entry-point-analyzer
Map the attack surface of smart contract codebases by identifying and categorizing state-changing entry points.
Discover reusable agent skills, browse implementation details, and find the right skill for your workflow.
82 skills found
Map the attack surface of smart contract codebases by identifying and categorizing state-changing entry points.
Create, test, and validate custom Semgrep rules for security vulnerabilities and code pattern detection.
Systematic security assessment using STRIDE threat modeling, OWASP top 10 review, and secure coding practices for code, architecture, and infrastructure.
Security-first auditing framework for AI-generated code. Provides multi-level protection including hardcoded secret detection, dangerous pattern identification, and comprehensive vulnerability audits for modern web applications.
Scans Solana programs (native/Anchor) for 6 critical vulnerabilities, including arbitrary CPI, improper PDA validation, and missing ownership checks, providing detailed fix recommendations.
Run Semgrep static analysis scans on codebases using parallel subagents, multi-language detection, and Pro-enabled cross-file taint tracking.
Automated security auditing for project dependencies. Scans package files (npm, pip, maven, etc.) for vulnerabilities, CVEs, and license issues, offering automated fix suggestions and integration for secure deployment workflows.
Parses and processes SARIF files from static analysis tools. Enables aggregation, deduplication, filtering, and CI/CD integration of scan results.
Audit AI skills for security vulnerabilities including prompt injection, hidden instructions, tool misuse, and data exfiltration risks.
Expert code reviewer for Rust projects. Performs comprehensive quality, security, performance, and architectural analysis using Bazel and project-specific conventions.
Analyze Substrate/Polkadot runtimes and FRAME pallets for 7 critical vulnerabilities including arithmetic overflow, DoS, and improper origin checks.
A systematic code auditing framework for identifying technical debt, security vulnerabilities, dead code, and code quality issues in software projects.