offensive-security▌
113 indexed skills · max 10 per page
agent-plugin-marketplace-review
whyashthakker/beam-cli · agent-plugin-marketplace-review
### agent-plugin-marketplace-review - Review a plugin, extension, or marketplace listing before bulk or organization-wide install — publisher identity and history, permission req - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
agent-network-segmentation
whyashthakker/beam-cli · agent-network-segmentation
### agent-network-segmentation - Review network reachability for an agent's execution environment — egress allow-lists, internal service and metadata-endpoint exposure, DNS - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
agent-web-security
whyashthakker/beam-cli · agent-web-security
### agent-web-security - Review agent-facing web interfaces, generated output rendering, and tool/API integrations for unsafe content handling, cross-user access, se - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
cloud-agent-security
whyashthakker/beam-cli · cloud-agent-security
### cloud-agent-security - Review supplied cloud deployment, IAM, workload identity, network, and logging configuration for AI agents and tool services. Trace effectiv - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
agent-transport-security
whyashthakker/beam-cli · agent-transport-security
### agent-transport-security - Review TLS, peer validation, credential forwarding, token verification, and cryptographic configuration protecting AI-provider, MCP, agent-c - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
api-auth-security
whyashthakker/beam-cli · api-auth-security
### api-auth-security - Review API authentication and authorization used by AI agents, tools, and application backends. Trace caller identity, tenant and object acc - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
cicd-agent-security
whyashthakker/beam-cli · cicd-agent-security
### cicd-agent-security - Review CI/CD workflows that run AI agents, install agent tooling, or publish their changes. Trace untrusted triggers, code checkout, shell i - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
agent-incident-response
whyashthakker/beam-cli · agent-incident-response
### agent-incident-response - Triage a suspected AI agent security incident from supplied logs, repository evidence, configuration, and timelines. Preserve evidence, dist - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
container-sandbox-security
whyashthakker/beam-cli · container-sandbox-security
### container-sandbox-security - Review supplied Docker, Compose, Kubernetes, and agent sandbox configuration for host exposure, privilege, writable mounts, network reach, a - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
llm-output-handling
whyashthakker/beam-cli · llm-output-handling
### llm-output-handling - Review how generated model output is rendered, executed, or forwarded downstream — HTML/markdown rendering, generated code execution, genera - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.