Verification layer for AI agents: endpoint, pricing, compliance, security, and claim checks.
Security / 安全
242 skills
Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.
AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents
MCP server for ScanMalware.com URL scanning, malware detection, and analysis.
Systematically testing web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.
Audits codebases for common security vulnerabilities that AI coding assistants introduce in "vibe-coded" applications. Checks for exposed API keys, broken access control (Supabase RLS, Firebase rules), missing auth validation, client-side trust issues, insecure payment flows, and more. Use this ski…
29 security tools for AI agents — CVE, OSINT, threat intel, code security. No API key needed.
Security gateway for AI agents: score tool calls, verify agent cards, enforce policy, audit.
Runtime constitutional verification for AI answers — claim reasoning, ECS, red team, audits.
Blockchain compliance: screen wallets vs OFAC SDN + threat intel, open cases, generate SAR drafts
ZEN SecDB MCP server for CVE intelligence, CVSS/EPSS scoring, advisories, SSVC, and package audits.
Crypto compliance MCP: stablecoin-freeze, token security, wallet screening, KYT & oracle verdicts.
HTTP MCP Server for comprehensive Python vulnerability scanning and security analysis.
Public data intelligence for AI agents — CVE, compliance, patents, contracts, domains.
Tools for Business Continuity, DR & compliance: DORA, SOC 2, NIS2, Cyber Essentials, NHS DSPT.
AI website growth audits: SEO, performance, AI readiness (GEO), conversion, a11y, security.
Deep security scans of repos you own from your editor: dependency CVEs, SAST, git-history secrets.
Unified threat intel - OTX, AbuseIPDB, GreyNoise, abuse.ch, Feodo Tracker
Free no-account URL security scan: 0-100 Launch Readiness score for any live site in ~15 seconds.
Governed threat modeling, code threat verification, traceability & compliance, as MCP tools.
Local-first security check for AI coding agents: secrets, .env exposure, git-history leaks, CVEs.
Scans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems, and signature replay. Use when auditing StarkNet projects.
Conduct a defensible cybersecurity risk assessment using the NIST SP 800-30 Rev 1 methodology: prepare scope and a risk model, identify threat sources and threat events, identify vulnerabilities and predisposing conditions, determine likelihood and impact, compute risk, and communicate results as a…
🔒 Security & Compliance skill suite derived from hesreallyhim/awesome-claude-code. Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response. Provides 10 specialised commands for security, compliance, gdpr workflows.
Security analysis for Aiken smart contracts on Cardano. 75 vulnerability detectors.
Jailbreak API-served LLMs using G0DM0D3 techniques — Parseltongue input obfuscation (33 techniques), GODMODE CLASSIC system prompt templates, ULTRAPLINIAN multi-model racing, encoding escalation, and Kheish-native prefill/system prompt integration. Use when a user wants to bypass safety filters, ja…
One-click security hardening system for AI agents and skills. Deploys input filters, command interceptors, model locks, persistent guards, and audit logging to protect against prompt injection, social engineering, dangerous command execution, and information leakage. Use when: "安全加固", "security har…
Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security engagements.
Security review and threat analysis for agent skills. Use when reviewing, auditing, or validating skills for security issues including prompt injection, code execution risks, data exfiltration, supply chain vulnerabilities, and policy violations. Triggers on requests to "review a skill", "audit ski…
A cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardco