Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Appsec Tools › Page 4

Appsec Tools (Page 4 of 7)

381 Claude Code skills in the Appsec Tools sub-category of Security.

381 skills · updated 2026-08-26 · showing 181–240 of 381 by quality score

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Use when apply log transformation when peak intensity distributions are right-skewed with heteroscedastic variance (intensity-dependent noise), particularly in QC-based batch…
API de Multi-CD (Centros de Distribuição) da Tray. Utilize quando o desenvolvedor precisar gerenciar múltiplos centros de distribuição, incluindo cadastro, atualização, exclusão…
Use when a task needs the judgment of a museum conservator — writing a condition report or treatment proposal, deciding whether damage warrants intervention, setting environmental…
Nessus integration. Manage data, records, and automate workflows. Use when the user wants to interact with Nessus data.
Systematische Erhebung, Dokumentation und Priorisierung von Non-Functional Requirements (NFRs) nach ISO 25010 und TOGAF-Qualitätsattributen.
Cleans up NNF deployments impacted by vulnerable or outdated container images using guided execution.
Cria o perfil de uma nova pessoa no vault em pessoas/.md — preenche frontmatter (nome, cargo, time, status, tipo-relacao) e estrutura as seções padrão (contexto, pontos…
Scans npm dependencies for known vulnerabilities using the npm audit JSON API and the OSV.dev REST API (api.osv.dev/v1/query).
Scanner de vulnerabilidades Nuclei como complemento al analisis LLM. Detecta CVEs conocidos, misconfiguraciones y paneles expuestos.
Nuclei is a high-performance vulnerability scanner by ProjectDiscovery that uses simple YAML-based templates to detect security issues across applications, APIs, networks, DNS,…
Executes ProjectDiscovery Nuclei security scanning templates against target URLs. Supports custom YAML template authoring, CVE detection via nuclei-templates repository, and SARIF…
Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation,…
Week 2 of the exploit development curriculum. Covers fuzzing methodology: target selection, corpus generation, coverage-guided fuzzing with AFL++/libFuzzer, structured fuzzing,…
KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.
WPA3 / SAE (Simultaneous Authentication of Equals) attack methodology — transition-mode (mixed WPA2/WPA3) downgrade, Dragonblood side-channel attacks (CVE-2019-9494, 9495, 13377,…
오픈소스 취약점 분석 스킬. 사용자가 오픈소스 패키지 이름과 사용 중인 버전을 입력하면, NVD(NIST), OSV.dev(Google), GitHub Advisory 3개 데이터 소스에서 CVE 취약점을 조회하여 최신 버전 정보와 함께 보안 리포트를 생성한다.
Backup and restore OpenClaw workspace state and agents across machines using git. Enables disaster recovery by syncing SOUL.md, MEMORY.md, memory files, cron jobs, agents…
>\n Configure and execute authenticated vulnerability scans using OpenVAS/Greenbone\
OSV-Scanner is Google's open-source vulnerability scanner that checks project dependencies against the OSV.dev database.
Scan for security vulnerabilities using pnpm audit, Snyk, and automated tools. Use when checking security, before deployments, or resolving CVEs.
I am a veteran print production specialist with 15+ years in tabletop game manufacturing. I've shepherded hundreds of games from digital files to retail-ready products, working…
API de Parceiros da Tray. Utilize quando o desenvolvedor precisar gerenciar parceiros/revendedores da loja, incluindo listagem, consulta, cadastro, atualização e exclusão.
Identify and eliminate host-device synchronizations in PyTorch code. Detects sync points (.item(), .cpu(), boolean indexing, torch.tensor on CUDA), classifies false vs true…
Configure and execute agentless vulnerability scanning using network protocols, cloud snapshot analysis, and
Configure and execute authenticated vulnerability scans using OpenVAS/Greenbone Vulnerability Management with
Authenticated (credentialed) vulnerability scanning uses valid system credentials to log into target hosts and
Leverage the CISA Known Exploited Vulnerabilities catalog alongside EPSS and CVSS to prioritize CVE remediation
Performs vulnerability remediation on endpoints by prioritizing CVEs based on risk scoring, deploying patches,
Personal Habit Optimization for disaster response networks. Use when work requires personal habit optimization for disaster response networks with guardrails, traceable execution,…
Audit whether a project can actually recover from data loss — not just whether backups exist — then emit a phased DR plan.
Audit a project for destructive-operation and migration safety gaps, then produce a phased safeguard plan.
Hosted MCP för Manager Pohlman Protean. Endast för orchestrator-subagenten. Kund, projekt, tasks, prio, status, assignee, kommentarer.
Preserve and conserve library and archival materials. Covers environmental controls (temperature, humidity, light), handling procedures, book repair techniques (torn pages, loose…
The Common Vulnerability Scoring System (CVSS) is the industry standard framework maintained by FIRST (Forum
Build and operate the "Privacy-Preserving Data Brokering for disaster response networks" capability for disaster response networks.
Use when escalating privileges on a Linux host — SUID/SGID & GTFOBins, sudo LPE (CVE-2025-32462/32463), capabilities & LD_PRELOAD, kernel LPE (CVE-2024-1086, Dirty Pipe,…
Use when escalating privileges on a Windows host — SeImpersonate Potato chains (GodPotato/PrintNotifyPotato), service & DLL hijacking, UAC bypass (fodhelper/ICMLuaUtil), kernel…
API de Produtos da Tray. Utilize quando o desenvolvedor precisar listar, consultar, cadastrar, atualizar ou excluir produtos no catálogo de uma loja Tray.
Padroes MVC do Protheus (FWFormModel/FWFormView) para ADVPL/TLPP. Use esta skill SEMPRE que o usuario pedir para criar ou manter rotinas MVC, cadastros CRUD, browses FWMBrowse,…
Proxmox VE administration for single-node and clustered environments. Use when Codex needs to operate or troubleshoot Proxmox hosts, VMs, LXCs, storage, networking, backups,…
Rapid7 Insight Platform integration. Manage Users, Roles, Organizations, Assets, Vulnerabilities, Findings and more.
CVE lookup and applicability assessment skill for matching collected product names, versions, and service fingerprints to known vulnerabilities.
CVE validation domain card. Use after CVE lookup has produced applicable or candidate CVEs and red-team mode needs scoped evidence to decide whether to continue, pivot, or report.
Define deployment reliability, availability zones, failover, degradation, backup, restore, RPO, RTO, disaster recovery, resilience testing, and recovery ownership.
Use when designing how a database keeps multiple copies of its data in agreement across nodes for availability, read scaling, and disaster recovery: the three foundational…
Restore the Exobrain harness onto a wiped Mac or a brand-new machine, from the daily collective backup tarball + GitHub + cloud re-auth.
Review and triage semgrep security scan results to identify true positive vulnerabilities. Use when analyzing semgrep output, triaging security findings, reviewing static analysis…
Automated code review and security linting integration for CI/CD pipelines using reviewdog. Aggregates findings from multiple security and quality tools (SAST, linters,…
Develop comprehensive risk management plans for collections and cultural venues including disaster preparedness, security protocols, and insurance coordination
Install SecOpsAgentKit when a Claude Code session needs repeatable security review skills for SAST, DAST, container scanning, secrets checks, policy review, and remediation…
Rust security skill for supply chain safety and memory-safe development. Use when auditing dependencies with cargo-audit, enforcing policies with cargo-deny, reviewing RUSTSEC…
Safety hooks for Claude Code — 695 pre-built hooks that prevent file deletion, credential leaks, git disasters, and token waste during autonomous AI coding sessions.
Source code vulnerability hunting (SAST). Decomposes analysis into specialized passes: map entry points, map dangerous ops, trace flows, find gaps, adversarial validation,…
Perform codebase analysis and architecture mapping as the first phase of a security assessment. Explores the tech stack, frameworks, entry points, data flows, and trust…
Static Application Security Testing orchestration and analysis. Execute Semgrep, Bandit, ESLint security plugins, CodeQL, and other SAST tools.
Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping. Use when: (1) Scanning Python code for security vulnerabilities and anti-patterns, (2)…
Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in…
Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.
Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code.
Industrialized DevSecOps pipeline integration combining Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis…
All Security skills →
More in SecurityRed Team (1,582) · Web Security (1,094) · Threat Hunting (754) · Identity Access (496) · Network Security (414) · Forensics (295) · Malware Analysis (207) · Compliance (204) · Cloud Security (94) · Zero Trust (82) · Appsec Build (66) · Crypto Keymgmt (65) · Incident Response (20) · Ot Ics Security (9)