Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 8

Claude Security Skills (Page 8 of 176)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

10,533 skills · updated 2026-08-26 · showing 421–480 of 10,533 by quality score

Sub-topics:Red Team (1,582)Web Security (1,094)Threat Hunting (754)Identity Access (496)Network Security (414)Appsec Tools (381)Forensics (295)Malware Analysis (207)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Configure and operate the kube-logging logging-operator (formerly Banzai Cloud) on Kubernetes — the CRD-driven log pipeline: Fluent Bit collector → fluentd or syslog-ng aggregator…
Analyze a PR for LVMS (LVM Storage) security threats with STRIDE/DFD analysis, MITRE ATT&CK and OWASP mapping
Strategic analysis of a project to identify the single highest-leverage, most innovative addition. Use when the user asks what to build next, what the most impactful improvement…
Android APK analysis using GDA.exe. AI drives analysis by tracing code paths, extracting IOCs (including encrypted), and producing structured malware reports.
Inspects and configures the web application firewall (WAF) in front of a Power Pages production site.
Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie…
Proactieve weekly management-sweep — draait alle 5 manager-agents (SEO, indexering, security, performance, content) parallel over de LIVE shop + codebase en levert één…
Open, local revenue-intelligence CLI for Maxio Advanced Billing - MRR waterfalls, retention, and per-client history computed offline from a SQLite mirror, so the trended history…
Use when the user asks to find wasted Microsoft 365 licenses, see who holds global admin or other privileged roles, triage new Microsoft Defender security alerts, flag…
Manage and interact with MisarDefender — the local macOS security daemon. Use when: checking security daemon status, viewing security events, starting/stopping defender, scanning…
Use when working with mise (mise-en-place) or planning to update mise.toml. If the project use mise consult it even for one-line edits to mise.toml/hk.pkl, hooks, or CI tool…
Score durability across 7 moat types (network, switching, scale, brand, IP, data, regulatory) with 0–10 per moat + decay-rate forecast. Routes to red-team-strategist.
Wykryj komendy lint i testow biezacego projektu i zapisz je jako strone wiki 'toolchain' w Monolynx. Jednorazowa konfiguracja per projekt - skille work i work-simple czyt — from…
Use when: structuring a multi-lens review of a change, spec, design, or implementation; combining intent, design, implementation, security, adversarial, and verification…
Use when the user asks to find a device in N-able N-central, run the morning NOC triage sweep, search across N-central servers, audit custom-property or maintenance-window…
Use when the user asks to audit autoscale across all their Nerdio Manager customers, sweep session-host power state, reconcile per-customer billing and usage, list customer…
Given an open good-first-issue on the configured `` repo, explain it in beginner terms and sketch a concrete approach: which files to read first, what "done" looks like,…
Every NinjaOne report, plus a local store that answers fleet-wide questions no single API call can: patch compliance, backup gaps, AV blast-radius, health, drift.
Use when drafting, editing, or reviewing chapters of The Old Songs of Aevoria narrative fiction series.
Connect Google (GTM, GA4, Google Ads) and Meta Ads to ppc-manager via OAuth. Walks through Google Cloud Console and Meta app setup, runs browser-based OAuth, and stores encrypted…
Answer a newcomer's "how do I contribute here" question by grounding the response in `CONTRIBUTING.md` and the project's own docs.
Generate `op://` secret references for every field on a 1Password item. Output is ready to paste into a `.env` template.
Użyj tego skilla do wieloźródłowego researchu w sieci: wyszukiwania jednego lub wielu tematów, pobierania wielu stron przez fetchWebContent i zapisywania oczyszczonych plików…
OpenAI Agents SDK (Python) development. Use when building AI agents, multi-agent handoffs, function tools, guardrails, sessions, streaming, or tracing with the `openai-agents` /…
Analyze affected packages and version ranges in OSV vulnerability records. Triggers on mentions of affected packages, version ranges, impacted ecosystems, package vulnerability…
Filter OSV vulnerability data by ecosystem, reference type, or alias pattern. Triggers on mentions of filtering vulnerabilities by package ecosystem (npm, PyPI, Maven), reference…
Parse an OSV (Open Source Vulnerability) JSON file and display structured vulnerability data. Triggers on mentions of OSV parsing, vulnerability JSON reading, CVE/GHSA data…
Extract specific sub-information from OSV vulnerability data — severity details (CVSS v2/v3), Maven package decomposition, version ranges, or event timelines.
Analyze CVSS severity data from OSV vulnerability records. Triggers on mentions of CVSS scores, vulnerability severity assessment, risk rating, or when user needs to evaluate the…
Validate OSV (Open Source Vulnerability) JSON files against the schema. Triggers on mentions of OSV validation, vulnerability format checking, schema compliance, or when user…
Use when the user asks for news, wants a briefing, says "/news-briefing", or asks to aggregate recent information on any topic.
Pack an EXTERNAL repository into a single AI-friendly file (markdown/xml/json). Use for third-party library analysis, security audits, or handoff to external LLMs.
Fan a local diff through three independent, axis-focused review passes (correctness, security, conventions), then merge the findings into a single structured report.
Run a structured pre-flight self-review on local changes before opening a PR. Reads the diff against a configurable base (default: the merge base of HEAD and the upstream default…
Use Pawahara Harness for difficult coding, CTF, competitive programming, debugging, optimization, or long-running tasks that benefit from diverse beam-search workers, scoring,…
Use when the user asks to reconcile Pax8 billing, find invoice leakage, compute Pax8 MRR and margin, catch usage overages before they invoice, see what changed in their book of…
Comprehensive 9-point audit of a Power BI PBIP project covering relationships, naming conventions, TMDL syntax, best practices, RLS security, performance, visual consistency,…
Pure-Python PDF toolkit with 50 commands covering reading, editing, conversion, forms, encryption, OCR, and IR.
Review an economics paper following Pedro Sant'Anna's writing style. Accepts a paper path and produces a structured editorial report covering abstract, introduction, terminology,…
Uruchamia pełny zestaw testów penetracyjnych Finora v2 — broken access control, SQL injection, rate limit bypass, XSS, ekspozycja danych, user enumeration, CSRF, misconfiguration.
Security review, hardening, and vulnerability scanning for Buildkite pipelines and self-hosted agents (CI/CD).
Pixa.com (eski Pixelcut) — Claude'a MCP-native baglanan yaratici AI araclari. Arka plan kaldir, gorsel olustur, kalite iyilestir, video olustur, nesne sil. API anahtari gerekmez.
Audit a project plan against the actual implementation — verifying code, types, security, and Supabase backend alignment.
Analyze agent extensions and generate self-contained HTML wiki reports with security audit and architecture diagrams. Use when asked to analyze, audit, or document a plugin.
Policy-diff veya gaps sonucunda bulunan boşluğu kapatmak için Türkçe/İngilizce iç politika üzerinde öneri redraft üretir.
Every Eventbrite organizer endpoint, plus a local SQLite mirror of your events, orders Trigger phrases: `sync my eventbrite events`, `which of my events are selling slowest`,…
Every Nylas API, plus a local SQLite mirror, cross-grant search, and confirm-by-hash sending no other Nylas tool has.
The first agent-native CLI for Pangolin — every endpoint, plus offline SQLite, cross-org audits Trigger phrases: `expose service through pangolin`, `back up pangolin config`,…
AI-powered PPT generation — 3 modes: FreeStyle (one-liner), Build Script (pixel-perfect), VI Build (enterprise template).
Critical security-focused PR review for GitHub Actions CI. Only posts feedback when issues are found. Prefers inline comments over summaries.
Verify all gates pass before merging a PR. Checks code review, user stories, QA, lint, build, and security audit.
Adversarial premortem for England & Wales civil litigation - builds the strongest version of a case, then attacks it from four angles to find where it loses before opposing…
Search for new preprints in infectious disease modelling from arXiv, medRxiv, and bioRxiv
ProductionOS — dual-target AI engineering operating system for repo-wide audits, upgrade plans, code reviews, strategic product reviews, security sweeps, UX audits, and recursive…
Wykryj komendy lint i testow biezacego projektu i zapisz je jako strone wiki 'toolchain' w Monolynx. Jednorazowa konfiguracja per projekt - skille work i work-simple czyt — from…
Run an OWASP LLM01 injection corpus against the system prompt + tool surface and report which payloads succeeded
Spec-driven manual QA testing and Playwright E2E code generation. Orchestrates browser skills to navigate apps like a human tester, producing structured test reports or…
Release 上線前的 QA 放行門(go/no-go gate)。彙整各方訊號——測試通過率、未關 P0/P1 bug、回歸結果、security/compliance/a11y/效能/離線各 gate 的 blocker 數、flaky 狀態、跨平台一致性——算出 readiness 分數,套 hard/soft gate 規則產出 go /…
Parallel QA using agent teams for comprehensive multi-type testing. Spawns specialized QA agents that simultaneously run different test categories (unit, integration, lint,…
Initialize a new project with qsdev. Detects ecosystem, generates security-hardened devenv configs, Claude Code settings, and pre-commit hooks.
Search all 10,533 Security skills →