Find the perfect skill
CIS OpenShift 1.3.3: Service Account Private Key File
Security
Ensure the --service-account-private-key-file argument is set appropriately in the OpenShift Controller Manager per CIS benchmark 1.3.3.
Scan Specific MCP Skill
Security
Scans a specific MCP skill by npm package name or GitHub URL to detect security threats.
Forter Agentic Readiness Audit
Security
Audit a website against the Forter Agentic Readiness Guide. Loads rubrics, probes the site, and produces a prioritized fix report.
Geo-Int Web Search
Security
Performs web searches to verify geographical clues, road standards, or point-of-interest locations.
Review Semgrep Findings
Security
Review and triage semgrep security scan results to identify true positive vulnerabilities. Performs deep code analysis to distinguish real vulnerabilities from false positives.
Testing for Broken Access Control
Security
Systematically testing web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.
Prowler Compliance Review
Security
Reviews PRs modifying compliance frameworks (CIS/NIST/PCI-DSS) by validating JSON, duplicates, and metadata.
Access Control Manager
Security
Audits user access permissions across cloud services, SaaS applications, and internal systems to enforce least-privilege principles. Connects to identity providers like Okta, Auth0, and AWS IAM to identify over-privileged accounts, unused access rights, and stale users. Generates access review reports and prioritized remediation playbooks.
Export NIST OSCAL from Compliance
Security
Export NIST OSCAL JSON from compliance evidence stored in ArangoDB. Supports NIST 800-171 and CMMC Level 2 frameworks.
Testing for Broken Access Control
Security
Systematically testing web applications for broken access control vulnerabilities including privilege escalation and insecure direct object references.
DeFi AMM Security
Security
Security checklist for Solidity AMM contracts, liquidity pools, and swap flows. Covers reentrancy, donation attacks, oracle manipulation, slippage, and integer math.
Frontend Security Expert
Security
Specialist in secure frontend coding: XSS prevention, output sanitization, CSP, and client-side attack protection.