Mmcp.market

doncheli-security skill

by doncheli·doncheli/don-cheli-sdd·57 stars·Apache-2.0

Perform OWASP Top 10 static security audit identifying vulnerabilities in access control, cryptography, injection, configuration, and logging. Activate when user mentions "security audit", "OWASP", "security scan", "vulnerabilities", "auditar seguridad".

A100/100content scan

Is the doncheli-security skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

No findings.

Install the doncheli-security skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/doncheli/don-cheli-sdd.git /tmp/don-cheli-sdd
mkdir -p ~/.claude/skills
cp -r /tmp/don-cheli-sdd/.opencode/skills/doncheli-security ~/.claude/skills/doncheli-security
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

Don Cheli: OWASP Security Audit

Categories

  • A01: Broken Access Control — endpoints without auth, IDOR, CORS
  • A02: Cryptographic Failures — plaintext passwords, JWT without expiration
  • A03: Injection — SQL, XSS, command injection
  • A04: Insecure Design — missing validation, bypassable business logic
  • A05: Security Misconfiguration — debug mode, default credentials, missing headers
  • A06: Vulnerable Components — dependencies with known CVEs
  • A07: Auth Failures — no brute-force protection, no session management
  • A08: Data Integrity — insecure deserialization
  • A09: Logging Failures — no audit log for security operations
  • A10: SSRF — unvalidated user-supplied URLs

Output

For each finding: ID, severity (Critical/High/Medium/Low), OWASP category, file:line, description, impact, recommended fix, effort estimate.

More skills from doncheli/don-cheli-sdd

  • Adoncheli-api-contractDesign complete API contracts covering endpoints, auth, rate limiting, error handling, retries, circuit breaker and idempotency. Activate when user mentions "api contract", "api design", "endpoint", "webhook", "REST", "GraphQL", "OpenAPI", "design the API".
  • Adoncheli-api-contractDesign complete API contracts covering endpoints, auth, rate limiting, error handling, retries, circuit breaker and idempotency. Activate when user mentions "api contract", "api design", "endpoint", "webhook", "REST", "GraphQL", "OpenAPI", "design the API".
  • Adoncheli-audit-trailRecord and query the decision log for a project. Activate when user mentions "audit", "trail", "log decisions", "decision history", "why was this decided", "ADR", "architecture decision".
  • Adoncheli-audit-trailRecord and query the decision log for a project. Activate when user mentions "audit", "trail", "log decisions", "decision history", "why was this decided", "ADR", "architecture decision".
  • Adoncheli-changelogAuto-generate CHANGELOG.md entries from git commit history. Activate when user mentions "changelog", "release notes", "what changed", "generate changelog", "CHANGELOG", "release history".
  • Adoncheli-changelogAuto-generate CHANGELOG.md entries from git commit history. Activate when user mentions "changelog", "release notes", "what changed", "generate changelog", "CHANGELOG", "release history".
  • Adoncheli-context-healthReport the current state of the context window and recommend compression or cleanup actions. Activate when user mentions "context health", "context window", "how much context", "context full", "running out of context", "compress context".
  • Adoncheli-context-healthReport the current state of the context window and recommend compression or cleanup actions. Activate when user mentions "context health", "context window", "how much context", "context full", "running out of context", "compress context".
  • Adoncheli-data-policyAudit and document what personal or sensitive data the project collects, processes, and stores. Activate when user mentions "privacy", "data policy", "what data", "GDPR", "personal data", "data retention", "PII".
  • Adoncheli-data-policyAudit and document what personal or sensitive data the project collects, processes, and stores. Activate when user mentions "privacy", "data policy", "what data", "GDPR", "personal data", "data retention", "PII".
  • Adoncheli-debateRun an adversarial multi-role debate to surface trade-offs and reach a reasoned decision. Activate when user mentions "debate", "discuss", "trade-off", "decision", "compare options", "pros and cons", "choose between".
  • Adoncheli-debateRun an adversarial multi-role debate to surface trade-offs and reach a reasoned decision. Activate when user mentions "debate", "discuss", "trade-off", "decision", "compare options", "pros and cons", "choose between".

All agent skills → · MCP servers