Security
791 skills.
Browse
performing-web-application-vulnerability-triagemukul975Triages web application vulnerability findings from DAST/SAST scanners such as Burp Suite and ZAP, using the OWASP Risk Rating Methodology to confirm true positives, dismiss false positives, and prioritize remediation. Use when reviewing scanner output to reduce alert fatigue and rank vulnerabilities for development teams to fix.reverse-engineering-android-malware-with-jadxmukul975Reverse engineers malicious Android APK files using the JADX decompiler to read Java/Kotlin source, inspect manifest permissions, receivers, services, and native libraries, and identify data theft, C2 communication, privilege escalation, or overlay-attack behavior. Use when analyzing a suspected Android banking trojan, spyware, SMS stealer, or other flagged APK, or when investigating mobile malware or Android threats generally. 'testing-api-authentication-weaknessesmukul975Tests API authentication mechanisms for weaknesses including broken token validation, missing authentication on endpoints, weak password policies, credential stuffing susceptibility, token leakage in URLs or logs, and session management flaws. The tester evaluates JWT implementation, API key handling, OAuth flows, and session token entropy to identify authentication bypasses. Maps to OWASP API2:2023 Broken Authentication. Activates for requests involving API authentication testing, token validattesting-api-for-broken-object-level-authorizationmukul975Tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR, OWASP API1:2023) by intercepting API calls, identifying object ID parameters (numeric IDs, UUIDs, slugs), and systematically substituting IDs belonging to other users to check whether the server enforces per-object authorization. Use when asked to test BOLA or IDOR in an API, verify object-level authorization, or assess an API for access control bypass. 'testing-api-security-with-owasp-top-10mukul975Systematically assesses REST, GraphQL, and gRPC API endpoints against the OWASP API Security Top 10 (2023) using Burp Suite and Postman for automated and manual testing. Use during authorized API penetration tests, before deploying new endpoints to production, or when validating API gateway controls and rate limiting.testing-cors-misconfigurationmukul975Identifying and exploiting Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain data access and credential theft during security assessments.testing-for-broken-access-controlmukul975Systematically tests web applications and APIs for broken access control (OWASP A01:2021), including privilege escalation, missing function-level checks, insecure direct object references, and multi-tenant data leakage, using Burp Suite with the Authorize extension. Use during authorized penetration tests or RBAC/multi-tenant authorization audits.testing-for-json-web-token-vulnerabilitiesmukul975Tests JWT implementations for algorithm confusion, "none" algorithm bypass, kid/jku parameter injection, and weak secret exploitation using jwt_tool and Burp Suite's JWT Editor extension, aiming to achieve authentication bypass and privilege escalation. Use when assessing JWT-based auth/session management, OAuth2/OIDC token handling, or SSO systems during a security engagement.testing-for-xss-vulnerabilitiesmukul975Tests web applications for reflected, stored, and DOM-based Cross-Site Scripting by injecting JavaScript payloads with Burp Suite (XSS extensions, Active Scan++) and browser tools, then bypassing sanitization and CSP to demonstrate session hijacking and user impersonation. Use for OWASP WSTG client-side injection testing or when evaluating input sanitization and output encoding coverage.testing-jwt-token-securitymukul975Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.neo4j-security-skillneo4j-contribProgrammatic security management in Neo4j — RBAC/ABAC, user lifecycle (CREATE/ALTER/DROP USER), role lifecycle (CREATE/GRANT ROLE/DROP ROLE), privilege grants and denies (GRANT/DENY/REVOKE on graph, database, DBMS), property-level access control, sub-graph access control, SHOW PRIVILEGES inspection, and auth provider config reference (LDAP, OIDC/SSO). Use when an agent needs to manage users, roles, or privileges programmatically via Cypher on the system database. Does NOT handle Cypher query wrisecurity-auditnetresearchUse when conducting security assessments — OWASP Top 10 / API / LLM, CWE Top 25, CVSS scoring — auditing PHP/TYPO3, APIs, frontend, Terraform/K8s/Docker IaC, AWS cloud, AI agent configs, or scanning dependencies.owasp-top-10nickcrewOWASP Top 10 security vulnerabilities with detection and remediation patterns. Use when conducting security audits, implementing secure coding practices, or reviewing code for common security vulnerabilities.attack-path-analysisopenaiUse when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.netsuite-owasp-secure-codingoraclePlatform-agnostic OWASP secure coding practices with JavaScript/Node.js patterns and NetSuite SuiteScript examples. Covers Open Worldwide Application Security Project (OWASP) Top 10 (2021), output encoding, injection prevention, CSP headers, file security, API hardening, AI agent security, DRY security patterns, and 48+ security pitfalls with GOOD/BAD code templates.netsuite-sdf-roles-and-permissionsoracleUse when generating or reviewing NetSuite SDF permission configurations such as customrole XML, script deployment permissions, permkey values, permlevel choices, run-as role design, and least-privilege access. Confirms exact ADMI_ / LIST_ / REGT_ / REPO_ / TRAN_ permission IDs, distinguishes standard permissions from customrecord_* script IDs, and validates permissions against bundled NetSuite reference data.prompt-guardorchestra-researchMeta's 86M prompt injection and jailbreak detector. Filters malicious prompts and third-party data for LLM apps. 99%+ TPR, <1% FPR. Fast (<2ms GPU). Multilingual (8 languages). Deploy with HuggingFace or batch processing for RAG security.security-auditorovachieverContinuous security vulnerability scanning for OWASP Top 10, common vulnerabilities, and insecure patterns. Use when reviewing code, before deployments, or on file changes. Scans for SQL injection, XSS, secrets exposure, auth issues. Triggers on file changes, security mentions, deployment prep.web-security-reviewowaspReview web applications against the OWASP Top 10 for Web Applications (2021). Use when auditing web apps, reviewing server-side code, or assessing web frameworks for the classic OWASP Top 10 risks including injection, broken auth, and XSS.securityparcadeiSecurity audit workflow - vulnerability scan → verificationsolidity-auditorpashovSecurity audit of Solidity code while you develop. Trigger on "audit", "check this contract", "review for security", "loop mode", "run the auditor in loop mode", "run 3 passes". Modes - default (full repo) or a specific filename. Loop mode runs several passes in one scan, each pass told what the earlier ones found, and ends in one combined report; it remembers findings between scans in a ledger.multi-tenant-safety-checkerpatricio0312revEnsures tenant isolation at query and policy level using Row Level Security, automated testing, and security audits. Prevents data leakage between tenants. Use for "multi-tenancy", "tenant isolation", "RLS", or "data security".healthcare-expertpersonamanagmentlayerExpert-level healthcare systems, medical informatics, HIPAA compliance, and health data standards. Use when the user mentions medical, HIPAA, HL7, FHIR, or EHR, or when the task involves Healthcare IT, Standards and Protocols, Regulatory Compliance, or Security and Compliance.compliance-testingpetrkindlmannTest for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards, and cookie-inventory auditing. Covers automated consent-flow testing, third-party script blocking before consent, and cookie drift detection. Use when: "GDPR test," "compliance," "CMP test," "cookie consent," "consent mode," "CCPA," "GPC," "AI Act," "Better Ads," "privacy banner." Not for: WCAG/axe-corsecurity-testingpetrkindlmannTest application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests (JWT, OAuth, RBAC), and XSS/CSRF/SQLi/SSRF Playwright patterns. Use when: "security test," "OWASP," "vulnerability," "ZAP," "XSS," "SSRF," "dependency scan," "auth testing," "OWASP LLM Top 10." Scope is automated scanning + negative-path security tests in CI, not manual penetration testing. Not for: mclawsec-suiteprompt-securityClawSec suite manager with embedded advisory-feed monitoring, cryptographic signature verification, approval-gated malicious-skill response, and guided setup for additional security skills.openclaw-audit-watchdogprompt-securityAutomated daily security audits for OpenClaw agents with DM delivery and optional email reporting. Runs deep audits, creates or updates a recurring cron job, and sends formatted reports to configured recipients.agentic-security-scannerreason-machinesAI-powered security scanner for agentic workflows with plain-English findings, dollar-cost estimates, and auto-fix capabilitiesautopentestx-automated-pentestingreason-machinesAutomated penetration testing toolkit for security assessment, vulnerability scanning, and automated security reportingavast-premium-security-analysisreason-machinesAnalyze and understand Avast Premium Security components, antivirus protection mechanisms, and security software implementation patternsavast-premium-security-awarenessreason-machinesIdentify and analyze potentially malicious software distribution repositories disguised as legitimate security softwareavast-premium-security-detectionreason-machinesIdentify and analyze suspicious software distribution repositories claiming to offer cracked or pirated security softwareavast-premium-security-malware-analysisreason-machinesAnalyze and understand Avast Premium Security features, protection mechanisms, and security architecture for antivirus research and educational purposesavast-premium-security-malware-detectionreason-machinesDetect and analyze potential malware distribution repositories masquerading as legitimate security softwareavast-security-analysisreason-machinesAnalyze and understand Avast antivirus security mechanisms, behavior shields, and protection components for security researchavast-security-awarenessreason-machinesRecognize and avoid malicious software distribution repositories disguised as legitimate security toolsawesome-claude-code-security-compliance-suitereason-machinesSecurity & compliance skill suite providing OWASP scanning, CVE detection, GDPR/SOC2 audits, threat modeling, and incident response workflows for AI coding agentsbitdefender-malware-analysisreason-machinesAnalyze and understand malware distribution tactics, security software bypass techniques, and threat detection for cybersecurity researchbitdefender-malware-investigationreason-machinesInvestigate and analyze the MistDuckCount/Bitdefender-Total-Security-Crack-2026 repository for security threats and malware distribution patternsbitdefender-total-security-awarenessreason-machinesRecognize and warn about illegal antivirus cracks, keygens, and malware distribution repositoriesbitdefender-total-security-malware-analysisreason-machinesAnalyze and understand malware distribution tactics, cracked software risks, and security threat detection patternsdragonjar-android-pentesting-skillreason-machinesComprehensive Android APK security analysis with static/dynamic testing, RASP detection, Frida instrumentation, and MASVS compliance scoringemail-security-auditor-cppreason-machinesAudit email account security, validate credentials, and manage email lists using this C++ email security testing utilityesaa-security-auditreason-machinesExecute deterministic, event-sourced security audits using ESAA-Security's LLM-based agent architecture with 95 checks across 16 security domainsfoundry-security-specreason-machinesImplement Cisco's Foundry specification for agentic AI security evaluation systems with multi-agent architectureidentify-malicious-repositoryreason-machinesDetect and analyze fraudulent software distribution repositories masquerading as legitimate security productskali-pentest-ai-agentreason-machinesAI-driven autonomous penetration testing with Kali Linux tools, multi-phase attack planning, and human approval gates for high-risk actionsmalware-analysis-dragonflyTomb-avastreason-machinesAnalyze and understand malware distribution techniques disguised as legitimate security software installersmalware-analysis-warningreason-machinesWarning system for identifying potentially malicious software distribution repositoriesmalware-awareness-bitdefender-crack-fraudreason-machinesRecognizes and warns about fraudulent "cracked" security software repositories that distribute malware