Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Zero Trust

Zero Trust

82 Claude Code skills in the Zero Trust sub-category of Security.

82 skills · updated 2026-08-26 · showing 1–60 of 82 by quality score

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Runtime enforcement of file system boundaries and tool access restrictions. Blocks unauthorized operations and logs violations.
Runs a Trailmark structural review gate over a branch, pull request, fix commit, release diff, or git ref range to detect new entrypoints, new tainted paths, removed validation or…
Use this skill whenever the user needs to operate a VMware/Omnissa Horizon VDI environment via its Connection Server: list and manage desktop pools, RDS farms and published apps,…
Use before delivering work that incorporated content the agent did not author — fetched web pages, PDFs, retrieved or library documents, tool or subagent output — or that performs…
Expert network engineer specializing in cloud and hybrid network architectures, security, and performance optimization.
Review security boundaries for agent skills and tool-using workflows. Use when a skill, hook, script, adapter, or agent workflow touches tools, shell commands, file writes,…
Security hardening patterns for production AI agents. Covers prompt injection defense (7 rules), data boundary enforcement, read-only defaults for external integrations, WAL…
Real-time access control decision engine for 0xagentprivacy swordsman agents. Activates when evaluating incoming data requests against consent preferences, designing…
Specialist persona for amnesia-aware operations and reflection without memory. Activates for systems requiring structural forgetting, orbit maintenance, tidal boundary…
Classify whether a requested action is safe to proceed, requires explicit approval, or should not be executed.
Strategy layer for resilient Apex HTTP callouts: bounded retry with backoff, queueable async retry chains, circuit-breaker via Platform Cache, idempotency keys, dead-letter…
Verify code correctness before claiming done or committing. Run 6-dimension checklist: requirements coverage, concurrency safety, error handling, resource management, boundary…
Maps every entry point, component, and trust boundary of a target before testing begins — preventing missed coverage and prioritizing the highest-value attack paths.
Audit and repair readers for fixed-length binary credentials and their text encodings without mutating raw bytes.
Use when when two mapping implementations (or versions of the same mapper) show disagreement on per-read mapping status—e.g., one mapper leaves reads fully unmapped that the other…
Choose the smallest macOS-hosted boundary for development, compatibility, or authorized security research.
Expert in Cilium eBPF-based networking and security for Kubernetes. Use for CNI setup, network policies (L3/L4/L7), service mesh, Hubble observability, zero-trust security, and…
Diagnose and fix runtime errors in Lightning Web Components including wire adapter failures, shadow DOM boundary violations, event propagation mistakes, async rendering timing…
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for Android APK hooking, Frida tracing, request-signing recovery, SSL pinning bypass, JNI bou — from…
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for crypto, encoding, steganography, APK, IPA, and mobile trust-boundary challenges.
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for prompt-injection, retrieval poisoning, memory contamination, planner drift, MCP or tool-b — from…
Analyzes events through cybersecurity lens using threat modeling, attack surface analysis, defense-in-depth, zero-trust architecture, and risk-based frameworks (CIA triad — from…
Analyzes events through cybersecurity lens using threat modeling, attack surface analysis, defense-in-depth, zero-trust architecture, and risk-based frameworks (CIA triad — from…
Analyzes events through cybersecurity lens using threat modeling, attack surface analysis, defense-in-depth, zero-trust architecture, and risk-based frameworks (CIA triad — from…
Trigger: security rules, credential leaks, auth tokens, input sanitization, threat model. Scope: Software security guidelines, threat prevention, secure data handling.
DingTalk Workspace CLI (dws) - officially open-sourced cross-platform CLI tool from DingTalk. Provides 86 commands across 12 products: Contact, Chat, Bot, Calendar, Todo,…
Shared reference for the Electron cluster: the main/renderer/preload process model, the context-isolation security boundary (the one decision everything turns on), app lifecycle,…
Produce a short threat-model note before building a security-relevant feature in argus. Use when adding messaging, key, auth, attachment, admin, or tenant features — anything that…
NixOS file server setup and configuration using Tailscale VPN, Samba/CIFS, NFS, and SFTP with security design and client access methods
Decide and audit the security boundary a Flow runs at — System Context With Sharing, System Context Without Sharing, or User Context — plus the per-element runInMode override and…
Fortinet FortiSASE audit — Secure Web Gateway policy review, ZTNA application gateway assessment, thin edge FortiGate integration validation, SD-WAN security overlay analysis,…
Use when reasoning about the pattern where a language model emits, as structured output, a description of UI components or a UI sub-tree that an application then renders for the…
Git security best practices for 2025 including signed commits, zero-trust workflows, secret scanning, and verification
Prevent panics, silent corruption, and subtle runtime bugs in Go: typed-nil interfaces, slice aliasing, integer overflow on conversion, float comparison, defer in loops, defensive…
Use when deciding whether to route a task to OpenAI's GPT-5.5 frontier model versus Claude Opus or Sonnet — picking the model lane for infrastructure scripts, CI pipelines,…
Compares Trailmark code graphs at two source code snapshots (git commits, tags, or directories) to surface security-relevant structural changes.
Use when creating a draw.io diagram for compliance scope, authorization boundaries, trust boundaries, in-scope/out-of-scope systems, and system context diagrams in a GRC,…
Enterprise secrets lifecycle management pattern using HashiCorp Vault. Enforces Zero-Trust access controls, dynamic database credential leasing, secret rotation engines,…
Higher-Kinded-J Spring Boot integration (hkj-spring-boot-starter). Use PROACTIVELY whenever the working file or task involves: (1) a Spring controller method (@RestController /…
Implement continuous identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based
Implement Linkerd service mesh patterns for lightweight, security-focused service mesh deployments. Use when setting up Linkerd, configuring traffic policies, or implemen — from…
Implement Linkerd service mesh patterns for lightweight, security-focused service mesh deployments. Use when setting up Linkerd, configuring traffic policies, or implemen — from…
Structural security design principles for building LLM agents, autonomous systems, and self-improving harnesses.
Checks application security boundaries: secrets, injection, XSS, input validation, and sensitive env defaults. Use when auditing exploitable code paths.
Run this appropriateness check the moment you are about to integrate a retrieved long-term memory — a Grove content-addressed hit, a chroma/pgvector neighbour, a…
Presents a risk framework for every configurable security control in NemoClaw. Use when evaluating security posture, reviewing sandbox security defaults, or assessing control…
Use when user needs network architecture design, security implementation, performance optimization, and troubleshooting for cloud and hybrid environments.
Use for OZM-managed security, credential, permission, authz/authn, secret, network boundary, or payload-less risk work.
Architects Port Daddy's outbound-only event relay and the zero-trust crypto stack that governs it — PKI choice (ACME vs OIDC vs Web-of-Trust), per-publisher Merkle event chains,…
PostgreSQL's PL/pgSQL procedural-language implementation — `src/pl/plpgsql/src/` — the parser (`pl_gram.y` + `pl_scanner.c`), compiler (`pl_comp.c` — turns source text into…
Pre-engagement recon and target prioritization for a bug-bounty or VDP scope. Given a program URL (HackerOne, Bugcrowd, Intigriti, YesWeHack, self-hosted VDP) or a pasted list of…
ISTQB Foundation Level (CTFL) aligned QA toolkit for manual and automated testing. Use when asked to create test plans, test strategies, test conditions, test cases, bug reports,…
Compact operational boundary policy for durable red-team workflows. It does not route domains or decide workflow completion.
Design know-how for ADR-0075 observability-by-default — every feature that performs external I/O, calls an LLM, or makes non-deterministic/heuristic decisions ships a replayable…
Senior Supabase RLS+Auth Boundary Auditor for tenant isolation gaps in migrations and policy DDL BEFORE deploy.
Rubrik Mythos high-ROI steal: AI discovery outruns human review. Multi-pass filter with file-hash checkpoints, trust-boundary prune, tightly-scoped auto-remediation, and Track B…
Secure credential intake via local web form. Spin up a one-page server on Tailscale, paste keys, upload PEM/JSON files, hit submit — secrets land in .hex/secrets/ with 600 perms…
HashiCorp Vault, cloud secret managers, rotation strategies, and zero-trust secret access
Read a diff for security by tracing attacker-controlled input to dangerous operations and checking every trust boundary it crosses.
Architecture Zero Trust — never trust always verify, micro-segmentation réseau, approche identity-centric et accès conditionnel.
All Security skills →
More in SecurityRed Team (1,582) · Web Security (1,094) · Threat Hunting (754) · Identity Access (496) · Network Security (414) · Appsec Tools (381) · Forensics (295) · Malware Analysis (207) · Compliance (204) · Cloud Security (94) · Appsec Build (66) · Crypto Keymgmt (65) · Incident Response (20) · Ot Ics Security (9)