24,943 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
Parallel multi-agent code review using Agent Teams with 4 specialized reviewers. Spawns a coordinated team of security, performance, test coverage, and code quality agents. Teammates can share findings with each other for cross-domain insights. Produces unified report with severity-ranked findings saved to /output/.…
Comprehensive reference for the VirusTotal API v3, covering authentication, rate limits, endpoint usage, and the critical differences between Free (Public) and Premium (Enterprise) tiers. Use this skill whenever a user asks about VirusTotal, VT API, scanning files or URLs with VirusTotal, threat intelligence lookups…
Audit a vibe-coded or AI-generated SaaS for security and payment failures before it ships, focused on the Next.js + Supabase + Stripe stack. Use this whenever the user is about to deploy, launch, or "ship" a web app that handles authentication, user data, or payments. Trigger on phrases like "is my app secure", "can…
Defensive, local-first security recon that briefs your AI coding agent on your OWN codebase. Read-only by default: facts + tailored probes + a calibrated findings ledger, code-in / artifacts-out, no LLM / no server / no running app. Live probes are opt-in against a TEST instance you own; production is out of scope.
★not rated 2 todayA
tokens not measured
originalMIT
Fresh-eyes supervision pass for any database work an AI agent just built (schema, RLS policies, migrations, edge functions touching the database, storage policies). The builder never grades its own homework - a separate agent plays the "Investigate" role, proves who-can-see-what with real queries, and gives an…
Use proactively when a dependency file changes (package.json, requirements.txt, Pipfile, pyproject.toml, Cargo.toml, go.mod, Gemfile, pom.xml, build.gradle), or on demand for a periodic audit. Identifies outdated, vulnerable, unused, duplicated, and license-incompatible dependencies.
Catches the garbage your AI assistant left behind — security shortcuts, secrets buried in git history, code nobody understands. One 0-100 score, 100% local, no LLM in the loop.
★not rated 2 2mo agoA
tokens not measured
AGPL-3.0
Authorized software reverse engineering, binary analysis, and program comprehension for legitimate purposes including security review, interoperability, migration, modernization, debugging, and documentation. USE WHEN: user needs to analyze software they own or have explicit authorization to inspect, including legacy…
Checks whether a website is legally covered against the complaints and demand letters sites actually receive: trackers and session recording running without consent, missing privacy or cookie policies, accessibility gaps. Detects the business profile and which countries it sells to, then shows exposure only for the…
Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use…
Expert code review specialist. Proactively reviews code for quality, security, and maintainability. Use immediately after writing or modifying code. MUST BE USED for all code changes.
Audit and safely harden authorized SaaS web applications across frameworks and hosting providers. Use for OWASP-aligned reviews, runtime browser checks, HTTP headers, XSS/CSRF, access control, secrets, payments, uploads, privacy, abuse controls, supply-chain risk, link injection, or security remediation; do not use…
A Chinese-language guide for authorized penetration testing and security research. Penetration testing is controlled testing used to find security weaknesses in software or systems.
Conduct a security-led audit of code, systems, APIs, infrastructure, dependencies, and AI workflows with threat modeling and exploitability-backed remediation. Use when security risk is the primary concern. Do not use for a generic code review, database design, or non-security debugging.
Install, update, secure, daemonize, expose through Cloudflare Tunnel, and enable speech input for the open-source Open Codex UI application. Use when a user asks to install or enable Open Codex UI, configure its login daemon, set its access password, install or manage the sherpa-onnx bilingual speech model…
Turn a folder of saved spam into mail filter rules, ranked honestly by how likely each is to catch real mail. Checks your sample for contamination first, gives exact copy-paste strings and the field to match, and says plainly which rules will decay. Also diagnoses rules you already have.
★not rated 2 18d agoA
tokens not measured
CC-BY-4.0
Audits any SaaS / web application codebase for production readiness and delivers a prioritized report covering security, scalability, reliability, performance, testing, observability, data, APIs, CI/CD, infrastructure, cost, and compliance. Use when the user asks to "make my project production-grade", wants a final…
★not rated 2 1mo agoA106 tokens
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: