Build internal apps and AI agents on RootCX — the open-source platform with shared PostgreSQL, auto-generated CRUD APIs, OIDC SSO, role-based access control, audit logging, scheduled jobs, message queuing, encrypted secrets, file storage, managed deployment, and pre-built integrations. Get everything you need to ship…
Deep storage and data security analysis for AWS Infrastructure-as-Code. Detects unencrypted data stores, public S3 buckets, missing backup/DR posture, dangerous access patterns, ransomware readiness gaps, data classification issues, and storage-layer attack surfaces. Consumes structured output from iac-analysis and…
Walk a client through a Responsible AI assessment questionnaire and score their answers 0-5 across eight RAI dimensions (Governance, Privacy & Security, Safety, Veracity & Robustness, Controllability, Fairness, Explainability, Transparency). Use when a user asks to run a Responsible AI assessment, RAI scorecard…
Use when building, changing, or deploying an instancez backend - editing instancez.yaml (tables, RLS, auth, storage, rpc, functions), running the inz CLI, or debugging why a query is denied. instancez is a single-binary Supabase-compatible backend defined by one YAML file.
A source-code security audit tool for web projects written in Go, Java, Python, PHP, or JavaScript. It checks for high- and medium-risk flaws and writes reports in the audited project’s reports/ folder.
Offline compliance and hygiene scanning of an AAB or APK with gplay preflight — manifest flags, restricted permissions, 64-bit and 16 KB page alignment, listing assets, secrets, billing, privacy SDKs, target API floor, and size. Use before uploading a build, as a CI gate, or when diagnosing a Play rejection. Runs…
Create or update reusable workflow DAGs. Use when authoring or revising saved workflows. Must be mandatorily used before calling the createworkflow tool.
Amazon OpenSearch Service domain health assessment. Performs read-only, API-driven checks against a customer's OpenSearch domain(s) covering cluster health, node/shard configuration, performance metrics, security posture, and cost optimization signals. Activate this skill for requests about OpenSearch or Elasticsearch…
★not rated 45 3d agoASkillSpector: pass136 tokens
originalApache-2.0
Use when auditing an AI agent plugin, skill bundle, or MCP tool package for supply chain integrity — generate deterministic SHA-256 manifests, detect modified or untracked files, flag unpinned dependencies, and gate promotion to production.
Investigate and remediate exactly one user-selected CodeInspectus finding with evidence-gated reproduction, a separately approved minimal patch, focused regression testing, and an exact-prior-scan rescan. Use when a user asks an agent to examine, reproduce, fix, or verify one CodeInspectus finding without batching…
Review code with real engineering criteria — logic bugs, security vulnerabilities, and technical debt. Use when the user says /review, asks for a code review, or wants the branch diff checked before opening a PR.
Guide for understanding and contributing to the awesome-ai-security curated resource list. Use this skill when adding resources, organizing categories, or maintaining README.md consistency (no duplicates).
Create dev-only auth shortcuts so AI browser automation agents can authenticate instantly. Analyzes your auth system, creates guarded endpoints/scripts, detects your browser automation tools, and updates agent instructions. Use when setting up dev authentication for browser automation, or when agents struggle with…
First-pass recon net for an Android APK — hunt secrets, insecure storage, weak crypto, broken TLS, and risky configuration in one broad sweep. Fires on manifest signals (android:debuggable="true", android:allowBackup="true", android:usesCleartextTraffic="true", a networkSecurityConfig that trusts user CAs or permits…
Set up a web app on a single cheap, hardened VPS the "levels.io" way — one Hetzner/DigitalOcean box running Next.js (or any Node app) on SQLite + Caddy (auto-HTTPS) + systemd, secured with Tailscale, put behind a Cloudflare domain, and set up to charge money with Stripe. The whole "idea → app that makes money on a…
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: