Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 6

Claude Security Skills (Page 6 of 176)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

10,533 skills · updated 2026-08-26 · showing 301–360 of 10,533 by quality score

Sub-topics:Red Team (1,582)Web Security (1,094)Threat Hunting (754)Identity Access (496)Network Security (414)Appsec Tools (381)Forensics (295)Malware Analysis (207)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Comprehensive codebase cleanup across 11 quality dimensions: dead code, duplication, weak types, circular deps, defensive cruft, legacy code, AI slop, type consolidation,…
Erstellt Mandantenbriefe in einfacher, verständlicher Sprache – kein Juristenjargon. Übersetzt komplexe Bescheids-, Widerspruchs- oder Klageinhalte in klare, handlungsori — from…
Tworzy i rozbudowuje profesjonalne dokumenty ofertowe dla klientów w formacie .docx. Zachowuje ustalony styl — nagłówki bez numeracji, zwięzłe listy (2-3 punkty), tabele…
API reference for CoinMarketCap cryptocurrency endpoints including quotes, listings, OHLCV, trending, and categories.
API reference for CoinMarketCap DEX endpoints including token lookup, pools, transactions, trending, and security analysis.
Audits the entire codebase for bugs, security vulnerabilities, CLAUDE.md violations, dead code, duplicate code, and test quality issues.
Review code for quality, correctness, and security vulnerabilities. Use when the user asks to review code, audit for security issues, or check for bugs and anti-patterns.
Generate a comprehensive codebase profile — architecture topology, dependency graph, code quality metrics, security surface, test posture, and infrastructure snapshot.
Use when you need a comprehensive code review combining architecture, security, and test perspectives - especially before merging, releasing, or after major changes.
Run an A/B codex review experiment — holistic codex review vs 3 focused dimension passes (security, ecto, liveview) on the branch diff, classify findings, report a panel-value…
Run Codex adversarial review — actively tries to break confidence in the change. Use when asked \"adversarial review\", \"적대적 리뷰\", or wants thorough security/correctness…
Multi-language code reviewer with 9 review personas (API Design & Schema Guardian, Architecture & Abstraction Guardian, Convention & Documentation Steward, Infrastructure…
Porter 5 Forces + game-theory primer for a specific market — equilibrium prediction, response-game tree, exit scenarios. Routes to red-team-strategist agent.
Build a compliance bundle — CycloneDX SBOM, SPDX license report, SARIF findings, OpenVEX/CycloneDX VEX, optional cosign signatures, manifest.json with SHA-256 sums, Markdown…
Aggregates findings from the other security audits into one prioritized security report. Use after running individual security reviews to produce a consolidated report.
Calculate derived football metrics and models. Use when the user wants to compute xG, xGOT, PPDA, passing networks, expected threat, possession value, pressing intensity, or any…
Create and troubleshoot AWS Glue connections to JDBC databases (Oracle, SQL Server, PostgreSQL, MySQL, RDS), Redshift, Snowflake, and BigQuery.
Use when the user asks to check ConnectWise Automate fleet health, find stale or offline agents, report patch compliance by client, triage open alerts across clients, inventory…
Use when the user asks to list, search, or inspect ConnectWise Control (ScreenConnect) remote-support and access sessions, run a command on a guest machine, rename or tag…
Use when the user asks to triage a ConnectWise board, find unbilled time before an invoice run, check agreement burn against block hours, pull a client account 360, log time on a…
Diagnose Claude Code environment health — context budget, description obesity, trigger collisions, hooks, MCP, plugins, CLAUDE.md, memory, and skill-security scan.
Review a contribution PR for safety, quality, and readiness. Checks for security concerns, test coverage, size appropriateness, and intent alignment.
Convene a council, ask the council, debate this, get a panel to critique, run this by a council of experts, council of advisors, devil's advocate panel, red-team this decision,…
Use when: reviewing, designing, implementing, or debugging C/C++ for SEI CERT secure-coding violations detected by clang-tidy cert-* checks: unchecked standard-library return…
Use when: reviewing, designing, or hardening a C++ network server (HTTP/TLS/socket) against connection-holding DoS, resource exhaustion, weak crypto defaults, and per-connection…
n8n credential types, REST API credential management, HTTP Request node authentication, predefinedCredentialType vs genericCredentialType, httpCustomAuth JSON format, credential…
分析crypto exchange compliance相关互联网金融合规问题。 覆盖:监管框架、资质要求、合规要点、违规风险。 适用情形:用户提及crypto exchange compliance相关事项。
Empacota uma escalação para Devs, Produto ou Davidson com contexto completo. Use quando um bug precisa de atenção além do suporte normal, vários clientes reportam o mesmo…
Package an escalation for engineering, product, or leadership with full context. Use when a bug needs engineering attention beyond normal support, multiple customers report the…
Research CVEs and security advisories for project dependencies. Uses Exa, NVD API, OSV.dev, and GitHub Advisory Database to find known vulnerabilities.
Scan project dependencies for known CVEs using native audit tools (npm, pip, composer, cargo, go, bundler, dart)
Pull CVEs against the current dependency set (osv.dev / GHSA) and classify each as exploitable / theoretical / not-applicable
SQL query design, optimization, EXPLAIN analysis, index strategy, pagination, upserts, and N+1 prevention for relational databases (PostgreSQL, MySQL, SQL Server, SQLite, Oracle).
Examines all database interactions for injection, access control, encryption, and data-exposure risks. Use when auditing database and data-layer security.
Sync your whole Datto BCDR fleet into local SQLite and answer the questions the per-appliance Partner Portal can't.
Every Datto RMM API operation, plus a local SQLite fleet store and fleet-wide analytics no other Datto tool has.
Analyze code quality, view issues, check metrics, find dependency vulnerabilities, and report test coverage via DeepSource CLI.
Delete a TPU VM and (optionally) the per-region networking that was set up alongside it. By default deletes ONLY the VM — Cloud NAT, IAP firewall, and Private Google Access stay…
Pre-add risk gate for a new dependency — composes vuln history (`vdb vulns`), AI-malware check (`vdb ai-malware`), license compatibility, EOL status, maintainer health,…
Audit npm dependencies across all package.json files — reports outdated, security issues, and unused packages
Dependency-conflict resolution when a `/vulnetix:fix` version bump fails — diagnose the peer-dep tree, find a compatible safe version set, propose package-manager overrides…
Bir tanık veya taraf (isticvap) için duruşma/ifade soru taslağı (outline) hazırlar — şirket içi belgeleri veya UYAP evraklarını çeker, hukuki teori etrafında başlıkları düzenler…
Record a vetted Hex package version in hex_vet.exs after a security review — manages the audit ledger, not the scanner.
IDS/IPS detection content for a CVE — Snort/Suricata-compatible rules, YARA signatures, ProjectDiscovery Nuclei templates, traffic-filter rules.
Read-only audit dispatch for the active feature on the requested axis — security (OWASP, trust boundary, secrets), perf (measure-first, N+1, CWV), or simplify (Chesterton's Fence,…
Audit software supply chain across every ecosystem (npm, pip, Go, Ruby, Cargo, Maven, Docker, Terraform) — pinning, vulnerabilities, secrets, SBOM, signing, branch protection,…
Every Domotz endpoint, plus a local SQLite fleet mirror that answers cross-site questions. Trigger phrases: `which domotz sites are down`, `list offline devices across all sites`,…
Trigger on: /coeus:dug_binary, "dug project", "dugprj", "list horizons from dug", "list polygons from dug", "list volumes from dug", "processes per volume", "volume lineage",…
Security hardening audit — OWASP Top 10 prevention, secrets scan, dependency audit, input validation, auth review.
员工侵犯商业秘密风险评估与防控方案。 为企业评估员工侵犯商业秘密风险,识别高风险主体,制定防控方案:竞业限制协议有效性审查、 保密协议执行评估、员工带走信息的技术手段防护(上网行为管理/USB管控/邮件审计)、 离职交接流程规范性检查、证据保全与快速响应机制。 适用情形:员工离职带走商业秘密风险评估、商业秘密保护制度建设、竞业限制与保密协议审查、…
Audit env var usage vs .env.example and code references — surface drift, unused vars, missing docs, and security risks.
Generate a runnable exploit-validation command (Nuclei template, Metasploit module hint, AI-assisted Python script, or curl-based PoC) against a user-specified authorised target.
Search for exploits across all vulnerabilities with filtering by ecosystem, severity, source, and EPSS
Reviews file upload and handling for path traversal, type validation, storage, and related logic flaws. Use when auditing file upload or processing security.
Fetch the consolidated financial snapshot for a given tax year from a DocVault instance (tax docs, sales, mileage, retirement, brokerage, crypto, bank accounts, real estate).
Generuje gotowy post na Instagram o projekcie Finora w formacie karuzeli 7 slajdów — format zoptymalizowany pod algorytm Instagrama (maksymalne swipe-through, czas spędzony,…
Zero-tolerance code quality enforcement. Fixes ALL errors, warnings, suppressions, and security issues.
Verifies that git commits address security audit findings without introducing bugs. This skill should be used when the user asks to "verify these commits fix the audit findings",…
Flutter development skill for Miqotul Khoir TV (MKT) project. Use for: implementing new Flutter features, fixing UI bugs, modifying widgets, creating Cubit state management,…
Cross-agent self-inspection of your AI-agent stack. Audits skills, MCP servers, hooks, plugins, commands, credentials, and memory files across Claude Code, Codex, OpenClaw, and…
Search all 10,533 Security skills →