Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 156

Claude Security Skills (Page 156 of 176)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

10,533 skills · updated 2026-08-26 · showing 9301–9360 of 10,533 by quality score

Sub-topics:Red Team (1,582)Web Security (1,094)Threat Hunting (754)Identity Access (496)Network Security (414)Appsec Tools (381)Forensics (295)Malware Analysis (207)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Generalist agent that plans, browses, executes shell commands, and writes files.
Autonomous security vulnerability scanner for codebases. Detects secrets, XSS, missing security headers, auth issues, OWASP Top 10 patterns, dependency vulnerabilities, PII…
Use when handling a Washington landlord-tenant matter — residential evictions, unlawful-detainer summary proceedings, mobile-home L&T, security-deposit recovery, warranty of…
WhatsApp message relay and firewall for OpenClaw agents. Intercepts messages from third parties (non-owner contacts), notifies the owner, and sends replies only when explicitly…
Stage 1. Sign up at Wasender, get a Personal Access Token, create a WhatsApp session, scan the QR with the user's phone, and verify the connection works end-to-end.
DeFi risk analysis toolkit powered by WACH.AI via x402 payments using AWAL wallet custody. Use when the user asks to check if a token is safe, assess DeFi risk, detect honeypots,…
Waermepumpe: Red-Team und Qualitätskontrolle im Miet- und WEG-Recht: fachlich vertieftes Modul mit Normenradar (BGB/WEG/BetrKV/GEG), Tatbestands-/Beweislastmatrix, Fristen- und…
Web Application Firewall fingerprinting — Cloudflare, AWS WAF, Akamai, Imperva, etc.
Waf Rule Creator - Auto-activating skill for Security Advanced. Triggers on: waf rule creator, waf rule creator Part of the Security Advanced skill category.
Wahoo Fitness Cloud API — fetch workouts, download FIT files, parse power/HR/cadence/GPS into local SQLite for analysis
Add or modify a PostgreSQL WAL / XLOG record — covers choosing built-in rmgr vs Generic WAL (generic_xlog.c) vs custom rmgr (RegisterCustomRmgr), the XLogInsert +…
Validation discipline for any "documented workflow" (README reproduction recipe, getting-started guide, install script, onboarding doc, deploy procedure).
Evaluate delegated-wallet, embedded-wallet, or agent-signer policy evidence without sharing credentials or raw provider payloads.
Manage crypto wallets, transfers, swaps, and balances via the Sponge Wallet API.
Trade crypto tokens: swap, bridge across 14 chains. Manage wallets, agent tokens, and security policies.
WAMP (Web Application Messaging Protocol) secure Pub/Sub for distributed agent event bus. Autobahn|JS patterns, authenticated subscriptions, RPC over WAMP, topic-based routing,…
Sync WaniKani Japanese learning progress data from the API to local storage for analysis and insights.
Use the Warden App (agentic wallet) via browser automation to execute crypto tasks (swap, bridge, deposit/withdraw, perps, portfolio/research) and to build an OpenClaw skill…
Full security audit — secrets, dependencies, IAM, auth, injection, XSS, HTTPS, rate limiting, public storage.
Produce a hardening spec and implement it — auth patterns, security headers, rate limiting, input validation, secrets management, dependency hygiene.
Security reconnaissance — full inventory of secrets management, IAM, dependencies, auth, encryption, audit logging, and compliance gaps.
Automated SAST + dependency vulnerability scan. Runs Semgrep (code vulnerabilities) and pip-audit (CVE-matched dependencies) and writes a structured JSON report.
Security and privacy by design — GDPR principles, secure coding defaults, and data handling rules
Produce a threat model — assets, ranked threats, mitigations, accepted risks. Use when asked to "threat model this", "what could go wrong security-wise", "map our attack surface",…
View, toggle, and configure wardens — the quality gates that review plans, code, and security
Generate warehouse analytics charts, table images, and report-ready visuals from SQLite/CSV data. Use when the user asks for warehouse charts, product table images, stock health…
Universal database IDE CLI — query PostgreSQL, MySQL, SQLite, BigQuery, MongoDB with cost projection
The Warmup. A daily intelligence brief for the first coffee. CISO mode delivers a structured cybersecurity digest — active threat actors mapped to MITRE ATT&CK, emerging CVEs with…
Crear, servir y operar web apps locales sobre PHP (WebAssembly) + SQLite con la CLI `wasam`, e interactuar con ellas por API HTTP o por CLI.
Wasmtime WASI sandbox for agent-executed code — capability-based security, component model, WASI Preview 2. Isolate untrusted code from the host filesystem/network.
Poll the Anthropic plugin marketplace manifest until "channelhub" appears, then notify the user. Use when waiting for the security review to land — the submission portal shows…
Scan repos for health issues: stale PRs, failing CI, old issues, TODO refs, lockfile problems, and security advisories.
Use when manually monitoring, watching, tracking, or reviewing AI assistant storage, session, transcript, JSONL, or SQLite format drift after official upstream repository,…
3-wave parallel audit — Wave 1 discovery (4 agents), Wave 2 verification (4 agents), Wave 3 cross-optimization (1 synthesizer). Each wave runs agents in parallel.
Generate WaveJSON timing diagrams for digital signals and create HTML viewers to display them. Use when documenting signal timing, creating timing diagrams, analyzing protocol…
Use when results for a The World Bank Economic Review (WBER) manuscript may be sensitive to specification, sample, measurement, or inference choices — and you need a…
Weaves custom Skills for Claude following official best practices including proper structure, metadata, progressive disclosure, and security guidelines.
Use when a task needs the judgment of a Web Administrator — diagnosing an outage or slow-page incident, planning a TLS/DNS cutover, deciding CDN vs origin caching policy, or…
Threat-model, implement, review, and verify defensive security for web frontends, backends, APIs, data stores, dependencies, build pipelines, and deployments.
Use to plan web authentication — session vs token model, httpOnly cookies vs localStorage risks, CSRF, SSR/middleware auth on Next.js, OAuth/managed-provider evaluation, refresh…
Apply modern web development best practices for security, compatibility, and code quality. Use when asked to "apply best practices", "security audit", "modernize code", " — from…
Expert 10x engineer with comprehensive knowledge of web development, internet protocols, and web standards.
Explore an authorized URL with headless Chrome DevTools/CDP, build a bounded SPA state-and-action graph, capture and classify browser traffic, optionally harvest browser-loaded…
Gather security intelligence for Proteus hypotheses: expected behavior, public-known status, advisories, changelogs, issues, PRs, docs, tests, affected-version timeline, duplicate…
Run a website launch as a verification-gated process, not a to-do list. Use when taking a site (or a major site section) to production — scoping a launch, building or walking a…
Documentação e integração do pacote npm @lina-openx/web-lina-pay-sdk (Lina OpenX / Open Finance). Use este skill sempre que o utilizador pedir ajuda com este SDK: exemplos de…
Authorized web application penetration testing — reconnaissance, vulnerability analysis, proof-based exploitation, and professional reporting.
Web search using DuckDuckGo Instant Answer API (no API key required). Use when you need to search the web for information, definitions, calculations, conversions, or quick facts.
OWASP Top 10, security headers, CSP, XSS prevention, and vulnerability prevention.
Expert guidance on identifying and mitigating common web vulnerabilities from a bug hunter's perspective.
Hardens websites against common attacks — security headers, CSP policies, input validation, CORS configuration, dependency auditing, and OWASP Top 10 mitigation.
Security best-practices and hardening review for JavaScript/TypeScript web applications. Use when asked to harden an app, review security posture or secure defaults, assess OWASP…
Security code review for JavaScript/TypeScript web applications. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP…
Web application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and access control issues.
单目标 Web 深度漏洞扫描策略。当已知目标 URL、需要对一个 Web 应用进行深度漏洞测试时使用。与 recon-full(资产发现)不同——本技能假设目标已确定,聚焦漏洞层面的深度测试。覆盖指纹驱动的扫描策略选择、自动化+手动测试结合、漏洞优先级排序。优先发现 RCE、SQL注入等高危漏洞
OWASP Top 10 for Web Applications (2025) vulnerability knowledge base for identifying, assessing, and remediating security risks in web application environments.
Generate comprehensive web application vulnerability assessments with OWASP-aligned checklists, r。Use when 需要安全检测、合规审计、漏洞扫描、加密防护时使用。不适用于渗透测试未授权目标。适用于独立开发者、企业团队和自动化工作流场景。
Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing…
Complete reference for 18 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples.
AI-powered tools for Web3 bug bounty automation. Use when you want to automate recon, run autonomous audits, or use AI agents for vulnerability discovery.
Search all 10,533 Security skills →