Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 78

Claude Security Skills (Page 78 of 104)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

6,191 skills · updated 2026-06-16 · showing 4621–4680 of 6,191 by quality score

Sub-topics:Web Security (751)Threat Hunting (476)Red Team (453)Identity Access (329)Network Security (284)Appsec Tools (280)Compliance (159)Malware Analysis (138)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Expert in compliance frameworks (SOC2, ISO 27001), automated auditing, and risk management.
Specialista na autentizaci a autorizaci. MUSÍ být použit při analýze bezpečnosti kódu — hledá slabé hashování hesel (MD5/SHA1) a chybějící autorizační kontroly.
Базовая безопасность в реализации — валидация входных данных (Zod), secrets management, безопасные ошибки, auth/authz patterns, XSS/injection prevention, dependency audit, secure…
Security Benchmark Runner - Auto-activating skill for Security Advanced. Triggers on: security benchmark runner, security benchmark runner Part of the Security Advanced skill…
Implement security best practices for web applications and infrastructure. Use when securing APIs, preventing common vulnerabilities, or implementing security policies.
Master security blue team kql with comprehensive coverage of concepts, implementation, optimization, and production best practices.
Build a minimal but real security policy for sensitive apps. The output is a single, coherent Blue Book document using MUST/SHOULD/CAN language, with explicit assumptions — from…
Build a minimal but real security policy for sensitive apps. The output is a single, coherent Blue Book document using MUST/SHOULD/CAN language, with explicit assumptions — from…
中文优先:用于安全bountyhunter相关任务,帮助识别、设计、实现或验证对应工作流。English keywords: Hunt for exploitable, bounty-worthy security issues in repositories.
Führt Produktteam durch Security-by-Design: Bedrohungsmodell, Updatekanal, SBOM, Schwachstellenprozess, Logging und Notfallplan. — from Klotzkette/claude-fuer-deutsches-recht
Comprehensive AI-powered security scanning suite with 48 skills covering OWASP Top 10, 7 language-specific deep scanners (Go, TypeScript, Python, PHP, Rust, Java, C#), supply…
OWASP-based security checklist any agent can reference when reviewing or writing code
Przegląd bezpieczeństwa zmian w kodzie i konfiguracji.
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting…
Vérification de conformité sécurité incluant ISO 27001, SOC 2, HIPAA, NIST et audit trail. Se déclenche avec "ISO 27001", "SOC 2", "HIPAA", "NIST", "conformité sécurité", "audit…
You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards.
Performs advanced SAST (Static Application Security Testing) and compliance analysis on Pull Request diffs.
Shared reference for the security cluster: the trust-boundary model (untrusted input/action → privileged sink), the defend-vs-attack × code/config/runtime surface map, severity &…
Walk a security team member through allocating a CVE for an tracking issue. Prints the ASF Vulnogram allocation URL and a CVE-ready title (the issue title strip — from…
GitHub security alerts command center -- triage Dependabot, code scanning, and secret scanning alerts entirely from the editor.
Master security data encryption in use with comprehensive coverage of concepts, implementation, optimization, and production best practices.
Audit de sécurité des dépendances — détection de vulnérabilités connues, mises à jour critiques et gestion du cycle de vie des packages.
Drafts an irrevocable standby letter of credit securing a commercial lease deposit under ISP98 and UCC Article 5.
Design security controls and threat mitigations. Use for features involving auth, data, or external exposure.
Detect infrastructure and security-critical file changes to trigger security agent review recommendations ensuring proper security oversight for sensitive modifications.
Create security policies, guidelines, compliance documentation, and security best practices. Use when documenting security policies, compliance requirements, or security…
SEOcrawler security vulnerability scanner and hardening specialist for comprehensive security audits.
Implement security best practices across the application stack. Use when securing APIs, implementing authentication, preventing vulnerabilities, or conducting security reviews.
Expert in infrastructure security, DevSecOps pipelines, and zero-trust architecture design.
Curated bundle of essential security skills for building secure applications. Includes threat modeling, hardening guides, audit checklists, compliance frameworks, and contract…
Security specialist perspective for the weekly review. Focuses on XSS/CSRF, authorization boundaries, input validation, secrets handling, and dependency CVEs.
Security remediation en vulnerability fix skill. Past fixes toe voor kwetsbaarheden uit security check-rapporten.
Auto-invoke when reviewing authentication, authorization, input handling, data exposure, or any user-facing code. Enforces OWASP top 10 awareness and security-first thinking.
Verify security considerations were addressed before shipping. Issues result in WARNINGS that strongly recommend fixing.
Chief Information Security Officer (CISO) level GRC expertise. Governance, Risk, and Compliance for SaaS platforms.
Security Group Generator - Auto-activating skill for AWS Skills. Triggers on: security group generator, security group generator Part of the AWS Skills skill category.
Expert en sécurité applicative pour détecter les vulnérabilités, auditer le code, et guider les bonnes pratiques de sécurité.
Expert en sécurité applicative pour détecter les vulnérabilités, auditer le code, et guider les bonnes pratiques de sécurité.
Expert en sécurité applicative pour détecter les vulnérabilités, auditer le code, et guider les bonnes pratiques de sécurité.
Adversarial defense layer for the mortgage plugin — protects against prompt injection, system prompt extraction, PII leakage, workflow bypass, and social engineering attacks.
PreToolUse security-anti-pattern hook for Claude Code. Catches 12 common security risks (command injection, XSS, SQL injection, unsafe deserialization, GitHub Actions workflow…
OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation
Sécurisation d'agents IA contre injections, abus et fuites de données. Se déclenche avec "sécurité agent", "agent security", "prompt injection", "jailbreak", "agent abuse — from…
AIDefence security layer with prompt injection blocking, input validation, sandboxed execution, output sanitization, and STRIDE threat modeling.
Review code for application-level security hardening issues beyond framework checklists. Focuses on abuse prevention, API protection, business logic exploitation, rate limiting,…
Security headers and hardening for Next.js — CSP, CORS, rate limiting, CSRF protection, input sanitization, secrets management.
Configure HTTP security headers including CSP, HSTS, X-Frame-Options, and XSS protection. Use when hardening web applications against common attacks.
Security Headers Generator - Auto-activating skill for Security Fundamentals. Triggers on: security headers generator, security headers generator Part of the Security Fundamentals…
Use when running, interpreting, or acting on Salesforce Security Health Check results — reading the score, understanding risk categories, evaluating specific settings, creating or…
Sets up Claude Code security hooks — protective PreToolUse guards that block sensitive file access, dangerous commands, destructive git ops, system path writes, network calls, and…
Comprehensive security patterns for authentication, authorization, input validation, and common vulnerability prevention
When to use: active or suspected Salesforce org compromise, unauthorized access investigation, attacker containment, forensic evidence collection from EventLogFile/LoginHistory,…
Plan de réponse aux incidents de sécurité — préparation, détection, containment, éradication, recovery et lessons learned.
Security Incident Shop Datenschutzmeldung: prüft die einschlägigen Voraussetzungen, Dokumente, Risiken und Ausnahmen.
Klausel-Spezialskill für Security Incidents: prüft, redlined und entwirft die Klausel mit Risikoampel, Verbraucher-/B2B-Unterscheidung und praxistauglicher Ersatzfassung.
Master security ioc enrichment with comprehensive coverage of concepts, implementation, optimization, and production best practices.
Merge two tracking issues that describe the same root-cause vulnerability (typically discovered independently by two reporters, arriving via different channels) — from…
Attempt to fix a security issue tracked in by implementing the change in a public PR.
Scan for reports that have not yet been copied into as tracking issues, present the proposed imports to the user, and — defaulting to *import un — from…
Open one or more `` tracking issues from a markdown file containing a batch of security findings (typically the output of an AI security review or a third-party — from…
Search all 6,191 Security skills →