Find the perfect skill
HTTP Request Smuggling
Security
Provides a methodology for detecting and exploiting HTTP request smuggling vulnerabilities, including CL.TE, TE.CL, and TE.TE variants, as well as HTTP/2 smuggling. Helps identify desynchronizations between front-end and back-end servers to bypass WAFs, poison caches, or hijack credentials.
Firebase APK Security Scanner
Security
Scans Android APKs for Firebase misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions.
Firebase APK Scanner
Security
Scans Android APKs for Firebase security misconfigurations like open databases, storage buckets, auth issues, and exposed cloud functions. For authorized security research only.
Dependency Audit and Security Analysis
Security
Expert in dependency security: vulnerability scanning, license compliance, and supply chain security analysis.
OSCAL Export
Security
Export NIST OSCAL JSON from compliance evidence in ArangoDB graph, supporting NIST 800-171 and CMMC Level 2 frameworks.
Export NIST OSCAL JSON from compliance
Security
Export NIST OSCAL compliance evidence from ArangoDB, supports NIST 800-171 and CMMC Level 2.
Threat Model Status
Security
Displays a comprehensive overview of the threat model state, including asset counts, threat distribution by severity, control verification status, and compliance coverage. Use it to check threat model status, get an overview of security posture, or review the current state.
Dependency Audit and Security Analysis
Security
Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages and provide actionable remediation strategies.
Auditing Wallet Security
Security
Execute review of crypto wallet security including private key management and transaction signing.
Export OSCAL
Security
Export NIST compliance evidence as OSCAL JSON from an ArangoDB graph. Supports NIST 800-171 and CMMC Level 2 frameworks.
Cloud Log Forensics with AWS Athena
Security
Leverage AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigations. Includes DDL for partition projection and SQL queries for detecting unauthorized access and data exfiltration.
AI Situational Awareness
Security
Detects internal reasoning quality threats like hallucination risk, scope creep, and context degradation using adapted Cooper color codes and OODA loop decision-making. Helps maintain awareness during complex or unfamiliar tasks and before high-stakes outputs.