為無測試的 Android 舊代碼建立安全網 — Characterization Tests、Robolectric Native Graphics、MockK、Compose Preview Screenshot Test、Roborazzi/Paparazzi 視覺迴歸、Detekt/Lint baseline、Golden Master、覆蓋率量化目標
Security / 安全
242 skills
Scan AI agents for tool-calling vulnerabilities: prompt leaks, hijacking, injections, and more.
Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and board-level security reporting. Use when building security programs, justifying security budget, selecti…
FinishKit MCP: scan GitHub repos for security vulnerabilities, deployment blockers, and quality
Analyze MITRE ATT&CK T1583.006 Web Services in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1583.006, Web Services, or enterprise ATT&CK. Adversaries may reg…
The Beamix R3.x security model for agent-to-agent trust: HMAC signature verification, nonce replay prevention, sentinel-bracketed spec parsing, and issuer allowlists. Use when building or auditing the Cloudflare bridge, writing trust spec validation code, or authoring agents that accept inbound spe…
Generate, review, and test OPA Rego policies following security best practices. Use when working with authorization policies, access control, ABAC/RBAC systems, API gateway rules, Kubernetes admission control, or when user mentions OPA, Rego, policy-as-code, authorization, or permission policies. A…
Analyze MITRE ATT&CK T1218.012 Verclsid in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1218.012, Verclsid, or enterprise ATT&CK. Adversaries may abuse vercl…
Scans source code for security vulnerabilities — injection flaws, authentication bypasses, hardcoded secrets, XSS, and more — then filters false positives and ranks findings by severity and confidence. Supports all programming languages. Uses a three-phase audit-filter-report workflow with customiz…
Scan an MCP server for EU AI Act Art. 50, tool quality, OAuth hygiene & security before shipping.
MCP server for Shodan API — device search, IP lookup, DNS, and CVE/CPE queries.
🔒 Security & Compliance skill suite derived from anthropics/skills. Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response. Provides 10 specialised commands for security, compliance, gdpr workflows.
Expert HIPAA compliance assistant for healthcare and software contexts. Use this skill whenever the user mentions HIPAA, PHI (Protected Health Information), ePHI, covered entities, business associates, healthcare data privacy, medical records, health information security, BAA (Business Associate Ag…
对 PMContext 做 relentless 质询压力测试——红队攻击承重假设(steelman-then-attack 三段式:先述最强版本再攻击)+ 八维置信度盘问 + 用户/市场/可行性/度量四面逼问,产出致命缺口清单与最便宜证伪测试。Use when the user asks to stress-test or pressure-test PMContext, mentions 质询、压力测试、红队、red team、grill、盘问、挑刺、stress test、challenge assumptions、攻击假设、承重假设、kill criteria、最便宜测试、steel…
Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks
Scans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal).
OWASP threat scanner auditing codebases for safety leaks.
AI agent security scanner — prompt injection detection, SQL injection, PII isolation, threat intel.
DeFi smart contract forensic auditor and vulnerability scanner.
Local permission gateway and security policy engine for MCP tool execution.
Linux CVE prioritisation: 16 MCP tools for scan, fleet, runtime, and PR-able fix discovery.
Anthropic logs audit filter and cybersecurity threat analyzer.
Scan prompts for injection attacks, redact PII, and audit LLM SDK usage from any MCP client
AI agent governance — security scanning, BYOK routing, audit logging, and Council approvals.
Electron.js MCP server — IPC scaffolding, security auditing, build tooling for AI assistants
MCP gateway with 10 tools for code analysis, architecture, package audit & security.
Verification layer for AI agents: endpoint, pricing, compliance, security, and claim checks.
Use when asked to simplify, clean up, tidy, or refactor code for clarity without changing what it does, or when the user says "simplify this", "clean this up", "make it readable", "reduce the complexity", or "tidy this". Behavior-preserving only; not a bug or security audit (use bug-hunt or securit…
Use when the user adds, edits, lists, or applies chezmoi-managed secrets; syncs Bitwarden sessions; runs GPG encryption on project files; or works with the .secrets submodule. Also use when troubleshooting chezmoi config path issues in this repository.
Runtime AI-to-AI security monitor. 23 anomaly types, OWASP MCP Top 10 coverage.