All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 29,002
- 1,209
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 1,513–1,536 of 29,002 skills
- Authorizedsec Ai Tool And Prompt Security Threat Modeling Option Comparison MatrixUse when several tools, designs, methods, or workflows could satisfy the same need for Authorized cybersecurity testing and defense: AI tool and prompt security for threat modeling. Produce an evidence-backed option-comparison matrix with scope, versions, decisions, and evidence for this task-specific gate: Rank abuse cases by asset, trust boundary, impact, likelihood, and existing controls without performing out-of-scope exploitation. Success means options are compared on user-approved crite...Votes: 0GitHub stars: 2
- Authorizedsec Ai Tool And Prompt Security Threat Modeling Failure Triage And RecoveryUse when an unexpected result needs diagnosis without widening risk or losing evidence for Authorized cybersecurity testing and defense: AI tool and prompt security for threat modeling. Produce a failure-triage record and reversible recovery plan with scope, versions, decisions, and evidence for this task-specific gate: Rank abuse cases by asset, trust boundary, impact, likelihood, and existing controls without performing out-of-scope exploitation. Success means the failure is bounded by obse...Votes: 0GitHub stars: 2
- Authorizedsec Ai Tool And Prompt Security Threat Modeling Design BlueprintUse when a solution needs a coherent structure before implementation or production for Authorized cybersecurity testing and defense: AI tool and prompt security for threat modeling. Produce a staged design blueprint with scope, versions, decisions, and evidence for this task-specific gate: Rank abuse cases by asset, trust boundary, impact, likelihood, and existing controls without performing out-of-scope exploitation. Success means interfaces, dependencies, constraints, and review points are ...Votes: 0GitHub stars: 2
- Authorizedsec Ai Tool And Prompt Security Threat Modeling Build Configuration RunbookUse when an authorized implementation needs repeatable steps and a visible change boundary for Authorized cybersecurity testing and defense: AI tool and prompt security for threat modeling. Produce a bounded build or configuration runbook with scope, versions, decisions, and evidence for this task-specific gate: Rank abuse cases by asset, trust boundary, impact, likelihood, and existing controls without performing out-of-scope exploitation. Success means the prepared result is reproducible, r...Votes: 0GitHub stars: 2
- Authorizedsec Ai Tool And Prompt Security Secure Configuration Failure Triage And RecoveryUse when an unexpected result needs diagnosis without widening risk or losing evidence for Authorized cybersecurity testing and defense: AI tool and prompt security for secure configuration. Produce a failure-triage record and reversible recovery plan with scope, versions, decisions, and evidence for this task-specific gate: Compare observed settings to current authoritative requirements and document any environment-specific exception. Success means the failure is bounded by observations, one...Votes: 0GitHub stars: 2
- Authorizedsec Ai Tool And Prompt Security Secure Configuration Design BlueprintUse when a solution needs a coherent structure before implementation or production for Authorized cybersecurity testing and defense: AI tool and prompt security for secure configuration. Produce a staged design blueprint with scope, versions, decisions, and evidence for this task-specific gate: Compare observed settings to current authoritative requirements and document any environment-specific exception. Success means interfaces, dependencies, constraints, and review points are testable befo...Votes: 0GitHub stars: 2
- Marketing PsychologyUse when a task involves applying behavioral science to improve a marketing experience while preserving user understanding and choice to identify the intended outcome, relevant inputs, platform or version, sensitive data, and permission boundary before acting. Use current primary documentation for version-sensitive behavior, produce a reviewable artifact, and verify it against stated criteria. Trigger for planning, implementation, evaluation, or troubleshooting in this focused domain; do not ...Votes: 0GitHub stars: 2
- Parallel Web SearchUse when a task involves using an approved Parallel web-search integration for source discovery, extraction, or targeted research to identify the intended outcome, relevant inputs, platform or version, sensitive data, and permission boundary before acting. Use current primary documentation for version-sensitive behavior, produce a reviewable artifact, and verify it against stated criteria. Trigger for planning, implementation, evaluation, or troubleshooting in this focused domain; do not inst...Votes: 0GitHub stars: 2
- Mcp Streamable Http Stateless Deployment ReviewUse when deploying, upgrading, or auditing an MCP server over Streamable HTTP, especially when moving from session-based or HTTP+SSE behavior to the 2026-07-28 stateless request model to review the endpoint, POST/SSE flow, request metadata, Origin validation, authentication, subscriptions, cancellation, and legacy compatibility. Success means each request is correctly scoped, network exposure is intentional, and no deprecated stream/session assumption creates a security or interoperability gap.Votes: 0GitHub stars: 2
- Mcp Server Integration SafetyUse when selecting, configuring, building, or reviewing an MCP server or connection to assess publisher and version, tool schemas, authentication, scopes, data access, network egress, sandbox, approval gates, and audit logging before enabling actions. Trigger before connecting new MCP tools, changing permissions, or exposing agent capabilities to a server.Votes: 0GitHub stars: 2
- Mcp Server DevelopmentUse when building or modifying an MCP server that exposes tools, resources, prompts, or transport behavior to an agent host to verify current protocol and SDK documentation, keep capabilities narrow, validate every boundary, and test through a local or staging client before exposing the service. Trigger for MCP server authoring, SDK upgrades, or transport changes.Votes: 0GitHub stars: 2
- Mcp Multiroundtrip Input Flow ReviewUse when designing or testing an MCP request that may pause to ask the client or user for additional input before completing, such as a tool call that needs approval or a prompt/resource that needs a selection to review InputRequiredResult, input requests/responses, opaque request state, retry IDs, consent, replay handling, and supported request types. Success means the retry is bound to the original request, user decisions remain explicit, and incomplete or repeated input cannot cause an uni...Votes: 0GitHub stars: 2
- Mcp Http Authorization And Registration AuditUse when auditing OAuth authorization between an MCP client, protected MCP server, and authorization server over an HTTP transport to verify protected-resource discovery, issuer binding, client registration, resource indicators, token audience, scopes, PKCE, and separation from upstream API credentials. Success means a token is accepted only for its intended MCP resource and authorization context, least privilege is demonstrable, and mismatched or overbroad credentials are rejected without le...Votes: 0GitHub stars: 2
- Mcp Conformance And Interoperability Test PlanUse when preparing a test plan for an MCP client, server, SDK, or integration across protocol versions, transports, capabilities, or optional extensions to produce a reproducible matrix of discovery, request/response, authorization, errors, cancellation, and extension scenarios. Success means tests cover both expected behavior and meaningful failure paths for each supported peer combination, findings identify exact versions, and no single visual inspection is presented as full protocol confor...Votes: 0GitHub stars: 2
- Gh Aw Workflow Supply Chain Change ReviewUse when a task involves reviewing changes to actions, agents, skills, MCP servers, and model dependencies in a workflow to record the product, runtime and repository version, identity, trust boundary, data sensitivity, controlling artifact, owner, and approval scope before applying the method. Distinguish documented behavior from tested behavior, verify with a bounded reproducible case, preserve provenance, and report compatibility and uncertainty. Do not install, grant access, send external...Votes: 0GitHub stars: 2
- Gh Aw Workflow Secrets Context AuditUse when a task involves checking which workflow jobs and agent processes can access named secrets to record the product, runtime and repository version, identity, trust boundary, data sensitivity, controlling artifact, owner, and approval scope before applying the method. Distinguish documented behavior from tested behavior, verify with a bounded reproducible case, preserve provenance, and report compatibility and uncertainty. Do not install, grant access, send external writes, or change pro...Votes: 0GitHub stars: 2
- Gh Aw Workflow Permission Elevation ReviewUse when a task involves reviewing any workflow stage that increases permissions beyond the initial analysis job to record the product, runtime and repository version, identity, trust boundary, data sensitivity, controlling artifact, owner, and approval scope before applying the method. Distinguish documented behavior from tested behavior, verify with a bounded reproducible case, preserve provenance, and report compatibility and uncertainty. Do not install, grant access, send external writes,...Votes: 0GitHub stars: 2
- Gh Aw Workflow Human Override And StopUse when a task involves designing a clear human mechanism to pause or stop an active agent workflow to record the product, runtime and repository version, identity, trust boundary, data sensitivity, controlling artifact, owner, and approval scope before applying the method. Distinguish documented behavior from tested behavior, verify with a bounded reproducible case, preserve provenance, and report compatibility and uncertainty. Do not install, grant access, send external writes, or change p...Votes: 0GitHub stars: 2
- Gh Aw Trigger Scope And Event AuthorizationUse when a task involves reviewing which GitHub events are allowed to start an agentic workflow to record the product, runtime and repository version, identity, trust boundary, data sensitivity, controlling artifact, owner, and approval scope before applying the method. Distinguish documented behavior from tested behavior, verify with a bounded reproducible case, preserve provenance, and report compatibility and uncertainty. Do not install, grant access, send external writes, or change produc...Votes: 0GitHub stars: 2
- Gh Aw Trigger Rate And Abuse ThrottleUse when a task involves setting limits on repeated or adversarial events that can invoke an agent workflow to record the product, runtime and repository version, identity, trust boundary, data sensitivity, controlling artifact, owner, and approval scope before applying the method. Distinguish documented behavior from tested behavior, verify with a bounded reproducible case, preserve provenance, and report compatibility and uncertainty. Do not install, grant access, send external writes, or c...Votes: 0GitHub stars: 2
- Gh Aw Safe Summary Claim Evidence AuditUse when a task involves checking that a workflow summary distinguishes verified results from model-generated interpretation to record the product, runtime and repository version, identity, trust boundary, data sensitivity, controlling artifact, owner, and approval scope before applying the method. Distinguish documented behavior from tested behavior, verify with a bounded reproducible case, preserve provenance, and report compatibility and uncertainty. Do not install, grant access, send exte...Votes: 0GitHub stars: 2
- Gh Aw Safe Output Write Scope AuditUse when a task involves auditing the repository writes an agent workflow may perform after analysis to record the product, runtime and repository version, identity, trust boundary, data sensitivity, controlling artifact, owner, and approval scope before applying the method. Distinguish documented behavior from tested behavior, verify with a bounded reproducible case, preserve provenance, and report compatibility and uncertainty. Do not install, grant access, send external writes, or change p...Votes: 0GitHub stars: 2
- Gh Aw Reusable Workflow Trust ReviewUse when a task involves reviewing inherited authority and code when an agentic workflow calls a reusable workflow to record the product, runtime and repository version, identity, trust boundary, data sensitivity, controlling artifact, owner, and approval scope before applying the method. Distinguish documented behavior from tested behavior, verify with a bounded reproducible case, preserve provenance, and report compatibility and uncertainty. Do not install, grant access, send external write...Votes: 0GitHub stars: 2
- Gh Aw Pull Request Comment SanitizationUse when a task involves reviewing how model-generated text is sanitized before posting to a pull request to record the product, runtime and repository version, identity, trust boundary, data sensitivity, controlling artifact, owner, and approval scope before applying the method. Distinguish documented behavior from tested behavior, verify with a bounded reproducible case, preserve provenance, and report compatibility and uncertainty. Do not install, grant access, send external writes, or cha...Votes: 0GitHub stars: 2