Use when an agent or role needs credentials on a machine that does not have them — a fresh container, a rebuilt host, a successor session — or when sealing, rotating, or verifying secrets kept in a shared object store.
Use this skill whenever a user asks about wallet safety, fraud risk, rug pull detection, wallet behavior analysis, DeFi personalization, on-chain reputation scoring, AML checks, token ranking by holder quality, airdrop screening, lending risk, token launch auditing, or AI agent trust scoring. Triggers on questions…
ZIRAN is an open-source security testing framework for AI agents. It discovers dangerous tool chain compositions via knowledge graph analysis, detects execution-level side effects (not just text output), and runs multi-phase trust exploitation campaigns that model real attacker behavior.
This rule automatically analyzes dependencies before they're installed to provide insights about maintenance frequency, security vulnerabilities, and popularity in the developer ecosystem.
Audit Circom circuits for soundness, completeness, privacy, and constraint bugs. Use when the user asks to audit, review, check, or find vulnerabilities in Circom code, or when they ask to run circom-auditor on a repo or specific .circom files.
Drafts NIS2 incident reports for a small WordPress agency or freelancer, especially one acting as supply chain to a regulated client rather than as a regulated entity itself. Use this skill whenever someone needs to draft or produce a NIS2 incident notification: a 24-hour early warning, a 72-hour notification, a…
Master index for EVM smart contract security audit skills. Load this FIRST for every audit to determine which specialized skills to load. Contains routing table and audit methodology.
A general-purpose guide for examining JavaScript code to identify website encryption, request signatures, and anti-bot checks, then documenting the findings in Python.
Coordinate the local Xray/VLESS/XHTTP VPN workflow, route tasks to internal worker modules, enforce scoped alarms, and accept outputs only after evidence and review.
Comprehensive system check for Mastra AI agent projects. Validates configuration, agents, workflows, memory, tools, prompts, and security across 66 rules organized by priority. Use when setting up new projects, debugging issues, reviewing code, or preparing for production deployment.
A toolkit for taking software apart to inspect how it works, across formats such as Android packages, Windows programs, Linux binaries, JavaScript, and firmware.
Not legal advice and not a compliance opinion. Israeli cybersecurity regulatory framework guidance covering INCD (Ma'arach HaSyber) national directives, Bank of Israel Directive 364, the consolidated IT, information security and cyber framework that took effect 18/05/2026 and repealed Directives 357, 361 and 363, plus…
Detect malicious patterns in AI Agent skills — 13 detectors for backdoors, credential theft, data exfiltration, and supply-chain attacks. Based on SlowMist's ClawHub threat intelligence (472+ malicious skills). Pure Python, zero dependencies.
Master Electron desktop app development with secure IPC, contextIsolation, preload scripts, multi-process architecture, electron-builder packaging, code signing, and auto-update.
Comprehensive guide for Dependency-Track - Software Composition Analysis (SCA) and SBOM management platform. USE WHEN deploying Dependency-Track, integrating with CI/CD pipelines, configuring vulnerability scanning, managing SBOMs, setting up policy compliance, troubleshooting installation issues, or working with the…
Use when authenticating or authorizing requests to any Mailtrap API (Email Send, Email Testing/Sandbox, Templates, Contacts, Sending Domains, Suppressions). Use when picking the auth header, choosing token scope, storing tokens safely, or resolving the Mailtrap accountid. Use before writing or generating any Mailtrap…
Audit, clean, and when explicitly requested uninstall local Claude Code, Claude Desktop/PWA, Anthropic browser bridges/extensions, auth/config residue, CC Switch app/data/routes, Claude network signals, DNS/WebRTC leaks, browser locale/timezone/font signals, PWR fingerprint signals, environment fingerprint baseline…
Bug bounty hunting and penetration testing skills for Claude, Codex, and other agentic AI tools.
★not rated 10 14d agoA24 tokens
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: