sast-configuration
by LocoLoboZ
Automate the setup and optimization of Semgrep, SonarQube, and CodeQL for high-signal security testing.
New: Software for Agents, always up-to-date, delivered via MCP or web. Browse
THE AGENSI STORE
20 skills found
by LocoLoboZ
Automate the setup and optimization of Semgrep, SonarQube, and CodeQL for high-signal security testing.
by Shandra
Turns dependency scan reports and security alerts into prioritized remediation plans with severity, exploitability, affected area, safe fix strategy, and verification checklists.
A specialized security architect skill for performing deep audits, compliance checks, and DevSecOps integrations.
by LocoLoboZ
Generate structured, scored attack trees with AND/OR logic to visualize threat paths and identify security gaps.
by LocoLoboZ
Convert cyber incident evidence into blameless post-mortem reports, root cause analyses, and action trackers.
by Liam Romanis
Automated detection and remediation auditing for the CVE-2026-46243 "CIFSwitch" Linux privilege escalation vulnerability.
by Liam Romanis
Detect and remediate CVE-2026-45185 "Dead.Letter" RCE vulnerabilities in Exim mail servers.
by LocoLoboZ
Professional-grade security assessment framework for IoT, OT, and connected device ecosystems.
by Liam Romanis
Detect and assess CVE-2026-31431 "Copy Fail" vulnerability on Linux systems and Kubernetes clusters.
One-line summary description Stop your agent from claiming "done" before it's proven. A verification gate that classifies each change by risk (payment, auth, database, user-facing), picks the tests that actually cover it, demands evidence, maps regression risk, and outputs an honest pass/fail report. Turns "looks good to me" into "here's what I ran, and here's what's still unverified."
An adversarial gate that audits cloud and infrastructure-as-code config — Terraform, Kubernetes, IAM, security groups, buckets — for the misconfigurations that cause real breaches, and returns a structured PASS/REVISE/BLOCK verdict with severities and exact fixes before anything reaches your environment.
by Liam Romanis
Deep audit and detection of the Dirty Frag (CVE-2026-43284/43500) Linux privilege escalation exploit chain.
Audit the decoded text a QR code carries before you print it on something. Flags URLs that are not absolute, link shorteners that hide the real destination, unsafe schemes (javascript:, data:, file:), payloads too long to scan reliably, malformed Wi-Fi or contact payloads, and exposed credentials like a Wi-Fi password or a token sitting in a URL. It audits the decoded payload you paste; it does not read images.
A DevSecOps engineer that stands up and tunes static analysis (Semgrep, SonarQube, CodeQL) for high-signal findings — picks the right tool for the stack, writes the config and rulesets, wires a sane CI gate, and tunes out the false positives that get scanners muted.
by Timoranjes
Evaluate third-party agent skills for command injection, prompt injection, and data exfiltration before installation.
Adversarially audit your agent hooks before you trust them. Catches command injection, secret leakage, over-broad matchers, destructive actions, and blocking-logic mistakes in pre/post-tool-use, prompt, and stop hooks — with a PASS or REVISE verdict and severity-ranked fixes.
by Roy Yuen
Prevent vulnerabilities before they happen by forcing early security framing and secure-by-default design patterns.
by Sinu
Senior-level DevOps automation for CI/CD, IaC, Kubernetes, and production-ready GitOps pipelines.
by Joker
Enterprise security with NIST/ISO27001/zero-trust frameworks. Threat modeling, GDPR compliance, DevSecOps guidance.
by Timoranjes
Structured security auditing for AI agent skills to detect prompt injection, data exfiltration, and malicious commands.