Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 113

Claude Security Skills (Page 113 of 176)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

10,533 skills · updated 2026-08-26 · showing 6721–6780 of 10,533 by quality score

Sub-topics:Red Team (1,582)Web Security (1,094)Threat Hunting (754)Identity Access (496)Network Security (414)Appsec Tools (381)Forensics (295)Malware Analysis (207)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Executes Atomic Red Team tests for MITRE ATT&CK technique validation using the atomic-operator Python framework.
Performs proactive threat hunting in Elastic Security SIEM using KQL/EQL queries, detection rules, and Timeline
Use YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems
Use PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management,
Conduct a sector-specific threat landscape assessment by analyzing threat actor targeting patterns, common attack
Use OWASP Threat Dragon to create data flow diagrams, identify threats using STRIDE and LINDDUN methodologies,
Simulates VLAN hopping attacks using switch spoofing and double tagging techniques in authorized environments
Performs authenticated and unauthenticated vulnerability scanning using Tenable Nessus to identify known vulnerabilities,
Bypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution,
Performs systematic security testing of web applications following the OWASP Web Security Testing Guide (WSTG)
Triage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to
Execute web cache deception attacks by exploiting path normalization discrepancies between CDN caching layers
Exploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through
Execute a wireless network penetration test to assess WiFi security by capturing handshakes, cracking WPA2/WPA3
Conduct wireless network security assessments using Kismet to detect rogue access points, hidden SSIDs, weak
Develop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral
Use when Jared asks about selling or positioning the PerformOS agent package to clients. Covers cloud (Orgo) and local editions, two-tier Standard/Advanced pricing, "up to 10…
Genera fragmentos de código inicial funcionales para Arduino IDE y ESP-IDF a partir del mapeo de pines y periféricos de un microcontrolador ESP32.
中文优先:用于Perl安全相关任务,帮助识别、设计、实现或验证对应工作流。English keywords: Comprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web…
Use when designing or reviewing permission-set-group architecture, especially profile minimization, group composition, muting strategy, and migration away from profile-heavy…
Use when designing or auditing Salesforce access control — deciding between Profiles, Permission Sets, and Permission Set Groups.
Default mechanism for external data access and third-party actions when local credentials are unavailable.
Apply Perplexity security best practices for API key management and query safety. Use when securing API keys, implementing query sanitization, or auditing Perplexity security…
Keep searchable long-term memory for coding agents in a local SQLite store and expose it through MCP when sessions keep forgetting prior decisions, conventions, and useful…
Windows persistence mechanism scanner. Scans all autorun vectors: Registry Run/RunOnce keys (T1547.001), Startup folders (T1547.004), Scheduled Tasks (T1053.005), and WMI Event…
Audit SQLite persistence layer for unused tables and broken integrations. Trigger when: (1) checking database usage, (2) cleaning up schema, (3) finding missing methods.
Run a local Agent Memory Service for persistent self-improvement with proper Ed25519 cryptography. Fixed signature implementation for reliable memory storage and retrieval.
Configure Persona API authentication with sandbox and production API keys. Use when setting up identity verification, configuring API credentials, or initializing Persona in your…
Security-first decision framework for threat modeling, vulnerability assessment, and compliance review.
Secure Persona API keys, webhook secrets, PII handling in verification data. Use when working with Persona identity verification.
Persona-driven exploratory browser testing against a live URL. Drives a browser as a specific user persona using a Plan → Act → Reflect loop, takes screenshots at each step,…
Römisches Recht: Personae Status Und Familie. Geführter Fachmodul mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
Use when a task needs the judgment of a personal financial advisor — building a retirement income plan, evaluating a Social Security claiming strategy, structuring a tax-loss…
Personal Habit Optimization for disaster response networks. Use when work requires personal habit optimization for disaster response networks with guardrails, traceable execution,…
Steuerberater: personalakten lohnsteuer geheimnis - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit,…
Berliner Start-up-HR: Personalaktenstruktur mit Rollenrechten, Ablageplan, Audit-Trail, Trennung sensibler Daten und Löschlogik.
Create encrypted backups of agent personality files, memory, config, secrets, and projects. Use when the agent needs to set up, run, or manage automated backups of its workspace…
Use when the user asks for Security Awareness Training from supplied source materials. Trigger language: security awareness training; cyber awareness training; employee security…
Track garden pests and diseases with treatments. Identify problems, track treatments, and monitor effectiveness.
Use when scanning an external macro environment with PESTEL/PESTLE (and its variant family STEEPLE, STEEPLED, PESTLIED, STEEP, DESTEP, LoNGPESTLE): political, economic, social,…
Build a production-ready feature, app, or multi-task goal from a short description. Small changes run one enforced loop: spec and pass/fail bars first, implement, machine gates…
Searches and downloads royalty-free images from Pexels API with smart filtering by orientation, color, and size.
Run all PatternFly compliance checks on a project — imports, components, colors, legacy CSS, and security.
Scan PatternFly React code for security anti-patterns — XSS via dangerouslySetInnerHTML, unsanitized user input in tooltips/labels, and insecure href patterns.
Römisches Recht: Pfandrecht Pignus Hypotheca. Geführter Fachmodul mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
Develop, test, benchmark, and operate PostgreSQL extensions with reusable harnesses and reference protocols.
Run a multi-agent comprehensive review of a PostgreSQL patch (CommitFest entry, GitHub PR, or local .patch file) — orchestrates the mechanical pre-amble (fetch + apply + build +…
PostgreSQL DB에 직접 접근하는 스킬. DB 조회, 테이블 구조 확인, 데이터 검증이 필요할 때 사용한다. Node.js 스크립트로 직접 연결하며 접속 정보는 환경변수 또는 credentials 파일에서 읽는다.
Build frontend Solana applications with Phantom Connect SDK and Helius infrastructure. Covers React, React Native, and browser SDK integration, transaction signing via He — from…
Runtime enforcement phase overview. Policy-as-code with Kyverno, resource limits, image source verification, security context enforcement, and policy observability for production…
Use when a multi-slice phase has been implemented and the operator wants an independent audit of ALL slices before sign-off, or asks to "audit the phase", "review all slices",…
Adaptive post-implementation phase verification through fresh subagents with S/M/L sizing (bug-fix → feature → architecture).
Trade on Phemex (USDT-M futures, Coin-M futures, Spot) — place orders, manage positions, check balances, and query market data.
Philips Hue スマートライトの制御スキル。Hue BridgeのローカルCLIP API v2を使用して照明のON/OFF、明るさ調整、色変更、シーン制御を行う。「Hueの電気をつけて」「リビングを暖色にして」「全部の照明を消して」「ライトの一覧」などの依頼時に使用。
Visual AI activity indicator using Philips Hue lights. Pulse red when thinking, green when done.
Bauleiter Phishing-Incident-Triage: Erstbewertung, Containment, Beweissicherung, betroffene Konten, Hauptansprechpartner.
Bauleiter Phishing-Incident-Triage: Erstbewertung, Containment, Beweissicherung, betroffene Konten, Hauptansprechpartner. Pruefraster fuer IT-Sec und Datenschutz.
Leitfaden Meldepflichten Phishing: Art. 33 DSGVO Aufsichtsbehoerde 72 Stunden, Art. 34 Betroffene, BSI bei KRITIS, Versicherer. Pruefraster Eskalationsstufen.
Analyze suspicious emails for phishing indicators. Parses email headers, extracts URLs, checks sender reputation, and provides a risk score.
Phishing am Arbeitsplatz: Arbeitnehmer-Haftung fuer durch Phishing verursachten Schaden. Innerbetriebliche Schadensausgleichung (BAG-Rechtsprechung), gestufte Haftung.
Search all 10,533 Security skills →