Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Forensics

Forensics

200 Claude Code skills in the Forensics sub-category of Security.

200 skills · updated 2026-07-27 · showing 1–60 of 200 by quality score

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Use when answering factual or explanatory questions about the current project — codebase, architecture, conventions, workflows, constraints — with minimal cited evidence.
GLAW Investigations Bureau — the Case Commander. An FBI-style multi-agent investigative department that runs Field, Cyber, OSINT, HUMINT, Financial-Crimes, Legal-Intelligence,…
GLAW Investigations Bureau — the Special Agent (Field Investigator). The boots-on-the-ground collector: plans lawful interviews and interrogations, builds chain-of-custody for…
Automated evidence collection across compliance frameworks from cloud providers, identity systems, and security tools
Systematically verifies suspected security bugs to eliminate false positives. Produces TRUE POSITIVE or FALSE POSITIVE verdicts with documented evidence for each bug.
GLAW Investigations & White-Collar Crime Division lead — the firm's FBI/forensic case-building bench.
GLAW alter-ego / veil-piercing analyst — the factor engine that decides whether the corporate shield holds.
Build a compliance bundle — CycloneDX SBOM, SPDX license report, SARIF findings, OpenVEX/CycloneDX VEX, optional cosign signatures, manifest.json with SHA-256 sums, Markdown…
Cross-agent self-inspection of your AI-agent stack. Audits skills, MCP servers, hooks, plugins, commands, credentials, and memory files across Claude Code, Codex, OpenClaw, and…
Run the Vibe Innovation Framework mini-gate assessment to scope, justify, and execute a loop-back. Use when evidence in the current phase suggests an earlier phase's output is…
Extract specific sub-information from OSV vulnerability data — severity details (CVSS v2/v3), Maven package decomposition, version ranges, or event timelines.
Security forensics for git repos, AI skills, and MCP servers. Audits dependencies, detects prompt injection, credential theft, runtime dynamism, manifest drift, known CVEs, CISA…
**WORKFLOW SKILL** — Risk awareness before action. USE FOR: assessing risks (security, data integrity, compatibility, operational, reversibility) of any task at variable depth.
Use this skill when the user reports API authentication or missing credential issues in an aide-managed project, or when you observe authentication failures (401, 403, missing API…
Triage a security scanner's multi-finding output (read via a pluggable scan-format adapter) and turn findings into security work only after a complete operator-reviewed triage.
Full end-to-end browser testing for local web apps with a persistent logged-in session. Log in once into a named Chrome profile, then drive real flows with trace evidence against…
**DEFAULT for cost analysis spanning LLM tokens, cloud spend, and database query cost — produces a ranked findings list with monthly $-cost estimate, severity, and remediation…
Use when targeting ACM Asia Conference on Computer and Communications Security (ASIACCS) or deciding whether a computer-science manuscript fits this venue.
Use when targeting ACM Conference on Computer and Communications Security (CCS) or deciding whether a computer-science manuscript fits this venue.
Use when targeting ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec) or deciding whether a computer-science manuscript fits this venue.
Reviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection.
MANDATORY verification system that prevents Claude Code instances from making false claims or fabricating evidence.
MANDATORY verification system that prevents Claude Code instances from making false claims or fabricating evidence.
Govern Alibaba Cloud Container Registry (ACR) — Enterprise Edition vs Personal Edition selection, image vulnerability scanning, namespace IAM least privilege, image retention…
Use when user mentions ticker symbols, tokens, forex pairs, commodities, portfolio, trade, DCF, valuation, technical analysis, on-chain metrics, risk management, position sizing,…
Performs tracked, evidence-bounded security posture assessment for a project, sub-directory, module, concept, or feature topic with standards mapping and registered report output.
Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or
Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusion attempts, unauthorized
Use when targeting Annual Computer Security Applications Conference (ACSAC) or deciding whether a computer-science manuscript fits this venue.
Evaluate an app or website and produce a prioritized, evidence-backed report — SEO and crawlability, AI-readiness, social/sharing assets, security and standards,…
Drafts appellee response briefs for federal and state appellate courts, exploiting standards of review and record evidence to defend trial court decisions.
Test ranked attack surfaces autonomously, preserve evidence, and turn new access into additional attack-chain hypotheses.
APRA CPS 234 expert for Australian prudential information security. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment…
Use when audit binder, evidence binder, decision traceability, gate evidence, security evidence, legal evidence, or audit readiness needs.
A narrow, opinionated post-generation lint for backend/server-side code. Audits a changeset against a named catalogue of backend anti-patterns — swallowed errors, unvalidated…
Build the strongest possible bear case against a stock — a deliberate short-seller red-team that argues why NOT to hold, surfacing counterevidence to any bullish thesis
Edit, review, and create source-grounded technical and product documentation for common use across software projects.
Business performance and context analysis for CX projects. Diagnoses a company's health across five domains — revenue, customer metrics, operational health, market position, and…
Expert blockchain forensics assistant for investigators and auditors. Covers the full investigation methodology: threat recognition, incident scoping, data collection, transaction…
Assesses Non-Functional Requirements (security, performance, reliability, maintainability, observability) with evidence-based codebase analysis.
Conducts digital forensics investigations following a personal data breach, covering evidence preservation, chain of custody documentation, log analysis, scope determination, and…
Analyze web browser artifacts for forensic investigation. Use when investigating user browsing activity, downloaded files, cached content, or web-based attacks.
Builds tamper-evident audit logging — structured actor/action/target/result records for security-relevant events, append-only hash-chained or WORM/object-lock storage, PII-safe…
Use when determining the amount of alimony under Polish KRO — calculating justified needs of the entitled person vs. earning/property capacity of the obligor (art.
Implements CCPA Section 1798.105 right to delete and CPRA amendments including service provider obligations, statutory exceptions for legal, security, and internal uses, consumer…
Use after Cell reviews arrive to triage the decision, prioritize the (often substantial) new experiments by impact × feasibility, and draft a point-by-point response that is…
On-chain analysis and transaction forensics for blockchain security investigations. Provides capabilities for tracing fund flows, identifying suspicious patterns, MEV analysis,…
Festlandchina Wirtschaftsverkehr: Evidence Preservation China. Geführter Spezialskill mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
GLAW Master Command — the top-level intelligence-fusion orchestrator. Coordinates the FBI bureau, FinCEN financial-intelligence cell, CIA strategic-intelligence cell, SEC…
Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for
Docker, containerd/CRI-O, and Kubernetes forensic investigation covering container inventory (docker and crictl), privilege checks, image verification, layer analysis (dive),…
Review local PRs and high-risk local diffs through independent fresh-context reviewers and a root-verified evidence ledger.
Verifies provider credentials via NPI MCP, searches Medicare coverage policies via CMS Coverage MCP, and maps clinical evidence against payer policy requirements with…
Use when the user faces a PR crisis or reputational threat and needs rapid severity assessment, stakeholder messaging, and a communication timeline.
Write a structured escalation brief for an at-risk customer account. Use when an account has escalated, when a customer is threatening churn, when a P1 customer issue needs…
Digital forensics and blockchain analysis for CTF challenges. Use when analyzing disk images, memory dumps, event logs, network captures, or cryptocurrency transactions.
Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation.
Run and interpret CyberEdge's reviewed, bounded Nuclei vulnerability baseline for an explicitly authorized Scope.
Produces structured cybersecurity breach summary documents for regulatory and compliance use. Use when drafting breach summaries, incident response reports, forensic report…
Cybersecurity senior. Pentesting, red team, blue team, threat intel, compliance, forensics.
All Security skills →
More in SecurityRed Team (1,515) · Web Security (939) · Threat Hunting (588) · Identity Access (420) · Network Security (357) · Appsec Tools (333) · Compliance (191) · Malware Analysis (175) · Cloud Security (83) · Zero Trust (68) · Appsec Build (61) · Crypto Keymgmt (53) · Incident Response (18) · Ot Ics Security (7)