Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Appsec Build

Appsec Build

61 Claude Code skills in the Appsec Build sub-category of Security.

61 skills · updated 2026-07-27 · showing 1–60 of 61 by quality score

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Infrastructure as Code security scanning and policy enforcement for Terraform, CloudFormation, Kubernetes, and Pulumi
Developer security training and assessment for secure coding practices and vulnerability prevention
Use when: reviewing, designing, implementing, or debugging C/C++ for SEI CERT secure-coding violations detected by clang-tidy cert-* checks: unchecked standard-library return…
Audit software supply chain across every ecosystem (npm, pip, Go, Ruby, Cargo, Maven, Docker, Terraform) — pinning, vulnerabilities, secrets, SBOM, signing, branch protection,…
Autonomous DevSecOps & FinOps Guardrails. Orchestrates Gemini 3 Flash to audit Linux Kernel patches, Terraform cost drifts, and K8s compliance.
Expert infrastructure security engineer specializing in DevSecOps, cloud security, and compliance frameworks.
Review Azure workload security posture against the Well-Architected Framework Security pillar: identity and access, network boundaries, data protection, threat detection,…
Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning,
Security best practices for GitHub Actions workflows, supply chain security, and secure CI/CD pipelines
Enforces GitHub Actions security and compliance for this monorepo. Use when adding third-party actions, handling secrets, defining permissions, and reviewing CI security…
Maintain CI security/quality gates when changing workflows, dependency tooling, lint/type/test steps, audit policies, or merge-blocking checks for backend/frontend pipelines.
Detect code injection vulnerabilities in packages that dynamically generate or evaluate code via new Function(), eval(), vm.run*, or template literal interpolation.
Code Injection Detector - Auto-activating skill for Security Fundamentals. Triggers on: code injection detector, code injection detector Part of the Security Fundamentals skill…
Conjur integration. Manage security and secrets-management data, records, and workflows. Use when the user wants to interact with Conjur data.
Dockerfile security linting and best practice validation using Hadolint with 100+ built-in rules aligned to CIS Docker Benchmark.
Эксперт по container registry. Используй для настройки ECR, Harbor, Docker Hub, image security и CI/CD интеграции.
Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities — including custom security implementations such as ha — from…
Guide for implementing DefectDojo - an open-source DevSecOps, ASPM, and vulnerability management platform.
Combined DevOps and DevSecOps skill for CI/CD pipelines, infrastructure as code, security scanning, container hardening, cloud infrastructure, and monitoring.
DevSecOps skill for securing CI/CD pipelines, infrastructure as code, containers, Kubernetes, cloud deployments, secrets handling, dependency management, SAST/DAST/SCA, release…
Expert DevSecOps engineer specializing in secure CI/CD pipelines, shift-left security, security automation, and compliance as code.
Looks up OWASP DevSecOps Guideline phases, security tools, and pipeline checks. Returns tool configurations, CWE mappings, and integration patterns for CI/CD security.
DevSecOps patterns — shift-left security, SAST (semgrep/CodeQL), secrets detection (gitleaks/trufflehog), dependency scanning (trivy/grype), DAST, OPA/Falco policy-as-code,…
DevSecOps methodology guidance covering shift-left security, SAST/DAST/IAST integration, security gates in CI/CD pipelines, vulnerability management workflows, and security…
Performs end-to-end DevSecOps security analysis on any GitHub repository. Runs a 6-stage pipeline: repo ingestion and inventory, application context classification with STRIDE…
Drafting and iterating sections of The Federated Harbor whitepaper — the third paper in the Curiositech sequence after Anchor (local identity) and Bonded Commons (local…
Adversarial reviewer for The Federated Harbor whitepaper — the third paper in the Curiositech sequence after Anchor and Bonded Commons.
Evaluate GCP workload security posture against the Google Cloud Well-Architected Framework security pillar — covering zero trust, shift-left security, preemptive cyber defense, AI…
Analyze Infrastructure-as-Code (IaC) in git repositories to extract cloud architecture and security configurations for threat modeling.
Expert Harbor container registry administrator specializing in registry operations, vulnerability scanning with Trivy, artifact signing with Notary, RBAC, and multi-region…
Harden-Runner by StepSecurity is a CI/CD security agent that works like an EDR for GitHub Actions runners.
Infrastructure as Code security scanning for Terraform, Kubernetes, CloudFormation, and Azure ARM. Detects misconfigurations, security risks, and compliance violations before…
Reduce container attack surface by building application images on Google distroless base images that contain
Integrates Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software
Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities — including custom security implementations such as ha — from…
Implement centralized logging with ELK Stack, Loki, or Splunk for log collection, parsing, storage, and analysis across infrastructure.
Log Analysis Security - Auto-activating skill for Security Advanced. Triggers on: log analysis security, log analysis security Part of the Security Advanced skill category.
Review Oracle Cloud Infrastructure security, IAM, network, logging, encryption, and compliance posture.
Store and inject Salesforce auth URLs, JWT keys, and API credentials into CI without leaking them. NOT for runtime secrets in Apex.
Formal protocol verification with ProVerif and Tamarin Prover for multi-agent coordination systems. Use when modeling secrecy properties (escrow opacity, session note…
Use when stellar-forge release publishing touches GitHub Actions permissions, secrets, protected environments, token scope, signing keys, provenance, OIDC, registry credentials,…
Python-based threat modeling using pytm library for programmatic STRIDE analysis, data flow diagram generation, and automated security threat identification.
Use when configuring reCAPTCHA on Web-to-Case, Web-to-Lead, Experience Cloud forms, or Headless Identity flows, or when designing bot-mitigation strategies for Salesforce…
Orchestrates static analysis, vulnerability scanning, and automated patching into a continuous security workflow.
CronWorkflow patterns for scheduled automation: time-based execution, concurrency policies, orchestration pipelines, and GitHub Actions integration for DevSecOps.
Use to audit for exposed secrets — scanning code, config, git history, logs, images, and client bundles for credentials/keys/tokens; confirming exposure; and driving rotation (not…
Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions.
Scan commit history and CI for leaked credentials and rotate on every hit, because a pushed secret is already compromised.
Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities — including custom security implementations such as ha — from…
Use when performing deep security review of auth, crypto, secrets, or PII code requiring confidence-rated severity findings and OWASP checks
Secure coding practices and defensive programming patterns for building security-first applications. Use when implementing authentication, handling user input, managing sensitive…
Harbor is an open-source container registry that provides security features including vulnerability scanning
Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.
Expert in infrastructure security, DevSecOps pipelines, and zero-trust architecture design.
Execute use when setting up log aggregation solutions using ELK, Loki, or Splunk. Trigger with phrases like "setup log aggregation", "deploy ELK stack", "configure Loki", or…
Accesses TurboTax Online for prior year return downloads (PDF), current year filing status, imported W-2 and 1099 data summary, estimated refund or amount owed, and key return…
This skill enables Claude to manage container registries, including ECR, GCR, and Harbor. It should be used when the user needs to create, configure, or manage container image…
This skill sets up log aggregation solutions using ELK (Elasticsearch, Logstash, Kibana), Loki, or Splunk.
This skill covers hardening container images by minimizing attack surface, removing unnecessary packages, implementing
Use this skill when Salesforce development pipelines must be reviewed for DevSecOps compliance — covering Salesforce Code Analyzer (SCA) finding triage and false positive review,…
All Security skills →
More in SecurityRed Team (1,515) · Web Security (939) · Threat Hunting (588) · Identity Access (420) · Network Security (357) · Appsec Tools (333) · Forensics (200) · Compliance (191) · Malware Analysis (175) · Cloud Security (83) · Zero Trust (68) · Crypto Keymgmt (53) · Incident Response (18) · Ot Ics Security (7)