Enforce zero-daemon Landlock/Seatbelt security boundaries, network isolation, and subagent capability controls when executing untrusted commands or running subagents. Use when running terminal commands, testing untrusted scripts, isolating AI subagent workflows, or performing read-only session recovery for Codex and…
Audit an app, website, metadata, SDKs, and marketing for privacy, security, AI transparency, consumer claims, subscriptions, content rights, user-generated content, children, health, financial, export, and platform-policy risks. Use before TestFlight, submission, release, paid marketing, or after adding tracking…
Cryptographic compliance verification. Sign security tool output into verifiable CPOEs (JWT-VC), verify vendor proofs via trust.txt, detect drift with diff, and assess third-party risk. Use when the user mentions compliance proofs, CPOE, trust.txt, SCITT, vendor assessment, GRC evidence, or compliance drift.
Use before installing, updating, auditing, or executing dependencies, package-manager commands, project generators, CI actions/workflows, release jobs, IDE extensions, MCP servers, or AI-agent tools. Also use when investigating suspected compromise or advisories, debugging publish or release authentication, or…
Auditoria de segurança aplicada (AppSec). Varre código, dependências e configurações contra OWASP Top 10 / CWE Top 25, identifica segredos expostos, valida controles de auth/authz e gera relatório priorizado. Use para "revisar segurança", "auditar vulnerabilidades", "threat modeling" ou "security review".
Decompose requirements into roadmap tasks. Must run in isolated context/subagent. Protocol-invoked only; do not auto-trigger from casual user requests.
System diagnostics using osquery. Use when asked about CPU usage, memory consumption, network connections, running processes, disk I/O, fan speeds, temperatures, or system security. Triggers: "why is my computer slow", "what's using memory", "what's using CPU", "network connections", "suspicious processes", "system…
A dependency-free Claude skill that groups vulnerability findings by the fix they share and ranks the shortest set of actions that retires the most weighted risk.
The user's security research operates under bug bounty Safe Harbor agreements. Major bounty platforms (HackerOne, Bugcrowd, Intigriti, YesWeHack) and individual programs from major tech companies — including AI labs (OpenAI, Anthropic, Google DeepMind), cloud providers (AWS, GCP, Azure, Cloudflare), social platforms…
OSINT investigation toolkit. Use when the user wants to investigate or gather open-source intelligence on an indicator — a person's name, email, username, domain, IP address, phone number, company, coordinates, IBAN, or crypto address — and needs the right set of curated OSINT search links, or wants to validate an…
Before running a risky shell command, check it with Sigil's assess and refuse anything Sigil would block. Use whenever you are about to execute a destructive, privileged, or unfamiliar command.
★not rated 13 15d agoA✓ AI review46 tokens
originalApache-2.0
Authorized penetration tester persona — offensive security specialist for network, web app, cloud, and Active Directory assessments. Requires explicit authorization.
A security-testing skill that plans multi-stage attack paths and coordinates specialized security tasks. It covers scenarios such as moving from an external foothold toward internal systems, but is not needed for single tasks like port scanning.
★not rated 13 28d agoA✓ AI review0 tokens
originalMIT
Attack patterns and real-world examples sourced from the HackerBot Claw campaign analysis by StepSecurity (2025): https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation -->.
A set of rules for carrying out authorized black-box penetration tests, where the tester examines a system without access to its source code. It defines testing boundaries, safety limits, and the evidence needed to report a vulnerability.
Review this codebase against the prodcheck pre-production checklists — security, performance, scale, integrations and post-launch readiness. Use when asked to check whether a project is ready to ship, to audit an area before launch, or to work through a specific checklist. Produces evidence with file:line citations…
Draft a responsible vulnerability disclosure policy for SaaS/devtools: scope, safe harbor posture, channels, timelines, and what not to do — no exploit detail. Triggers: responsible disclosure policy, vulnerability disclosure policy VDP, security.txt companion policy, report vulnerability page, coordinated disclosure.…
Assess and enhance software projects for enterprise-grade security, quality, and automation. This skill should be used when evaluating projects for production readiness, implementing supply chain security (SLSA, signing, SBOMs), hardening CI/CD pipelines, establishing quality gates, reviewing code or PRs, writing…
★not rated 12 6mo agoA113 tokens
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: