197 tools found
SAST Configuration skill provides setup and configuration guidance for static application security testing tools including Semgrep, SonarQube, and CodeQL.
Skill for CI/CD secrets: Vault or cloud secret retrieval, workload identity, GitHub Actions credentials and rotation without leaking values.
Skill running automated AWS compliance checks against CIS Foundations, PCI-DSS, HIPAA, and SOC 2 with ready-to-run scripts.
Skill that automates AWS Secrets Manager rotation with Lambda, covering RDS, API keys, monitoring, and compliance.
Comprehensive AWS security audit skill covering IAM, network, data protection, and logging misconfigurations with CLI checks.
Skill for deriving actionable security requirements, user stories and test cases from a threat model and business context.
Skill for scanning project dependencies across ecosystems, generating SBOMs, and planning safe, tested remediation of vulnerable packages.
Defense-in-depth security workflow that coordinates specialized agents to scan, harden, and monitor applications across all layers with DevSecOps automation.
SAST security skill integrating Bandit, Semgrep, ESLint Security, and more across seven languages with framework-specific fixes.
A skill for finding footgun APIs and dangerous defaults: evaluates whether the easy path in an API or config leads to insecurity.
Threat modeling skill mastering STRIDE, attack trees, and data flow analysis for security architecture review.
CAMEL-AI toolkit giving an agent access to MiniMax's multimedia generation - text-to-audio, voice cloning, video, image, and music generation.