Security
Scanning, secrets, and compliance
60 artifacts
@compartmentdev/audit-type-ownership
Audit type ownership and boundary placement in the compartment repo: misplaced or duplicated types, query/service leaks, root export surface, and phased move plans.
compartmentdev/compartment
AskillSecurity247@majiayu000/owasp-zap-security-scanner
Automated web application security scanning using OWASP ZAP for finding XSS, SQL injection, CSRF, and other OWASP Top 10 vulnerabilities.
majiayu000/claude-skill-registry
AskillSecurity529@majiayu000/ops-compliance
Check codebases against compliance frameworks (SOC2, GDPR, HIPAA, PCI-DSS). Generates compliance reports with pass/fail status and remediation guidance.
majiayu000/claude-skill-registry
AskillSecurity529@xalgorix/implementing-deception-based-detection-with-canarytoken
Deploy and monitor Canary Tokens via the Thinkst Canary API for deception-based breach detection using web bug
xalgorix/xalgorix
AskillSecurity813@symph0nia/cyberedge-scan-vulnerabilities
Run and interpret CyberEdge's reviewed, bounded Nuclei vulnerability baseline for an explicitly authorized Scope. Use when an AI operator must execute versioned signed templates, wait for the Task, correlate normalized Findings with immutable scanner Evidence, or distinguish negative coverage from adapter failure.
Symph0nia/CyberEdge
AskillSecurity611@aj-geddes/api-security-hardening
Secure REST APIs with authentication, rate limiting, CORS, input validation, and security middleware. Use when building or hardening API endpoints against common attacks.
aj-geddes/useful-ai-prompts
AskillSecurity302@mukul975/hunting-for-cobalt-strike-beacons
Detect Cobalt Strike beacon network activity using default TLS certificate
mukul975/Anthropic-Cybersecurity-Skills
AskillSecurity27k@26zl/performing-cryptographic-audit-of-application
A cryptographic audit systematically reviews an application's use of
26zl/cybersec-toolkit
AskillSecurity34@ashermahonin/security-owasp-llm
Review an LLM-powered feature against the OWASP Top 10 for Large Language Model Applications: prompt injection, sensitive information disclosure, supply-chain risk for models and data, data and model poisoning, improper output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, misinformation, unbounded consumption. Produces a per-category status, threat model for the LLM data flow, abuse-case test plan, and release verdict. Use whenever the product surface includes any LLM call, retrieval augmentation, fine-tune, embedding store, or model-routed automation.
ashermahonin/agentic-skills
AskillSecurity10@backbay-labs/security-review
Security review for risky code changes
backbay-labs/clawdstrike
AskillSecurity284@kimyx0207/code-security
Runs Semgrep security scans on the current project to detect vulnerabilities, secrets leakage, and OWASP Top 10 issues. Use when the user asks for security scanning, vulnerability detection, code auditing, secrets checking, or says things like 安全扫描, 代码扫描, 扫漏洞, 安全检查, 漏洞检测, 扫一下安全.
KimYx0207/SkillSemgrep
AskillSecurity37@lowyshin/security-scan
Performs a rapid security sweep for secrets, API keys, and common vulnerabilities using cross-platform platform tools.
LowyShin/giip-fde-agent
AskillSecurity33@majiayu000/accessibility-compliance-accessibility-audit
You are an accessibility expert specializing in WCAG compliance, inclusive design, and assistive technology compatibility. Conduct audits, identify barriers, and provide remediation guidance.
majiayu000/claude-skill-registry
AskillSecurity529@lionelsimai/medical-coding-audit
Design medical coding audit programs. TRIGGERS - Use when user needs help with medical-coding-audit related tasks.
lionelsimai/claude-skills-collection
AskillSecurity18@lionelsimai/home-energy-audit
Conduct home energy audits. TRIGGERS - Use when user needs help with home-energy-audit related tasks.
lionelsimai/claude-skills-collection
AskillSecurity18@tacoda/keystone-audit
Full dual-flywheel audit — Learning (capture from review) + Pruning (remove dead rules). Periodic charter hygiene.
tacoda/keystone
AskillSecurity42@agentera/security-audit-reporter
Triage raw security-scan findings (hardcoded secrets, injection patterns, vulnerable dependencies) into a prioritized, actionable security audit report. Use for security audit, code audit, vulnerability triage, and risk review.
AgentEra/Agently
AskillSecurity1.6k@yv1ing/binwalk
Use binwalk for authorized firmware, binary blob, archive, filesystem, and embedded-content triage with bounded extraction and evidence handling.
yv1ing/Z3r0
AskillSecurity589@phenobarbital/git-commit-formatter-3
Formats git commit messages according to Conventional Commits specification. Use this when the user asks to commit changes or write a commit message.
phenobarbital/navigator-auth
AskillSecurity15@majiayu000/security-incident-playbook-generator
Creates response procedures for security incidents with containment steps, communication templates, and evidence collection. Use for "incident response", "security playbook", "breach response", or "IR plan".
majiayu000/claude-skill-registry
AskillSecurity529@hunvreus/audit
Audit a new or unfamiliar project to understand its structure, health, risks, documentation gaps, and next actions. Use when initially entering a repo, assessing project quality, preparing onboarding, or asking what should be improved first.
hunvreus/skill-issue
AskillSecurity34@tonone-ai/compat-audit
Audit a proposed API change for breaking changes — classification and impact assessment.
tonone-ai/tonone
AskillSecurity67@majiayu000/agent-security-auditor
Expert security auditor specializing in comprehensive security assessments, compliance validation, and risk management. Masters security frameworks, audit methodologies, and compliance standards with focus on identifying vulnerabilities and ensuring regulatory adherence.
majiayu000/claude-skill-registry
AskillSecurity529@transilienceai/cloud-defense
Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the preventive controls that close each step. Use for cloud detection engineering, hardening, remediation write-ups, or blue-team posture review of the lateral-movement -> privilege-escalation -> exfiltration -> evasion chain.
transilienceai/communitytools
AskillSecurity444@majiayu000/tool-quality-audit
Audit tool integrations for deterministic behavior, error contracts, and logging before agents depend on them. Use when adding or updating tools or MCP servers.
majiayu000/claude-skill-registry
AskillSecurity529@majiayu000/burp-suite-web-security-skill
Web application security testing with Burp Suite integration
majiayu000/claude-skill-registry
AskillSecurity529@armorerlabs/armorer
Use Armorer as the TypeScript control plane for managed local agents.
ArmorerLabs/Armorer
AskillSecurity59@majiayu000/security-reactnative
Security - React Native Best Practices. Use when reviewing security, implementing auth, or hardening code.
majiayu000/claude-skill-registry
AskillSecurity529@docxology/codomyrmex
Full-spectrum coding workspace skill — PAI MCP bridge, ~600 production @mcp_tool lines, trust/verify workflows. USE WHEN user says verify codomyrmex, codomyrmexTrust, audit tools, codomyrmex tools, or any codomyrmex automation surface.
docxology/codomyrmex
AskillSecurity11@moffran/ce-regulatory-compliance
Compatibility shim that redirects to the canonical shared skill definition in `.claude/skills/ce-regulatory-compliance/SKILL.md`.
Moffran/calibrated_explanations
AskillSecurity78@majiayu000/enforce-security-vigilance
Enforce continuous security vigilance and threat monitoring.
majiayu000/claude-skill-registry
AskillSecurity529@arogyareddy/senior-security
../../../engineering-team/senior-security/SKILL.md
ArogyaReddy/alirezarezvani-claude-skills
AskillSecurity30@majiayu000/web-security-standards
Trusted domains, security assessment patterns, and domain research standards for WebFetch permissions
majiayu000/claude-skill-registry
AskillSecurity529@mitkox/security-audit-rlm
Run and troubleshoot privacy-preserving, local DSPy RLM security audits for large legacy .NET codebases. Use when asked to scan repositories for vulnerabilities, tune RLM/tool limits, fix truncation/stall issues, or produce actionable markdown/json audit outputs without loading entire codebases into model context.
mitkox/megacode
AskillSecurity77@cyberstrikeus/cp-10-6-component-protection
Protect system components used for recovery and reconstitution.
CyberStrikeus/CyberStrike
BskillSecurity1.3k@cyberstrikeus/cis-azure-database-6-2
Ensure Azure Database for PostgreSQL uses only Microsoft Entra Authentication
CyberStrikeus/CyberStrike
BskillSecurity1.3k@cyberstrikeus/au-13-1-use-of-automated-tools
Monitor open-source information and information sites using [organization-defined].
CyberStrikeus/CyberStrike
BskillSecurity1.3k@cyberstrikeus/cis-tomcat10-v110-1-1
Remove extraneous files and directories (Manual)
CyberStrikeus/CyberStrike
BskillSecurity1.3k@cyberstrikeus/cis-ocp-v190-1-3-3
Ensure that the --service-account-private-key-file argument is set as appropriate (Manual)
CyberStrikeus/CyberStrike
BskillSecurity1.3k@cyberstrikeus/cis-ubuntu2004-v300-1-1-2-4-1
Ensure separate partition exists for /var
CyberStrikeus/CyberStrike
BskillSecurity1.3k@cyberstrikeus/cis-ubuntu1604-v200-1-7-2
Ensure local login warning banner is configured properly
CyberStrikeus/CyberStrike
BskillSecurity1.3k@cyberstrikeus/cis-k8s-v1120-5-6-2
Ensure that the seccomp profile is set to docker/default in your pod definitions (Manual)
CyberStrikeus/CyberStrike
BskillSecurity1.3k@fr-e-d/skill-usage-audit
Scan all artefacts (epics, stories, PRDs) for Base Rule #2 compliance — verify that every artefact declares skills_invoked and related_decs in frontmatter. Produces an audit report with pass/fail per artefact and overall compliance rate.
Fr-e-d/GAAI-framework
BskillSecurity155@cyberstrikeus/cis-ubuntu1804-v220-4-2-10
Ensure sshd IgnoreRhosts is enabled
CyberStrikeus/CyberStrike
BskillSecurity1.3k@cyberstrikeus/cis-ubuntu-14-04-lts-1-2-2-ensure-gpg-keys-are-configured
Verify that GPG keys are configured for package manager to ensure package integrity
CyberStrikeus/CyberStrike
BskillSecurity1.3k@cyberstrikeus/cis-k8s-v200-5-2-7
Minimize the admission of root containers (Manual)
CyberStrikeus/CyberStrike
BskillSecurity1.3k@cyberstrikeus/cis-ubuntu1204-v110-9-3-6
Set SSH IgnoreRhosts to Yes
CyberStrikeus/CyberStrike
BskillSecurity1.3k@signalpilot-labs/env-setup
Use when setting up a project environment — installing dependencies, verifying builds, detecting the tech stack. Covers Phase 0 of a new session.
SignalPilot-Labs/AutoFyn
BskillSecurity99@cyberstrikeus/cis-ubuntu1204-v110-2-3
Set nosuid option for /tmp Partition
CyberStrikeus/CyberStrike
BskillSecurity1.3k@cyberstrikeus/cis-tomcat7-v110-10-19
use the logEffectiveWebXml and metadata-complete settings for deploying applications in production
CyberStrikeus/CyberStrike
BskillSecurity1.3k@trezor/skills-and-code-style-contribution
How to contribute to the Trezor Suite code style guide, including issue proposals and pull request workflows. Use when proposing code style changes.
trezor/trezor-suite
BskillSecurity1.0k@camunda/ci-security-compliance
Enforces GitHub Actions security and compliance for this monorepo. Use when adding third-party actions, handling secrets, defining permissions, and reviewing CI security trade-offs.
camunda/camunda
BskillSecurity4.2k@cyberstrikeus/cis-k8s-v1110-5-2-5
Minimize the admission of containers wishing to share the host network namespace (Manual)
CyberStrikeus/CyberStrike
BskillSecurity1.3k@pypl0/ombre
- Prompt injection detection (20+ attack patterns)
pypl0/Ombre
BskillSecurity10@wrsmith108/claude-skill-security-auditor
Run structured security audits with actionable remediation plans.
wrsmith108/claude-skill-security-auditor
BskillSecurity32@eastsword/dfyx-code-security-review
高级白盒安全审计专家。基于深度数据流分析和业务逻辑理解的专家级代码安全审计工具。
EastSword/skill-dfyx_code_security_review
BskillSecurity135@cyberstrategyinstitute/ai-safe2-framework
> This file (root `skill.md`) covered AI SAFE2 v2.1 (128 controls, 14 frameworks).
CyberStrategyInstitute/ai-safe2-framework
BskillSecurity137@championswimmer/ui-testing
How to run, write, and debug local UI tests for Android, iOS, and browser builds.
championswimmer/TwoFac
BskillSecurity123@forter/forter-agentic-readiness-audit
Audit a website against the Forter Agentic Readiness Guide. Loads the 25 weighted rubrics in `audit/`, probes the target site (and optional source code), scores each guideline Pass/Partial/Fail/N/A with sub-check granularity, and produces a prioritized fix report. Use when a user asks "score my site against the agentic readiness guide", "audit https://… for agent readiness", or "what do I need to fix to be agent-ready".
forter/agentic-readiness-guide
BskillSecurity106@ok-helloworld/vibe-pentest
AI 渗透测试:多 Agent 并行架构的 Web 应用渗透测试技能。 流程: 指纹识别 → 后台入口扫描 → API 预扫描 → 浏览器登录提取凭证(可选) → GoSpider 爬虫 → 过滤数据 → 指纹汇总 → 多 Agent 并行渗透测试 → 攻击链分析 → 漏洞证据复查 → 导出 JSON 报告。 纯黑盒测试,不依赖源码。平台无关设计,可在任意 Agent 平台创建和使用。
ok-helloworld/vibe-pentest
BskillSecurity229