Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 68

Claude Security Skills (Page 68 of 176)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

10,533 skills · updated 2026-08-26 · showing 4021–4080 of 10,533 by quality score

Sub-topics:Red Team (1,582)Web Security (1,094)Threat Hunting (754)Identity Access (496)Network Security (414)Appsec Tools (381)Forensics (295)Malware Analysis (207)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Review frontend code for accessibility, UI security, missing states, and UX regressions. Use when asked to review React components, run a pre-merge frontend review, or check a11y…
Audit frontend codebases for security vulnerabilities and bad practices. Use when performing security reviews, auditing code for XSS/CSRF/DOM vulnerabilities, checking Content…
Secure Solana frontends against phishing, bad prompts, and unsafe signing requests. Use for audits of wallet UX and dApp sites.
Expert in secure frontend coding practices specializing in XSS prevention, output sanitization, and client-side security patterns.
Produce a staff-grade frontend system-design RFC for the active task: a 12-section design document (problem, requirements, architecture, data model, API and interface contract,…
Patentanwälte: fruehe veroeffentlichung konferenz - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit,…
Use when revising an ESEC/FSE paper for a practitioner-grounded software-engineering contribution on the first page, research-question contracts, a threats-to-validity section…
Implement data persistence using SQLite with Dapper, JSON files, or event sourcing. Use when: "database", "save data", "store", "CRUD", "create table", "query", "SQL", "SQLite",…
Import any CSV stream into a Fulcra account as annotations — body weight, mood scores, expenses, sleep, media plays, anything timestamped.
Orchestrate a full non-mutating app or repo review across architecture, live flows, frontend quality, testing and coverage, security, observability and error instrumentation,…
Triggered when the user submits code or requests a comprehensive code quality analysis. Automatically performs static analysis, code review, and quality scoring.
ใช้สกิลนี้เมื่อต้องออกแบบ พัฒนา แก้บั๊ก รีแฟกเตอร์ หรือรีวิวโค้ด Web Application แบบ Full Stack บน stack React + TypeScript + Vite + Bun + Hono + PostgreSQL…
Master-level fullstack software engineering with deep backend expertise. Use when building production-grade APIs, database architectures, authentication systems, microservices, or…
Builds security-focused full-stack web applications by implementing integrated frontend and backend components with layered security at every level.
Builds security-focused full-stack web applications by implementing integrated frontend and backend components with layered security at every level.
Design and review caller-facing names and contracts: functions, tools, commands, CLI flags, parameters, config keys, env vars, profiles, event types, and node/edge identifiers.
Prüft Subscription Line, NAV Facility, GP Commitment, LP Capital Call Security und Borrowing Limits im Private Equity Praxis.
Real-time funding rate data MCP across Binance, OKX, Bybit, and other major crypto exchanges.
Trigger FA_STANDARD flag detected (protocol uses FungibleAsset standard) - Used by Breadth agents, depth-token-flow
Prüft Funkmodule, WLAN, 5G, Bluetooth, RED, EMV, Cybersecurity und Betriebsumgebung.
Parse, modify, encode, decode, and deduplicate URLs from the command line. Use when the user needs to extract URL components, manipulate URLs, encode/decode URL strings, or…
Sets up dynamic security testing — coverage-guided fuzzing of parsers and input handlers (libFuzzer/cargo-fuzz/AFL++/go test -fuzz/atheris) and DAST scanning of a running app…
Advanced fuzzing techniques for finding zero-days and hidden vulnerabilities. Use when automated scanners miss
Essential fuzzing payloads: SQL injection, command injection, special characters. Curated essentials for vulnerability testing.
Configure perform API fuzzing to discover edge cases, crashes, and security vulnerabilities. Use when performing specialized testing.
Configure perform API fuzzing to discover edge cases, crashes, and security vulnerabilities. Use when performing specialized testing.
Building effective fuzzing harnesses to maximize code coverage and vulnerability discovery through automated input generation
GA4 user access management, permission audits, and cross-property security. Triggers: ga4 users, add user, remove user, permissions, access audit, role management, user migration.
Configure auth for the GA4 Data API — OAuth user credentials for interactive use, or a service account for automation / CI.
Analyze in-game economy systems including soft and hard currency source-sink balance, inflation projection modeling, loot table drop rate fairness and pity system evaluation,…
Pre-launch quality gate for games: audit rendering and memory performance against platform budgets, run QA for crash-causing defects and platform certification blockers, review…
Audits existing game code against design principles — checks server-authority, schema conventions, auth security, payment safety, narrative coherence, and MVP scope drift.
Game-specific security review covering cheat prevention, exploit surfaces, and server authority. Audits client-side authority vulnerabilities (damage, health, currency, cooldown,…
面向加密协议的博弈论分析框架(免费版). 基于Five Questions分析模型,覆盖Nash Equilibrium、Dominant Strategy等核心概念, 支持基础Common Crypto Games识别与Red Flags检测. 免费版不含高级分析能力(Repeated Games、Bayesian Games等)与外部工具集成.
Implement security best practices for Gamma integration. Use when securing API keys, implementing access controls, or auditing Gamma security configuration.
Plays Gandalf, a Capture The Flag prompt security game by Lakera. Extracts guarded secret passwords from AI defenders across 8 levels of increasing difficulty.
DB 조회/분석 지원. gandy 쿼리, .gandy 설정, 데이터 수집/분석 워크플로우. Use when querying databases, writing gandy queries, setting up .gandy project config, collecting or analyzing DB data, exploring…
Onboard company employees (Claude Code CLI users) to use gapless-crypto-clickhouse package with ClickHouse Cloud credentials.
Garden design and layout planning for gardeners. Plan your garden with companion planting, spacing, and sun requirements.
Run a Claude Code powered security review pass on trusted pull requests so suspicious auth, secret, injection, and unsafe logic changes surface before merge.
The drum sounds. Spider and Raccoon gather for complete security work. Use when implementing auth or auditing security end-to-end.
Configure the GrowthBook plugin's API credentials so every other skill can run. Use when the user says "set up growthbook", "configure my api key", "growthbook isn't working",…
gc-vault でラップされた GCP プロジェクトに対して gcloud / gcloud storage / bq / terraform 等のコマンドを実行する際に使用する。直接の gcloud auth login やローカル credentials に頼らず、1Password に保管された bootstrap SA…
Interact with the Calendar Bridge — a self-hosted Node.js service that provides a persistent REST API for Google Calendar events.
Reads and creates calendar events via the Google Calendar API. Used by calendar-agent for weekly agenda generation, focus time block analysis, multi-calendar event aggregation,…
Container-adapted Google Cloud CLI authentication. Supports service account key files, application default credentials, and browser login for headless environments.
Audit and govern Cloud KMS key lifecycles, Secret Manager secrets, CMEK configurations across GCP services (Cloud SQL, BigQuery, GCS, Compute), key rotation schedules, and…
Review GCP security posture via Security Command Center findings, CIS GCP Benchmark gaps, org policy enforcement baseline, Assured Workloads controls, Binary Authorization, and…
Evaluate GCP workload security posture against the Google Cloud Well-Architected Framework security pillar — covering zero trust, shift-left security, preemptive cyber defense, AI…
Internal fetcher module for Google Docs and Sheets. Fetches content via MCP (preferred, when available), Google API with bearer token or public URL export (fallback), or browser…
Expert skill for creating, formatting, and maintaining security audit reports in Google Docs via the Docs API.
Elite incident response and legal compliance guidance for data breaches under GDPR Articles 33 & 34. Use when: (1) User reports a data breach or security incident, (2) User asks…
Guides a comprehensive organisational data protection audit against key GDPR requirements including Articles 5, 24, 25, 28, 30, 32, 35, and 37.
Gdpr Compliance Scanner - Auto-activating skill for Security Advanced. Triggers on: gdpr compliance scanner, gdpr compliance scanner Part of the Security Advanced skill category.
Reads and writes document scans and records files to configured Google Drive folders via the Drive API.
Patentanwälte: gebuehren und kostentransparenz - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit,…
Anwälte: gebuehrenunterschreitung und pro bono - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit,…
Use when building the conceptual or analytical framework for a Global Environmental Change (GEC) manuscript.
GeckoTerminal API - DeFi and DEX aggregator providing real-time cryptocurrency prices, trading volumes, OHLCV charts, and liquidity data across 250+ blockchain networks and 1,800+…
结对编程搭档。当用户要求"边写边审"、"结对编程"、"写完自己 review 一遍"、"高可靠地实现",或明确希望代码交付时附带自我审查意见时使用。交付代码的同时输出结构化审查(正确性/安全/性能/可读性/健壮性五维度),重点捕捉 AI 生成代码的特有缺陷。不用于:对已有 PR 的正式评审(用 code review 流程)、安全专项扫描(用…
Search all 10,533 Security skills →