home/categories/testing-security
domain cluster

Testing & Security

QA, penetration testing, and code quality.

9326 اسکلزall categories
sorting
stars
current ordering strategy
query
all entries
refine the visible subset
security
0

system-security

This skill should be used when implementing authentication, authorization, API security, or securing systems. It provides guidance on authentication methods (JWT, OAuth 2.0), authorization models (RBAC, ABAC, ACL), and API security techniques (rate limiting, CORS, injection prevention).

thependalorian
thependalorian
testing-security
open
security
0

moai-core-env-security

Environment variable security, secrets management, and secure credential handling for MoAI-ADK projects

jg-chalk-io
jg-chalk-io
testing-security
open
security
0

security-scanner

Comprehensive security scanning for SAST, secrets, OWASP vulnerabilities, container and IaC security

nikhillinit
nikhillinit
testing-security
open
security
0

using-loaded-knowledge

MANDATORY protocol enforcing knowledge check before EVERY response - prevents explaining systems without reading docs, claiming without verification, and ignoring auto-loaded context

adilkalam
adilkalam
testing-security
open
security
0

security-audit-checklist

Provides exhaustive security vulnerability checklists with severity classifications, point deductions, and detection commands. Use when performing security audits, code reviews, penetration testing preparation, or checking OWASP compliance.

mgd34msu
mgd34msu
testing-security
open
security
0

token-usage

Sprawdzenie zużycia tokenów/kontekstu w sesji. Triggers: token usage, ile tokenów, ile zostało

kmylpenter
kmylpenter
testing-security
open
security
0

security-scanning

Security scanning tools (gosec, govulncheck). Use when running security analysis.

IvanTorresEdge
IvanTorresEdge
testing-security
open
security
0

log-entity-actions

Security pattern for implementing security logging and audit trails. Use when designing logging systems for security events, implementing non-repudiation, creating audit trails, or addressing security monitoring and incident response needs. Addresses "Entity repudiates action request" problem.

igbuend
igbuend
testing-security
open
security
0

injection-hunter

Hunt for injection vulnerabilities including SQL injection, command injection, XSS, SSTI, path traversal, LDAP injection, and other input validation flaws. Use when auditing code that processes user input.

MAF2414
MAF2414
testing-security
open
security
0

random-hash

Generate salted hash URLs with QR codes displayed in terminal. Use when user wants to create a unique URL with a random salt appended to an identifier, or needs a QR code linking to a user profile page. Triggers on /random-hash commands.

erikdrouhard
erikdrouhard
testing-security
open
security
0

dos-resource-exhaustion

Find denial of service vulnerabilities through resource exhaustion, algorithmic complexity, memory exhaustion, and file/network resource abuse. Use when auditing code for availability issues.

MAF2414
MAF2414
testing-security
open
security
0

secure

Find and fix security issues before they become incidents. Vulnerability scanning, SBOM generation, supply chain security, and secure authentication workflows.

adaptive-enforcement-lab
adaptive-enforcement-lab
testing-security
open
securitymarketplace
0

quantum-signing

Use when implementing quantum-resistant cryptographic signing. Triggers: "quantum signing", "ML-DSA", "post-quantum", "operation signing", "quantum-resistant". NOT for: Standard encryption or non-cryptographic integrity checks.

pagerguild
pagerguild
testing-security
open
security
0

iam-migration-validation

Automated post-migration validation for iam-migration (ETBC to IAM). Use when designing or executing verification that legacy ETBC users can log in to the portal, permissions are consistent, and app/menu mappings are correct across iam-management-service, iam-auth-center-service, APISIX, and portal-front.

LLLLimbo
LLLLimbo
testing-security
open
security
0

macos-security

macOSアプリのセキュリティレビュー。Notarization、Hardened Runtime、Sandbox、コード署名をチェック。Use when: macOS、公証、Notarization、Sandbox、署名 を依頼された時。

miyakawa2449
miyakawa2449
testing-security
open
security
0

security

Security and data protection guidelines for RawDrive. Use when implementing authentication, handling user data, validating inputs, or reviewing security-sensitive code.

veerababumanyam
veerababumanyam
testing-security
open
security
0

security-auth

Authentication and security patterns for EFT-Tracker using NextAuth. Covers password reset, session management, CSRF protection, and security reviews. Activates when user mentions: auth, authentication, password, NextAuth, session, security, login, logout, CSRF, rate limit, token, JWT.

tuckerandrew21
tuckerandrew21
testing-security
open
security
0

rpt-permissions

Configure RPT token exchange and permission-based authorization for affolterNET.Web.Bff. Use when setting up Keycloak permissions, resource policies, or fine-grained access control.

Mcafee123
Mcafee123
testing-security
open
security
0

1password

Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.

HarleyCoops
HarleyCoops
testing-security
open
security
0

authentication

Authentication patterns for JWT, sessions, OAuth, MFA, and secure auth flows. Trigger: When implementing authentication, when setting up JWT tokens, when building login flows, when integrating OAuth providers, when implementing password reset, when adding MFA.

Dsantiagomj
Dsantiagomj
testing-security
open
security
0

wa-security-review

Conduct a focused security audit based on the Well-Architected Framework Security pillar. Use when user says "security review", "wa security", or "security audit". Analyzes authentication, authorization, data protection, input validation, and secrets management.

brendankowitz
brendankowitz
testing-security
open
security
0

security-stance-analyzer

Analyzes the security posture of systems, codebases, and infrastructure. Examines authentication, authorization, data protection, network security, dependency vulnerabilities, secrets management, and compliance. Use when assessing security risks, performing security audits, or evaluating defensive measures.

gurdiga
gurdiga
testing-security
open
security
0

keycloak-administration

Provides comprehensive KeyCloak administration guidance including realm management, user/group administration, client configuration, authentication flows, identity brokering, authorization policies, security hardening, and troubleshooting. Covers SSO configuration, SAML/OIDC setup, role-based access control (RBAC), user federation (LDAP/AD), social login integration, multi-factor authentication (MFA), and high availability deployments. Use when configuring KeyCloak, setting up SSO, managing realms and clients, troubleshooting authentication issues, implementing RBAC, or when users mention "KeyCloak", "SSO", "OIDC", "SAML", "identity provider", "IAM", "authentication flow", "user federation", "realm configuration", or "access management".

DauQuangThanh
DauQuangThanh
testing-security
open
security
0

draconian-rls-audit

Default-Deny security posture for Supabase. Mandates strict RLS and 'WITH CHECK' clauses.

cityfish91159
cityfish91159
testing-security
open
Previous
Page 334 / 389
Next