Explore skills
4,475 skills found
Category alert
Get new Segurança skills every Monday
android-architecture
Architecture assessment for Android projects. Evaluates Jetpack Compose adoption, UDF pattern (ViewModel + StateFlow), dependency injection, type-safe navigation, repository pattern, and module structure. Triggers on: "architecture", "compose adoption", "module structure", "dependency injection".
android-accessibility
Accessibility preflight for Android projects. Uses static source evidence to flag likely issues in semantics, labels, and touch-target setup while clearly separating low-confidence heuristics from verified findings.
slowmist-security-cc
SlowMist AI Agent Security Review — a comprehensive security framework for skills, repositories, URLs, on-chain addresses, and products (Claude Code version).
anti-fraud
Multi-layered anti-fraud and bot detection system for registration flows. It's used for securing registration forms, detecting bots, analyzing user behavior, and implementing various fraud prevention techniques like risk scoring and disposable email detection.
api-review
Review an authorized API surface for access control, mass assignment, schema validation, rate limiting, SSRF, error leakage, webhook verification, and unsafe defaults. Use for REST, GraphQL, RPC, and webhook handlers.
pr-diff-review
Review an authorized pull request diff for security regressions. Use when changes modify trust boundaries, auth logic, data-access scope, file handling, logging, headers, or secrets.
query-review
Review an authorized codebase for ORM misuse, N+1 query patterns, authorization-after-fetch bugs, raw SQL risks, cache key collisions, and missing tenant scopes. Use for data-access layers and security-adjacent performance pitfalls.
query-review
Review an authorized codebase for ORM misuse, N+1 query patterns, authorization-after-fetch bugs, raw SQL risks, cache key collisions, and missing tenant scopes. Use for data-access layers and security-adjacent performance pitfalls.
api-review
Review an authorized API surface for access control, mass assignment, schema validation, rate limiting, SSRF, error leakage, webhook verification, and unsafe defaults. Use for REST, GraphQL, RPC, and webhook handlers.
quick-triage
Perform a rapid defensive triage on an authorized code area when time is limited. Use to find the most plausible high-impact issues fast, then recommend the next best review target.
pr-diff-review
Review an authorized pull request diff for security regressions. Use when changes modify trust boundaries, auth logic, data-access scope, file handling, logging, headers, or secrets.
quick-triage
Perform a rapid defensive triage on an authorized code area when time is limited. Use to find the most plausible high-impact issues fast, then recommend the next best review target.