Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 133

Claude Security Skills (Page 133 of 176)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

10,533 skills · updated 2026-08-26 · showing 7921–7980 of 10,533 by quality score

Sub-topics:Red Team (1,582)Web Security (1,094)Threat Hunting (754)Identity Access (496)Network Security (414)Appsec Tools (381)Forensics (295)Malware Analysis (207)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Przegląd bezpieczeństwa zmian w kodzie i konfiguracji.
Read a diff for security by tracing attacker-controlled input to dangerous operations and checking every trust boundary it crosses.
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting…
Vérification de conformité sécurité incluant ISO 27001, SOC 2, HIPAA, NIST et audit trail. Se déclenche avec "ISO 27001", "SOC 2", "HIPAA", "NIST", "conformité sécurité", "audit…
You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards.
Performs advanced SAST (Static Application Security Testing) and compliance analysis on Pull Request diffs.
Guidance for Microsoft Security Copilot - the generative-AI security platform that helps analysts investigate, hunt, summarise, and respond using natural language, plugins,…
Guidance for Microsoft Security Copilot agents — autonomous, purpose-built AI agents (e.g., phishing triage, alert triage, conditional access optimization, vulnerability…
Shared reference for the security cluster: the trust-boundary model (untrusted input/action → privileged sink), the defend-vs-attack × code/config/runtime surface map, severity &…
Walk a security team member through allocating a CVE for an tracking issue. Prints the ASF Vulnogram allocation URL and a CVE-ready title (the issue title strip — from…
GitHub security alerts command center -- triage Dependabot, code scanning, and secret scanning alerts entirely from the editor.
Master security data encryption in use with comprehensive coverage of concepts, implementation, optimization, and production best practices.
Procedures for handling untrusted content, suspected prompt injection, secret exposure, data exfiltration, and manual security inspection.
Audit de sécurité des dépendances — détection de vulnérabilités connues, mises à jour critiques et gestion du cycle de vie des packages.
Drafts an irrevocable standby letter of credit securing a commercial lease deposit under ISP98 and UCC Article 5.
Get your security deposit back — the move-out documentation that wins disputes before they start, the itemized-deduction challenge, the demand-letter ladder, and the small-claims…
Design security controls and threat mitigations. Use for features involving auth, data, or external exposure.
Detect infrastructure and security-critical file changes to trigger security agent review recommendations ensuring proper security oversight for sensitive modifications.
Apply Microsoft's Security Development Lifecycle so threat modeling, tooling, and sign-off are built into each phase instead of bolted on before ship.
Use when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set. — from openai/plugins
Track private vulnerability reports from triage through fix, CVE coordination, embargo, publication, and post-disclosure closure
Create security policies, guidelines, compliance documentation, and security best practices. Use when documenting security policies, compliance requirements, or security…
SEOcrawler security vulnerability scanner and hardening specialist for comprehensive security audits.
Implement security best practices across the application stack. Use when securing APIs, implementing authentication, preventing vulnerabilities, or conducting security reviews.
Operate as a security engineer who reduces real risk through threat models, targeted reviews, scalable tooling, and incident duty.
Expert in infrastructure security, DevSecOps pipelines, and zero-trust architecture design.
AUTO-INVOKE when user mentions cryptography, AEAD, KDF, chain of trust, signing key, auth factor, MFA, secret hygiene, supply chain trust, physical threat, DFIR readiness, or…
Curated bundle of essential security skills for building secure applications. Includes threat modeling, hardening guides, audit checklists, compliance frameworks, and contract…
Generate the quarterly macOS security-compliance evidence screenshot package for Nathan. Use when asked to create/recreate the evidence zip (e.g.
Security specialist perspective for the weekly review. Focuses on XSS/CSRF, authorization boundaries, input validation, secrets handling, and dependency CVEs.
Use when a task needs the judgment of a security and fire alarm systems installer — laying out detector/notification-appliance placement against NFPA 72, choosing Class A vs Class…
Security remediation en vulnerability fix skill. Past fixes toe voor kwetsbaarheden uit security check-rapporten.
Workflow for authorized, evidence-preserving security review and remediation-task preparation.
Perform a scoped security review by establishing assets, trust boundaries, attacker prerequisites, and evidence-backed findings across authentication, authorization, validation,…
Review browser security: XSS, storage, CSP, CORS, CSRF, caching, and exposed data.
Auto-invoke when reviewing authentication, authorization, input handling, data exposure, or any user-facing code. Enforces OWASP top 10 awareness and security-first thinking.
Verify security considerations were addressed before shipping. Issues result in WARNINGS that strongly recommend fixing.
Baut oder prüft ein ISMS als juristisch verwertbares Kontrollsystem im Nis2 Cybersecurity Compliance.
Chief Information Security Officer (CISO) level GRC expertise. Governance, Risk, and Compliance for SaaS platforms.
Security Group Generator - Auto-activating skill for AWS Skills. Triggers on: security group generator, security group generator Part of the AWS Skills skill category.
Use when a task needs the judgment of a Security Guard — deciding whether to physically detain a suspected shoplifter or trespasser, choosing when to use force versus call police,…
Expert en sécurité applicative pour détecter les vulnérabilités, auditer le code, et guider les bonnes pratiques de sécurité.
Expert en sécurité applicative pour détecter les vulnérabilités, auditer le code, et guider les bonnes pratiques de sécurité.
Expert en sécurité applicative pour détecter les vulnérabilités, auditer le code, et guider les bonnes pratiques de sécurité.
Adversarial defense layer for the mortgage plugin — protects against prompt injection, system prompt extraction, PII leakage, workflow bypass, and social engineering attacks.
PreToolUse security-anti-pattern hook for Claude Code. Catches 12 common security risks (command injection, XSS, SQL injection, unsafe deserialization, GitHub Actions workflow…
OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation
Sécurisation d'agents IA contre injections, abus et fuites de données. Se déclenche avec "sécurité agent", "agent security", "prompt injection", "jailbreak", "agent abuse — from…
AIDefence security layer with prompt injection blocking, input validation, sandboxed execution, output sanitization, and STRIDE threat modeling.
Review code for application-level security hardening issues beyond framework checklists. Focuses on abuse prevention, API protection, business logic exploitation, rate limiting,…
Security headers and hardening for Next.js — CSP, CORS, rate limiting, CSRF protection, input sanitization, secrets management.
Configure HTTP security headers including CSP, HSTS, X-Frame-Options, and XSS protection. Use when hardening web applications against common attacks.
Security Headers Generator - Auto-activating skill for Security Fundamentals. Triggers on: security headers generator, security headers generator Part of the Security Fundamentals…
Audit and harden a web app's or API's HTTP security headers — Content-Security-Policy, HSTS, X-Content-Type-Options, frame-ancestors, Referrer-Policy, Permissions-Policy, and CORS…
Use when running, interpreting, or acting on Salesforce Security Health Check results — reading the score, understanding risk categories, evaluating specific settings, creating or…
Sets up Claude Code security hooks — protective PreToolUse guards that block sensitive file access, dangerous commands, destructive git ops, system path writes, network calls, and…
Comprehensive security patterns for authentication, authorization, input validation, and common vulnerability prevention
Creates response procedures for security incidents with containment steps, communication templates, and evidence collection.
When to use: active or suspected Salesforce org compromise, unauthorized access investigation, attacker containment, forensic evidence collection from EventLogFile/LoginHistory,…
Plan de réponse aux incidents de sécurité — préparation, détection, containment, éradication, recovery et lessons learned.
Search all 10,533 Security skills →