Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 56

Claude Security Skills (Page 56 of 176)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

10,533 skills · updated 2026-08-26 · showing 3301–3360 of 10,533 by quality score

Sub-topics:Red Team (1,582)Web Security (1,094)Threat Hunting (754)Identity Access (496)Network Security (414)Appsec Tools (381)Forensics (295)Malware Analysis (207)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

对 jar-analyzer-engine 构建的 SQLite 数据库执行安全审计分析查询。支持方法调用搜索、调用链追踪、Spring 组件分析、字符串搜索、漏洞模式检测等。
Electron 33+ desktop app development specialist covering Main/Renderer process architecture, IPC communication, auto-update, packaging with Electron Forge and electron-bu — from…
Performs deep documentation analysis on software repositories to build a comprehensive product context profile used to validate and enrich security vulnerability findings.
Gera documentação rica e profissional para projetos — README bilíngue EN+PT-BR, docs estruturados, placeholders de imagem com dimensões corretas, CHANGELOG, CONTRIBUTING, SECURITY…
Atualização INCREMENTAL da documentação project-doc — mapeia o diff do trabalho recente pros docs afetados (via scope inverso) e re-projeta SÓ eles, sem re-mineração completa.
SECURITY: the DOCA UROM Service binary has NO standalone access control (no authz list / `allowed_host` / `allowed_users` / `auth_token`) — access is governed ENTIRELY by DOCA…
Runs Trivy against a Docker image and produces a prioritized CVE list grouped by severity with fix availability. Filters out CVEs with no available fix.
Secure Docker containers and images with hardening, scanning, and secrets management
OWASP Docker Top 6 vulnerability knowledge base for identifying, assessing, and remediating security risks in containerized Docker environments.
Audits Dockerfiles for security vulnerabilities using Hadolint and Trivy container scanner. Recommends hardening steps based on CIS Docker Benchmark and Snyk container advisories.
Automatically applies when writing function docstrings. Uses Google-style format with Args, Returns, Raises, Examples, and Security Note sections for proper documentation.
Implement security best practices for Documenso document signing integrations. Use when securing API keys, configuring webhooks securely, or implementing document security…
Analiza la jerarquía de archivos de un repositorio técnico de fabricante de componentes electrónicos, construye un grafo semántico de relaciones entre documentos, y define el…
Crie, revise e mantenha a documentação do projeto Dental System. Use quando Codex precisar atualizar README, guias de instalação, scripts de execução, documentação de API,…
Systematically improve documentation quality from 7/10 → 9/10 using assessment checklists and transformation patterns.
Knowledge base from the OUSD(R&E) guidebook Implementing a MOSA in DoD Programs (Feb 2025). Use for the Modular Open Systems Approach as a DoD acquisition + design discipline: the…
Dodaje nowy wpis nastroju do VIBEO (dziennik nastroju w Supabase) na konkretny dzień — domyślnie dzisiaj.
Knowledge base from DOE Systems Engineering Methodology (SEM) Version 3 — the DOE SDLC for IT investments.
Security best practices for Dokploy templates: secrets management, network isolation, least privilege, image security, and hardening recommendations.
Dokploy 셀프호스팅 PaaS 플랫폼의 전체 관리 스킬. SSH 및 API를 통한 서버 관리, 애플리케이션 배포, Docker Compose/Swarm 관리, 데이터베이스(PostgreSQL, MySQL, MongoDB, Redis) 관리, Traefik 리버스 프록시 설정, SSL 인증서(Let's Encrypt,…
Configure Traefik labels for routing, SSL/TLS with LetsEncrypt, and advanced routing patterns including Cloudflare DNS challenge. Use when adding web access to Dokploy services.
Notare: dolmetscher und sprachrisiko - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit, Belegplan und…
Use when creating or updating a Dolphin{anty} antidetect browser profile from a Facebook account note in this vault.
Domain reconnaissance coordinator that orchestrates subdomain discovery and port scanning to build comprehensive domain attack surface inventory
DDD/Event Storming skill dlya issledovaniya novogo domena ili bounded context. Ispol'zuj pri zaprose "novyj domen", "event storming", "bounded context", "issledovaniye domena",…
Kullanıcının belirttiği anahtar kelimeleri ve sayısal hedefleri kullanarak yaratıcı ve akılda kalıcı domain isimleri listeler.
Kullanıcının belirttiği anahtar kelimeleri ve sayısal hedefleri kullanarak yaratıcı ve akılda kalıcı domain isimleri listeler.
Research any domain with WHOIS data, DNS records, SSL certificate details, domain age, reputation scoring, and security header analysis.
Transfer knowledge, frameworks, and mental models between domains in the skill library. Use when a concept from one domain could apply to another, when looking for cross-domain…
Escribe tutoriales completos en lenguaje natural para proyectos de domótica, contextualizados en escenarios reales de automatización del hogar con integración Home Assistant.
DOMPurify XSS sanitization for HTML content in agent outputs. Strip script tags and event handlers, allowlist-based tag/attribute filtering, sanitize LLM-generated HTML before…
NeRDS software development guidelines for Dutch government projects. Use when making architectural decisions, setting up CI/CD, implementing security practices, handling privacy…
Security standards and authentication tools for Dutch government software. Use when implementing DigiD, eHerkenning, OAuth, OIDC, PKIoverheid, or other Dutch government…
Record and query the decision log for a project. Activate when user mentions "audit", "trail", "log decisions", "decision history", "why was this decided", "ADR", "architecture…
Perform strict 7-dimension peer review analyzing correctness, tests, performance, architecture, security, style, and diff cleanliness.
Perform OWASP Top 10 static security audit identifying vulnerabilities in access control, cryptography, injection, configuration, and logging.
別駭我!基本安全檢測 — Security self-check for Clawdbot/Moltbot. Run a quick audit of your clawdbot.json to catch dangerous misconfigurations — exposed gateway, missing auth, open DM…
Dope.security integration. Manage data, records, and automate workflows. Use when the user wants to interact with Dope.security data.
Validate and test Doppler secrets. TRIGGERS - add to Doppler, store secret, validate token, test credentials.
Doppler credential and publishing workflows. TRIGGERS - PyPI publish, AWS credentials, Doppler secrets.
DORA-Artikel-16-Fachmodul für Cyber- und Compliance-Teams: prüft, ob ein Finanzunternehmen den vereinfachten IKT-Risikomanagementrahmen nutzen kann, und baut Governance-, Asset-,…
Grenzt NIS-2 zu DORA bei Banken, Zahlungsdiensten und IKT-Drittparteien ab im Nis2 Cybersecurity Compliance.
Find denial of service vulnerabilities through resource exhaustion, algorithmic complexity, memory exhaustion, and file/network resource abuse.
dotenvx - secure environment variable management with encryption. Use for encrypting .env files, multi-environment configuration, cross-platform secret management, and migrating…
dotenvx is a secure, cross-platform environment variable manager from the creator of dotenv. It provides encrypted .env files, multi-environment support, and works with any…
Credentialed fixture whose script opens `.agentbundle/credentials.env` directly without the opt-out marker; AC26(c) finding expected.
Subject every non-trivial decision to a fresh-context adversarial review before it stands. Use when correctness matters more than speed, when working in unfamiliar code, when…
Subjects every non-trivial decision to a fresh-context adversarial review before it stands. Use when correctness matters more than speed, when working in unfamiliar code — from…
Down: Red-Team und Qualitätskontrolle im Insolvenzplan und StaRUG: fachlich vertieftes Modul mit Normenradar (InsO/StaRUG/Planrecht), Tatbestands-/Beweislastmatrix, Fristen- und…
Respond fast and safely if your personal information has been exposed or you're being doxxed — contain the spread, protect your safety and accounts, and report it.
English language Controller-to-Controller data sharing agreement template used between two independent controllers exchanging personal data under the GDPR.
English language technical and organisational measures (TOM) annex template for a DPA under Article 32 GDPR.
Provides a structured risk scoring methodology for Data Protection Impact Assessments aligned with ENISA threat taxonomy and ISO 29134.
Vstupní bod a společný standard pipeline pro řízení kvality dat v libovolné databázi (MySQL, PostgreSQL, SQL Server, Oracle, SQLite, DuckDB) — DQ dimenze, formát zjištění, škála…
Prevence vzniku chyb a monitoring kvality dat — cizí klíče a CHECK constrainty, opravy datových typů, DQ firewall na vstupu, kontinuální měření metrik s alertingem, metadatový…
Ensure architecture docs define RPO/RTO, failover paths, data consistency, and DR drillability.
Generate a Disaster Recovery plan with RTO/RPO targets. Use when someone asks to "create a DR plan", "disaster recovery", "business continuity", or "RTO RPO".
Default-Deny security posture for Supabase. Mandates strict RLS and 'WITH CHECK' clauses. — from security/security-misc
Default-Deny security posture for Supabase. Mandates strict RLS and 'WITH CHECK' clauses. — from security/security-misc
Generates Terms of Use and Cookie Policy documents for a cybersecurity company website, strictly limiting data usage to newsletters and event updates, prohibiting data sales, and…
Search all 10,533 Security skills →