Master SDLC orchestrator that reads TASK.md and executes a complete development cycle: TDD test design, TDD implementation, refactoring, code quality, security, documentation, git…
分析secret-identification-assessment相关知识产权侵权问题。 覆盖:侵权行为识别、证据收集、维权策略建议。 适用情形:用户说"secret-identification-assessment"相关问题。
Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation.
This skill enables Claude to seamlessly integrate with various secrets managers like HashiCorp Vault and AWS Secrets Manager.
Proactive security scanning for newly generated or modified code. Intelligently detects changes, runs appropriate scans (SAST, SCA, IaC), filters to only NEW issues, and prevents…
Helps choose secure, healthy open-source packages by evaluating vulnerability status, maintenance health, popularity, community, and security posture.
Define, build, review, and harden production-grade fullstack applications with strong security posture.
This skill covers hardening GitHub Actions workflows against supply chain attacks, credential theft, and privilege
Always use this skill when designing, applying, or debugging Access Rights and security in Pigment applications.
This skill covers security hardening for serverless compute platforms including AWS Lambda, Azure Functions,
This skill enables Claude to conduct a security-focused code review using the security-agent plugin. It analyzes code for potential vulnerabilities like SQL injection, XSS,…
This skill enables Claude to generate comprehensive security audit reports. It is designed to provide insights into an application or system's security posture, compliance status,…
This skill conducts legal review of security audit findings to assess regulatory disclosure obligations.
This skill designs and runs the security awareness training programme for all employees. Use when asked to create security training, run phishing simulations, or track training…
Establish a security baseline for a website or web app. Use this skill when configuring HTTPS and TLS, setting security headers, planning secrets management, evaluating CSP…
This skill establishes the security baseline configuration for all systems at project inception. Use when asked to set up security defaults, harden a new environment, or configure…
This skill should be used when the user asks about "cis benchmark", "cis kubernetes", "cis docker", "cis aws", "cis azure", "cis gcp", "soc2 rego", "soc2 policy", "hipaa…
个人信息保护认证顾问——指导企业通过个人信息保护认证 作为数据出境合规路径之一,或提升整体个人信息保护水平。 适用情形:用户说"个保认证怎么做"、"个人信息保护认证 有哪些"、"等保和个保认证的关系"、"认证对出境的帮助"、 "TC260认证"、"网络安全认证"。
Progressive-disclosure security-depth modules for the security-reviewer. Holds boundary-keyed checklists (access-control, authn-session, injection, path-and-file,…
Cross-cutting security & anti-fraud authority for the ERP/POS — money flows (refund/void/discount/cash/manual JE), RBAC integrity, audit-log completeness, PII & information-leak…
This skill analyzes HTTP security headers of a given domain to identify potential vulnerabilities and misconfigurations.
Security hygiene for GSD's self-modifying skill and agent system. Use this skill whenever: creating, editing, or deleting skill files (.claude/skills/, .claude/commands/),…
Assists with security incident response, investigation, and remediation. This skill is triggered when the user requests help with incident response, mentions specific incident…
This skill enables Claude to identify potential security misconfigurations in various systems and configurations.
This skill allows Claude to conduct comprehensive security audits of code, infrastructure, and configurations.
This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networ — from…
This skill automates security vulnerability testing. It is triggered when the user requests security assessments, penetration tests, or vulnerability scans.
Generate AI images using Volcengine Seedream model. Supports text-to-image (T2I), image editing (I2I), multi-image fusion, and web-search-based generation.
Generate images using the Doubao SeeDream API based on text prompts. Use this skill when users request AI-generated images, artwork, illustrations, or visual content creation.
Auditoria de segurança de Agent Skills (SKILL.md). Use esta skill sempre que o usuário pedir para analisar, auditar, revisar ou verificar a segurança de uma skill, SKILL.md, ou…
Use this skill any time the user wants to create, edit, design, generate, deploy, or debug a SentinelOne Singularity Data Lake (SDL) dashboard.
Establish outbound HTTP connections to external systems using REST, SOAP, and HTTP protocols. Covers RESTMessageV2, SOAPMessageV2, OAuth token retrieval as part of API flows, and…
Build NowAssist Skill configurations using the Fluent SDK NowAssistSkillConfig API. Covers the two-argument skill definition pattern, input/output typing, tool graph construction…
Secure data and credentials using cryptographic operations, encryption, and authentication primitives.
Sets up notification channels for CloudWatch alarms using SNS topics and subscriptions. Always use this skill when configuring alarm notifications — it creates encrypted SNS…
Generates a public-facing, investor-enticing changelog ("shipping log") from a git or GitHub repository's recent history.
This skill should be used when the user asks to "search for exposed devices on the internet," "perform Shodan reconnaissance," "find vulnerable services using Shodan," "scan IP…
This skill should be used when the user asks to "send a Signal message", "reply on Signal", "react to a Signal message", "edit/delete a sent Signal message", "make Signal feel…
Use this skill when reviewing Sigstore Cosign supply chain security for Kubernetes workloads. Trigger when the user asks whether images are properly signed, whether Kyverno…
> Use this skill whenever asked about Singapore cryptocurrency or digital asset taxation. Trigger on phrases like \"crypto tax Singapore\", \"Bitcoin Singapore\", \"digital tokens…
When adding a new skill to the `dev-security/claude-rules/skills/` pack, or when substantively revising an existing skill's structure or frontmatter, apply the pack's established…
[REQUIRED] Comprehensive description of what this skill does and when to use it. Include: (1) Primary functionality, (2) Specific use cases, (3) Security operations context.
Comprehensive security risk analysis for Claude skills. Use when asked to analyze security risks, review security stance, audit skills for vulnerabilities, check security before…
Audit an AI agent skill before installing it. Use proactively whenever the user is about to add, install, enable, or evaluate an unfamiliar skill — including phrases like "audit…
This skill should be used when scanning Claude Code skills or agent files for advisory security risks: code-execution, prompt-injection, supply-chain, filesystem-boundary,…
Security audit for AI agent skills before installation. Scans SKILL.md files, hooks, scripts, and MCP configs for prompt injection, data exfiltration, credential theft, and…
Find Agent Skills on skills.sh and adopt only the ones that pass a security audit. Use when the user wants to discover, search for, evaluate, or install a third-party skill ("find…
This skill is a disclosed z。ai model-routing guide and does not install code, request credentials。Use when 需要AI模型调用、智能对话、Agent编排、LLM应用时使用。不适用于需要100%确定性的关键决策。
Exploit SNMP services with write-accessible community strings to achieve remote code execution. Use this skill whenever you need to test SNMP security, enumerate SNMP services,…
Execute Snyk Code SAST (Static Application Security Testing) scans on source code files or projects, interpret vulnerability findings, generate structured security reports, and…
Complete security remediation workflow. Scans code for vulnerabilities using Snyk, fixes them, validates the fix, and optionally creates a PR.
Apply Cialdini's six principles of persuasion — Reciprocity, Commitment/Consistency, Social Proof, Liking, Authority, and Scarcity — to analyze or design influence strategies.
Identify and analyze cognitive biases including confirmation bias, anchoring, availability heuristic, and sunk cost fallacy in decision-making contexts.
Apply Rogers' Diffusion of Innovations theory to analyze how new products, ideas, or technologies spread through populations.
Conduct structured policy analysis including problem definition, alternative evaluation, and evidence-based recommendation.
Apply social network analysis concepts including nodes, ties, centrality, structural holes, and strong/weak ties to map and analyze relationship structures.
Conduct stakeholder analysis using identification, Power-Interest matrix classification, and influence strategy development.
Design and conduct user research using interviews, focus groups, surveys, and field observation. Use this skill when the user needs to understand customer needs, validate product…
This skill assists with SOC2 audit preparation by automating tasks related to evidence gathering and documentation.
Use this skill when integrating sol-safekey into Solana bots or tools, including encrypted keystores, interactive wallet management, password handling, wallet unlock, bot startup…