Published skills
Showing 48 of 2099
vendor-security-questionnaire
Automated vendor security assessment through questionnaire generation, response parsing, and risk scoring.
semantic-code-analyzer
LLM-powered semantic analysis of code diffs to detect business-logic trojans.
vendor-risk-monitor
Continuous vendor security monitoring for security ratings, breach notifications, and risk change detection.
aiml-security
AI/ML model security testing and adversarial research capabilities, including generating adversarial examples, testing model robustness, performing extraction attacks, testing for data poisoning, analyzing model fairness, and supporting ART framework integration.
doxygen-javadoc
Documentation generation for C, C++, and Java codebases using Doxygen and Javadoc. Extracts API documentation from source code, generates cross-references, call graphs, and comprehensive technical documentation.
openapi-swagger
Expert skill for OpenAPI/Swagger specification analysis, validation, and documentation generation. Parse and validate specs, detect breaking changes, generate code samples, and lint for best practices.
sphinx-docs
Expertise in the Sphinx documentation system for technical and API documentation. Configures projects, autodoc for Python APIs, intersphinx for cross-project linking, extensions, and multiple output formats.
soc2-compliance-automator
SOC 2 Trust Services Criteria compliance automation for evidence collection, control mapping, and audit preparation
Ghidra/IDA Reverse Engineering Skill
Deep integration with Ghidra and IDA Pro for binary analysis and reverse engineering
Binary Exploitation Skill
Advanced binary exploitation and mitigation bypass
cloud-security-testing
Multi-cloud security assessment and penetration testing capabilities. Execute Prowler/ScoutSuite assessments, analyze IAM policies, identify cloud misconfigurations, test permissions, and enumerate cloud resources across AWS/GCP/Azure.
Debugger Integration Skill
Advanced debugging integration for vulnerability research
Burp Suite/Web Security Skill
Web application security testing with Burp Suite integration
Fuzzing Operations Skill
Comprehensive fuzzing operations with AFL++, libFuzzer, and OSS-Fuzz integration
security-sandbox
Isolated analysis environment management for malware and exploit testing. Create and manage isolated VMs, configure Cuckoo Sandbox, set up REMnux/FlareVM environments, manage Docker-based analysis containers, and capture filesystem and process changes.
Smart Contract Analysis Skill
Ethereum and blockchain smart contract security analysis
STIX/TAXII Intelligence Skill
STIX/TAXII threat intelligence format and sharing
markdown
Markdown documentation, MDX, and content formatting.
CVE/CWE Database Skill
CVE and CWE database querying and management
incident-forensics
Digital forensics and incident response capabilities. Analyze memory dumps with Volatility, parse filesystem artifacts, extract browser forensics, analyze Windows event logs, create forensic timelines, recover deleted files, and generate forensic reports.
Mobile Security Testing Skill
Android and iOS application security testing
Network Protocol Analysis Skill
Network protocol capture, analysis, and fuzzing capabilities
adr-generator
Specialized skill for generating and managing Architecture Decision Records (ADRs). Supports Nygard, MADR, and custom templates with auto-numbering, linking, and status management.
c4-diagram-generator
Specialized skill for generating C4 model architecture diagrams. Supports Structurizr DSL, PlantUML, and Mermaid formats with multi-level abstraction (Context, Container, Component, Code).
cloudformation-analyzer
Validate and analyze AWS CloudFormation templates for security and best practices
MITRE ATT&CK Skill
MITRE ATT&CK framework mapping and analysis
Offensive Security Skill
Offensive security tools and techniques integration
chaos-runner
Run chaos engineering experiments using Chaos Monkey, Litmus, or Gremlin
cloud-cost-estimator
Estimate cloud costs across AWS, Azure, and GCP with pricing comparison
db-query-analyzer
Analyze database query performance with execution plans and index recommendations
Pwntools Exploitation Skill
Exploit development automation using pwntools framework
Static Analysis Tools Skill
Integration with security-focused static analysis tools
api-mock-server
Generate and run mock API servers from OpenAPI specifications
code-complexity-analyzer
Analyze code complexity metrics including cyclomatic complexity, code smells, and technical debt
docs-site-generator
Generate documentation sites using Docusaurus, MkDocs, or VuePress
YARA Rules Skill
YARA rule creation, testing, and deployment
dashboard-generator
Generate monitoring dashboards for Grafana and DataDog with alert integration
graphviz-renderer
Render Graphviz DOT graphs to images with multiple layout algorithms
markdown-processor
Specialized skill for processing Markdown and MDX documentation. Supports parsing, rendering, TOC generation, link validation, frontmatter processing, and diagram embedding.
openapi-validator
Validate OpenAPI specifications for correctness, security, and best practices
analytics
Google Analytics 4, tag management, and event tracking.
compliance-checker
Check compliance with SOC 2, GDPR, HIPAA, and PCI-DSS standards
graphql-schema-generator
Generate GraphQL schemas from data models with resolver stubs and federation support
log-schema-generator
Generate structured logging schemas with correlation ID patterns and ELK/Splunk integration
mermaid-renderer
Render Mermaid diagrams to images with theme customization and Markdown integration
plantuml-renderer
Render PlantUML diagrams to various image formats with theme and styling support
dependency-graph-generator
Generate module dependency graphs with circular dependency detection and coupling metrics
load-test-generator
Generate load test scripts for k6, Locust, and Gatling from OpenAPI specs
Category alert