6 agent skills for security, each from its publisher's own repository or a large open-source project. Open a skill for its license, install command and the date we checked it.
differential-review is Trail of Bits' agent skill for security review of a pull request, commit or diff, using git history, blast radius counts and test coverage, and ending in a written markdown report.
firebase-security-rules-auditor is the Firebase team's agent skill for auditing Firestore and Cloud Storage security rules for privilege escalation, update bypasses and missing limits, returning a 1 to 5 score in JSON.
gha-security-review is Sentry's agent skill for auditing GitHub Actions workflows for attacks an outsider can run, such as pwn requests, expression injection and credential theft, with a concrete exploit for each finding.
security-review is Sentry's agent skill for reviewing code for exploitable vulnerabilities, such as injection, XSS, broken access control and weak crypto, reporting only findings it has confirmed with high confidence.
semgrep-rule-creator is Trail of Bits' agent skill for writing custom Semgrep rules that detect vulnerabilities and bug patterns, test-first, with taint mode preferred and every test required to pass.
supply-chain-risk-auditor is Trail of Bits' agent skill for auditing a project's npm, PyPI and Go dependencies for known advisories, abandoned upstreams, publisher concentration and install scripts, measured by bundled scripts.