Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Appsec Tools › Page 2

Appsec Tools (Page 2 of 7)

381 Claude Code skills in the Appsec Tools sub-category of Security.

381 skills · updated 2026-08-26 · showing 61–120 of 381 by quality score

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Manage a Cobo TSS Node for MPC threshold signing. Use when: setting up a new TSS Node, starting/stopping the node service, checking node status or health, signing for key share…
Create, validate, inspect, and restore a secret-free allowlisted backup of Codex, Claude Code, and shared Agent skills, memories, rules, commands, and automations.
Post-edit loop that invokes `/codex:rescue` for a second-model review of the current branch, collects the findings, and hands them off to `refactor-verify`'s review-driven fix…
Configure code scanning in Harness pipelines using STO security scanners. Helps identify where to inject SAST/SCA scanning steps into existing pipelines, recommends appropriate…
Container vulnerability scanning and dependency risk assessment using Grype with CVSS severity ratings, EPSS exploit probability, and CISA KEV indicators.
Scans Docker and OCI container images for vulnerabilities using Trivy JSON output and the Docker Hub API v2 for image metadata.
Scans containers and Dockerfiles for security issues. Wraps Hadolint for Dockerfile linting and Trivy for container image scanning.
Apply Google's continuous fuzzing methodology using OSS-Fuzz and ClusterFuzz. Emphasizes coverage-guided fuzzing, automated bug triage, and integration into CI/CD.
Scans Cosmos SDK blockchain modules and CosmWasm contracts for consensus-critical vulnerabilities — chain halts, fund loss, state divergence.
Create custom Semgrep rules for vulnerability detection. Use when writing new rules for specific vulnerability patterns, creating org-specific detections, or building rules for…
Respond to crises using incident command structure, stakeholder communication, and recovery planning. Use during security breaches, PR disasters, or operational failures.
Audit emergency and crisis triage systems for call prioritization accuracy, resource dispatching algorithm quality, severity classification model evaluation, response time…
Startup crisis management operating system covering 14 crisis types with severity scoring, escalation matrices, war room protocols, stakeholder communication playbooks, runway…
Designs cloud architectures, creates migration plans, generates cost optimization recommendations, and produces disaster recovery strategies across AWS, Azure, and GCP.
Identifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance.
Expert methodology for identifying, assessing, and mitigating technical and operational risks including security, incidents, compliance, and disaster recovery.
Audit exact npm dependency versions against OSV through Runx native HTTP and emit replay-verified evidence with no unverified findings.
Look up Common Vulnerabilities and Exposures (CVEs) with severity scores, affected software, exploitability status, and remediation guidance.
CVE research, standalone PoC script and report generation. Given a CVE ID, researches NVD and advisories, generates a safe Python PoC, and writes a detailed vulnerability report.
Remediate dependency vulnerability scanner failures by verifying live package registry data and upgrading instead of suppressing.
Retrieve CVE risk scores from NVD. Auto-invoked whenever a CVE ID is mentioned to display CVSS score, severity, CWE, and description.
Searches the NIST NVD database for CVE vulnerabilities using API 2.0. Returns CVE details, CVSS scores, affected software, and references.
CVE vulnerability testing coordinator that identifies technology stacks, researches known vulnerabilities, and tests applications for exploitable CVEs using public exploits and…
Эксперт CVE tracking. Используй для vulnerability management, security advisories и patch prioritization.
Look up CVE vulnerability details by ID via MITRE CVE API with NVD fallback — severity, CVSS score, affected products, and references
Score a vulnerability with CVSS v3.1: derive the base metric vector, compute the score and severity rating, and explain each metric choice.
Computes an exact CVSS v3.1 base score and vector from a vulnerability description. Infers metrics from context, picks the most accurate score when info is sufficient, and asks…
Runs a Checkmarx ASCA (AI Security Code Assistant) SAST scan on a SOURCE CODE file to detect code vulnerabilities, and remediates findings using the Checkmarx MCP tool.
Fast web fuzzer for DAST testing with directory enumeration, parameter fuzzing, and virtual host discovery.
Fast, template-based vulnerability scanning using ProjectDiscovery's Nuclei with extensive community templates covering CVEs, OWASP Top 10, misconfigurations, and security issues…
Dynamic Application Security Testing with two tiers: Nuclei (fast, template-based) and ZAP (deep, active scanning via Docker).
Dynamic Application Security Testing execution and management. Configure and execute OWASP ZAP and Nuclei scans, run authenticated scanning, manage scan policies and scope,…
Dynamic application security testing (DAST) using OWASP ZAP (Zed Attack Proxy) with passive and active scanning, API testing, and OWASP Top 10 vulnerability detection.
Implement reliable data backup and recovery strategies with automated scheduling, encryption, rotation policies, and disaster recovery testing.
Set up database replication for high availability and disaster recovery. Use when configuring master-slave replication, multi-master setups, or replication monitoring.
Expert database administrator specializing in modern cloud databases, automation, and reliability engineering.
Implement backup and restore strategies for disaster recovery. Use when creating backup plans, testing restore procedures, or setting up automated backups.
Static Application Security Testing (SAST). Scans the code for security vulnerabilities. A BLOCKING GATE — the `sast` receipt is what lets a ticket leave CODE, in every tier.
Audit locked npm dependencies against OSV advisories and emit exact-version CVE evidence.
Use when the user names one or a few specific dependencies (with version) — not a whole project — and asks "does io.ktor:ktor-server-core 3.1.0 have any known vulnerabilities",…
Dependency Vulnerability Checker - Auto-activating skill for Security Fundamentals. Triggers on: dependency vulnerability checker, dependency vulnerability checker Part of the…
Scans project dependencies using OSV.dev API and Snyk CLI for known CVEs across npm, PyPI, Maven, and Go modules. Generates SBOM in CycloneDX format via syft.
Turns npm audit/Snyk results into prioritized patch plans with severity assessment, safe upgrade paths, breaking change analysis, and rollback strategies.
Dependency-upgrade campaign — outdated scan, batch-by-severity, breaking-change remediation, lockfile audit.
Designs and validates backup, point-in-time-recovery, and disaster-recovery strategy for datastores — sets RPO/RTO targets, configures snapshot plus continuous WAL/binlog/oplog…
Use when analyzing user journeys, auditing UX quality, prototyping flows, or designing new pages/features from a product perspective.
Analyse et évalue les vulnérabilités d'un système ou d'une application. À utiliser pour comprendre et prioriser les vulnérabilités.
Analyze disaster prediction and early warning systems — model accuracy for flood, earthquake, wildfire, hurricane, and tsunami hazards, data pipeline reliability from sensor…
Implement disaster recovery and backup strategies for Proxmox. Create and manage backups, test recovery procedures, and ensure business continuity for your infrastructure.
Use when designing, scheduling, or running a disaster recovery exercise — tabletops, live drills, chaos engineering, GameDays.
Write a disaster recovery plan for a service or system — covering RPO/RTO targets, failure scenario runbooks, backup and restore procedures, DR testing cadence, and communication…
Execute comprehensive disaster recovery tests, validate recovery procedures, and document lessons learned from DR exercises.
Manage DNS records, routing policies, and failover configurations for high availability and disaster recovery.
Runs Trivy against a Docker image and produces a prioritized CVE list grouped by severity with fix availability. Filters out CVEs with no available fix.
Audits Dockerfiles for security vulnerabilities using Hadolint and Trivy container scanner. Recommends hardening steps based on CIS Docker Benchmark and Snyk container advisories.
Crie, revise e mantenha a documentação do projeto Dental System. Use quando Codex precisar atualizar README, guias de instalação, scripts de execução, documentação de API,…
Ensure architecture docs define RPO/RTO, failover paths, data consistency, and DR drillability.
Generate a Disaster Recovery plan with RTO/RPO targets. Use when someone asks to "create a DR plan", "disaster recovery", "business continuity", or "RTO RPO".
Perform dynamic security testing against running web applications and APIs to discover vulnerabilities through active probing and fuzzing.
Property-based testing and fuzzing using Echidna for smart contracts. Includes invariant definition, corpus management, coverage analysis, and CI/CD integration for comprehensive…
All Security skills →
More in SecurityRed Team (1,582) · Web Security (1,094) · Threat Hunting (754) · Identity Access (496) · Network Security (414) · Forensics (295) · Malware Analysis (207) · Compliance (204) · Cloud Security (94) · Zero Trust (82) · Appsec Build (66) · Crypto Keymgmt (65) · Incident Response (20) · Ot Ics Security (9)