Reviews a feature segment in the main Civitai Next.js app (src/) for safety gaps — authorization scoping, money paths, PII exposure, NSFW/browsing-level gating, and the failure paths around them. Use before calling a segment done, alongside civitai-reuse-review, civitai-perf-review, civitai-test-review and…
Best practices for Android Intent security. Use this skill when auditing component configurations in AndroidManifest.xml activities, services, receivers) or source code handling incoming Intents (getIntent, getParcelableExtra) to prevent Intent Redirection and unauthorized access.
Helps developers create a NeMo Guardrails configuration for an LLM application. Use when users want to build, scaffold, configure, test, or iterate on input, output, retrieval, dialog, execution, Colang, or catalog-based guardrails. Trigger keywords - create guardrails, build guardrails, scaffold config, write rails…
Claude Code instructions for NVIDIA-NeMo/Guardrails, a project described as: NeMo Guardrails is an open-source toolkit for easily adding programmable guardrails to LLM-based conversational systems.
You are a security specialist reviewing a code diff. Your job is finding vulnerabilities that would survive correctness review: injection paths, authentication bypass, credential exposure, and trust boundary violations.
Claude Code instructions for trailofbits/skills, a project described as: Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows.
Audits GitHub Actions workflows for security vulnerabilities in AI agent integrations including Claude Code Action, Gemini CLI, OpenAI Codex, and GitHub AI Inference. Detects attack vectors where attacker-controlled input reaches AI agents running in CI/CD pipelines, including env var intermediary patterns, direct…
Searches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with regex patterns, extracting security audit findings, dumping proxy history or site map data, or analyzing HTTP traffic captured in a Burp project.
Runs before the agent uses a tool for Write, Edit, MultiEdit and Bash tool calls, executing guard_runtime_write.py via python (2 commands). From lingfengQAQ/webnovel-writer.
A detector for investment scams that examines signs such as coordinated recommendations, paid groups, false claims, and unusually promotional stock activity.
A planning agent for authorized, non-destructive security testing. It creates and revises detailed steps for an executor agent, with each step stating the target, allowed scope, one action, and expected evidence.
A method for finding attack chains by combining smaller capabilities such as reading files, writing files, making server requests, or using credentials. It treats a serious outcome as a sequence of separately gained abilities.
A collection of cybersecurity playbooks for investigating and exploiting specific systems, including GoEdge CDN, ARP man-in-the-middle attacks, BT Panel, OCS, MinIO, and CDN-to-S3 access chains.
Copilot instructions for microsoft/agent-governance-toolkit, covering copilot instructions for agent-governance-toolkit, architecture, build, test, and lint, python and install (editable, all extras).
Claude Code instructions for Tencent/AI-Infra-Guard, covering claude.md, project overview, build commands, build web server binary and build agent binary.