Find the perfect skill
Security Audit Scanner
Security
Analyzes code to detect OWASP Top 10 vulnerabilities.
OWASP Security Checklist
Security
Generates application security checklists based on the OWASP Top 10.
Threat Model Generator
Security
Generates threat model documents with STRIDE analysis.
Threat Modeling Expert
Security
Expert in threat modeling, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security requirement extraction. Use proactively for security reviews.
Incinerate: Anti-distillation Defense
Security
Anti-distillation defense. Generate pollution content to break distillation of your digital persona.
Implementing Cloud Workload Protection
Security
Implements cloud workload protection using boto3 and Google Cloud APIs for runtime security monitoring, process anomaly detection, and file integrity checking.
Kubernetes Security Policies
Security
This skill covers implementing Kubernetes security policies including NetworkPolicy, PodSecurityPolicy, and RBAC for production-grade security. Use it to enforce network segmentation, configure pod security standards, or set up least-privilege access controls.
SAST Configuration
Security
Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.
Firebase APK Security Scanner
Security
Scans Android APKs for Firebase security misconfigurations (open databases, storage buckets, auth issues, exposed cloud functions). For authorized mobile security audits.
Ensure service-account-private-key-file is set
Security
Ensure that the --service-account-private-key-file argument is set as appropriate for the controller manager in OpenShift, per CIS benchmark.
Supply Chain Scan
Security
Scan project dependencies for supply chain attacks using supplyify.
Eric Zimmerman Tools for Windows Artifact Analysis
Security
Learn to analyze Windows artifacts using Eric Zimmerman's open-source tools (KAPE, MFTECmd, PECmd) to examine registry hives, prefetch files, and event logs.