Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 71

Claude Security Skills (Page 71 of 176)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

10,533 skills · updated 2026-08-26 · showing 4201–4260 of 10,533 by quality score

Sub-topics:Red Team (1,582)Web Security (1,094)Threat Hunting (754)Identity Access (496)Network Security (414)Appsec Tools (381)Forensics (295)Malware Analysis (207)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Configures GKE edge networking, traffic routing, load balancing, and private service endpoints. Use when configuring Gateway API manifests, standard Ingress, Cloud Armor WAF…
Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces.
Elite U.S. corporate + commercial-litigation lawyer persona with a Florida specialty. Use for: reviewing/ drafting loan, financing, secured-lending, M&A and entity-governance…
Elite FBI/forensic-investigator + financial-crimes (Fintech) division case-builder. Connects dots across large evidence sets (chats, bank records, PDFs, contracts), uncovers…
Import Goods & Customs Compliance researcher — determines the legal, customs, tariff, duty, documentation, and process requirements to import goods into the United States.
GLAW 409A valuation orchestrator for audit-ready DRAFT work-product. Validates intake, runs DCF, market comps, VC method, PWERM, latest priced-round anchor, liquidation waterfall…
Adversarial RED-team for a 409A/IP valuation memo — a relentless IRS valuation examiner + audit-defense appraiser who attacks every input, method, and number to DESTROY the FMV…
GLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement,…
Token security: Indexing tokens have write access -- never expose in frontend. Trigger: "glean security basics", "security-basics".
Scan prompts for prompt injection attacks before sending them to any LLM. Detect jailbreaks, data exfiltration, encoding bypass, multilingual attacks, and 25+ attack cate — from…
Scan prompts for prompt injection attacks before sending them to any LLM. Detect jailbreaks, data exfiltration, encoding bypass, multilingual attacks, and 25+ attack cate — from…
Römisches Recht: Glossatoren Und Kommentatoren. Geführter Fachmodul mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
Gmail Inbox Zero Triage - Interactive inbox management using gog CLI with Telegram buttons. Use when the user wants to achieve inbox zero, triage their Gmail inbox interactively,…
Use when configuring or troubleshooting Gmail access for this plugin — checking that the .env credentials exist and IMAP login works.
Go API development guidelines using the standard library (1.22+) with best practices for RESTful API design, error handling, and security
Continuous integration for Go projects: GitHub Actions pipelines, caching, golangci-lint setup, test/coverage gates, vulnerability scanning, build matrices, and Makefile targets.
Apply Go project conventions — Go 1.25.x toolchain pinned via toolchain directive and GOTOOLCHAIN=local, vendored deps via go mod vendor, golangci-lint v2 strict (~50 enabled…
Database patterns for Go services: database/sql, connection management, transactions, migrations, query builders, and ORM usage (sqlc, GORM, ent).
Prevent panics, silent corruption, and subtle runtime bugs in Go: typed-nil interfaces, slice aliasing, integer overflow on conversion, float comparison, defer in loops, defensive…
Audit Go module dependencies: detect outdated packages, check for known vulnerabilities, review go.mod hygiene, identify unused or redundant deps, and evaluate dependency quality.
Run a grouped, bisectable Go dependency security sweep on the Fission repo. Use when the user asks to upgrade outdated/vulnerable Go dependencies, run a dep security pass, or…
Echo (LabStack) — Go Web framework リファレンス。routing(Group)、echo.Context、 Bind、Validator、HTTPError、HTTPErrorHandler、middleware(JWT, CORS, CSRF, BasicAuth, Gzip, Recover, Logger,…
Use for Go payment-data governance, tokenization, audit, retention, and PCI. Do not use for generic exploits or certification.
gRPC services in Go beyond the basics: proto design, status codes and error details, interceptors, deadlines, streaming, health checks, and graceful shutdown.
Release engineering for Go projects — GoReleaser v2 with version ldflags into an internal/version package, SBOMs and multi-arch container images, tag-triggered GitHub Actions…
Pre-release Go checklist for services, libraries, and CLIs (tests + race + lint + govulncheck + allowed-modules + TDD ceremony + CHANGELOG + API docs).
Orchestrate a comprehensive Go code review by triaging code changes, dispatching vertical review skills (security, concurrency, error, logic, performance, quality, test,…
Security review for Go applications: input validation, SQL injection, authentication/authorization, secrets management, TLS, OWASP Top 10, and secure coding patterns.
Use for generic Go exploit prevention: authz, SSRF, files, commands, crypto, secrets, and supply chain. Do not use for PCI scope.
Review Go code for security vulnerabilities including OWASP Top 10, injection, auth/authz, crypto, secrets, SSRF, XSS, and input validation.
Identify, assess, and fix security vulnerabilities in Go modules using govulncheck。Handle common。Use when 需要安全检测、合规审计、漏洞扫描、加密防护时使用。不适用于渗透测试未授权目标。适用于独立开发者、企业团队和自动化工作流场景。
使用 govulncheck 识别 Go 模块安全漏洞的基础能力,覆盖漏洞扫描、风险评级与基础修复建议。Use when 需要安全检测、合规审计、漏洞扫描、加密防护时使用。不适用于渗透测试未授权目标。适用于独立开发者、企业团队和自动化工作流场景。支持中文交互,无需复杂配置即开即用。输出结果可直接使用,减少二次加工成本。
Go coding standards, clean code, and security rules. Use when writing, reviewing, or refactoring Go code.
Use when: setting up Go modules/workspaces, configuring golangci-lint v2, scanning dependencies with govulncheck, modernizing code with go fix, or building a Go CI quality gate.
Validate Go formatting, linting, tests, and vulnerabilities for maintainable and secure code delivery.
Reference for what changed in Go 1.27 — use when writing or reviewing Go code in a `go 1.27`+ module so you do not fall back on pre-1.27 training-data assumptions.
Prüft entgegenstehenden Willen, öffentliches Interesse, Unterhaltspflichten und Schadensersatz bei aufgedrängter Hilfe.
Römisches Recht: Goa Vergleich. Geführter Fachmodul mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
GOAD (Game of Active Directory) lab environment — AWS-based Active Directory pentest lab with 1 Ubuntu jumpbox and 5 Windows Server VMs (2 forests, 3 domains).
God-level cloud security skill covering CSPM (Cloud Security Posture Management), CWPP (Cloud Workload Protection), CIEM (Cloud Infrastructure Entitlement Management), AWS-native…
Jailbreak API-served LLMs using G0DM0D3 techniques — Parseltongue input obfuscation (33 techniques), GODMODE CLASSIC system prompt templates, ULTRAPLINIAN multi-model racing,…
Wires Godot combat with Area2D Hitbox/Hurtbox, DamageData, HealthComponent, combo windows, ability cooldowns, i-frames, and damage popups.
Persists Godot 4.7+ game state with FileAccess JSON or store_var, user:// slots, PERSIST-group snapshots, schema versioning, AES-encrypted files, and SHA-256 integrity.
Google Workspace CLI for Gmail, Calendar, and Auth (restricted via security wrapper).
Wirtschaftsprüfer: going concern warnsignale - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik, Verhältnismäßigkeit,…
Security best practices and vulnerability prevention for Golang. Covers injection (SQL, command, XSS), cryptography, filesystem safety, network security, cookies, secrets…
Deterministic entropy streams for reproducible testing and procedural generation. Perfect 50/50 statistical distribution with hash verification.
Step-by-step guide for setting up Google Calendar MCP server in Claude Code CLI. Use when users want to (1) connect Google Calendar to Claude Code, (2) set up the…
Provides expert guidance on authenticating and authorizing to Google Cloud services and APIs, covering human users, service identities, Application Default Credentials (A — from…
Guides agents through a structured 6-step discovery process to design and deploy Google Cloud global external Application Load Balancers with Cloud CDN, Cloud Armor, and Service…
Investigates Google Cloud networking issues by analyzing logs, metrics, and diagnostics. Use when investigating VPC Flow Logs, NAT, firewall, or threat logs, querying lat — from…
Provides expert guidance on authenticating and authorizing to Google Cloud services and APIs, covering human users, service identities, Application Default Credentials (A — from…
Deploys a baseline landing zone foundation for a Google Cloud Organization, establishing security guardrails using Organization Policies, resource hierarchy folders and projects,…
Investigates Google Cloud networking issues by analyzing logs, metrics, and diagnostics. Use when investigating VPC Flow Logs, NAT, firewall, or threat logs, querying lat — from…
Google Cloud Secret Manager conventions for JavaScript and TypeScript - @google-cloud/secret-manager setup, ADC/IAM, access/create/rotate/list/delete secrets, version pinning, and…
Stores, retrieves, and manages data as objects in Cloud Storage (Google Cloud Storage, or GCS) buckets.
Connect to Google Workspace services (Gmail, Docs, Sheets, Calendar, Drive, Tasks, Slides). Load when user mentions 'connect google', 'setup google', 'configure google', 'google…
Use for Google Maps Platform Environment APIs work, including Air Quality API, Pollen API, Solar API, Weather API, environmental heatmap tiles, current/forecast/history requests,…
Use for focused Google Maps JavaScript API 2D map work in either app, including API loading, map IDs/vector maps, camera, controls, Advanced Markers, info windows, data-driven…
Complete Google OAuth integration architecture including token storage and debugging
Search all 10,533 Security skills →