Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 66

Claude Security Skills (Page 66 of 176)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

10,533 skills · updated 2026-08-26 · showing 3901–3960 of 10,533 by quality score

Sub-topics:Red Team (1,582)Web Security (1,094)Threat Hunting (754)Identity Access (496)Network Security (414)Appsec Tools (381)Forensics (295)Malware Analysis (207)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Apply Fly.io security best practices for secrets management, private networking, TLS certificates, and deploy token scoping.
Write a SQL-callable C function or call PostgreSQL fmgr / SPI from C — covers PG_FUNCTION_INFO_V1, PG_GETARG_* / PG_RETURN_*, PG_ARGISNULL, SRF_* set-returning function…
Guides fnox provider selection and setup — age encryption, AWS (Parameter Store and Secrets Manager), 1Password, Bitwarden, GCP, Azure, Doppler, Vault, and local options.
Security best practices for fnox — key rotation, gitignore rules, CI/CD secret handling, access control, missing-secret enforcement, and avoiding common mistakes.
Use when running the final pre-upload audit of a FOCS (IEEE Symposium on Foundations of Computer Science) submission — the April HotCRP deadline clock, the…
Use when deciding whether a theoretical-computer-science result belongs at FOCS (IEEE Symposium on Foundations of Computer Science) — testing foundations-level significance,…
Normalize vendor-specific billing rows (AWS CUR, Azure Cost Management, GCP Billing Export, OCI) into FOCUS v1.2 columns from user-pasted CSV or JSON input.
Index important directories and perform safe folder operations with proper security checks.
Review a user's trade CSV or position snapshot into one local review card and an append-only investment-thesis record, with at most one user-chosen next-time rule.
Apply security best practices for Fondo including OAuth token management, financial data protection, SOC 2 compliance, and access control.
Apply ant colony optimization and foraging theory to resource search, exploration-exploitation tradeoffs, and distributed discovery.
Use when a task needs the judgment of a Foreign Language and Literature Professor — building a program-review case for a language major facing enrollment scrutiny, validating or…
Wirtschaftsprüfer: forensic services und unabhaengigkeit - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik,…
Use whois in Forensic Claw for lawful DFIR, cyber security, evidence triage, intrusion analysis, and case-backed forensic workflows.
Forensics Data Collector - Auto-activating skill for Security Advanced. Triggers on: forensics data collector, forensics data collector Part of the Security Advanced skill…
SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.
AUTO-INVOKE when user mentions forensics, incident response, IOC, log analysis, evidence preservation, breach investigation, threat hunting, attack timeline.
Analyze network traffic and security incidents with the depth of an "Ultimate Forensics Team". Emphasizes deep packet analysis (PCAP) as the source of truth, OSI layer…
Sichert digitale Beweise ohne Beweiswertverlust im Nis2 Cybersecurity Compliance.
Performs a lightweight pre-release readiness review of Atlassian Forge apps across manifest/module wiring, architecture, runtime compatibility, dependency posture, tests, deploy…
Audit existing infrastructure for security issues, waste, and misconfigurations. Use when asked to "audit my infra", "check cloud setup", "infra review", "are we wasting money",…
Authentication and session discipline. argon2id password hashing, server-side sessions vs JWT, OAuth 2.1 + PKCE, MFA via TOTP / WebAuthn, password reset hygiene, anti-enumeration…
Caddyfile discipline for production traffic. Global options, automatic HTTPS done right, security header pack, reverse_proxy with health checks, structured logs, multi-tenant…
Runs Forge's self-test + secret-leak scan across source, tests, and dashboard. Use before shipping or when asked to test everything, check it executes, or find leaks.
GitHub Actions workflow discipline. SHA-pinned third-party actions, scoped permissions per job, OIDC federation over long-lived cloud credentials, dependency caching, concurrency…
Forge playbook for building and validating n8n automation workflows. Use for n8n, workflow, webhook, trigger, cron, retry, error branch, credentials, validate_workflow.
Design and build networking infrastructure — VPCs, subnets, DNS, load balancers, firewall rules. Use when asked to "set up networking", "VPC design", "configure DNS", "load…
Interactive onboarding conversation that surveys a freshly-bootstrapped project's real repo and builds its initial Project Brain — projectFacts, knowledge entries (overview /…
Exhaustive actor-based QA warfare for FitnessMealPlanner. Targets 100% of the role × endpoint × state × input × assertion coverage matrix across…
Audit env.local, SOPS .env, and config files for plaintext secret leaks, key age, missing rotation dates, and overlong-lived credentials.
Secret handling discipline. Env loading with fail-fast validation, log redaction at source, error-to-client hygiene, weak-hash detection, rotation runbooks, hashed-at-rest API…
Performs a white-box security review of Atlassian Forge apps using structured, Forge-specific security rules and evidence-driven reporting.
Security patterns for web forms including autocomplete attributes for password managers, CSRF protection, XSS prevention, and input sanitization.
Static security analysis of HTML forms without sending any requests. Checks for CSRF tokens, insecure actions, missing validation, hidden field issues, and common security…
Redrafts user-provided text into formal, binding legal language for contracts, policies, or codes of ethics.
Router for web form development. Use when creating forms, handling validation, user input, or data entry across React, Vue, or vanilla JavaScript.
Römisches Recht: Formularprozess. Geführter Fachmodul mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
Use when the user wants to check, understand, or harden the security of their Mac, or asks whether their laptop is secure and what to fix.
Triage whether a known CVE/GHSA vulnerability is actually exploitable in this project. Use when the user wants a reachability verdict on a specific advisory — is the project…
Expert in Gravito security and authentication. Trigger this when setting up Auth, configuring CSP, or implementing security middleware.
FortiOS VDOM segmentation audit with UTM profile binding validation, FortiGuard service health assessment, SD-WAN security evaluation, and HA cluster posture check.
Fortinet FortiSASE audit — Secure Web Gateway policy review, ZTNA application gateway assessment, thin edge FortiGate integration validation, SD-WAN security overlay analysis,…
Manage device tags for categorization, filtering, and visualization. Use when the user asks "tag all vulnerable devices", "mark devices that failed STIG checks", "create a tag for…
Prüft FOSS in Robotik: kommerzielle Bereitstellung, Hochrisiko-KI-Ausnahmen, SBOM, Lizenzen, Security und Haftungsallokation.
Fix FOSSA NOTICE file from failed MR pipeline. Downloads the updated NOTICE artifact from a GitLab CI fossa-check-notice job and commits it.
Pure mathematical structure. Sets, groups, rings, fields, topology — the formal bedrock everything else rests on.
Manages founder business portfolio, signals, vault, and snapshots. Tracks business health, stores credentials securely, and generates AI-powered business analytics and…
Decision validation and thinking frameworks for startup founders. Use when you need to pressure-test a decision, validate your next steps, think through strategic options, or…
> French capital gains, investment income, and equity compensation tax rules. Trigger on phrases like \"plus-values mobilières\", \"PFU\", \"flat tax\", \"prélèvement forfaitaire…
> French cryptocurrency and digital asset taxation for individuals. Trigger on phrases like \"crypto France impôt\", \"fiscalité crypto\", \"bitcoin impôt France\", \"ethereum…
> French tax audit procedures, penalties, and taxpayer rights (contrôle fiscal). Trigger on phrases like \"contrôle fiscal\", \"vérification de comptabilité\", \"redressement…
Apply Framer security best practices for secrets and access control. Use when securing API keys, implementing least privilege access, or auditing Framer security configuration.
Use when choosing, replacing, or justifying a framework, library, SDK, runtime, database, UI kit, or platform by fit: constraints, team skill, ecosystem maturity, migration cost,…
AOSP Part VII — Framework Services. Use when reasoning about PackageManagerService (install/uninstall, APK parsing, permissions, package visibility), ContentProviders (Co — from…
프레임워크와 언어의 소스코드 및 개발자 가이드를 직접 분석하여 메타적 보안 구조를 파악하는 스킬. Spring의 mass assignment, Java getHost()의 URL Confusion처럼 프레임워크/언어 설계상의 보안 함의를 소스코드 레벨에서 추출한다.
Use when you need to design, review, or improve REST APIs with Micronaut — including @Controller routes, HTTP status codes, DTOs, Bean Validation, exception handlers, pag — from…
Use when you need to design, review, or improve security in Micronaut applications — including micronaut-security authentication, @Secured and intercept-url-map rules, JW — from…
Use when you need to design, review, or improve REST APIs with Quarkus REST (Jakarta REST) — including resource classes, HTTP methods, status codes, request/response DTOs — from…
Use when you need to design, review, or improve security in Quarkus applications — including Quarkus Security with JWT/OIDC, basic auth, @RolesAllowed / @Authenticated / — from…
Use when you need to design, review, or improve validation in Quarkus applications — including Bean Validation on JAX-RS resources, @Valid on parameters and CDI beans, co — from…
Search all 10,533 Security skills →