Loading...
Loading...
Found 5212 skills
igbuend
Detects excessive data exposure in API responses, database queries, and data serialization to prevent leakage of sensitive information.
igbuend
Detects common JWT misuse vulnerabilities in code, including 'none' algorithm attacks, weak secrets, and missing expiration.
igbuend
Identifies insecure CORS configurations with wildcard, null, or reflected origins in server/API code to prevent security risks (CWE-942).
igbuend
Detects absence of rate limiting in APIs and public services, preventing brute force, credential stuffing, and DoS attacks.
igbuend
Detects insecure temporary file handling in code, identifying predictable paths, insecure permissions, and missing cleanup to prevent security vulnerabilities.
igbuend
Detects AI-generated code importing non-existent packages, a critical security vulnerability (CWE-1357), preventing dependency confusion and slopsquatting risks.
igbuend
Delegates cryptographic operations and key management to external services, reducing key leakage and misconfiguration risks. Examples: AWS KMS, Azure Key Vault.
mnthe
Offers security best practices including OWASP patterns, input validation, and secure authentication to protect user input, secrets, and sensitive data handling.
mnthe
Security vulnerability detection using OWASP Top 10, secrets detection, and input validation for code handling user input, authentication, and APIs.
Knuckles-Team
Executes untrusted Python code in an isolated, secure environment to prevent system compromise.
plurigrid
Implements on-chain entropy storage using GF(3) in Aptos Move, leveraging bulk-boundary correspondence for secure cryptographic key generation.
plurigrid
Analyzes cryptographic code for timing side-channel vulnerabilities to ensure constant-time execution and prevent secret leakage.
plurigrid
Provides secure derivation of CapTP (Capability-based Transport Protocol) artifacts for building secure distributed systems.
phrazzld
Applies security and compliance best practices for payment and authentication integrations, including Stripe and Clerk setups and webhook configurations.
plutowang
Enforces security compliance by scanning code for PII, secrets, and unauthorized file types prior to processing.
euCann
Extracts structured compliance data from OSCAL documents in JSON, YAML, or XML formats for security control catalogs and system security plans.
euCann
Validates OSCAL System Security Plans against NIST 800-18 and FedRAMP baselines, identifying gaps and providing remediation for ATO compliance.
euCann
Generates detailed implementation guidance, technical procedures, and deployment plans for OSCAL security controls to ensure compliance and security posture.
euCann
Fetches official NIST 800-53 and FedRAMP OSCAL catalogs from authoritative sources for security and compliance assessments.
euCann
Validates OSCAL documents against security standards using JSON schema, business rules, and cross-reference checks for comprehensive compliance assurance.
euCann
Generates audit-ready compliance reports from OSCAL, SSPs, and POA&Ms in multiple formats for regulatory documentation.
euCann
Conducts comprehensive security risk assessments on OSCAL systems, including threat modeling, vulnerability analysis, and POA&M generation to evaluate posture and prioritize remediation.
euCann
Validates OSCAL documents for structural integrity and compliance with NIST OSCAL specifications before processing.
euCann
Extracts and analyzes security controls from OSCAL catalogs, profiles, and SSPs to provide detailed control hierarchies, statements, and implementation status for compliance assessments.