Pre-installation security gate for agent skills. This skill should be used when the user or agent attempts to install any skill — including requests like "install X", "add X skill", "help me set up the X skill", "npx skills add", or when the agent autonomously decides to install a skill. Also triggers on skill cleanup…
Comprehensive audit of the SKAPARA AI shopping assistant — conversation quality, RAG retrieval, session memory, usage metering, tool execution, streaming UX, cost optimization, and security. Use when asked to audit the AI assistant, chatbot, conversation system, RAG pipeline, AI usage limits, or chat UX.
Resolve a GitHub repository in the security graph and list the CVEs recorded against it, confirming from the graph's dependency data which vulnerable versions are actually installed. Produces the finding set that a reachability review then judges against the source.
Use when asked about a rebar repo's health, compliance, tier, or contract status — and before claiming any tier, badge, or "green" state in docs or commits. Runs the three status surfaces and reads them without conflating the two maturity vocabularies.
How to autonomously obtain secrets and API keys from a Cortex Auth server and launch projects with those secrets injected as environment variables — without any human intervention to configure keys. Use this skill whenever you need to: Run a project that requires API keys (OpenAI, Anthropic, SMTP, database passwords…
RAIGO × OWASP LLM Top 10 — official OWASP LLM Application Security Top 10 (2025) enforcement rules for Hermes agents. Covers all 10 OWASP LLM risks: prompt injection, insecure output handling, training data poisoning, model denial of service, supply chain vulnerabilities, sensitive information disclosure, insecure…
Automatically scan any npm package for supply-chain security risks BEFORE the user installs it. Trigger this skill whenever the user asks to install, add, or upgrade an npm package or dependency (e.g. "npm install X", "install X", "add X as a dependency", "yarn add X", "pnpm add X", "upgrade X"), or wants to…
Install a Claude-Code PreToolUse hook that blocks destructive git commands (push variants including force-push, hard reset, force clean, branch -D, checkout/restore overwrites) before Bash runs them. Use when the user wants git safety rails, force-push prevention, or repository-wipe protection.
Security scanner for supply chain attacks, malicious dependencies, prompt injection, and suspicious code patterns. Use this skill whenever the user asks to audit a project, scan for malicious packages, check dependencies for threats, look for prompt injection, detect typosquatting, review supply chain security, or…
Secure web and desktop application development. Use when writing authentication, authorization, API endpoints, form handling, database queries, file uploads, Electron apps, Tauri apps, IPC handlers, cryptography, secrets management, security headers, input validation, or when reviewing code for vulnerabilities. Covers…
Signs every Claude Code tool call with an offline-verifiable Ed25519 receipt. Lets you audit exactly what Claude did and when, without trusting any server.
Use this skill when the user wants to run a full structured AI red team audit, generate a red team report, compile findings from multiple techniques across multiple models, produce a markdown or JSON report of jailbreak test results, score model resilience, summarize which techniques succeeded or failed, or wrap up an…
A software security review based on South Korea’s KISA 2021 security weakness guide. It checks 69 design and implementation categories and labels each one as passed, vulnerable, needing review, or not applicable.
Quickly audit the current project for obvious malicious or untrustworthy behavior so the user can decide whether it is safe to run, build, or install. This is a triage pass, not a full security review — aim for a dozen targeted checks, not an exhaustive audit.
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
★not rated 5 7mo agoA36 tokens
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: