Read-only audit of dependency vulnerabilities, version health, and license facts across Node.js, Python, Go, Rust, JVM, and Ruby projects, with an evidence-backed report.
Scans a codebase for hardcoded credentials and blocks repomix packaging until it's clean.
Runs 28 scanners over a Git repo, AI skill, or MCP server to surface prompt injection, credential theft, supply-chain tampering, and known CVEs.
A playbook for running parallel code reviews across quality dimensions, then deduplicating findings, calibrating severity and producing one consolidated report.
Audits dependency manifests and server configs for CVEs, scores them with CVSS/EPSS/KEV, and produces a prioritized remediation report.
Turns Claude into a security reviewer grounded in OWASP Top 10:2025, ASVS 5.0, LLM Top 10 and Agentic AI risks.
Makes the agent run trace-mcp's security, quality-gate, and antipattern checks before every commit or pull request.
A read-only auditor that inventories the skills, MCP servers, hooks, plugins and credential files already installed on your machine and reports the risk surface.
Runs a deep security audit across OWASP Top 10, secrets, and dependency CVEs, then writes a dated report with an approval verdict.
Expert guidance for UK Cyber Essentials and CE Plus certification under the current Danzell (v3.3) question set, including gap assessments and scoping.
A California privacy skill that walks through CCPA/CPRA applicability, consumer-rights workflows, opt-out/SPI/ADMT mechanics, and GDPR gap analysis.
A security-compliance skill that scopes Implementation Groups, runs CIS Controls v8 gap assessments, gives safeguard-level implementation guidance, and maps to NIST CSF, ISO 27001, CMMC and SOC 2.
An OWASP-driven security review skill that hardens user input, auth, dependencies, and LLM features with concrete code patterns.
A zero-trust gatekeeper skill that scans every incoming file or URL and returns a pass/reject verdict plus a compliance scan report before any document processing happens.
Runs the liarjs CLI to cross-check a browser's JS fingerprint (canvas, WebGL, audio, fonts, WebRTC, timezone) against the TLS/HTTP/ASN view of the same request and scores the contradictions.
A defensive security-audit skill that scans your whole repo for dependency CVEs and risky code patterns, triages them by severity and reachability, then fixes them without suppressing alerts.
Reads a liarjs fingerprint report and attributes each failing check to the component that actually produced the signal.
Autonomously scans a codebase for personal data, runs an all-99-article GDPR gap analysis, and generates pre-filled DPA, ROPA and operational compliance documents.
Auto-checks forms, schemas, auth flows and APIs for personal-data risks before Claude writes the code, mapped to US privacy regulations.