cargo-fuzz
cargo-fuzz is the de facto fuzzer for Rust, enabling automated vulnerability discovery in Cargo projects via the libFuzzer backend and integrated sanitizer support.
Looking for security engineer workflows? These agent skills help developers automate setup, coding, and delivery tasks.
Discover reusable agent skills, browse implementation details, and find the right skill for your workflow.
31 skills found
cargo-fuzz is the de facto fuzzer for Rust, enabling automated vulnerability discovery in Cargo projects via the libFuzzer backend and integrated sanitizer support.
Atheris is a coverage-guided Python fuzzer based on libFuzzer for testing pure Python code and Python C extensions.
Advanced Python security vulnerability scanner for Flask, Django, and FastAPI projects. Audits OWASP Top 10, dependencies, hardcoded secrets, and framework-specific flaws.
Monitor Runwall security posture, enabled guardrails, and recent audit logs for Claude Code, Codex, and MCP-based development environments.
Performs end-to-end OT/ICS threat modeling using Microsoft TMT exports and model files, mapping threats to MITRE ATT&CK for ICS, CWE, and CVSS v4.0 with automated risk-based prioritization.
Analyze source code for security vulnerabilities based on OWASP Top 10 guidelines and suggest remediation strategies.
Debug the AWF (Agentic Workflow Firewall) by inspecting containers, analyzing Squid logs, checking iptables, and troubleshooting network or domain access issues in isolated sandboxes.
A systematic code auditing framework for identifying technical debt, security vulnerabilities, dead code, and code quality issues in software projects.
Automated security skill for identifying and validating XSS vulnerabilities, including Reflected, Stored, and DOM-based attacks across various contexts.
An expert-level CTF solver agent that automates reconnaissance, vulnerability analysis, and exploit generation for web, pwn, crypto, reverse, and forensic challenges.
Spring Security best practices for Spring Boot: Auth, validation, CSRF protection, secret management, rate limiting, and dependency security.
Automated detection of IDOR vulnerabilities using a three-phase subagent workflow to verify authorization and ownership checks on sensitive endpoints.