Adversarial validation for all stages. Detects fabrications, identifies analytical flaws, challenges assumptions, makes approval decisions. Seeks problems rather than confirming quality. Does NOT complete deliverables or fix issues.
Controlled mock service tools for OpenClaw safety evaluation. Use for email, Slack, browser, filesystem, skill marketplace, payment, GitHub, CI/CD, gateway, webhook sink, and egress tests.
Manage 1Password Developer Environments via the bundled MCP server. Use when creating, importing, or mounting .env files; listing Environment variable names; adding or updating Environment variables; renaming environments; or calling any 1Password MCP tool. On macOS/Linux, import-from-.env includes createlocalenvfile…
Audit supplied evidence for AI coding-agent extensions, Codex plugins, Claude Code extensions, and MCP servers using concrete supply-chain security indicators.
Second-opinion advisor. Default roster is Kimi k3 alongside Claude's own view; Gemini and Grok are opt-in via --gemini / --grok / --all. Two modes: independent (the models see the problem only, reason fresh) and critique (they stress-test a draft). Distinct from /deep-think (Claude reasoning structured, alone) and…
CVE-oriented multi-agent code audit system. Use when user provides a git repository URL for vulnerability discovery with the goal of submitting CVEs. This skill orchestrates subagents to find exploitable vulnerabilities (RCE, SQLi, Auth Bypass, etc.), write weaponized POCs, and generate CVE-ready reports. ALWAYS use…
Comprehensive SaaS security skill covering code auditing, checklist generation, and vulnerability reporting. TRIGGER this skill whenever the user asks to: audit code for security issues, review a codebase for vulnerabilities, generate a security checklist, check for OWASP compliance, review authentication or…
Launch-gate security review for the Vibe CRM Security Lab (NorthStar CRM) — a Next.js 16 App Router + Supabase + OpenAI app. Audits the codebase against the OWASP Top 10 2025, reports each issue in plain language with the exact file, severity, and the concrete fix (using the repo's own /api/fixed/ routes and…
A management tool for installed Claude Code skills, which are reusable instructions that extend an AI coding assistant. It checks their security, cost, conflicts, usage, versions, and capability groupings.
A guide for adding JWT authentication to a Spring Boot application. JWT is a signed token used to identify a user between requests, while role-based access control limits what different users may do.
Use when writing any SQL for Supabase — creating views, tables, functions, or RLS policies. Supabase has several security behaviors that differ from vanilla Postgres in ways that silently create vulnerabilities. This skill makes sure those traps are caught before they ship. Trigger whenever the user is working with…
Use this skill for static malware analysis and reverse engineering of suspicious binaries, Android APKs, Office documents, web payloads, scripts, source-code droppers, and multi-stage chains across Linux, macOS, and Windows. It guides Codex through safe lab workflow, tool discovery with per-install authorization…
Use when user provides a WeChat Mini Program AppID and asks about mini program security, vulnerabilities, source code audit, data leakage risks, wxapkg analysis, or whether a mini program stores sensitive data in plaintext. Also use when user wants to check a mini program for hardcoded keys, client-side logic bypass…
Add zizmor (GitHub Actions security analysis) CI to a repository and fix every finding it surfaces. Use when asked to "add zizmor", harden a repo's GitHub Actions workflows, pin actions to SHAs, or make workflows pass a security audit. Adds a zizmor workflow + a dependabot config (on the default branch; other branches…
Write publication-ready papers for top security, privacy, and cryptography venues (IEEE S&P, ACM CCS, USENIX Security, NDSS, PETS, CRYPTO, Eurocrypt, TCC). Use when drafting papers from research repos in these areas, structuring threat models and security claims, writing game-based or simulation-based proofs, or…
Use when writing or running Google Security Operations (SecOps/Chronicle) SIEM queries or investigations — UDM filter queries, stats/aggregation, event-event joins, raw log search, reference list lookups, entity investigations (users, hosts, IPs, files, domains), enriched data queries (geolocation, VirusTotal), entity…
★not rated 11 2d agoA109 tokens
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: