Explore skills
4,475 skills found
Category alert
Get new Segurança skills every Monday
security-audit
Use when you want a thorough security review of the codebase, a specific file/directory, or a set of changes before shipping.
cve-triage
Triage dependency vulnerabilities against CISA KEV, EPSS, reachability and compensating controls — turn a raw Dependabot/Snyk/osv-scanner dump into fix-now/sprint/quarter/accept decisions with rationale.
django-security
Django security review — CSRF, ORM-level SQL injection (raw/extra/annotate), template injection via |safe, admin hardening, middleware ordering, settings deploy checklist, and recent Django CVE patterns.
skillsync-mcp
SkillSync MCP provides security-gated skill management for Claude Code, OpenClaw, Cursor & Windsurf. It features a scanner with over 60 threat patterns.
cc-audit
Audits a project/codebase against Anthropic's published Claude Code engineering best practices for large codebases — CLAUDE.md hierarchy, .claude configuration, hooks, skills, plugins, MCP servers, LSP/code intelligence, subagent workflows, configuration maintenance cadence, and organizational governance — then produces a structured Markdown compliance report with per-item status, concrete evidenc
skill-distill
Audits installed skills and tools, classifying what to keep or remove, extracting their essence, and simplifying them. This skill acts as an internal "repo-analyst" to optimize and clean up your system's capabilities.
code-review
Code review combining language strictness rules, security auditing, and performance analysis. Use when a user says /code-review or asks to review a branch, PR, or set of changes. Auto-detects languages and applies the relevant rule sets from typescript-strict, rust-strict, swift-strict, go-strict, javascript-strict, security-audit-standard, performance-audit-standard, and github-standards.
skill-audit
Pre-install security audit for third-party AI agent skills. Detects malicious patterns, social engineering, and permission overreach in SKILL.md files before installation.
self-audit
A meta-gate that audits the current session's actions for philosophy, scope, convention, and token-budget violations before any commit. It's read-only, emits a single inline table verdict, and is used as the final step in multi-edit or multi-cycle tasks.
audit-plugin-l5
Triggers the L5 Red Team Sub-Agent to rigorously audit a plugin against the 39-point L4 pattern matrix.
github-management
Use when Codex needs to manage GitHub repositories via gh CLI or GitHub APIs. This includes tasks like handling issues, pull requests, CI, releases, branch protection, security audits, and repository governance.
ck:code-review
Review code quality with adversarial rigor. Supports input modes: pending changes, PR number, commit hash, codebase scan. Always-on red-team analysis finds security holes, false assumptions, and failure modes.