197 tools found
A skill for managing opencode permissions: reviews always-allow lists, suggests safe read-only commands, and configures allow/deny/ask patterns.
Applies GDPR Article 25 Privacy by Design to schemas, APIs, and user flows - minimization, consent, retention, PII logging.
Semgrep Rule Creator is a skill that helps you build custom static analysis rules by iterating between pattern matching and taint mode approaches.
A skill for porting existing Semgrep rules to new target languages with applicability analysis and test-first validation.
A 6-phase security review tool that scans third-party OpenClaw skills for malicious code before installation, protecting against the 7.5% confirmed threat rate.
An 8-phase skill security scanner combining a static-analysis script with manual review for prompt injection and malicious code.
A 7-phase auditor skill that verifies smart contract code against whitepapers line-by-line, with evidence-cited divergence findings.
Find every variant of a known vulnerability across a codebase: pattern-match, iteratively generalize, and triage with CodeQL/Semgrep.
Security skill enforcing secure-by-default environment variable handling in Claude Code sessions using Varlock, never exposing secrets.
Detects missing or compiler-eliminated zeroization of sensitive data in C/C++ and Rust, requiring IR/assembly evidence, not just source-level guesses.
Open-source Claude Code harness for autonomous vulnerability discovery, verification, and patching of C/C++ memory bugs via ASAN and gVisor sandboxing.
npm-scan is a CLI supply-chain scanner that catches behavioral npm package attacks CVE-based tools like npm audit miss.