Comprehensive comparison of crypto payment gateways and protocols. Compare centralized processors (Stripe, BitPay, Coinbase Commerce, NOWPayments) vs self-hosted solutions…
Cryptographic utilities — hashing, base64, JWT decode/verify, password hashing (argon2id/bcrypt/scrypt/pbkdf2), encryption (Fernet/AES-GCM/ChaCha20), key derivation…
Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscripti — from…
Comprehensive expertise in decentralized autonomous organization governance systems, including Snapshot off-chain voting, OpenZeppelin Governor on-chain execution, treasury…
Datenlokalisierung und grenzüberschreitender Datentransfer VR China: Cybersecurity Law Art. 37, Data Security Law Art. 31, PIPL Art.
Datenbankrecht: Datenbanklizenz Entwurf Nutzungsumfang und Audit mit geführtem Workflow, Normencheck, Beweis- und Fristenlogik, Red-Team und verwertbarem Ergebnis.
中文优先:用于DeFiAMM安全相关任务,帮助识别、设计、实现或验证对应工作流。English keywords: Security checklist for Solidity AMM contracts, liquidity pools, and swap flows.
Analyze DeFi security incidents including flash loan attacks, oracle manipulation, reentrancy exploits,
Builds, redesigns, polishes, and visually reviews websites and web UIs that must feel specific, time-appropriate, non-generic, and production-quality.
Detect DCSync attacks where adversaries abuse Active Directory replication privileges to extract password hashes
Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption
Detect NTLM relay attacks through Windows Security Event correlation by analyzing Event 4624 LogonType 3 for
Detects and responds to OAuth token theft and replay attacks in cloud environments, focusing on Microsoft Entra
Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit
Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials
Audit de sécurité de smart contracts Solidity et blockchain. Se déclenche avec "smart contract", "Solidity", "audit blockchain", "vulnérabilité smart contract", "reentran — from…
XAF Security System covering authentication (password, Windows, OAuth2), user and role setup for EF Core and XPO, authorization and Permission Policy,…
点破一段技术机制背后不明显的心智模型——角色是谁、token/凭证/密钥/证书归谁所有、谁在向谁证明什么、为什么设计成这个形状。资深工程师一句话能点明的东西("这个 token 是 OpenAI 的"),这个 skill 负责替用户点明。Use this whenever the user pastes a config, endpoint,…
Activate when: a founder asks 'can we avoid competing head-on with big players?', someone asks 'is this disruption or just a price war?', an investor wonders if a startup's entry…
Advanced Django security — file upload validation (extension/size/storage), DRF API security (rate limiting throttles, JWT), Content Security Policy middleware, django-environ…
Security standards and authentication tools for Dutch government software. Use when implementing DigiD, eHerkenning, OAuth, OIDC, PKIoverheid, or other Dutch government…
DORA-Artikel-16-Fachmodul für Cyber- und Compliance-Teams: prüft, ob ein Finanzunternehmen den vereinfachten IKT-Risikomanagementrahmen nutzen kann, und baut Governance-, Asset-,…
Duo Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with Duo Security data.
Production-ready Gmail and Outlook OAuth integration for Next.js with Supabase. Handles email scopes, token refresh, permission management, and secure API access for…
Audit and harden encryption across the full stack. Checks data-at-rest encryption (database TDE, field-level AES-256-GCM, file storage SSE, backup encryption), data-in-transit…
Design or audit enterprise tenant and administrator governance across ownership, organization hierarchy, domains, roles, permissions, delegated administration, SSO/SCIM authority…
Central authority for Claude Code enterprise security. Covers enterprise managed policies (managed-settings.json), settings precedence hierarchy, policy file locations (macOS,…
Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. USE FOR: create app registration, register Azure AD app, configure OAuth, set up…
Enumerate and exploit network services including SMB, FTP, SSH, RDP, HTTP, databases (MySQL, MSSQL, PostgreSQL, MongoDB), LDAP, NFS, DNS, and SNMP.
Use when working in a project that manages secrets with envx (envx-cli): .env. files, .env..gpg encrypted files, an .envrc passphrase file, an .envxrc JSON config,…
Use when authenticating a BaaS partner integration with eOS — OAuth 2.0 client-credentials, short-lived Bearer tokens, and request signing on protected calls.
AI inference you own, forever powering your OpenClaw agents via the Morpheus decentralized network. Stake MOR tokens, access Kimi K2.5 and 30+ models, and maintain persis — from…
AI inference you own, forever powering your OpenClaw agents via the Morpheus decentralized network. Stake MOR tokens, access Kimi K2.5 and 30+ models, and maintain persis — from…
Implement security best practices for Evernote integrations. Use when securing API credentials, implementing OAuth securely, or hardening Evernote integrations.
Executes authorized attack simulations against Active Directory environments to identify misconfigurations,
Tests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token lea — from…
Exploit misconfigured Active Directory Certificate Services (AD CS) ESC1 vulnerability to request certificates
BloodHound is a graph-based Active Directory reconnaissance tool that uses graph theory to reveal hidden and
Exploits JWT algorithm confusion vulnerabilities where the server''s token verification library accepts the
Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation,
Falco Runtime Security is built around Kubernetes orchestration platform. The underlying ecosystem is represented by kubernetes/kubernetes (121,313+ GitHub stars).
Use Famulor's OAuth-secured, read-only MCP profile to inspect assistant configurations, versions, workspace catalogs, and unified call, messaging, and email history.
Expert in securing FastAPI applications with JWT tokens and Better Auth. Use this when implementing authentication middleware, route protection, and user isolation.
Firestore Security Rules patterns for user-scoped access, RBAC with custom claims, multi-tenant isolation, field validation, immutable fields, and testing strategies.
Security-first checklist for Flare-family contract design, deployment, and audit. Covers both (1) GENERIC EVM security patterns the user must apply by default — Ownable2Step over…
Install and configure Flexport API authentication with API keys or OAuth credentials. Use when setting up a new Flexport logistics integration, configuring bearer tokens, or…
Apply security best practices for Fondo including OAuth token management, financial data protection, SOC 2 compliance, and access control.
Authentication and session discipline. argon2id password hashing, server-side sessions vs JWT, OAuth 2.1 + PKCE, MFA via TOTP / WebAuthn, password reset hygiene, anti-enumeration…
Secret handling discipline. Env loading with fail-fast validation, log redaction at source, error-to-client hygiene, weak-hash detection, rotation runbooks, hashed-at-rest API…
Use when you need to design, review, or improve security in Quarkus applications — including Quarkus Security with JWT/OIDC, basic auth, @RolesAllowed / @Authenticated / — from…
Zentrales Fristenbuch fuer die Kanzlei mit Haupt- und Vorfristen ueber alle Rechtsgebiete. Berechnet Fristbeginn nach den jeweiligen Verfahrensordnungen (ZPO StPO SGG FGO VwGO…
Configure auth for the GA4 Data API — OAuth user credentials for interactive use, or a service account for automation / CI.
Interact with the Calendar Bridge — a self-hosted Node.js service that provides a persistent REST API for Google Calendar events.
Reads and creates calendar events via the Google Calendar API. Used by calendar-agent for weekly agenda generation, focus time block analysis, multi-calendar event aggregation,…
Reads and writes document scans and records files to configured Google Drive folders via the Drive API.
Patentanwälte: gebuehren und kostentransparenz - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit,…
GeckoTerminal API - DeFi and DEX aggregator providing real-time cryptocurrency prices, trading volumes, OHLCV charts, and liquidity data across 250+ blockchain networks and 1,800+…
Central authority for Gemini CLI sandboxing and isolation. Covers Docker, Podman, macOS Seatbelt profiles, and security boundaries.
Supabase JWT 기반 Row Level Security(RLS) 시스템 구현 스킬. 테넌트(회사/조직/팀) 구조에서 관리자가 구성원에게 리소스(게시판/메뉴/기능) 접근 권한을 개별 부여하고, Auth Hook으로 JWT에 주입하여 DB 레벨까지 자동 강제하는 시스템.
Use when implementing GitHub OAuth + GitHub App authentication with Nango - provides two-connection pattern for user login and repo access with webhook handling