All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 28,990
- 1,208
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 1,129–1,152 of 28,990 skills
- Security Emergency Stop And Escalation DrillUse when a task involves verifying that an assessment can be paused quickly when unexpected impact appears to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval befo...Votes: 0GitHub stars: 2
- Security Email Phishing Report TriageUse when a task involves triaging a user-reported suspicious email using authorized message metadata to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before act...Votes: 0GitHub stars: 2
- Security Egress Exception Expiration AuditUse when a task involves reviewing outbound network exceptions for purpose, owner, evidence, and expiry to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before ...Votes: 0GitHub stars: 2
- Security Dns Change Ownership And Risk ReviewUse when a task involves reviewing an authorized DNS change for ownership, target, and exposure implications to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval be...Votes: 0GitHub stars: 2
- Security Detection Rule Evidence And Noise ReviewUse when a task involves reviewing a detection rule's evidence quality, scope, and operational noise to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before act...Votes: 0GitHub stars: 2
- Security Detection Coverage Gap To Test CaseUse when a task involves turning an identified defensive monitoring gap into a safe validation plan to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before acti...Votes: 0GitHub stars: 2
- Security Data Exposure Scope EstimationUse when a task involves estimating which data classes and records may have been exposed during a security incident to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit appr...Votes: 0GitHub stars: 2
- Security Control Test Sampling PlanUse when a task involves choosing a representative sample for a bounded security control verification to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before ac...Votes: 0GitHub stars: 2
- Security Cloud Resource Quarantine ReviewUse when a task involves planning a reversible cloud resource quarantine during a security incident to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before acti...Votes: 0GitHub stars: 2
- Security Cloud Audit Log Coverage MappingUse when a task involves checking which cloud control-plane actions are recorded and retained to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before active tes...Votes: 0GitHub stars: 2
- Security Cloud Audit Event TimelineUse when a task involves assembling cloud control-plane evidence for an incident review to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before active testing, ...Votes: 0GitHub stars: 2
- Security Clock Sync For Incident CorrelationUse when a task involves assessing whether clock synchronization supports reliable security event correlation to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval b...Votes: 0GitHub stars: 2
- Security Backup Restore Integrity ExerciseUse when a task involves evaluating recoverability of security-critical systems and data through an authorized exercise to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit ...Votes: 0GitHub stars: 2
- Security Authentication Policy Drift AuditUse when a task involves comparing deployed authentication controls with the approved identity policy to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before ac...Votes: 0GitHub stars: 2
- Security Asvs Versioned Requirement MappingUse when a task involves mapping application security verification evidence to an explicit OWASP ASVS version to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval b...Votes: 0GitHub stars: 2
- Security Assessment Report Audience Detail ControlUse when a task involves tailoring security findings to authorized report readers to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before active testing, contai...Votes: 0GitHub stars: 2
- Security Assessment Privacy Impact ScreenUse when a task involves screening a security test for exposure of personal or sensitive information to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval before act...Votes: 0GitHub stars: 2
- Security Active Passive Assessment BoundaryUse when a task involves classifying proposed security assessment actions by their potential to affect a target to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain explicit approval...Votes: 0GitHub stars: 2
- Security Account Takeover Containment ReviewUse when a task involves coordinating response when evidence suggests an identity may be controlled by an unauthorized actor to record the asset owner, authorized environment, exact scope, applicable policy or assessment approval, evidence source, data sensitivity, and potential service impact. Prefer current primary references, bounded non-destructive checks, synthetic data, and independently verifiable evidence. Separate observed facts from assumptions, preserve uncertainty, and obtain expl...Votes: 0GitHub stars: 2
- Pentest KaliUse when a task involves conducting a bounded penetration test with Kali tools against a system explicitly authorized for testing to identify the intended outcome, relevant inputs, platform or version, sensitive data, and permission boundary before acting. Use current primary documentation for version-sensitive behavior, produce a reviewable artifact, and verify it against stated criteria. Trigger for planning, implementation, evaluation, or troubleshooting in this focused domain; do not inst...Votes: 0GitHub stars: 2
- Pci Compliance Version CompatibilityUse when a Payment-card control evidence integration or upgrade depends on compatible runtime, client, service, or artifact versions. Produce a version-compatibility record for Payment-card control evidence with exact versions, supported combinations, and open questions. Success means the tested version tuple is explicit, each compatibility claim has a dated source or local result, and unsupported combinations are not presented as working. The review is bounded to in-scope data flow, system b...Votes: 0GitHub stars: 2
- Pci Compliance Reproducibility Fixture PlanUse when a Payment-card control evidence result must be independently repeated or compared without relying on an uncontrolled live action. Produce a reproducibility plan for Payment-card control evidence defining fixture identity, environment, expected observations, and cleanup boundary. Success means another reviewer can identify the fixture and environment, distinguish expected from observed behavior, and repeat the check without an unapproved external effect. The review is bounded to in-sc...Votes: 0GitHub stars: 2
- Pci Compliance Release Handoff RecordUse when a Payment-card control evidence review is ready to be handed to a maintainer or accountable operator. Produce a release-handoff record for Payment-card control evidence with version, evidence, open issues, approval state, and safe next step. Success means the receiver can distinguish verified facts, proposals, approvals, and unknowns, and no publication, deployment, write, or contact is claimed unless independently confirmed. The review is bounded to in-scope data flow, system bounda...Votes: 0GitHub stars: 2
- Pci Compliance Performance EnvelopeUse when Payment-card control evidence must be assessed against a user- or owner-defined latency, memory, throughput, size, or cost budget. Produce a performance-envelope note for Payment-card control evidence with test conditions, baseline, observed range, and limitations. Success means conditions and measurements are reproducible, the comparison uses the stated budget, and limitations or resource costs are visible. The review is bounded to in-scope data flow, system boundary, control eviden...Votes: 0GitHub stars: 2