Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Web Security › Page 11

Web Security (Page 11 of 16)

945 Claude Code skills in the Web Security sub-category of Security.

945 skills · updated 2026-07-28 · showing 601–660 of 945 by quality score

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

OWASP Top 10 security audit with Supabase-first methodology — RLS pass, bundle/secret scan, auth-path tracing, dependency CVEs. Plan only, no patches or destructive testing.
Expert guidance for Plang programming language (plang.is). Use when the user asks about Plang syntax, wants to generate Plang code, needs help debugging Plang goals, wants to…
Runs PMD's built-in Apex security ruleset (`category/apex/security.xml`) against Salesforce Apex source to detect injection, privilege-escalation, cryptographic, and XSS…
PocketBase is an open-source Go backend that ships as a single portable executable. It includes an embedded SQLite database with realtime subscriptions, built-in file and user…
PocketBase — single-file backend with SQLite, realtime subscriptions, auth, file storage, custom JS extensions
Multi-agent SECURITY review and pentest of a focus area (feature, section, or whole platform) via external AI advisors Codex Cursor Claude OpenCode Kilo Gemini.
Validates PopKit security posture using concrete vulnerability patterns, automated secret scanning, and OWASP-aligned checklists
How to keep template code database-agnostic and hosting-agnostic. Use when defining schemas, writing raw SQL, creating server routes, or anything that could leak a SQLite-only,…
Forked-context deep post-task reviewer — preloads verdict schema + OWASP security + deep code analysis + PM/docs accuracy + replan lens.
Use when building any web page that performs state-changing actions on click — login forms, payment buttons, delete confirmations, or settings toggles that could be exploited if…
Security design principles — trust boundaries and input validation, authentication vs authorization, secrets handling, secure defaults and defense in depth, lightweight threat…
Guides for configuring Prisma with different database providers (PostgreSQL, MySQL, SQLite, MongoDB, etc.).
You are an expert in Prisma ORM with deep knowledge of schema design, migrations, query optimization, relations modeling, and database operations across PostgreSQL, MySQL, and…
OWASP ZAP/Burp Suite/Nuclei integration, penetration test planning, DAST execution, and vulnerability scanning.
Use when implementing project state detection, designing STATE.md/TASKS.md templates, or configuring SQLite state store and MCP state protocol
Protect a React/Next.js SPA with route guards and middleware, and protect an API with token-verification middleware (signature + iss + aud + exp).
pschool (個人プログラミングスクール) の Q&A 教師エージェント。ユーザーが pschool コース (Udemy 1 コース粒度の座学 + ハンズオン演習) を受講中に詰まったときに起動し、答えを絶対に教えずに 3 段階のヒント (Lv 1 Conceptual / Lv 2 Directional / Lv 3 Specific)…
TspoonBase — a TypeScript backend-as-a-service with SQLite, auth, realtime, file storage, AI tools, vector search, and Admin UI.
Use when running pynchy locally — running the app, tests, linting, formatting, pre-commit hooks, or rebuilding the agent container.
Consolidated form validation skill. Owns ALL validation testing: empty-submit, invalid-format, real-time/blur feedback, whitespace, oversize input (10K), maxlength enforcement,…
Security scanning templates and checklists for OWASP Top 10, authentication, authorization, data protection. Use when conducting security testing or vulnerability assessment.
Launch quality subagents in parallel using Claude Code 2.1+ native Task tool. Includes ralph-security for OWASP validation and ralph-frontend for WCAG checks.
Quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security.
Use DBHub to expose guarded, token-efficient database inspection and SQL tools to MCP clients across Postgres, MySQL, SQL Server, MariaDB, and SQLite.
CRITICAL - Use when securing Rails applications - XSS, SQL injection, CSRF, file uploads, command injection prevention
Security baseline for Ruby on Rails 8 apps — strong params (and their common bypass mistakes), CSRF for browser apps, CSRF for SPAs, Brakeman + bundler-audit + Dependabot, Rails…
Performs security audits and vulnerability assessments on Ruby on Rails application code. Use when reviewing Rails code for security risks, assessing authentication or…
Build SQLite-backed reactive UI in `apps/desktop` using stable patterns for reads, selection, forms, writes, and loading states.
Recettix : compétence de recette et validation des livrables d'une application métier TypeScript. Couvre : Plan de Recette contractuel, critères d'acceptance Gherkin, jeux de…
Prueft Android-Apps vor Release als technische Pruefhilfe (KEINE anwaltliche Beratung) auf Abmahn-, Datenschutz-, Impressums-, Nutzungsbedingungen-, Widerrufs-, Google-Play-…
Brainstorma receptidéer, föreslå kompletta recept på svenska och spara nya recept till SQLite-databasen.
Complete open redirect detection and exploitation methodology — parameter discovery, 30+ bypass techniques, OAuth token theft, SSRF chaining, CSP abuse, phishing escalation, and…
Domain routing and boundary guidance for authorized CSRF testing, including token bypasses, SameSite bypasses, and JSON CSRF.
Detailed injection pack for SSRF, SQLi, XSS, SSTI, deserialization, XML, command, and expression injection paths.
Domain routing and boundary guidance for authorized SQL injection testing, including union-based, blind, error-based, stacked query, and second-order SQL injection variants.
Domain routing and boundary guidance for authorized cross-site scripting testing, including reflected, stored, DOM-based, mXSS, and CSP bypass variants.
Deep operational guide for 20 relational/SQL databases. PostgreSQL tuning (VACUUM, WAL, partitioning, extensions, PgBouncer), MySQL/MariaDB (InnoDB, Vitess, Galera, ProxySQL),…
Fixes specific web vulnerability classes — SQL/command injection, XSS, CSRF, SSRF, IDOR/broken access, insecure deserialization — by applying the canonical hardening…
Analisa e classifica um repositório GitHub via repo-radar CLI (SQLite + LLM), registrando o veredito em PROJECT_EVALUATIONS.md
Take a suspected injectable request, replay it on an authorized target, confirm the finding, and enumerate reachable database actions before manual follow-up.
Restore the latest production SQLite database backup to the local development environment
security auditof vulnerability , code security analysis, penetration test , improvement inthisbefore teamthis to countlower security audit pipeline.
Run a layered quality gate over a code change — code quality, security audit, and architecture consistency, in that order.
Checklist shift-left de segurança para React — XSS, tokens em storage, CSRF e atributo rel noopener — como parte do DoD do dev.
Master skill cho dự án Robot Bi. Kết hợp TDD, diagnosis loop, security audit, git safety, UI prototyping, và session hygiene — tất cả được calibrate cho codebase…
RSS AI 阅读器(免费版)。自动抓取 RSS/Atom 订阅源,通过 ai-assistant 生成中文摘要, 推送到飞书群机器人 Webhook。基于 SQLite 存储实现条目去重,避免重复推送.
Use Genie to turn a vague coding request into Claude Code brainstorm, wish, work, and review loops backed by markdown plans and local SQLite state.
Use when designing Rust CLIs backed by SQLite with migrations, transactions, tests, and data safety. Triggers:
Защитный Mythos-style security review для diff/PR/чувствительного кода. Используй для: /rldyour-security:ry-sec-review, проверь безопасность, секьюрити ревью, проверь авторизацию…
Create Goods Receipts (Material Documents) in SAP S/4HANA Cloud Public or on-prem private edition via OData V2 A_MaterialDocumentHeader deep-insert at API_MATERIAL_DOCUMENT_SRV.
Create supplier (AP) invoices in SAP S/4HANA Cloud Public or on-prem private edition via the SOAP A2X "Supplier Invoice ERP Create Request" service.
Create purchase orders (POs) in SAP S/4HANA Cloud Public or on-prem private edition via the OData V2 A_PurchaseOrder deep-insert at API_PURCHASEORDER_PROCESS_SRV.
Update existing records in SAP S/4HANA Cloud Public or on-prem private edition via OData V2 PATCH. Use whenever the user wants to update, change, edit, modify, patch, set, rename,…
Security checklist specifically for SaaS applications built with Next.js, Supabase, and Stripe. Covers authentication hardening, Row Level Security, Stripe webhook verification,…
Advanced input validation and sanitization using Zod. Use to prevent XSS and ensure data integrity before sending to Appwrite.
SAP Cloud Application Programming Model (CAP) development skill using Capire documentation. Use when: building CAP applications, defining CDS models, implementing services,…
Detect Insecure Direct Object Reference (IDOR) vulnerabilities in a codebase using a three-phase approach: recon (find candidates), batched verify (check authorization in parallel…
Detect SQL injection vulnerabilities in a codebase using a three-phase approach: recon (find unsafe SQL construction sites), batched verify (trace user input to those sites in…
Detect Server-Side Request Forgery (SSRF) vulnerabilities in a codebase using a three-phase approach: recon (find outbound call sites), batched verify (trace user input to…
Detect Cross-Site Scripting (XSS) vulnerabilities in a codebase using a three-phase approach: recon (find HTML/JS/DOM sink sites), batched verify (trace user input to sinks in…
All Security skills →
More in SecurityRed Team (1,518) · Threat Hunting (589) · Identity Access (433) · Network Security (361) · Appsec Tools (336) · Forensics (206) · Compliance (192) · Malware Analysis (175) · Cloud Security (83) · Zero Trust (68) · Appsec Build (61) · Crypto Keymgmt (53) · Incident Response (18) · Ot Ics Security (7)