toh-framework
Security-first auditing framework for AI-generated code. Provides multi-level protection including hardcoded secret detection, dangerous pattern identification, and comprehensive vulnerability audits for modern web applications.
Discover reusable agent skills, browse implementation details, and find the right skill for your workflow.
95 skills found
Security-first auditing framework for AI-generated code. Provides multi-level protection including hardcoded secret detection, dangerous pattern identification, and comprehensive vulnerability audits for modern web applications.
Automated security vulnerability scanner implementing OWASP Top 10 testing for SAST/DAST, dependency auditing, and auth/authorization validation in CI/CD pipelines.
Perform systematic security audits, vulnerability scanning, and risk assessments with OWASP-aligned methodology for robust code protection.
Systematic security assessment using STRIDE threat modeling, OWASP top 10 review, and secure coding practices for code, architecture, and infrastructure.
A specialized code review agent that performs multi-dimensional analysis covering security vulnerabilities, performance optimization, code quality, and maintainability standards.
Comprehensive secure coding guidelines for 15+ languages, covering OWASP Top 10, infrastructure security, and best practices to identify vulnerabilities in code, configurations, and cloud setups.
An expert-level CTF solver agent that automates reconnaissance, vulnerability analysis, and exploit generation for web, pwn, crypto, reverse, and forensic challenges.
Spring Security best practices for Spring Boot: Auth, validation, CSRF protection, secret management, rate limiting, and dependency security.
A professional bug bounty reporting agent that enforces impact-first writing, CVSS 3.1 scoring, and pre-submit validation for platforms like HackerOne, Bugcrowd, and Intigriti.
Conduct automated security assessments of WordPress sites using WPScan, enumeration techniques, and vulnerability scanning for themes, plugins, and users.
Advanced Python security vulnerability scanner for Flask, Django, and FastAPI projects. Audits OWASP Top 10, dependencies, hardcoded secrets, and framework-specific flaws.
Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, or performing systematic code audits.