Labsco

Agent Skills

Instruction packs that give your AI agent know-how — some work anywhere, some only with the tool they came with.

posthog · Finance

10 standalone skills
github logo

agent-owasp-compliance

✓★ 36,202

by github

Check any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks. Use this skill when: - Evaluating an agent system's security posture before production deployment - Running a compliance check against OWASP ASI 2026 standards - Mapping existing security controls to the 10 agentic risks - Generating a compliance report for security review or audit - Comparing agent framework security features against the standard - Any request like "is my agent OWASP compliant?", "chec

🔥🔥🔥🔥✓ VerifiedFreeNeeds API keys
github logo

postgresql-code-review

✓★ 36,202

by github

PostgreSQL-specific code review assistant focusing on PostgreSQL best practices, anti-patterns, and unique quality standards. Covers JSONB operations, array usage, custom types, schema design, function optimization, and PostgreSQL-exclusive security features like Row Level Security (RLS).

🔥🔥🔥🔥✓ VerifiedFreeQuick setup
github logo

security-review

✓★ 36,202

by github

AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching tools miss. Use this skill when asked to scan code for security vulnerabilities, find bugs, check for SQL injection, XSS, command injection, exposed API keys, hardcoded secrets, insecure dependencies, access control issues, or any request like "is my code secure?", "review for security issues", "audi

🔥🔥🔥🔥✓ VerifiedFreeQuick setup
microsoft logo

azure-security-keyvault-keys-dotnet

✓★ 2,676

by microsoft

Azure Key Vault Keys SDK for .NET. Client library for managing cryptographic keys in Azure Key Vault and Managed HSM. Use for key creation, rotation, encryption, decryption, signing, and verification. Triggers: "Key Vault keys", "KeyClient", "CryptographyClient", "RSA key", "EC key", "encrypt decrypt .NET", "key rotation", "HSM".

🔥🔥🔥✓ VerifiedFreeQuick setup
microsoft logo

azure-keyvault-py

✓★ 2,676

by microsoft

Azure Key Vault SDK for Python. Use for secrets, keys, and certificates management with secure storage. Triggers: "key vault", "SecretClient", "KeyClient", "CertificateClient", "secrets", "encryption keys".

🔥🔥🔥🔥✓ VerifiedFreeQuick setup
microsoft logo

azure-security-keyvault-keys-java

✓★ 2,676

by microsoft

Azure Key Vault Keys Java SDK for cryptographic key management. Use when creating, managing, or using RSA/EC keys, performing encrypt/decrypt/sign/verify operations, or working with HSM-backed keys.

🔥🔥🔥✓ VerifiedFreeQuick setup
microsoft logo

owasp-infrastructure

✓★ 1,245

by microsoft

OWASP Infrastructure Top 10 knowledge base for identifying, assessing, and remediating internal IT infrastructure security risks.

🔥🔥🔥🔥✓ VerifiedFreeQuick setup
microsoft logo

owasp-top-10

✓★ 1,245

by microsoft

OWASP Top 10 for Web Applications (2025) knowledge base for identifying, assessing, and remediating web application security risks.

🔥🔥🔥🔥✓ VerifiedFreeQuick setup
zxkane logo

aws-cost-operations

★ 327

by zxkane

AWS cost optimization, monitoring, and operational excellence expert. Use when analyzing AWS bills, estimating costs, setting up CloudWatch alarms, querying logs, auditing CloudTrail activity, or assessing security posture. Essential when user mentions AWS costs, spending, billing, budget, pricing, CloudWatch, observability, monitoring, alerting, CloudTrail, audit, or wants to optimize AWS infrastructure costs and operational efficiency.

🔥🔥🔥✓ VerifiedFreeQuick setup
semgrep logo

code-security

★ 232

by semgrep

Security guidelines for writing secure code. Use when writing code, reviewing code for vulnerabilities, or asking about secure coding practices like 'check for SQL injection' or 'review security'. IMPORTANT: Always consult this skill when writing or reviewing any code that handles user input, authentication, file operations, database queries, network requests, cryptography, or infrastructure configuration (Terraform, Kubernetes, Docker, GitHub Actions) — even if the user doesn't explicitly menti

🔥🔥🔥🔥✓ VerifiedFreeQuick setup