Analyze Web3 security risks with SpoonOS agents. Use when checking token safety (honeypots, rugs), simulating transactions, detecting MEV, or auditing contracts.
Analista de seguridad ofensiva/defensiva nivel senior. Pentesting, OWASP Top 10, threat modeling, código seguro, SIEM, IR.
Security analyst persona with deep OWASP expertise, vulnerability classification, risk assessment, and compliance mapping
Comprehensive security vulnerability analysis for codebases and infrastructure. Scans dependencies (npm, pip, gem, go, cargo), containers (Docker, Kubernetes), cloud IaC…
Evaluate security posture and regulatory compliance for a system architecture. Produces .forge/security.md with auth model, data isolation, PII inventory, regulatory requirements,…
Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations.
Use when writing or reviewing code that parses user input, builds SQL/shell commands, handles secrets/credentials, hashes passwords, changes auth checks, deserializes untrusted…
Use when generating Java code for web applications, APIs, or enterprise systems - prevents OWASP Top 10 vulnerabilities in Spring Boot, Jakarta EE, and core Java
Durcissement de la sécurité des APIs — rate limiting, validation d'entrée, headers de sécurité, CORS, protection contre les attaques courantes.
Security Architect: Security by Design fuer den gesamten Entwicklungsprozess. 4 Modi: DESIGN (Threat Modeling bei Ideation/Planung), REVIEW (Security-Check bei Code-Aenderungen),…
Use when conducting a dedicated security architecture review of a Salesforce org — assessing sharing model completeness, FLS/CRUD enforcement, Apex security patterns, exposed API…
Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table.
Execute STRIDE threat modeling, vulnerability scanning, and security control validation with risk scoring
引导安全审查和漏洞评估,遵循 OWASP 标准。 使用时机:安全审计、漏洞检查、安全编码审查、威胁建模。 关键字:security, OWASP, vulnerability, authentication, authorization, 安全, 漏洞, 认证。
Prepare or audit one truthful customer security-assurance packet and its claim-evidence operating loop across questionnaires, procurement responses, trust-center content, gated…
Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.
Review security of command execution, tool permissions, and API key handling. Use when user mentions "security review", "audit", "check security", "vulnerabilities", or before…
Security review or audit of code, architecture, or infrastructure - Threat modeling sessions - Reviewing PRs for security implications
Detect common security vulnerabilities in code. Covers OWASP patterns, SQL injection, bare excepts, shell injection. Framework-agnostic.
Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.
Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks…
Automatisation d'audits de sécurité incluant scanning, reporting, intégration CI/CD et remediation tracking.
Perform a security audit of a codebase checking for exposed secrets, vulnerable dependencies, injection vulnerabilities, insecure configurations, and OWASP Top 10 issues.
Comprehensive security audit workflow including dependency scanning, unsafe code detection, and secret management.
Security Audit Skill is built around OWASP security tooling ecosystem. The underlying ecosystem is represented by zaproxy/zaproxy (14,896+ GitHub stars).
Security audit methodology and checklist for codebases. Use when performing security reviews, auditing a project for vulnerabilities, or hardening an application before…
Inspect third-party Claude/OpenClaw/Codex/OpenCode skills, plugins, repos, npm packages, pip packages, shell installers, and GitHub Actions before any download or installation.
[METHODOLOGY] Comprehensive security analysis against OWASP Top 10 standards (authentication, user input, database queries, external APIs). Preloaded by security-auditor agent.
Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.
Application security agent that audits code for OWASP Top 10 vulnerabilities, hardcoded secrets, and common security flaws.
Expert in compliance frameworks (SOC2, ISO 27001), automated auditing, and risk management.
Specialista na autentizaci a autorizaci. MUSÍ být použit při analýze bezpečnosti kódu — hledá slabé hashování hesel (MD5/SHA1) a chybějící autorizační kontroly.
Security auth/session review: cookies, tokens, logout, MFA, CSRF, browser storage.
Базовая безопасность в реализации — валидация входных данных (Zod), secrets management, безопасные ошибки, auth/authz patterns, XSS/injection prevention, dependency audit, secure…
Security Benchmark Runner - Auto-activating skill for Security Advanced. Triggers on: security benchmark runner, security benchmark runner Part of the Security Advanced skill…
Implement security best practices for web applications and infrastructure. Use when securing APIs, preventing common vulnerabilities, or implementing security policies.
Master security blue team kql with comprehensive coverage of concepts, implementation, optimization, and production best practices.
Build a minimal but real security policy for sensitive apps. The output is a single, coherent Blue Book document using MUST/SHOULD/CAN language, with explicit assumptions — from…
Build a minimal but real security policy for sensitive apps. The output is a single, coherent Blue Book document using MUST/SHOULD/CAN language, with explicit assumptions — from…
中文优先:用于安全bountyhunter相关任务,帮助识别、设计、实现或验证对应工作流。English keywords: Hunt for exploitable, bounty-worthy security issues in repositories.
Strategic principles for integrating security from the start, not retrofitting it later
Führt Produktteam durch Security-by-Design: Bedrohungsmodell, Updatekanal, SBOM, Schwachstellenprozess, Logging und Notfallplan. — from Klotzkette/claude-fuer-deutsches-recht
Comprehensive AI-powered security scanning suite with 48 skills covering OWASP Top 10, 7 language-specific deep scanners (Go, TypeScript, Python, PHP, Rust, Java, C#), supply…
OWASP-based security checklist any agent can reference when reviewing or writing code
Przegląd bezpieczeństwa zmian w kodzie i konfiguracji.
Read a diff for security by tracing attacker-controlled input to dangerous operations and checking every trust boundary it crosses.
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting…
Vérification de conformité sécurité incluant ISO 27001, SOC 2, HIPAA, NIST et audit trail. Se déclenche avec "ISO 27001", "SOC 2", "HIPAA", "NIST", "conformité sécurité", "audit…
You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards.
Performs advanced SAST (Static Application Security Testing) and compliance analysis on Pull Request diffs.
Guidance for Microsoft Security Copilot - the generative-AI security platform that helps analysts investigate, hunt, summarise, and respond using natural language, plugins,…
Guidance for Microsoft Security Copilot agents — autonomous, purpose-built AI agents (e.g., phishing triage, alert triage, conditional access optimization, vulnerability…
Shared reference for the security cluster: the trust-boundary model (untrusted input/action → privileged sink), the defend-vs-attack × code/config/runtime surface map, severity &…
Walk a security team member through allocating a CVE for an tracking issue. Prints the ASF Vulnogram allocation URL and a CVE-ready title (the issue title strip — from…
GitHub security alerts command center -- triage Dependabot, code scanning, and secret scanning alerts entirely from the editor.
Master security data encryption in use with comprehensive coverage of concepts, implementation, optimization, and production best practices.
Audit de sécurité des dépendances — détection de vulnérabilités connues, mises à jour critiques et gestion du cycle de vie des packages.
Drafts an irrevocable standby letter of credit securing a commercial lease deposit under ISP98 and UCC Article 5.
Get your security deposit back — the move-out documentation that wins disputes before they start, the itemized-deduction challenge, the demand-letter ladder, and the small-claims…
Design security controls and threat mitigations. Use for features involving auth, data, or external exposure.