Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 13

Claude Security Skills (Page 13 of 155)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

9,256 skills · updated 2026-08-01 · showing 721–780 of 9,256 by quality score

Sub-topics:Red Team (1,538)Web Security (965)Threat Hunting (629)Identity Access (441)Network Security (372)Appsec Tools (354)Forensics (243)Compliance (198)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Send and receive cryptographically signed messages between AI agents using the Agent Messaging Protocol (AMP).
Reviews router and switch configurations for security, correctness, stale references, risky change-window commands, and missing operational guardrails.
Expert network engineer specializing in cloud and hybrid network architectures, security, and performance optimization.
Fork any project for open-sourcing. Copies files, strips secrets and credentials (20+ patterns), replaces internal references with placeholders, generates .env.example, and cleans…
Deep, excruciating code review. Use anytime to analyze code for correctness, edge cases, security, performance, and design issues. Not tied to baseline—this is pure code analysis.
Dependency management, updates, and security advisory handling. Use when adding, updating, or auditing project dependencies.
Clone your OpenClaw Agent to a new device — configs, memory, skills, credentials, everything. Triggers: '帮我迁移', '搬到新设备', 'migrate device', 'device move', '设备搬家', 'pack and go',…
Expert penetration tester specializing in ethical hacking, vulnerability assessment, and security testing.
Run attacker and defender agents in a fix-and-re-attack loop so exploitable bugs get found, triaged, fixed, and verified before ship.
Create concise role-specific Codex window prompts and current-window handoffs with an architecture-first gateway and role-window registry.
Traces data flow from entry points to dangerous operations. Cross-file reasoning to determine which entries can reach which dangers, and what validation exists in between.
Run agent-adapted STRIDE + access-control analysis on an agent system. Produces a ranked risk list with agentic mitigations (scope / split / filter / gate / review).
Run a security audit as agents that map the attack surface, review each surface in parallel, skeptic-test every finding, and assemble one report.
Expert security auditor specializing in comprehensive security assessments, compliance validation, and risk management.
Expert security auditor specializing in comprehensive security assessments, compliance validation, and risk management.
Review security boundaries for agent skills and tool-using workflows. Use when a skill, hook, script, adapter, or agent workflow touches tools, shell commands, file writes,…
Expert infrastructure security engineer specializing in DevSecOps, cloud security, and compliance frameworks.
Sécurisation d'agents IA contre injections, abus et fuites de données. Se déclenche avec "sécurité agent", "agent security", "prompt injection", "jailbreak", "agent abuse — from…
Security hardening patterns for production AI agents. Covers prompt injection defense (7 rules), data boundary enforcement, read-only defaults for external integrations, WAL…
Pre-production security checklist for Agentforce deployments: permission scope, data exposure, authentication, logging.
Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles user input, authentication, API endpoints, or sensitive data.
Agentic security patterns for AI agent systems including attack vector defense, sandboxing, input sanitization, security scanning, CVE awareness, and least-privilege tool access.
Comprehensive compliance and security self-assessment for AI agents. 14-check framework producing a structured threat model + compliance report with RED/AMBER/GREEN ratings across…
Security scanning for Agent Skills and MCP servers using Snyk agent-scan. Use when installing new skills, auditing existing skills, reviewing MCP server security, or when user…
Security audit and validation tools for the Agent Skills ecosystem. Scan skill packages for common vulnerabilities like credential leaks, unauthorized file access, and Git history…
SSRF vulnerability hunting specialist. Use for testing URL-accepting parameters, webhook endpoints, file import features, and any server-side request functionality.
Implementation + audit loop using parallel agent teams with structured simplify, harden, and document passes.
Agent skill for v3-security-architect - invoke with $agent-v3-security-architect
Give the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection.
Give the AI agent its own EVM wallet with admin-controlled policies the agent CANNOT bypass even under prompt injection.
XSS specialist covering reflected (H1 #60), stored (H1 #61), and DOM (H1 #62). Dispatcher passes subtype — 'reflected', 'stored', or 'dom' — in the task; falls back to inference…
Deploy and operate AI agents on GreenNode AgentBase. Supports two resource types: Custom Agent (user-built Docker image, /agent-runtimes) and OpenClaw (platform templates for…
Redact PII before it reaches Agentforce prompts, models, and logs. Trigger keywords: agentforce pii, pii redaction, data masking llm, einstein trust layer, prompt pii filter,…
Dependency management guidelines for Jarvy - crate selection criteria, feature flag best practices, version management, security auditing with cargo-audit and cargo-deny.
Security best practices and guidelines for the Jarvy CLI codebase - a cross-platform development environment provisioning tool that executes system commands with elevated…
Canonical quality engineering: test strategy, case generation, coverage gates, exploratory checks, and security-tinged QA (incl. Shannon-style pentest track when requested).
Audit codebases, infrastructure, AND agentic AI systems for security issues。Covers traditional s。Use when 需要安全检测、合规审计、漏洞扫描、加密防护时使用。不适用于渗透测试未授权目标。适用于独立开发者、企业团队和自动化工作流场景。
Scan and validate AI agent skills against the OWASP Agentic Skills Top 10 (AST10) security framework.
Collaborative programming framework for production-ready development. Use when starting features, writing code, handling security/errors, adding comments, discussing requirements,…
Provision and harden a fresh Linux VPS into an autonomous-agent dev host using the capability-preserving model — the box IS the sandbox: full agent autonomy inside it (non-root…
OWASP Agentic Security Top 10 vulnerability knowledge base for identifying, assessing, and remediating security risks in AI agent systems.
Crypto wallet operations via the awal CLI — sign in, check balances, send USDC/ETH/POL/SOL, trade tokens, fund the wallet, and use the x402 payment protocol to discover p — from…
Crypto wallet operations via the awal CLI — sign in, check balances, send USDC/ETH/POL/SOL, trade tokens, fund the wallet, and use the x402 payment protocol to discover p — from…
Coinbase AgentKit - Toolkit for enabling AI agents with crypto wallets and onchain capabilities. Use for building autonomous agents that can execute transfers, swaps, DeFi…
Use when an agent folder must pass the Agentlas Cloud 2-stage security scan (static rules + BYOK LLM judgment) before private sync or public publish, or when asked to…
Install and operate the AgentPay SDK. Trigger this when an agent needs to install `agentpay`, explain AgentPay SDK capabilities without probing the machine first, bind Link for…
Foundational skill for amnesia-as-ZK-primitive patterns. Applies when designing systems where forgetting is the proof, separation creates trust, and the inability to reconstruct…
AI Agent System Designer for 0xagentprivacy. Activates for dual-agent TEE architecture, separation matrix physical enforcement, agent lifecycle design, Oracle architecture,…
Real-time access control decision engine for 0xagentprivacy swordsman agents. Activates when evaluating incoming data requests against consent preferences, designing…
ZKP Protocol Engineer for 0xagentprivacy. Activates when the user needs zero-knowledge proof design, circuit architecture (Groth16, PLONK, Nova), mixer protocols, recursive…
Compression-as-defence principle for 0xagentprivacy V5. Activates when discussing BRAID 74× compression, R(d,compression) modifier, token reduction as attack surface reduction,…
Zero-knowledge proof systems for 0xagentprivacy. Activates when discussing ZKP circuits (Groth16, PLONK, Nova), proof composition, Privacy Pool cryptography, reconstruction…
Dark forest strategy and adversarial environment navigation for 0xagentprivacy. Activates when discussing R(d) strategic disclosure, information asymmetry, predator-prey dynamics…
Dihedral group foundation for dual-agent separation. Activates when discussing the D₂ₙ group structure, Swordsman as negation generator, Mage as complement generator, Φ_agent as…
Quantum threat response persona. Activates when discussing post-quantum security, the 1200-qubit threshold, secp256k1 vulnerability, dragon flight conditions, or the transition…
Operational mechanics of the three inscription paths (Shadow, Guarded, Open) for 0xagentprivacy trust commitments.
Traffic analysis resistance, timing obfuscation, and metadata stripping for 0xagentprivacy swordsman operations.
Dihedral convergence navigator persona. Activates when discussing UOR-grimoire convergence, 2D to manifold transitions, the dihedral mirror pattern, or cross-framework translation…
Specialist persona for amnesia-aware operations and reflection without memory. Activates for systems requiring structural forgetting, orbit maintenance, tidal boundary…
Device security, OS hardening, network configuration, and physical security for 0xagentprivacy swordsman infrastructure.
Search all 9,256 Security skills →