Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Web Security › Page 2

Web Security (Page 2 of 16)

945 Claude Code skills in the Web Security sub-category of Security.

945 skills · updated 2026-07-28 · showing 61–120 of 945 by quality score

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Quick OWASP security scan for injection risks, hardcoded secrets, weak crypto, and Spring Security misconfigs.
Jenkins UI and frontend development — Jelly views, Design Library components, form controls, help files, JavaScript integration, and XSS prevention.
QA code review in 8 dimensions (Security with OWASP Top 10 + STRIDE, Errors, Consistency, Impact, Env vars, Versioning, Second opinion cross-model, Visual audit vs design-spec).
Use when the user asks to run their Kaseya BMS service desk from the terminal - check the queue, find stale or aging tickets, balance technician workload, review unbilled billable…
Every Level RMM endpoint, plus a local SQLite fleet store and offline cross-entity rollups no Level tool has: at-risk ranking, patch posture, alert triage, and stale-device…
Use when the user asks to see what changed across their Liongard environments, find stale launchpoints or offline agents, run an estate-wide health or coverage check, pivot a…
Reviews LLM-powered applications against the OWASP Top 10 for Large Language Model Applications (2025 edition).
Analyze a PR for LVMS (LVM Storage) security threats with STRIDE/DFD analysis, MITRE ATT&CK and OWASP mapping
Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie…
Open, local revenue-intelligence CLI for Maxio Advanced Billing - MRR waterfalls, retention, and per-client history computed offline from a SQLite mirror, so the trended history…
Use when the user asks to find wasted Microsoft 365 licenses, see who holds global admin or other privileged roles, triage new Microsoft Defender security alerts, flag…
Use when the user asks to audit autoscale across all their Nerdio Manager customers, sweep session-host power state, reconcile per-customer billing and usage, list customer…
OpenAI Agents SDK (Python) development. Use when building AI agents, multi-agent handoffs, function tools, guardrails, sessions, streaming, or tracing with the `openai-agents` /…
Use when the user asks to reconcile Pax8 billing, find invoice leakage, compute Pax8 MRR and margin, catch usage overages before they invoice, see what changed in their book of…
Every Eventbrite organizer endpoint, plus a local SQLite mirror of your events, orders Trigger phrases: `sync my eventbrite events`, `which of my events are selling slowest`,…
Every Nylas API, plus a local SQLite mirror, cross-grant search, and confirm-by-hash sending no other Nylas tool has.
The first agent-native CLI for Pangolin — every endpoint, plus offline SQLite, cross-org audits Trigger phrases: `expose service through pangolin`, `back up pangolin config`,…
Run an OWASP LLM01 injection corpus against the system prompt + tool surface and report which payloads succeeded
Use when the user asks to see who is overbooked in Resource Guru, find who is on the bench, check a resource's day-by-day utilization, work out remaining capacity before booking a…
Use when the user asks to triage their RocketCyber managed SOC, see what broke across clients overnight, rank devices at risk in Defender, compute incident MTTR for a QBR, trend…
Every Rootly incident, alert, and on-call object as a typed command, with a local SQLite mirror for offline analytics.
Use when the user asks to inventory their runZero attack surface, triage which assets are most exposed, see what changed since the last sync, trace which assets a CVE affects,…
Run a full security-in-depth audit including OWASP Top 10, dependency analysis, and defense-in-depth review. Use for security audit, pentest review, or vulnerability assessment.
Ghost Security - SAST code scanner. Finds security vulnerabilities in source code by planning and executing targeted scans for issues like SQL injection, XSS, BOLA, BFLA, SSRF,…
Proactive secure-coding coach scoped to the file or topic you are working on — surfaces relevant SAST rule IDs, CWE patterns, language-specific PASS/FAIL code snippets.
Seed the SQLite database with project data from seed.json. Use 'reset' argument to drop and recreate tables first.
Use when the user asks to triage SentinelOne threats across client sites, trace a threat's blast radius, find dark/stale/under-protected agents, check protection-coverage gaps,…
Use when the user asks to reconcile Sherweb billing, compute net margin per customer (receivable minus payable), find orphaned or under-billed subscriptions, catch metered usage…
Use when the user asks to audit SkyKick Cloud Backup across customers - which Microsoft 365 tenants have a backup gap, which mailboxes silently stopped snapshotting, what's…
Use when: performing code review, pull request review, security review, designing, implementing, or testing SSRF fixes, outbound HTTP requests, outbound fetch helpers,…
Use when the user asks to triage a SuperOps queue, see who's about to breach SLA, pull a client 360 before a QBR, find at-risk assets (unpatched and actively alerting), check…
Reviews AI/ML model supply chains for security risks including model provenance verification, training data lineage, fine-tuning pipeline integrity, inference dependency review,…
Use when the user asks to check Tactical RMM fleet health, triage the agents that need attention first, sweep patch posture across every client, find agents that have gone dark,…
Use when the user asks to triage ThreatLocker application approvals across tenants, approve a file hash everywhere it's pending, export or check retention on the Unified Audit…
Analyze a PR for TNF (Two-Node Fencing) security threats with STRIDE/DFD analysis, MITRE ATT&CK and OWASP mapping
STRIDE + OWASP-based security audit with optional auto-fix. Scans code for vulnerabilities, categorizes by severity, and can iteratively fix findings using vc:autoresearch pattern.
Use when the user asks to check Veeam backup health across customers, find failing or stale backup jobs, surface workloads past their RPO, triage VSPC alarms, or report per-tenant…
Web application security testing with Burp Suite integration
Chief Security Officer mode. Infrastructure-first security audit: secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply cha — from…
ALWAYS use this skill when the user mentions PKA, personal knowledge, repo map, knowledge base setup, replacing Obsidian/Notion/Tana/Heptabase, organizing notes and files into a…
ALWAYS use this skill when the user wants a dashboard, browser interface, or visual view of their knowledge base, notes, projects, or PKA system.
SQLite-based project documentation logger for tracking API references, components, and project progress.
Безопасность сайтов на «1С-Битрикс: Управление сайтом» — модуль «Проактивная защита» (проактивный фильтр/WAF, веб-антивирус, панель безопасности, OTP/двухфакторка), безопасная…
Use when you need to design, review, or improve security in Spring Boot applications — including SecurityFilterChain, OAuth2/JWT resource server patterns, form login basi — from…
Protect your SaaS app from common vulnerabilities. Use when building auth, handling user data, or deploying features.
Use when you need to design, review, or improve security in Micronaut applications — including micronaut-security authentication, @Secured and intercept-url-map rules, JW — from…
Action Text (rich text) in Rails 8 — Trix editor integration, has_rich_text on models, Active Storage for embedded attachments, the safe-list of HTML tags, custom embeds via…
Scaffold the next database migration for this repo. Use when adding or altering a SQLite table/index/schema.
Security audit: OWASP Top 10, multi-tenancy, injection, auth, XSS, dependencies.
Shortcut for security review on current change set. Runs layered checks (secret-scan, dep-audit, semgrep, OWASP patterns, prompt-injection review).
Composite skill — full security pass across secrets, dependencies, code paths, and OWASP risks. Chains security-audit (broad) + socket-audit (npm supply chain) + semgrep (pattern…
Use when the user asks to check Afi SaaS backup coverage across Microsoft 365 / Google Workspace tenants, find which mailboxes or sites aren't backed up, catch protected resources…
企业级网络安全评估与加固体系(免费版),覆盖安全态势评估、STRIDE威胁建模、 OWASP Top 10应用安全审计、基础设施加固。核心能力: - 12阶段安全评估方法论(态势评估到评分体系) - STRIDE+威胁建模与风险优先级矩阵(P0-P3) - OWASP Top 10(A01-A10)应用安全审计清单 -…
Coleta e consulta dados de leiloeiros oficiais de todas as 27 Juntas Comerciais do Brasil. Scraper multi-UF, banco SQLite, API FastAPI e exportacao CSV/JSON.
Attack surface mapping for LLM agent systems. Threat model, blast radius calculation, entry points, trust boundaries, lateral movement paths, and MITRE ATLAS techniques for AI…
MCP Agent Mail - Mail-like coordination layer for multi-agent workflows. Identities, inbox/outbox, file reservations, contact policies, threaded messaging, pre-commit guard, Human…
Agent memory system security — poisoning prevention, L1/L2 integrity, context window attacks, memory exfiltration defense, and session isolation.
Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles user input, authentication, API endpoints, or sensitive data.
SSRF vulnerability hunting specialist. Use for testing URL-accepting parameters, webhook endpoints, file import features, and any server-side request functionality.
XSS specialist covering reflected (H1 #60), stored (H1 #61), and DOM (H1 #62). Dispatcher passes subtype — 'reflected', 'stored', or 'dom' — in the task; falls back to inference…
All Security skills →
More in SecurityRed Team (1,518) · Threat Hunting (589) · Identity Access (433) · Network Security (361) · Appsec Tools (336) · Forensics (206) · Compliance (192) · Malware Analysis (175) · Cloud Security (83) · Zero Trust (68) · Appsec Build (61) · Crypto Keymgmt (53) · Incident Response (18) · Ot Ics Security (7)