Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 170

Claude Security Skills (Page 170 of 176)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

10,533 skills · updated 2026-08-26 · showing 10141–10200 of 10,533 by quality score

Sub-topics:Red Team (1,582)Web Security (1,094)Threat Hunting (754)Identity Access (496)Network Security (414)Appsec Tools (381)Forensics (295)Malware Analysis (207)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Scan project scripts and deliverables for vulnerabilities and malicious code execution risk. Use this skill whenever the user mentions deliverable scanning, malicious code, script…
Use this skill when reviewing Prometheus or AlertManager configuration for cardinality, alerting correctness, scrape security, remote_write safety, or retention adequacy.
Use this skill when working with SentinelOne Purple AI - natural language cybersecurity investigation, threat hunting, behavioral anomaly analysis, MITRE ATT&CK TTP mapping, and…
Comprehensive healthcare AI toolkit for developing, testing, and deploying machine learning models with clinical data.
Comprehensive healthcare AI toolkit for developing, testing, and deploying machine learning models with clinical data.
Comprehensive healthcare AI toolkit for developing, testing, and deploying machine learning models with clinical data.
This skill should be used when establishing comprehensive QA testing processes for any software project.
Use this skill when working with Checkpoint Harmony Email quarantine - listing, searching, releasing, deleting quarantined emails.
Setup, configure, debug and extend Quasarr — the bridge that connects JDownloader with Radarr, Sonarr and LazyLibrarian via a fake Newznab indexer and SABnzbd client interface.
Use this skill as the designated specialist reviewer for Zeta.Core's query planner / optimiser — join ordering, predicate pushdown, index selection, SIMD/tensor-intrinsic kernel…
Use this skill to audit RAG and AI application security, including retrieval boundaries, prompt injection, citations, memory, and data exposure.
Generates tailored giskard.checks evaluation suites for RAG (Retrieval-Augmented Generation) systems.
Use this skill to rate, audit, grade, stress-test, red-team, or issue a ship/no-ship verdict on a vibe-coded, AI-built, prototype, or MVP app, repository, or live deployment.
Use this skill to rate, audit, stress-test, red-team, or issue a ship/no-ship verdict on a concrete API, worker, realtime service, data pipeline, backend repository, or server…
This skill should be used when the user is securing a React application, asking about "XSS in React", "dangerouslySetInnerHTML security", "Server Actions security", "React data…
This skill should be used when the user asks to "follow red team methodology", "perform bug bounty hunting", "automate reconnaissance", "hunt for XSS vulnerabilities", "enumerate…
Autonomous memecoin discovery and paper trading system using gmgn.ai, dexscreener.com, and other scanners.
Package code repositories into AI-friendly files. Use this skill when packaging codebases for AI analysis, creating repository snapshots, analyzing third-party libraries,…
Use this skill when resolving Blumira findings, choosing the correct resolution type, or understanding resolution workflows and their impact on security metrics.
Implements Google Drive file listing, reading, and management using generated clients and MCP tools. Use when doing ANYTHING that touches Google Drive, files, or documents in any…
Complete end-to-end evaluation of an app/codebase — measures the codebase against the dev-best-practices rules of this repo (essential/app/github/architecture).
LLM system review grounded in CMU 11-667 (Harms + Attacking LLMs), Berkeley CS294-196 (Safety/Guardrails), and OWASP LLM Top 10.
Handle a brand's review response workflow and reputation management program — draft specific, personalized responses to positive/neutral/negative reviews across Google, Yelp,…
Drafts the final reviewer reply document and applies tracked-change edits to the manuscript, given a frozen plan from reviewer-reply-planning.
Orchestrates the end-to-end reviewer-reply workflow from raw reviewer comments to a submission-ready response document and tracked-changes manuscript.
This skill should be used when verifying that work meets its acceptance criteria and is sound — checking a task or change against its spec, judging code quality, or applying a…
Generate LinkedIn-style "RIP" influencer posts in the "X killt Y" genre — the reflective, credentials-flexing, arrow-bullet-laden posts that flood LinkedIn every time a new AI…
Use this skill when the user says 'check RLS', 'audit RLS', 'RLS policies', 'row level security', 'Supabase security audit', or needs to verify table-level access control.
Use this skill when creating or altering database tables in Supabase or PostgreSQL projects. Triggers include: CREATE TABLE, ALTER TABLE, migration files, 'RLS', 'row level…
Purple-team DRILL for the rmagent-windows skill. Stages 8 reversible living-off-the-land (LOTL) artifacts on WS1/WS2 — failed Administrator logons, a new local admin, a SYSTEM…
Pull-based remote-witness habit for a Windows estate — the "RMAgent" knock. Ask two workgroup Windows servers (WS1/WS2) eight allowlisted named questions (attest, sketch, edges,…
Framework-agnostic Roblox/Luau coding standards. Use when writing, reviewing, or refactoring any Luau code (Script, LocalScript, ModuleScript) in a Roblox project, or when the…
Security hardening and best practices for robotic systems, covering SROS2 DDS security, network segmentation, secrets management, secure boot, and the physical-cyber safety…
How to exploit buffer overflow vulnerabilities by leaking libc addresses using ROP chains. Use this skill whenever the user mentions buffer overflow, ROP, return-oriented…
Comprehensive best practices, design patterns, and common pitfalls for ROS2 (Robot Operating System 2) development.
Use this skill when reviewing exported RPA workflow definitions for resilience and security defects that cause unattended bots to fail silently in production.
> Use this skill whenever asked about the taxation of cryptocurrency or digital currency (цифровая валюта) for individuals in Russia.
Runtime security guardian for OpenClaw agents. Use this skill whenever the user mentions security, skill safety, prompt injection, malware, suspicious behavior, credential leaks,…
This skill should be used when the user asks to "safely buy a token", "safe trade", "buy with security check", "safe swap", "check before buying", or "安全买入".
Write, read, debug, and review Sage X3 V12 4GL code — also called L4G, X3 script, Adonix, or SAFE X3 scripting.
Sails.js framework patterns for The Boring JavaScript Stack - actions, helpers, routes, policies, hooks, configuration, security, middleware, file uploads, deployment, and more.
Use this skill when Salesforce development pipelines must be reviewed for DevSecOps compliance — covering Salesforce Code Analyzer (SCA) finding triage and false positive review,…
Analyze codebases to generate optimal Claude Code Sandbox configurations. Use this skill when users need to set up sandbox security settings for their projects.
Guide for sanitizing git repositories by identifying and replacing sensitive information such as API keys, tokens, and credentials.
This skill should be used when the user asks to "check CWE Top 25", "run SANS analysis", "check for common weaknesses", or mentions "CWE" or "SANS Top 25" in a security context.
This skill handles SAP BTP (Business Technology Platform) development including CAP (Cloud Application Programming Model), Fiori Elements, SAP Build Apps, Integration Suite,…
This skill provides comprehensive guidance for SAP Cloud Logging service on SAP BTP. Use when setting up Cloud Logging instances, configuring log ingestion from Cloud Foundry or…
This skill should be used when developing SAP UI5 applications, including creating freestyle apps, Fiori Elements apps, custom controls, testing, data binding, OData integration,…
Software Bill of Materials (SBOM) security analysis for vulnerability assessment and third-party risk management.
This skill covers integrating Aqua Security''s Trivy scanner into CI/CD pipelines for comprehensive container
This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networ — from…
This skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networ — from…
Score a documentation package against the ten-dimension weighted rubric in `references/scorecard-rubric.md` with a cited justification per dimension, then evaluate the eighteen…
Scrape Google Maps for any business type in any location, then find and verify contact emails. Use when the user wants leads/businesses from Google Maps with verified emails —…
One-shot setup of the full Scrutineer skill set for the current repository. Use this skill whenever the user says /scrutineer-setup, asks to "install scrutineer", "set up the…
Special Court for Sierra Leone (SCSL, 2002-2013) and the Residual Special Court for Sierra Leone (RSCSL, 2013-) research, drafting, and analysis.
Use this skill any time the user wants to create, edit, design, generate, deploy, or debug a SentinelOne Singularity Data Lake (SDL) dashboard.
Master SDLC orchestrator that reads TASK.md and executes a complete development cycle: TDD test design, TDD implementation, refactoring, code quality, security, documentation, git…
分析secret-identification-assessment相关知识产权侵权问题。 覆盖:侵权行为识别、证据收集、维权策略建议。 适用情形:用户说"secret-identification-assessment"相关问题。
Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation.
Search all 10,533 Security skills →