Bounty Security Pattern Master Library — 399 Vulnerability Patterns
A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.
New: USDC payouts with Zoneless. Creators get paid in USDC on Solana -> Set up payouts
THE AGENSI STORE
96 skills found
A premium library of 399 vulnerability patterns and DeFi attack vectors for AI-driven bug hunting and security audits.
by Roy Yuen
Audit AI agent skills for security risks, packaging errors, and marketplace readiness with professional reports.
by Roy Yuen
Automated governance and risk audit for AI agent tool permissions and authentication boundaries.
by Roy Yuen
Automated security and compatibility firewall for installing AI agent skills and Codex/OpenClaw packages.
Scan AI agent skill definitions for malicious instructions, prompt injections, and security risks—locally.
by Roy Yuen
A modular governance framework for AI policy, agent risk assessment, human-in-the-loop approvals, and audit trails.
A security gate that intercepts sensitive agent actions like payments and deletes for mandatory human approval.
by tudor
Build a full-stack AI chatbot trained on your own documents across any industry — legal, healthcare, e-commerce, HR, finance, real estate, insurance, education, cybersecurity, government, and more.
Penetration-test your Claude Code agent's guardrails before you deploy. Throws prompt-injection payloads, shell-chaining, and path-traversal attempts at your PreToolUse/PostToolUse hooks and sensitive-file protections, then returns a pass/fail report on 10+ attack vectors with copy-paste remediation for every gap.
by Edric Vale
Safe dependency upgrade plans: changelog-aware risk scoring, test hints, and rollback paths.
An adversarial senior engineer review gate that audits AI-written code for security gaps and logic errors before shipping.
by Timoranjes
Comprehensive security auditing for AI agents, covering prompt injection, tool permissions, and data leakage risks.
Analyzes AI agents for performance, reliability, security, and optimization opportunities.
Systematic audit for AI prompts to detect security flaws, bias, and cost-inefficiencies with auto-optimization.
by Timoranjes
The security auditor for AI agents. Detect prompt injection, secret leaks, and unsafe tool access in SKILL.md files.
An adversarial security gate that audits untrusted content — web pages, tool outputs, documents, emails — for embedded instructions, exfiltration, and authority spoofing, then returns a SAFE/REVIEW/BLOCK verdict.
An adversarial gate that audits an MCP server or agent tool definition — schemas, descriptions, scopes, auth — for tool poisoning, excessive agency, injectable descriptions, and missing access controls, then returns one SAFE/REVIEW/BLOCK verdict.
by Nex AI
A rule-based security scanner and auto-hardener for AI agent skills to detect injections and unsafe code.
Transform fragile AI prototypes into resilient, enterprise-ready production agents with professional hardening tools.
by Timoranjes
Evaluate third-party agent skills for command injection, prompt injection, and data exfiltration before installation.
by GTDataworks
Run a buyer-readiness check before publishing an AI agent skill package.
Messy, insecure, unfixable — that's what AI builds without architecture. This file is the architecture: 10 years of senior judgement on rendering, caching, security and SEO, so your agent builds it right from day one.
Stop leaving your AI startup exposed to malicious users trying to steal your proprietary system prompts or bypass your paywalls. The AI Prompt Injection Defense Shield is an automated code review agent that deeply analyzes your Next.js or Python backend, instantly detecting insecure LLM input fields, un-sanitized API data streams, and weak prompt boundaries. By automatically generating the exact copy-paste code patches required to harden your AI wrapper against the latest OWASP top 10 LLM vulnerabilities, this skill allows solo developers and indie hackers to confidently launch their SaaS without the fear of massive, unexpected API billing spikes or catastrophic data leaks.
Scaffold a secure, spec-compliant MCP server from a description of the tools you want to expose. Sets up the official SDK (TypeScript or Python/FastMCP), defines tools/resources/prompts with strict JSON Schema, wires the right transport (stdio or Streamable HTTP), adds OAuth 2.1 for remote, and hardens against the MCP-specific footguns — prompt injection via tool output, token passthrough, over-broad scopes, command/path/SSRF injection, leaked secrets — before it ships. Returns a runnable skeleton plus a security checklist. Built by someone who's shipped production MCP servers.