Explore

Find agent skills by outcome

83,517 skills indexed with the new KISS metadata standard.

Showing 24 of 83,517Categories: Creative, General, Coding & Debugging, Cursor-rules
General
PromptBeginner5 minmarkdown

In `TODO_vulnerability-auditor.md`

include:

0
General
PromptBeginner5 minmarkdown

- Compliance standards applicable to the project (OWASP

PCI DSS

0
General
PromptBeginner5 minmarkdown

- **HTTP Hardening**: HTTPS redirection

HSTS

0
General
PromptBeginner5 minmarkdown

- **NuGet Supply Chain**: Dependency scanning

pinned versions

0
Coding & Debugging
PromptBeginner5 minmarkdown

Write all proposed audit findings and any code snippets to `TODO_vulnerability-auditor.md` only. Do not create any other files. If specific files should be created or edited

include patch-style diffs or clearly labeled file blocks inside the TODO.

0
General
PromptBeginner5 minmarkdown

- **Auth Schemes**: Correct JWT/cookie/OAuth configuration

token validation

0
Coding & Debugging
PromptBeginner5 minmarkdown

If the target is an ASP.NET Core / .NET Web API

include these additional checks.

0
Coding & Debugging
PromptBeginner5 minmarkdown

- **Hardcoded secrets**: API keys

passwords

0
General
PromptBeginner5 minmarkdown

- **Weak cryptography**: Use of MD5

SHA1

0
General
PromptBeginner5 minmarkdown

- Review log collection

centralization

0
General
PromptBeginner5 minmarkdown

- Review access logging

audit trails

0
General
PromptBeginner5 minmarkdown

- Assess resource limits

quotas

0
Coding & Debugging
PromptBeginner5 minmarkdown

- Test for encoding evasion: Unicode tricks

Base64 variants

0
Coding & Debugging
PromptBeginner5 minmarkdown

- Check for unsafe output rendering: script injection

executable code

0
General
PromptBeginner5 minmarkdown

- Test for known jailbreak patterns

encoding-based bypass

0
General
PromptBeginner5 minmarkdown

- Audit for sensitive information leakage: secrets

credentials

0
General
PromptBeginner5 minmarkdown

- Analyze security headers (CSP

X-Frame-Options

0
General
PromptBeginner5 minmarkdown

If the target system includes LLM agents

prompts

0
General
PromptBeginner5 minmarkdown

- Analyze indirect injection channels: tool output

document-based

0
General
PromptBeginner5 minmarkdown

- Validate and restrict CORS origins to known

trusted domains only.

0
General
PromptBeginner5 minmarkdown

- Verify HTTPS enforcement

HSTS

0
General
PromptBeginner5 minmarkdown

- Use `bcrypt` or `argon2-cffi` for password hashing

never `hashlib` directly.

0
General
PromptBeginner5 minmarkdown

- Avoid `eval()`

`Function()`

0
General
PromptBeginner5 minmarkdown

- Validate and sanitize input with libraries like `joi`

`zod`

0