Merged timeline of 219 items — blog publish times and listing timestamps, cut at midnight . Page 1 of 5.
Web Search Agents by Nimble automates web research and retrieval, saving time and enhancing productivity.
Hello Inbox helps ensure more marketing emails reach the inbox, improving campaign effectiveness.
Oats is a free, open-source meeting notetaker that operates directly on your device.
Slashy Assistant automates email management, allowing users to focus on more important tasks.
Naoma AI Demo Agent V2 transforms website visitors into scheduled, qualified meetings, enhancing your sales pipeline.
### webhook-callback-security - Review inbound webhooks and callbacks that trigger agent actions — signature verification, replay protection, payload trust, and the authori - Practical, repeatable guidance for authorize…
### training-data-security - Review datasets and pipelines used for fine-tuning, embedding, or few-shot example curation for provenance, poisoning, label-flipping, embed - Practical, repeatable guidance for authorized s…
### skill-scanner - Review agent skill folders, archives, repository references, or updates before installation for instruction abuse, executable behavior, perm - Practical, repeatable guidance for authorized security w…
### security-reporting - Review and consolidate security findings into a reproducible, redacted assessment report with calibrated severity, confidence, remediation, - Practical, repeatable guidance for authorized securi…
### security-assessment - Coordinate a scoped security assessment across AI agents, applications, agent infrastructure, and supplied evidence. Route work to relevant - Practical, repeatable guidance for authorized secur…
### tool-schema-review - Review tool and function definitions exposed to a model — names, descriptions, parameter schemas, and return shapes — for embedded instructi - Practical, repeatable guidance for authorized secur…
### secrets-egress-review - Trace how AI agents and their applications can read secrets or sensitive data and send it to logs, tools, model providers, files, or network - Practical, repeatable guidance for authorized se…
### rag-memory-security - Review retrieval-augmented generation and agent memory pipelines for cross-user disclosure, poisoned context, unsafe persistence, provenance - Practical, repeatable guidance for authorized secu…
### mcp-scanner - Scan MCP configurations, server source, package references, and supplied tool manifests before connection or after updates. Review executabl - Practical, repeatable guidance for authorized security wor…
### prompt-injection-review - Review an agent application, prompt assembly, retrieved content, or supplied incident trace for prompt injection and unsafe tool effects. Us - Practical, repeatable guidance for authorized…
### llm-output-handling - Review how generated model output is rendered, executed, or forwarded downstream — HTML/markdown rendering, generated code execution, genera - Practical, repeatable guidance for authorized secu…
### multi-agent-trust-review - Review systems where one agent spawns, delegates to, or consumes output from other agents or sub-agents — orchestrators, planner/worker patt - Practical, repeatable guidance for authorized…
### model-artifact-scanner - Statically review supplied model packages, checkpoints, adapters, tokenizer assets, and loader configuration for unsafe deserialization, exe - Practical, repeatable guidance for authorized s…
### dependency-supply-chain - Review dependency changes and executable supply-chain inputs used by AI agents, skills, MCP servers, and applications. Inspect manifests, lo - Practical, repeatable guidance for authorized…
### data-retention-privacy-review - Review what agent transcripts, tool arguments, and outputs get retained, for how long, and who can access them — retention windows, deletion - Practical, repeatable guidance for autho…
### container-sandbox-security - Review supplied Docker, Compose, Kubernetes, and agent sandbox configuration for host exposure, privilege, writable mounts, network reach, a - Practical, repeatable guidance for authoriz…
### cicd-agent-security - Review CI/CD workflows that run AI agents, install agent tooling, or publish their changes. Trace untrusted triggers, code checkout, shell i - Practical, repeatable guidance for authorized secu…
### cloud-agent-security - Review supplied cloud deployment, IAM, workload identity, network, and logging configuration for AI agents and tool services. Trace effectiv - Practical, repeatable guidance for authorized sec…
### browser-agent-security - Review agents that control a browser or GUI (clicking, typing, navigating, screenshotting) for prompt injection from page content, dangerous - Practical, repeatable guidance for authorized s…
### ai-security - Assess the security of an AI application, LLM agent, or RAG workflow using source review and scoped testing of instruction boundaries, tool - Practical, repeatable guidance for authorized security work…
### ai-asset-scanner - Discover and review AI assets in a supplied repository or exported inventory, including agents, model dependencies, prompts, MCP integration - Practical, repeatable guidance for authorized securit…
### api-auth-security - Review API authentication and authorization used by AI agents, tools, and application backends. Trace caller identity, tenant and object acc - Practical, repeatable guidance for authorized securi…
### agent-web-security - Review agent-facing web interfaces, generated output rendering, and tool/API integrations for unsafe content handling, cross-user access, se - Practical, repeatable guidance for authorized secur…
### agent-network-segmentation - Review network reachability for an agent's execution environment — egress allow-lists, internal service and metadata-endpoint exposure, DNS - Practical, repeatable guidance for authorize…
### agent-monitoring-review - Review supplied agent telemetry, hook configuration, collector code, and event exports to assess observation coverage, provenance, redaction - Practical, repeatable guidance for authorized…
### agent-incident-response - Triage a suspected AI agent security incident from supplied logs, repository evidence, configuration, and timelines. Preserve evidence, dist - Practical, repeatable guidance for authorized…
### agent-transport-security - Review TLS, peer validation, credential forwarding, token verification, and cryptographic configuration protecting AI-provider, MCP, agent-c - Practical, repeatable guidance for authorized…
### agent-permissions-review - Review an AI agent's effective filesystem, execution, network, tool, and credential permissions against its authorized tasks. Use for a requ - Practical, repeatable guidance for authorized…
### agent-plugin-marketplace-review - Review a plugin, extension, or marketplace listing before bulk or organization-wide install — publisher identity and history, permission req - Practical, repeatable guidance for aut…
### agent-cost-abuse-review - Review agent deployments for runaway spend, quota and rate-limit abuse, and resource exhaustion — token/API budget controls, loop and retry - Practical, repeatable guidance for authorized s…
### offensive-zigbee-thread-matter - Zigbee, Thread, and Matter mesh-protocol attack methodology — IEEE 802.15.4 sniffing with TI CC2531 / CC2540 / Sonoff Zigbee Dongle E, Kille - Practical, repeatable guidance for auth…
### offensive-z-wave - Z-Wave attack methodology — sniffing with Z-Force / EZ-Wave / RTL-SDR + ZniffMobile, S0 (legacy) network-key derivation flaw and key reuse, - Practical, repeatable guidance for authorized security…
### offensive-wps - WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, Media - Practical, repeatable guidance for authorized security w…
### offensive-wpa3-sae - WPA3 / SAE (Simultaneous Authentication of Equals) attack methodology — transition-mode (mixed WPA2/WPA3) downgrade, Dragonblood side-channe - Practical, repeatable guidance for authorized secur…
### offensive-wpa-enterprise - WPA/WPA2/WPA3-Enterprise (802.1X / EAP) attack methodology — EAP method identification (PEAP-MSCHAPv2, EAP-TTLS, EAP-TLS, EAP-GTC, EAP-PWD, - Practical, repeatable guidance for authorized…
### offensive-wpa2-psk - WPA/WPA2-PSK attack methodology — four-way handshake capture via targeted deauthentication, PMKID attacks (no client required), hcxdumptool - Practical, repeatable guidance for authorized securi…
### offensive-wifi - Wireless / 802.11 attack methodology for red team engagements and wireless security assessments. Covers monitor-mode setup, WPA/WPA2-PSK han - Practical, repeatable guidance for authorized security…
### offensive-wifi-recon - Wi-Fi reconnaissance methodology — adapter selection, monitor mode and packet injection setup, regulatory domain handling, multi-band airspa - Practical, repeatable guidance for authorized sec…
### offensive-lorawan-sub-ghz - LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay - Practical, repeatable guidance for authorize…
### offensive-krack-fragattacks - KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks - Practical, repeatable guidance for authori…
### offensive-evil-twin - Evil Twin / KARMA / Mana access point methodology — rogue AP construction with hostapd-mana / wifiphisher / airgeddon, KARMA universal probe - Practical, repeatable guidance for authorized secu…
### offensive-deauth-disassoc - Deauthentication and disassociation attacks against 802.11 networks — targeted single-client deauth for handshake capture, broadcast deauth - Practical, repeatable guidance for authorized…
### offensive-bluetooth-classic - Bluetooth Classic (BR/EDR) attack methodology — device discovery, service enumeration via SDP, LMP/L2CAP layer attacks, legacy PIN cracking - Practical, repeatable guidance for authoriz…
### offensive-bluetooth-ble - Bluetooth Low Energy (BLE) attack methodology — GATT enumeration, characteristic read/write without auth, pairing downgrade (Just Works forc - Practical, repeatable guidance for authorized…
### offensive-xxe - - **Skill Name**: xxe - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.