Find the perfect skill
Security Analyzer
Security
Comprehensive security vulnerability analysis for codebases and infrastructure. Scans dependencies, containers, cloud IaC, and detects exposed secrets.
Security Scanning and Hardening
Security
Coordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls.
Secrets Management
Security
Implement secure secrets management for CI/CD pipelines using tools like HashiCorp Vault, AWS Secrets Manager, or native platform solutions. This skill covers storing and rotating sensitive credentials such as API keys and database passwords, integrating retrieval into CI pipelines, and following least-privilege access principles.
File Carving with Foremost
Security
Recover files from disk images and unallocated space using Foremost's header-footer signature carving to extract evidence regardless of file system state.
Security Audit Phase 1
Security
First phase of the security audit pipeline that scans the codebase (src/app) for vulnerabilities like unprotected endpoints, missing input validation, authorization gaps, and exposed secrets. Outputs a prioritized findings list in SECURITY_PLAN.md. Use after /full-security-audit or invoke directly with '/1-security-audit'.
WPeGPT Analyzer
Security
Automated reverse analysis of binary executables (PE/ELF) using IDA and WPeGPT. Outputs structured reports including program purpose, network IoCs, suspicious functions, and vulnerability assessment.
Add Cloudflare Access User
Security
Adds new users to Cloudflare Access by updating authentication policies. Syncs allowed emails to all protected services.
Malware Analyst
Security
Expert malware analyst specializing in defensive malware research, threat intelligence, and incident response.
Telegram Channel Access Management
Security
Manage Telegram channel access: approve pairing codes, edit allowlists, set DM/group policy, and handle pending requests by editing the access state JSON file.
Threat Modeling
Security
Disciplined threat modeling loop for software architectures and APIs. Map assets, apply STRIDE, classify impact, and recommend mitigations. Responses in Portuguese.
Export OSCAL
Security
Export NIST OSCAL JSON compliance evidence from an ArangoDB graph for NIST 800-171 and CMMC L2 frameworks.
Frontend Security Expert
Security
Specialist in secure frontend coding: XSS prevention, output sanitization, CSP, and client-side attack protection.