sast-semgrep
High Risk 38Audit Code with Semgrep
Security flaws can remain hidden across large, multilingual repositories. This skill guides focused Semgrep scans, triage, custom rules, CI gates, and standards-aligned remediation.
Unified search
Start with the task. Skillstore will show complete packs first, then individual skills when they are a better match.
Showing results for "security"
Use these when you need one narrow capability instead of a whole pack.
Audit Code with Semgrep
Security flaws can remain hidden across large, multilingual repositories. This skill guides focused Semgrep scans, triage, custom rules, CI gates, and standards-aligned remediation.
Assess Dependencies with Black Duck
Dependency vulnerabilities and license risks can reach production unnoticed. This skill guides Black Duck scans, policy gates, SBOM creation, and remediation triage.
Build Security Operations Skills
Security skill authors need consistent workflows, references, and validation patterns. This template provides reusable structures for security guidance, rules, and CI scanning.
Scan Web Servers with Nikto
Web teams need a repeatable way to identify server weaknesses before attackers find them. This skill guides authorized Nikto scans and structured remediation reporting.
Build Secure Claude Code Hooks
Claude Code hooks are easy to misconfigure or expose to unsafe input. This skill provides practical patterns for hook structure, validation, testing, and PRPM publishing.
Manage Microsoft 365 Tenant Tasks
Microsoft 365 tenant administration requires careful planning, repeatable scripts, and security review. This skill creates setup plans, checklists, and PowerShell drafts for tenant, user, license, and security workflows.
Build AMap JSAPI Web Maps
AMap integrations require coordinated setup, security configuration, overlays, events, and service APIs. This skill provides focused guidance and examples for JSAPI v2.0 web projects.
Containerize Applications for Docker and Kubernetes
Container configuration is easy to misalign across local and production environments. This skill creates Dockerfiles, Compose setups, Helm structures, and security checks.
Deploy Applications to Cloud Kubernetes
Production Kubernetes deployments often fail because images, variables, pipelines, and clusters use incompatible settings. This skill provides practical deployment, GitOps, security, observability, and troubleshooting guidance.
Deploy Secure Docker and Kubernetes Workloads
Teams need repeatable container and Kubernetes patterns that reduce production security risk. This skill helps Claude, Codex, and Claude Code generate hardened Dockerfiles, manifests, GitOps examples, and observability guidance.
Audit Neovim Configurations with Confidence
Neovim configurations can hide deprecated APIs, security issues, and startup bottlenecks. This skill provides structured checks, version guidance, and practical recommendations.
Analyze Android APKs with Apktool
Android APK internals are difficult to inspect in packaged form. This skill guides decoding, resource review, smali analysis, rebuilding, signing, and troubleshooting with Apktool.