Security Principles

2.5k
exceptionlessexceptionless

Security best practices for the Exceptionless codebase. Secrets management, input validation, secure defaults, and avoiding common vulnerabilities. Keywords: security, secrets, encryption, PII, logging, input validation, secure defaults, environment variables, OWASP, cryptography

193 days ago

secure-code-guardian

1.8k
openclawopenclaw

Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities. Invoke for authentication, authorization, input validation, encryption, OWASP Top 10 prevention.

193 days ago

clawphone

1.8k
openclawopenclaw

Encrypted Clawdbot-to-Clawdbot messaging. Send messages to friends' Clawdbots with end-to-end encryption.

193 days ago

clawlink

1.8k
openclawopenclaw

Encrypted Clawbot-to-Clawbot messaging. Send messages to friends' Clawbots with end-to-end encryption.

193 days ago

azure-keyvault-py

1.8k
openclawopenclaw

Azure Key Vault SDK for Python. Use for secrets, keys, and certificates management with secure storage. Triggers: "key vault", "SecretClient", "KeyClient", "CertificateClient", "secrets", "encryption keys".

193 days ago

cryptowallet

1.8k
openclawopenclaw

Complete cryptocurrency wallet management for Web3, DeFi, and blockchain applications. Create and manage EVM (Ethereum, Polygon, BSC, Arbitrum, Optimism, Base, Avalanche) and Solana wallets with encrypted local storage. Query balances for native tokens (ETH, MATIC, BNB, SOL) and standard tokens (ERC20, SPL). Send transactions, interact with smart contracts, and manage multiple addresses across 12+ networks. Secure password-protected key storage with AES-256 encryption. Use for: (1) Creating new crypto wallets, (2) Importing existing wallets, (3) Checking token balances across chains, (4) Sending cryptocurrency and tokens, (5) Interacting with DeFi protocols and smart contracts, (6) Multi-chain portfolio management, (7) NFT transfers, (8) Blockchain development and testing. Keywords: crypto, cryptocurrency, wallet, blockchain, ethereum, solana, web3, defi, token, erc20, nft, smart contract, metamask alternative, hardware wallet, cold storage, hot wallet, blockchain wallet, digital wallet, bitcoin.

193 days ago

git-crypt-backup

1.8k
openclawopenclaw

Backup Clawdbot workspace and config to GitHub with git-crypt encryption. Use for daily automated backups or manual backup/restore operations.

193 days ago

azure-security-keyvault-keys-dotnet

1.6k
microsoftmicrosoft

Azure Key Vault Keys SDK for .NET. Client library for managing cryptographic keys in Azure Key Vault and Managed HSM. Use for key creation, rotation, encryption, decryption, signing, and verification. Triggers: "Key Vault keys", "KeyClient", "CryptographyClient", "RSA key", "EC key", "encrypt decrypt .NET", "key rotation", "HSM".

193 days ago

azure-keyvault-py

1.6k
microsoftmicrosoft

Azure Key Vault SDK for Python. Use for secrets, keys, and certificates management with secure storage. Triggers: "key vault", "SecretClient", "KeyClient", "CertificateClient", "secrets", "encryption keys".

193 days ago

azure-security-keyvault-keys-dotnet

1.6k
Microsoft Agent Skills Azure Security Keyvault Keys DotnetMicrosoft Agent Skills Azure Security Keyvault Keys Dotnet

Azure Key Vault Keys SDK for .NET. Client library for managing cryptographic keys in Azure Key Vault and Managed HSM. Use for key creation, rotation, encryption, decryption, signing, and verification. Triggers: "Key Vault keys", "KeyClient", "CryptographyClient", "RSA key", "EC key", "encrypt decrypt .NET", "key rotation", "HSM".

193 days ago

automating-database-backups

1.5k
jeremylongshorejeremylongshore

This skill automates database backups using the database-backup-automator plugin. It creates scripts for scheduled backups, compression, encryption, and restore procedures across PostgreSQL, MySQL, MongoDB, and SQLite. Use this when the user requests database backup automation, disaster recovery planning, setting up backup schedules, or creating restore procedures. The skill is triggered by phrases like 'create database backup', 'automate database backups', 'setup backup schedule', or 'generate restore procedure'.

193 days ago

encrypting-and-decrypting-data

1.5k
jeremylongshorejeremylongshore

Validate encryption implementations and cryptographic practices. Use when reviewing data security measures. Trigger with 'check encryption', 'validate crypto', or 'review security keys'.

193 days ago

encryption-at-rest-checker

1.5k
jeremylongshorejeremylongshore

Encryption At Rest Checker - Auto-activating skill for Security Advanced. Triggers on: encryption at rest checker, encryption at rest checker Part of the Security Advanced skill category.

193 days ago

llvm-obfuscation

790
gmh5225gmh5225

Expertise in LLVM-based code obfuscation techniques including OLLVM, control flow flattening, string encryption, virtualization, and anti-analysis methods. Use this skill when working on code protection, anti-reverse engineering, or implementing custom obfuscation passes.

193 days ago

electron-base

572
jezwebjezweb

Build secure desktop applications with Electron 33, Vite, React, and TypeScript. Covers type-safe IPC via contextBridge, OAuth with custom protocol handlers, native module compatibility (better-sqlite3, electron-store), and electron-builder packaging. Use when building cross-platform desktop apps, implementing OAuth flows in Electron, handling main/renderer process communication, or packaging with code signing. Prevents: NODE_MODULE_VERSION mismatch, hardcoded encryption keys, context isolation bypasses, sandbox conflicts with native modules.

193 days ago

rot13-encryption

550
OpenHandsOpenHands

This skill helps encrypt and decrypt messages using ROT13 cipher. Use when the user asks to "encrypt" or "decrypt" a message.

193 days ago

axiom-file-protection-ref

535
Charleswiltgen Axiom Axiom File Protection RefCharleswiltgen Axiom Axiom File Protection Ref

Use when asking about 'FileProtectionType', 'file encryption iOS', 'NSFileProtection', 'data protection', 'secure file storage', 'encrypt files at rest', 'complete protection', 'file security' - comprehensive reference for iOS file encryption and data protection APIs

193 days ago

crypto-analyzer

376
a5c-aia5c-ai

Analysis and validation of cryptographic implementations for encryption algorithms, key sizes, and certificate management.

193 days ago

security-auditor

360
DokhacgiakhoaDokhacgiakhoa

MASTER SECURITY: OWASP Top 10, SAST/DAST, PenTest, Auth/JWT Audit, Data Encryption, Incident Response. Use for Code Security, Armor config, and Audits.

193 days ago

implementing-tls

296
ancolemanancoleman

Configure TLS certificates and encryption for secure communications. Use when setting up HTTPS, securing service-to-service connections, implementing mutual TLS (mTLS), or debugging certificate issues.

193 days ago

Android Security

279
HoangNguyen0403HoangNguyen0403

Standards for Data Encryption, Network Security, and Permissions

193 days ago

qe-n8n-security-testing

215
proffesor-for-testingproffesor-for-testing

Credential exposure detection, OAuth flow validation, API key management testing, and data sanitization verification for n8n workflows. Use when validating n8n workflow security.

n8nsecuritycredentials+4
193 days ago

n8n Security Testing

215
proffesor-for-testingproffesor-for-testing

Detect credential exposure, validate OAuth flows, test API key management, and verify data sanitization for n8n workflows. Use this when validating n8n workflow security.

n8nsecuritycredentials+4
193 days ago

payuni-checkout

208
paid-twpaid-tw

Implements PAYUNi UPP checkout integration including AES256 encryption, form submission, and payment callback handling. Use when integrating payment gateway, creating checkout flows, or building 統一金流 payment pages.

193 days ago

newebpay-checkout

207
paid-twpaid-tw

Implements NewebPay MPG checkout integration including AES256 encryption, form submission, and payment callback handling. Use when integrating payment gateway, creating checkout flows, or building 藍新金流 payment pages.

193 days ago

crypto-best-practices

207
Hack23Hack23

Implement strong encryption, secure hashing, and proper key management following NIST and OWASP cryptography guidelines

193 days ago

custom-fields-development

152
RelaticleRelaticle

Adds dynamic custom fields to Eloquent models without migrations using Filament integration. Use when adding the UsesCustomFields trait to models, integrating custom fields in Filament forms/tables/infolists, configuring field types, working with field validation, or managing feature flags for conditional visibility, encryption, and multi-tenancy.

193 days ago

aws-sdk-java-v2-kms

128
giuseppe-trisciuogliogiuseppe-trisciuoglio

Provides AWS Key Management Service (KMS) patterns using AWS SDK for Java 2.x. Use when creating/managing encryption keys, encrypting/decrypting data, generating data keys, digital signing, key rotation, or integrating encryption into Spring Boot applications.

193 days ago

aws-cloudformation-security

126
giuseppe-trisciuogliogiuseppe-trisciuoglio

Provides AWS CloudFormation patterns for infrastructure security, secrets management, encryption, and secure data handling. Use when creating secure CloudFormation templates with AWS Secrets Manager, KMS encryption, secure parameters, IAM policies, VPC security groups, TLS/SSL certificates, and encrypted traffic configurations. Covers template structure, parameter best practices, cross-stack references, and defense-in-depth strategies.

193 days ago

aws-cloudformation-dynamodb

126
giuseppe-trisciuogliogiuseppe-trisciuoglio

Provides AWS CloudFormation patterns for DynamoDB tables, GSIs, LSIs, auto-scaling, and streams. Use when creating DynamoDB tables with CloudFormation, configuring primary keys, local/global secondary indexes, capacity modes (on-demand/provisioned), point-in-time recovery, encryption, TTL, and implementing template structure with Parameters, Outputs, Mappings, Conditions, cross-stack references.

193 days ago

ring:production-readiness-audit

122
LerianStudioLerianStudio

Comprehensive Ring-standards-aligned 44-dimension production readiness audit. Detects project stack, loads Ring standards via WebFetch, and runs in batches of 10 explorers appending incrementally to a single report file. Categories - Structure (pagination, errors, routes, bootstrap, runtime, core deps, naming, domain modeling, nil-safety, api-versioning, resource-leaks), Security (auth, IDOR, SQL, validation, secret-scanning, data-encryption, multi-tenant, rate-limiting, cors), Operations (telemetry, health, config, connections, logging, resilience, graceful-degradation), Quality (idempotency, docs, debt, testing, dependencies, performance, concurrency, migrations, linting, caching), Infrastructure (containers, hardening, cicd, async, makefile, license). Produces scored report (0-430, max 440 with multi-tenant) with severity ratings and standards cross-reference.

193 days ago

sip-authentication-security

98
TheBushidoCollectiveTheBushidoCollective

Use when implementing SIP authentication, security mechanisms, and encryption. Use when securing SIP servers, clients, or proxies.

193 days ago

fnox-providers

98
TheBushidoCollectiveTheBushidoCollective

Use when configuring Fnox providers for encryption and secret storage. Covers age encryption, cloud providers (AWS, Azure, GCP), and password managers.

193 days ago

fnox-security-best-practices

98
TheBushidoCollectiveTheBushidoCollective

Use when implementing secure secrets management with Fnox. Covers encryption, key management, access control, and security hardening.

193 days ago

aws-s3-management

95
aj-geddesaj-geddes

Manage S3 buckets with versioning, encryption, access control, lifecycle policies, and replication. Use for object storage, static sites, and data lakes.

193 days ago

cloud-security-configuration

95
aj-geddesaj-geddes

Implement comprehensive cloud security across AWS, Azure, and GCP with IAM, encryption, network security, compliance, and threat detection.

193 days ago

aws-rds-database

95
aj-geddesaj-geddes

Deploy and manage relational databases using RDS with Multi-AZ, read replicas, backups, and encryption. Use for PostgreSQL, MySQL, MariaDB, and Oracle.

193 days ago

secrets-rotation

95
aj-geddesaj-geddes

Implement automated secrets rotation for API keys, credentials, certificates, and encryption keys. Use when managing secrets lifecycle, compliance requirements, or security hardening.

193 days ago

discover-cryptography

76
randrand

Automatically discover cryptography skills when working with encryption, TLS, certificates, PKI, and security

193 days ago

PCI-DSS Compliance Testing

71
PramodDuttaPramodDutta

Testing PCI-DSS compliance for payment processing including encryption validation, access control testing, and secure data storage verification.

pci-dsspaymentcompliance+2
193 days ago

HIPAA Compliance Testing

71
PramodDuttaPramodDutta

Testing HIPAA compliance for healthcare applications including PHI handling, audit logging, access controls, and data encryption verification.

hipaahealthcarecompliance+2
193 days ago

SSL/TLS Certificate Testing

71
PramodDuttaPramodDutta

SSL/TLS configuration testing including certificate validation, cipher suite analysis, protocol version checks, and HSTS verification.

ssltlscertificate+2
193 days ago

workers-runtime-apis

69
secondskysecondsky

Cloudflare Workers Runtime APIs including Fetch, Streams, Crypto, Cache, WebSockets, and Encoding. Use for HTTP requests, streaming, encryption, caching, real-time connections, or encountering API compatibility, response handling, stream processing errors.

193 days ago

age-file-encryption

67
besoeasybesoeasy

Encrypt and decrypt files or streams using age — a simple, modern, and secure encryption tool with small explicit keys, passphrase support, SSH key support, post-quantum hybrid keys, and UNIX-style composability. No config options, no footguns.

193 days ago

analysis-tshark

64
AgentSecOpsAgentSecOps

Network protocol analyzer and packet capture tool for traffic analysis, security investigations, and forensic examination using Wireshark's command-line interface. Use when: (1) Analyzing network traffic for security incidents and malware detection, (2) Capturing and filtering packets for forensic analysis, (3) Extracting credentials and sensitive data from network captures, (4) Investigating network anomalies and attack patterns, (5) Validating encryption and security controls, (6) Performing protocol analysis for vulnerability research.

packet-capturenetwork-analysisforensics+3
193 days ago

crack-hashcat

64
AgentSecOpsAgentSecOps

Advanced password recovery and hash cracking tool supporting multiple algorithms and attack modes. Use when: (1) Performing authorized password auditing and security assessments, (2) Recovering passwords from captured hashes in forensic investigations, (3) Testing password policy strength and complexity, (4) Validating encryption implementations, (5) Conducting security research on cryptographic hash functions, (6) Demonstrating password weakness in penetration testing reports.

password-crackinghashcatforensics+2
193 days ago

feal-linear-cryptanalysis

62
letta-ailetta-ai

This skill provides guidance for FEAL cipher linear cryptanalysis tasks. It should be used when recovering encryption keys from FEAL-encrypted data using known plaintext-ciphertext pairs, implementing linear approximation attacks on block ciphers, or solving cryptanalysis challenges involving the FEAL cipher family. The skill emphasizes mathematical analysis over brute-force approaches.

193 days ago

feal-differential-cryptanalysis

62
letta-ailetta-ai

Guidance for implementing differential cryptanalysis attacks on FEAL and similar Feistel ciphers. This skill should be used when asked to break FEAL encryption, recover cipher keys through differential attacks, or implement cryptanalysis techniques on block ciphers with weak round functions. Covers proper differential characteristic construction, not ad-hoc statistical methods.

193 days ago