FinTech future-proofing. Scans and migrates classical encryption to NIST-approved Post-Quantum Cryptography (PQC) / Migrasi ke Kriptografi Pasca-Kuantum (PQC) yang disetujui NIST untuk sistem FinTech.
日本語の概要は準備中です。原文の説明を表示しています。
72 件 ・ 関連度順
概要と使いどころ
FinTech future-proofing. Scans and migrates classical encryption to NIST-approved Post-Quantum Cryptography (PQC) / Migrasi ke Kriptografi Pasca-Kuantum (PQC) yang disetujui NIST untuk sistem FinTech.
日本語の概要は準備中です。原文の説明を表示しています。
Stanford FDCI research bridge connecting Dan Boneh's cryptographic primitives (ZK proofs, BLS signatures, threshold cryptography) with Tim Roughgarden's mechanism design (TFM, MEV mitigation, welfare maximization).
日本語の概要は準備中です。原文の説明を表示しています。
AI-powered code vulnerability analysis and dependency scanning using Gemini CLI security extension patterns. Detects hardcoded secrets, injection attacks, weak cryptography, authentication flaws, and LLM prompt injection. Also scans dependencies against the OSV.dev vulnerability database.
日本語の概要は準備中です。原文の説明を表示しています。
Write custom Semgrep rules to identify organization-specific logic flaws, improper cryptography usage, or missing authorization checks during source code review. This skill focuses on moving beyond default rulesets to locate complex vulnerabilities.
日本語の概要は準備中です。原文の説明を表示しています。
Detects weak or misconfigured cryptography in mobile apps (Android/iOS). Trigger on: hardcoded keys, ECB mode, DES, 3DES, RC4, MD5, SHA-1, SecureRandom misuse, static IV, reused IV, Math.random, arc4random, CommonCrypto, CryptoKit, Android Keystore, SecKey, AES-ECB, RSA without OAEP, insufficient key size, predictable seed, insecure key storage, broken hash, PBKDF2 iteration count. Covers MASVS-CRYPTO-1 (algorithm choice) and MASVS-CRYPTO-2 (key management).
日本語の概要は準備中です。原文の説明を表示しています。
Exploit implementations of JSON Web Tokens (JWT) through algorithmic confusion (e.g., RS256 to HS256), "none" algorithm attacks, and signature stripping. Use this skill to forge administration tokens and achieve unauthenticated Account Takeover (ATO) on REST APIs and modern web applications.
日本語の概要は準備中です。原文の説明を表示しています。
Identify and exploit Algorithm Confusion vulnerabilities in JSON Web Tokens (JWT). This skill details how to bypass signature verification by changing the signing algorithm from asymmetric (RS256) to symmetric (HS256) and using the public key as the symmetric secret.
日本語の概要は準備中です。原文の説明を表示しています。
Identifies cryptographic algorithms embedded in a binary by scanning for well-known constants and tables (AES S-box, SHA-256/MD5 init constants, ChaCha sigma, CRC32 table, base64 alphabet). Activates for requests to identify crypto in a binary, find AES/SHA constants, or detect which encryption algorithm a sample uses.
日本語の概要は準備中です。原文の説明を表示しています。
Locates candidate encryption keys in a binary by finding high-entropy fixed-size regions (16/24/32 bytes) near cryptographic constants or crypto API references, and surfacing printable key/passphrase strings. Activates for requests to extract encryption keys, find an AES key in a sample, or recover hardcoded crypto material.
日本語の概要は準備中です。原文の説明を表示しています。
Analyzes how a ransomware sample encrypts files: identifying the crypto scheme (symmetric/asymmetric/hybrid), key handling, file targeting and extension/marker changes, shadow-copy deletion, and ransom-note artifacts. Activates for requests to analyze ransomware encryption, assess decryptability, or study ransomware behavior.
日本語の概要は準備中です。原文の説明を表示しています。
Guideline for designing, implementing, and verifying secure Python applications following OWASP Top 10 best practices. Use when the user wants to: (1) review Python code for security vulnerabilities, (2) design a secure Python application architecture, (3) implement security features (authentication, authorization, cryptography, input validation), (4) audit Python dependencies for known vulnerabilities, (5) create security checklists or verification plans, (6) fix security bugs or harden existing Python code, (7) set up security testing and static analysis (bandit, safety, semgrep), or (8) handle any Python security concern including injection prevention, secure deserialization, SSRF protection, secrets management, and secure deployment.
日本語の概要は準備中です。原文の説明を表示しています。
Guideline for designing, implementing, and verifying secure TypeScript and JavaScript applications following OWASP Top 10 best practices. Use when the user wants to: (1) review TypeScript or JavaScript code for security vulnerabilities, (2) design a secure Node.js, Deno, or browser application architecture, (3) implement security features (authentication, authorization, cryptography, input validation), (4) audit npm/yarn/pnpm dependencies for known vulnerabilities, (5) create security checklists or verification plans, (6) fix security bugs or harden existing TypeScript or JavaScript code, (7) set up security testing and static analysis (ESLint security plugins, Semgrep, Snyk), or (8) handle any TypeScript/JavaScript security concern including injection prevention, prototype pollution, XSS protection, SSRF prevention, secrets management, and secure deployment.
日本語の概要は準備中です。原文の説明を表示しています。
Expert in groups, rings, fields, and algebraic structures with applications to cryptography and number theory
日本語の概要は準備中です。原文の説明を表示しています。
Expert-level number theory knowledge. Use when working with divisibility, prime numbers, modular arithmetic, congruences, Diophantine equations, cryptography, quadratic residues, or analytic number theory. Also use when the user mentions 'prime', 'divisibility', 'modular arithmetic', 'congruence', 'GCD', 'Euler totient', 'Fermat little theorem', 'Chinese remainder theorem', 'quadratic residue', 'Diophantine equation', 'RSA', or 'prime factorization'.
日本語の概要は準備中です。原文の説明を表示しています。
Hardware Security Modules (HSMs) are tamper-resistant physical devices that safeguard cryptographic keys and perform cryptographic operations in a hardened environment. Keys stored in an HSM never lea
日本語の概要は準備中です。原文の説明を表示しています。
TLS 1.3 (RFC 8446) is the latest version of the Transport Layer Security protocol, providing significant improvements over TLS 1.2 in both security and performance. It reduces handshake latency to 1-R
日本語の概要は準備中です。原文の説明を表示しています。
A Certificate Authority (CA) is the trust anchor in a PKI hierarchy, responsible for issuing, signing, and revoking digital certificates. This skill covers building a two-tier CA hierarchy (Root CA +
日本語の概要は準備中です。原文の説明を表示しています。
Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network communication, authentication, cryptography, and platform-specific security controls. The tester performs static analysis of application binaries, dynamic analysis at runtime, and API security testing to evaluate the complete mobile attack surface. Activates for requests involving mobile app pentest, iOS security assessment, Android security testing, or OWASP MASTG assessment.
日本語の概要は準備中です。原文の説明を表示しています。
Use when performing cybersecurity operations - offensive or defensive - including threat detection and hunting, SOC operations, incident response, digital forensics and DFIR, malware analysis and reverse engineering, threat intelligence, cloud/container/network/application/API security, identity-access and zero-trust, OT/ICS and endpoint security, vulnerability and supply-chain management, DevSecOps, cryptography, AI security, compliance and governance, and red-team or penetration testing under signed rules of engagement; routes to one of 800+ technique playbooks mapped to MITRE ATT&CK, D3FEND, and NIST CSF.
日本語の概要は準備中です。原文の説明を表示しています。
FlutterSecureStorage (v10.x) for encrypted key-value storage of sensitive data using platform-native secure enclaves with biometric authentication support. Use this skill when storing OAuth tokens (access tokens, refresh tokens, ID tokens), API keys and secrets, user passwords or PINs, session tokens, encryption keys, private keys for cryptography, certificate data, biometric enrollment data, banking credentials, health data, or any sensitive information requiring platform-level encryption (iOS Keychain with Secure Enclave, Android Keystore with Hardware-backed keys). Supports Touch ID, Face ID, and Android biometric prompt integration. Handles biometric change invalidation (resetOnError), data migration from SharedPreferences/EncryptedSharedPreferences, Google Drive backup exclusion, automatic key rotation, configurable encryption algorithms (AES), and prevents data extraction even on rooted/jailbroken devices. Essential for authentication flows, secure credential management, or compliance requirements (PCI DSS, HIPAA, GDPR data protection).
日本語の概要は準備中です。原文の説明を表示しています。
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching tools miss. Use this skill when asked to scan code for security vulnerabilities, find bugs, check for SQL injection, XSS, command injection, exposed API keys, hardcoded secrets, insecure dependencies, access control issues, or any request like "is my code secure?", "review for security issues", "audit this codebase", or "check for vulnerabilities". Covers injection flaws, authentication and access control bugs, secrets exposure, weak cryptography, insecure dependencies, and business logic issues across JavaScript, TypeScript, Python, Java, PHP, Go, Ruby, and Rust.
日本語の概要は準備中です。原文の説明を表示しています。
AES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST (FIPS 197) used to protect classified and sensitive data. bu skill covers implementing AES-256 encryption in GCM m
日本語の概要は準備中です。原文の説明を表示しています。
Ed25519 is a high-performance digital signature algorithm using the Edwards curve Curve25519. It provides 128-bit security with 64-byte signatures and 32-byte keys, offering significant advantages ove
日本語の概要は準備中です。原文の説明を表示しています。
RSA (Rivest-Shamir-Adleman) is the most widely Dağıtılmış asymmetric cryptographic algorithm, used for digital signatures, key exchange, and encryption. bu skill covers generating, storing, rotating,
日本語の概要は準備中です。原文の説明を表示しています。