Skill4Agent
Skill4Agent
All SkillsSearchTools
|
Explore
Skill4Agent
Skill4Agent

AI Agent Skills Directory with categorization, English/Chinese translation, and script security checks.

Sitemap

  • Home
  • All Skills
  • Search
  • Tools

About

  • About Us
  • Disclaimer
  • Copyright

Help

  • FAQ
  • Privacy
  • Terms
Contact Us:osulivan147@qq.com

© 2026 Skill4Agent. All rights reserved.

All Skills

Total 54,475 skills, Security & Compliance has 2133 skills

Categories

Showing 12 of 2133 skills

Per page
Downloads
Sort
Security & Compliancelawve-ai/awesome-legal-sk...

whistleblower-policy-malik-taiar

Guide for (a) auditing an existing whistleblower system or (b) drafting a compliant reporting policy from a provided template. Covers EU Directive 2019/1937, the amended Sapin II law (Waserman 2022), Decree 2022-1284, CNIL guidelines, public sector requirements, and duty of vigilance.

🇺🇸|EnglishTranslated
16
Security & Compliancejaygptpro/amazon-pro-skil...

amz-1099k-reconciliation

Reconcile Amazon's 1099-K against actual deposits, fees, and refunds for tax filing. Explains the gap between gross sales on the 1099-K and what hit the bank, maps the numbers to Schedule C lines, and produces the worksheet the seller or their CPA needs. Use when a user asks about 1099-K, Amazon tax documents, reconciling gross vs net sales, year-end tax prep, or why the 1099-K is higher than their deposits. Trigger phrases: "1099-K", "tax forms", "Amazon tax document", "gross vs net", "Schedule C", "year end". Works with zero tools. the user pastes the 1099-K and Payments summary.

🇺🇸|EnglishTranslated
16
Security & Complianceauth0/agent-skills

auth0-dpop

Use when adding DPoP (Demonstrating Proof-of-Possession) token binding to protect API calls with device-bound, sender-constrained access tokens that cannot be replayed if stolen. Also use when a user says "bind tokens to the client", "prevent token theft", or "sender-constrained tokens".

🇺🇸|EnglishTranslated
16
Security & Compliancekevintsai1202/law-powers

compliance-verification

Used to review the legality of contract drafts and business behaviors, compare with laws such as the Civil Code, Labor Standards Act, Personal Data Protection Act, and Company Act, mark high, medium, and low-risk clauses, and provide modification suggestions.

🇨🇳|ChineseTranslated
16
Security & Compliancebrowserbase/skills

what-antibot

Detect antibot vendors on one or more URLs without opening a browser session. Use when the user asks what antibot, bot protection, WAF, captcha, or challenge provider a site uses, or asks to check sites for Cloudflare, Akamai, DataDome, PerimeterX, Imperva/Incapsula, Kasada, reCAPTCHA, hCaptcha, Anubis, or Shape Security markers.

🇺🇸|EnglishTranslated
15
1 scripts/Attention
Security & Compliancegarrytan/gstack

cso

Chief Security Officer mode. Infrastructure-first security audit: secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, plus OWASP Top 10, STRIDE threat modeling, and active verification. Two modes: daily (zero-noise, 8/10 confidence gate) and comprehensive (monthly deep scan, 2/10 bar). Trend tracking across audit runs. Use when: "security audit", "threat model", "pentest review", "OWASP", "CSO review". (gstack) Voice triggers (speech-to-text aliases): "see-so", "see so", "security review", "security check", "vulnerability scan", "run security".

🇺🇸|EnglishTranslated
15
Security & Complianceunitoneai/securityskills

log-analysis

Guides structured security log analysis across authentication, network, endpoint, and cloud audit log sources. Auto-invoked when the user shares log data, asks about suspicious events, needs help interpreting Windows Event IDs or Linux auth logs, or is establishing baselines for anomaly detection. Produces log source taxonomy, anomaly identification, baseline recommendations, and correlation findings mapped to MITRE ATT&CK v16 techniques.

🇺🇸|EnglishTranslated
15
Security & Complianceinfisical/ai-skills

infisical-user-setup-guide

Interactive setup guide for using Infisical as a secret management tool in your projects. Helps users integrate Infisical into local development (CLI), Docker containers (build-time and runtime secret injection), CI/CD pipelines (GitHub Actions, GitLab CI), Kubernetes (Operator + CRDs), and application code (Node.js, Python, Go, Java, .NET, Ruby SDKs). Also walks through choosing and configuring machine identity auth methods (Universal Auth, AWS Auth, Kubernetes Auth, OIDC, etc.). Use this skill whenever someone asks about: using Infisical, injecting secrets, infisical run, infisical init, connecting their app to Infisical, Docker secrets, Kubernetes secrets operator, machine identity setup, SDK initialization, CI/CD secret injection, or 'how do I get my secrets into my app'.

🇺🇸|EnglishTranslated
15
Security & Compliancejoellewis/finance_skills

sales-practices

Identify and prevent sales practice violations under FINRA and SEC rules governing broker-dealer conduct. Use when the user asks about churning or excessive trading metrics, mutual fund breakpoint discounts, selling away or private securities transactions, outside business activities, unauthorized trading, supervisory procedure design, senior investor protections, trusted contact persons, variable annuity suitability, or options account approval. Also trigger when users mention 'turnover ratio is high', 'rep did trades without authorization', 'breakpoint abuse', 'trusted contact for elderly client', 'selling away from the firm', 'supervision failure', '1035 exchange review', 'marking the close', or ask whether a broker's conduct violates FINRA rules.

🇺🇸|EnglishTranslated
15
Security & Compliancebagelhole/devops-security...

ssl-tls-management

Manage SSL/TLS certificates with Let's Encrypt and internal PKI. Configure secure HTTPS, certificate renewal, and cipher suites. Use when implementing secure communications.

🇺🇸|EnglishTranslated
15
Security & Compliancedaemon-blockint-tech/agen...

technical-program-manager-security-cvd

Guides technical program management for security coordinated vulnerability disclosure (CVD)— disclosure policy, intake and triage SLAs, researcher coordination, fix/remediation tracking, embargo and publication timelines, CVE/advisory coordination, bug bounty program operations, and cross-functional gates (security engineering, legal, comms, product). Use when running a CVD or responsible disclosure program, disclosure calendar, bounty ops, or unblocking multi-team remediation for reported vulnerabilities—not for hands-on pentest (offensive-security-analyst), SOC triage (defensive-security-analyst), vuln scanning in CI (devsecops), enterprise security strategy (cybersecurity), generic non-security programs (technical-program-manager), or contract redlines (commercial-counsel).

🇺🇸|EnglishTranslated
15
Security & Compliancedaemon-blockint-tech/agen...

defensive-security-analyst

Guides defensive security analysis—alert triage, log and SIEM investigation, threat hunting, detection engineering basics, MITRE ATT&CK mapping, incident scoping, containment recommendations, and DFIR evidence handling for SOC and blue-team analysts. Use when investigating security alerts, writing detection rules, tuning false positives, analyzing EDR/network/auth logs, building timelines of suspicious activity, recommending containment steps, or documenting findings for incident command—not for enterprise security strategy (cybersecurity), CI/CD pipeline hardening (devsecops), offensive pentest execution (authorize red team separately), or LLM adversarial testing (ai-redteam), or designing on-call rotations and postmortem programs (incident-management-engineer).

🇺🇸|EnglishTranslated
15
1...8283848586...178
Page