Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
HomeBy role › Claude Code skills for security engineers

Claude Code skills for security engineers

Penetration testing, OWASP scanning, CVE triage, cloud-config audits, threat modeling, and bug-bounty workflows. Skills that wrap industry scanners so one prompt yields a structured findings report.

Related searches: claude code skills for security engineers, AI security engineering skills, claude penetration testing skills, claude code OWASP scanner skills.

security-analyzer

Comprehensive security vulnerability analysis for codebases and infrastructure. Scans dependencies (npm, pip, gem, go, cargo), containers (Docker, Kubernetes), cloud IaC (Terraform, CloudFormation), a

security

llm-security-audit

Comprehensive security auditing framework for LLM applications covering OWASP Top 10 for LLMs, threat modeling, penetration testing, and compliance with NIST AI RMF and ISO 42001Use when "security aud

security

penetration-testing

Use this skill when conducting authorized penetration tests, vulnerability assessments, or security audits within proper engagement scope. Triggers on pentest methodology, vulnerability scanning, OWAS

engineering

gungnir

Attack your own system — under explicit authorization — to prove its defenses hold, before launch and continuously after: scope and authorize, recon, scan and enumerate, exploit and confirm real vulne

security

repo-forensics

Security forensics for git repos, AI skills, and MCP servers. Audits dependencies, detects prompt injection, credential theft, runtime dynamism, manifest drift, known CVEs, CISA KEV (actively exploite

security

Geek-skills-security-audit

全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库(如React2Shell CVE-2025-55182、Next.js CVE-2025-66478),(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - AP

security

probe

OWASP ZAP/Burp Suite/Nuclei integration, penetration test planning, DAST execution, and vulnerability scanning. For dynamic security testing, pentesting, or runtime vulnerability validation. Complemen

security

security-auditor-saas

Application security agent that audits code for OWASP Top 10 vulnerabilities, hardcoded secrets, and common security flaws. Triggers on: security audit, vulnerability scan, OWASP check, security revie

security

application-security-pentesting

Production Application Security (AppSec) standards, OWASP Top 10 vulnerability remediation, SAST/DAST pipeline integration, secure code review, threat modeling, and defensive security posture.

security

audit-security-of-skill

SENTINEL — a comprehensive security audit skill for Claude Skills. Performs red-team/blue-team analysis on any SKILL.md (and its bundled scripts, hooks, and references), producing a formal vulnerabili

security

awesome-pentest

Runs an authorization-gated penetration-test engagement against a target (repo, web app, API, network, cloud, or mobile client) following PTES, OWASP WSTG/MASTG/API Top 10, and NIST SP 800-115 — from

security

code-security-review

Conducts comprehensive security code reviews including vulnerability detection (OWASP Top 10, CWE), authentication/authorization flaws, injection attacks, cryptography issues, sensitive data exposure,

security

pentest-audit

In-depth security audit and penetration testing of web, API, and mobile applications. Static source-code analysis, dynamic testing, configuration checks, and generation of structured reports with seve

security

secure-me

Comprehensive, framework-agnostic security auditor. Audits codebases for common vulnerabilities introduced by AI coding assistants in "vibe-coded" applications, as well as complex enterprise attack ve

security

vapt

Comprehensive vulnerability assessment and penetration testing skill leveraging Secator, NetExec, Metasploit, and raw Python for advanced exploitation chaining across Linux, Windows, Unix, macOS syste

security

loom-security-audit

Comprehensive security audits identifying vulnerabilities, misconfigurations, and best-practice violations across applications, APIs, infrastructure, and data pipelines. Use for OWASP Top 10 reviews,

security

performing-penetration-testing

This skill enables automated penetration testing of web applications. It uses the penetration-tester plugin to identify vulnerabilities, including OWASP Top 10 threats, and suggests exploitation techn

engineering

security-audit-triage

Map pentest reports and CVEs to real code. Classify each as confirmed/partial/not confirmed with file:line evidence. Assess API risk (injection, XSS, auth bypass), check OWASP Top 10 patterns, evaluat

security

rwrw01-security-audit

Run a full security-in-depth audit including OWASP Top 10, dependency analysis, and defense-in-depth review. Use for security audit, pentest review, or vulnerability assessment.

security

threat-feed

Daily threat-intel digest — AI-discovered vulnerabilities, AI-in-the-wild exploitation observations, AI-authored malware families, exploit-trends rollup, vendor-trends month-over-month deltas. Use whe

security

awesome-security-audit

Audits code for common vulnerabilities: injection, secrets, auth, dependency CVEs, CI/CD pipeline exposure, and cryptographic misuse — with confidence-gated, evidence-backed findings mapped to CWE/OWA

security

bb-local-toolkit

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps,

security

Container Security

Comprehensive container security guidance including vulnerability scanning with Trivy, image hardening, secrets management, and CIS benchmark compliance. Activates when working with "container securit

security

cyber-audit

Read-only exposure audit of the user's machine and projects for a CVE, breach, malicious package, or other security advisory, then write a structured report to a local audit folder. Use when the user

security

dast-nuclei

Fast, template-based vulnerability scanning using ProjectDiscovery's Nuclei with extensive community templates covering CVEs, OWASP Top 10, misconfigurations, and security issues across web applicatio

security

finding-writer

Converts raw pentest notes, logs, or observations into a structured audit finding ready for a security report. Use when you have evidence of a specific vulnerability — notes, tool output, an HTTP requ

content

fireworks-security

Security hardening superbrain — CWE Top 25, STRIDE threat modeling, Electron hardening, encryption, dependency audits, OWASP compliance

security

go-security-audit

Security review for Go applications: input validation, SQL injection, authentication/authorization, secrets management, TLS, OWASP Top 10, and secure coding patterns. Use when performing security revi

security

hexstrike-ai-pentest

MCP-based cybersecurity automation with 150+ tools and 12 AI agents. Use when running automated pentests, solving CTF challenges, conducting bug bounty reconnaissance, or orchestrating vulnerability s

security

ln-625-dependencies-auditor

Checks outdated packages, unused deps, reinvented wheels, CVE/CVSS vulnerability scan. Use when auditing dependencies. — from security/appsec-tools

security