24,943 mods in this category, of every kind an
agent can take. Each one carries what it costs per session, what the
scan found, and whether it is the original.
Creates a STRIDE threat model of the current project with ASCII diagrams and outputs a threat.md file. Use when analyzing system security, designing architectures, or identifying threats in applications.
Fleet-wide Azure Key Vault health check — pulse check for availability, API latency, throttling (429s), auth failures (401/403), and vault saturation across all vaults, then deep-dives into the top 7 most interesting vaults with metrics and resource logs. Tracks known issues across sessions via persistent report. On…
Audit a repo for PII leakage, secrets, and sensitive data before commits or publishing. Runs gitleaks if available, scans git history, checks working tree for known and novel patterns, and optionally wires up a pre-commit hook. Use before making a private repo public, after importing external data into a project, or…
Reviews code diffs after implementation, auto-fixes safe issues, and runs specialist security and architecture reviewers on large diffs. Also triages issues and PRs when the user mentions them. Not for exploring ideas or debugging.
Run a comprehensive code audit on any codebase. Analyzes security vulnerabilities, hardcoded secrets, dependency CVEs, test coverage, code structure, and AI-generated code patterns. Generates CODEAUDITREPORT.md with findings, severity ratings, and remediation guidance. Intelligently selects and orchestrates the best…
Scans files changed in the current branch for security vulnerabilities including OWASP Top 10, hardcoded secrets, injection flaws, and insecure patterns. Use when the user wants a security audit, vulnerability check, or security review of their changes.
Product readiness auditor that crawls any codebase, maps what exists, identifies gaps, incomplete code, vulnerabilities, and dead ends, then produces a prioritized remediation plan. Trigger this skill when the user says 'inspect this project', 'audit my code', 'what's broken', 'product readiness check', 'MVP audit'…
Analyze Istio, Consul, and Linkerd service mesh configurations for security vulnerabilities with NIST 800-53 control mappings. Use when users need to audit mesh security, identify misconfigurations, check mTLS settings, review ACL policies, or prepare for FedRAMP assessments. Triggers on keywords like "mesh config"…
Security audit orchestration for Soroban/Stellar Rust smart contracts. Use when user asks to "audit this codebase", "run soroban auditor", or "check for security vulnerabilities". Utilizes AST squeezing, pre-computed guard/state/integration/divergence/invariant/unsafe maps, parallel agent spawning, a verification…
Implement authentication and authorization in web applications. Use when adding login, signup, sessions, JWT tokens, OAuth, SSO, API key auth, role-based access control (RBAC), permissions, protected routes, middleware guards, password hashing, MFA/2FA, refresh token rotation, CSRF protection, or integrating auth…
Security-engineering rules for an interactive gaming platform under the GLI Gaming Security Framework (GLI-GSF-1) — the deep security-controls layer beneath GLI-19's technical-security appendix, owning the infrastructure and network security territory (DNS, firewalls, remote access, hardening, segmentation, IDS/IPS…
Auditoria e correção de segurança nível enterprise — AppSec, Cloud Security, DevSecOps, Infra Security. Detecta e corrige riscos do básico ao avançado, incluindo vibe coding e código gerado por IA.
Harden ALB-backed services (LiteLLM, generic APIs) behind CloudFront + WAF. Creates CloudFront distribution with secret origin header, WAF Web ACL with path whitelist, and locks down ALB Security Group to CloudFront-only. Use when deploying any internet-facing ALB service that should not be directly accessible.
Convert a compliance-document PDF (law, regulation, industry standard) into a validated OSCAL Catalog JSON. Use when the user wants to turn a compliance PDF into an OSCAL Catalog, ingest a new framework into the OSCAL ecosystem, or regenerate a catalog from a revised PDF while keeping control IDs stable.
Security auditing skill for web applications and codebases. Scans for OWASP Top 10, dependency vulnerabilities, secrets exposure, XSS/CSRF/injection flaws, auth weaknesses, and misconfigurations. Use when task involves security scan, vulnerability assessment, pen test review, threat modeling, or hardening a codebase.
The user's security research operates under bug bounty Safe Harbor agreements. Major bounty platforms (HackerOne, Bugcrowd, Intigriti, YesWeHack) and individual programs from major tech companies — including AI labs (OpenAI, Anthropic, Google DeepMind), cloud providers (AWS, GCP, Azure, Cloudflare), social platforms…
Secure deployment practices for production systems.
★not rated 2 todayA10 tokens
originalMIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: