All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 28,990
- 1,208
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 1,105–1,128 of 28,990 skills
- Security Privileged Access Periodic ReviewUse when a task involves reviewing whether privileged roles remain assigned to approved people and workloads to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval be...Votes: 0GitHub stars: 2
- Security Post Incident Lessons And Improvement TrackingUse when a task involves turning incident findings into owned, measurable preparation and control improvements to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval ...Votes: 0GitHub stars: 2
- Security Network Segmentation Test Evidence ReviewUse when a task involves evaluating whether evidence supports a claimed network-segmentation boundary to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before ac...Votes: 0GitHub stars: 2
- Security Network Flow Evidence CorrelationUse when a task involves correlating approved network telemetry with a security incident timeline to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before active...Votes: 0GitHub stars: 2
- Security Mfa Coverage And Exception ReviewUse when a task involves measuring multi-factor authentication coverage for defined identities and systems to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval befo...Votes: 0GitHub stars: 2
- Security Malware Alert Triage No ExecutionUse when a task involves reviewing a malware or endpoint detection alert without running the suspected file to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval bef...Votes: 0GitHub stars: 2
- Security Log Source Integrity PreservationUse when a task involves preserving trustworthy log copies while investigating a suspected security event to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval befor...Votes: 0GitHub stars: 2
- Security Legal Privacy Notification HandoffUse when a task involves routing a potential reportable security incident to privacy and legal decision-makers to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval ...Votes: 0GitHub stars: 2
- Security Incident Status BriefUse when a task involves writing a concise, evidence-based status update during a security incident to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before acti...Votes: 0GitHub stars: 2
- Security Incident Severity Priority CalibrationUse when a task involves assigning an initial incident priority from impact, scope, confidence, and time sensitivity to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit app...Votes: 0GitHub stars: 2
- Security Incident Role And Authority MatrixUse when a task involves clarifying who can investigate, approve containment, communicate, and restore during a security incident to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain...Votes: 0GitHub stars: 2
- Security Incident Decision Log And TimelineUse when a task involves maintaining an auditable sequence of incident observations, decisions, and actions to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval bef...Votes: 0GitHub stars: 2
- Security Incident Alert TriageUse when a task involves deciding whether a security alert requires escalation into an incident workflow to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before...Votes: 0GitHub stars: 2
- Security Identity Anomaly InvestigationUse when a task involves reviewing unusual authentication events without assuming that a signal proves compromise to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approv...Votes: 0GitHub stars: 2
- Security Hardening Baseline Deviation TriageUse when a task involves reviewing a system's deviations from a named security configuration baseline to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before ac...Votes: 0GitHub stars: 2
- Security Forensic Collection Authorization GateUse when a task involves reviewing permission and proportionality before acquiring endpoint or cloud evidence to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval b...Votes: 0GitHub stars: 2
- Security Fix Regression Test Quality GateUse when a task involves reviewing whether a security remediation includes a useful and non-brittle regression check to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit app...Votes: 0GitHub stars: 2
- Security Firewall Rule Change Justification ReviewUse when a task involves reviewing a firewall policy change for business need, scope, expiry, and rollback to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval befo...Votes: 0GitHub stars: 2
- Security Finding Disclosure RoutingUse when a task involves routing a verified security finding to the authorized owner without exposing it broadly to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approva...Votes: 0GitHub stars: 2
- Security Evidence Lifecycle GovernanceUse when planning how security-control evidence and operational security logs are collected, protected, accessed, retained, and disposed to produce an evidence-lifecycle plan linking each control claim or log source to a minimal artifact, owner, classification, collection period, access rule, retention deadline, integrity check, and disposal path. Success means evidence is sufficient and traceable without collecting unrelated secrets or user records, access is least-privilege, backup and lega...Votes: 0GitHub stars: 2
- Security Evidence Hash Integrity CheckUse when a task involves checking whether an approved evidence artifact changed after collection to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before active ...Votes: 0GitHub stars: 2
- Security Evidence Custody RegisterUse when a task involves tracking who collected, accessed, transferred, or stored incident evidence to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before acti...Votes: 0GitHub stars: 2
- Security Event Timezone NormalizationUse when a task involves aligning timestamps from endpoint, cloud, identity, and network sources during triage to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval ...Votes: 0GitHub stars: 2
- Security Endpoint Isolation Approval GateUse when a task involves evaluating whether an endpoint can be isolated during a suspected compromise to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before ac...Votes: 0GitHub stars: 2