Web security assessment with vulnerability scanning, penetration testing methodology, and professional reporting.
Security
Security scanning, authentication, and vulnerability detection
Self-security scan of SuperPAI configuration with graded report
Security news aggregation from tldrsec, no.security, and other sources.
Security reconnaissance for authorized targets. Map attack surface, discover assets, enumerate services.
Annual report aggregation and analysis. Security reports, threat landscape, industry reports.
Run security checks before code leaves the machine — secrets scanning (gitleaks), .gitignore hygiene, dependency...
Use when provisioning or verifying gpc authentication, including service-account setup, profile switching, doctor...
Enforce security standards when writing or reviewing code that handles authentication, authorization, user input,...
Squash consecutive co-authored commits into one. Always asks for confirmation before proceeding.
>-
Use the open-source free `Meziantou.Analyzer` package for design, usage, security, performance, and style rules in...
信息溯源与信源信誉追踪。追溯信息源头(谁先报的、谁说的最准、原作者是谁),长期积累信源画像。Triggers on: 谁先报的, 谁最先说的, 消息来源, 信息溯源, 最早发布, 首发, 源头, 这个消息可信吗, 这是真的吗,...
Code-level security posture evaluation. Scans for OWASP Top 10 vulnerabilities, authentication flaws, injection...
Use this skill whenever the user wants to do anything with PDF files. This includes reading or extracting...
Configure and enable unattended-upgrades (automatic security/package updates) on Debian/Ubuntu hosts, including...
Add JWT authentication to pico-fastapi controllers. Use when protecting endpoints, adding role-based access control,...
Code quality, security, and performance scan with FIPD-classified findings
Migrate a Base44 app to Vercel (frontend + serverless functions) and Supabase (PostgreSQL + Auth). Scans the repo,...
File, directory, or component to audit
セキュリティ脆弱性検出の判断基準。security-reviewerが使用する専用知識ベース。
Designs a secure authentication and authorization flow for any application, covering login, sessions, roles, and edge cases.
Sync OneLap FIT files to Strava and run auth initialization flows. Use when users ask to sync activities, download...
Binance Spot request using the Binance API. Authentication requires API key and secret key. Supports testnet,...
Binance Margin-trading request using the Binance API. Authentication requires API key and secret key.