All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 26,873
- 1,120
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 193–216 of 26,873 skills
- Crypto AlgorithmsAlgorithm selection guide: a decision tree for cryptographic choices, key size guidelines, modes of operation, and worked examples for authenticated encryption with libsodium, Argon2id password hashing, and Ed25519 signatures. Use when picking an algorithm, mode, or key size.Votes: 0GitHub stars: 4
- Dockerfile HardeningSecure Dockerfile patterns: base image hierarchy, multi-stage builds for Node.js and Go on distroless or scratch, BuildKit secret mounts, and non-root execution. Use when writing or reviewing a Dockerfile.Votes: 0GitHub stars: 4
- Container Runtime SecurityContainer runtime isolation reference: namespaces, Linux capabilities, seccomp, AppArmor, user namespace remapping, hardened docker run and Compose examples, and anti-patterns such as --privileged, Docker socket mounts, and --pid=host. Use when configuring how containers run.Votes: 0GitHub stars: 4
- Soc2 ControlsSOC 2 Type II reference: the Trust Service Criteria, Common Criteria controls, evidence requirements, a readiness pattern, and common auditor requests. Use when preparing for a SOC 2 audit or designing controls to satisfy it.Votes: 0GitHub stars: 4
- Gdpr RequirementsGDPR reference for technology teams: key definitions, Article 5 principles, lawful bases, data subject rights, data protection by design, processor duties, breach notification, DPIAs, a SaaS compliance checklist, and a data deletion pattern. Use when building or reviewing systems that process EU personal data.Votes: 0GitHub stars: 4
- Gcp Iam PatternsGCP IAM reference: the permission model, role types, deny policies, least-privilege service accounts, Workload Identity Federation for CI, custom roles, domain-restricted sharing, and GKE Workload Identity. Use when writing or reviewing GCP IAM bindings.Votes: 0GitHub stars: 4
- Azure Identity PatternsEntra ID security patterns: Conditional Access baseline policies, managed identities, Privileged Identity Management, certificate-based service principals, and anti-patterns such as permanent Global Administrator assignments and client secrets. Use when designing or reviewing Azure identity.Votes: 0GitHub stars: 4
- Aws S3 SecurityS3 security reference: access control layers, encryption models, a secure bucket baseline in Terraform, TLS-only bucket policies, access points, and anti-patterns such as public buckets and ACL reliance. Use when configuring or auditing S3 buckets.Votes: 0GitHub stars: 4
- Aws Iam PatternsAWS IAM reference: policy evaluation logic, policy types, least-privilege Lambda roles, permission boundaries, SCP guardrails, cross-account access with external ID, and IAM anti-patterns such as unconstrained PassRole. Use when writing or reviewing IAM policies.Votes: 0GitHub stars: 4
- Vuln Report WritingGuide to vulnerability reports that get accepted and triaged: title writing, CVSS v3.1 scoring, reproduction steps, impact writing, the report lifecycle, chaining, evidence, and minimal PoC scripts. Use when drafting or reviewing a bug bounty or disclosure report.Votes: 0GitHub stars: 4
- Recon MethodologyReconnaissance methodology for authorized bug bounty programs: passive recon (certificate transparency, search engine and code dorking, historical URLs), in-scope active recon (subdomain enumeration, live host probing, content and JavaScript analysis), and attack surface mapping. Use when scoping recon inside a program's published rules.Votes: 0GitHub stars: 4
- Threat Hunting MethodologyHypothesis-driven threat hunting framework with hunt categories, required data sources, worked hunts for DNS tunneling, lateral movement, and persistence, and a hunt documentation template. Use when planning, running, or documenting a threat hunt.Votes: 0GitHub stars: 4
- Detection EngineeringDetection engineering reference: the detection lifecycle and quality metrics, Sigma rule syntax and modifiers, YARA rule writing, a detection-as-code CI pipeline, and essential Windows detections. Use when writing, testing, or maintaining detection rules.Votes: 0GitHub stars: 4
- Api Auth PatternsSecure implementation patterns for API authentication and authorization: OAuth 2.0 flows, JWT best practices, API key handling with constant-time comparison, mTLS, session management, authorization middleware, token refresh, and rate limiting. Use when building or reviewing API auth code.Votes: 0GitHub stars: 4
- llllLLLL (Layrix Logic Layer Loop) — Embedded Compliance Layer for AI-built software. Continuously active compliance engine integrated into development workflows — performing software resilience auditing, automated security scanning, feature-to-policy mapping, compliance diagnosis, gap detection, checklist generation, actionable briefs, GRC dashboards, push/release compliance gates (LLLL Guard), human expert review escalation, and design-time governance.Votes: 0GitHub stars: 2
- ChangelogA `custom-service` permission request may name the header a pasted token is sent as. Before, a custom service without a browser sign-in could only take `Authorization: Bearer <token>`, so an API keyed by `X-Api-Key` or any other header was out of reach even though `latchkey auth set` stores arbitrary headers. The request payload gains an optional `header`, a header line with `{token}` where the value goes, validated by the same rule as `token-capture`'s `header` plus what the gateway must nev...Votes: 0GitHub stars: 413
- Opencode Mcp Server SetupAdd or configure an MCP server in opencode's config (~/.config/opencode/opencode.json or project .opencode/) — both server types: LOCAL/stdio {"type": "local", "command": ["npx", "pkg"], "enabled": true} and REMOTE/HTTP {"type": "remote", "url": "...", "enabled": true}. Use when the user says 'add the X MCP server', 'install/configure MCP', 'connect to <service> MCP', an MCP server appears in docs but isn't wired into opencode, tools from a known MCP server are missing in a session, or a serv...Votes: 0GitHub stars: 39
- Trade Export ControlThis source skill describes how an AML agent should work with the **Trade, export control** source category inside a client-approved implementation profile. It is a source workflow, not a bundled data subscription. It does not include credentials, paid database access, provider-specific bypass instructions or proprietary source content.Votes: 0GitHub stars: 2
- Pep Media Public SearchThis source skill describes how an AML agent should work with the **PEP, media and public search** source category inside a client-approved implementation profile. It is a source workflow, not a bundled data subscription. It does not include credentials, paid database access, provider-specific bypass instructions or proprietary source content.Votes: 0GitHub stars: 2
- Official Sanctions DatabasesThis source skill describes how an AML agent should work with the **Official sanctions databases** source category inside a client-approved implementation profile. It is a source workflow, not a bundled data subscription. It does not include credentials, paid database access, provider-specific bypass instructions or proprietary source content.Votes: 0GitHub stars: 2
- Kyb Ubo Regulator RegistersThis source skill describes how an AML agent should work with the **KYB, UBO and regulator registers** source category inside a client-approved implementation profile. It is a source workflow, not a bundled data subscription. It does not include credentials, paid database access, provider-specific bypass instructions or proprietary source content.Votes: 0GitHub stars: 2
- Domain Dns Ip IntelligenceThis source skill describes how an AML agent should work with the **Domain, DNS and IP intelligence** source category inside a client-approved implementation profile. It is a source workflow, not a bundled data subscription. It does not include credentials, paid database access, provider-specific bypass instructions or proprietary source content.Votes: 0GitHub stars: 2
- Blockchain IntelligenceThis source skill describes how an AML agent should work with the **Blockchain intelligence** source category inside a client-approved implementation profile. It is a source workflow, not a bundled data subscription. It does not include credentials, paid database access, provider-specific bypass instructions or proprietary source content.Votes: 0GitHub stars: 2
- Supplier ReviewOperation skill.Votes: 0GitHub stars: 2