Security
791 skills.
Browse
thinking-red-teamtjboudreauxFor authorized security review of code, auth, or APIs you control, model the attacker, map the attack surface, and report only findings with a reproducible exploit path and verified mitigation.Skills-Security-Checktoolsai通過靜態和AI檢查技能 Skills 安全風險、潛在威脅。當使用者請求檢查技能,掃描技能的時候啟動技能評測評估功能。Detect Skill vulnerabilities using static and AI checks. Automatically activate evaluation upon scan requests.ghidra-headlesstrailofbitsReverse engineers binaries using Ghidra's headless analyzer. Use when decompiling executables, extracting functions, strings, symbols, or analyzing call graphs from compiled binaries without the Ghidra GUI.open-sourcingtrailofbitsThis skill should be used when the user asks to "open source this project", "prepare this repository for public release", "make this repo public", "check open-source readiness", "choose a license for this project", or "set up release automation" ahead of a public launch. Provides a release-readiness workflow covering secrets hygiene, licensing, documentation, CI, and language-specific packaging.trailmark-finding-triagetrailofbitsPerforms graph-assisted triage of a single security finding, SARIF result, weAudit annotation, suspicious function, or report excerpt using Trailmark reachability, entrypoint paths, taint, privilege-boundary, blast-radius, caller/callee, and neighborhood evidence. Use when deciding whether one candidate issue is reachable, prioritizing a finding before PoC work, preparing evidence for exploit validation, or checking whether a static-analysis result is actionable.trailmark-review-gatetrailofbitsRuns a Trailmark structural review gate over a branch, pull request, fix commit, release diff, or git ref range to detect new entrypoints, new tainted paths, removed validation or authorization calls, privilege-boundary drift, blast-radius growth, complexity growth, and newly reachable sensitive sinks. Use when reviewing a PR, branch, remediation commit, or release diff where graph-level security regressions should be checked before merge.trailmark-variant-neighborhoodtrailofbitsExpands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common entrypoint paths, interface implementations, override relationships, type/reference neighbors, and structurally similar nodes. Use after one issue is found to seed variant-analysis, semgrep-rule-creator, static-analysis, or manual review with graph-derived candidate locations.vulnerability-triage-brocardstrailofbitsThis skill should be used when the user asks to "triage a vulnerability report", "assess a CVE", "evaluate a bug bounty submission", "decide if a finding is valid", "review a security finding", "dismiss a vulnerability", "should we fix this CVE", "prioritize a vulnerability report", or needs to determine whether an incoming vulnerability report warrants investigation. Applies 7 brocards (rules of thumb) to systematically accept, dismiss, or request more information on vulnerability reports, or nattack-path-stitchertransilienceaiStitches confirmed single-asset findings into multi-hop attack paths across the organization. Builds a graph where nodes are assets and edges are confirmed exploit hops citing the findings that enable them.v4-security-foundationsuniswapSecurity-first Uniswap v4 hook development. Use when user mentions "v4 hooks", "hook security", "PoolManager", "beforeSwap", "afterSwap", or asks about V4 hook best practices, vulnerabilities, or audit requirements.config-hardeneruseai-proAudit and harden your OpenClaw configuration. Checks AGENTS.md, gateway settings, sandbox config, and permission policies for security weaknesses.credential-scanneruseai-proScan your project for exposed credentials, API keys, and secrets before running OpenClaw skills. Prevents accidental exfiltration.dependency-auditoruseai-proAudit npm, pip, and Go dependencies that OpenClaw skills try to install. Checks for known vulnerabilities, typosquatting, and malicious packages.incident-responderuseai-proStep-by-step incident response for OpenClaw security breaches. Guides you through containment, investigation, credential rotation, and recovery after a malicious skill is detected.network-watcheruseai-proAudit and monitor network requests made by OpenClaw skills. Detects data exfiltration, unauthorized API calls, and suspicious outbound connections.output-sanitizeruseai-proSanitize OpenClaw agent output before display. Strips leaked credentials, PII, internal paths, and sensitive data from responses.permission-auditoruseai-proAnalyze OpenClaw skill permissions and explain exactly what each permission allows. Identifies over-privileged skills and suggests minimal permission sets.prompt-guarduseai-proDetect and neutralize prompt injection attacks in OpenClaw skill content, user inputs, and external data sources. Prevents instruction hijacking and context manipulation.sandbox-guarduseai-proGenerate Docker sandbox configurations for safely running untrusted OpenClaw skills. Isolates filesystem, network, and process access.setup-auditoruseai-proAudit your OpenClaw environment for credential leaks, unsafe defaults, and missing sandbox configuration. Wizard-style: answers questions about your setup and produces a fix checklist.'skill-auditoruseai-proComprehensive security auditor for OpenClaw skills. Checks for typosquatting, dangerous permissions, prompt injection, supply chain risks, and data exfiltration patterns — before you install anything.skill-guarduseai-proRuntime security monitor for active OpenClaw skills. Watches file access, network calls, and shell commands. Flags anomalous behavior and enforces permission boundaries.software-crypto-web3vasilyu1983Guides secure blockchain development across EVM, Bitcoin, Solana, Cosmos, and TON. Use when building contracts, wallets, custody flows, bridges, or on-chain backends.payment-pci-securityvtexApply when handling credit card data, implementing secureProxyUrl flows, or working with payment security and proxy code. Covers PCI DSS compliance, Secure Proxy card tokenization, sensitive data handling rules, X-PROVIDER-Forward-To header usage, custom token creation, and the constraint that Secure Proxy applies only to card authorization (not post-auth operations like cancel, capture, or refund). Use for any payment connector that processes credit, debit, or co-branded card payments to prevenvtex-io-security-boundariesvtexApply when reviewing or designing security-sensitive boundaries in VTEX IO apps. Covers public versus private exposure, trust assumptions at route and integration boundaries, sensitive data handling, validating what crosses the app boundary, and avoiding leakage across accounts, workspaces, users, or integrations. Use for route hardening, data exposure review, or evaluating whether a service boundary is too permissive.security-reviewwaybarriosPerform a focused security review of pending git changes to identify high-confidence security vulnerabilities with real exploitation potential. Use this skill when the user asks for a security review, security audit, vulnerability scan, or wants to check pending changes on a branch for security issues before merging. This is NOT a general code review.dependency-auditwu529778790Use when auditing project dependencies for security vulnerabilities, outdated packages, or license compliance across npm/yarn/pnpm, pip, go, and cargo.supabase-audit-auth-configyoanbernabeuAnalyze Supabase authentication configuration for security weaknesses and misconfigurations.supabase-audit-auth-signupyoanbernabeuTest if user signup is open and identify potential abuse vectors in the registration process.supabase-audit-auth-usersyoanbernabeuTest for user enumeration vulnerabilities through various authentication endpoints.supabase-audit-buckets-listyoanbernabeuList all storage buckets and their configuration to identify the storage attack surface.supabase-audit-buckets-publicyoanbernabeuIdentify storage buckets that are publicly accessible and may contain sensitive data.supabase-audit-buckets-readyoanbernabeuAttempt to list and read files from storage buckets to verify access controls.supabase-audit-functionsyoanbernabeuDiscover and test Supabase Edge Functions for security vulnerabilities and misconfigurations.supabase-audit-realtimeyoanbernabeuTest Supabase Realtime WebSocket channels for unauthorized subscriptions and data exposure.supabase-audit-rlsyoanbernabeuTest Row Level Security (RLS) policies for common bypass vulnerabilities and misconfigurations.supabase-audit-rpcyoanbernabeuList and test exposed PostgreSQL RPC functions for security issues and potential RLS bypass.supabase-audit-tables-listyoanbernabeuList all tables exposed via the Supabase PostgREST API to identify the attack surface.supabase-audit-tables-readyoanbernabeuAttempt to read data from exposed tables to verify actual data exposure and RLS effectiveness.supabase-detectyoanbernabeuDetect if a web application uses Supabase by analyzing client-side code, network patterns, and API endpoints.supabase-extract-anon-keyyoanbernabeuExtract the Supabase anon/public API key from client-side code. This key is expected in client apps but important for RLS testing.supabase-extract-db-stringyoanbernabeuCRITICAL - Detect exposed PostgreSQL database connection strings in client-side code. Direct DB access is a P0 issue.supabase-extract-jwtyoanbernabeuExtract and decode Supabase-related JWTs from client-side code, cookies, and local storage patterns.supabase-extract-service-keyyoanbernabeuCRITICAL - Detect if the Supabase service_role key is leaked in client-side code. This is a P0 severity issue.supabase-extract-urlyoanbernabeuExtract the Supabase project URL from client-side JavaScript code, environment variables, and configuration files.supabase-helpyoanbernabeuQuick reference for all Supabase security audit skills with usage examples and command overview.supabase-pentestyoanbernabeuOrchestrate a complete Supabase security audit with guided step-by-step execution and ownership confirmation.supabase-reportyoanbernabeuGenerate a comprehensive Markdown security audit report with executive summary, findings, and remediation guidance.supabase-report-compareyoanbernabeuCompare two security audit reports to track remediation progress and identify new vulnerabilities.security-patternsyonatangrossSecurity patterns for authentication, defense-in-depth, input validation, OWASP Top 10, LLM safety, and PII masking. Use when implementing auth flows, security layers, input sanitization, vulnerability prevention, prompt injection defense, or data redaction.
