com um clique
appsec-agent-skills
appsec-agent-skills contém 8 skills coletadas de XavierEr, com cobertura ocupacional por repositório e páginas de detalhe dentro do site.
Skills neste repositório
Validates API specifications against actual endpoint behavior. Tests any HTTP API regardless of backend technology.
Maps security findings to compliance frameworks (OWASP Top 10, CWE, NIST SP 800-53, PCI DSS, SANS/CWE Top 25, ISO 27001) and generates audit-ready compliance reports
Dynamic Application Security Testing - sends crafted HTTP requests to running web server endpoints to detect vulnerabilities
Scan dependency manifests for known CVEs across multiple programming ecosystems
General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis. Trigger when the user asks to: "analyze code for vulnerabilities", "review code security", "find security bugs", "do a SAST scan", "check for [vulnerability type] in code", "audit source code", or requests a security code review of any language or framework. Covers 34 vulnerability classes across web, API, auth, mobile, and logic layers.
Remediation validation skill that re-runs targeted scans after fixes to confirm vulnerabilities are resolved and detect regressions. Trigger when the user asks to: "verify a fix", "validate remediation", "confirm a vulnerability is resolved", "re-scan after fixing", "check if a patch works", "did my fix work", "validate the security fix", "re-test after remediation", or "check for regressions after the fix".
Master orchestrator skill for comprehensive security auditing. Auto-detects the project's technology stack and selectively invokes applicable security scanning skills. Produces a unified report with context-aware remediation. Trigger when the user asks for: "security audit", "full security scan", "comprehensive vulnerability assessment", "scan this project for security issues", "run all security checks", "full pentest", or any request for a broad, multi-dimensional security review.
Reviews infrastructure and configuration files for security misconfigurations across Docker, Kubernetes, CI/CD pipelines, web frameworks, and secrets management.