Discover Agent Skills for security & testing. Browse 105 skills for Claude, ChatGPT & Codex.
Automates comprehensive security audits, vulnerability scanning, and secret detection for complex multi-service architectures.
Identifies authorization vulnerabilities and privilege escalation paths within your source code using the STRIDE threat modeling framework.
Systematically identifies, groups, and resolves failing tests to restore codebase stability and achieve a green test suite.
Implements secure handling, storage, and rotation of sensitive credentials across major CI/CD platforms and cloud providers.
Implements secure smart contract development patterns and identifies critical vulnerabilities in Solidity code to ensure robust blockchain applications.
Configures and automates Static Application Security Testing (SAST) tools for comprehensive vulnerability detection in application code.
Implements comprehensive Python testing strategies using pytest, fixtures, mocking, and test-driven development best practices.
Implements comprehensive smart contract testing suites using Hardhat and Foundry to ensure blockchain security and gas efficiency.
Systematically traces bugs through call stacks to identify and fix the original source of errors rather than just their symptoms.
Analyzes serverless applications for security vulnerabilities including overprivileged IAM policies, event injection, and insecure configuration.
Performs multi-dimensional codebase reviews using specialized AI agents to identify security, performance, and architectural issues.
Manages persistent security preferences, tool thresholds, and scan exclusions for integrated application security workflows.
Identifies security weaknesses and maps vulnerabilities to CWE identifiers using the PASTA threat modeling methodology.
Analyzes source code for detectability threats and timing side channels to prevent unauthorized inference of system interactions.
Enforces a strict Red-Green-Refactor workflow to ensure all production code is verified by failing tests first.
Analyzes source code to identify and mitigate linkability threats where user data can be correlated across services, sessions, or contexts.
Master the Bash Automated Testing System (Bats) to create robust, production-grade unit tests for shell scripts and CI/CD pipelines.
Performs comprehensive security audits, network reconnaissance, and vulnerability management directly from the command line using Shodan, OSV, and KEV integrations.
Automates end-to-end testing and UI debugging for local web applications using Playwright and managed server lifecycles.
Maps and inventories every application entry point to identify potential security exposure and undocumented interfaces.
Conducts exhaustive, multi-framework security audits and generates comprehensive, compliance-ready reports.
Teaches application security through interactive, guided walkthroughs using your own codebase as the primary teaching material.
Implements production-grade Kubernetes security policies including NetworkPolicy, RBAC, and Pod Security Standards to ensure cluster-wide defense-in-depth.
Audits application and infrastructure configurations to identify and remediate security vulnerabilities based on OWASP standards.
Analyzes WebSocket implementations for security vulnerabilities like CSWSH, missing authentication, and inadequate message validation.
Enforces a rigorous four-phase framework to identify root causes and eliminate guess-and-check thrashing during the software debugging process.
Analyzes application architecture to identify components, trust boundaries, and data sensitivity for formal threat modeling.
Implement robust testing strategies for JavaScript and TypeScript applications using modern frameworks like Jest and Vitest.
Audits source code for authentication vulnerabilities and session management failures to align with OWASP security standards.
Analyzes source code to identify and remediate identity spoofing vulnerabilities and authentication weaknesses based on the STRIDE threat model.
Scroll for more results...