Find the perfect skill
Speak Security Basics
Security
Apply Speak security best practices for secrets, user data, and audio handling in language learning applications.
Windsurf Audit Logging
Security
Configure AI interaction audit logging for compliance (SOC 2, ISO 27001, HIPAA) with SIEM integrations and alerts.
CTF Here
Security
Set competition context for the current challenge directory. Initializes .ctf/ folder, detects files, guesses category, and saves metadata.
Frontend Security Coder
Security
Expert in secure frontend coding: XSS prevention, output sanitization, CSP, and client-side security patterns. Use for implementing or reviewing frontend security.
Testing for Broken Access Control
Security
Systematically testing web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.
API Security Checklist
Security
API-focused security checklist covering OWASP API Top 10, authentication hardening, input validation, rate limiting, and compliance controls for API surfaces.
Code Injection Detector
Security
Automated skill for detecting and preventing code injection vulnerabilities. Covers input validation, secure coding practices, and vulnerability detection following OWASP standards.
CIS OpenShift 1.3.3 Service Account Key
Security
Verify that the --service-account-private-key-file argument is set appropriately for the OpenShift Controller Manager, ensuring service account token keys can be rotated.
Performing File Carving with Foremost
Security
Recover files from disk images and unallocated space using Foremost's header-footer signature carving to extract evidence regardless of file system state.
Cryptographic Audit of Applications
Security
Systematic audit of application cryptography to detect weak algorithms, insecure modes, hardcoded keys, and TLS misconfigurations. Includes building an automated scanner for Python and config files.
Perplexity Security Basics
Security
Security best practices for Perplexity API keys, tokens, and access control. Covers secret rotation, least privilege, and audit logging.
Containerized Security Auditing and Ethical Hacking
Security
Containerized security auditing and ethical hacking tools. All operations run in isolated Docker containers for safety.