Find the perfect skill
Scan Specific MCP Skill
Security
Scans a specific MCP skill package by npm name or GitHub URL, audits it for threats, and reports findings.
Scan Specific MCP Skill
Security
Analyze a specific MCP skill package for security threats using the ATR engine.
Export NIST OSCAL from Compliance
Security
Export NIST OSCAL assessment-results JSON from compliance evidence stored in ArangoDB. Supports NIST 800-171 and CMMC Level 2 frameworks.
Insecure Deserialization Checker
Security
Validates insecure deserialization checker operations with automated vulnerability detection. Auto-activating skill for Security Fundamentals covering secure coding practices.
Performing Cryptographic Audit of Application
Security
Systematic cryptographic audit of applications to identify vulnerabilities in weak algorithms, insecure modes, hardcoded keys, and protocol misconfigurations.
Malware Analyst
Security
Expert malware analyst specializing in defensive malware research, threat intelligence, and incident response. Masters sandbox analysis and malware family identification.
Attack Tree Construction
Security
Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.
Firebase APK Scanner
Security
Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions.
CIS OpenShift 1.3.3 - Service Account Private Key
Security
Ensures the --service-account-private-key-file argument is set for the controller manager as per the CIS OpenShift benchmark.
Cyberpunk Hacking Mini-Game
Security
Play a cyberpunk hacking mini-game where you must crack a 4-digit code.
Frontend Security Coder
Security
Expert in secure frontend coding, specializing in XSS prevention, output sanitization, and client-side security patterns.
Set service-account-private-key-file appropriately
Security
Ensure the controller manager has --service-account-private-key-file set to the correct key file for signing service account tokens.