New: Skill bounties are live. Post a request, fund the bounty, and creators compete for 7 days to build it -> See open bounties

    Browse The Skill Store

    254 skills found

    🔐 Email Auth Deliverability Doctor

    by JustHandled Labs

    $12

    Audit your SPF, DKIM, and DMARC records for the misconfigurations that get mail rejected or sent to spam. Flags a missing DMARC record or p=none, missing rua reporting, a missing or duplicated SPF record, SPF over the 10-lookup limit, permissive +all/?all, a missing DKIM selector, and SPF/DKIM domain-alignment mismatches. Paste a DNS zone file or dig/nslookup output.

    1
    0

    Cloud & Infrastructure Config Security Gate

    by PubsProToolkit

    Free

    An adversarial gate that audits cloud and infrastructure-as-code config — Terraform, Kubernetes, IAM, security groups, buckets — for the misconfigurations that cause real breaches, and returns a structured PASS/REVISE/BLOCK verdict with severities and exact fixes before anything reaches your environment.

    1
    0

    🔳 QR Payload Auditor

    by JustHandled Labs

    $5

    Audit the decoded text a QR code carries before you print it on something. Flags URLs that are not absolute, link shorteners that hide the real destination, unsafe schemes (javascript:, data:, file:), payloads too long to scan reliably, malformed Wi-Fi or contact payloads, and exposed credentials like a Wi-Fi password or a token sitting in a URL. It audits the decoded payload you paste; it does not read images.

    1
    0

    WordPress Accessibility Auditor

    by Arnstein Larsen

    $13.99

    A structured WCAG 2.1 AA audit and fix agent for WordPress themes, organized by block theme, Gutenberg, forms, and navigation context, with scored findings and complete before-to-after code patches.

    1
    0

    Security Audit & Compliance Toolkit

    by Arnstein Larsen

    $12.99

    A professional-grade toolkit for SAST code reviews, PII scanning, and automated compliance gap analysis.

    1
    0

    nex multitenant saas fastapi

    by Nex AI

    $9

    Prevent data leaks with auto-injected SQLAlchemy tenant scoping and Cloudflare Access auth for FastAPI SaaS apps.

    6
    0

    dockerfile hardener

    by Timoranjes

    Free

    A security auditor that identifies Docker vulnerabilities, scores configurations, and generates hardened replacements.

    1
    2

    PII & Privacy Leak Gate

    by PubsProToolkit

    Free

    An adversarial security gate to detect and redact PII, secrets, and confidential data before sending prompts.

    1
    0

    AI Disclosure & Provenance Gate

    by PubsProToolkit

    Free

    An adversarial gate to verify AI-use disclosures and draft compliant provenance statements for any venue.

    1
    0

    cve 2026 31431 copy fail

    by Liam Romanis

    $5

    Detect and assess CVE-2026-31431 "Copy Fail" vulnerability on Linux systems and Kubernetes clusters.

    2
    0

    ai act transparency pack

    by Nex AI

    $9/mo

    Automate EU AI Act transparency audits, Article 50 disclosures, and AI literacy documentation for your apps.

    5
    0

    code repair spine

    by GTDataworks

    Free

    Generate source-safe repository audits and repair handoff bundles without mutating your code.

    1
    2

    cve 2026 43284 dirty frag

    by Liam Romanis

    $5

    Deep audit and detection of the Dirty Frag (CVE-2026-43284/43500) Linux privilege escalation exploit chain.

    2
    0

    skill hardening certifier

    by Nex AI

    $7

    A rule-based security scanner and auto-hardener for AI agent skills to detect injections and unsafe code.

    6
    0

    ai agent production hardening kit

    by Arnstein Larsen

    $19

    Transform fragile AI prototypes into resilient, enterprise-ready production agents with professional hardening tools.

    1
    0

    Human Oversight Evidence Pack

    by PubsProToolkit

    Free

    Generate structured, audit-ready evidence logs documenting human review of AI-assisted work products.

    1
    0

    nex resend belgian compliance

    by Nex AI

    $7

    Stop AI hallucinations in cold email with server-side legal footers and Belgian GDPR compliance guardrails.

    6
    0

    agent skill security auditor

    by Timoranjes

    $0

    Evaluate third-party agent skills for command injection, prompt injection, and data exfiltration before installation.

    2
    0

    Auth System Designer

    by Arnstein Larsen

    $9.99

    Auth is where one wrong early decision becomes a security incident with your name on it — JWTs chosen for sessions because a tutorial used them, refresh token rotation implemented wrong, RBAC bolted on after the fact

    1
    0

    epb dossier checklist

    by Nex AI

    $5

    Structures Belgian EPB energy performance obligations into actionable checklists and responsibility matrices.

    4
    0

    toegankelijkheid audit

    by Nex AI

    $7

    Professional accessibility auditing for architects, balancing legal regulations with real-world usability.

    4
    0

    Dockerfile & Container Build Sanity Gate

    by PubsProToolkit

    Free

    An adversarial reviewer for Dockerfiles and container builds. It flags root users, image bloat, unpinned or cache-busting layers, leaked secrets, and missing hardening, then returns a PASS / FIX / BLOCK verdict — before you build or push the image.

    1
    0

    Dependency & Supply Chain Risk Gate

    by PubsProToolkit

    Free

    Audit your project's dependencies for supply-chain risk before they ship. Detects the ecosystem, runs the right vulnerability scanners against live advisory data, and adds the checks tooling misses — outdated or abandoned packages, typosquatted or suspicious names, risky install scripts, and license conflicts — then returns a prioritized fix list and a PASS / REVIEW / BLOCK verdict. It's npm audit with triage and judgment on top.

    1
    0

    ⚠️ Dangerous Command Linter

    by JustHandled Labs

    $12

    Flag the destructive operations in a shell command or script before anyone runs it. Catches recursive force deletes, force pushes and history rewrites, database drops and truncates, disk-wipe commands (mkfs, dd to a device), permission blowouts (chmod 777), remote content piped into a shell, broad wildcard deletes, and prod-targeting or disabled-safety flags. Each finding comes with a severity and a safer alternative.

    1
    0