🔒

Security

2492 skills in Testing & Security > Security

oauth

Implement OAuth 2.0 authentication flows for CRM API access. Use when authenticating with Salesforce, HubSpot, or other CRM APIs, managing access tokens, refreshing expired tokens, or building OAuth-based integrations.

benchflow-ai/skillsbench
24
9
Actualizado 5d ago

padding-oracle

Exploit padding oracle vulnerabilities in CBC mode encryption. Use this skill when attacking web applications or services that leak information about PKCS7 padding validity.

benchflow-ai/skillsbench
24
9
Actualizado 5d ago

snowflake-connections

Configuring Snowflake connections using connections.toml (for Snowflake CLI, Streamlit, Snowpark) or profiles.yml (for dbt) with multiple authentication methods (SSO, key pair, username/password, OAuth), managing multiple environments, and overriding settings with environment variables. Use this skill when setting up Snowflake CLI, Streamlit apps, dbt, or any tool requiring Snowflake authentication and connection management.

sfc-gh-dflippo/snowflake-dbt-demo
23
6
Actualizado 5d ago

security-testing

Test for security vulnerabilities using OWASP principles. Use when conducting security audits, testing auth, or implementing security practices.

proffesor-for-testing/sentinel-api-testing
23
7
Actualizado 5d ago

code-reviewer

A skill that helps review code for best practices, bugs, and security issues

hidai25/eval-view
22
3
Actualizado 5d ago

software-security-appsec

Modern application security patterns including OWASP Top 10:2025, zero trust architecture, supply chain security, authentication, authorization, input validation, and cryptography for 2024-2025

vasilyu1983/AI-Agents-public
21
6
Actualizado 5d ago

security-fastapi

FastAPI security audit patterns. Use when reviewing FastAPI apps (fastapi imports, main.py/app.py, requirements/pyproject with fastapi, uvicorn). Covers auth dependencies, CORS configuration, TrustedHost/HTTPS middleware, and common FastAPI/Starlette security footguns.

IgorWarzocha/Opencode-Workflows
21
4
Actualizado 5d ago

ai-mlops

Complete MLOps skill covering production ML lifecycle and security. Includes data ingestion, model deployment, drift detection, monitoring, plus ML security (prompt injection, jailbreak defense, RAG security, privacy, governance). Modern automation-first patterns with multi-layered defenses.

vasilyu1983/AI-Agents-public
21
6
Actualizado 5d ago

api-credentials

Securely manages API credentials for multiple providers (Anthropic Claude, Google Gemini, GitHub). Use when skills need to access stored API keys for external service invocations.

oaustegard/claude-skills
21
1
Actualizado 5d ago

security-engineer

Expert infrastructure security engineer specializing in DevSecOps, cloud security, and compliance frameworks. Masters security automation, vulnerability management, and zero-trust architecture with emphasis on shift-left security practices.

zenobi-us/dotfiles
21
4
Actualizado 5d ago

mcp-installer

Find, install, and configure Model Context Protocol (MCP) servers for OpenCode. Use when user asks about finding MCP servers, installing them, configuring OAuth, or troubleshooting MCP issues.

IgorWarzocha/Opencode-Workflows
21
4
Actualizado 5d ago

network-engineer

Expert network engineer specializing in cloud and hybrid network architectures, security, and performance optimization. Masters network design, troubleshooting, and automation with focus on reliability, scalability, and zero-trust principles.

zenobi-us/dotfiles
21
4
Actualizado 5d ago

wordpress-master

Elite WordPress architect specializing in full-stack development, performance optimization, and enterprise solutions. Masters custom theme/plugin development, multisite management, security hardening, and scaling WordPress from small sites to enterprise platforms handling millions of visitors.

zenobi-us/dotfiles
21
4
Actualizado 5d ago

security-docker

Docker/container security audit patterns. Load when Dockerfile or docker-compose.yml present. Covers secrets in layers, port exposure, non-root users, multi-stage builds, and compose security.

IgorWarzocha/Opencode-Workflows
21
4
Actualizado 5d ago

security-ai-keys

AI API key leakage review patterns. Use when code integrates AI providers (OpenAI, OpenRouter, Anthropic, Google/Gemini/Vertex, AWS Bedrock, Azure OpenAI, Mistral, Cohere, Groq, Replicate, Together, Perplexity, Fireworks, Hugging Face) or when env vars/keys are present. Focuses on client-side exposure, logging/redaction, and build artifacts.

IgorWarzocha/Opencode-Workflows
21
4
Actualizado 5d ago

security-auditor

Expert security auditor specializing in comprehensive security assessments, compliance validation, and risk management. Masters security frameworks, audit methodologies, and compliance standards with focus on identifying vulnerabilities and ensuring regulatory adherence.

zenobi-us/dotfiles
21
4
Actualizado 5d ago

electron-pro

Desktop application specialist building secure cross-platform solutions. Develops Electron apps with native OS integration, focusing on security, performance, and seamless user experience.

zenobi-us/dotfiles
21
4
Actualizado 5d ago

kubernetes-specialist

Expert Kubernetes specialist mastering container orchestration, cluster management, and cloud-native architectures. Specializes in production-grade deployments, security hardening, and performance optimization with focus on scalability and reliability.

zenobi-us/dotfiles
21
4
Actualizado 5d ago

security-vite

Vite security audit patterns. Load when reviewing Vite apps (vite.config.ts present). Covers VITE_* exposure, build-time secrets, dev server security, and SPA-specific issues.

IgorWarzocha/Opencode-Workflows
21
4
Actualizado 5d ago

dependency-manager

Expert dependency manager specializing in package management, security auditing, and version conflict resolution across multiple ecosystems. Masters dependency optimization, supply chain security, and automated updates with focus on maintaining stable, secure, and efficient dependency trees.

zenobi-us/dotfiles
21
4
Actualizado 5d ago