Skill4Agent
Skill4Agent
All SkillsSearchTools
|
Explore
Skill4Agent
Skill4Agent

AI Agent Skills Directory with categorization, English/Chinese translation, and script security checks.

Sitemap

  • Home
  • All Skills
  • Search
  • Tools

About

  • About Us
  • Disclaimer
  • Copyright

Help

  • FAQ
  • Privacy
  • Terms
Contact Us:osulivan147@qq.com

© 2026 Skill4Agent. All rights reserved.

All Skills

Total 54,046 skills, Security & Compliance has 2122 skills

Categories

Showing 12 of 2122 skills

Per page
Downloads
Sort
Security & Compliancematteocervelli/llms

owasp-checker

Verify compliance with OWASP Top 10 2021 security standards. Use when performing OWASP compliance checks and security certification.

🇺🇸|EnglishTranslated
22
Security & Compliancecodyswanngt/lisa

security-zap-scan

Run an OWASP ZAP baseline security scan locally using Docker. Checks for the ZAP baseline script, executes the scan, and summarizes findings by risk level with remediation recommendations.

🇺🇸|EnglishTranslated
22
Security & Compliancevchirrav/owasp-secure-cod...

dependency-confusion-detect

Run Confused and GuardDog to detect dependency confusion and typosquatting risks. Checks if internal package names exist on public registries and identifies malicious packages.

🇺🇸|EnglishTranslated
22
Security & Compliancegtmagents/gtm-agents

compliance-briefing-kit

Standardized template for campaign compliance intake, reviews, and approvals.

🇺🇸|EnglishTranslated
22
Security & Complianceaws/agent-toolkit-for-aws

creating-secrets-using-best-practices

Creates and manages secrets in AWS Secrets Manager following security best practices. Always use this skill when creating secrets — it sets up dedicated KMS encryption keys, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management that are essential for production-grade secret handling.

🇺🇸|EnglishTranslated
22
Security & Compliancejd-opensource/joysafeter

pentest-ai-llm-security

AI/LLM application security testing — prompt injection, jailbreaking, data exfiltration, and insecure output handling per OWASP LLM Top 10.

🇺🇸|EnglishTranslated
22
Security & Compliancejim60105/copilot-prompt

typescript-security

Guideline for designing, implementing, and verifying secure TypeScript and JavaScript applications following OWASP Top 10 best practices. Use when the user wants to: (1) review TypeScript or JavaScript code for security vulnerabilities, (2) design a secure Node.js, Deno, or browser application architecture, (3) implement security features (authentication, authorization, cryptography, input validation), (4) audit npm/yarn/pnpm dependencies for known vulnerabilities, (5) create security checklists or verification plans, (6) fix security bugs or harden existing TypeScript or JavaScript code, (7) set up security testing and static analysis (ESLint security plugins, Semgrep, Snyk), or (8) handle any TypeScript/JavaScript security concern including injection prevention, prototype pollution, XSS protection, SSRF prevention, secrets management, and secure deployment.

🇺🇸|EnglishTranslated
22
Security & Compliancesisodiabhumca/agent-skill...

security-exception-expiry-tracker-20260527-02

Vendor-neutral skill to track security exception expirations and generate remediation reminders.

🇺🇸|EnglishTranslated
22
1 scripts/Checked
Security & Complianceauth0/agent-skills

auth0-custom-domains

Use when setting up, troubleshooting, managing, removing, or checking the health of an Auth0 custom authentication domain (e.g. login.example.com), OR when diagnosing an error (400/403/404/409/429) from the /custom-domains Management API — especially Free-tier 403s (credit card on file, not a plan upgrade), self-managed cert 403s, PATCH-type 400s, `operation_not_supported` on `relying_party_identifier`, and 409 domain-already-exists. Handles CNAME creation in the user's DNS provider (Cloudflare, AWS Route 53, Azure DNS automated; other registrars guided), verification polling, Multiple Custom Domains (MCD), default-domain selection, TLS policy, client-IP header, per-domain passkey relying party identifier, and domain metadata.

🇺🇸|EnglishTranslated
22
1 scripts/Attention
Security & Complianceleapcat-ai/leapcat-skills

leapcat-kyc

Guide users through KYC verification on Leapcat. Covers document upload, personal information submission, agreements, and status polling via the leapcat CLI.

🇺🇸|EnglishTranslated
22
Security & Compliancetrailofbits/skills

mermaid-to-proverif

Translates Mermaid sequenceDiagrams describing cryptographic protocols into ProVerif formal verification models (.pv files). Use when generating a ProVerif model, formally verifying a protocol, converting a Mermaid diagram to ProVerif, verifying protocol security properties (secrecy, authentication, forward secrecy), checking for replay attacks, or producing a .pv file from a sequence diagram.

🇺🇸|EnglishTranslated
22
Security & Compliancegaliais/ctf-sandbox-orche...

competition-forensic-timeline

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for DFIR chronology, cross-artifact correlation, persistence chains, and incident timeline reconstruction. Use when the user asks to build a forensic timeline, correlate EVTX, PCAP, registry, disk, memory, mailbox, or browser artifacts, explain the order of attacker actions, or pinpoint the stage where the decisive artifact appears. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.

🇺🇸|EnglishTranslated
22
1...3738394041...177
Page