Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 5

Claude Security Skills (Page 5 of 154)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

9,232 skills · updated 2026-07-31 · showing 241–300 of 9,232 by quality score

Sub-topics:Red Team (1,537)Web Security (961)Threat Hunting (627)Identity Access (441)Network Security (370)Appsec Tools (353)Forensics (243)Compliance (198)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Comprehensive audit capabilities for security, code quality, module structure, compliance, and performance analysis.
모든 사용자 발화·agent 행동·phase 전환·gate 판정을 ISO 8601 타임스탬프와 함께 감사 로그에 기록한다. 사용자 입력은 축약·요약 없이 verbatim blockquote로 보존하며, SOC2·ISMS-P 감사 요구사항에 매핑되는 보존 정책(30·90·365일)을 프로젝트별로 선택한다.
Use this skill to verify milestone achievement against its definition of done, checking requirements coverage, cross-phase integration, and end-to-end flows.
Analyzes a single web page URL for SEO quality, identifying issues with title tags, meta descriptions, heading structure, and content.
Use when: auditing a website URL or codebase, checking site health score, SEO audit, performance audit, security scan, accessibility audit, mobile audit, broken links, meta tags,…
All-in-one fullstack dev engine. /aura: 46 modes (build/fix/clean/deploy/review/spec/lore/ax/experiment/payment/debug/qa/orchestrate/escalate+), 6-layer security with 32 hooks,…
Audit authentication and authorization patterns. Checks JWT, sessions, OAuth2, PKCE implementations for security best practices and common vulnerabilities.
Use when: reviewing, designing, implementing, or testing auth/security claim contracts for optional claims, JWT/OIDC/SAML/session/token claims, missing-vs-invalid semantics,…
Conducts a comprehensive authentication security review covering login, sessions, tokens, and credential handling. Use when auditing authentication for vulnerabilities.
Use when the user asks to triage the Autotask service desk, find unbilled or uninvoiced time before a billing run, check contract burn or retainer run-out, pull a company 360, age…
Guides container vulnerability remediation using Averlon MCP. Use when the user wants to fix container vulnerabilities, update Dockerfile packages, or get Averlon container…
Use when the user asks to check Axcient x360Recover backups across an MSP fleet - whose backups failed or went stale last night, who is breaching RPO, per-client backup-compliance…
The before-the-first-line lens for a frontend build: fix what is expensive to reverse before sunk cost exists.
Audit an AI agent benchmark for hackability. Detects evaluation vulnerabilities like missing isolation, leaked answers, eval() on untrusted input, prompt injection in LLM judges,…
Use when the user asks to check what's down in Better Stack, find monitors that would page nobody, report incident MTTA/MTTR, see who's on call or where on-call has gaps, rank…
Use when: billing audit, subscription lifecycle review, Stripe/Paddle integration check, webhook security, payment form CSRF, pricing centralization, webhook idempotency, billing…
Use when the user asks to triage Blumira findings across client accounts, see what changed in Blumira since the last sync, check detection-coverage drift versus the basis ruleset,…
Полный аудит бота: 3 senior-ревью (баги, security, рефакторинг) + 5 QA-агентов (50 тестов по 10) + health-check. 8 параллельных агентов.
Generate contextual briefings for legal work — daily summary, topic research, or incident response. Use when starting your day and need a scan of legal-relevant items across…
Probe a site's authentication flow for redirect leaks, missing CSRF, weak session cookies, and OAuth misconfiguration; produces an auth findings.md
Zero-tolerance multi-agent code annihilation system. Spawns parallel brutal agents for Security, Architecture, Quality, Performance, and Style review with full MCP integration.
Security review and vulnerability scanning for Buildkite plugins (Bash, Docker, Go). Use when auditing or hardening a plugin, reviewing plugin code for vulnerabilities before…
Analyzes business logic for security flaws such as workflow bypasses, race conditions, and abuse cases. Use when reviewing application logic for exploitable behavior.
Opt-in lightweight STRIDE pass for a sensitive feature before implementation. Not a routine gate — invoke it when a change warrants security thought.
Captures a validated learning into the Memory Graph (SQLite). Invoke when: a bug is resolved non-obviously, a pattern is discovered, the user corrects a mistake, or a solution…
Audits a GitHub Actions workflow YAML file (or a directory under `.github/workflows/`) against 30 deterministic checks (top-level `name:`, permissions, timeouts, concurrency,…
Prueft Helm Chart-Dateien eines Kamerplanter-Komponente auf NFR-002-Konformitaet: SecurityContext, NetworkPolicies, Resource Limits, Health Probes,…
USE FOR anything touching CIBA backchannel auth — cibaService.js, cibaEnhanced.js, routes/ciba.js, CIBAPanel.js UI, CIBA grant type (urn:openid:params:grant-type:ciba),…
Use when the user asks to roll up Microsoft 365 posture across all their CIPP tenants (MFA, Conditional Access, Standards, BPA), find unused M365 licenses, flag stale accounts,…
5 expert personas debate proposed changes before implementation. Catches architectural, security, performance, and UX issues early.
Automated multi-agent PR security review. Fleet of specialized agents examine code for logic errors, security vulnerabilities, broken edge cases, and regressions.
Comprehensive codebase cleanup across 11 quality dimensions: dead code, duplication, weak types, circular deps, defensive cruft, legacy code, AI slop, type consolidation,…
Erstellt Mandantenbriefe in einfacher, verständlicher Sprache – kein Juristenjargon. Übersetzt komplexe Bescheids-, Widerspruchs- oder Klageinhalte in klare, handlungsori — from…
Tworzy i rozbudowuje profesjonalne dokumenty ofertowe dla klientów w formacie .docx. Zachowuje ustalony styl — nagłówki bez numeracji, zwięzłe listy (2-3 punkty), tabele…
API reference for CoinMarketCap cryptocurrency endpoints including quotes, listings, OHLCV, trending, and categories.
API reference for CoinMarketCap DEX endpoints including token lookup, pools, transactions, trending, and security analysis.
Audits the entire codebase for bugs, security vulnerabilities, CLAUDE.md violations, dead code, duplicate code, and test quality issues.
Review code for quality, correctness, and security vulnerabilities. Use when the user asks to review code, audit for security issues, or check for bugs and anti-patterns.
Generate a comprehensive codebase profile — architecture topology, dependency graph, code quality metrics, security surface, test posture, and infrastructure snapshot.
Use when you need a comprehensive code review combining architecture, security, and test perspectives - especially before merging, releasing, or after major changes.
Run an A/B codex review experiment — holistic codex review vs 3 focused dimension passes (security, ecto, liveview) on the branch diff, classify findings, report a panel-value…
Run Codex adversarial review — actively tries to break confidence in the change. Use when asked \"adversarial review\", \"적대적 리뷰\", or wants thorough security/correctness…
Multi-language code reviewer with 9 review personas (API Design & Schema Guardian, Architecture & Abstraction Guardian, Convention & Documentation Steward, Infrastructure…
Porter 5 Forces + game-theory primer for a specific market — equilibrium prediction, response-game tree, exit scenarios. Routes to red-team-strategist agent.
Build a compliance bundle — CycloneDX SBOM, SPDX license report, SARIF findings, OpenVEX/CycloneDX VEX, optional cosign signatures, manifest.json with SHA-256 sums, Markdown…
Aggregates findings from the other security audits into one prioritized security report. Use after running individual security reviews to produce a consolidated report.
Calculate derived football metrics and models. Use when the user wants to compute xG, xGOT, PPDA, passing networks, expected threat, possession value, pressing intensity, or any…
Create and troubleshoot AWS Glue connections to JDBC databases (Oracle, SQL Server, PostgreSQL, MySQL, RDS), Redshift, Snowflake, and BigQuery.
Use when the user asks to check ConnectWise Automate fleet health, find stale or offline agents, report patch compliance by client, triage open alerts across clients, inventory…
Use when the user asks to list, search, or inspect ConnectWise Control (ScreenConnect) remote-support and access sessions, run a command on a guest machine, rename or tag…
Use when the user asks to triage a ConnectWise board, find unbilled time before an invoice run, check agreement burn against block hours, pull a client account 360, log time on a…
Diagnose Claude Code environment health — context budget, description obesity, trigger collisions, hooks, MCP, plugins, CLAUDE.md, memory, and skill-security scan.
Review a contribution PR for safety, quality, and readiness. Checks for security concerns, test coverage, size appropriateness, and intent alignment.
Convene a council, ask the council, debate this, get a panel to critique, run this by a council of experts, council of advisors, devil's advocate panel, red-team this decision,…
Use when: reviewing, designing, implementing, or debugging C/C++ for SEI CERT secure-coding violations detected by clang-tidy cert-* checks: unchecked standard-library return…
Use when: reviewing, designing, or hardening a C++ network server (HTTP/TLS/socket) against connection-holding DoS, resource exhaustion, weak crypto defaults, and per-connection…
n8n credential types, REST API credential management, HTTP Request node authentication, predefinedCredentialType vs genericCredentialType, httpCustomAuth JSON format, credential…
分析crypto exchange compliance相关互联网金融合规问题。 覆盖:监管框架、资质要求、合规要点、违规风险。 适用情形:用户提及crypto exchange compliance相关事项。
Empacota uma escalação para Devs, Produto ou Davidson com contexto completo. Use quando um bug precisa de atenção além do suporte normal, vários clientes reportam o mesmo…
Package an escalation for engineering, product, or leadership with full context. Use when a bug needs engineering attention beyond normal support, multiple customers report the…
Search all 9,232 Security skills →