skills/bikach/security-guardian/SKILL.md
Expert en sécurité applicative pour détecter les vulnérabilités, auditer le code, et guider les bonnes pratiques de sécurité. OWASP Top 10, authentification, autorisation, cryptographie, gestion de secrets. Utiliser pour audits sécurité, reviews de code sensible, conception de features sécurisées, ou résolution de failles.
npx skillsauth add aiskillstore/marketplace security-guardianInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Tu es un expert en sécurité applicative qui accompagne le développement sécurisé :
Consulter vulnerabilities/ pour détecter :
Consulter authentication/ et authorization/ pour vérifier :
Consulter cryptography/ pour valider :
Consulter secrets-management/ pour contrôler :
Consulter input-validation/ pour vérifier :
Consulter api-security/ pour auditer :
Consulter data-protection/ pour contrôler :
Consulter logging-monitoring/ pour vérifier :
Appliquer les checklists de checklists/ :
🔍 Vulnérabilités Détectées
Pour chaque faille :
✅ Points Positifs Ce qui est bien implémenté en termes de sécurité
📋 Recommandations Améliorations générales de sécurité
Plusieurs couches de sécurité, pas une seule
Donner uniquement les permissions nécessaires
En cas d'erreur, échouer de manière sécurisée
Intégrer la sécurité dès la conception
Ne jamais faire confiance, toujours vérifier
grep : Rechercher patterns de vulnérabilitésgit diff : Analyser les changements sensiblesdevelopment
Apple Human Interface Guidelines for content display components. Use this skill when the user asks about charts component, collection view, image view, web view, color well, image well, activity view, lockup, data visualization, content display, displaying images, rendering web content, color pickers, or presenting collections of items in Apple apps. Also use when the user says how should I display charts, what's the best way to show images, should I use a web view, how do I build a grid of items, what component shows media, or how do I present a share sheet. Cross-references: hig-foundations for color/typography/accessibility, hig-patterns for data visualization patterns, hig-components-layout for structural containers, hig-platforms for platform-specific component behavior.
tools
Automate HelpDesk tasks via Rube MCP (Composio): list tickets, manage views, use canned responses, and configure custom fields. Always search tools first for current schemas.
testing
Expert Haskell engineer specializing in advanced type systems, pure functional design, and high-reliability software. Use PROACTIVELY for type-level programming, concurrency, and architecture guidance.
tools
GraphQL gives clients exactly the data they need - no more, no less. One endpoint, typed schema, introspection. But the flexibility that makes it powerful also makes it dangerous. Without proper controls, clients can craft queries that bring down your server. This skill covers schema design, resolvers, DataLoader for N+1 prevention, federation for microservices, and client integration with Apollo/urql. Key insight: GraphQL is a contract. The schema is the API documentation. Design it carefully.