Find the perfect skill
Review Semgrep Security Findings
Security
Analyze and triage Semgrep scan results to identify true positive vulnerabilities and filter out false positives.
Navan Security Basics
Security
Secure Navan API credentials using OAuth2 best practices, SSO/SAML, and SCIM provisioning. Ideal for hardening integrations, rotating credentials, or configuring identity provider SSO.
TwinMind Security Basics
Security
Implement security best practices for TwinMind integrations, including secure API key management, environment configuration, webhook signature validation, and data encryption at rest. This skill helps when securing API keys, configuring privacy settings, or implementing data protection for meeting recordings.
Web Dependency Security Scan
Security
Scan a deployed website to detect outdated frontend libraries, CMS platforms, and security header misconfigurations. It interactively collects the target URL and scan scope, then triggers a specialized agent to identify known CVEs and generate a detailed security report without requiring source code access.
Full Threat Modeling Workflow
Security
Orchestrates the complete threat modeling workflow from initialization through reporting, including asset discovery, threat analysis, control verification, compliance mapping, and documentation generation. Use when performing a full security assessment or generating comprehensive threat documentation.
Chief Security Officer Audit
Security
Chief Security Officer mode for comprehensive security audit: secrets discovery, supply chain, CI/CD security, OWASP Top 10, STRIDE threat modeling. Two modes: daily and comprehensive.
sqlmap - SQL Injection Detection and Exploitation
Security
Detect and exploit SQL injection vulnerabilities with sqlmap. Supports parameter testing, database enumeration, and advanced techniques like tamper scripts for WAF bypass.
Security Audit - CSO
Security
Infrastructure-first security audit covering secrets, dependencies, CI/CD, OWASP, STRIDE, and active verification. Use for comprehensive security review.
Scan Specific MCP Skill
Security
Scan a specific MCP skill by npm package name or GitHub URL for security threats and vulnerabilities.
Scan Specific MCP Skill
Security
Scan a specific MCP skill by npm package name or GitHub URL to identify security threats and generate a report.
Spring Boot JWT Security
Security
Provides JWT authentication and authorization patterns for Spring Boot 3.5.x using Spring Security 6.x and JJWT.
Eric Zimmerman Tools for Windows Artifact Analysis
Security
Learn to analyze Windows artifacts using Eric Zimmerman's open-source tools (KAPE, MFTECmd, PECmd) to examine registry hives, prefetch files, and event logs.