Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 3

Claude Security Skills (Page 3 of 176)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

10,533 skills · updated 2026-08-26 · showing 121–180 of 10,533 by quality score

Sub-topics:Red Team (1,582)Web Security (1,094)Threat Hunting (754)Identity Access (496)Network Security (414)Appsec Tools (381)Forensics (295)Malware Analysis (207)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

GLAW Private Client + Asset Protection strategist — designs and papers LEGITIMATE asset-protection structures around a new corp/founder (self-settled DAPT, third-party irrevocable…
GLAW Chief Counsel & autonomous managing orchestrator — the firm's decision authority. Reads the firm roster (skills management), ingests Drive comments/suggestions, runs a…
GLAW Litigation seat — federal trial counsel. Federal civil/criminal trial strategy, pleadings, motions, and trial posture.
Design and launch SEC-compliant tokenized securities offerings. Covers the DTC No-Action Letter (Dec 2025), SEC five-category taxonomy (Mar 2026), OTCM/RWA Tokens Category 1…
Retroactively verify threat mitigations for a completed phase — from Gustavosareto/gerenciador-de-quadras
Chief Security Officer mode. Infrastructure-first security audit: secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply cha — from…
Automated PR Review, Windows Compatibility & Security Audit. Wraps maintainer_auditor.py to scan active files for Unix Bashisms, hardcoded Unix paths, and hardcoded secrets,…
Containerized security auditing and ethical hacking tools. All operations run in isolated Docker containers for safety.
Harden software supply chain security by configuring minimum release age across package managers. Auto-detects active managers or accepts explicit argument.
Fills gaps in existing healthcare practitioner lists — adds missing phone numbers, credentials, specialties, contact info, education, reviews, and regulatory data.
Extracts structured practitioner data from healthcare practice websites. Returns names, credentials, specialties, contact info, and education for every provider on a practice's…
Validates practitioner credentials and license status against the NPI registry. Cross-references specialties, credentials, and practice addresses against official records.
HIPAA security and privacy compliance automation for ePHI protection, safeguards assessment, and audit preparation
Infrastructure as Code security scanning and policy enforcement for Terraform, CloudFormation, Kubernetes, and Pulumi
Creates repository following Clean Architecture with Protocol in domain layer and Implementation in infrastructure layer.
Internet.nl batch API voor het geautomatiseerd testen van meerdere domeinen op internetstandaarden. Authenticatie, batch requests, polling, resultaten JSON, dashboard-integratie.
Mailstandaarden getest door internet.nl: SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), DMARC (Domain-based Message Authentication), STARTTLS, DANE (DNS-based…
Stap-voor-stap implementatiegidsen uit de internet.nl toolbox-wiki. Configuratie van DNSSEC, HTTPS/TLS, DMARC, DKIM, SPF, DANE en IPv6 op veelgebruikte platformen (BIND, NSD,…
Webstandaarden getest door internet.nl: HTTPS, TLS 1.2/1.3, HSTS, DNSSEC voor websites, IPv6 dual-stack, RPKI route origin validation, security headers (CSP, X-Frame-Options,…
Detects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production.
GLAW Strategic Intelligence Cell — the Analyst. The analytic brain that turns raw collection into a calibrated intelligence estimate using structured analytic techniques (ACH,…
GLAW Strategic Intelligence Cell — Counterintelligence (corporate CI). Detects hostile activity aimed at the client: insider-threat and insider-fraud indicators,…
Create investigations from security events, detections, or LCQL queries. Performs HOLISTIC investigations - not just process trees, but initial access hunting, org-wide scope…
GLAW Investigations & White-Collar Crime Division lead — the firm's FBI/forensic case-building bench.
Check my code, is this correct, what do you think of this, review my changes, pre-merge check, PR feedback, look over my implementation.
Expert-level Istio service mesh management, traffic control, security, and observability for Kubernetes
Use when working with SQLite databases in Bun. Covers Bun's built-in SQLite driver, database operations, prepared statements, and transactions with high performance.
Cryptographic key lifecycle management orchestration including generation, rotation, and destruction across key management systems
Run Checkmarx KICS for Infrastructure as Code security scanning. Use when analyzing Terraform, CloudFormation, Kubernetes, Ansible, Dockerfile, or other IaC for misconfigurations…
Helpt bij het implementeren van LLM-specifieke beveiligingscontrols voor overheidstoepassingen, gebaseerd op de OWASP LLM Top 10, BIO2, NIS2 en AVG.
ASCENT engineering framework. Use to scaffold new projects, enhance existing ASCENT projects, migrate non-ASCENT projects to ASCENT standards, or answer questions about ASCENT's…
Scan project dependencies for CVEs, outdated packages, and license compliance across npm, pip, cargo, go, maven, and other ecosystems.
Service mesh implementation with Istio for microservices traffic management, security, and observability.
Designs and optimizes prompts for large language models including system prompts, agent signals, and few-shot examples.
Comprehensive security audits identifying vulnerabilities, misconfigurations, and best-practice violations across applications, APIs, infrastructure, and data pipelines.
Quick routine security checks for secrets, dependencies, container images, and common vulnerabilities.
Threat modeling methodologies (STRIDE, DREAD, PASTA, attack trees) for secure architecture design. Use when planning new systems, reviewing architecture security, mapping trust…
API Design Rules (ADR) voor NL GOV REST APIs: Spectral-linting, naming, transport security, signing, encryption, problem+json errors, geo-extensie.
Gebruik deze skill wanneer de gebruiker vraagt over 'OAuth', 'OpenID Connect', 'OIDC', 'authenticatie', 'autorisatie', 'AuthZEN', 'SAML', 'identity management', 'toegangsbeheer',…
Cena TRIDIMENSIONAL no ManimCE — `ThreeDScene`, a `ThreeDCamera` (phi, theta, gamma, zoom, focal_distance, frame_center), `ThreeDAxes`, `Surface` e os sólidos (`Sphere` `Cube`…
Annotate every pentest finding with its OWASP Top 10 (2021) category by applying a deterministic rule table keyed on source skill, finding category, detail keywords, and CWE…
Generates a comprehensive crypto market report using CoinMarketCap MCP data. Use when users ask about overall market conditions, sentiment, or want a summary.
Query, inspect, and manage saved database connections through the Go `miudb` CLI. Use when the user asks to run SQL, list schemas, add native connections, smoke-test connections,…
Enterprise Encryption Security with AI-powered cryptographic architecture, Context7 integration, and intelligent encryption orchestration for data protection
Unified cloud security posture management across AWS, Azure, and GCP with normalized metrics and CIS benchmark comparison
Helpt bij het ontwerpen van overheidssystemen conform de Nederlandse Overheid Referentie Architectuur (NORA), inclusief basisprincipes, afgeleide principes, informatiebeveiliging…
Use when the user asks to create, edit, inspect, polish, verify, or deliver Word `.docx` documents, Google Docs-targeted drafts, business briefs, forms, reports, tables,…
OpenSearch detection engineering: SIGMA authoring, query DSL translation, MITRE ATT&CK mapping, anomaly detection, correlation rules, SOC incident escalation.
Run multiple Ralph loops concurrently for independent tasks. Supports all 6 ralph-* teammates (coder, reviewer, tester, researcher, frontend, security).
A Web security assessment workflow built on globally installed Chrome DevTools MCP and Burp MCP. It establishes real browser state, synchronizes Burp evidence, models endpoints…
Enhance SEO (meta tags, semantic HTML) and security (vulnerability checks, hardening). Triggers: SEO, security, meta tags, vulnerability, 검색 최적화, 보안.
Phase agent for the verify step of the 9-phase orchestrator pipeline (CTL-450). NEW skill — has no canonical wrapper.
Phishing simulation campaign execution and analysis for security awareness assessment
Bounded, interactive engineering-readiness review of a concrete implementation plan BEFORE coding — routine features, refactors, bug fixes.
Intensely interviews the user about their plan — one question at a time — challenging it against the project's existing domain model, sharpening terminology, and updating/creating…
Maximum-rigor, exhaustive review of a HIGH-RISK or cross-cutting implementation plan, design doc, or architecture proposal — use only when the user explicitly asks for a…
Single orchestrator for the post-plan workflow. Runs commit/push/PR, diff classification, code review, security audit, verification, CI monitoring, retrospective, worktree…
Probe a target for HTTP methods that should not be enabled in production — TRACE (XST attack), unrestricted PUT/DELETE, DEBUG/CONNECT, WebDAV (PROPFIND/MKCOL/COPY/MOVE), and Allow…
Expert skill for protocol fuzzing, vulnerability discovery, and security testing
Use when auditing a Rails app for SQL injection, XSS, CSRF, mass-assignment, or Gemfile.lock CVEs, or when reviewing only NEW security regressions in a PR vs base branch.
Search all 10,533 Security skills →