stacks/security-devops

🔒

Security & DevOps

For developers who need to ship securely

The only stack featuring Trail of Bits — one of the world's most respected security research firms. Their skill plus Sigma threat hunting rules, web fuzzing, and safe encryption patterns. AWS CDK for infrastructure. Playwright for automated testing. Exclusive to theskills.directory.

8 skills
securitydevopsawstestingexclusive

Skills in this stack

8 skills

Why this stack exists

Security requires institutional knowledge that generic AI models don't carry. Trail of Bits is among the world's most respected security research firms — their skill encodes real review patterns, not surface-level checklists. The Security & DevOps stack is the only one that combines this with Sigma threat hunting, web fuzzing, safe encryption, and AWS CDK — all exclusive to theskills.directory.

Who it's for

Developers who need to ship securely — teams with compliance requirements, security engineers doing code review, and DevOps engineers building production infrastructure. Also useful for solo developers who don't have a security team but can't afford to skip security.

How these skills work together

  • trail-of-bits-security applies real-world security review patterns from one of the industry's most respected firms.
  • safe-encryption ensures cryptographic implementations are correct — right algorithms, right modes, right key management.
  • threat-hunting-sigma generates Sigma rules for SIEM detection — turn an incident into a detection rule in minutes.
  • ffuf-web-fuzzing automates web application fuzzing to find endpoints, parameters, and injection points.
  • aws-cdk-skills generates correct CDK constructs with security best practices baked in.
  • playwright-automation tests security-critical flows — auth, access control, rate limiting — in a real browser.
  • agent-manager and vibe-testing keep the workflow automated and regression-safe.

Example prompts

"Review this authentication implementation for security issues."
"Generate a Sigma rule to detect this attacker behaviour pattern."
"Fuzz this login endpoint and report any unusual responses."
"Build an AWS CDK stack for a VPC with private subnets and a NAT gateway."