Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 21

Claude Security Skills (Page 21 of 155)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

9,256 skills · updated 2026-08-01 · showing 1201–1260 of 9,256 by quality score

Sub-topics:Red Team (1,538)Web Security (965)Threat Hunting (629)Identity Access (441)Network Security (372)Appsec Tools (354)Forensics (243)Compliance (198)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

This ASE skill uses zizmor to audit GitHub Actions workflows and composite actions for security mistakes before they ship.
Shared audit integrity framework for all AppSec agents — enforces output quality, intellectual honesty, and continuous improvement through anti-rationalization guards,…
Comprehensive audit logging for compliance and security. Track user actions, data changes, and system events with tamper-proof storage.
Baut den Nachweisordner für Audit, Aufsicht und Streit im Nis2 Cybersecurity Compliance.
Run comprehensive parallel audit — dispatches specialized agents by scope (frontend, backend, infra, security)
Read-only audit for payment/money-movement systems, scope-gated so a simple Stripe-Checkout site and an in-house ledger/gateway each see only relevant findings.
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and…
Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures…
Prepare your codebase for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures…
Scan Python requirements and environments for known vulnerable or malicious packages before they move further through delivery or promotion workflows.
Check Python environments and requirements files for published vulnerabilities before shipping, upgrading, or approving dependency changes.
Reviews pull requests for compliance regressions. Scans code diffs for security and compliance violations, flags issues, and suggests fixes aligned with frameworks like SOC 2, ISO…
Audit a full-stack app against the RealWorld ("Conduit") reference — its formal API spec, shared Bruno/Hurl E2E suite, and closest-stack reference implementation — to find what is…
Template and formatting guidelines for security audit reports. Provides consistent structure for findings, severity classification, ASVS mapping, and remediation recommendations.
Use when auditing or profiling complex Rust CLIs, libraries, Tokio services, Tauri backends, Cargo workspaces, local-first single binaries, or SQLite-backed applications,…
Generate a security audit scope document from one or more GitHub repo URLs and/or API access descriptions.
Quick security audit checking for hardcoded secrets, SSRF vectors, injection points, dependency issues, and missing security headers
Use when adding packages, bumping versions, or responding to security alerts. Enforces supply chain security and vulnerability remediation.
Expert security auditor for AI Skills and Bundles. Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated…
Audit Trail und Logs: steuert wer hat wann was gesehen, geändert, freigegeben oder exportiert zwischen Kanzlei, Mandant und Rechtsabteilung mit Dashboard, Budget, Fristen,…
Audit-Trail für Meldungen: Version, Quelle, Berechnung, Prüfung, Freigabe, Versand und Korrekturhistorie im Berichtspflichten.
Audit Trail Helper - Auto-activating skill for Enterprise Workflows. Triggers on: audit trail helper, audit trail helper Part of the Enterprise Workflows skill category.
Fuehrt das Audit-Trail-Protokoll des Wuerfels — jeder Reviewlauf jede Prompt-Aenderung jede Pruefer-Abnahme jeder Cache-Treffer jede Hash-Pruefung wird unveraenderlich…
Comprehensive guide to implementing audit trails and logging for AI agents including tracing, observability, compliance, and debugging
Programmatic and empirical UI audit of a deployed Tau environment (taucad.dev staging or tau.new production) covering Core Web Vitals, accessibility (WCAG 2.2 AA), security…
Audit websites for SEO, technical, content, and security issues using squirrelscan CLI. Returns LLM-optimized reports with health scores, broken links, meta tag analysis, and…
Workflow полного health check проекта. Architecture → Security → Quality → Report → (Fix). Use before major release or onboarding.
Audit and enable security-oriented Xcode build settings. Progressively enables compiler warnings, static analyzer checkers, and Enhanced Security features.
Audit access control implementations for security vulnerabilities and misconfigurations. Use when reviewing authentication and authorization.
Use right after `board-superpowers:classifying-actions` returns a decision, every time a board-superpowers skill is recording what it is about to do or what it just did.
Screens transaction data for suspicious patterns using red flag typologies and structures SAR narrative elements.
Use when targeting 《审计与经济研究》(Auditing and Economics Research — 南京审计大学主办、专家匿名审稿、不收审稿费/版面费的审计经济双月刊) or deciding whether a Chinese auditing/accounting/econ manuscript fits this…
Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs,
Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies,
Audits the security posture of a CockroachDB cluster (Cloud or self-hosted) across network, authentication, authorization, encryption, audit logging, and backup dimensions.
Audit code against OWASP Top 10 vulnerabilities with structured findings. Use when reviewing code for security issues or conducting security audits.
Reviews coded encounters for accuracy using OIG compliance guidelines and CMS documentation requirements.
Auditing and updating npm dependencies to prevent security vulnerabilities in TypeScript projects
Use when reviewing a Dependabot (or similar) dependency-bump PR — npm/pnpm minor/patch group bumps or GitHub Actions SHA bumps — and you need to do a supply-chain audit before…
Run Microsoft Entra ID tenant reconnaissance, token acquisition and manipulation, and federation backdoor testing with the AADInternals PowerShell toolkit to validate…
Pre-deployment security audit of Solidity smart contracts in a Foundry project. Combines static analysis (Slither, Aderyn), symbolic execution (Mythril), and property-based…
Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage,
Conducts HIPAA compliance assessments with Privacy Rule, Security Rule, and Breach Notification analysis.
Audits the fit between a model's reasoning capability and the complexity of the context it receives. Use when an AI system is underperforming despite good retrieval, when teams…
Auditing Kubernetes cluster RBAC configurations to identify overly permissive roles, wildcard permissions, dangerous
Find over-permissive RBAC roles and service-account token abuse paths in Kubernetes using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess during authorized cluster…
Scan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.
Runs KiCad DRC/ERC checks, exports gerbers and BOM, and generates a structured findings report. Use when reviewing PCB designs, running design rule checks, or preparing…
Audits notification permission request flows. Use when reviewing or improving permission prompts, settings paths, or denial handling.
Audits the project for consistency issues that may arise from manual editing. Checks package scripts, tsconfig paths, README tables, and other conventions.
Audit README.md files against best practices for repos, accounts, or orgs. Detects missing sections, stale links, inconsistent formatting, and convention violations.
Use when targeting 《审计研究》(Auditing Research — 审计署主管、中国审计学会主办、匿名审稿、不收版面费的审计权威核心双月刊) or deciding whether a Chinese auditing manuscript fits this venue.
Use when reviewing website copy, SEO titles/descriptions, marketing content, or public messaging - applies Anil Dash's shareability framework to ensure others can authentically…
Canonical home for utilities shared across the auditing-* skill families (auditing-cc-configs, auditing-skills, auditing-subagents, auditing-context-files, and — as of ADR-0042 in…
Audits optimizer table statistics for staleness, missing coverage, and data quality issues using SHOW STATISTICS.
Use when running a technical SEO audit, debugging Core Web Vitals regressions, checking indexability, validating schema and sitemaps, diagnosing why a site isn't ranking, or…
Auditing Terraform infrastructure-as-code for security misconfigurations using Checkov, tfsec, Terrascan, and
Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains
Use Intel CHIPSEC to assess platform firmware configuration, SPI flash write protection, BIOS lock, SMM/SMRR, and Secure Boot variable state, dump SPI flash, and triage UEFI…
Use when checking if beads-superpowers is outdated, before a plugin release, or when auditing for missing capabilities — covers upstream drift, test execution, documentation,…
Search all 9,256 Security skills →