MightyOpen Mighty
Skills Marketplace

Skills your agents can run

Plug-and-play capabilities — vetted, versioned, and runnable from any Mighty agent.

168
Skills indexed
31
Categories
Self-hosted
Your hub, your data

jwt-authentication

Community

Configures JWT Bearer authentication for .NET APIs. Includes token generation, validation, refresh tokens, and user context extraction from claims.

016Security Passwords

pact-security-patterns

Community

Security best practices and threat mitigation patterns for PACT framework development. Use when: implementing authentication or authorization, handling API credentials, integrating external APIs, processing sensitive data (PII, financial, health), reviewing code for vulnerabilities, or enforcing SACROSANCT security rules. Triggers on: security audit, credential handling, OWASP, auth flows, encryption, data protection, backend proxy pattern, frontend credential exposure.

016Security Passwords

laravel-security-audit

Community

Security auditor for Laravel applications. Analyzes code for vulnerabilities, misconfigurations, and insecure practices using OWASP standards and Laravel security best practices.

016Security Passwords

exploiting-oauth-misconfiguration

Community

Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during security assessments.

016Security Passwords

better-auth

Community

Skill for integrating Better Auth - comprehensive TypeScript authentication framework for Cloudflare D1, Next.js, Nuxt, and 15+ frameworks. Use when adding auth, encountering D1 adapter errors, or implementing OAuth/2FA/RBAC features.

016Security Passwords

api-fuzzing-bug-bounty

Community

Use this skill when the user asks to test API security, fuzz APIs, find IDOR vulnerabilities, test REST APIs, test GraphQL, perform API penetration testing, or work on bug bounty engagements.

016Security Passwords

openclaw-vault-pro

Community

Full credential lifecycle security: detect exposed credentials, auto-fix permissions, quarantine exposed files, rotation tracking, git history scanning, and automated protection. Everything in openclaw-vault (free) plus automated countermeasures.

016Security Passwords

memory-forensics

Community

Master memory forensics techniques including memory acquisition, process analysis, and artifact extraction using Volatility and related tools. Use when analyzing memory dumps, investigating incidents, performing malware analysis, or conducting post-breach triage to recover volatile evidence not present on disk.

016Security Passwords

performing-static-malware-analysis-with-pe-studio

Community

Performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine file headers, imports, strings, resources, and indicators without executing the binary. Identifies suspicious characteristics including packing, anti-analysis techniques, and malicious imports. Activates for requests involving static malware analysis, PE file inspection, Windows executable analysis, or pre-execution malware triage.

015Security Passwords

Windows Privilege Escalation

Community

This skill should be used when the user asks to "escalate privileges on Windows," "find Windows privesc vectors," "enumerate Windows for privilege escalation," "exploit Windows misconfigurations," or "perform post-exploitation privilege escalation." It provides comprehensive guidance for discovering and exploiting privilege escalation vulnerabilities in Windows environments.

015Security Passwords

crypto-primitives

Community

Implementation and secure usage of cryptographic primitives including ECDSA, BLS, Schnorr signatures, key derivation, secret sharing, and constant-time operations. Provides guidance for secure cryptographic implementations in blockchain applications.

015Security Passwords

pci-dss-compliance

Community

PCI DSS compliance planning for payment card handling including scope reduction, SAQ selection, and security controls

015Security Passwords

attack-tree-construction

Community

Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.

015Security Passwords

api-security

Community

Comprehensive API security guidance covering authentication methods, rate limiting, input validation, CORS, security headers, and protection against OWASP API Top 10 vulnerabilities. Use when designing API authentication, implementing rate limiting, configuring CORS, setting security headers, or reviewing API security.

015Security Passwords

xxe-testing

Community

XXE XML外部实体注入测试的专业技能和方法论

015Security Passwords

threat-hunting

Community

Proactively search for security threats, vulnerabilities, and suspicious patterns in applications and infrastructure before they cause damage. Use when conducting security audits, identifying vulnerabilities, analyzing security logs, detecting suspicious patterns, investigating potential breaches, performing penetration testing, or implementing security monitoring.

015Security Passwords

oauth-implementation

Community

Implement secure OAuth 2.0, OpenID Connect (OIDC), JWT authentication, and SSO integration. Use when building secure authentication systems for web and mobile applications.

015Security Passwords

openssl

Community

Generate secure random strings, passwords, and cryptographic tokens using OpenSSL. Use when creating passwords, API keys, secrets, or any secure random data.

015Security Passwords

security

Community

This skill should be used when auditing code for security issues, reviewing authentication/authorization, evaluating input validation, analyzing cryptographic usage, or reviewing dependency security. Provides OWASP patterns, CWE analysis, and threat modeling guidance.

015Security Passwords

Hacking Fundamentals

Community

This skill should be used when the user asks to "understand hacking basics", "learn about hacker types", "understand network protocols", "learn DNS concepts", "understand attack types", or "explore security tool categories". It provides foundational cybersecurity knowledge.

015Security Passwords