Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Appsec Tools › Page 3

Appsec Tools (Page 3 of 6)

333 Claude Code skills in the Appsec Tools sub-category of Security.

333 skills · updated 2026-07-27 · showing 121–180 of 333 by quality score

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Configure perform API fuzzing to discover edge cases, crashes, and security vulnerabilities. Use when performing specialized testing.
Building effective fuzzing harnesses to maximize code coverage and vulnerability discovery through automated input generation
Generate a CVE 5.x JSON document from an tracking issue, ready to paste into the Vulnogram `#source` tab of the ASF CVE tool at…
[FREE — public data, free API key required] Environmental disaster and hazard data -- GDACS disaster alerts, USGS earthquakes, NASA FIRMS fire detection, NASA EONET natural events
Gitleaks is an open-source SAST tool for detecting hardcoded secrets like passwords, API keys, and tokens in Git repositories, files, and directories.
Configures GKE Backup Plans and restore workflows. Use for backup policies, disaster recovery, or GKE cluster restores. Don't use for database backups.
Improves GKE workload reliability, using PDBs, health probes, and topology spread constraints. Use when configuring GKE workload reliability, setting up PDBs, or configuring GKE…
Apply Go project conventions — Go 1.25.x toolchain pinned via toolchain directive and GOTOOLCHAIN=local, vendored deps via go mod vendor, golangci-lint v2 strict (~50 enabled…
Scan container images, filesystems, and SBOMs for known vulnerabilities using Anchore Grype. Supports major OS package ecosystems and language-specific packages with EPSS risk…
Design backups that actually work when they are needed. Covers RPO and RTO definition, the 3-2-1 rule, encryption before leaving the host, ransomware-resistant immutable storage,…
Runs the HawkScan DAST security loop — configure, scan, fix all reported vulnerabilities (not just your changes), rescan to verify.
Help HR and business leaders plan for and respond to workforce crises — layoffs handled poorly, safety incidents, natural disasters, leadership scandals, or sudden business…
Hunt CI/CD pipeline vulnerabilities — GitHub Actions workflow injection (pull_request_target Pwnrequest + ${{ }}-into-shell), self-hosted runner poisoning, OIDC trust-policy…
Hunt gRPC vulnerabilities — server reflection enabled (enumerate all services/methods), missing authentication / metadata-stripping on internal endpoints, plaintext gRPC over…
Hunt Spring Boot specific vulnerabilities — Actuator endpoints (heapdump, env, loggers, mappings, shutdown), Spring Expression Language (SpEL) injection → RCE, H2 console RCE,…
Infrastructure as Code (IaC) security scanning using Checkov with 750+ built-in policies for Terraform, CloudFormation, Kubernetes, Dockerfile, and ARM templates.
Terraform / Pulumi / CloudFormation review — state management, module contract, plan output, drift detection, security scan (tfsec/checkov/OPA), cost diff (Infracost).
Scans Infrastructure as Code for security misconfigurations. Wraps tfsec for Terraform and Checkov for multi-cloud IaC.
Provides comprehensive IBM Mainframe administration, development, and modernization guidance including z/OS operations, JCL scripting, COBOL/PL/I programming, CICS/IMS…
Integrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based
Deploy and configure Rapid7 InsightVM Security Console and Scan Engines for authenticated and unauthenticated
Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards,
Deploy and operate Greenbone/OpenVAS vulnerability management using the python-gvm library to create scan targets,
Vulnerability remediation SLAs define mandatory timeframes for patching or mitigating identified vulnerabilities
Build automated alerting for vulnerability remediation SLA breaches with severity-based timelines, escalation
Scan for reports that have not yet been copied into as tracking issues, present the proposed imports to the user, and — defaulting to *import un — from…
Use when the user mentions infrastructure, cloud, AWS, GCP, Terraform, deployment, DevOps, containers, Kubernetes, serverless, VPC, networking, databases, load balancers, CDN,…
Check JFrog Public Catalog and stored packages for a version, interpret catalog security signals, and download through Artifactory (JFrog Platform locations, remote cache,…
KLIC & WIBON expert skill voor Nederland. Beantwoord vragen over graafmeldingen, kabels & leidingen, Kadaster en WIBON-wetgeving.
Audits project dependencies for vulnerabilities. Multi-ecosystem support (npm, .NET, Python, Go). CVSS-based severity classification.
Esta skill deve ser usada quando o usuário solicitar candidaturas automáticas em vagas do LinkedIn relacionadas a Inteligência Artificial (IA) no Brasil, priorizando vaga — from…
Esta skill deve ser usada quando o usuário solicitar candidaturas automáticas em vagas do LinkedIn relacionadas a Inteligência Artificial (IA) no Brasil, priorizando vaga — from…
Checks outdated packages, unused deps, reinvented wheels, CVE/CVSS vulnerability scan. Use when auditing dependencies. — from security/appsec-tools
Checks outdated packages, unused deps, reinvented wheels, CVE/CVSS vulnerability scan. Use when auditing dependencies. — from majiayu000/claude-skill-registry
Use when apply log transformation when peak intensity distributions are right-skewed with heteroscedastic variance (intensity-dependent noise), particularly in QC-based batch…
API de Multi-CD (Centros de Distribuição) da Tray. Utilize quando o desenvolvedor precisar gerenciar múltiplos centros de distribuição, incluindo cadastro, atualização, exclusão…
Nessus integration. Manage data, records, and automate workflows. Use when the user wants to interact with Nessus data.
Systematische Erhebung, Dokumentation und Priorisierung von Non-Functional Requirements (NFRs) nach ISO 25010 und TOGAF-Qualitätsattributen.
Cleans up NNF deployments impacted by vulnerable or outdated container images using guided execution.
Cria o perfil de uma nova pessoa no vault em pessoas/.md — preenche frontmatter (nome, cargo, time, status, tipo-relacao) e estrutura as seções padrão (contexto, pontos…
Scans npm dependencies for known vulnerabilities using the npm audit JSON API and the OSV.dev REST API (api.osv.dev/v1/query).
Scanner de vulnerabilidades Nuclei como complemento al analisis LLM. Detecta CVEs conocidos, misconfiguraciones y paneles expuestos.
Nuclei is a high-performance vulnerability scanner by ProjectDiscovery that uses simple YAML-based templates to detect security issues across applications, APIs, networks, DNS,…
Executes ProjectDiscovery Nuclei security scanning templates against target URLs. Supports custom YAML template authoring, CVE detection via nuclei-templates repository, and SARIF…
Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation,…
Week 2 of the exploit development curriculum. Covers fuzzing methodology: target selection, corpus generation, coverage-guided fuzzing with AFL++/libFuzzer, structured fuzzing,…
KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.
WPA3 / SAE (Simultaneous Authentication of Equals) attack methodology — transition-mode (mixed WPA2/WPA3) downgrade, Dragonblood side-channel attacks (CVE-2019-9494, 9495, 13377,…
오픈소스 취약점 분석 스킬. 사용자가 오픈소스 패키지 이름과 사용 중인 버전을 입력하면, NVD(NIST), OSV.dev(Google), GitHub Advisory 3개 데이터 소스에서 CVE 취약점을 조회하여 최신 버전 정보와 함께 보안 리포트를 생성한다.
Backup and restore OpenClaw workspace state and agents across machines using git. Enables disaster recovery by syncing SOUL.md, MEMORY.md, memory files, cron jobs, agents…
>\n Configure and execute authenticated vulnerability scans using OpenVAS/Greenbone\
OSV-Scanner is Google's open-source vulnerability scanner that checks project dependencies against the OSV.dev database.
Scan for security vulnerabilities using pnpm audit, Snyk, and automated tools. Use when checking security, before deployments, or resolving CVEs.
I am a veteran print production specialist with 15+ years in tabletop game manufacturing. I've shepherded hundreds of games from digital files to retail-ready products, working…
API de Parceiros da Tray. Utilize quando o desenvolvedor precisar gerenciar parceiros/revendedores da loja, incluindo listagem, consulta, cadastro, atualização e exclusão.
Identify and eliminate host-device synchronizations in PyTorch code. Detects sync points (.item(), .cpu(), boolean indexing, torch.tensor on CUDA), classifies false vs true…
Configure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and
Configure and execute authenticated vulnerability scans using OpenVAS/Greenbone Vulnerability Management with
Authenticated (credentialed) vulnerability scanning uses valid system credentials to log into target hosts and
Leverage the CISA Known Exploited Vulnerabilities catalog alongside EPSS and CVSS to prioritize CVE remediation
All Security skills →
More in SecurityRed Team (1,515) · Web Security (939) · Threat Hunting (588) · Identity Access (420) · Network Security (357) · Forensics (200) · Compliance (191) · Malware Analysis (175) · Cloud Security (83) · Zero Trust (68) · Appsec Build (61) · Crypto Keymgmt (53) · Incident Response (18) · Ot Ics Security (7)