Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 137

Claude Security Skills (Page 137 of 176)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

10,533 skills · updated 2026-08-26 · showing 8161–8220 of 10,533 by quality score

Sub-topics:Red Team (1,582)Web Security (1,094)Threat Hunting (754)Identity Access (496)Network Security (414)Appsec Tools (381)Forensics (295)Malware Analysis (207)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Generates and reviews Salesforce Apex code (Brite edition) with 150-point scoring. TRIGGER when user writes, reviews, or fixes Apex classes, triggers, test classes,…
Salesforce Connected Apps and OAuth configuration with 120-point scoring. TRIGGER when: user configures OAuth flows, JWT bearer auth, Connected Apps, or touches…
Salesforce integration architecture (Brite edition) with 120-point scoring. TRIGGER when user sets up Named Credentials, External Services, REST/SOAP callouts, Platform Events,…
Lightning Web Components (Brite edition) with PICKLES methodology and 165-point scoring. TRIGGER when user creates/edits LWC components, touches lwc/**/*.js, .html, .css,…
SFRA (Storefront Reference Architecture) code review skill using Swarm pattern. Analyzes controllers, models, ISML, services, jobs for best practices, security, and performance.
Audit a fleet of AWS security groups for the multi-hop lateral-movement path that no single ingress rule reveals.
Search Singapore property rental and sale listings with flexible filters. Use when asked to search Singapore properties, find rental or sale listings, check property prices near…
Añadir y usar componentes de shadcn/ui en este repo — CLI de instalación, alias `#/components/ui`, estilo `new-york`, iconos `lucide`, util `cn` y Tailwind v4.
Detect and triage shadow AI usage from Git repositories and source trees, including model/provider SDKs, agent frameworks, MCP configs, prompts, RAG/vector stores, eval or…
Create or refine a concise, normative security policy ("Blue Book") for sensitive applications. Use when users need a threat model, data classification rules, auth/session policy,…
Notare: share deal closing notar - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit, Belegplan und…
Generate a patient-controlled SMART Health Link (SHL) QR code for sharing health records with a clinic or provider.
SharePoint Automation: manage sites, lists, documents, folders, pages, and search content across SharePoint and OneDrive — from security/threat-hunting
Clean up a shared drive nobody owns — the ownership-first move, the top-down audit that finds the 80% (stale projects, duplicates, ex-employee folders), the archive-don't-delete…
Secrets management, XSS prevention, CSRF protection, dependency scanning, DOMPurify sanitization, CSP headers, CODEOWNERS, HttpOnly cookies
Classify shell commands by risk level (SAFE to CRITICAL) before your OpenClaw agent executes them. Color-coded output, transparency enforcement, audit logging.
Configure Shield Platform Encryption with customer-supplied (BYOK) or customer-held (Cache-Only Key Service) tenant secrets, rotate them, and recover.
Implement cuttlefish-inspired adaptive interfaces — polymorphic APIs, context-aware behavior, feature flags, and attack surface reduction.
Production AI engineering disciplines (intentional multi-tenant DynamoDB/vector retrieval, shift-zero in-prompt threat modeling, and AI tech debt lifecycle governance) for…
Generate UI for .NET MAUI (Shiny.Maui.Controls) and Blazor (Shiny.Blazor.Controls) - includes TableView with 14 cell types, TreeView with lazy loading, drag/drop reorder…
Pre-production audit that scans a codebase for security, database, deployment, code quality, AI/LLM, dependency, frontend, and observability issues.
Full cycle: audit site, check Dependabot alerts, fix issues, push, verify CI, deploy, close. Prioritizes Security > Availability > New features. Parallel dispatch for speed.
Run ship-safe security and quality audit on the current project. Executes npx ship-safe audit . and reports findings by severity. Use before shipping any feature or PR.
The durable documentation set that makes an AI-built (vibe-coded) app reviewable before shipping. A small core every app needs — architecture, user/permission flows, permissions,…
Use when delivering or releasing a completed Shipyard phase under Codex — final verification, pre-ship security audit, documentation, and release.
当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…
Search Shodan for internet-connected devices, open ports, and services — host lookups and database queries
Performs network reconnaissance using the Shodan REST API and Shodan InternetDB. Discovers exposed services, CVE mappings, and generates asset inventories with risk scores for…
Provide systematic methodologies for leveraging Shodan as a reconnaissance tool during penetration testing engagements.
Install and configure Shopify app authentication with OAuth, session tokens, and the @shopify/shopify-api SDK.
Configure Shopify apps across development, staging, and production environments with separate stores, API credentials, and app instances.
Apply Shopify security best practices for API credentials, webhook HMAC validation, and access scope management.
Steuert die Compliance-Reaktion auf Short-Seller-Berichte: Ad-hoc-Pflicht, Dementierungsgrenzen, BaFin-Zusammenarbeit und Marktmanipulationsvorwurf im Insiderrecht Compliance.
Tear a written plan apart to find gaps before implementing it. Use when the user has a plan — a docs/*-plan.md file or a plan just produced in the conversation — and wants it…
Use when writing or modifying Terraform modules, terragrunt.hcl files, or AWS infrastructure (VPC, ECS, Lambda, DynamoDB, S3, security groups, API Gateway).
Use when handling security-sensitive code: credentials, IAM policy, encryption, PII (autori/artisti), copyright codes (ISWC/ISRC). Applies OWASP Top 10 + AWS security policy SIAE.
Siem Rule Generator - Auto-activating skill for Security Advanced. Triggers on: siem rule generator, siem rule generator Part of the Security Advanced skill category.
Guide Claude to use SigCLI correctly — check auth, login, get credentials, configure providers, and onboard new websites.
Secure AI agent wallets via Sigil Protocol. Use when you need to deploy a smart wallet, send transactions through the Guardian, manage spending policies, create session keys,…
Use this when: track aircraft in real time, monitor vessel positions, build situational awareness dashboard, my OSINT pipeline is broken, ingest threat feeds, set up geospatial…
Authenticate against the Sigma Computing REST API and obtain a bearer token. Use whenever the user wants to call the Sigma API directly with curl/HTTP, exchange OAuth client…
Create, retrieve, or modify a Sigma data model spec (the JSON/YAML semantic-layer definition with sources, columns, metrics, relationships, filters, controls, folder groupings,…
Apply Sigma rules against log sources for threat hunting; convert rules to Elasticsearch, Splunk, and grep queries
Continuous macro-market signal detection and classification engine that surfaces emerging trends, threats, and whitespace opportunities.
Multi-timeframe market analysis and trade recommendation engine. Use when user asks for: 'trading advice', 'should I buy BTC', 'analyze BTC market', 'is it a good time to…
Close a meaningful build milestone before the next development phase by protecting accepted state, recording evidence in the Build Ledger or a staged delta, preserving failures…
Evaluate researched options against explicit decision criteria, constraints, strategic fit, technical fit, licensing, cost, security, readiness burden, reversibility, integration…
Review untrusted input and dynamic execution boundaries including shell commands, PowerShell/cmd, plugins, code loading, archive extraction, deserialization, tool invocation,…
Govern whether an exact accepted artifact may be promoted or distributed by checking artifact identity, provenance, acceptance evidence, security/recovery gates, versioning,…
Review completed or proposed work for scope fidelity, protected-state violations, architecture/contract drift, unnecessary complexity, dependency/provenance concerns,…
Route a request to the smallest appropriate active Signalproof skill or skill sequence without silently expanding authority.
Review and govern credentials, tokens, keys, passwords, secret storage, redaction, transport, logging, rotation implications, and secret exposure without unnecessarily reproducing…
Verify whether a specific claim is actually supported by the available evidence without silently upgrading static, compile, automated, runtime, human-observed, security, signing,…
SignalRadar — Monitor Polymarket prediction markets for probability changes and send alerts when thresholds are crossed.
Pre-flight, configure, and route a FINALIZED contract for e-signature (DocuSign, Adobe Sign, Dropbox Sign, Notarius).
Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls.
Gets AWS credentials for CLI/SDK access via `aws login`. Activates when a developer needs to authenticate to AWS for local development, when an AWS operation fails due to missing…
Verifies container image signatures and SBOMs using Sigstore Cosign and Rekor transparency log. Enforces supply chain security policies by validating keyless signatures against…
Launch a Windows background process (.bat, node, python, .exe) with no visible console window — no black console flash on login or restart.
Silmaril API and SDK for AI application firewalls. Use when the user mentions Silmaril, AI security, prompt injection defense, or AI firewall workflows.
Search all 10,533 Security skills →