Remote MCP security gateway for auth, redaction, policy enforcement, and audit logging.
Security / 安全
242 skills
Search and query HackTricks pentesting documentation with quick lookup and section extraction
Scan AI agent skills for 25 attack classes + runtime monitoring. 1,316+ findings.
Environmental justice screening indicators, pollution burden, and demographic vulnerability
Project-specific security guidelines for secrets, input validation, dependencies, auth, and common vulnerabilities
Monitoring with SAML. security monitoring.
Audit this Firebase + Vue app for security issues before deploy. Use when asked to "security review", "セキュリティレビュー", "安全性チェック", "デプロイ前チェック", "脆弱性チェック", or after changing rules / functions / auth. Covers Firestore & Storage rules, App Check enforcement, exposed secrets, callable-function auth guards,…
Review Dom Based XSS Prevention concerns, trust boundaries, and operational assumptions against OWASP Dom Based XSS Prevention guidance.
You need to add a new API key to the system, update an existing credential, check what secrets are configured for the org or a specific agent, onboard a new third-party tool that needs credentials, diagnose why an agent cannot access a service because a key appears missing, rotate a compromised or …
Implement a vulnerability aging dashboard and SLA tracking system to measure remediation performance against severity-based timelines and drive accountability.
An enterprise-grade, AI-powered penetration testing automation CLI tool. Orchestrates multiple specialized AI agents (Planner, ToolAgent, Analyst, Reporter) backed by 4 AI providers (OpenAI, Claude, Gemini, OpenRouter) and 19 integrated security tools through YAML-defined workflows. Produces profes…
Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.
Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.
当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro 漏洞"。覆盖单目标探测、密钥爆破、Gadget 链自动检测、命令执行、内存马注入和 Key 修改。
Project-specific Electron desktop-app conventions and industry-standard security defaults. Used by the Electron Engineer, Reviewer, Test Engineer, Test Reviewer, and Packager.
Write better incident response and other reports, get guidance on security best practices.
Runs security vulnerability scanning and static analysis. Use when checking for security issues, vulnerabilities, CVEs, OWASP violations, or when the user mentions security review, penetration testing, or code audit.
Investigate sudden drops in organic traffic or rankings and run a structured forensic SEO incident response with triage, root-cause analysis and recovery plan.
Conduct an organizational assessment of risk prior to the acquisition or outsourcing of information security services;
Audit project security posture. Review for OWASP Top 10 vulnerabilities, secrets, injection flaws, and auth gaps. Use --setup to configure security strategy.
Retrieve and present the latest OpenClaw security headlines from the curated news repository.
Full SEO/GEO/AEO/Citability/Content/Performance/Vertical/Security audit with auto-fix. Scans, reports, fixes, and verifies.
Use when performing security audits, threat modeling, vulnerability assessments, or dependency reviews. Provides OWASP checklists, STRIDE templates, vulnerability report structures, and dependency audit formats.
Run and troubleshoot privacy-preserving, local DSPy RLM security audits for large legacy .NET codebases. Use when asked to scan repositories for vulnerabilities, tune RLM/tool limits, fix truncation/stall issues, or produce actionable markdown/json audit outputs without loading entire codebases int…
Monitoring with TLS/SSL. security monitoring.
Vulnerability and exploit intelligence for AI assistants (370K+ CVEs, 105K+ exploits)
Social engineering testing - phishing, pretexting, vishing, and physical security assessment techniques.
高级白盒安全审计专家。基于深度数据流分析和业务逻辑理解的专家级代码安全审计工具。
نظام إدارة واكتشاف ومعالجة الثغرات الأمنية. استخدم هذا الـ skill عند: فحص الثغرات، إدارة نقاط الضعف، اختبار الاختراق، تقييم المخاطر الأمنية، OWASP compliance، إدارة الأحداث الأمنية (SIEM)، استجابة الحوادث، تحديثات أمنية، مسح الشبكة، أو أي مهمة تتعلق بالأمن السيبراني. يتوافق مع إطار عمل الهيئة الوطن…
Cursor rules for secure coding, secret handling, dependency hygiene, authentication, authorization, security testing, and compliance documentation.