690 catalog entries · 41 server-rendered examples
Testing & Security agent skills
Browse 690 open Testing & Security agent skills, including 41 server-rendered examples that agents can evaluate without JavaScript.
Search all Testing & Security skills Browse the 500-page static cohort
Server-readable Testing & Security skills
- skill-creatorCreate new skills, modify and improve existing skills, and measure skill performance. Use when users want to create a skill from scratch, edit, or optimize an existing skill, run evals to test a skill
- android_ui_verificationAutomated end-to-end UI testing and verification on an Android Emulator using ADB.
- antigravity-workflowsOrchestrate multiple Antigravity skills through guided workflows for SaaS MVP delivery, security audits, AI agent builds, and browser QA.
- api-fuzzing-bug-bountyProvide comprehensive techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing engagements. Covers vulnerability discovery, authentication bypass, IDOR exp
- api-security-testingAPI security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.
- audit-context-buildingEnables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.
- aws-security-auditComprehensive AWS security posture assessment using AWS CLI and security best practices
- azure-cosmos-db-pyBuild production-grade Azure Cosmos DB NoSQL services following clean code, security best practices, and TDD principles.
- azure-resource-manager-playwright-dotnetAzure Resource Manager SDK for Microsoft Playwright Testing in .NET.
- azure-security-keyvault-keys-javaAzure Key Vault Keys Java SDK for cryptographic key management. Use when creating, managing, or using RSA/EC keys, performing encrypt/decrypt/sign/verify operations, or working with HSM-backed keys.
- bash-scriptingBash scripting workflow for creating production-ready shell scripts with defensive patterns, error handling, and testing.
- bats-testing-patternsMaster Bash Automated Testing System (Bats) for comprehensive shell script testing. Use when writing tests for shell scripts, CI/CD pipelines, or requiring test-driven development of shell utilities.
- burp-suite-testingExecute comprehensive web application security testing using Burp Suite's integrated toolset, including HTTP traffic interception and modification, request analysis and replay, automated vulnerability
- burpsuite-project-parserSearches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with regex patterns, extracting security audit findings, dumping proxy histo
- cicd-automation-workflow-automateYou are a workflow automation expert specializing in creating efficient CI/CD pipelines, GitHub Actions workflows, and automated development processes. Design and implement automation that reduces man
- codebase-audit-pre-pushDeep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. Checks every file line-by-line for production readiness.
- codebase-cleanup-deps-auditYou are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, ou
- comprehensive-review-pr-enhanceGenerate structured PR descriptions from diffs, add review checklists, risk assessments, and test coverage summaries. Use when the user says "write a PR description", "improve this PR", "summarize my
- data-quality-frameworksImplement data quality validation with Great Expectations, dbt tests, and data contracts. Use when building data quality pipelines, implementing validation rules, or establishing data contracts.
- dependency-management-deps-auditYou are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, ou
- dependency-upgradeMaster major dependency version upgrades, compatibility analysis, staged upgrade strategies, and comprehensive testing approaches.
- deployment-validation-config-validateYou are a configuration management expert specializing in validating, testing, and ensuring the correctness of application configurations. Create comprehensive validation schemas, implement configurat
- differential-reviewSecurity-focused code review for PRs, commits, and diffs.
- ethical-hacking-methodologyMaster the complete penetration testing lifecycle from reconnaissance through reporting. This skill covers the five stages of ethical hacking methodology, essential tools, attack techniques, and profe
- ffuf-web-fuzzingExpert guidance for ffuf web fuzzing during penetration testing, including authenticated fuzzing with raw requests, auto-calibration, and result analysis
- file-uploadsCareful about security and performance. Never trusts file extensions. Knows that large uploads need special handling. Prefers presigned URLs over server proxying.
- find-bugsFind bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.
- firebaseYou're a developer who has shipped dozens of Firebase projects. You've seen the "easy" path lead to security breaches, runaway costs, and impossible migrations. You know Firebase is powerful, but you
- firmware-analystExpert firmware analyst specializing in embedded systems, IoT security, and hardware reverse engineering.
- fix-reviewVerify fix commits address audit findings without new bugs
- fixing-motion-performanceAudit and fix animation performance issues including layout thrashing, compositor properties, scroll-linked motion, and blur effects. Use when animations stutter, transitions jank, or reviewing CSS/JS
- gha-security-reviewFind exploitable vulnerabilities in GitHub Actions workflows. Every finding MUST include a concrete exploitation scenario — if you can't build the attack, don't report it.
- git-hooks-automationMaster Git hooks setup with Husky, lint-staged, pre-commit framework, and commitlint. Automate code quality gates, formatting, linting, and commit message enforcement before code reaches CI.
- git-pr-workflows-git-workflowOrchestrate a comprehensive git workflow from code review through PR creation, leveraging specialized agents for quality assurance, testing, and deployment readiness. This workflow implements modern g
- git-pr-workflows-pr-enhanceYou are a PR optimization expert specializing in creating high-quality pull requests that facilitate efficient code reviews. Generate comprehensive PR descriptions, automate review processes, and ensu
- graphql-architectMaster modern GraphQL with federation, performance optimization, and enterprise security. Build scalable schemas, implement advanced caching, and design real-time systems.
- html-injection-testingIdentify and exploit HTML injection vulnerabilities that allow attackers to inject malicious HTML content into web applications. This vulnerability enables attackers to modify page appearance, create
- infinite-gratitudeMulti-agent research skill for parallel research execution (10 agents, battle-tested with real case studies).
- java-proMaster Java 21+ with modern features like virtual threads, pattern matching, and Spring Boot 3.x. Expert in the latest Java ecosystem including GraalVM, Project Loom, and cloud-native patterns.
- kotlin-coroutines-expertExpert patterns for Kotlin Coroutines and Flow, covering structured concurrency, error handling, and testing.
- laravel-security-auditSecurity auditor for Laravel applications. Analyzes code for vulnerabilities, misconfigurations, and insecure practices using OWASP standards and Laravel security best practices.