toh-framework
Security-first auditing framework for AI-generated code. Provides multi-level protection including hardcoded secret detection, dangerous pattern identification, and comprehensive vulnerability audits for modern web applications.
Discover reusable agent skills, browse implementation details, and find the right skill for your workflow.
92 skills found
Security-first auditing framework for AI-generated code. Provides multi-level protection including hardcoded secret detection, dangerous pattern identification, and comprehensive vulnerability audits for modern web applications.
Systematic security assessment using STRIDE threat modeling, OWASP top 10 review, and secure coding practices for code, architecture, and infrastructure.
A comprehensive security auditing and hardening assistant that applies best practices for authentication, input validation, secrets management, and SQL injection prevention to your codebase.
Automated security validation, RLS enforcement, OWASP compliance, and vulnerability scanning for AI-assisted development workflows.
Automated security vulnerability scanner implementing OWASP Top 10 testing for SAST/DAST, dependency auditing, and auth/authorization validation in CI/CD pipelines.
Perform systematic security audits, vulnerability scanning, and risk assessments with OWASP-aligned methodology for robust code protection.
Spring Security best practices for Spring Boot: Auth, validation, CSRF protection, secret management, rate limiting, and dependency security.
Analyze source code for security vulnerabilities based on OWASP Top 10 guidelines and suggest remediation strategies.
Comprehensive secure coding guidelines for 15+ languages, covering OWASP Top 10, infrastructure security, and best practices to identify vulnerabilities in code, configurations, and cloud setups.
A specialized code review agent that performs multi-dimensional analysis covering security vulnerabilities, performance optimization, code quality, and maintainability standards.
Configure host-based firewalls (UFW, nftables, iptables) and cloud security groups (AWS, GCP, Azure) with production-ready security rules.
Monitor Runwall security posture, enabled guardrails, and recent audit logs for Claude Code, Codex, and MCP-based development environments.