All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 28,990
- 1,208
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 1,057–1,080 of 28,990 skills
- Vulnerability Sbom Enrichment Quality ReviewUse when a task involves checking component identity and provenance before attaching vulnerability data to an SBOM to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit appro...Votes: 0GitHub stars: 2
- Vulnerability Risk Exception Expiry GovernanceUse when a task involves reviewing an approved vulnerability exception before its expiry or renewal to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before acti...Votes: 0GitHub stars: 2
- Vulnerability Remediation Retest Closure EvidenceUse when a task involves verifying that an approved vulnerability remediation is complete before closing its record to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit appr...Votes: 0GitHub stars: 2
- Vulnerability Remediation Priority QueueUse when a task involves building a reviewable order for a security backlog with changing exposure and threat evidence to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit a...Votes: 0GitHub stars: 2
- Vulnerability Public Report Intake TriageUse when a task involves handling a vulnerability report from an external researcher through an authorized intake channel to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explici...Votes: 0GitHub stars: 2
- Vulnerability Product Version ApplicabilityUse when a task involves determining whether an advisory applies to the exact product and version in an asset inventory to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit ...Votes: 0GitHub stars: 2
- Vulnerability Patch Validation In StagingUse when a task involves verifying a proposed security update in a representative non-production environment to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval be...Votes: 0GitHub stars: 2
- Vulnerability Kev Prioritization CheckUse when a task involves checking the current CISA Known Exploited Vulnerabilities catalog during remediation triage to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit app...Votes: 0GitHub stars: 2
- Vulnerability Firmware Applicability ReviewUse when a task involves checking whether a firmware advisory matches an installed hardware and firmware revision to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approv...Votes: 0GitHub stars: 2
- Vulnerability False Positive Evidence StandardUse when a task involves deciding whether evidence is sufficient to mark a scanner finding as not applicable to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval be...Votes: 0GitHub stars: 2
- Vulnerability Exposure And Asset Criticality RankingUse when a task involves prioritizing findings using the affected asset's exposure and business role to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before act...Votes: 0GitHub stars: 2
- Vulnerability Exploitation Signal TriangulationUse when a task involves evaluating whether available evidence supports active exploitation of a vulnerability to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval ...Votes: 0GitHub stars: 2
- Vulnerability Epss Signal Limit ReviewUse when a task involves using an exploit-prediction score as one bounded input to vulnerability triage to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before ...Votes: 0GitHub stars: 2
- Vulnerability End Of Life Component DecisionUse when a task involves choosing a supported response when an affected component no longer receives security updates to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit ap...Votes: 0GitHub stars: 2
- Vulnerability Duplicate Finding ClusteringUse when a task involves grouping repeated vulnerability findings without hiding distinct affected assets to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval befor...Votes: 0GitHub stars: 2
- Vulnerability Dependency Reachability AssessmentUse when a task involves determining whether a vulnerable software dependency is present and reachable in a product to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit appr...Votes: 0GitHub stars: 2
- Vulnerability Cvss Severity Context ReviewUse when a task involves interpreting a CVSS score without confusing severity with local risk to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before active tes...Votes: 0GitHub stars: 2
- Vulnerability Cve Record Status ValidationUse when a task involves checking whether a CVE record is reserved, published, rejected, or disputed before use to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval...Votes: 0GitHub stars: 2
- Vulnerability Cpe Applicability ValidationUse when a task involves interpreting NVD product configuration statements against a real deployment to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before act...Votes: 0GitHub stars: 2
- Vulnerability Compensating Control Evidence ReviewUse when a task involves assessing whether a compensating control meaningfully reduces an unpatched vulnerability's risk to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit...Votes: 0GitHub stars: 2
- Vulnerability Authenticated Scan Evidence CheckUse when a task involves assessing whether an authorized scan had the identity and permissions needed to see relevant configuration to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obta...Votes: 0GitHub stars: 2
- Security Tls Configuration Versioned AssessmentUse when a task involves reviewing a service's TLS settings against a versioned policy or approved baseline to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval bef...Votes: 0GitHub stars: 2
- Security Tls Certificate Expiry ReadinessUse when a task involves planning certificate renewal before an authorized service certificate expires to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before a...Votes: 0GitHub stars: 2
- Security Threat Model Change Trigger ReviewUse when a task involves deciding whether an architecture or operational change requires threat-model updates to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval b...Votes: 0GitHub stars: 2