Find the perfect skill
CSO - Security Audit
Security
CSO mode for comprehensive security audits: infrastructure, supply chain, CI/CD, LLM/AI, OWASP Top 10, STRIDE threat modeling.
Firebase APK Security Scanner
Security
Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. For authorized security research only.
Huawei Cloud Registry Artifact Governor
Security
Govern Huawei Cloud SWR registries: enforce image retention policies, VSS vulnerability scanning, least-privilege namespace permissions, cross-region replication, and supply chain security.
CSO Mode - Security Audit
Security
Chief Security Officer mode for comprehensive security audits: secrets archaeology, supply chain, CI/CD pipeline, LLM/AI security, OWASP Top 10, and STRIDE threat modeling.
Safety Audit
Security
Audit unsafe Rust code for memory safety, FFI lifetime violations, leaks, and Vulkan spec compliance.
StackHawk Security Onboarding
Security
Automatically analyzes a repository to determine if it's a candidate for API security testing with StackHawk. If appropriate, generates a pull request with a stackhawk.yml configuration, GitHub Actions workflow, and documentation. Helps development teams set up automated security testing for their APIs.
Firebase APK Security Scanner
Security
Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. For authorized security research only.
AI Guardrail Audit
Security
Audit AI guardrail coverage: bypass vectors, false positive rates, and policy gaps. Includes red-team scenarios to test filter robustness.
Authentication & Authorization Review
Security
Reviews authentication and authorization designs—including JWT, OAuth, RBAC/ABAC—by tracing login flows, token management, route protection, and privilege escalation risks. Helps security engineers audit auth modules for misconfigurations and hardcoded vulnerabilities.
Cloud Log Forensics with Athena
Security
Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation. Covers CREATE TABLE DDL with partition projection and forensic SQL queries.
Threat Analysis (STRIDE/PASTA)
Security
Systematically identifies and analyzes threats using STRIDE or PASTA frameworks. Generates a threat catalog, attack trees, abuse cases, and a prioritized risk register. Useful when modeling security threats or performing risk assessments.
Eric Zimmerman Tools for Windows Artifact Analysis
Security
Learn to analyze Windows artifacts using Eric Zimmerman's open-source tools (KAPE, MFTECmd, PECmd) to examine registry hives, prefetch files, and event logs.