draft
Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing A...
- invoke
/auth-implementation-patterns
draft
Automated compliance checking against CIS, PCI-DSS, HIPAA, and SOC 2 benchmarks
- invoke
/aws-compliance-checker
draft
IAM policy review, hardening, and least privilege implementation
- invoke
/aws-iam-best-practices
draft
Automate AWS secrets rotation for RDS, API keys, and credentials
- invoke
/aws-secrets-rotation
draft
Comprehensive AWS security posture assessment using AWS CLI and security best practices
- invoke
/aws-security-audit
draft
This skill should be used when the user asks to "test for broken authentication vulnerabilities", "assess session management security", "perform credential stuffing tests", "evaluate ...
- invoke
/broken-authentication
draft
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist a...
- invoke
/cc-skill-security-review
draft
Expert patterns for Clerk auth implementation, middleware, organizations, webhooks, and user sync Use when: adding authentication, clerk auth, user authentication, sign in, sign up.
- invoke
/clerk-auth
draft
Expert malware analyst specializing in defensive malware research,
- invoke
/malware-analyst
draft
Expert in secure mobile coding practices specializing in input
- invoke
/mobile-security-coder
draft
This skill should be used when the user asks to "plan a penetration test", "create a security assessment checklist", "prepare for penetration testing", "define pentest scope", "foll...
- invoke
/pentest-checklist
draft
This skill should be used when the user asks to "run pentest commands", "scan with nmap", "use metasploit exploits", "crack passwords with hydra or john", "scan web vulnerabilities ...
- invoke
/pentest-commands
draft
Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.
- invoke
/security-audit
draft
Expert security auditor specializing in DevSecOps, comprehensive
- invoke
/security-auditor
draft
You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards. Perform compliance audits and provide im...
- invoke
/security-compliance-compliance-check
draft
You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across ecosystems to identify vulnerabilities, ass...
- invoke
/security-scanning-security-dependencies
draft
Coordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls.
- invoke
/security-scanning-security-hardening
draft
Static Application Security Testing (SAST) for code vulnerability
- invoke
/security-scanning-security-sast
draft
Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementin...
- invoke
/solidity-security
draft
Map identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control effectiveness.
- invoke
/threat-mitigation-mapping
draft
Expert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security requirement extraction. Use for security architecture r...
- invoke
/threat-modeling-expert
draft
Advanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization.
- invoke
/vulnerability-scanner