Bounty Security Pattern Master Library — 399 Vulnerability Patterns
A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.
Skills for security audits, static analysis, vulnerability triage, and compliance checks. Ship safer software and meet regulatory requirements faster.
73 skills
A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.
Prevent vulnerabilities before they happen by forcing early security framing and secure-by-default design patterns.
Professional security audit skill for web apps and APIs with structured severity-based findings and remediation plans.
A high-performance wrapper to route security tasks directly to the Anthropic-Cybersecurity-Skills library.
Audit AI agent skills for security risks, packaging errors, and marketplace readiness with professional reports.
Expert AI guidance for ISO-compliant cleanroom design, HVAC filtration setup, and controlled environment installation.
Automated security and compatibility firewall for installing AI agent skills and Codex/OpenClaw packages.
Messy, insecure, unfixable — that's what AI builds without architecture. This file is the architecture: 10 years of senior judgement on rendering, caching, security and SEO, so your agent builds it right from day one.
Find accessibility barriers and WCAG 2.2 AA failures in web and mobile UI code — with file:line, the exact criterion, and a fix
Transform AI claims into verified, risk-assessed technical reports for production, DevOps, and enterprise governance.
Audit dependencies for security, licenses, and health while generating a phased, low-risk upgrade and migration plan.
Automate the setup and optimization of Semgrep, SonarQube, and CodeQL for high-signal security testing.
Comprehensive security auditing for AI agents, covering prompt injection, tool permissions, and data leakage risks.
Automated security audit and health check for software dependencies across polyglot projects.
Scan local SQL, CSV, JSON, seed, fixture, and log files for PII-indicating names plus email-, SSN-, card-, and phone-like values. Get file/line findings with matched values redacted by default—no network, writes, database connection, or compliance claim.
A fast, free 3-point accessibility screen (text contrast, image alt text, form labels) to spot the most common ADA/WCAG problems before they cost you.
Audit frontend code for WCAG 2.2 AA compliance with prioritized remediation steps and deep semantic analysis.
Automated open-source license audit and risk assessment based on your project's specific distribution model.
Turns dependency scan reports and security alerts into prioritized remediation plans with severity, exploitability, affected area, safe fix strategy, and verification checklists.
Professional network forensics and packet analysis for incident response and security investigations.
Sanitize Mac admin logs and MDM evidence before sharing.
Secure, battle-tested patterns for user detection and credential prompting in Jamf and Kandji scripts
Automated factual verification using tiered official sources to eliminate hallucinations and circular reasoning.
The security auditor for AI agents. Detect prompt injection, secret leaks, and unsafe tool access in SKILL.md files.
Transform APT threat intelligence into MITRE ATT&CK Navigator layers and prioritized detection gap analyses.
Automatically detect GDPR compliance risks in websites, codebases, marketing assets, and AI workflows.
Scan a SKILL.md package for prompt injection and secret exfiltration before you install or publish an agent skill. Flags env-variable-to-URL exfiltration wording, conditional triggers with hidden side effects, imperative instructions buried in HTML comments, zero-width characters, base64 and long-token blobs, remote content treated as instructions, pipe-to-shell and recursive force-delete references, and overbroad tool requests (network plus browser plus file-write with no scope).
Professional-grade Kubernetes YAML auditor for security, API deprecations, and deployment best practices.
Deep audit and detection of the Dirty Frag (CVE-2026-43284/43500) Linux privilege escalation exploit chain.
Get SOC2 Type II-ready in 90 days. 17 policy templates, 64 control mappings, automated AWS/GCP/GitHub evidence collection.
Stop AI hallucinations in cold email with server-side legal footers and Belgian GDPR compliance guardrails.
Audit prompts and MCP tools for prompt injection. 47 attack patterns, OWASP LLM Top 10, generates adversarial tests. CVSS-scored.
Enterprise security with NIST/ISO27001/zero-trust frameworks. Threat modeling, GDPR compliance, DevSecOps guidance.
Generate source-safe repository audits and repair handoff bundles without mutating your code.
A security auditor that identifies Docker vulnerabilities, scores configurations, and generates hardened replacements.
Structured security auditing for AI agent skills to detect prompt injection, data exfiltration, and malicious commands.
Generate the model and vendor risk register a security lead asks for the morning after a model gets switched off. It scans your codebase for every model and provider, merges in the owner and data-residency notes you supply, and renders a register with provider, model, where it's used, fallback status, and an availability-risk rating per dependency. Markdown by default, CSV with a flag. Continuity-focused, not a compliance assessment.
Specialized static security scanner for MCP servers and Python tool handlers to prevent injection and data leaks.
First-pass screener that flags AI-generated, paper-mill, and fabricated scholarship using tortured-phrase, citation, statistical, and template detectors.
Container Security - A Premium AI Agent Skill
Api Security Scanner - A Premium AI Agent Skill
Stop leaving your AI startup exposed to malicious users trying to steal your proprietary system prompts or bypass your paywalls. The AI Prompt Injection Defense Shield is an automated code review agent that deeply analyzes your Next.js or Python backend, instantly detecting insecure LLM input fields, un-sanitized API data streams, and weak prompt boundaries. By automatically generating the exact copy-paste code patches required to harden your AI wrapper against the latest OWASP top 10 LLM vulnerabilities, this skill allows solo developers and indie hackers to confidently launch their SaaS without the fear of massive, unexpected API billing spikes or catastrophic data leaks.
Moderate toxic language, detect personal data leaks, and audit domain security configurations via MCP.
Professional accessibility auditing for architects, balancing legal regulations with real-world usability.
Audit domain health, SSL certificates, DNS records, and mail security posture via MCP.
Validates AI skills for malware and audits domain security configurations via MCP.
Classify AI content and apply official EU AI Act Article 50 disclosure labels to images programmatically.
A security auditor that detects malicious instructions, credential theft, and hidden payloads in agent skills.
Triage a vendor email, invoice, or bank-detail change request for BEC/fraud signals before you pay — mechanical CLEAR / VERIFY / HOLD verdict, honest about what it can't check.
Turns prompt edits, version notes, testing observations, failure fixes, evaluation outcomes, approval notes, and rollback details into clean prompt change logs, release notes, testing notes, version history, impact summaries, and rollback instructions for prompt-heavy teams, AI workflow owners, agencies, and product teams.
Sovereign cryptographic identity (Ed25519), message signing, and P2P trust mesh for AI agents.
Compares draft policies against expected policy sections, ownership, responsibilities, control requirements, evidence needs, review cycles, approval routes, training requirements, implementation plans, monitoring expectations, and governance gaps across HR, finance, IT, compliance, risk, operations, data protection, security, and internal control environments.
A production-grade blueprint for designing, hardening, and shipping stable, autonomous AI agents.
Audits agent skills and MCP manifests for prompt injection, data exfiltration, and over-permissioned access.
Enforce three-way IOLTA reconciliation and detect regulatory defects to prevent bar discipline.
docker-compose-linter-pro
Identify and audit EU AI Act Article 50 transparency obligations for chatbots and AI-generated content.
Audits contracts for regulatory-change triggers and maps obligations to primary monitoring sources.
Determines NIS2 scope, entity classification, and readiness gaps based on sector, size, and EU Member State law.
Audits EVM contract bytecode for honeypots, drainers, and malicious owner patterns before you interact.
dependency-health-check-pro
Turn your AI agent into a Senior Next.js 15 & React 19 Architect │ to automatically enforce strict App Router patterns, secure Server │ Actions with Zod, and eliminate performance bottlenecks.
Audits AI hiring tools against Illinois HB 3773 requirements, including ZIP code proxies and notice obligations.
Audit any Jira project in seconds. Point Claude at a Jira URL or project key and get a full 16-category health report: stale high-priority issues, unassigned tickets, sprint overflow, zombie To Dos, orphaned issues, blocker deadlocks, and more. Saves a formatted `report.md` and per-category CSVs into a timestamped folder — ready to share with your team or paste into a retro.
Converts complex contracts into structured registers with deadlines, owners, service levels, and renewal logic.
Standardizes end-to-end customer support workflows from intent identification to verified resolution.
Audit AI-generated code for hallucinations, security flaws, and architectural drift before you merge.
Detect hidden prompt injections, invisible text, and malicious metadata in Office documents.
Creates audit PBC lists, evidence request emails, document trackers, follow-up wording, request prioritisation, ownership logs, status summaries, escalation language, and audit-ready evidence collection templates for internal audit, external audit, compliance reviews, assurance teams, risk teams, and professional services engagements.
Turns process notes, walkthrough summaries, policy extracts, procedure descriptions, and audit planning notes into clear internal control narratives, process summaries, risk-control matrices, walkthrough questions, control descriptions, testing prompts, evidence requests, and documentation QA checks for auditors, compliance teams, governance teams, finance teams, and risk professionals.
Production-grade reliability and security audit for inbound and outbound webhook integrations.
Verify a versioned software release is genuinely complete.
Creates supplier due diligence questionnaires, third-party risk checks, onboarding summaries, approval notes, evidence requests, review schedules, risk ratings, monitoring actions, and supplier governance packs for procurement, compliance, finance, operations, legal, IT, information security, and vendor management teams.