All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 26,873
- 1,120
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 121–144 of 26,873 skills
- Security And HardeningUse when handling sensitive data, authentication, network communication, or before shipping to the Play Store. Three-tier framework (Always Do, Ask First, Never Do) with Android-specific security patterns, plus data privacy and compliance (GDPR/CCPA, Play Data safety, account deletion).Votes: 0GitHub stars: 2
- Addyosmani Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.Votes: 0GitHub stars: 2
- Addyosmani Code Review And QualityConducts multi-axis code review. Use before merging any change. Use when reviewing code written by yourself, another agent, or a human. Use when you need to assess code quality across multiple dimensions before it enters the main branch.Votes: 0GitHub stars: 2
- Arxiv 2609 28900 Codetta Multi Agent CollusionResearch paper: Codetta: High-Capacity, Keyless, and Undetectable Multi-Agent Collusion.Votes: 0GitHub stars: 3
- Arxiv 2609 28693 Progressive Skill Discovery Access ControlResearch paper: Progressive Skill Discovery as Access Control for Tool-Using LLM Agents: Structural Governance through Role-Scoped Capability Delivery.Votes: 0GitHub stars: 3
- Quantum Auction Summation ReductionsReductions between quantum auctions and secure summation.Votes: 0GitHub stars: 3
- Arxiv 2609 39788 Safety Of Latent Communication In Multi Agent SystemsResearch paper: Safety of Latent Communication in Multi-Agent Systems. Demonstrates that benign link training in latent communication increases harmful compliance relative to text-based communication. Develops RL-based attack raising harmful-compliance from 27.9 to 76.9, and shows reward adaptation enables repair without updating agents.Votes: 0GitHub stars: 3
- Ai Code Generation GuardrailsAutonomous AI code generation safety guardrail register: static AST analysis, forbidden import filters, and zero-day vulnerability checks.Votes: 0GitHub stars: 6
- ReviewFull QA review pipeline covering security audit (OWASP Top 10), performance analysis, accessibility check (WCAG 2.2 AA), and code quality reviewVotes: 0GitHub stars: 46
- Provider Access SubmitEnd-to-end execution of a scouted third-party provider access campaign. Use when a Provider Access Launch task is ready_to_submit or scouted easy_execute and needs account or app registration, scopes, reviewer assets, Vault credential custody, the canonical connection, and real verification.Votes: 0GitHub stars: 3
- Provider Access ScoutDecision-ready scouting record for a user-connected provider access campaign. Use when an assigned Provider Access Launch task needs its easiest official route, minimum scopes, cost, account needs, approval path, implementation consumer, and easy-execute verdict established before submission. NOT for client Local Listings distribution.Votes: 0GitHub stars: 3
- Provider Access ChaseFollow-up sweep for pending third-party provider access campaigns. Use when the recurring 30-minute Provider Access Launch dispatcher wakes, or for a manual status check of due email threads, developer portals, support cases, or review deadlines.Votes: 0GitHub stars: 3
- Persistence Repair PatrolScheduled patrol that finds real persistence and error bugs and fixes them. Use when running the system-error repair patrol automation, or when stuck rows, SLA breaches, the system_errors queue, or app_log ERROR rows need a repair rather than a report.Votes: 0GitHub stars: 3
- Mcp Server AuditSecurity audit of Model Context Protocol (MCP) servers — tool poisoning, prompt injection via tool descriptions and results, unscoped/over-privileged tools, path traversal in file tools, command injection in shell/exec tools, SSRF in fetch tools, secret leakage through tool output, missing approval gates on state-changing actions, confused-deputy and rug-pull tool redefinition, token passthrough, and unsafe stdio/HTTP transport config. Covers auditing both first-party and third-party MCP serv...Votes: 0GitHub stars: 5,270
- Llm RedteamLLM application red-teaming — prompt injection (direct + indirect), jailbreak, system-prompt leak, data exfiltration, guardrail bypass, multi-turn crescendo, cross-lingual + cipher + invisible-unicode token smuggling, excessive agency / tool abuse, insecure output handling. Canonical OWASP LLM Top 10 + ASI01-ASI10 mapping. Use when a target exposes a chat/completions/assistant/copilot endpoint, an AI feature that consumes user text or documents, or any /v1/chat, /api/chat, /mcp surface.Votes: 0GitHub stars: 5,270
- Cloud PentestPost-access cloud exploitation for AWS, GCP, and Azure — what to do AFTER you obtain credentials or reach a metadata endpoint. Covers IAM enumeration and privilege escalation (iam:PassRole, CreatePolicyVersion, AssumeRole chains, GCP service-account impersonation, Azure managed-identity abuse), IMDSv1/v2 metadata credential theft, STS token abuse, S3/GCS/Blob bucket takeover and object exfil, Lambda/Cloud Functions env-var secrets, cross-account and cross-service pivoting, and turning leaked ...Votes: 0GitHub stars: 5,270
- Angular Upgrade Angular Upgrade Validation GateValidates each Angular major hop with repository-specific build, test, and lint checks before allowing the next upgrade step.Votes: 0GitHub stars: 4
- Angular Security Angular Dependency Vulnerability TriageTriage Angular dependency vulnerabilities by separating real blockers from low-risk advisories.Votes: 0GitHub stars: 4
- Security ScanSecurity review in one pass, design first and code second: identity, authentication and permission design, secrets by design and in the tree, boundary validation and injection (command, SQL, path, template), crypto and randomness, unsafe and dynamic code, trust in third-party code (plugins, models, dependencies), with a posture stating what was swept clean and what was not covered. Use for security reviews or audits, auth or permission design, secrets, injection, crypto, unsafe code, plugin t...Votes: 0GitHub stars: 3
- Django AdminUse when customizing Django Admin - save_formset, get_search_results, formsets, queryset optimization, db_index, custom URLsVotes: 0GitHub stars: 21
- LockdownUse when auditing or hardening a repository against software supply-chain attacks — including dependency lockfile integrity, CVE scanning, malware/typosquat detection, GitHub Actions SHA pinning, secrets scanning, provenance/signing, and SLSA/HIPAA control mapping. Triggers on phrases like "lock down dependencies", "supply chain audit", "is this repo secure", "dependency poisoning", "typosquat", "harden actions", "pin actions", "audit deps", or any concern about consuming or shipping third-pa...Votes: 0GitHub stars: 2
- Otopcy AuditUse before shipping to production, or when asked to audit, review or harden the security of an app — including a vibe-coded or AI-generated one, with or without access to the source. Runs 20 controls, ranks findings by real impact, and refuses to mark anything green without evidence. Also covers what to do when a key has been exposed (revoke first, investigate second).Votes: 0GitHub stars: 2
- Vp Woo Pont Shipping LabelsIntegrate with the shipping-label workflow in Csomagpontok és Címkék WooCommerce-hez. Covers the PRO boundary, normalized label payload, `generate_label()` and idempotency, HPOS-safe parcel meta, payload filters, label-created/error/removed actions, provider selection, PDF links, permissions, remote voiding versus local clearing, Számlázz.hu invoice references, and safe external side effects. Use when another WooCommerce plugin must add label fields, trigger generation, sync tracking numbers,...Votes: 0GitHub stars: 22
- Firestore Rules Creation"Designs, authors, refactors, and hardens production-grade CloudVotes: 0GitHub stars: 16