Threat Modeler
@snippbot/threat-modeler ORG
Generate STRIDE threat models for system architectures. Identifies Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege threats with risk ratings, CWE references, and actionable mitigations.
Compliance Report Generator
@snippbot/job-compliance-report ORG
Weekly scheduled job that generates a compliance scorecard. Reviews authentication and access control, data protection, audit logging, vulnerability management, incident response, and change management — scoring each area and flagging anything below threshold.
OWASP Security Cheatsheets
@snippbot/owasp-cheatsheets ORG
Collection of OWASP-based security cheatsheets covering SQL injection prevention, XSS prevention, authentication best practices, secure headers, API security, and secrets management.
Dependency Vulnerability Alert
@snippbot/hook-dep-vuln-alert ORG
Hook that triggers when dependency files change (package.json, requirements.txt, Cargo.toml, go.mod). Scans updated dependencies against known vulnerability databases and alerts on HIGH/CRITICAL CVEs.
Security Audit Sandbox
sandbox_preset@snippbot/sandbox-security-audit ORG
Security auditing environment with Bandit, Semgrep, Trufflehog, Safety, and vulnerability scanners.
Incident Response Workflow
@snippbot/workflow-incident-response ORG
Structured incident response workflow following NIST SP 800-61. Guides teams through six phases — Detection, Triage, Containment, Investigation, Remediation, and Post-Mortem — each with checklists, prompts, and evidence-collection guidance.
Security Analyst Profile
@snippbot/profile-security-analyst ORG
AI assistant configured as an expert security analyst. Threat modeling, vulnerability assessment, OWASP Top 10, SAST/DAST, compliance frameworks, and incident response.
CVE Lookup MCP Server
@snippbot/mcp-cve-lookup ORG
MCP server for searching the NIST National Vulnerability Database (NVD). Look up CVE details by ID, search by keyword or product, and check library versions for known vulnerabilities with CVSS severity scores.
Security Analyst Suite
@snippbot/suite-security-analyst ORG
Complete Snippbot setup for security analysts. Bundles a security-focused AI persona with threat modeling, CVE lookup, an incident-response workflow, dependency vulnerability alerts, weekly compliance reporting, and an OWASP knowledge base.