Audit any MCP server's security & quality — OWASP MCP Top 10 + explainable 0-100 MCP Score
Security / 安全
242 skills
Compliance & security scan for your app: secrets, exposed files, headers, privacy, AI-disclosure.
AI-powered security scanning using Black Duck Signal for vulnerability detection.
GitHub Actions workflow security audit - 21 checks: pinning, permissions, secrets, injection.
Security audit for docker-compose.yml — 25 checks: secrets, privileges, network, volumes, images.
CISA Known Exploited Vulnerabilities feed + remediation deadlines for US federal + critical infr...
Local-first secret scanning, rotation, vault, and audit-log tools for AI agents.
Automated code review tool that analyzes code quality, detects bugs, identifies security vulnerabilities, and suggests improvements based on industry best practices
Cybersecurity Ai MCP server. Tools: classify vulnerability, lookup cve, check security heade...
OWASP Top 10 for AI Agents security assessment tools. Capabilities: full agent security scan...
DORA Article 26 Threat-Led Penetration Testing planner — TIBER-EU pathway scoping, white-tea...
Ai Ops MCP server. Tools: system health check, check service, security scan. Built by MEOK A...
Use when turning a public-equity base case, model, thesis, event, or catalyst into scenario skew, sensitivity, breakpoint, and PM action-threshold analysis. Do not use for first-pass model builds, credit-security valuation, or generic planning.
코드 리뷰, PR 리뷰, 품질 리뷰, 성능 리뷰, code review - Expert at reviewing code for quality, adherence to architectural principles, security, and performance. Use when reviewing PRs, verifying code quality before merge, or auditing implemented features. Do NOT use for initial implementation or debugging.
Live npm/PyPI dependency-health verdicts so AI agents stop recommending stale or CVE'd packages
Dependency Updater Ai MCP server. Tools: check outdated, suggest updates, security audit. Bu...
Security auditor for Laravel applications. Analyzes code for vulnerabilities, misconfigurations, and insecure practices using OWASP standards and Laravel security best practices.
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
Build comprehensive threat actor profiles using open-source intelligence (OSINT) techniques to document adversary motivations, capabilities, infrastructure, and TTPs for proactive defense.
Security tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.
Test JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid parameter injection, and weak secret exploitation to achieve authentication bypass and privilege escalation.
This skill covers hardening and securing process historian servers (OSIsoft PI, Honeywell PHD, GE Proficy, AVEVA Historian) in OT environments. It addresses network placement across Purdue levels, access control for historian interfaces, data replication through DMZ using data diodes or PI-to-PI co…
Unified application security skill for Coding Agent systems like OpenCode. Use when reviewing or writing code that touches authentication, authorization, user input, payments, database access, secrets, deployment, dependencies, or AI/agent workflows. Includes OWASP Top 10 (2025), ASVS 5.0 highlight…
Discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.
AI URL safety validator: SAFE/SUSPICIOUS/DANGEROUS verdict, trust score, threat intel.
Quantum-safe vault, encryption & compliance for AI agents. NIST FIPS 203/204 ML-KEM-768 + ML-DSA-65.
Structures a clear, actionable malware analysis report covering summary, sample identity, capabilities, IOCs, ATT&CK mapping, and detection guidance for both technical and decision-making audiences. Activates for requests to write, structure, or review a malware analysis or reverse-engineering repo…
Testing rsync daemon services (default port 873) for unauthenticated module listing and access, weak/default credentials and brute force, arbitrary file read/download and write/upload (including authorized_keys planting), and rsyncd.conf/secrets misconfiguration during authorized engagements.
Perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including KAPE, MFTECmd, PECmd, LECmd, JLECmd, and Timeline Explorer for parsing registry hives, prefetch files, event logs, and file system metadata.
Tenable Nessus is the industry-leading vulnerability scanner used to identify security weaknesses across network infrastructure including servers, workstations, network devices, and operating systems.