Published Skills 29
webapp-sqlmap
Assess SQL Injection with SQLMap
Manual SQL injection testing is slow and inconsistent. This skill provides structured SQLMap commands, authorization checks, validation steps, and reporting guidance for approved assessments.
skill-name
Build Security Operations Skills
Security skill authors need consistent workflows, references, and validation patterns. This template provides reusable structures for security guidance, rules, and CI scanning.
webapp-nikto
Scan Web Servers with Nikto
Web teams need a repeatable way to identify server weaknesses before attackers find them. This skill guides authorized Nikto scans and structured remediation reporting.
secrets-gitleaks
Scan Repositories for Hardcoded Secrets
Hardcoded credentials can expose systems and fail compliance checks. This skill guides Gitleaks scans, configurations, hooks, CI pipelines, triage, and remediation.
sca-trivy
Scan Dependencies and Containers with Trivy
Security teams need consistent visibility into vulnerable components, images, and infrastructure configuration. This skill provides practical Trivy workflows for assessment, reporting, and remediation.
sca-blackduck
Assess Dependencies with Black Duck
Dependency vulnerabilities and license risks can reach production unnoticed. This skill guides Black Duck scans, policy gates, SBOM creation, and remediation triage.
sbom-syft
Generate SBOMs with Syft
Manual software inventories are incomplete and difficult to maintain. This skill guides repeatable Syft SBOM generation for containers, filesystems, archives, and CI pipelines.
sast-semgrep
Audit Code with Semgrep
Security flaws can remain hidden across large, multilingual repositories. This skill guides focused Semgrep scans, triage, custom rules, CI gates, and standards-aligned remediation.
sast-horusec
Scan Code with Horusec
Security flaws and exposed secrets can cross language boundaries and reach production. This skill guides Horusec scans, result triage, and CI integration.
sast-bandit
Scan Python Code with Bandit
Python security flaws can reach production unnoticed. This skill guides Bandit scans, prioritization, CI integration, and remediation with CWE and OWASP references.
reviewdog
Integrate Reviewdog Security Feedback into CI
Security scanner results are often fragmented across CI logs. This skill helps configure reviewdog to publish focused findings in pull requests and local hooks.
recon-nmap
Run Authorized Network Reconnaissance with Nmap
Manual network discovery can miss exposed services and inconsistent configurations. This skill provides structured Nmap workflows for authorized discovery, enumeration, vulnerability checks, and reporting.
pytm
Build pytm Threat Models as Code
Threat modeling often becomes outdated and disconnected from architecture changes. This skill helps create pytm models, STRIDE analysis, and diagram workflows for security reviews and CI.
policy-opa
Enforce OPA Policy as Code
Security teams need repeatable policy checks across clusters, infrastructure, and compliance controls. This skill guides Claude, Codex, and Claude Code through OPA Rego policy creation, testing, and CI/CD enforcement.
pentest-metasploit
Audit Metasploit Workflows Safely
Security teams need structured review of authorized exploit validation, but these workflows carry high misuse risk. This skill documents Metasploit assessment steps with scope checks, logging, and cleanup guidance.
network-netcat
Audit Netcat Network Testing Workflows
Network testers need clear netcat workflows for connectivity checks and controlled validation. This skill organizes netcat commands, authorization steps, and documentation guidance.
ir-velociraptor
Investigate Endpoints with Velociraptor VQL
Endpoint investigations require consistent queries, collection plans, and evidence controls. This skill provides Velociraptor workflows, VQL patterns, and deployment templates for authorized response.
iac-checkov
Scan Infrastructure Code with Checkov
Infrastructure teams need consistent security checks before deployment. This skill guides Checkov scans, policy customization, suppression governance, compliance mapping, and CI integration.
forensics-osquery
Investigate Endpoints with osquery
Endpoint investigations often require many platform-specific tools and commands. This skill provides osquery workflows, detection queries, and packs for consistent forensic collection across major platforms.
detection-sigma
Build Portable Sigma Detection Rules
SIEM-specific rules are difficult to reuse and maintain across platforms. This skill structures Sigma detections, conversions, ATT&CK mappings, and compliance coverage.
dast-zap
Automate OWASP ZAP DAST Scans
Security teams need repeatable runtime testing before releases. This skill guides authorized OWASP ZAP scans, authentication setup, API testing, and CI reporting.
dast-nuclei
Run Authorized Nuclei Security Scans
Known vulnerabilities and misconfigurations can escape manual review. This skill guides authorized Nuclei scans, template selection, validation, and reporting.
dast-ffuf
Plan Authorized Web Fuzzing with ffuf
Web fuzzing creates noisy results and legal exposure when scope, filters, and rate limits are unclear. This skill produces authorized ffuf workflows with focused discovery, filtering, output, and CI guidance.
crack-hashcat
Audit Password Hashes with Hashcat
Password audits need repeatable hash identification, attack selection, and reporting. This skill guides authorized Hashcat workflows for recovery, policy testing, and defensive remediation.