4. Security & Compliance
Found 3608 skills
break-filter-js-from-html
letta-ai
Guides on bypassing HTML sanitization filters to execute JavaScript payloads, targeting XSS filter evasion for security testing and CTF challenges.
openssl-selfsigned-cert
letta-ai
Guides creation of self-signed SSL/TLS certificates via OpenSSL, including key generation, certificate creation, and verification scripts.
password-recovery
letta-ai
Recovers passwords and sensitive data from disk images, deleted files, and binary data in digital forensic investigations.
vulnerable-secret
letta-ai
Guides extraction of secrets from vulnerable executables via binary analysis and reverse engineering for CTFs and authorized security testing.
break-filter-js-from-html
letta-ai
Guides security professionals in bypassing HTML sanitization filters to test for XSS vulnerabilities in web applications.
sanitize-git-repo
letta-ai
Guides removal of API keys, tokens, and credentials from Git repositories to prevent security breaches and ensure compliance.
path-tracing-reverse
letta-ai
Guides reverse engineering of compiled binaries to recreate source code with byte-for-byte accuracy, focusing on algorithm extraction and behavioral replication.
vulnhunter
sendaifun
Detects and analyzes security vulnerabilities, dangerous APIs, and error-prone configurations across codebases.
zz-code-recon
sendaifun
Builds deep architectural context for security audits, codebase understanding, and vulnerability analysis through trust boundary mapping.
test-data-management
proffesor-for-testing
Manages test data generation and ensures privacy compliance with GDPR and CCPA, handling PII for realistic and legal testing scenarios.
compliance-testing
proffesor-for-testing
Provides regulatory compliance testing for GDPR, CCPA, HIPAA, SOC2, and PCI-DSS to ensure legal adherence and audit readiness.
accessibility-testing
proffesor-for-testing
Validates WCAG 2.2 compliance, screen reader compatibility, and inclusive design to ensure legal adherence for accessible applications.
security-testing
proffesor-for-testing
Tests security vulnerabilities using OWASP principles and security testing techniques for audits, authentication, and authorization.
input-validation-hardening
Robotti-io
Hardens input validation processes to prevent injection attacks and logic abuse through canonicalization and safe parsing techniques.
threat-model-lite
Robotti-io
Provides lightweight, repeatable threat modeling for features/services with prioritized mitigation strategies.
secure-fix-validation
Robotti-io
Provides a standardized checklist to validate security fixes, ensuring effectiveness and absence of behavioral regressions.
genai-acceptance-review
Robotti-io
Reviews AI/LLM outputs to prevent over-trust, injection attacks, and unsafe automation, ensuring secure deployment.
dependency-cve-triage
Robotti-io
Automates vulnerability triage for software dependencies by assessing reachability, impact, and generating safe remediation plans.
secure-code-review
Robotti-io
Conducts systematic security code reviews to identify vulnerabilities and provide actionable remediation steps.
secrets-and-logging-hygiene
Robotti-io
Prevents secret and PII leaks in logs through automated redaction and security hygiene defaults.
authn-authz-review
Robotti-io
Reviews authentication and authorization flows (sessions, tokens, RBAC/ABAC) and provides actionable security fix guidance.
security-audit
lovedragonball
Reviews application security by implementing best practices including CSP, XSS prevention, input validation, and secrets management.
accessibility-audit
lovedragonball
Audits websites for WCAG compliance, identifies accessibility issues, and provides fixes for inclusive design implementation.
pine-publisher
TradersPost
Ensures Pine Scripts meet TradingView's House Rules and documentation standards for community library publication.