Explore skills

4,475 skills found

Category alert

Get new Segurança skills every Monday

threat-mitigation-mapping

2

Map identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control effectiveness.

Segurançaby bg-szy

web-security-testing

2

Web application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and access control issues.

Segurança#testby bg-szy

webapp-nikto

2

Web server vulnerability scanner for identifying security issues, misconfigurations, and outdated software versions. Use when: (1) Conducting authorized web server security assessments, (2) Identifying common web vulnerabilities and misconfigurations, (3) Detecting outdated server software and known vulnerabilities, (4) Performing compliance scans for web server hardening, (5) Enumerating web serv

Segurançaby bg-szy

when-auditing-security-use-security-analyzer

2

Comprehensive security auditing across static analysis, dynamic testing, dependency vulnerabilities, secrets detection, and OWASP compliance

Segurança#testby bg-szy

firebase-apk-scanner

2

Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. Use when analyzing APK files for Firebase vulnerabilities, performing mobile app security audits, or testing Firebase endpoint security. For authorized security research only.

Segurança#testby bg-szy

semgrep

2

Run Semgrep static analysis scan on a codebase using parallel subagents. Supports two scan modes — "run all" (full ruleset coverage) and "important only" (high-confidence security vulnerabilities). Automatically detects and uses Semgrep Pro for cross-file taint analysis when available. Use when asked to scan code for vulnerabilities, run a security audit with Semgrep, find bugs, or perform static

Segurança#aiby bg-szy

security-review

2

When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model", "security audit", "pen test prep".

Segurança#ai#testby Maudeunfledged834

pr-diff-review

2

Review an authorized pull request diff for security regressions. Use when changes modify trust boundaries, auth logic, data-access scope, file handling, logging, headers, or secrets.

Segurança#aiby MuhammedZohaib

zero-day

2

This skill involves hunting novel vulnerabilities using reversing, patch diffing, fuzzing, and attack surface analysis, including PoC development. It covers zero-day, variant analysis, exploit development, and CVEs, distinct from SAST security audits.

Segurança#ai#testby iuliandita

lockpick

2

Handles authorized privilege escalation, CTFs, and post-exploitation on Linux, containers, and K8s, with triggers including 'privesc', 'CTF', 'pentest', 'post-exploitation', 'container escape', 'SUID', and 'GTFOBins'. This skill is not for hardening; use security-audit for that.

Segurança#ai#testby iuliandita

gs-review

2

Pre-landing PR review - gstack staff-engineer code review army. CARL TRIGGERS: review the code, audit this branch, check this PR, find bugs, code review, review my changes. SOURCE: garrytan/gstack/review, integrated as gs-review on 2026-05-29.

Segurançaby YousefNabil-SOC

security-and-hardening

2

Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.

Segurança#aiby LLl0k0laD