Loading...
Loading...
Found 5212 skills
bonny
Verifies WordPress.org compliance for freemium plugins, covering feature restrictions, license key validation, and avoiding trialware violations during development.
githubnext
Securely manages secret tokens in HTTP headers for authentication and security compliance.
githubnext
Provides safety guidelines to prevent and handle error patterns in agentic engines, ensuring secure and reliable operation.
yhy0
Detects and exploits authentication bypass vulnerabilities including IDOR and privilege escalation in systems with login, permission control, or JWT/Session authentication.
yhy0
Performs web application reconnaissance for penetration testing, including directory scanning, port scanning, and service fingerprinting to identify attack surfaces.
yhy0
Detects and exploits Server-Side Request Forgery (SSRF) vulnerabilities in web applications, targeting URL parameters and remote resource handling features.
yhy0
Detects and exploits SQL injection vulnerabilities in web applications using UNION, error-based, and blind injection techniques.
yhy0
Detects and exploits remote code execution vulnerabilities in targets with command execution, code execution, or template injection flaws.
yhy0
Detects and exploits Local File Inclusion (LFI) and Remote File Inclusion (RFI) vulnerabilities in web applications.
yhy0
Detects and exploits Cross-Site Scripting (XSS) vulnerabilities including reflected, stored, and DOM-based XSS in web applications.
WellApp-ai
Audits Value Delivery compliance adherence following pull request pushes to ensure regulatory and process standards are met.
mckinsey
Resolves security vulnerabilities from penetration tests, security audits, and OWASP Top 10 reports for the Ark platform.
mckinsey
Automates CVE research, patching, and security mitigation for Ark projects using API integration and security-focused PR templates.
benchflow-ai
Scans code repositories for leaked API keys, tokens, and passwords using pre-commit hooks and CI checks to prevent security breaches.
benchflow-ai
Specializes in attack surface analysis, exploit scenario generation, and vulnerability chaining to identify and mitigate security risks.
benchflow-ai
Scans git repositories for hardcoded secrets using Gitleaks, preventing credential exposure and ensuring compliance with security standards.
benchflow-ai
Provides universal patterns for detecting common security vulnerabilities (e.g., hardcoded secrets, SQL injection) across programming languages.
benchflow-ai
Scans files for secrets (tokens, keys) without revealing content, redacts them in-place, and determines publish gate status for secure publishing workflows.
benchflow-ai
Analyzes binary files for malicious content, extracts technical details, and provides threat assessment to determine file safety.
benchflow-ai
Assists in reverse engineering unknown binaries by identifying functions, analyzing data structures, and understanding program behavior for security analysis.
benchflow-ai
Provides OWASP Top 10 and CWE vulnerability lookup with attack vectors, payloads, and bounty payout estimates for security researchers.
benchflow-ai
Protects APIs from brute force attacks, spam, and resource abuse through configurable rate limiting implementation.
benchflow-ai
Provides secure code patterns to remediate common injection vulnerabilities (SQLi, XSS, Command) with language-specific examples.
benchflow-ai
Provides techniques for detecting, exploiting, and understanding XSS and HTML injection vulnerabilities in web applications to enhance security testing.