Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 8

Claude Security Skills (Page 8 of 154)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

9,232 skills · updated 2026-07-31 · showing 421–480 of 9,232 by quality score

Sub-topics:Red Team (1,537)Web Security (961)Threat Hunting (627)Identity Access (441)Network Security (370)Appsec Tools (353)Forensics (243)Compliance (198)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Review an economics paper following Pedro Sant'Anna's writing style. Accepts a paper path and produces a structured editorial report covering abstract, introduction, terminology,…
Uruchamia pełny zestaw testów penetracyjnych Finora v2 — broken access control, SQL injection, rate limit bypass, XSS, ekspozycja danych, user enumeration, CSRF, misconfiguration.
Security review, hardening, and vulnerability scanning for Buildkite pipelines and self-hosted agents (CI/CD).
Pixa.com (eski Pixelcut) — Claude'a MCP-native baglanan yaratici AI araclari. Arka plan kaldir, gorsel olustur, kalite iyilestir, video olustur, nesne sil. API anahtari gerekmez.
Audit a project plan against the actual implementation — verifying code, types, security, and Supabase backend alignment.
Analyze agent extensions and generate self-contained HTML wiki reports with security audit and architecture diagrams. Use when asked to analyze, audit, or document a plugin.
Policy-diff veya gaps sonucunda bulunan boşluğu kapatmak için Türkçe/İngilizce iç politika üzerinde öneri redraft üretir.
Every Eventbrite organizer endpoint, plus a local SQLite mirror of your events, orders Trigger phrases: `sync my eventbrite events`, `which of my events are selling slowest`,…
Every Nylas API, plus a local SQLite mirror, cross-grant search, and confirm-by-hash sending no other Nylas tool has.
The first agent-native CLI for Pangolin — every endpoint, plus offline SQLite, cross-org audits Trigger phrases: `expose service through pangolin`, `back up pangolin config`,…
AI-powered PPT generation — 3 modes: FreeStyle (one-liner), Build Script (pixel-perfect), VI Build (enterprise template).
Critical security-focused PR review for GitHub Actions CI. Only posts feedback when issues are found. Prefers inline comments over summaries.
Verify all gates pass before merging a PR. Checks code review, user stories, QA, lint, build, and security audit.
Adversarial premortem for England & Wales civil litigation - builds the strongest version of a case, then attacks it from four angles to find where it loses before opposing…
Search for new preprints in infectious disease modelling from arXiv, medRxiv, and bioRxiv
ProductionOS — dual-target AI engineering operating system for repo-wide audits, upgrade plans, code reviews, strategic product reviews, security sweeps, UX audits, and recursive…
Run an OWASP LLM01 injection corpus against the system prompt + tool surface and report which payloads succeeded
Spec-driven manual QA testing and Playwright E2E code generation. Orchestrates browser skills to navigate apps like a human tester, producing structured test reports or…
Release 上線前的 QA 放行門(go/no-go gate)。彙整各方訊號——測試通過率、未關 P0/P1 bug、回歸結果、security/compliance/a11y/效能/離線各 gate 的 blocker 數、flaky 狀態、跨平台一致性——算出 readiness 分數,套 hard/soft gate 規則產出 go /…
Parallel QA using agent teams for comprehensive multi-type testing. Spawns specialized QA agents that simultaneously run different test categories (unit, integration, lint,…
Initialize a new project with qsdev. Detects ecosystem, generates security-hardened devenv configs, Claude Code settings, and pre-commit hooks.
Migrate off the Rancher-bundled `rancher-logging` chart (cattle-logging-system, rancher/mirrored-kube-logging-* images) to the upstream kube-logging logging-operator ≥6.7.0 —…
Pre-release audit orchestrator — runs advisory multi-domain audits (Security, Code Quality, UI/UX, Docs, Performance, Regulated-Data, Mobile, Infra) across the project, produces…
Emit the paste-ready command sequence to tag an RC, build artefacts, sign each artefact, generate checksums, and stage them to the adopter's distribution backend.
Security forensics for git repos, AI skills, and MCP servers. Audits dependencies, detects prompt injection, credential theft, runtime dynamism, manifest drift, known CVEs, CISA…
Resolve GitHub Dependabot security alerts by updating vulnerable dependencies, recompiling requirements, and submitting PRs.
Use when the user asks to see who is overbooked in Resource Guru, find who is on the bench, check a resource's day-by-day utilization, work out remaining capacity before booking a…
Platform-adaptive review orchestrator. Reviews the current change by running review-implementation (find → classify) AND invoking only the review skills that apply to this project…
Deep audit of a Rust crate for vulnerabilities, bugs, unfinished work, inconsistencies, duplicate code, and oversights. Works on the current crate or a specified path.
Fetch a Gerrit change by ID and run a structured code review using the gerrit-reviewer agent. Use when the user wants feedback on a Gerrit patch — code quality, security, project…
Use when code changes need review before merge - validates architecture, types, security, and test coverage.
Generate a Supabase Row-Level-Security policy bundle from an access-model description. Outputs SQL + test queries + admin-impersonation patterns.
Use when the user asks to triage their RocketCyber managed SOC, see what broke across clients overnight, rank devices at risk in Defender, compute incident MTTR for a QBR, trend…
Adversarial cross-family review of baton artifacts, PRs, and governance docs. Dispatches a non-Anthropic fleet model (cross-family invariant) and returns structured findings with…
Every Rootly incident, alert, and on-call object as a typed command, with a local SQLite mirror for offline analytics.
Use for tightly scoped Kerberos ticket and account validation during authorized pentests. Trigger on approved ticket analysis, Kerberos exposure review, and proving whether a…
Use when the user asks to inventory their runZero attack surface, triage which assets are most exposed, see what changed since the last sync, trace which assets a CVE affects,…
Run a full security-in-depth audit including OWASP Top 10, dependency analysis, and defense-in-depth review. Use for security audit, pentest review, or vulnerability assessment.
Find the newest version of a package that is free of known vulnerabilities, capped by a `--max-major-bump` policy.
**WORKFLOW SKILL** — Risk awareness before action. USE FOR: assessing risks (security, data integrity, compatibility, operational, reversibility) of any task at variable depth.
PainMap (painmap.io) platform help — an AI market-validation and product-research tool that runs parallel research across Reddit, X, G2, Capterra, and Trustpilot to mine real…
Pipedrive (pipedrive.com) platform help — pipeline-first sales CRM with deals, leads, persons/organizations, activities, automation, and reporting.
Redreach platform help — AI-powered Reddit lead generation with keyword auto-discovery, relevance scoring, Google-ranking post detection, AI reply suggestions, competitor…
Static application security testing (SAST) for changed source files — Vulnetix''s built-in rule set plus optional Semgrep augmentation when `.semgrep` config is present.
Security auditor for smart contracts - identifies vulnerabilities, logic flaws, reentrancy, access control issues, MEV/economic attacks, and oracle manipulation.
Ghost Security - SAST code scanner. Finds security vulnerabilities in source code by planning and executing targeted scans for issues like SQL injection, XSS, BOLA, BFLA, SSRF,…
Ghost Security - Software Composition Analysis (SCA) scanner. Scans dependency lockfiles for known vulnerabilities, identifies CVEs, and generates findings with severity levels…
Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary.
Hardcoded-secret detection — AWS keys, GitHub PATs, Slack tokens, Stripe keys, generic high-entropy strings. Pre-commit (`--staged-only`), explicit paths, or full repo.
Use this skill when the user reports API authentication or missing credential issues in an aide-managed project, or when you observe authentication failures (401, 403, missing API…
Proactive secure-coding coach scoped to the file or topic you are working on — surfaces relevant SAST rule IDs, CWE patterns, language-specific PASS/FAIL code snippets.
Triage a security scanner's multi-finding output (read via a pluggable scan-format adapter) and turn findings into security work only after a complete operator-reviewed triage.
Security-focused code review that emits a numeric composite score (0.0–1.0) suitable for the evolve-loop Builder self-review convergence loop
Quy tắc raw bắt buộc khi Claude Code thiết kế, viết, review hoặc kiểm thử bảo mật production cho frontend, backend, API, config, dependency và vận hành.
Scan codebase for security vulnerabilities, hardcoded secrets, injection flaws, misconfigurations, and attack surfaces.
Bootstrap OSS community health files — CONTRIBUTING.md, LICENSE, SECURITY.md, CODE_OF_CONDUCT.md, README sections (Getting Started, Badges), .github/PULL_REQUEST_TEMPLATE.md,…
Seed the SQLite database with project data from seed.json. Use 'reset' argument to drop and recreate tables first.
Use when the user asks to triage SentinelOne threats across client sites, trace a threat's blast radius, find dark/stale/under-protected agents, check protection-coverage gaps,…
Analyzes session and cookie security, including flags, expiration, fixation, and storage. Use when auditing session management and cookie configuration.
Use when the user asks to reconcile Sherweb billing, compute net margin per customer (receivable minus payable), find orphaned or under-billed subscriptions, catch metered usage…
Search all 9,232 Security skills →