources, method semantics, schemas, errors, pagination, compatibility, and security boundaries before implementation. Trigger for new endpoints, public or partner APIs, versioning decisions, and contract reviews.Votes: 0GitHub stars: 2
- Github Issue AuthoringUse when a task involves turning a verified problem or feature request into a concise, actionable GitHub issue to identify the intended outcome, relevant inputs, platform or version, sensitive data, and permission boundary before acting. Use current primary documentation for version-sensitive behavior, produce a reviewable artifact, and verify it against stated criteria. Trigger for planning, implementation, evaluation, or troubleshooting in this focused domain; do not install or run third-pa...Votes: 0GitHub stars: 2
- Create Github Pull Request From SpecificationUse when a task involves turning an approved technical specification into a small, reviewable GitHub pull request to identify the intended outcome, relevant inputs, platform or version, sensitive data, and permission boundary before acting. Use current primary documentation for version-sensitive behavior, produce a reviewable artifact, and verify it against stated criteria. Trigger for planning, implementation, evaluation, or troubleshooting in this focused domain; do not install or run third...Votes: 0GitHub stars: 2
- Create Github Action Workflow SpecificationUse when a task involves specifying a GitHub Actions workflow before implementation, including events, permissions, jobs, outputs, and failure handling to identify the intended outcome, relevant inputs, platform or version, sensitive data, and permission boundary before acting. Use current primary documentation for version-sensitive behavior, produce a reviewable artifact, and verify it against stated criteria. Trigger for planning, implementation, evaluation, or troubleshooting in this focus...Votes: 0GitHub stars: 2
- Architecture Blueprint GeneratorUse when a task involves turning system requirements into a reviewable architecture blueprint with boundaries, data flows, and decision points to identify the intended outcome, relevant inputs, platform or version, sensitive data, and permission boundary before acting. Use current primary documentation for version-sensitive behavior, produce a reviewable artifact, and verify it against stated criteria. Trigger for planning, implementation, evaluation, or troubleshooting in this focused domain...Votes: 0GitHub stars: 2
- Quantum Cryptographic Transition Risk BriefUse when a task involves preparing a high-level quantum risk assessment for cryptographic assets to define the target, lifecycle stage, controlling artifact, authoritative evidence, version or operating conditions, sensitivity, and approval boundary before applying the method. Separate observed facts from assumptions and model output. Verify the result with appropriate independent checks, preserve provenance, and report uncertainty and limitations. Do not perform production, financial, device...Votes: 0GitHub stars: 2
- Macos Nested Code Signature Order AuditUse when a task involves checking signing order and signature integrity for a macOS app with embedded code to record Swift, Xcode, operating-system, build, and target versions; reproduction steps; data sensitivity; and the permission boundary before acting. Check current Apple or Swift documentation, preserve source and trace provenance, and verify on an owned test target. Do not change signing credentials, publish, notarize, or operate production systems without explicit approval.Votes: 0GitHub stars: 2
- Iot Device Inventory And Identity AuditUse when a task involves auditing device identity, ownership, and lifecycle records in an IoT fleet to define the target, lifecycle stage, controlling artifact, authoritative evidence, version or operating conditions, sensitivity, and approval boundary before applying the method. Separate observed facts from assumptions and model output. Verify the result with appropriate independent checks, preserve provenance, and report uncertainty and limitations. Do not perform production, financial, dev...Votes: 0GitHub stars: 2
- Iot Camera Fleet Credential Rotation PlanUse when a task involves planning credential rotation for a managed camera fleet to define the target, lifecycle stage, controlling artifact, authoritative evidence, version or operating conditions, sensitivity, and approval boundary before applying the method. Separate observed facts from assumptions and model output. Verify the result with appropriate independent checks, preserve provenance, and report uncertainty and limitations. Do not perform production, financial, device-control, deploy...Votes: 0GitHub stars: 2
- Emc Precompliance CheckUse when a task involves screening a PCB design for likely electromagnetic-compatibility risks before formal testing to identify the intended outcome, relevant inputs, platform or version, sensitive data, and permission boundary before acting. Use current primary documentation for version-sensitive behavior, produce a reviewable artifact, and verify it against stated criteria. Trigger for planning, implementation, evaluation, or troubleshooting in this focused domain; do not install or run th...Votes: 0GitHub stars: 2
- Embedded Wifi Low Power DiagnosticsUse when a task involves collecting structured evidence for Wi-Fi sleep-current or wake failures in an embedded device to define the target, lifecycle stage, controlling artifact, authoritative evidence, version or operating conditions, sensitivity, and approval boundary before applying the method. Separate observed facts from assumptions and model output. Verify the result with appropriate independent checks, preserve provenance, and report uncertainty and limitations. Do not perform product...Votes: 0GitHub stars: 2
- Dataverse Python Advanced PatternsUse when a task involves building a Python integration with Microsoft Dataverse using current supported authentication, paging, and API behavior to identify the intended outcome, relevant inputs, platform or version, sensitive data, and permission boundary before acting. Use current primary documentation for version-sensitive behavior, produce a reviewable artifact, and verify it against stated criteria. Trigger for planning, implementation, evaluation, or troubleshooting in this focused doma...Votes: 0GitHub stars: 2
- Pr To VideoUse when a task involves turning an approved pull request into a concise, accurate video summary for its intended audience to identify the intended outcome, relevant inputs, platform or version, sensitive data, and permission boundary before acting. Use current primary documentation for version-sensitive behavior, produce a reviewable artifact, and verify it against stated criteria. Trigger for planning, implementation, evaluation, or troubleshooting in this focused domain; do not install or ...Votes: 0GitHub stars: 2
- Vulnerability Workaround Expiry And Patch TransitionUse when a task involves managing a temporary workaround until a vendor fix is available and validated to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before a...Votes: 0GitHub stars: 2
- Vulnerability Vendor Advisory CrosscheckUse when a task involves corroborating a vulnerability record against the affected vendor's primary advisory to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval be...Votes: 0GitHub stars: 2
- Vulnerability Transitive Dependency Impact TriageUse when a task involves understanding how a transitive package finding affects the owning application to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before a...Votes: 0GitHub stars: 2
- Vulnerability Severity Normalization Across ToolsUse when a task involves reconciling different scanner severity labels into one transparent triage view to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before ...Votes: 0GitHub stars: 2
- Vulnerability Scanner Coverage ReconciliationUse when a task involves checking which assets and protocols a vulnerability scan did and did not cover to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before ...Votes: 0GitHub stars: 2