197 tools found
Burp Suite skill for authorized web app testing: intercept HTTP traffic, use Repeater and Intruder, run scans - gated on written authorization.
A security review checklist for Next.js/Supabase/TypeScript apps covering secrets, input validation, SQLi, XSS, CSRF, auth, and rate limiting.
Cloud Penetration Testing skill conducts authorized security assessments of Azure, AWS, and GCP infrastructure, covering reconnaissance, privilege escalation
AI-powered code review skill combining SonarQube/CodeQL/Semgrep static analysis with LLM review across security, performance, and architecture.
Skill for dependency security audits: vulnerability scanning, license compliance, outdated-package detection, and remediation plans.
Expert deployment engineer skill for CI/CD pipelines, GitOps, progressive delivery, zero-downtime rollouts and pipeline security.
Claude skill covering the full authorized penetration-testing lifecycle - recon, scanning, exploitation, persistence and reporting - for security engagements.
An authorized-use-only path traversal testing skill covering exploitation techniques, bypass methods, LFI-to-RCE escalation, and secure coding prevention.
A structured branch-diff review skill for bugs, security vulnerabilities, and code quality, with a full attack-surface mapping and security checklist.
Verifies that fix commits properly address security audit findings, resolve the root cause, and introduce no new bugs or regressions.
Methodology for HTML injection flaws - discovery, payloads, phishing/defacement PoC, filter bypass, remediation. Authorized testing only.
Systematic methodology for identifying and exploiting Insecure Direct Object Reference (IDOR) vulnerabilities in web applications through parameter