Find the perfect skill
SARIF Parsing
Security
Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. Handles filtering, deduplication, format conversion, and CI/CD integration.
Firebase APK Scanner
Security
Scans Android APKs for Firebase misconfigurations: open databases, storage, auth issues, and exposed cloud functions. For authorized security testing.
Local RLM Security Audit
Security
Run local privacy-preserving RLM security audits for large .NET legacy codebases. Produce actionable markdown/JSON audit outputs without loading full code into model context.
Ensure service account private key file is set
Security
CIS 1.3.3 control for OpenShift verifying the service account private key file is set on the controller manager.
Dependency Audit and Security Analysis
Security
Analyze project dependencies for vulnerabilities, license issues, and outdated packages, and provide actionable remediation strategies.
Scan Specific MCP Skill
Security
Audit a specific MCP skill by npm package name or GitHub URL. Generates security findings and optionally creates a post draft for critical issues.
Authentication Flow Builder
Security
Implement secure authentication flows with JWT, OAuth2, OIDC, and multi-factor authentication.
Building Cloud SIEM with Sentinel
Security
Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR platform. Configure multi-cloud data connectors, write KQL detection queries, build response playbooks, and perform threat hunting.
Security Code Review
Security
Reviews security vulnerabilities and suggests fixes. Detects auth issues, SQL injection, sensitive data exposure, and more.
Scan Specific MCP Skill
Security
Scan a specific MCP skill by npm package name or GitHub URL to detect threats and generate reports.
Security Review Checklist
Security
A security review checklist for Convex functions, auth logic, public queries, admin routes, webhooks, uploads, and AI-generated code.
CIS OpenShift Control 1.3.3 - Service Account Private Key
Security
Ensure the --service-account-private-key-file argument is set appropriately on the controller manager.