home/categories/testing-security
domain cluster

Testing & Security

QA, penetration testing, and code quality.

9326 اسکلزall categories
sorting
stars
current ordering strategy
query
all entries
refine the visible subset
security
0

rbac-validator

Validates role-based access control (RBAC) implementation for four-tier permissions in the NABIP AMS (Member, Chapter Admin, State Admin, National Admin). Use when implementing permission checks, RLS policies, UI access controls, or audit logging for multi-tenant association management.

markus41
markus41
testing-security
open
security
0

review-trufflehog

Review and triage Trufflehog secret detection scan results to identify real credential exposures. Use when analyzing trufflehog output, triaging secret findings, reviewing credential leaks, or when the user has trufflehog results to review. Can also run scans for an organization. Filters out test/demo secrets and prioritizes verified findings with source code context analysis.

chrismcmacken
chrismcmacken
testing-security
open
security
0

idor-vulnerability-testing

This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references," or "bypass authorization to access other users' data." It provides comprehensive guidance for detecting, exploiting, and remediating IDOR vulnerabilities in web applications.

MAF2414
MAF2414
testing-security
open
security
0

security

Security Engineer and application security expert. Performs threat modeling, security architecture review, penetration testing, vulnerability assessment, and security compliance. Handles OWASP Top 10, authentication security, authorization, encryption, secrets management, HTTPS/TLS, CORS, CSRF, XSS, SQL injection prevention, secure coding practices, security audits, and compliance (GDPR, HIPAA, PCI-DSS, SOC 2). Activates for security, security review, threat model, vulnerability, penetration testing, pen test, OWASP, authentication security, authorization, encryption, secrets, HTTPS, TLS, SSL, CORS, CSRF, XSS, SQL injection, secure coding, security audit, compliance, GDPR, HIPAA, PCI-DSS, SOC 2, security architecture, secrets management, rate limiting, brute force protection, session security, token security, JWT security, is this secure, security check, review security, find vulnerabilities, security scan, security test, hack proof, prevent hacking, protect from attacks, DDoS protection, bot protection, WAF,

angeldev96
angeldev96
testing-security
open
security
0

generate-policy

Generates a Laravel Policy class for authorization logic. Use when adding permission checks for a model or resource (e.g., "Create a policy for the Course model").

hieupvXmasEve
hieupvXmasEve
testing-security
open
security
0

supabase-auth

Implements Supabase Authentication with email, OAuth, magic links, and phone auth. Use when building apps with Supabase, needing auth integrated with Row Level Security, or implementing passwordless login.

mgd34msu
mgd34msu
testing-security
open
security
0

security-hardening

Review code for application-level security hardening issues beyond framework checklists. Focuses on abuse prevention, API protection, business logic exploitation, rate limiting, input validation, and early request rejection. Use when auditing code for security, reviewing endpoints for abuse potential, or checking application resilience to real-world attacks.

colinmollenhour
colinmollenhour
testing-security
open
security
0

authz-bypass-hunter

Hunt for authorization bypass vulnerabilities including IDOR, privilege escalation, missing access controls, broken object-level authorization. Use when auditing authentication/authorization code or API endpoints.

MAF2414
MAF2414
testing-security
open
security
0

auth-patterns

Authentication security patterns and standards for NextAuth.js v5. Use when implementing or reviewing authentication code.

RPvars
RPvars
testing-security
open
security
0

permissions

Guide for working with team-based permissions and authorization in the WODsmith codebase. Use when touching TEAM_PERMISSIONS constants, hasTeamPermission/requireTeamPermission functions, adding permission checks to actions or server functions, creating features requiring authorization, or ensuring client-server permission consistency.

wodsmith
wodsmith
testing-security
open
security
0

security-observation

セキュリティ観測。認可漏れ、インジェクション、機密漏えい、暗号誤用、依存脆弱性を検出。Use when: 認証/認可実装、外部入力処理、依存更新、コミット前チェック、セキュリティレビューして、脅威分析が必要な時。

CAPHTECH
CAPHTECH
testing-security
open
security
0

hashing-passwords

CRITICAL security skill teaching proper credential and password handling. NEVER store passwords, use bcrypt/argon2, NEVER accept third-party credentials. Use when handling authentication, passwords, API keys, or any sensitive credentials.

djankies
djankies
testing-security
open
security
0

authentication-management

Manages authentication flow for MutuaPIX (Laravel Sanctum + Next.js), handles mock mode security, and validates environment configurations

Lucasdoreac
Lucasdoreac
testing-security
open
security
0

fastapi-jwt-auth

This skill should be used when implementing secure, reusable JWT verification dependency for FastAPI routes. It ensures strict user isolation and identity verification using Better Auth secrets.

SyedaNabila559
SyedaNabila559
testing-security
open
security
0

global-validation

Implement comprehensive input validation with server-side validation (security), client-side validation (UX), fail-early patterns (KISS), specific error messages, allowlists over blocklists, and reusable validators (DRY). Use this skill when validating user input in forms, API endpoints, or data processing functions. Use when implementing validation rules for data types, formats, ranges, required fields, or business rules (SRP). Use when creating validator functions, validation schemas (Zod, Joi, Yup), form validation logic, or input sanitization to prevent injection attacks (SQL, XSS). Use when working with backend validators, frontend form libraries (React Hook Form, Formik), or consistent validation across web forms, API endpoints, and background jobs. Apply validation at multiple layers for defense in depth.

maksimtereshin
maksimtereshin
testing-security
open
security
0

approval-checker

Verifies that an authorized user has approved the fix plan before proceeding with implementation.

JuniYadi
JuniYadi
testing-security
open
security
0

openrouter-config-validator

Configuration validation and testing utilities for OpenRouter API. Use when validating API keys, testing model availability, checking routing configuration, troubleshooting connection issues, analyzing usage costs, or when user mentions OpenRouter validation, config testing, API troubleshooting, model availability, or cost analysis.

vanman2024
vanman2024
testing-security
open
security
0

security

Implements security features following OWASP guidelines. Use when validating input, preventing XSS, adding rate limiting, verifying auth, or handling file uploads. Includes security-utils, sanitize-utils, and rate-limiter patterns.

jhlee0409
jhlee0409
testing-security
open
security
0

protection-audit

Audit protected files, generate protection reports, and verify protection consistency. Use for protection system maintenance and compliance.

AEtherlight-ai
AEtherlight-ai
testing-security
open
security
0

pal-secaudit

Comprehensive security audit with OWASP Top 10 analysis, compliance evaluation, and threat modeling using PAL MCP. Use for security reviews, vulnerability assessment, or compliance checks. Triggers on security audit requests, vulnerability scanning, or compliance reviews.

estiens
estiens
testing-security
open
securitymarketplace
0

verification-mode

Verification mode that stops and analyzes on failures, workarounds, or resolution issues

cuioss
cuioss
testing-security
open
security
0

global-validation

Apply input validation best practices including server-side validation, early failure, specific error messages, and input sanitization. Use this skill when validating user input in n8n nodes, implementing parameter validation, checking data types and formats, sanitizing input to prevent injection attacks, or writing business rule validation. Apply when handling API endpoints, form inputs, or any data entry points in n8n node development.

dpietersz
dpietersz
testing-security
open
security
0

security-audit

Security review checklist and patterns

buildworksai
buildworksai
testing-security
open
Previous
Page 343 / 389
Next