AI security skills grounded in mid-2026 threat reality, not stale framework documentation. 51 skills, 11 catalogs (459 CVEs / 181 CWEs / 805 ATT&CK + ICS / 170 ATLAS / 468 D3FEND / 8888 RFCs), 35 jurisdictions, 10-class catalog gap detector + budget gate,
- capability exposureinferred+35
- recent driftinferred+20
- trust mitigatorsmixed−9
inferredmixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 15m ago · see ecosystem CVEs →
- C · 58 → C · 46
no known CVEs for this server.
- highdangerous code
env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (/tmp/obs-code-xd6Y6S/package/orche
analyzed v0.18.6 · analyzer v17 · 1d ago
skills & prompt files 52
- agent-rulespackage/AGENTS.md
- skillpackage/skills/age-gates-child-safety/skill.md
- skillpackage/skills/ai-attack-surface/skill.md
- skillpackage/skills/ai-c2-detection/skill.md
- skillpackage/skills/ai-risk-management/skill.md
- skillpackage/skills/api-security/skill.md
- skillpackage/skills/attack-surface-pentest/skill.md
- skillpackage/skills/audit-log-integrity/skill.md
- skillpackage/skills/cloud-iam-incident/skill.md
- skillpackage/skills/cloud-security/skill.md
- skillpackage/skills/compliance-theater/skill.md
- skillpackage/skills/container-runtime-security/skill.md
- skillpackage/skills/coordinated-vuln-disclosure/skill.md
- skillpackage/skills/decompression-dos/skill.md
- skillpackage/skills/defensive-countermeasure-mapping/skill.md
- skillpackage/skills/dlp-gap-analysis/skill.md
- skillpackage/skills/email-security-anti-phishing/skill.md
- skillpackage/skills/exploit-scoring/skill.md
- skillpackage/skills/framework-gap-analysis/skill.md
- skillpackage/skills/fuzz-testing-strategy/skill.md
- skillpackage/skills/global-grc/skill.md
- skillpackage/skills/identity-assurance/skill.md
- skillpackage/skills/idp-incident-response/skill.md
- skillpackage/skills/incident-response-playbook/skill.md
- skillpackage/skills/kernel-lpe-triage/skill.md
- skillpackage/skills/log-injection-telemetry/skill.md
- skillpackage/skills/mail-server-hardening/skill.md
- skillpackage/skills/mcp-agent-trust/skill.md
- skillpackage/skills/mlops-security/skill.md
- skillpackage/skills/multitenancy-isolation/skill.md
- skillpackage/skills/network-trust/skill.md
- skillpackage/skills/ot-ics-security/skill.md
- skillpackage/skills/policy-exception-gen/skill.md
- skillpackage/skills/pqc-first/skill.md
- skillpackage/skills/privacy-consent-ops/skill.md
- skillpackage/skills/rag-pipeline-security/skill.md
- skillpackage/skills/ransomware-response/skill.md
- skillpackage/skills/researcher/skill.md
- skillpackage/skills/sector-energy/skill.md
- skillpackage/skills/sector-federal-government/skill.md
- skillpackage/skills/sector-financial/skill.md
- skillpackage/skills/sector-healthcare/skill.md
- skillpackage/skills/sector-telecom/skill.md
- skillpackage/skills/security-maturity-tiers/skill.md
- skillpackage/skills/self-update-integrity/skill.md
- skillpackage/skills/skill-update-loop/skill.md
- skillpackage/skills/supply-chain-integrity/skill.md
- skillpackage/skills/threat-model-currency/skill.md
- skillpackage/skills/threat-modeling-methodology/skill.md
- skillpackage/skills/vc-wallet-trust/skill.md
- skillpackage/skills/webapp-security/skill.md
- skillpackage/skills/zeroday-gap-learn/skill.md
- recent drift+20 capability drift →
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of dotcoocoo.