Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 12

Claude Security Skills (Page 12 of 155)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

9,256 skills · updated 2026-08-01 · showing 661–720 of 9,256 by quality score

Sub-topics:Red Team (1,538)Web Security (965)Threat Hunting (629)Identity Access (441)Network Security (372)Appsec Tools (354)Forensics (243)Compliance (198)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Configure Adobe OAuth credentials and API access across development, staging, and production environments with separate Developer Console projects, secret managers, and…
Apply Adobe security best practices for OAuth credentials, secret rotation, I/O Events webhook signature verification, and least-privilege scoping.
Multi-agent debate orchestration for Architecture Decision Records. Automatically triggers on ADR create/edit/delete.
Answer questions about Adspirer itself — pricing, plans, quota and tool-call limits, what Adspirer can do, connecting an ad account, supported platforms and AI clients, security,…
Composite skill — full project health check across testing, config, hooks, performance, security, MCP, and plugins.
Full dependency lifecycle composite — audit known vulnerabilities, triage by severity and breaking-change risk, upgrade targeted packages, verify tests pass, ship PR.
Aggregate every signal that gates a PR merge (CI, reviews, conflicts, branch staleness, security scans, third-party reviewers like CodeRabbit/Greptile/Sonar) into a single…
Define and manage recurring automated agent runs — CI monitoring, dep updates, security scans
Shortcut for security review on current change set. Runs layered checks (secret-scan, dep-audit, semgrep, OWASP patterns, prompt-injection review).
Composite skill — full security pass across secrets, dependencies, code paths, and OWASP risks. Chains security-audit (broad) + socket-audit (npm supply chain) + semgrep (pattern…
Apply Advanced Alchemy custom SQLAlchemy types such as `DateTimeUTC`, encrypted fields, `GUID`, `JsonB`, password hashing, and stored file objects with backend-aware behavior and…
Use when designing, planning, reviewing, or generating enterprise-grade automations, scheduled jobs, CI/CD workflows, database syncs, webhook processors, API integrations,…
Specialized reverse engineering analysis workflows for binary analysis, pattern recognition, and vulnerability assessment
Use when designing C2 infrastructure or OPSEC for a long-haul red-team op — redirectors, malleable profiles, tiered/segregated infra, living-off-the-land, data exfiltration
Use before delivering work that incorporated content the agent did not author — fetched web pages, PDFs, retrieved or library documents, tool or subagent output — or that performs…
Structured debate protocol that constructs an advocate, deploys critic attacks, and renders a judge verdict through iterative rounds.
Library of realistic adversarial attack vectors and anti-patterns to avoid. Contains examples of valid attacks and subtle gaming patterns to reject.
Full adversarial quality loop — implement, self-attack, parallel verification, quality gates, final validation. 全品質循環:實現、自攻、並行驗證、質量關卡、最終確認.
Use when the user asks for an advisor, Opus second opinion, optimal approach, design critique, or when a task has unresolved high-risk trade-offs, repeated failed investigations,…
Mine GitHub Security Advisories and CVE databases for incomplete fixes, finding variant vulnerabilities in patched code or similar patterns in related packages.
Strict semantic firewall with Human-in-the-Loop execution authorization. Airgaps external data and enforces zero-trust environment.
Blockchain security API for AI agents。Scan tokens, simulate transactions, check addresses for th。Use when 需要AI模型调用、智能对话、Agent编排、LLM应用时使用。不适用于需要100%确定性的关键决策。
Autonomous DevSecOps & FinOps Guardrails. Orchestrates Gemini 3 Flash to audit Linux Kernel patches, Terraform cost drifts, and K8s compliance.
Use when an AEJ: Economic Policy manuscript's headline policy estimate needs to be shown stable and credible against specification, sample, inference, and identification threats.
Römisches Recht: Aequitas. Geführter Fachmodul mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
Harness-native operator system cho agentic work — skills, instincts, memory optimization, security scanning, cross-harness workflows. 205K stars.
Use when the user asks to check Afi SaaS backup coverage across Microsoft 365 / Google Workspace tenants, find which mailboxes or sites aren't backed up, catch protected resources…
Complete cybersecurity assessment, threat modeling, and hardening system。Use when conducting sec。Use when 需要AI模型调用、智能对话、Agent编排、LLM应用时使用。不适用于需要100%确定性的关键决策。
企业级网络安全评估与加固体系(免费版),覆盖安全态势评估、STRIDE威胁建模、 OWASP Top 10应用安全审计、基础设施加固。核心能力: - 12阶段安全评估方法论(态势评估到评分体系) - STRIDE+威胁建模与风险优先级矩阵(P0-P3) - OWASP Top 10(A01-A10)应用安全审计清单 -…
Coleta e consulta dados de leiloeiros oficiais de todas as 27 Juntas Comerciais do Brasil. Scraper multi-UF, banco SQLite, API FastAPI e exportacao CSV/JSON.
Analyze and optimize AGC (Automatic Gain Control) parameters for WaveCap-SDR channels. Use when audio is too quiet, too loud, has pumping artifacts, or when tuning AGC…
Encrypt and decrypt files with age (FiloSottile/age), a simple, modern encryption tool with small explicit keys, post-quantum support, no config options, and UNIX-style…
Library of 232 AI agent personalities across 16 business divisions — Engineering, Design, Sales, Marketing, Security, Finance, Game Dev, GIS, Academic and more.
Intelligent system governor that continuously shadow-tests APIs for performance while enforcing strict financial and security guardrails against runaway costs.
Attack surface mapping for LLM agent systems. Threat model, blast radius calculation, entry points, trust boundaries, lateral movement paths, and MITRE ATLAS techniques for AI…
SkillHub quality gate agent. Runs security scans, quality scoring, and cross-promo linting on skill PRs. Internal use only.
Senior backend engineer specializing in scalable API development and microservices architecture. Builds robust server-side solutions with focus on performance, security, and…
Expert blockchain developer specializing in smart contract development, DApp architecture, and DeFi protocols.
Use agent-bom to check package, SBOM, inventory, and agent dependency exposure against OSV, GitHu。Use when 需要AI模型调用、智能对话、Agent编排、LLM应用时使用。不适用于需要100%确定性的关键决策。
Interact with Channel Talk using extracted desktop app or browser credentials - read chats, send messages, search messages, manage groups
Use this agent for expert adversarial security and logic review of ChiaLisp (CLVM) puzzles and spend construction, including singletons, DIDs, NFTs, CATs, offers and settlement,…
Expert cloud architect specializing in multi-cloud strategies, scalable architectures, and cost-effective solutions.
Enables DID registration, cryptographic signing, verification, Relay connection, and end-to-end encryption for secure AI agent communication.
Review small, non-sensitive AI-agent commerce action manifests before execution. Use for proposed wallet spending, paid API calls, deployments, token operations, marketplace jobs,…
Audit agent configuration files for security vulnerabilities and misconfigurations. Covers settings.json, .mcp.json, .codex/config.toml, AGENTS.md, hooks, plugin manifests, and…
Expert database administrator specializing in high-availability systems, performance optimization, and disaster recovery.
PostgreSQL database specialist for query optimization, schema design, security, and performance. Use PROACTIVELY when writing SQL, creating migrations, designing schemas, or…
Orchestration workflow for delegating work to the configured custom agents (bug-finder, bulk-scanner, codebase-analysis, debugger, executor, planning-agent, researcher, verifier,…
Expert dependency manager specializing in package management, security auditing, and version conflict resolution across multiple ecosystems.
Convene several reviewer agents with fixed distinct lenses, correctness, security, cost, and simplicity, then synthesize their verdicts into one.
Dispatch ad-hoc tasks to remote agent-box (agent-box scripts or free-form claude prompts). Maps named aliases (ci-watch, health, security, etc.) to shell scripts on homelab;…
Enables your agent to earn cryptocurrency by registering skills, negotiating tasks with escrow, building reputation, and auto-matching to paid jobs globally.
Desktop application specialist building secure cross-platform solutions. Develops Electron apps with native OS integration, focusing on security, performance, and seamles — from…
Use when setting up a secure email inbox for any AI agent — configuring inbound email via Resend, webhooks, tunneling for local development, and implementing security measures to…
Build automated evaluation suites for AI agents using golden datasets, rubrics, and regression gates.
Implement hooks for permission control and security in custom agents. Use when adding security controls, blocking dangerous operations, implementing audit trails, or desi — from…
Implement hooks for permission control and security in custom agents. Use when adding security controls, blocking dangerous operations, implementing audit trails, or desi — from…
Encrypted credential vault keyed off the agent's Alien Agent ID private key. Store, retrieve, list, and remove external-service credentials (GitHub PAT, Slack token, AWS keys,…
MCP Agent Mail - Mail-like coordination layer for multi-agent workflows. Identities, inbox/outbox, file reservations, contact policies, threaded messaging, pre-commit guard, Human…
Agent memory system security — poisoning prevention, L1/L2 integrity, context window attacks, memory exfiltration defense, and session isolation.
Search all 9,256 Security skills →