Showing 30 of 22820 results
Runs code reviews using external LLM CLIs (OpenAI Codex, Google Gemini) on uncommitted changes, branch diffs, or specific commits. Bundles codex-mcp-server for direct MCP tool access to Codex.
Pre-commit secret gate: a PreToolUse hook scans staged changes and blocks commits carrying secrets, plus a semantic review subagent. Zero config.
Secrets lifecycle with masking: set, get, list, rotate, delete, validate, run-with-secrets, and a web UI (/secrets:*). Bundles the PostToolUse output-masking hook so plugin installs mask credentials with no host script setup.
Inject and audit 1Password secrets via the op CLI: op:// references with op run/op inject, an always-ask permission gate, and an opt-in deny-capable PreToolUse audit hook. Use for API keys, tokens, credentials, .env secrets, OP_SERVICE_ACCOUNT_TOKEN, or 1Password.
Secure Boot certificate-rotation suite — triage and remediate the Microsoft Secure Boot 2011→2023 UEFI CA rotation (CAs expiring 2026) across Dell PowerEdge / iDRAC9 bare metal, Ubuntu/Linux servers, and Harvester HCI / KubeVirt guest VMs: the PK→KEK→db trust chain, per-platform fixes (iDRAC BIOS-staged keys applied on reboot, self-authenticating manual `db` append via the existing 2011 KEK, the Harvester OVMF v1.6.0 floor with ephemeral-vs-persistent NVRAM triage), and audit via mokutil / efi-readvar / racadm bioscert / Redfish.
Security hardening skills for GitHub Actions pipeline hardening and CI security.
Two complementary JavaScript/TypeScript web security skills: web-security-review traces data flow and reports only proven vulnerabilities; web-security-hardening performs an applicability-aware OWASP ASVS 5.0.0 gap assessment across browser controls, input/files, identity/sessions/secrets, frameworks, storage, and deployment.
Security scanning: quick/full/deep scans (gitleaks, git history, pip-audit), finding explanations, and risk-graded permission audits (/security:*).
Two complementary JavaScript/TypeScript web security skills: web-security-review traces data flow and reports only proven vulnerabilities; web-security-hardening performs an applicability-aware OWASP ASVS 5.0.0 gap assessment across browser controls, input/files, identity/sessions/secrets, frameworks, storage, and deployment.
The pre-release security gate for any repository. Catches PII, secrets/credentials, and supply-chain risk before they ship. Runs parallel, multi-agent audits across data files, git history, source, and frontend, and consolidates them into a single severity-ranked report with a PASS / REVIEW / BLOCK verdict. Stands alone, or serves as foundry's SECURITY gate when both are installed.
Security reviewer for AI-generated and vibe-coded apps — hunts the hardcoded secrets, broken row-level security, and prompt-injection sinks that coding assistants ship by default, then drives a scan, fix, and rescan loop with honest, CWE-mapped findings.
面向 AI 生成与 vibe coding 应用的安全审查专家——专抓编码助手默认会带上的硬编码密钥、失效的行级安全(RLS)和提示注入注入点,然后驱动"扫描—修复—复扫"闭环,输出诚实、映射到 CWE 的发现。
AppSec specialist who secures the software development lifecycle through threat modeling, secure code review, SAST/DAST integration, and developer security education that makes secure code the default.
AppSec 专家,通过威胁建模、安全代码审查、SAST/DAST 集成以及让安全代码成为默认的开发者安全教育,为软件开发生命周期保驾护航。
Expert security architect specializing in threat modeling, secure-by-design architecture, trust-boundary analysis, defense-in-depth, and risk-based security reviews across web, API, cloud-native, and distributed systems. Designs the security model; hands code-level SAST/DAST and SDLC work to the AppSec Engineer.
专家级安全架构师,专精威胁建模、安全内建(secure-by-design)架构、信任边界分析、纵深防御,以及横跨 Web、API、云原生和分布式系统的基于风险的安全评审。负责设计安全模型;代码级的 SAST/DAST 与 SDLC 工作交给 AppSec 工程师。
Auditoría de seguridad completa de un proyecto, en modo solo lectura. Genera un informe claro en español ordenado por gravedad, sin modificar el código.
Audit de sécurité — secret scanning, CVE deps, contrôle d'anonymisation, analyse de patterns.
Security frameworks, accessibility guidelines, performance optimization, and code quality best practices for building secure, maintainable, and high-performance applications.
Expert smart contract security auditor specializing in vulnerability detection, formal verification, exploit analysis, and comprehensive audit report writing for DeFi protocols and blockchain applications.
智能合约审计与漏洞分析专家
Cloud-native security specialist designing zero trust architectures, implementing defense-in-depth across AWS, Azure, and GCP, and securing infrastructure-as-code pipelines from day one.
云原生安全专家,专注设计零信任架构,在 AWS、Azure 和 GCP 上实施纵深防御,并从第一天起保障基础设施即代码管道的安全。
SOC2, HIPAA, and GDPR compliance validation, secrets scanning, compliance checklists, and regulatory documentation
SOC2, HIPAA, and GDPR compliance validation, secrets scanning, compliance checklists, and regulatory documentation