Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 2

Claude Security Skills (Page 2 of 154)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

9,232 skills · updated 2026-07-31 · showing 61–120 of 9,232 by quality score

Sub-topics:Red Team (1,537)Web Security (961)Threat Hunting (627)Identity Access (441)Network Security (370)Appsec Tools (353)Forensics (243)Compliance (198)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Audit a target's HTTP security headers — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the Cross-Origin trio (COOP, COEP, CORP).
AI-powered analysis of chromosomal instability (CIN) signatures for cancer prognosis, immunotherapy response prediction, and therapeutic vulnerability identification.
The Claude Security menu — pick a job: scan the codebase (the whole repository or a scoped part of it), scan changes (this branch's or a pull request's diff, or one commit), or…
Use when interacting with the CLAWILD autonomous crypto intelligence agent on Moltbook
Helpt bij het beoordelen en implementeren van cloudoplossingen voor de Nederlandse overheid conform het rijksbrede cloudbeleid, BIO cloud-controls, SLM en de strategische…
Analyseert cloud-architecturen op digitale soevereiniteitsrisico's, met focus op de Amerikaanse CLOUD Act, FISA 702, en extraterritoriale jurisdictie.
Validate and analyze AWS CloudFormation templates for security and best practices
Fetches cryptocurrency market data, prices, technical analysis, news, and trends using the CoinMarketCap MCP.
Universal coding principles: DRY, security by default, null guards, and YAGNI. Trigger: When writing or reviewing code in any language or technology.
Scans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis.
Expert-level CodeQL for static analysis, vulnerability detection, and security code scanning
Комбайн — непрерывный конвейер: ОЧЕРЕДЬ → ВЫПОЛНЕНИЕ → ПРОВЕРКА → ПУБЛИКАЦИЯ → ЗАКРЫТИЕ. НЕ останавливается между шагами.
Automated evidence collection across compliance frameworks from cloud providers, identity systems, and security tools
Read findings JSONL files from cluster 1-4 skills, deduplicate by fingerprint, group by severity, and compose a deliverable- grade markdown vulnerability report with per-finding…
Verify that a penetration test has explicit, written, signed authorization before any scanning begins.
System bottleneck identification and exploitation skill with throughput analysis and five focusing steps implementation
GLAW Consumer Protection seat — consumer-side claims and debt-collection defense under the FDCPA (15 U.S.C.
Container image and Kubernetes security scanning for CVEs, misconfigurations, and compliance
GLAW Court Records — the firm's docket-and-opinion fetch agent. Pulls dockets, filings, and opinions from CourtListener's free REST API v4 (with optional PACER/RECAP for federal…
Gets secure, one-time-use payment credentials (cards, tokens) from a Link wallet so agents can complete purchases on behalf of users.
Cryptographic implementation analysis and validation for encryption algorithms, key sizes, and certificate management
Performs comprehensive due diligence on a cryptocurrency using CoinMarketCap MCP data. Use when users ask about a specific coin beyond just its price.
Medical device cybersecurity risk assessment skill per FDA premarket and postmarket guidance
Validates permission inheritance between parent and child agents. Ensures child permissions are equal to or more restrictive than parent.
Runtime enforcement of file system boundaries and tool access restrictions. Blocks unauthorized operations and logs violations.
Defense-in-depth security validation — multi-layered checks for OWASP Top 10, secrets, auth, crypto, and data protection.
Parse the ROE scope definition, enumerate every in-scope target (hostnames, IPs, CIDRs, URLs, cloud accounts, SaaS tenants), validate syntax, detect overlap with out-of-scope or…
Evaluates whether a programming language dependency should be used by analyzing maintenance activity, security posture, community health, documentation quality, dependency…
Scan a source tree for command-injection vulnerable patterns: shell=True calls in Python subprocess, os.system / os.popen with interpolated strings, Node child_process.exec with…
Probe a target for directories that return auto-generated index listings instead of denying or serving a specific file — exposes the full file tree under any reachable directory,…
Scan a source tree for dynamic-code-execution APIs that an attacker can hijack: Python eval / exec / compile, JavaScript eval / Function() / setTimeout(string), Ruby eval /…
Probe a target for accidentally-served secret-bearing files in the web root — `.git/`, `.env`, `.DS_Store`, backup files, database dumps, key files, CI configs, IDE configs.
Scan a source tree for SQL-injection vulnerable patterns: string concatenation into queries, f-string interpolation in SQL, string-format substitution into raw queries, deprecated…
Audit a target's TLS certificate beyond protocol/expiry — chain ordering, OCSP stapling, revocation status, Certificate Transparency presence, key-usage flags, and over-broad…
Scan a source tree for weak cryptographic primitives: MD5 / SHA-1 used for security purposes, DES / 3DES / RC4 ciphers, ECB block mode, custom-built crypto (XOR loops, hand-rolled…
Performs security-focused differential review of code changes (PRs, commits, diffs). Adapts analysis depth to codebase size, uses git history for context, calculates blast radius,…
Helpt bij het implementeren van Digikoppeling voor beveiligde system-to-system communicatie tussen overheidsorganisaties.
TOS-compliant Discord notification monitor. Watches YOUR Discord server for security content forwarded by researchers, matches keywords, and pushes to paper-writer/dogpile via…
Create test data with Zenstruck Foundry v2 factories (PersistentObjectFactory, real objects); define states, sequences, and relationships
EATP SDK implementation reference — TrustPlane, BudgetTracker, PostureStore, security patterns, store backends, enterprise features.
Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state, categorizes them by…
Evaluate npm packages for maintenance health, community adoption, security posture, and alternatives. Runs security pre-checks via Socket.dev and OSV.dev.
GLAW FinCEN Cell — Crypto / Blockchain Intelligence Agent. A blockchain-analyst persona that tracks on-chain activity from PUBLIC blockchain data and explorers: wallet…
Identify the server software, framework, and component versions a target is running from its HTTP response signatures — Server header, X-Powered-By, Via, X-AspNet-Version,…
Deploy payloads and shell commands fleet-wide using reliable tasking. Execute scripts, collect data, or run commands across all endpoints with automatic handling of offline…
Systematically verifies suspected security bugs to eliminate false positives. Produces TRUE POSITIVE or FALSE POSITIVE verdicts with documented evidence for each bug.
GCP security configuration scanning and hardening using Security Command Center, Forseti, and ScoutSuite
Genera ejercicio R-exams tipo SCHOICE (seleccion unica) METACOGNITIVO. TODO ejercicio debe aplicar Progressive Disclosure y analisis de errores conceptuales.
Compose an exec-readable summary from a unified findings JSONL plus the OWASP coverage report. Computes a single engagement risk score (0-100, severity-weighted with OWASP-breadth…
GLAW Private Client + Asset Protection strategist — designs and papers LEGITIMATE asset-protection structures around a new corp/founder (self-settled DAPT, third-party irrevocable…
GLAW Chief Counsel & autonomous managing orchestrator — the firm's decision authority. Reads the firm roster (skills management), ingests Drive comments/suggestions, runs a…
GLAW Litigation seat — federal trial counsel. Federal civil/criminal trial strategy, pleadings, motions, and trial posture.
Design and launch SEC-compliant tokenized securities offerings. Covers the DTC No-Action Letter (Dec 2025), SEC five-category taxonomy (Mar 2026), OTCM/RWA Tokens Category 1…
Retroactively verify threat mitigations for a completed phase — from Gustavosareto/gerenciador-de-quadras
Chief Security Officer mode. Infrastructure-first security audit: secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply cha — from…
Automated PR Review, Windows Compatibility & Security Audit. Wraps maintainer_auditor.py to scan active files for Unix Bashisms, hardcoded Unix paths, and hardcoded secrets,…
Containerized security auditing and ethical hacking tools. All operations run in isolated Docker containers for safety.
Harden software supply chain security by configuring minimum release age across package managers. Auto-detects active managers or accepts explicit argument.
Fills gaps in existing healthcare practitioner lists — adds missing phone numbers, credentials, specialties, contact info, education, reviews, and regulatory data.
Extracts structured practitioner data from healthcare practice websites. Returns names, credentials, specialties, contact info, and education for every provider on a practice's…
Search all 9,232 Security skills →