Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 135

Claude Security Skills (Page 135 of 176)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

10,533 skills · updated 2026-08-26 · showing 8041–8100 of 10,533 by quality score

Sub-topics:Red Team (1,582)Web Security (1,094)Threat Hunting (754)Identity Access (496)Network Security (414)Appsec Tools (381)Forensics (295)Malware Analysis (207)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Security anti-patterns — localStorage token storage (XSS risk), trusting client-side authorization checks, reflecting full error details to clients, blacklist vs whitelist input…
Security-review methodology for the security-reviewer-agent — surfaces fuzzy security risks the deterministic lint cannot see (prompt-injection openings, scope-bypass patterns,…
Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices gu — from…
Audit a pull request diff for common security concerns (input validation, sanitization, authentication and authorization, secrets management, unsafe dependencies, and related…
Audit a product or tech spec pull request diff for high-level security concerns (threat surface, authentication and authorization model, trust boundaries, sensitive data handling,…
Security patterns for Web3 and blockchain applications — Solana wallet signature verification, transaction validation, smart contract interaction security, and checklist for…
Identifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance.
Isolated analysis environment management for malware and exploit testing. Create and manage isolated VMs, configure Cuckoo Sandbox, set up REMnux/FlareVM environments, manage…
Scan the codebase for security vulnerabilities based on the OWASP Top 10. Use when the user asks to audit security, find vulnerabilities, check for security issues, or says…
引导自动化安全扫描、依赖包审计和机密检测。 使用时机:依赖审计、CVE 扫描、机密检测、许可证合规。 关键字:scan, audit, CVE, dependency, secret, SBOM, vulnerability, 扫描, 漏洞。
Comprehensive database security scanner with OWASP compliance checks, vulnerability detection, and automated remediation
Schneller Security-Scan der Speicher Analyse Tauri-App (React + TypeScript Frontend). Prüft Command Injection, XSS, Path Traversal und Tauri-Sicherheitskonfiguration.
Audits code security against OWASP Top 10. Validates user ID from session, detects sensitive data leaks, verifies Zod validation. HAS VETO POWER - blocks insecure code.
Use when scanning files for security vulnerabilities. Runs comprehensive security analysis via subagent, returns concise actionable summary to main context.
Security-Scanner Agent fuer fabrikIQ und andere Projekte. Fuehrt umfassende Sicherheitspruefungen durch. — from tools-only/X-Skills
Scan AI agent skills for security vulnerabilities, dangerous code patterns, and undeclared permissions.
AgentShield security audit with 5 scanning categories, 102 static analysis rules, and optional red-team simulation.
You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security.
Coordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls.
Detect exposed secrets and provide rotation/fix steps. Use when the user explicitly invokes $security-secrets-fix or asks for this security secrets-fix workflow.
Automatisation d'audits de sécurité incluant scanning, reporting, intégration CI/CD et remediation tracking.
Use when working with authentication, API routes, user input, or sensitive data. Audits code for security vulnerabilities based on OWASP Top 10.
Frozen baseline sentinel — runs deterministic-only checks. The gateway-side SentinelRunner executes the checks without LLM calls; the llm_config here is a thin orchestrator…
Detect prompt injection, jailbreak, role-hijack, and system extraction attempts. Applies multi-layer defense with semantic analysis and penalty scoring.
Build and operate the "Security Skill Gap Diagnoser" capability for Security and Privacy. Trigger when this exact capability is needed in mission execution.
Security scanner for ClawdHub skills - detects suspicious patterns, manages whitelists, and monitors Moltbook for security threats. — from ndesv21/awesome-openclaw-skills-1
Audit Solidity and EVM smart contracts, web3 protocols, and on-chain code. Use for smart contract review, Solidity or DeFi audit, proxy and upgradeability checks, invariant and…
Guide pour analyste SOC — triage d'alertes, investigation, SIEM, indicateurs de compromission et playbooks de réponse.
סיוע באבטחת אפליקציות ווב ו-APIs. השתמש כשמבקשים לאבטח פרויקט, לבדוק חולשות, להגדיר הרשאות, לנהל API keys, או להגן על נתונים.
Mini Diarium's opinionated security, encryption, and privacy stance. Load when touching crypto (src-tauri/src/crypto/), auth (src-tauri/src/auth/, commands/auth/), IPC boundaries…
Security standards and checklist enforcing OWASP Top 10, secret management, and input validation. Auto-activates when: API endpoints, authentication, user input handling, data…
Run composable security analysis across binaries, prompts, traces, and policies.
Use when a task needs the judgment of a first-line security supervisor — building post coverage and shift schedules, deciding how to fill a callout or staffing gap, reviewing an…
[STUB - Not implemented] Security testing strategies including vulnerability scanning and penetration testing guidance. PROACTIVELY activate for: [TODO: Define on implementation].
Security testing patterns including SAST, DAST, penetration testing, and vulnerability assessment techniques.
Scans code for security vulnerabilities and unsafe patterns. Use when the user asks about security, mentions OWASP, credentials, secrets, XSS, SQL injection, or wants to audit…
Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat mo — from…
Analyze codebase architecture to generate a STRIDE-based threat model with data flow diagrams, trust boundaries, prioritized threats, and mitigations.
Modélisation des menaces pour applications et systèmes — identification des surfaces d'attaque, classification STRIDE, arbres d'attaque et stratégies de mitigation.
Generate a self-contained HTML dashboard of `` repository statistics for security-team review.
Prüft Security-Schulung der Leitung und Mitarbeitern im Nis2 Cybersecurity Compliance.
Triage GitHub security advisories for OpenClaw with high-confidence close/keep decisions, exact tag and commit verification, trust-model checks, optional hardening notes, and a…
نظام إدارة واكتشاف ومعالجة الثغرات الأمنية. استخدم هذا الـ skill عند: فحص الثغرات، إدارة نقاط الضعف، اختبار الاختراق، تقييم المخاطر الأمنية، OWASP compliance، إدارة الأحداث…
Server-side / API-side security per OWASP Top-10 (2025 release). Use when writing or reviewing backend code (Go+Fiber business core, Python+FastAPI AI adapter, Node) for broken…
Use when creating backlog tasks from security findings, integrating security scans into workflow states, or managing security remediation tracking.
Document security research, CTF solutions, and malware analysis. Includes REPORT.md and STATUS.md templates.
Run an OWASP ZAP baseline security scan locally using Docker. Checks for the ZAP baseline script, executes the scan, and summarizes findings by risk level with remediation…
Architecture Zero Trust — never trust always verify, micro-segmentation réseau, approche identity-centric et accès conditionnel.
Review Blumark24 OS security, permissions, privacy, Saudi PDPL alignment, and Zero Trust controls. Use for authentication, authorization, tenant isolation, sensitive data, and…
Apply version-specific secure coding guidance to AI-generated or human-written code that uses supported open source libraries.
Security-first skill auditing and quarantine for OpenClaw skills. Use when installing new skills, reviewing skills from unknown sources, scanning skills for prompt…
Audit HTTP security headers for any URL and receive a grade (A+ to F) with specific recommendations for missing headers
SecurityTrails integration. Manage data, records, and automate workflows. Use when the user wants to interact with SecurityTrails data.
Automate Securitytrails tasks via Rube MCP (Composio). Always search tools first for current schemas. — from security/security-misc
Reset the local SQLite DB to sample data and launch the API + Vite dev servers for manual verification.
Out-of-the-box Seedance 2.0 API skill — just one API key to generate AI videos. Builds storyboards, generates reference images with Seedream 4.5, submits video tasks, and polls…
基于火山方舟 seedream 5.0 lite 模型的 AI 图片生成器,支持文生图、图生图、组图生成与提示词优化。输入关键词即可生成高分辨率图片,使用 seedream 图片生成、AI 绘图、文生图、图生图时调用此 Skill。
Generate and edit AI images with Seedream (ByteDance) via AceDataCloud API. Use when creating images from text prompts, editing existing images, or working with high-reso — from…
Generate and edit AI images with Seedream (ByteDance) via AceDataCloud API. Use when creating images from text prompts, editing existing images with inpainting/outpaintin — from…
Generate images via Seedream API (doubao-seedream models). Synchronous generation.
Search all 10,533 Security skills →