api-spectral
Critical 38Validate API Specifications with Spectral
Inconsistent API definitions can hide security and governance defects. This skill guides Spectral configuration, OWASP-focused linting, custom rules, reporting, and CI integration.
Unified search
Start with the task. Skillstore will show complete packs first, then individual skills when they are a better match.
Showing results for "security"
Use these when you need one narrow capability instead of a whole pack.
Validate API Specifications with Spectral
Inconsistent API definitions can hide security and governance defects. This skill guides Spectral configuration, OWASP-focused linting, custom rules, reporting, and CI integration.
Audit Password Hashes with Hashcat
Password audits need repeatable hash identification, attack selection, and reporting. This skill guides authorized Hashcat workflows for recovery, policy testing, and defensive remediation.
Plan Authorized Web Fuzzing with ffuf
Web fuzzing creates noisy results and legal exposure when scope, filters, and rate limits are unclear. This skill produces authorized ffuf workflows with focused discovery, filtering, output, and CI guidance.
Automate OWASP ZAP DAST Scans
Security teams need repeatable runtime testing before releases. This skill guides authorized OWASP ZAP scans, authentication setup, API testing, and CI reporting.
Scan Infrastructure Code with Checkov
Infrastructure teams need consistent security checks before deployment. This skill guides Checkov scans, policy customization, suppression governance, compliance mapping, and CI integration.
Audit Netcat Network Testing Workflows
Network testers need clear netcat workflows for connectivity checks and controlled validation. This skill organizes netcat commands, authorization steps, and documentation guidance.
Audit Metasploit Workflows Safely
Security teams need structured review of authorized exploit validation, but these workflows carry high misuse risk. This skill documents Metasploit assessment steps with scope checks, logging, and cleanup guidance.
Enforce OPA Policy as Code
Security teams need repeatable policy checks across clusters, infrastructure, and compliance controls. This skill guides Claude, Codex, and Claude Code through OPA Rego policy creation, testing, and CI/CD enforcement.
Run Authorized Network Reconnaissance with Nmap
Manual network discovery can miss exposed services and inconsistent configurations. This skill provides structured Nmap workflows for authorized discovery, enumeration, vulnerability checks, and reporting.
Integrate Reviewdog Security Feedback into CI
Security scanner results are often fragmented across CI logs. This skill helps configure reviewdog to publish focused findings in pull requests and local hooks.
Scan Python Code with Bandit
Python security flaws can reach production unnoticed. This skill guides Bandit scans, prioritization, CI integration, and remediation with CWE and OWASP references.
Scan Code with Horusec
Security flaws and exposed secrets can cross language boundaries and reach production. This skill guides Horusec scans, result triage, and CI integration.