Infrastructure as Code security scanning and policy enforcement for Terraform, CloudFormation, Kubernetes, and Pulumi
Developer security training and assessment for secure coding practices and vulnerability prevention
Use when: reviewing, designing, implementing, or debugging C/C++ for SEI CERT secure-coding violations detected by clang-tidy cert-* checks: unchecked standard-library return…
Audit software supply chain across every ecosystem (npm, pip, Go, Ruby, Cargo, Maven, Docker, Terraform) — pinning, vulnerabilities, secrets, SBOM, signing, branch protection,…
Autonomous DevSecOps & FinOps Guardrails. Orchestrates Gemini 3 Flash to audit Linux Kernel patches, Terraform cost drifts, and K8s compliance.
Expert infrastructure security engineer specializing in DevSecOps, cloud security, and compliance frameworks.
Review Azure workload security posture against the Well-Architected Framework Security pillar: identity and access, network boundaries, data protection, threat detection,…
Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning,
Rebuild and validate Skillz Forge catalog truth, evidence contracts, and provenance without credentials.
Security best practices for GitHub Actions workflows, supply chain security, and secure CI/CD pipelines
Enforces GitHub Actions security and compliance for this monorepo. Use when adding third-party actions, handling secrets, defining permissions, and reviewing CI security…
Maintain CI security/quality gates when changing workflows, dependency tooling, lint/type/test steps, audit policies, or merge-blocking checks for backend/frontend pipelines.
Detect code injection vulnerabilities in packages that dynamically generate or evaluate code via new Function(), eval(), vm.run*, or template literal interpolation.
Code Injection Detector - Auto-activating skill for Security Fundamentals. Triggers on: code injection detector, code injection detector Part of the Security Fundamentals skill…
Conjur integration. Manage security and secrets-management data, records, and workflows. Use when the user wants to interact with Conjur data.
Dockerfile security linting and best practice validation using Hadolint with 100+ built-in rules aligned to CIS Docker Benchmark.
Эксперт по container registry. Используй для настройки ECR, Harbor, Docker Hub, image security и CI/CD интеграции.
Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities — including custom security implementations such as ha — from…
Guide for implementing DefectDojo - an open-source DevSecOps, ASPM, and vulnerability management platform.
Combined DevOps and DevSecOps skill for CI/CD pipelines, infrastructure as code, security scanning, container hardening, cloud infrastructure, and monitoring.
DevSecOps skill for securing CI/CD pipelines, infrastructure as code, containers, Kubernetes, cloud deployments, secrets handling, dependency management, SAST/DAST/SCA, release…
Expert DevSecOps engineer specializing in secure CI/CD pipelines, shift-left security, security automation, and compliance as code.
Looks up OWASP DevSecOps Guideline phases, security tools, and pipeline checks. Returns tool configurations, CWE mappings, and integration patterns for CI/CD security.
DevSecOps patterns — shift-left security, SAST (semgrep/CodeQL), secrets detection (gitleaks/trufflehog), dependency scanning (trivy/grype), DAST, OPA/Falco policy-as-code,…
DevSecOps methodology guidance covering shift-left security, SAST/DAST/IAST integration, security gates in CI/CD pipelines, vulnerability management workflows, and security…
Performs end-to-end DevSecOps security analysis on any GitHub repository. Runs a 6-stage pipeline: repo ingestion and inventory, application context classification with STRIDE…
Knowledge base from DOE Systems Engineering Methodology (SEM) Version 3 — the DOE SDLC for IT investments.
Drafting and iterating sections of The Federated Harbor whitepaper — the third paper in the Curiositech sequence after Anchor (local identity) and Bonded Commons (local…
Adversarial reviewer for The Federated Harbor whitepaper — the third paper in the Curiositech sequence after Anchor and Bonded Commons.
Coordinate vulnerability, dependency, base-image, and container-image patching while preserving downstream runtime contracts.
Evaluate GCP workload security posture against the Google Cloud Well-Architected Framework security pillar — covering zero trust, shift-left security, preemptive cyber defense, AI…
Analyze Infrastructure-as-Code (IaC) in git repositories to extract cloud architecture and security configurations for threat modeling.
Expert Harbor container registry administrator specializing in registry operations, vulnerability scanning with Trivy, artifact signing with Notary, RBAC, and multi-region…
Harden-Runner by StepSecurity is a CI/CD security agent that works like an EDR for GitHub Actions runners.
Infrastructure as Code security scanning for Terraform, Kubernetes, CloudFormation, and Azure ARM. Detects misconfigurations, security risks, and compliance violations before…
Reduce container attack surface by building application images on Google distroless base images that contain
Integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software
差分に追加されたソースコードへ混入した不可視・危険な Unicode 文字(タグ文字・異体字セレクター・ゼロ幅文字・双方向制御/マーク・変則空白)を検出する。GlassWorm 型サプライチェーン攻撃・ASCII smuggling・Trojan Source(CVE-2021-42574)でコードを不可視化する手口を、決定論的な静的解析(列挙した…
Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities — including custom security implementations such as ha — from…
Implement centralized logging with ELK Stack, Loki, or Splunk for log collection, parsing, storage, and analysis across infrastructure.
Log Analysis Security - Auto-activating skill for Security Advanced. Triggers on: log analysis security, log analysis security Part of the Security Advanced skill category.
Review Oracle Cloud Infrastructure security, IAM, network, logging, encryption, and compliance posture.
Store and inject Salesforce auth URLs, JWT keys, and API credentials into CI without leaking them. NOT for runtime secrets in Apex.
|- 功能涵盖: plug, enterprise,。Use when 用户需要plug-enterprise-security-suite相关功能时使用。不适用于超出本技能能力范围的复杂需求。适用于独立开发者、企业团队和自动化工作流场景。支持中文交互,无需复杂配置即开即用。提供结构化输出和错误处理机制。…
Formal protocol verification with ProVerif and Tamarin Prover for multi-agent coordination systems. Use when modeling secrecy properties (escrow opacity, session note…
Use when stellar-forge release publishing touches GitHub Actions permissions, secrets, protected environments, token scope, signing keys, provenance, OIDC, registry credentials,…
Python-based threat modeling using pytm library for programmatic STRIDE analysis, data flow diagram generation, and automated security threat identification.
Use when configuring reCAPTCHA on Web-to-Case, Web-to-Lead, Experience Cloud forms, or Headless Identity flows, or when designing bot-mitigation strategies for Salesforce…
Orchestrates static analysis, vulnerability scanning, and automated patching into a continuous security workflow.
CronWorkflow patterns for scheduled automation: time-based execution, concurrency policies, orchestration pipelines, and GitHub Actions integration for DevSecOps.
Use to audit for exposed secrets — scanning code, config, git history, logs, images, and client bundles for credentials/keys/tokens; confirming exposure; and driving rotation (not…
Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions.
Scan commit history and CI for leaked credentials and rotate on every hit, because a pushed secret is already compromised.
Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities — including custom security implementations such as ha — from…
Use when performing deep security review of auth, crypto, secrets, or PII code requiring confidence-rated severity findings and OWASP checks
Secure coding practices and defensive programming patterns for building security-first applications. Use when implementing authentication, handling user input, managing sensitive…
Harbor is an open-source container registry that provides security features including vulnerability scanning
Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.
Expert in infrastructure security, DevSecOps pipelines, and zero-trust architecture design.
Execute use when setting up log aggregation solutions using ELK, Loki, or Splunk. Trigger with phrases like "setup log aggregation", "deploy ELK stack", "configure Loki", or…