Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 110

Claude Security Skills (Page 110 of 149)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

8,927 skills · updated 2026-07-28 · showing 6541–6600 of 8,927 by quality score

Sub-topics:Red Team (1,518)Web Security (945)Threat Hunting (589)Identity Access (433)Network Security (361)Appsec Tools (336)Forensics (206)Compliance (192)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Review SAP identity and access management posture: Cloud Identity Services (IAS/IPS), Authorization and Trust Management (XSUAA), role collections, GRC Access Control, and…
Advisory triage of an SAP transformation program portfolio: workstream prioritization, dependency and risk mapping, value vs effort classification, readiness gating across…
Source code vulnerability hunting (SAST). Decomposes analysis into specialized passes: map entry points, map dangerous ops, trace flows, find gaps, adversarial validation,…
Perform codebase analysis and architecture mapping as the first phase of a security assessment. Explores the tech stack, frameworks, entry points, data flows, and trust…
Static Application Security Testing orchestration and analysis. Execute Semgrep, Bandit, ESLint security plugins, CodeQL, and other SAST tools.
Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping. Use when: (1) Scanning Python code for security vulnerabilities and anti-patterns, (2)…
Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in…
Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.
Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code.
Industrialized DevSecOps pipeline integration combining Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis…
Detect insecure file upload vulnerabilities in a codebase using a three-phase approach: discovery (find all upload sites), batched verify (check extension bypass and related…
Detect GraphQL injection vulnerabilities in a codebase using a three-phase approach: recon (confirm GraphQL usage and find unsafe operation document assembly sites), batched…
Detect hardcoded sensitive data (API keys, access tokens, private keys, passwords, etc.) in publicly accessible code — frontend JavaScript, mobile apps, client-side bundles, and…
Multi-language static application security testing using Horusec with support for 18+ programming languages and 20+ security analysis tools.
Detect Insecure Direct Object Reference (IDOR) vulnerabilities in a codebase using a three-phase approach: recon (find candidates), batched verify (check authorization in parallel…
Wire a static analysis scanner into CI so it blocks real security bugs while staying under a defined noise budget.
Detect insecure JWT (JSON Web Token) implementations in a codebase using a two-phase approach: first map all JWT issuance and verification sites to understand the token lifecycle…
Detect missing authentication and broken function-level authorization vulnerabilities in a codebase using a three-phase approach: recon (map endpoints and the role/permission…
Detect path traversal vulnerabilities in a codebase using a three-phase approach: recon (find file-loading sinks with dynamic paths), batched verify (trace user input and…
Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration.
Runs static application security testing using Semgrep rules and CodeQL queries against pull request diffs.
Detect Remote Code Execution (RCE) vulnerabilities in a codebase using a three-phase approach: recon (find dangerous execution sinks), batched verify (trace user input to sinks in…
Consolidate all SAST vulnerability results from the sast/ folder into a single final report ranked by severity and confidentiality impact.
Run or ingest static application security testing (SAST) results on a codebase, triage them to remove false positives, and confirm the real issues with code evidence and…
Compiles and validates custom Semgrep SAST rules using the semgrep-core engine. Tests pattern matching against sample codebases and generates rule performance benchmarks with p/ci…
Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.
Detect SQL injection vulnerabilities in a codebase using a three-phase approach: recon (find unsafe SQL construction sites), batched verify (trace user input to those sites in…
Detect Server-Side Request Forgery (SSRF) vulnerabilities in a codebase using a three-phase approach: recon (find outbound call sites), batched verify (trace user input to…
Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched…
Detect Cross-Site Scripting (XSS) vulnerabilities in a codebase using a three-phase approach: recon (find HTML/JS/DOM sink sites), batched verify (trace user input to sinks in…
Detect XML External Entity (XXE) vulnerabilities in a codebase using a three-phase approach: recon (find XML parsing sites without external-entity hardening), batched verify…
Generate a Software Bill of Materials (SBOM) from your AWS environment and scan for vulnerable/compromised packages.
Sbom Cyber Serviceroboter Haushalt im Robotik- und KI-Recht: prüft konkret Prüft SBOM, Dependency-Management, CVE-Tracking, Sicherheitsanforderungen und Na.
Generates Software Bill of Materials using Syft for container images and matches components against the NVD CVE database via OSV.dev API.
Erstellt SBOM- und Software-Composition-Workflows für OSS, Security, CRA, Kundenverträge und M&A im Softwarerecht De Eu Us.
Software Bill of Materials (SBOM) generation using Syft for container images, filesystems, and archives.
Prüft SBOM, Dependency-Management, CVE-Tracking, Sicherheitsanforderungen und Nachweise für Robotiksoftware.
Sbom Vulnerability Gate skill for security operations in Creative Liberation Engine V6.
Generates Software Bill of Materials using Syft and scans for CVEs with Grype. Cross-references findings against the NVD and OSV databases for comprehensive vulnerability…
REST, GraphQL, and gRPC API security audit — authentication, authorization, data exposure, and configuration
Clickjacking and UI redressing detection — missing frame protection headers and CSP frame-ancestors
Cryptography misuse detection — weak algorithms, ECB mode, static IVs, weak PRNG, and key management flaws
Cross-Site Request Forgery detection — missing tokens, SameSite misconfiguration, and CORS-CSRF interaction
Incremental security scan for changed files only — optimized for PR and commit-level reviews
Infrastructure-as-Code security scanning — Dockerfile, Kubernetes, Terraform, and GitHub Actions misconfigurations
Master orchestration skill that coordinates the entire 4-phase security scanning pipeline
Path traversal and directory traversal detection — LFI, RFI, zip slip, and symlink attacks
Final consolidated security assessment report generator with CVSS severity and remediation roadmap
Hardcoded secrets, API keys, tokens, credentials, and private key detection in source code
SQL Injection detection across all variants — classic, blind, time-based, second-order, and UNION-based
Cross-Site Scripting detection for Reflected, Stored, and DOM-based XSS across all frameworks
Software Composition Analysis (SCA) using Synopsys Black Duck for identifying open source vulnerabilities, license compliance risks, and supply chain security threats with CVE,…
Plan and remediate dependency vulnerabilities with Endor SCA findings, VersionUpgrade/UIA evidence, separate low-risk PR lanes, deterministic risk decisions, local validation, and…
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC…
Scaledrone integration. Manage data, records, and automate workflows. Use when the user wants to interact with Scaledrone data.
Review and design Scaleway network topology for security and high availability: VPC layout, Private Network attachment across zones, security group rules, Load Balancer…
Run OWASP dep-scan before adopting dependencies, containers, or generated code so agents get a reviewable vulnerability, license, SBOM, and risk report.
Run a pre-trust security pass over skill packs and prompt bundles before they get shared, merged, or deployed.
Use Agentic Radar to statically scan agent workflows, map tools and MCP servers, generate shareable security reports, and optionally run adversarial runtime tests before rollout.
Generate a reviewable security report for a supported agent workflow before deployment by scanning its code, tools, MCP usage, and known vulnerability surface.
Search all 8,927 Security skills →