Find the perfect skill
RLS Templates for Supabase
Security
Provides production-ready Row Level Security policy templates for Supabase applications. Covers multi-tenant patterns, user isolation, role-based access, and AI-specific patterns like chat and embedding security. Helps quickly implement and test RLS policies to secure user data in Supabase projects.
Command Injection to RCE Proof
Security
Turn suspected OS command injection into proof of remote code execution via an OAST callback, then demonstrate a safe follow-on impact like reading a file.
Crisis Response Skill
Security
Skill for handling immediate crises (suicide, self-harm, abuse, psychosis, medical emergency). Assesses risk and routes to human help.
Frontend Security Coder
Security
Frontend security coding expert specializing in XSS prevention, output sanitization, CSP, and safe DOM manipulation. Use proactively to secure client-side implementations.
Containerized Security Auditing & Ethical Hacking
Security
Containerized security auditing and ethical hacking tools. All operations run in isolated Docker containers for safety.
Ensure Regular Patching of RDS Systems
Security
Ensures that Amazon RDS instances and their database engines are regularly updated and patched to address security vulnerabilities and maintain compliance.
Backend Security Coder
Security
Expert in secure backend coding specializing in input validation, authentication, and API security.
Export NIST OSCAL Compliance Evidence
Security
Exports NIST OSCAL assessment-results JSON from compliance evidence in an ArangoDB graph, supporting NIST 800-171 and CMMC Level 2. Includes dry-run and validation modes.
Penetration Testing Practical Skills
Security
Full penetration testing workflow: information gathering, vulnerability discovery (3 tiers, 9+3+6 types), exploitation, post-exploitation, and evasion. Triggered on specific targets with offensive intent.
Firebase APK Security Scanner
Security
Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. For authorized security research.
Python Sandbox Escape
Security
Provides techniques to escape restricted Python eval/exec environments, including basic command execution, class hierarchy traversal, and keyword bypasses using encoding or concatenation. Useful for penetration testing and CTF challenges involving Python jails or sandbox restrictions.
Eric Zimmerman Tools for Windows Artifact Analysis
Security
Learn to analyze Windows artifacts using Eric Zimmerman's open-source tools (KAPE, MFTECmd, PECmd) to examine registry hives, prefetch files, and event logs.