home/categories/security
category focus

Security

Encryption, auth, and vulnerability scanning.

2506 مهارةall categories
sorting
stars
current ordering strategy
query
all entries
refine the visible subset
security
44

troubleshooting-authentication

Provides authentication troubleshooting for MSAL, JWT, and Entra ID. Use when debugging 401 errors, token issues, MSAL configuration problems, or credential failures in this repository.

microsoft-foundry
microsoft-foundry
testing-security
open
security
44

ln-621-security-auditor

Security audit worker (L3). Scans codebase for hardcoded secrets, SQL injection, XSS, insecure dependencies, missing input validation. Returns findings with severity (Critical/High/Medium/Low), location, effort, and recommendations.

levnikolaevich
levnikolaevich
testing-security
open
security
38

api-rate-limiting

Implement API rate limiting strategies using token bucket, sliding window, and fixed window algorithms. Use when protecting APIs from abuse, managing traffic, or implementing tiered rate limits.

aj-geddes
aj-geddes
testing-security
open
security
38

security-testing

Identify security vulnerabilities through SAST, DAST, penetration testing, and dependency scanning. Use for security test, vulnerability scanning, OWASP, SQL injection, XSS, CSRF, and penetration testing.

aj-geddes
aj-geddes
testing-security
open
security
38

csrf-protection

Implement Cross-Site Request Forgery (CSRF) protection using tokens, SameSite cookies, and origin validation. Use when building forms and state-changing operations.

aj-geddes
aj-geddes
testing-security
open
security
38

security-compliance-audit

Conduct comprehensive security compliance audits for SOC 2, GDPR, HIPAA, PCI-DSS, and ISO 27001. Use when preparing for certification, annual audits, or compliance validation.

aj-geddes
aj-geddes
testing-security
open
security
38

zero-trust-architecture

Implement Zero Trust security model with identity verification, microsegmentation, least privilege access, and continuous monitoring. Use when building secure cloud-native applications.

aj-geddes
aj-geddes
testing-security
open
security
38

security-headers-configuration

Configure HTTP security headers including CSP, HSTS, X-Frame-Options, and XSS protection. Use when hardening web applications against common attacks.

aj-geddes
aj-geddes
testing-security
open
security
38

oauth-implementation

Implement secure OAuth 2.0, OpenID Connect (OIDC), JWT authentication, and SSO integration. Use when building secure authentication systems for web and mobile applications.

aj-geddes
aj-geddes
testing-security
open
security
38

session-management

Implement secure session management systems with JWT tokens, session storage, token refresh, logout handling, and CSRF protection. Use when managing user authentication state, handling token lifecycle, and securing sessions.

aj-geddes
aj-geddes
testing-security
open
security
38

vulnerability-scanning

Automated vulnerability detection using OWASP tools, CVE databases, and security scanners. Use when performing security audits, compliance checks, or continuous security monitoring.

aj-geddes
aj-geddes
testing-security
open
security
37

mapbox-token-security

Security best practices for Mapbox access tokens, including scope management, URL restrictions, rotation strategies, and protecting sensitive data. Use when creating, managing, or advising on Mapbox token security.

mapbox
mapbox
testing-security
open
security
37

python-security-scan

Comprehensive security vulnerability scanner for Python projects including Flask, Django, and FastAPI applications. Detects OWASP Top 10 vulnerabilities, injection flaws, insecure deserialization, authentication issues, hardcoded secrets, and framework-specific security problems. Audits dependencies for known CVEs and generates actionable security reports.

sugarforever
sugarforever
testing-security
open
security
35

pact-security-patterns

Security best practices and threat mitigation patterns for PACT framework development. Use when: implementing authentication or authorization, handling API credentials, integrating external APIs, processing sensitive data (PII, financial, health), reviewing code for vulnerabilities, or enforcing SACROSANCT security rules. Triggers on: security audit, credential handling, OWASP, auth flows, encryption, data protection, backend proxy pattern, frontend credential exposure.

ProfSynapse
ProfSynapse
testing-security
open
security
35

standard-security-auth

Security & Authentication Specialist - Expert in JWT, cookie-based auth, MFA, and generic security patterns

salavender
salavender
testing-security
open
security
33

create-auth-skill

A skill to create auth service for new applications.

kriegcloud
kriegcloud
testing-security
open
security
33

security-testing

Test for security vulnerabilities using OWASP principles and security testing techniques. Use when conducting security audits, testing authentication/authorization, or implementing security practices.

proffesor-for-testing
proffesor-for-testing
testing-security
open
security
32

secrets-and-logging-hygiene

Workflow for preventing secret leaks and sensitive logging (PII/credentials) and adding redaction defaults.

Robotti-io
Robotti-io
testing-security
open
security
32

input-validation-hardening

Process for tightening input validation, canonicalization, and safe parsing to prevent injection and logic abuse.

Robotti-io
Robotti-io
testing-security
open
Previous
Page 58 / 105
Next