All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 28,990
- 1,208
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 1,153–1,176 of 28,990 skills
- Pci Compliance Failure Triage RecordUse when a reproducible Payment-card control evidence symptom needs bounded diagnosis before any corrective change. Produce a failure-triage record for Payment-card control evidence with symptom, environment, evidence, hypothesis, and next safe check. Success means the diagnosis distinguishes observation from inference, each proposed check is reversible and scoped, and unresolved causes remain open. The review is bounded to in-scope data flow, system boundary, control evidence, retention, and...Votes: 0GitHub stars: 2
- Pci Compliance Change Impact AssessmentUse when a proposed Payment-card control evidence version, setting, schema, model, or integration change may affect existing consumers. Produce a change-impact record for Payment-card control evidence with baseline, affected dependencies, validation needs, and recovery boundary. Success means affected dependencies and compatibility assumptions are evidenced, unknown consumers are named as unknown, and no migration or rollout is implied. The review is bounded to in-scope data flow, system boun...Votes: 0GitHub stars: 2
- Pci Compliance Capability Surface MapUse when the actual capability boundary of Payment-card control evidence needs to be distinguished from assumptions. Produce a capability map for Payment-card control evidence covering the requested behavior, verified support, exclusions, and unknowns. Success means each in-scope capability is tied to local configuration, a version-matched authoritative reference, or an observed non-production result, and all unknowns remain explicit. The review is bounded to in-scope data flow, system bounda...Votes: 0GitHub stars: 2
- Cloud Identity Credential ReviewUse when a task involves reviewing cloud identity and credential configuration for least privilege, lifecycle, and exposure risks to identify the intended outcome, relevant inputs, platform or version, sensitive data, and permission boundary before acting. Use current primary documentation for version-sensitive behavior, produce a reviewable artifact, and verify it against stated criteria. Trigger for planning, implementation, evaluation, or troubleshooting in this focused domain; do not inst...Votes: 0GitHub stars: 2
- Azure Security Keyvault Secrets Java Version CompatibilityUse when a Azure Key Vault Secrets SDK for Java integration or upgrade depends on compatible runtime, client, service, or artifact versions. Produce a version-compatibility record for Azure Key Vault Secrets SDK for Java with exact versions, supported combinations, and open questions. Success means the tested version tuple is explicit, each compatibility claim has a dated source or local result, and unsupported combinations are not presented as working. The review is bounded to secret identit...Votes: 0GitHub stars: 2
- Azure Security Keyvault Secrets Java Reproducibility Fixture PlanUse when a Azure Key Vault Secrets SDK for Java result must be independently repeated or compared without relying on an uncontrolled live action. Produce a reproducibility plan for Azure Key Vault Secrets SDK for Java defining fixture identity, environment, expected observations, and cleanup boundary. Success means another reviewer can identify the fixture and environment, distinguish expected from observed behavior, and repeat the check without an unapproved external effect. The review is bo...Votes: 0GitHub stars: 2
- Azure Security Keyvault Secrets Java Release Handoff RecordUse when a Azure Key Vault Secrets SDK for Java review is ready to be handed to a maintainer or accountable operator. Produce a release-handoff record for Azure Key Vault Secrets SDK for Java with version, evidence, open issues, approval state, and safe next step. Success means the receiver can distinguish verified facts, proposals, approvals, and unknowns, and no publication, deployment, write, or contact is claimed unless independently confirmed. The review is bounded to secret identity, ve...Votes: 0GitHub stars: 2
- Azure Security Keyvault Secrets Java Performance EnvelopeUse when Azure Key Vault Secrets SDK for Java must be assessed against a user- or owner-defined latency, memory, throughput, size, or cost budget. Produce a performance-envelope note for Azure Key Vault Secrets SDK for Java with test conditions, baseline, observed range, and limitations. Success means conditions and measurements are reproducible, the comparison uses the stated budget, and limitations or resource costs are visible. The review is bounded to secret identity, version lifecycle, c...Votes: 0GitHub stars: 2
- Azure Security Keyvault Secrets Java Failure Triage RecordUse when a reproducible Azure Key Vault Secrets SDK for Java symptom needs bounded diagnosis before any corrective change. Produce a failure-triage record for Azure Key Vault Secrets SDK for Java with symptom, environment, evidence, hypothesis, and next safe check. Success means the diagnosis distinguishes observation from inference, each proposed check is reversible and scoped, and unresolved causes remain open. The review is bounded to secret identity, version lifecycle, cache behavior, mas...Votes: 0GitHub stars: 2
- Azure Security Keyvault Secrets Java Change Impact AssessmentUse when a proposed Azure Key Vault Secrets SDK for Java version, setting, schema, model, or integration change may affect existing consumers. Produce a change-impact record for Azure Key Vault Secrets SDK for Java with baseline, affected dependencies, validation needs, and recovery boundary. Success means affected dependencies and compatibility assumptions are evidenced, unknown consumers are named as unknown, and no migration or rollout is implied. The review is bounded to secret identity, ...Votes: 0GitHub stars: 2
- Azure Security Keyvault Secrets Java Capability Surface MapUse when the actual capability boundary of Azure Key Vault Secrets SDK for Java needs to be distinguished from assumptions. Produce a capability map for Azure Key Vault Secrets SDK for Java covering the requested behavior, verified support, exclusions, and unknowns. Success means each in-scope capability is tied to local configuration, a version-matched authoritative reference, or an observed non-production result, and all unknowns remain explicit. The review is bounded to secret identity, ve...Votes: 0GitHub stars: 2
- Application Security ReviewUse when reviewing application code, APIs, dependencies, or configuration for security weaknesses, especially around identity, authorization, untrusted input, sensitive data, or external integrations to map trust boundaries, test relevant controls safely, and report evidence-based risks with practical mitigations. Trigger for a requested security review or a high-risk software change; this is not an authorization to exploit systems or alter production.Votes: 0GitHub stars: 2
- Aas Secure Delivery Webhook Replay Threshold Rule CheckUse when a webhook signature and replay protection decision depends on a limit, eligibility rule, policy, or target to produce a rule-check record for the webhook verification test matrix showing source, units, boundary case, and outcome. Success means the rule source and effective date are verified, units and scope match, and borderline cases are flagged rather than auto-approved; valid events are accepted once and tampered or replayed events are rejected. Use configured search, fetch, read,...Votes: 0GitHub stars: 2
- Aas Secure Delivery Webhook Replay Source Provenance LedgerUse when a decision about webhook signature and replay protection depends on facts from several records or public sources to produce a source-to-claim provenance ledger for the webhook verification test matrix. Success means each material claim has a source, version/date, location, and confidence note; valid events are accepted once and tampered or replayed events are rejected. Use configured search, fetch, read, browser, test, and write capabilities only when relevant and authorized. Record ...Votes: 0GitHub stars: 2
- Aas Secure Delivery Webhook Replay Scope Intake GateUse when a new webhook signature and replay protection request needs a bounded work scope to produce a scoped intake card for the webhook verification test matrix. Success means owner, objective, permitted sources, acceptance condition, exclusions, and deadline are explicit; valid events are accepted once and tampered or replayed events are rejected. Use configured search, fetch, read, browser, test, and write capabilities only when relevant and authorized. Record evidence, limit refinement t...Votes: 0GitHub stars: 2
- Aas Secure Delivery Webhook Replay Scenario Sensitivity MatrixUse when the webhook signature and replay protection team needs to compare options under changing assumptions to produce a baseline-plus-scenarios matrix for the webhook verification test matrix with assumptions and ranges. Success means the baseline is reproducible, scenario inputs are explicit, comparable units are used, and conclusions state uncertainty; valid events are accepted once and tampered or replayed events are rejected. Use configured search, fetch, read, browser, test, and write...Votes: 0GitHub stars: 2
- Aas Secure Delivery Webhook Replay Recovery Readiness DrillUse when the webhook signature and replay protection workflow needs a safe recovery, rollback, replay, or continuity check to produce a recovery-drill record for the webhook verification test matrix with starting state, test, and observed outcome. Success means the dry-run or approved non-production drill meets the predeclared recovery target and leaves the baseline intact; valid events are accepted once and tampered or replayed events are rejected. Use configured search, fetch, read, browser...Votes: 0GitHub stars: 2
- Aas Secure Delivery Webhook Replay Exception Triage QueueUse when the webhook signature and replay protection workflow has exceptions, missing evidence, or competing priorities to produce a prioritized exception queue for the webhook verification test matrix with evidence, owner, and next action. Success means every exception has a severity rationale, source, owner or explicit unassigned state, and a bounded next step; valid events are accepted once and tampered or replayed events are rejected. Use configured search, fetch, read, browser, test, and...Votes: 0GitHub stars: 2
- Aas Secure Delivery Webhook Replay Completeness ReconciliationUse when the webhook signature and replay protection workflow receives records that must agree across sources, periods, or statuses to produce a reconciliation worksheet for the webhook verification test matrix with matched, unmatched, and unresolved rows. Success means counts and key fields reconcile or every variance is quantified, sourced, and left unresolved for an owner; valid events are accepted once and tampered or replayed events are rejected. Use configured search, fetch, read, brows...Votes: 0GitHub stars: 2
- Aas Secure Delivery Webhook Replay Closeout Handoff LedgerUse when a webhook signature and replay protection work item is nearing completion, pause, or transfer to another owner to produce a closeout ledger for the webhook verification test matrix with status, evidence, owner, and retention state. Success means all deliverables, unresolved items, approvals, and next owners are recorded, and the stop reason is explicit; valid events are accepted once and tampered or replayed events are rejected. Use configured search, fetch, read, browser, test, and ...Votes: 0GitHub stars: 2
- Aas Secure Delivery Webhook Replay Change Impact TraceUse when a version, rule, source, or stakeholder change may affect webhook signature and replay protection to produce a before/after change record and impact map for the webhook verification test matrix. Success means each material difference is tied to affected dependencies, consumers, owners, and a test or explicitly unknown impact; valid events are accepted once and tampered or replayed events are rejected. Use configured search, fetch, read, browser, test, and write capabilities only when...Votes: 0GitHub stars: 2
- Aas Secure Delivery Webhook Replay Approval Evidence PacketUse when a webhook signature and replay protection result is ready for a human owner to approve, reject, or redirect to produce a decision packet for the webhook verification test matrix containing options, evidence, risks, and open questions. Success means the decision owner, requested decision, source evidence, alternatives, uncertainty, and consequence of no action are all visible; valid events are accepted once and tampered or replayed events are rejected. Use configured search, fetch, re...Votes: 0GitHub stars: 2
- Aas Secure Delivery Vulnerability Response Threshold Rule CheckUse when a application vulnerability response coordination decision depends on a limit, eligibility rule, policy, or target to produce a rule-check record for the vulnerability response handoff showing source, units, boundary case, and outcome. Success means the rule source and effective date are verified, units and scope match, and borderline cases are flagged rather than auto-approved; a responsible owner and safe next step are assigned without publishing sensitive details. Use configured s...Votes: 0GitHub stars: 2
- Aas Secure Delivery Vulnerability Response Source Provenance LedgerUse when a decision about application vulnerability response coordination depends on facts from several records or public sources to produce a source-to-claim provenance ledger for the vulnerability response handoff. Success means each material claim has a source, version/date, location, and confidence note; a responsible owner and safe next step are assigned without publishing sensitive details. Use configured search, fetch, read, browser, test, and write capabilities only when relevant and ...Votes: 0GitHub stars: 2