Explore skills
4,475 skills found
Category alert
Get new Segurança skills every Monday
security-review
When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model", "security audit", "pen test prep".
hydra
This multi-perspective code review council involves advisors analyzing, reviewers cross-examining, and a chairman synthesizing a verdict. It is ideal for complex tasks like architecture decisions, security audits, and deep pre-merge reviews, but not for simple code generation or syntax fixes.
query-review
Review an authorized codebase for ORM misuse, N+1 query patterns, authorization-after-fetch bugs, raw SQL risks, cache key collisions, and missing tenant scopes. Use for data-access layers and security-adjacent performance pitfalls.
query-review
Review an authorized codebase for ORM misuse, N+1 query patterns, authorization-after-fetch bugs, raw SQL risks, cache key collisions, and missing tenant scopes. Use for data-access layers and security-adjacent performance pitfalls.
zero-day
This skill involves hunting novel vulnerabilities using reversing, patch diffing, fuzzing, and attack surface analysis, including PoC development. It covers zero-day, variant analysis, exploit development, and CVEs, distinct from SAST security audits.
security-audit
Audits code security, focusing on OWASP, credentials, authentication, access control, supply chain, and hardening. It's triggered by terms like 'security audit' or 'OWASP', and is not for offensive work (use lockpick).
lockpick
Handles authorized privilege escalation, CTFs, and post-exploitation on Linux, containers, and K8s, with triggers including 'privesc', 'CTF', 'pentest', 'post-exploitation', 'container escape', 'SUID', and 'GTFOBins'. This skill is not for hardening; use security-audit for that.
nsauditor-ai
Use this skill to perform network security scanning, auditing, vulnerability assessment, or host reconnaissance with NSAuditor AI.
quality-nonconformance
Codified expertise for quality control, non-conformance investigation, root cause analysis, corrective action, and supplier quality management in regulated manufacturing. Informed by quality engineers with 15+ years experience across FDA, IATF 16949, and AS9100 environments. Includes NCR lifecycle management, CAPA systems, SPC interpretation, and audit methodology. Use when investigating non-confo
business-logic-review
Review an authorized application for business-logic vulnerabilities, workflow abuse, approval bypasses, replay conditions, quota circumvention, plan enforcement bugs, and state-transition errors. Use for billing, invites, approvals, refunds, admin actions, and multi-step workflows.
security-audit
Conduct authorized defensive security audits of codebases and web applications. Use for broad appsec review across OWASP, authz, business logic, SSRF, XSS, CSRF, injection, file upload, secrets, logging, and tenant isolation. Produces structured findings with severity, confidence, evidence, and safe remediation guidance.
quick-triage
Perform a rapid defensive triage on an authorized code area when time is limited. Use to find the most plausible high-impact issues fast, then recommend the next best review target.