Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 126

Claude Security Skills (Page 126 of 148)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

8,844 skills · updated 2026-07-27 · showing 7501–7560 of 8,844 by quality score

Sub-topics:Red Team (1,515)Web Security (939)Threat Hunting (588)Identity Access (420)Network Security (357)Appsec Tools (333)Forensics (200)Compliance (191)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Expert guidance for Kyverno, the Kubernetes-native policy engine that validates, mutates, and generates resources using YAML policies (no Rego required).
Expert guidance for OPA (Open Policy Agent), the CNCF policy engine for unified authorization across the stack.
Expert guidance for Semgrep, the fast, open-source static analysis tool that finds bugs, security vulnerabilities, and anti-patterns in code.
Anwälte: terminsvertreter und untervollmacht - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit,…
Project-specific security patterns for Agenda Systems modules. Use when adding security controls to any module or resource — Security Groups, RDS, ElastiCache, ECS IAM, Secrets…
Use when designing, reviewing, or hardening Terraform remote state and secret handling after the repo/module scaffold exists and security and infrastructure-platform have decided…
Adversarial red-team of a running web, React Native, or Capacitor hybrid app. Drives Playwright browser MCP (web/PWA), Playwright Android WebView attach (Capacitor), or adb…
[Tier 2 — Non-Functional: Security · ISO 25010] Security test workflow — OWASP Top 10, dependency CVEs, secrets scanning, and auth testing. Run after Tier 1 functional tests pass.
Wirtschaftsprüfer: testat widerruf oder ergänzung - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit,…
Battle-tested Playwright patterns for writing, debugging, and scaling reliable test suites. Use when you need guidance for E2E, API, component, visual, accessibility, or security…
Tests Android inter-process communication (IPC) through intents for vulnerabilities including intent injection,
Tests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify object properties they
Systematically assessing REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated
Identifying flaws in application business logic that allow price manipulation, workflow bypass, and privilege
Test JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid
Identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters,
Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks
Tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into
Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater — from mahipal
Discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF,
Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization
Test and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification,
Tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket
Instrukce pro návrh pytest testů pro Python kód. MUSÍ být použity při analýze testovacího pokrytí — happy path, edge cases, error cases, security regrese, fixtures.
Interpret testssl-inspector normalized findings, recommend remediations, and tie evidence back to SCF anchor controls plus SOC 2 / NIST 800-53 r5 / PCI DSS 4.0.1 / ISO 27002:2022…
Texas Data Privacy and Security Act (TDPSA) compliance. No revenue threshold applies to all businesses.
Expert Tezos blockchain development guidance. Provides security-first smart contract development, FA1.2/FA2 token standards, gas optimization, and production deployment patterns.
Subjects every non-trivial decision to a fresh-context adversarial review before it stands. Use when correctness matters more than speed, when working in unfamiliar code — from…
Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations.
Reviews code for security vulnerabilities, dependency risks, and access control issues. Use before merging any security-sensitive change, on a regular audit schedule, or when…
Validates commit messages, PR titles, branch health, and repository standards. Use to enforce conventions locally and in CI, run health checks, and audit repository hygiene.
Simulate enterprise procurement and security review of your product before your first big deal meets it for real — the questionnaire, the gaps, the deal-slowing findings.
Conducts multi-axis code review across correctness, readability, architecture, security, and performance. Use before merging any change.
theHarvester is an open-source OSINT tool for gathering emails, subdomains, hosts, employee names, open ports, and banners from public sources.
Constrói teoria da mudança (insumos → atividades → resultados → impactos) e deriva indicadores de monitoramento com desagregações por grupo vulnerabilizado.
Audit therapy and behavioral health documentation platforms for clinical quality and regulatory compliance.
Run an extremely strict security audit for auth flaws, injection vectors, secrets exposure, broken access control, and boundary validation failures.
Use any time someone asks for a thermonuclear review or a thorough/intense code review of a PR or some changes.
Evaluates competing actions under uncertainty by building a decision tree of choice and chance nodes, placing explicit probabilities on outcomes the decider does not control,…
Produces an adversarial critique by constructing the strongest case against a proposal or thesis (the best objections an intelligent adversary would raise), then judging which…
Produces an anti-goals register by assuming a design succeeds at scale, narrating the near-future in which that success harms third parties (including non-users) and is exploited…
Produces a constraint-intervention plan that names the single binding constraint capping a system's throughput and attaches its exploit, subordinate, and elevate decisions, after…
Deliberately attack your own plans, systems, and assumptions to find weaknesses before adversaries or reality does.
Prüft Fernwartung durch Lieferanten und Dienstleister im Nis2 Cybersecurity Compliance.
Maintain THOR installs using thor-util: update signatures, upgrade versions, download offline packs, generate reports, manage YARA-Forge.
Cybersecurity incident response expert (NIST SP 800-61r2, SANS, ISO 27035). Guides the full incident lifecycle: detection, triage, severity classification, containment, e — from…
Generate a personalized threat advisory based on your tech stack — what CVEs, breaches, and supply chain attacks matter to YOU.
Conduct threat assessments for organizations. TRIGGERS - Use when user needs help with threat-assessment related tasks.
Use when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry.
Proactive threat hunting workflow. Triggers for: structured hunt campaigns, TTP-based hypothesis generation, SIEM query development, anomaly investigation, or any exercise…
Implement a structured threat intelligence lifecycle encompassing planning, collection, processing, analysis, — from Undermybelt/hermes-skills
Map identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control eff — from…
Map identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control eff — from…
Generate a threat model from spec.md using STRIDE methodology. Use when you need to identify security threats, attack surfaces, and mitigations for a feature before…
Full STRIDE-A threat model analysis and incremental update skill for repositories and systems. Supports two modes: (1) Single analysis — full STRIDE-A threat model of a…
Build a practical threat model for a feature or system using STRIDE — diagram the data flow, mark trust boundaries, enumerate concrete threats where data crosses them, and…
Threat Model Creator - Auto-activating skill for Security Advanced. Triggers on: threat model creator, threat model creator Part of the Security Advanced skill category.
Use when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before…
Produces a design-level STRIDE threat model — decomposes the architecture into a data-flow diagram with trust boundaries, enumerates threats per element, rates them by likelihood…
Use when reviewing a change, feature, or design for security — walk Shostack's four questions and STRIDE across every trust boundary of THIS stack, not a generic checklist.
Search all 8,844 Security skills →