Bounty Security Pattern Master Library — 399 Vulnerability Patterns
A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.
Skills for security audits, static analysis, vulnerability triage, and compliance checks. Ship safer software and meet regulatory requirements faster.
67 skills
A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.
by Roy Yuen
Professional security audit skill for web apps and APIs with structured severity-based findings and remediation plans.
by Roy Yuen
A high-performance wrapper to route security tasks directly to the Anthropic-Cybersecurity-Skills library.
by Roy Yuen
Audit AI agent skills for security risks, packaging errors, and marketplace readiness with professional reports.
by Roy Yuen
Prevent vulnerabilities before they happen by forcing early security framing and secure-by-default design patterns.
by Roy Yuen
Automated security and compatibility firewall for installing AI agent skills and Codex/OpenClaw packages.
Expert AI guidance for ISO-compliant cleanroom design, HVAC filtration setup, and controlled environment installation.
by rayyer
Find accessibility barriers and WCAG 2.2 AA failures in web and mobile UI code — with file:line, the exact criterion, and a fix
by Roy Yuen
Transform AI claims into verified, risk-assessed technical reports for production, DevOps, and enterprise governance.
by Samuel Rose
Audit dependencies for security, licenses, and health while generating a phased, low-risk upgrade and migration plan.
by LocoLoboZ
Automate the setup and optimization of Semgrep, SonarQube, and CodeQL for high-signal security testing.
by Timoranjes
Comprehensive security auditing for AI agents, covering prompt injection, tool permissions, and data leakage risks.
by Roy Yuen
A modular governance framework for AI policy, agent risk assessment, human-in-the-loop approvals, and audit trails.
by Timoranjes
Automated security audit and health check for software dependencies across polyglot projects.
by Tate Lyman
Automated launch-readiness auditor for x402 and agent-payment API surfaces.
A fast, free 3-point accessibility screen (text contrast, image alt text, form labels) to spot the most common ADA/WCAG problems before they cost you.
Scan your schemas, seed data, config, and logs for personal data before it leaks. Detects PII-indicating column and key names (email, ssn, phone, address) across SQL, CSV, and JSON, plus PII in the data itself: email addresses, SSN-like numbers, credit-card-like numbers, phone numbers, and PII written into log files. Each finding is flagged with its location and a GDPR-style review note. Heuristic by design: it surfaces what to review, not a compliance guarantee.
by Timoranjes
Audit frontend code for WCAG 2.2 AA compliance with prioritized remediation steps and deep semantic analysis.
Audit and refine vulnerability reports to maximize bounty payouts and reduce N/A or duplicate closures.
by LB Creations
Secure, battle-tested patterns for user detection and credential prompting in Jamf and Kandji scripts
Monitors SSL cert expiry dates and sends Telegram alerts before they expire. Critical at <7d, warning at <30d.
by LB Creations
Sanitize Mac admin logs and MDM evidence before sharing.
by Shandra
Turns dependency scan reports and security alerts into prioritized remediation plans with severity, exploitability, affected area, safe fix strategy, and verification checklists.
by LocoLoboZ
Design and analyze industrial control system anomaly detection logic for safe, protocol-aware OT security monitoring.
by LocoLoboZ
Transform incident timelines into structured Cyber Kill Chain mappings and high-impact defensive roadmaps.
by LocoLoboZ
Transform raw vulnerability data into compliant remediation reports, ageing registers, and executive dashboards.
by Timoranjes
Expert regex architect for building, auditing, and optimizing high-performance, ReDoS-safe patterns.
by Shogun Labs
Automate secret scanning with gitleaks — detect API keys, passwords, tokens before incidents.
by LocoLoboZ
Build safety-first, framework-aligned incident response playbooks for ICS, SCADA, and OT environments.
by Timoranjes
The security auditor for AI agents. Detect prompt injection, secret leaks, and unsafe tool access in SKILL.md files.
An adversarial security gate that audits untrusted content — web pages, tool outputs, documents, emails — for embedded instructions, exfiltration, and authority spoofing, then returns a SAFE/REVIEW/BLOCK verdict.
by Nex AI
Prevent data leaks with auto-injected SQLAlchemy tenant scoping and Cloudflare Access auth for FastAPI SaaS apps.
by LocoLoboZ
Design, govern, and report on enterprise-grade anti-phishing training programs and simulation metrics.
Automatically detect GDPR compliance risks in websites, codebases, marketing assets, and AI workflows.
Audit your Supabase project for the row-level-security mistakes that quietly expose data: tables without RLS, policies that resolve to true, leaked service-role keys, missing auth.uid() checks, open storage buckets, overbroad grants, and migration drift. A local, read-only scan plus a full review checklist, each finding with severity, evidence, and a fix. No database changes without confirmation.
by Timoranjes
Professional-grade Kubernetes YAML auditor for security, API deprecations, and deployment best practices.
by Kaymue
Audit prompts and MCP tools for prompt injection. 47 attack patterns, OWASP LLM Top 10, generates adversarial tests. CVSS-scored.
by Corey Jacobs
Generate source-safe repository audits and repair handoff bundles without mutating your code.
Scan a SKILL.md package for prompt injection and secret exfiltration before you install or publish an agent skill. Flags env-variable-to-URL exfiltration wording, conditional triggers with hidden side effects, imperative instructions buried in HTML comments, zero-width characters, base64 and long-token blobs, remote content treated as instructions, pipe-to-shell and recursive force-delete references, and overbroad tool requests (network plus browser plus file-write with no scope).
by Timoranjes
Structured security auditing for AI agent skills to detect prompt injection, data exfiltration, and malicious commands.
Audit and harden GitHub Actions workflows against overbroad permissions, secrets exposure, and supply-chain risks.
Check your app for the security mistakes that leak data before you launch, explained in plain English. Flags API keys and secrets sitting in your code, a committed .env file, data with no login protecting it, database tables anyone can read, debug mode left on, wide-open sharing (CORS), hardcoded admin passwords, and public storage buckets. Built for non-technical founders shipping AI-built apps: every finding tells you what is wrong, why it matters, and how to fix it.
by Timoranjes
A security auditor that identifies Docker vulnerabilities, scores configurations, and generates hardened replacements.
Audit a Helm chart for insecure defaults before you deploy to Kubernetes. Flags privileged containers, allowPrivilegeEscalation, missing CPU/memory limits and requests, hostPath volumes, hostNetwork/hostPID/hostIPC sharing, readOnlyRootFilesystem not set, runAsNonRoot not enforced (or runAsUser 0), plaintext secrets in values.yaml, missing NetworkPolicy, and NodePort/LoadBalancer services exposed without restriction.
by SkillBill
Complete security audit for Linux systems and WSL2. Checks kernel CVEs, SSH, firewall, users, and more hardening in one shot.
Stop leaving your AI startup exposed to malicious users trying to steal your proprietary system prompts or bypass your paywalls. The AI Prompt Injection Defense Shield is an automated code review agent that deeply analyzes your Next.js or Python backend, instantly detecting insecure LLM input fields, un-sanitized API data streams, and weak prompt boundaries. By automatically generating the exact copy-paste code patches required to harden your AI wrapper against the latest OWASP top 10 LLM vulnerabilities, this skill allows solo developers and indie hackers to confidently launch their SaaS without the fear of massive, unexpected API billing spikes or catastrophic data leaks.
by Nex AI
Automate EU AI Act transparency audits, Article 50 disclosures, and AI literacy documentation for your apps.
A structured WCAG 2.1 AA audit and fix agent for WordPress themes, organized by block theme, Gutenberg, forms, and navigation context, with scored findings and complete before-to-after code patches.
by Nex AI
Professional accessibility auditing for architects, balancing legal regulations with real-world usability.
by Echo Rose
Api Security Scanner - A Premium AI Agent Skill
A pre-submission gate for medical and scientific manuscripts. It audits your near-final draft, abstract, poster, or congress submission for the disclosures journals now screen on intake — AI/LLM-use disclosure (ICMJE-aligned), authorship against the four ICMJE criteria, conflict-of-interest and funding statements, and data availability — then returns a PASS/REVISE verdict naming every gap, plus a ready-to-paste AI-use disclosure statement. Built by a CMPP-certified medical writer.
A DevSecOps engineer that stands up and tunes static analysis (Semgrep, SonarQube, CodeQL) for high-signal findings — picks the right tool for the stack, writes the config and rulesets, wires a sane CI gate, and tunes out the false positives that get scanners muted.
An automated security auditor that scans code for OWASP vulnerabilities, secrets, and injection flaws before deployment.
Scan your OpenClaw config for the settings that quietly hand your agent too much power: unrestricted exec, open inbound DMs, secrets committed in config, the deny-write bypass, sandbox turned off, dangerous Docker binds, and elevated tools. Read-only, plain-English findings, grounded in the OpenClaw docs.
by Julian GM
Public-source due diligence and risk assessment for companies, vendors, and business counterparties — every finding labeled verified, reported, or unverified.Automated OSINT due diligence and risk assessment for companies, vendors, and business counterparties.
Local-first GDPR/TDDDG compliance cockpit that actually executes — scan a live site locally, check uploads fully offline, or build a compliant site, all with an evidence-backed report.
Before you send proprietary or sensitive data to an AI vendor, assess the risk. Classifies what's actually your moat versus regulated, contractual, or harmless data, maps the real exposure vectors by vendor tier, lists the questions to get in writing, and gives a send / send-with-controls / keep-in-house recommendation per data type.
Red-team your own AI agent for prompt-injection and tool-misuse vulnerabilities before it ships — then fix them. Maps your attack surface, generates a defensive test plan with the safe behavior expected for each case, and gives a prioritized mitigations list. Defensive use only.
by Julian GM
Triage a vendor email, invoice, or bank-detail change request for BEC/fraud signals before you pay — mechanical CLEAR / VERIFY / HOLD verdict, honest about what it can't check.
by Echo Rose
App Firewall - A Premium AI Agent Skill
A third-party skill is instructions your agent will trust. Review it before you install it. Structured security auditing for third-party skills to detect injection, exfiltration, and hidden malicious logic.
by acarchidi
DeFi safety layer for agents providing rug checks, transaction decoding, and contract audits on EVM and Solana.
by Echo Rose
Ai Robustness Tester - A Premium AI Agent Skill
Audits codebases for HIPAA Security Rule gaps, identifies PHI leaks, and maps BAA requirements.
A 6-layer engineering containment gate for agents that move real money.
Audit and remediate Shopify and WooCommerce stores for EAA, WCAG 2.1 AA, and ADA Title II compliance.
by Roy Yuen
Local-first revenue assurance tool to identify billing leakage, unbilled usage, and expired discounts.