Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Page 83

Claude Security Skills (Page 83 of 176)

Security auditing, penetration testing, vulnerability scanning, OWASP, cloud security, and compliance skills for Claude Code.

10,533 skills · updated 2026-08-26 · showing 4921–4980 of 10,533 by quality score

Sub-topics:Red Team (1,582)Web Security (1,094)Threat Hunting (754)Identity Access (496)Network Security (414)Appsec Tools (381)Forensics (295)Malware Analysis (207)

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use for ISMS design, security risk assessment, control implementation, ISO 27001…
Drafts a board-approvable Information Security Policy covering data classification, access controls, encryption, incident response, breach notification, and enforcement.
Information security strategy, risk management, security program governance, and compliance framework integration
Prüft IT-Sicherheit, Forschungsdaten, Ransomware, Hochschul-CERT und Verantwortlichkeiten im Hochschulrecht Länder.
Detects and removes infostealer malware (credential stealers, data exfiltrators) via full-system file search, cryptographic hashing, and public threat-intelligence cross-checks…
Manage infrastructure for local development. Subcommands: docker, terraform, db. Covers container orchestration with Colima awareness, IaC workflows with safety gates, and…
Use this agent when you need to audit domain security posture, configure DNS records, or manage Cloudflare security features (WAF, Workers, Zero Trust) via the Cloudflare MCP…
WHEN: Infrastructure security audit, secrets management, network policies, compliance checks WHAT: Secrets scanning + Network policies + IAM/RBAC audit + Compliance validation +…
OWASP Infrastructure Top 10 vulnerability knowledge base for identifying, assessing, and remediating security risks in internal IT infrastructure environments.
Erzeugt präzise Rückfragen an Technik, QM, Datenschutz, IT-Security, Vertrieb und Service, damit das Recht nicht im Nebel prüft. — from Klotzkette/claude-fuer-deutsches-recht
When Igor pastes ANY credential (password, API key, token, client secret) in chat, immediately ingest it into macOS Keychain, confirm service+account only, never refuse with…
Use when gaining initial access to a target — phishing, payload delivery, HTML smuggling, ISO/IMG/MOTW bypass, supply-chain, credential stuffing, exposed-service exploitation
Römisches Recht: Iniuria Persoenlichkeitsverletzung. Geführter Fachmodul mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
Materialize age or PGP encrypted SOPS secrets inside declarative NixOS and Home Manager systems during activation without hand-copying values.
Injection vulnerability testing - SQL, NoSQL, OS Command, SSTI, XXE, and LDAP/XPath injection techniques.
Hunt for injection vulnerabilities including SQL injection, command injection, XSS, SSTI, path traversal, LDAP injection, and other input validation flaws.
Revisão de segurança em nível de código-fonte focada exclusivamente em vetores de injeção e técnicas de bypass de sanitização.
Spot prompt-injection in untrusted content before an agent acts on it — the anatomy of injected instructions across the channels attackers use (email, web, files, tool outputs,…
Validate NoSQL injection vulnerabilities across MongoDB, Cassandra, CouchDB, Redis, and other NoSQL databases.
Auditoria de injecoes, XSS, CSRF e headers de seguranca para qualquer stack — queries parametrizadas/ORM, escaping por contexto (HTML/atributo/URL/JS/CSS), tokens CSRF, validacao…
Use when adding cross-cutting concerns to durable functions — structured logging or tracing across all functions, error tracking with Sentry, payload encryption for sensitive…
Römisches Recht: Innominatkontrakte. Geführter Fachmodul mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
Scan untrusted external text (web pages, tweets, search results, API responses) for prompt injection attacks. Returns severity levels and alerts on dangerous content.
Эксперт по санитизации ввода. Используй для XSS prevention, encoding, validation и security headers.
Input Validation Checker - Auto-activating skill for Security Fundamentals. Triggers on: input validation checker, input validation checker Part of the Security Fundamentals skill…
Identifies and fixes XSS, SQL injection, and command injection vulnerabilities with validation schemas, sanitization libraries, and safe coding patterns.
Webアプリケーションにおける包括的な入力検証とサニタイズ。型安全な検証、許可リストフィルタリング、 コンテキスト対応エンコーディングを通じて、XSS、SQLインジェクション、コマンドインジェクション、 パストラバーサルなどの入力ベースの攻撃を防止。
Findet Schwachstellen in Insidervermerk, Aufschubakte, Insiderliste, Ad-hoc-Entwurf und Handelsfreigabe.
Spezialskill Insiderrecht fuer Short Seller Attack: MAR-Pruefung, Ad-hoc, Aufschub, Insiderliste, Handelsverbot, Beweis- und Kommunikationsspur.
Insecure Deserialization Checker - Auto-activating skill for Security Fundamentals. Triggers on: insecure deserialization checker, insecure deserialization checker Part of the…
Database schema patterns for InsForge including social graphs, e-commerce, content publishing, and multi-tenancy with RLS policies.
Use when the user mentions infrastructure, cloud, AWS, GCP, Terraform, deployment, DevOps, containers, Kubernetes, serverless, VPC, networking, databases, load balancers, CDN,…
Prüft syndizierte LMA-Finanzierung in Insolvenz/StaRUG: Facility Agent, Security Agent, Majority Lenders, Waiver, Standstill, Acceleration und Forderungsanmeldung im…
Insolvenzrechtliche: Erstprüfung, Rollenklärung und Mandatsziel im Insolvenzrecht: fachlich vertieftes Modul mit Normenradar (InsO/StaRUG/GesR), Tatbestands-/Beweislastmatrix,…
Inspect Apple application bundles, extensions, frameworks, dylibs, static archives, XCFrameworks, IPA files, Mach-O executables, dSYMs, crash artifacts, dyld caches, kernel…
Check ELF or PE binaries for hardening gaps like NX, PIE, RELRO, stack canaries, and Fortify before release or incident review.
Correlate suspicious macOS process, file, network, permission, and log activity. Use for unexpected processes, child execution, downloads, open files, DNS/connections, privacy…
Inspects a Linux container or sandbox environment and produces a structured HTML report covering filesystem mounts, process security context, and network configuration.
Add a large source-backed cybersecurity skills library to Claude Code, Codex CLI, Cursor, Gemini CLI, and other agents so security investigations follow structured analyst…
Install a department's slice of the company brain via multi-agent probes of the head's connected tools (Notion, HubSpot, Linear, Slack, Granola, Gmail, etc., via Syroco Connect /…
Usa esta skill SIEMPRE antes de añadir, actualizar o eliminar cualquier dependencia en un proyecto Node.js. Aplica a frontend, backend y monorepo.
Install VT Sentinel security plugin. Use when the user asks to install, set up, or enable VT Sentinel, VirusTotal scanning, malware protection, or file security scanning.
Set up Instantly.ai API v2 authentication and project configuration. Use when creating a new Instantly integration, generating API keys, or configuring environment variables for…
Apply Instantly.ai security best practices for API keys, scopes, and access control. Use when securing API keys, implementing least-privilege access, or auditing Instantly…
Red-Team gegen Institutionen-, Ordnung- und Lebenswirklichkeitsrhetorik: trennt echte soziale Struktur von normativer Bindung, Kompetenz, Grundrechten und demokratischer…
Drafting tool-verified answers to cyber-insurance renewal, new-business, and underwriter security questionnaires: the standard recurring question set (MFA everywhere including…
Integra um banco, instituição de pagamento ou lotérica com a API do Boleto Ringer da Conta Comigo Digital (digitalbank 2.0): login OAuth2, cadastro de pessoa pagadora, webhook de…
Use when integrating a third-party/external system — calling a vendor API (anti-corruption adapter behind your own interface, resilient HTTP with circuit breaker + retry/backoff,…
Integrates a THIRD-PARTY identity provider via OpenID Connect — "Log in with Google/GitHub/Microsoft/Apple" or acting as an OAuth client to a third-party API.
Connect WhatsApp to your product with Kapso: onboard customers with setup links, detect connections, receive events via webhooks, and send messages/templates/media.
Use when managing Connected Apps for integration purposes — configuring OAuth policies, IP restrictions, refresh token expiry, and monitoring connected app usage.
Guide for creating new OAuth-based integrations in the Orient codebase. Use when adding external service integrations (APIs like Linear, GitHub, Slack, Notion, etc.), implementing…
Use when designing a reusable integration layer in Salesforce that serves multiple external APIs through a shared callout infrastructure.
Architecture-layer guidance for securing Salesforce integrations: mTLS mutual authentication, OAuth 2.0 flow selection, API gateway placement, IP allowlisting strategy on…
Use when a task needs the judgment of a law-enforcement or security Intelligence Analyst — building an Analysis of Competing Hypotheses (ACH) matrix from fragmentary reporting,…
Intelligent workplace inspection system with guided setup, configurable inspection tasks, AI-powered image analysis, and Feishu alerting.
Use quando Pedro digitar /intent-guard (status, baixa N, off, on, projeto-off, projeto-on), perguntar o que está no caderno de pedidos, pedir para arquivar um pedido, ou quando o…
Use BEFORE any tool call that could modify state, touch sensitive targets, rewrite history, install dependencies, publish packages, or expose credentials/environment data.
Implement OAuth flows and manage credentials for external services (Google, Slack, Salesforce, etc.) through Interactor.
Intercepts and analyzes HTTP/HTTPS traffic from mobile applications using Burp Suite proxy to identify insecure
Search all 10,533 Security skills →