Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches,
Personal Habit Optimization for disaster response networks. Use when work requires personal habit optimization for disaster response networks with guardrails, traceable execution,…
Audit a project for destructive-operation and migration safety gaps, then produce a phased safeguard plan.
Hosted MCP för Manager Pohlman Protean. Endast för orchestrator-subagenten. Kund, projekt, tasks, prio, status, assignee, kommentarer.
Preserve and conserve library and archival materials. Covers environmental controls (temperature, humidity, light), handling procedures, book repair techniques (torn pages, loose…
The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum
Build and operate the "Privacy-Preserving Data Brokering for disaster response networks" capability for disaster response networks.
Use when escalating privileges on a Linux host — SUID/SGID & GTFOBins, sudo LPE (CVE-2025-32462/32463), capabilities & LD_PRELOAD, kernel LPE (CVE-2024-1086, Dirty Pipe,…
Use when escalating privileges on a Windows host — SeImpersonate Potato chains (GodPotato/PrintNotifyPotato), service & DLL hijacking, UAC bypass (fodhelper/ICMLuaUtil), kernel…
API de Produtos da Tray. Utilize quando o desenvolvedor precisar listar, consultar, cadastrar, atualizar ou excluir produtos no catálogo de uma loja Tray.
Padroes MVC do Protheus (FWFormModel/FWFormView) para ADVPL/TLPP. Use esta skill SEMPRE que o usuario pedir para criar ou manter rotinas MVC, cadastros CRUD, browses FWMBrowse,…
Proxmox VE administration for single-node and clustered environments. Use when Codex needs to operate or troubleshoot Proxmox hosts, VMs, LXCs, storage, networking, backups,…
Rapid7 Insight Platform integration. Manage Users, Roles, Organizations, Assets, Vulnerabilities, Findings and more.
CVE lookup and applicability assessment skill for matching collected product names, versions, and service fingerprints to known vulnerabilities.
CVE validation domain card. Use after CVE lookup has produced applicable or candidate CVEs and red-team mode needs scoped evidence to decide whether to continue, pivot, or report.
Define deployment reliability, availability zones, failover, degradation, backup, restore, RPO, RTO, disaster recovery, resilience testing, and recovery ownership.
Use when designing how a database keeps multiple copies of its data in agreement across nodes for availability, read scaling, and disaster recovery: the three foundational…
Restore the Exobrain harness onto a wiped Mac or a brand-new machine, from the daily collective backup tarball + GitHub + cloud re-auth.
Review and triage semgrep security scan results to identify true positive vulnerabilities. Use when analyzing semgrep output, triaging security findings, reviewing static analysis…
Automated code review and security linting integration for CI/CD pipelines using reviewdog. Aggregates findings from multiple security and quality tools (SAST, linters,…
Develop comprehensive risk management plans for collections and cultural venues including disaster preparedness, security protocols, and insurance coordination
Install SecOpsAgentKit when a Claude Code session needs repeatable security review skills for SAST, DAST, container scanning, secrets checks, policy review, and remediation…
Rust security skill for supply chain safety and memory-safe development. Use when auditing dependencies with cargo-audit, enforcing policies with cargo-deny, reviewing RUSTSEC…
Safety hooks for Claude Code — 695 pre-built hooks that prevent file deletion, credential leaks, git disasters, and token waste during autonomous AI coding sessions.
Source code vulnerability hunting (SAST). Decomposes analysis into specialized passes: map entry points, map dangerous ops, trace flows, find gaps, adversarial validation,…
Perform codebase analysis and architecture mapping as the first phase of a security assessment. Explores the tech stack, frameworks, entry points, data flows, and trust…
Static Application Security Testing orchestration and analysis. Execute Semgrep, Bandit, ESLint security plugins, CodeQL, and other SAST tools.
Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping. Use when: (1) Scanning Python code for security vulnerabilities and anti-patterns, (2)…
Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in…
Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.
Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code.
Industrialized DevSecOps pipeline integration combining Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis…
Detect insecure file upload vulnerabilities in a codebase using a three-phase approach: discovery (find all upload sites), batched verify (check extension bypass and related…
Detect GraphQL injection vulnerabilities in a codebase using a three-phase approach: recon (confirm GraphQL usage and find unsafe operation document assembly sites), batched…
Detect hardcoded sensitive data (API keys, access tokens, private keys, passwords, etc.) in publicly accessible code — frontend JavaScript, mobile apps, client-side bundles, and…
Multi-language static application security testing using Horusec with support for 18+ programming languages and 20+ security analysis tools.
Wire a static analysis scanner into CI so it blocks real security bugs while staying under a defined noise budget.
Detect missing authentication and broken function-level authorization vulnerabilities in a codebase using a three-phase approach: recon (map endpoints and the role/permission…
Detect path traversal vulnerabilities in a codebase using a three-phase approach: recon (find file-loading sinks with dynamic paths), batched verify (trace user input and…
Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration.
Runs static application security testing using Semgrep rules and CodeQL queries against pull request diffs.
Detect Remote Code Execution (RCE) vulnerabilities in a codebase using a three-phase approach: recon (find dangerous execution sinks), batched verify (trace user input to sinks in…
Consolidate all SAST vulnerability results from the sast/ folder into a single final report ranked by severity and confidentiality impact.
Run or ingest static application security testing (SAST) results on a codebase, triage them to remove false positives, and confirm the real issues with code evidence and…
Compiles and validates custom Semgrep SAST rules using the semgrep-core engine. Tests pattern matching against sample codebases and generates rule performance benchmarks with p/ci…
Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.
Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched…
Sbom Cyber Serviceroboter Haushalt im Robotik- und KI-Recht: prüft konkret Prüft SBOM, Dependency-Management, CVE-Tracking, Sicherheitsanforderungen und Na.
Generates Software Bill of Materials using Syft for container images and matches components against the NVD CVE database via OSV.dev API.
Prüft SBOM, Dependency-Management, CVE-Tracking, Sicherheitsanforderungen und Nachweise für Robotiksoftware.
Generates Software Bill of Materials using Syft and scans for CVEs with Grype. Cross-references findings against the NVD and OSV databases for comprehensive vulnerability…
Final consolidated security assessment report generator with CVSS severity and remediation roadmap
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC…
Structure individual scenes using Scene-Sequel framework with goal-conflict-disaster beats
Structure scenes and control pacing using scene-sequel rhythm. Use when individual scenes work but don't accumulate, when pacing feels off (too rushed or too slow), when…
API de Scripts Externos da Tray. Utilize quando o desenvolvedor precisar gerenciar scripts JavaScript customizados injetados na vitrine da loja, incluindo listagem, cadastro,…
Detect secrets, credentials, and sensitive data in code and configurations. Scan git history for secrets, detect API keys, tokens, passwords, check environment files, monitor…
Comprehensive secure code analysis and vulnerability review using Semgrep, Gitleaks, Trivy, CodeQL, and Horusec in a layered defense approach.
Guides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformance/token integration), generates visual…
Securing container registry images by implementing vulnerability scanning with Trivy and Grype, enforcing image