Discover Agent Skills for security & testing. Browse 105skills for Claude, ChatGPT & Codex.
Provides comprehensive methodologies for detecting, exploiting, and remediating Insecure Direct Object Reference (IDOR) vulnerabilities in web applications.
Simulates adversary behaviors and security assessments based on the industry-standard MITRE ATT&CK framework.
Guides the development of NestJS backends using a strict, iterative Test-Driven Development (TDD) methodology.
Facilitates end-to-end testing and interaction with local web applications using Playwright scripts and automated server management.
Audits IAM policies, ACLs, and permission configurations to identify security vulnerabilities and privilege escalation paths.
Audits system access controls and IAM policies to identify security vulnerabilities, misconfigurations, and privilege escalation risks.
Audits and identifies vulnerabilities in IAM policies, network ACLs, and application-level access controls to ensure security compliance.
Performs automated accessibility audits to ensure web applications meet WCAG standards and ARIA best practices.
Conducts automated accessibility audits to ensure web applications comply with WCAG standards and ARIA best practices.
Automates the analysis and management of snapshot test failures across major JavaScript testing frameworks.
Performs automated fuzz testing on REST APIs to discover vulnerabilities, input validation flaws, and potential security breaches.
Automates the generation and execution of comprehensive API tests for REST and GraphQL endpoints to ensure contract compliance and security.
Automates the generation and execution of comprehensive test suites for REST and GraphQL APIs to ensure contract compliance and security.
Validates application authentication mechanisms against security best practices and industry standards to identify vulnerabilities.
Validates authentication implementations against security best practices to identify vulnerabilities in JWT, OAuth, and session management.
Automates cross-browser testing across multiple devices and browsers to ensure consistent web application performance and visual fidelity.
Automates multi-browser and cross-device testing to ensure consistent web application performance across Chrome, Firefox, Safari, and Edge.
Designs and executes controlled chaos engineering experiments to identify system vulnerabilities and improve overall service resilience.
Designs and executes controlled failure injection experiments to validate system resilience and recovery mechanisms.
Analyzes infrastructure configurations against SOC2, HIPAA, and PCI-DSS standards to identify security risks and compliance gaps.
Automates the creation of professional compliance reports and security audits for standards like HIPAA, SOC 2, and PCI DSS.
Automates the creation of professional compliance and security audit reports for major regulatory standards like HIPAA, PCI DSS, and SOC 2.
Scans container images and running containers for vulnerabilities using industry-standard tools like Trivy and Snyk.
Validates API contracts using consumer-driven testing and OpenAPI specifications to ensure seamless compatibility between providers and consumers.
Validates API contracts and ensures backward compatibility using Pact and OpenAPI specifications.
Validates and audits Cross-Origin Resource Sharing (CORS) configurations to identify security vulnerabilities and ensure compliant web access policies.
Analyzes and validates Cross-Origin Resource Sharing (CORS) configurations to identify security vulnerabilities and ensure policy compliance.
Identifies and validates Cross-Site Request Forgery (CSRF) protection mechanisms in web applications to prevent unauthorized state-changing attacks.
Validates web application endpoints and security configurations to identify and remediate Cross-Site Request Forgery (CSRF) vulnerabilities.
Audits web applications for Cross-Site Request Forgery vulnerabilities by validating security tokens, cookie attributes, and endpoint protections.
Scroll for more results...