Labsco

Agent Skills

Instruction packs that give your AI agent know-how — some work anywhere, some only with the tool they came with.

Security

46 standalone skills
github logo

ai-prompt-engineering-safety-review

✓★ 36,202

by github

Comprehensive AI prompt engineering safety review and improvement prompt. Analyzes prompts for safety, bias, security vulnerabilities, and effectiveness while providing detailed improvement recommendations with extensive frameworks, testing methodologies, and educational content.

🔥🔥🔥🔥✓ VerifiedFreeQuick setup
openai logo

security-ownership-map

✓★ 23,283

by openai

Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. Trigger only when the user explicitly wants a security-oriented ownership or bus-factor analysis grounded in git history (for example: orphaned sensitive code, security maintainers, CODEOWNERS reality checks for risk, sensitive hotspots, or ownership clusters). Do not trigger for general maintainer lists or n

🔥🔥🔥✓ VerifiedFreeQuick setup
openai logo

security-best-practices

✓★ 23,283

by openai

Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.

🔥🔥🔥🔥✓ VerifiedFreeQuick setup
openai logo

security-scan

✓★ 4,081

by openai

Use when the user asks for a repository-wide or scoped-path security scan.

openai logo

threat-model

✓★ 4,081

by openai

Use when Codex is already in the threat-modeling phase of a security scan, the user explicitly invokes $threat-model, or the user explicitly asks to create, update, or persist a repository threat model. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

openai logo

twilio-security-compliance-hipaa

✓★ 4,081

by openai

Configure Twilio accounts for HIPAA compliance. Covers BAA requirements, HIPAA Project designation (self-service and support), eligible services list, per-product requirements (Voice, SMS, ConversationRelay, Conversation Intelligence, Flex, Verify), message redaction, and what is NOT eligible. Use this skill when developers are building healthcare workflows on Twilio.

openai logo

validation

✓★ 4,081

by openai

Use when Codex is already in the validation phase of a security scan or the user explicitly asks to determine whether one or more candidate security findings are valid. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

openai logo

vercel-firewall

✓★ 4,081

by openai

Vercel Firewall and security expert guidance. Use when configuring DDoS protection, WAF rules, rate limiting, bot filtering, IP allow/block lists, OWASP rulesets, Attack Challenge Mode, or any security configuration on the Vercel platform.

openai logo

security-diff-scan

✓★ 4,081

by openai

Use when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set.

openai logo

triage-finding

✓★ 4,081

by openai

Use when the user supplies or imports existing security findings, vulnerability reports, or security/vulnerability Jira/Linear tickets from scanners, advisories, GitHub, Atlassian Rovo, Linear, or similar backlog sources and wants static repo-impact triage. Do not use for discovery, duplicate-bug triage, validation, or fixes.

openai logo

track-findings

✓★ 4,081

by openai

Track validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories. Use it for one finding or an explicitly selected batch of up to 25 findings tracked as Linear, Jira, or GitHub issues. Includes duplicate checks, exact previews, approval-gated writes, and readback. Do not use it for scans or fixes.

openai logo

deep-security-scan

✓★ 4,081

by openai

Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated independent discovery passes over one resolved scope with worker-specific threat models, semantically merge candidates, synthesize one canonical validation threat model, then run validation, attack-path analysis, canonical JSON completion, and generated reporting once. Do not use for PRs, commits, branch diffs, or working-tree diffs.

openai logo

attack-path-analysis

✓★ 4,081

by openai

Use when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

openai logo

finding-discovery

✓★ 4,081

by openai

Use when Codex is already in the finding-discovery phase of a security scan or the user explicitly asks to discover candidate security findings in a repository or code change. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

openai logo

twilio-security-hardening

✓★ 4,081

by openai

Secure Twilio applications against common attacks. Covers credential management (API keys vs auth tokens), request validation (webhook signature verification), PCI DSS compliance, HIPAA account requirements, SMS pumping prevention, geo-permissions, and account isolation patterns. Use this skill when developers are building or deploying Twilio apps.

openai logo

twilio-security-api-auth

✓★ 4,081

by openai

Choose the right Twilio authentication method and implement it correctly. Covers Auth Token (testing only), API Keys (production standard), OAuth2 client_credentials (time-limited bearer tokens), Access Tokens (client-side SDKs), and test credentials. Use this skill before making any Twilio API calls in production.

openai logo

code-review

✓★ 4,081

by openai

Reviews code changes using CodeRabbit AI. Use when user asks for code review, PR feedback, code quality checks, security issues, or requests fix-review cycles.

openai logo

fix-finding

✓★ 4,081

by openai

Use when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

github logo

code-checklist

✓★ 2,713

by github

Team code quality checklist - use for checking Python code quality, bugs, security issues, and best practices

🔥🔥✓ VerifiedFreeQuick setup
microsoft logo

supply-chain-security

✓★ 1,245

by microsoft

Software supply chain security reference for OpenSSF Scorecard, SLSA, Sigstore, SBOM, and posture/backlog taxonomies.

microsoft logo

security-planning

✓★ 1,245

by microsoft

Security planning reference set for operational buckets, STRIDE analysis, standards mapping, NIST control families, and backlog scaffolding.

microsoft logo

owasp-agentic

✓★ 1,245

by microsoft

OWASP Agentic Security Top 10 knowledge base for identifying, assessing, and remediating AI agent system security risks.

🔥🔥🔥🔥✓ VerifiedFreeQuick setup
microsoft logo

backlog-templates

✓★ 1,245

by microsoft

Shared work-item templates and conventions for ADO and GitHub backlog handoff across the RAI, Security, SSSC, Accessibility, and Privacy planners

microsoft logo

owasp-mcp

✓★ 1,245

by microsoft

OWASP MCP Top 10 knowledge base for identifying, assessing, and remediating Model Context Protocol security risks.

🔥🔥🔥🔥✓ VerifiedFreeQuick setup
dbt-labs logo

auditing-skills

★ 608

by dbt-labs

Use when checking skills for security or quality issues, reviewing audit results from skills.sh or Tessl, or remediating findings across published skills.

🔥🔥🔥✓ VerifiedFreeQuick setup
microsoft logo

security-review

✓★ 413

by microsoft

Runs a guided, end-to-end security review of a Power Pages site and consolidates every finding into one HTML report covering the live site, browser headers, firewall, authentication, and role-based permissions. Use when the user wants a full security review, a release-readiness check before publishing, an access-and-config check during development, live site monitoring, or asks open-ended questions like "review my site security", "is my site safe to ship", "do a security check", "monitor my site

microsoft logo

audit-permissions

✓★ 413

by microsoft

Audits existing table permissions on a Power Pages site by analyzing them against site code and Dataverse metadata. Generates an HTML audit report with findings grouped by severity (critical, warning, info, pass) and suggests fixes for issues found. Use when the user wants to review, verify, or check table permissions for security issues.

🔥🔥FreeQuick setup
microsoft logo

manage-headers

✓★ 413

by microsoft

Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related site settings. Identifies gaps and walks the user through fixes. Use when the user wants to review headers, fix CSP errors, allow embedding in another site, control cross-origin access, harden cookie settings, or asks "are my browser settings safe?", "fix my CSP", "set up CORS" — even if they only mentio

microsoft logo

dv-security

✓★ 163

by microsoft

Security-role assignment, user access, application users, business units, and admin self-elevation in Dataverse environments. Use when the user wants to give someone access, grant a role, become an admin, or add a service principal.

🔥🔥🔥✓ VerifiedFreeQuick setup
microsoft logo

dv-overview

✓★ 163

by microsoft

Tool routing and cross-cutting rules for Dataverse work — which skill applies to which task, environment-confirmation, and pull-to-repo. Use when the user mentions Dataverse, Dynamics 365, Power Platform, or CRM; this skill picks the specialist (dv-connect / dv-data / dv-metadata / dv-query / dv-solution / dv-admin / dv-security) for the request.

🔥🔥✓ VerifiedFreeQuick setup
Page 1 of 2Next →