Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 140

Claude Security Skills (Page 140 of 148)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

8,844 skills · updated 2026-07-27 · showing 8341–8400 of 8,844 by quality score

Sub-topics:Red Team (1,515)Web Security (939)Threat Hunting (588)Identity Access (420)Network Security (357)Appsec Tools (333)Forensics (200)Compliance (191)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Structured workflows for triaging GitHub issues, reviewing PRs, sprinting through milestones, and running security/quality/performance audits — with configurable validation gates,…
This skill should be used when the user asks to "analyze a GitHub repo", "check repo health", "audit a repository", "review a codebase", "measure tech stack conformance",…
Use this skill when the user asks to audit a GitHub repository, check repository health, review project governance quality, check if a project has the required files like…
Plans, executes, and validates Google Kubernetes Engine (GKE) cluster upgrades and maintenance operations for both Standard and Autopilot clusters.
Implement server-side validation with allowlists, specific error messages, type checking, and sanitization to prevent security vulnerabilities and ensure data integrity.
Implement comprehensive server-side validation with allowlists, type checking, input sanitization, and consistent error messages, while using client-side validation for user…
Manage GoCD pipelines, pipeline groups, agents, environments, config repos, server administration, users, roles, authorization configs, plugins, backups, materials, artifact…
Use this skill when administering, operating, or debugging a GoClaw gateway through the GoClaw CLI/runtime package.
Use this skill when working with gogo for host, port, service, banner, fingerprint, or vulnerability-hint discovery.
Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF).
This skill should be used when the user asks to "integrate goth with echo", "oauth echo framework", "echo authentication", "goth session management", "oauth security", "secure…
Apply organizational ambidexterity theory to balance exploration and exploitation activities. Use this skill when the user needs to diagnose whether an organization is…
Apply Christensen's Disruptive Innovation theory to assess low-end and new-market threats to incumbents.
Apply the Efficient Market Hypothesis (Fama, 1970) to evaluate information incorporation in asset prices across weak, semi-strong, and strong forms.
Apply panel data analysis with fixed effects, random effects, and dynamic GMM to exploit longitudinal variation and control for unobserved heterogeneity.
Apply Smith and Lewis's paradox theory to identify and manage organizational tensions across performing, organizing, belonging, and learning dimensions.
Apply social capital theory (Putnam, Coleman, Bourdieu, Burt) to analyze how network structures and trust generate value or impose constraints.
Use this skill when listing or creating M365 groups in CIPP — security groups, distribution lists, M365 groups, mail-enabled security groups.
When the user wants to build GTM automation with code, design workflow architectures, use AI agents for GTM tasks, or implement the 'architecture over tools' principle.
Use this skill when you need to deploy HyperShift clusters on AWS infrastructure with proper STS credentials, IAM roles, and VPC configuration
This skill should be used when user asks to "deploy to Hetzner", "create Hetzner server", "manage Hetzner Cloud", "hcloud CLI", or works with Hetzner Cloud infrastructure…
This skill enables Claude to automatically check for HIPAA (Health Insurance Portability and Accountability Act) compliance issues in codebases, infrastructure configurations, and…
HIPAA compliance for Rails apps handling PHI (Protected Health Information) — Active Record Encryption for PHI at rest, audit logs that survive deletion, access controls (RBAC),…
HITL Protocol — the open standard for human decisions in autonomous agent workflows. When a website or API needs human input, it returns HTTP 202 with a review URL.
houtu-dependencies enterprise-grade Spring Cloud microservice foundational framework complete usage guide.
Apply structured critical thinking — identifying claims, evidence, reasoning chains, hidden assumptions, and logical fallacies — to evaluate or construct specific written…
Hunt TLS/SSL and DNS misconfigurations — missing HSTS (downgrade attack), weak cipher suites, expired/invalid certificates, mTLS bypass, missing SPF/DKIM/DMARC (email spoofing),…
Author Kubernetes manifests for Hush UAM (Universal Access Management) — AccessCredential, AccessPrivilege, AccessPolicy CRDs from Hush Security.
Converts a long source document (opdrachtbeschrijving, stage-plan, intern rapport, draft, bedrijfsbrief, onderzoeksnotities) into a properly structured afstudeerrapport-outline…
Provides cryptocurrency trading data analytics including smart money tracking, whale monitoring, market data queries, and trader statistics.
Internationalization and localization rules for UMRS: locale detection, gettext wiring, .po/.pot file management, French Canadian (fr_CA) translation, security label fidelity, and…
Purchase API keys from iAutoPay Fact API using USDC on Base chain. Use this skill when: - Buying API keys for AI agent payment services - Managing API key subscriptions (1/7/30…
Use this skill whenever asked to calculate, review, or advise on Indonesian payroll — PPh 21 (income tax withholding), BPJS Kesehatan (health insurance), BPJS Ketenagakerjaan…
Use this skill when an identity lifecycle event (joiner, mover, leaver) or an access request must be evaluated end-to-end across Microsoft Entra identity, Conditional Access…
This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or…
Generate a production-grade Industrial IoT protocol bridge — OPC UA ↔ MQTT Sparkplug B, Modbus → MQTT, or direct PLC (Rockwell/Siemens/Beckhoff) → cloud (AWS IoT Core / Azure IoT…
Use this skill when advising on Israeli cryptocurrency tax reporting and capital gains calculations. Trigger on phrases like \"crypto tax Israel\", \"bitcoin tax Israel\", \"מס…
This skill covers deploying AWS Security Hub as a centralized cloud security posture management platform that
This skill covers deploying and tuning Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare
This skill covers designing and implementing security zones and conduits for industrial automation and control
This skill covers implementing automated security scanning for Infrastructure as Code (IaC) templates using
ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).
This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories.
> Use this skill whenever asked about Indian EPF (Employees' Provident Fund), ESI (Employees' State Insurance), or employer social security obligations.
Use this skill to convert a security incident or public vulnerability pattern into reusable audit prompts, checklists, tests, and AGENTS.md rules.
Use this skill when a security incident must be triaged, contained, remediated, and reviewed in a Zero Trust assume-breach posture across Microsoft 365 and Dynamics 365…
> Use this skill whenever asked about India cryptocurrency or virtual digital asset (VDA) taxation. Trigger on phrases like \"crypto tax India\", \"Bitcoin India tax\", \"VDA…
> Use this skill when advising on LEGAL tax minimization strategies for Indian taxpayers — salaried individuals, self-employed professionals, and business owners.
Detect and reject indirect prompt injection attacks when reading external content (social media posts, comments, documents, emails, web pages, user uploads).
Infisical is an open-source platform for managing application secrets, environment variables, and certificates across teams and infrastructure.
Integrate InFlow stablecoin payments into any project. Use this skill when the user wants to: accept payments, add a checkout, request a payment, build a payment flow, integrate…
This skill enables Claude to automatically scan source code for potential input validation vulnerabilities.
This skill covers integrating OWASP ZAP (Zed Attack Proxy) for Dynamic Application Security Testing in CI/CD
This skill covers integrating Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub
This skill should be used when the user asks to "check for integrity issues", "analyze deserialization", "find supply chain vulnerabilities", "review CI/CD security", "check SRI",…
Turn ambiguous or high-impact product and engineering changes into scoped, verifiable acceptance criteria before or alongside implementation.
Intershop Commerce Management (ICM) backend development best practices. This skill should be used when writing, reviewing, or refactoring ICM Java code to ensure optimal patterns…
Classify incoming IONOS Cloud requests and route them to the narrowest applicable specialist agent. Covers DCD topology review, security and GDPR compliance, managed Kubernetes,…
iOS data persistence expert skill covering SwiftData (@Model, ModelContainer, @Query, #Predicate, migrations, CloudKit), Core Data (NSPersistentContainer, NSFetchRequest, batch…
iOS physical use-after-free exploitation via IOSurface heap spray. Use this skill whenever the user mentions iOS kernel exploitation, physical UAF, IOSurface, page table…
Search all 8,844 Security skills →