Read-only audit of dependency vulnerabilities, version health, and license facts across Node.js, Python, Go, Rust, JVM, and Ruby projects, with an evidence-backed report.
Runs 3 vulnerability hunters and 2 PoC engineers in parallel so only findings with a proven, reproducible attack path survive.
An AI/ML-specific security skill that scans for prompt injection and jailbreaks, scores model inversion and data poisoning risk, and maps findings to MITRE ATLAS.
A guided, safety-first workflow to scan for and purge secrets, private domains/IPs and PII from Git history, then force-push safely.
Scans a codebase for hardcoded credentials and blocks repomix packaging until it's clean.
A Bugcrowd-specific reporting overlay: VRT selection, manual severity-override requests, and ready-made out-of-scope rebuttals.
Runs 28 scanners over a Git repo, AI skill, or MCP server to surface prompt injection, credential theft, supply-chain tampering, and known CVEs.
An expert skill for DORA (Regulation (EU) 2022/2554): article-level gap analysis, ICT incident classification and reporting, third-party risk, and TLPT scoping.
A playbook for running parallel code reviews across quality dimensions, then deduplicating findings, calibrating severity and producing one consolidated report.
Runs six Article-cited forcing questions to pressure-test an AI system's readiness for the EU market.
An end-to-end malware workflow for static/dynamic analysis, YARA rule authoring, and safe sandbox setup.
Audits dependency manifests and server configs for CVEs, scores them with CVSS/EPSS/KEV, and produces a prioritized remediation report.
Turns Claude into a security reviewer grounded in OWASP Top 10:2025, ASVS 5.0, LLM Top 10 and Agentic AI risks.
Mint tamper-evident, post-quantum-signed receipts for consequential agent actions and verify them offline from the certificate alone.
Makes the agent run trace-mcp's security, quality-gate, and antipattern checks before every commit or pull request.
Read-only audit of the skills, MCP servers, hooks, plugins, and credentials already installed across Claude Code, Codex, OpenClaw, and Cursor, with a structured risk briefing.
A read-only auditor that inventories the skills, MCP servers, hooks, plugins and credential files already installed on your machine and reports the risk surface.
Runs a deep security audit across OWASP Top 10, secrets, and dependency CVEs, then writes a dated report with an approval verdict.
A security-compliance skill that scopes Implementation Groups, runs CIS Controls v8 gap assessments, gives safeguard-level implementation guidance, and maps to NIST CSF, ISO 27001, CMMC and SOC 2.
Expert guidance for UK Cyber Essentials and CE Plus certification under the current Danzell (v3.3) question set, including gap assessments and scoping.