All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 28,990
- 1,208
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 1,081–1,104 of 28,990 skills
- Security Third Party Test Consent ReviewUse when a task involves checking permissions when an in-scope service depends on a hosting, SaaS, CDN, or identity provider to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain expl...Votes: 0GitHub stars: 2
- Security Third Party Service Dependency MapUse when a task involves mapping vendor-owned dependencies that can receive assessment traffic or evidence to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval befo...Votes: 0GitHub stars: 2
- Security Third Party Incident Intake ReviewUse when a task involves handling a security incident notification from a cloud, software, or service provider to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval ...Votes: 0GitHub stars: 2
- Security Test Window And Change Freeze CoordinationUse when a task involves coordinating authorized security testing with service changes and business events to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval befo...Votes: 0GitHub stars: 2
- Security Test Tool Provenance And Version ReviewUse when a task involves reviewing the source, version, permissions, and side effects of a security tool before use to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit appr...Votes: 0GitHub stars: 2
- Security Test Observability Owner NoticeUse when a task involves aligning authorized security testing with monitoring and operations teams to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before activ...Votes: 0GitHub stars: 2
- Security Test Credential Lifecycle ReviewUse when a task involves controlling credentials issued for a security assessment to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before active testing, contai...Votes: 0GitHub stars: 2
- Security Test Backout And Service Recovery PlanUse when a task involves preparing a recoverable test plan before a security change or stateful check to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before ac...Votes: 0GitHub stars: 2
- Security Test Artifact Cleanup VerificationUse when a task involves confirming that temporary test artifacts and access are removed after an assessment to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval be...Votes: 0GitHub stars: 2
- Security Target Resolution Drift GuardUse when a task involves preventing an approved hostname from resolving to an unapproved target during a test to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval b...Votes: 0GitHub stars: 2
- Security Target Ownership VerificationUse when a task involves confirming that a security test target belongs to the consenting organization to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before a...Votes: 0GitHub stars: 2
- Security Synthetic Identity Test Account PlanUse when a task involves creating test identities that safely exercise authorized security controls to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before acti...Votes: 0GitHub stars: 2
- Security Ssdf Practice Evidence MapUse when a task involves mapping secure-development claims to current NIST SSDF practice evidence to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before active...Votes: 0GitHub stars: 2
- Security Service Account Owner And Expiry AuditUse when a task involves identifying service accounts without a clear owner, purpose, or review date to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before act...Votes: 0GitHub stars: 2
- Security Secret Exposure Response And RevocationUse when a task involves responding safely when a credential or key may have appeared in code, logs, or a report to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approva...Votes: 0GitHub stars: 2
- Security Scope Expiry And Renewal CheckUse when a task involves checking whether security testing authorization remains valid after time or scope changes to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit appro...Votes: 0GitHub stars: 2
- Security Scan Rate And Concurrency PlanUse when a task involves planning bounded scan pacing for an authorized asset inventory to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before active testing, ...Votes: 0GitHub stars: 2
- Security Sandbox Equivalence And Isolation ReviewUse when a task involves choosing a representative test environment without connecting tools to production targets to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit appro...Votes: 0GitHub stars: 2
- Security Rules Of Engagement MatrixUse when a task involves translating written testing permission into an action-by-action rules-of-engagement matrix to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit appr...Votes: 0GitHub stars: 2
- Security Remediation Diff Scope ReviewUse when a task involves reviewing whether a security-fix change stays within its approved remediation scope to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval be...Votes: 0GitHub stars: 2
- Security Recovery And Residual Access ValidationUse when a task involves checking that service recovery did not leave incident persistence or unauthorized access behind to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit...Votes: 0GitHub stars: 2
- Security Ransomware Restore Readiness TabletopUse when a task involves evaluating ransomware response and recovery roles through a non-destructive tabletop exercise to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit a...Votes: 0GitHub stars: 2
- Security Production Probing Impact BudgetUse when a task involves setting impact limits for authorized security checks on a live service to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before active t...Votes: 0GitHub stars: 2
- Security Privileged Account Containment ReviewUse when a task involves planning an approved containment action for an account with elevated access to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before act...Votes: 0GitHub stars: 2