Terminal Pty Audit
Use this skill to audit terminal, PTY, shell session, container exec, and WebSocket terminal backends. Do not use it for unrelated frontend UI review.
Backend Authz Audit
Use this skill to audit backend authorization, IDOR, ownership checks, and tenant isolation. Do not use it for smart contracts or legal contract review.
Rag Ai App Security Audit
Use this skill to audit RAG and AI application security, including retrieval boundaries, prompt injection, citations, memory, and data exposure. Do not use it as a scanner or exploit runner.
Fix Selected Security Findings
Use this skill only when the user explicitly selects security finding IDs to fix. Do not use it to fix all findings or perform broad refactors.
Ci Cd Supply Chain Audit
Use this skill to audit CI/CD workflows, dependencies, build scripts, releases, artifacts, and package publishing. Do not use it for runtime application authz review.
Secrets Logging Privacy Audit
Use this skill to audit secrets, PII, logs, traces, metrics, debug endpoints, and error responses. Do not use it for general performance review.
Incident To Prompt
Use this skill to convert a security incident or public vulnerability pattern into reusable audit prompts, checklists, tests, and AGENTS.md rules. Do not use it to generate exploit instructions.
Pr Security Review
Use this skill to review a PR or diff for security regressions. Do not use it for full-repository audits or legal contract review.
Smart Contract Audit
Use this skill to audit Solidity, Vyper, EVM, DeFi, oracle, accounting, reentrancy, and upgradeability risks. Do not use it for legal contract review.
Llm Agent Tooling Audit
Use this skill to audit LLM agents, tool calling, MCP integrations, prompt injection, data exfiltration, and tool permissions. Do not use it for ordinary backend authz unless agent/tooling is involved.