audit-skills
Audit AI skills for security vulnerabilities including prompt injection, hidden instructions, tool misuse, and data exfiltration risks.
Discover reusable agent skills, browse implementation details, and find the right skill for your workflow.
79 skills found
Audit AI skills for security vulnerabilities including prompt injection, hidden instructions, tool misuse, and data exfiltration risks.
Analyze source code for security vulnerabilities based on OWASP Top 10 guidelines and suggest remediation strategies.
Detects indirect prompt injection and goal hijacking in AI agents by evaluating how they process external content like RAG, documents, and web data.
A suite of professional tools for auditing, evaluating, chunking, and scaffolding production-ready RAG pipelines within Claude Code.
Automated security auditing for Flutter applications based on OWASP Mobile Top 10 (2024). Perform vulnerability scans for hardcoded secrets, insecure storage, dependency risks, and network configuration issues.
Generate Software Bill of Materials (SBOM) for container images and filesystems using Syft. Supports 28+ ecosystems, multiple formats like CycloneDX and SPDX, and integration into CI/CD for supply chain security.
Comprehensive secure coding guidelines for 15+ languages, covering OWASP Top 10, infrastructure security, and best practices to identify vulnerabilities in code, configurations, and cloud setups.
Parses and processes SARIF files from static analysis tools. Enables aggregation, deduplication, filtering, and CI/CD integration of scan results.
An expert-level CTF solver agent that automates reconnaissance, vulnerability analysis, and exploit generation for web, pwn, crypto, reverse, and forensic challenges.
AI-powered secrets and credentials scanner. Detects hardcoded API keys, passwords, and sensitive data in your codebase with contextual analysis to reduce false positives.
Performs end-to-end OT/ICS threat modeling using Microsoft TMT exports and model files, mapping threats to MITRE ATT&CK for ICS, CWE, and CVSS v4.0 with automated risk-based prioritization.
Perform deep security analysis on codebases using CodeQL for interprocedural data flow, taint tracking, and automated vulnerability detection across multiple languages.