Azure compliance scanning, Key Vault expiration auditing, and resource configuration validation. Runs azqr (Azure Quick Review) for comprehensive compliance assessment against best practices across subscriptions and resource groups Monitors Key Vault keys, secrets, and certificates for expiration dates and identifies items without expiration policies Detects orphaned, misconfigured, and non-compliant resources using Resource Graph queries Classifies findings by priority (Critical, High, Medium, Low) with remediation guidance for each issue
Automated security auditor for Firestore rules using red-team methodology. Evaluates rules against a mandatory checklist covering update bypasses, authority sources, business logic alignment, resource exhaustion, and type safety Identifies vulnerabilities across six critical dimensions: privilege escalation, data integrity, PII exposure, validation inconsistencies, and access control gaps Scores findings on a 1–5 scale (critical to secure) with detailed recommendations for each issue discovered Includes special handling for admin bootstrapping patterns to avoid false positives on legitimate hardcoded admin email checks
Review docs/prose for Writing Guidelines compliance. Use when asked to "review my docs", "check writing style", "audit prose", "review docs voice and tone", or…
Audit a browser fingerprint for internal contradictions with the liarjs CLI - canvas, WebGL, WebGL2, WebGPU, audio, 220 fonts, WebRTC and timezone probes,…
Set up, repair, or migrate to Cloudflare Turnstile bot verification in an existing frontend and backend, including server-side Siteverify.
Design, configure, troubleshoot, or review Cloudflare One Zero Trust and SASE deployments. Use cloudflare-one-migrations for migration planning from other…
Check and interpret data-breach exposure for an email, username, phone or name using Have I Been Pwned, the Pwned Passwords k-anonymity range API, DeHashed,…
Check and interpret data-breach exposure for an email, username, phone or name using Have I Been Pwned, the Pwned Passwords k-anonymity range API, DeHashed,…
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or…
Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP…
Google Workspace IT administration with security monitoring and configuration capabilities. Requires three prerequisite skills: gws-gmail, gws-drive, and gws-calendar for full functionality Includes standup-report workflow to review pending IT requests and security alerts at the start of each day Supports monitoring of suspicious login activity, audit log review, and Drive sharing policy configuration Recommends using --dry-run flag before bulk operations and regular permission verification via gws auth status
Google Model Armor: Filter user-generated content for safety. Provides three core helper commands: sanitize prompts, sanitize responses, and create custom filtering templates Integrates with Google Workspace services via the gws CLI tool with shared authentication and security rules Requires schema inspection via gws schema to discover available resources, methods, and parameter requirements before executing API calls
Create Google Model Armor templates to filter prompts and responses for safety. Requires GCP project ID, location, and template ID; supports preset templates (jailbreak) or custom JSON configuration Templates work with companion sanitize-prompt and sanitize-response commands for comprehensive content filtering Write operation requiring user confirmation before execution Defaults to jailbreak preset if no preset or JSON configuration is specified
Sanitize user prompts through Google Model Armor safety templates. Requires a Model Armor template resource name and accepts text input via flag, stdin, or full JSON request body Designed for inbound prompt safety; use the companion +sanitize-response command for outbound response filtering Integrates with Google Cloud authentication and global flags defined in gws-shared
Sanitize model responses through Google Model Armor templates for outbound safety. Applies Model Armor templates to filter model outputs before delivery to users Accepts text input via --text flag or piped stdin, with optional full JSON request body override Requires template resource name in format projects/PROJECT/locations/LOCATION/templates/TEMPLATE Complements the +sanitize-prompt command for inbound user input safety
Audit and harden a Convex app's authorization: identity-from-arg impersonation, missing per-document ownership checks, public queries leaking data by a…
Authorization system with role-based access control. Must-have for all apps that manage personal or access-restricted data.
Transform threat analysis into actionable security requirements. Converts STRIDE threat categories into functional, non-functional, and constraint requirements with automatic priority calculation based on impact and likelihood Generates security user stories, acceptance criteria, and test cases directly from threats; includes traceability matrices linking threats to requirements Maps requirements to compliance frameworks (PCI-DSS, HIPAA, GDPR, SOC2, NIST, ISO 27001, OWASP) and identifies coverage gaps Organizes requirements by security domain (authentication, authorization, data protection, audit logging, input validation, cryptography, and six others) with built-in filtering and export to markdown
Install the CLI. Run your first Skill in 30 seconds. Scale when you're ready.