skillshop-ostyles avatar

agents-security

v1.0.0

by skillshop-ostyles

agents-security is an Agent Plugin published by skillshop-ostyles. It packages 21 skills. We fetched the plugin.json from GitHub on 2026-10-05 and checked it against the official Agent Plugins 1.0.0 schema.

Security analysis skills: trust boundaries, secrets, authorization, input validation.

Skills
21
MCP servers
0
Stars
0
License
MIT
Repo created
2026-07-22
Last pushed
2026-08-22
Publisher type
User
Version
1.0.0

Links

Skills · 21

api-contract-guardian
API contract guard: extracts the API surface (HTTP routes with params, DTO fields, exported signatures, preferring OpenAPI files when present) from two git states of a repo, diffs them, classifies every change as breaking / non-breaking / additive, and writes a ready-to-ship consumer migration not…
authorization-xray
Authorization X-ray for your own codebase (defensive audit): inventories every HTTP endpoint and every recognizable protection layer (middleware chains, authorize decorators, inline role checks, router mounts), builds the permission matrix endpoint x required check, and reports unprotected mutating…
authz-coverage-gap-detector
Finds mutating endpoints that lack explicit authorization, relying solely on middleware inheritance, the dangerous gaps where middleware failure leaves endpoints unprotected. Read-only. Audience: Senior. Trigger: /authz-coverage
config-cartographer
Configuration cartographer: maps a system's complete config surface, every env var, setting and flag, where it is defined (.env, yaml/json configs, compose, Dockerfile) versus where it is read in code, and reports read-but-never-defined keys (crash candidates), defined-but-never-read orphans and…
cors-config-drift
CORS config drift scanner: harvests every Access-Control-Allow-Origin header, cors()-middleware call, @cross_origin decorator, options-handler with cors config, and per-route origin/credentials settings. LLM analyses each per-route CORS posture: credentials+wildcard = fatal, permissive origin patte…
crypto-downgrade-detector
Crypto downgrade detector: harvests every weak-algorithm usage (MD5, SHA1, DES, 3DES, RC4, ECB, CBC, deprecated createCipher), modern alternatives (subtle.encrypt, bcrypt, argon2, scrypt, PBKDF2), JWT signing-config (hardcoded-secret vs asymmetric key), cert/key-generation calls, and patch/version-…
data-trail-tracker
Maps PII fields and their sinks, logs, third-party APIs, exports, purely via field names, never via actual data. Trigger: /data-trail-tracker
dep-inheritance
Dependency inheritance audit: for every direct dependency answers the questions nobody asks, why is it here (from actual usage sites), how deep is the coupling, how replaceable is it, and what is the concrete exit plan. Parses manifests/lockfiles, scans usage, optionally enriches with registry met…
error-message-leakage
Error message leakage detector: harvests every HTTP-error-return and log-error-call, classifies what kind of information leaks (stacktrace, SQL error message, env-vars, user input echo, request dump). LLM validates each finding as legitimate production-leak and proposes sanitization. Read-only. Aud…
flask-anti-pattern-detector
Flask anti-pattern detector: scans Flask projects for hardcoded SECRET_KEY, debug-mode in production, dangerous template rendering (render_template_string), pickle/eval/exec on request data, unsafe session config, SQL injection via raw queries, insecure file upload, and debug toolbar enabled. LLM v…
input-validation-audit
Input validation audit: statically detects all input surfaces (HTTP params, CLI args, env vars, file reads, stdin) across a codebase, classifies their validation state (none/weak/adequate), and flags high-risk gaps. Produces an evidence-backed report with severity, location, and remediation suggest…
log-injection-detector
Log injection detector: harvests every console.log/logger.info/log.Error/etc call, classifies arguments for attacker-controlled input (CWE-117), CRLF injection surface, sensitive data leakage (passwords, tokens, secrets). LLM validates each finding as injectable and proposes sanitization (parameter…
permission-chain
rate-limit-shape-analyzer
secret-lifecycle-auditor
security-smell-scanner
session-state-anomaly
ssrf-detector
third-party-trust
tls-config-drift
type-confusion-bypass-detector

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.

Category

Security & Compliance. Assigned by this directory. Agent Plugins 1.0.0 has no category field, so no manifest declares one.

Keywords

agent-skills · security · secrets · authorization

Related by publisher and keywords

  • agents-ai-mlskillshop-ostyles

    AI/ML pipeline skills: prompts, LLM costs, RAG, embeddings, guardrails.

  • agents-dataskillshop-ostyles

    Data layer skills: schemas, migrations, fixtures, and query patterns.

  • agents-operationsskillshop-ostyles

    Operations and SRE skills: deployment, resilience, backups, CI health.

  • agents-qualityskillshop-ostyles

    Code quality, smells, refactoring signals, and consistency skills.

  • agents-runtimeskillshop-ostyles

    Runtime analysis skills: performance, startup, concurrency, production parity.

  • agents-understandingskillshop-ostyles

    Codebase understanding skills: architecture, onboarding, knowledge preservation.

Add the verified badge to your README[![Verified by AgentPluginsDirectory.com against Schema 1.0.0](https://agentpluginsdirectory.com/badge.svg)](https://agentpluginsdirectory.com/plugins/agents-security)

✓ Verified . We fetched the manifest from GitHub and checked it against the official Agent Plugins 1.0.0 schema at agent-plugins.org.