Auth0's official agent skill: a router that detects your framework and intent, then loads the right Auth0 guidance for login, MFA, Organizations, tenant audits, debugging or provider migration.
Security
Protecting systems and data — vulnerability review, secrets, access control and hardening.
14 skills and 8 MCP servers tagged Security.
Skills
Trail of Bits' security review skill for PRs, commits, and diffs: risk-first analysis with git history, blast radius, and honest coverage limits.
Google's official Well-Architected Framework skill for the security pillar — turns an architecture review into a structured interview, gap analysis and prioritised recommendations.
Google's official AlloyDB for PostgreSQL skill — cluster and instance lifecycle from gcloud, plus hard rules on private connectivity, IAM database auth and backup behaviour.
Harden a Twilio integration against credential leaks and fraud — API keys instead of auth tokens, webhook signature validation, geo-permissions, SMS pumping prevention and zero-downtime credential rotation.
Answer "who changed what" from Datadog Audit Trail — configuration-change forensics, API key compromise, cost-spike root cause, SOC 2/PCI evidence and AI activity audits.
Skill: Firebase Security Rules Auditor
by Firebase
Firebase's official red-team skill for auditing Firestore and Cloud Storage security rules — hunting privilege escalation, create/update bypasses and resource-exhaustion holes.
Skill: Microsoft Entra Agent ID
by Microsoft
Microsoft's official skill for giving AI agents real OAuth2 identities in Entra — blueprints, agent identities, sponsors, workload identity federation and the auth sidecar.

Skill: Authenticating to Google Cloud
by Google Cloud
Google's official skill for getting Google Cloud authentication right — human identities, service accounts, Application Default Credentials, and the failure modes agents usually hit.
Skill: GitHub Actions Security Review
by Sentry
Audit GitHub Actions workflows for the exploitation patterns that leak secrets or allow code execution from a fork.
Skill: Find Bugs in Branch Changes
by Sentry
Audit the changes on your current branch for bugs, security vulnerabilities, and quality problems before you push.
Skill: Engineering Code Review
by Sentry
Review pull requests against a real engineering practice — security, performance, testing, and design, in that order.
Skill: Deno Sandbox
by Deno
Run untrusted or model-generated code in an isolated environment using the @deno/sandbox SDK.
Skill: Cloudflare Sandbox SDK
by Cloudflare
Build secure code-execution features on Cloudflare — sandboxes for AI-generated code, interpreters, and CI systems.
MCP servers
Official read-only MCP server for HackerOne bug bounty reports, programs, and remediation data.
Run AI-generated code safely in an isolated cloud sandbox, with results returned as data rather than text.
Okta's official open-source MCP server: manage users, groups, apps, policies and branding in your Okta org from an AI agent, with scope-gated tools and confirmation on destructive actions.
Bitwarden's official MCP server — unlock the vault, read and edit items, generate passwords and TOTP codes, and run organisation administration. Local use only.
Semgrep's official MCP server — scan code for security vulnerabilities, write and test custom rules, and pull findings from Semgrep Cloud, from inside an agent session.
Snyk's official MCP server, shipped inside the Snyk CLI: scan code, dependencies, containers and IaC for vulnerabilities, generate SBOMs and monitor projects from your agent.
MCP: SonarQube MCP Server
by SonarSource
Official SonarSource MCP server — pull code-quality issues, security hotspots, quality gates and rule explanations from SonarQube Cloud or Server into your agent.
MCP: Docker MCP Gateway
by Docker
Docker's official CLI plugin that runs MCP servers in isolated containers behind one gateway — secrets management, OAuth flows and a single config every client shares.
Related tags
Tags that appear alongside this one, ranked by how often.