Browse 138,453 skills across 70 categories. Mirrored from majiayu000/claude-skill-registry.
Run a security-oriented review of dependencies, secrets exposure, configuration risk, and code-level security issues for...
Audits code security against OWASP Top 10. Validates user ID from session, detects sensitive data leaks, verifies Zod va...
Run a comprehensive security scan across all systems
Run ASH (Automated Security Helper) security scan with delta detection
Security scan workflow — dependency audit, OWASP checklist, secrets scan, vulnerability report. Applies software-enginee...
Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection...
Run comprehensive security audits including SAST, dependency scanning, and secret detection
Proactive security scanning. Triggers when modifying auth, API endpoints, user data, or sensitive operations.
Comprehensive security analysis with vulnerability detection and remediation tracking
Run security scans locally (Semgrep, Trivy, Gitleaks) to detect vulnerabilities, secrets, and code issues before pushing...
Trivyで依存関係/コンテナの脆弱性をスキャンし、重大度順に潰す。リリース前チェックで使う。
Automated security scanning workflow using Semgrep MCP. Scans changed files for OWASP Top 10 vulnerabilities, CWE patter...
Scans DAPR projects for security issues including plain-text secrets, missing ACLs, insecure configurations, and securit...
Perform security scanning, vulnerability assessment, and code analysis. Use tools like Trivy, Snyk, OWASP ZAP, and stati...
全面的安全分析,识别OWASP Top 10漏洞、检测硬编码密钥和审查安全配置。
Run security scans including SAST, dependency scanning, and secret detection
Automatically scan code for security vulnerabilities when user asks if code is secure or shows potentially unsafe code....
Automated security scanning for dependencies and code. Use when running npm audit, pip-audit, Semgrep, secret detection,...
SAST rules, vulnerability patterns, secret detection, and security scanning configuration
Security vulnerability scanning, secret detection, dependency auditing, and OWASP best practices. Use when performing se...
You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security....
Use when working with security scanning security hardening
Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks
Comprehensive security analysis including SAST, DAST, dependency scanning, secret detection, and vulnerability assessmen...
Secret detection patterns and scanning workflow. Auto-loaded by security-reviewer agent for all security audits. Contain...
Use this agent when performing security audits, vulnerability assessments, or security reviews of code. Triggers on requ...
Performs security audits for vulnerabilities, input validation, auth/authz, hardcoded secrets, and OWASP compliance. Use...
Use when working with authentication, API routes, user input, or sensitive data. Audits code for security vulnerabilitie...
Configure and manage Claude Code security protections for sensitive files, credentials, and data. Use when the user invo...
**SECURITY SHIELD**: '보안', '인증', '로그인', '비밀번호', 'JWT', '토큰', '암호화', '취약점', 'SQL 인젝션', 'XSS', '보안 검사' 요청 시 자동 발동. .env/au...
Application security patterns - authentication, secrets management, input validation, OWASP Top 10. Use when: auth, JWT,...
安全专家。专注于应用安全、威胁建模、安全合规和数据保护。提供安全审查、漏洞扫描、安全配置和合规检查。用于构建安全可靠的应用系统。
提供安全审计、风险评估和合规检查能力。当需要进行安全审查、风险评估或合规验证时使用。
Implement authentication, authorization, data protection, vulnerability checks, and security best practices. Use when ad...
Security standards for credential handling and authentication
Activate when conducting security analysis using STRIDE threat modeling, vulnerability assessment, and security architec...
Composable security suite for binary and prompt-surface assurance, static analysis, dynamic tracing, repo-native redteam...
Sicherheit & DSGVO - Atoll Tourisme. Use when reviewing security, implementing auth, or hardening code.
Seguridad & RGPD - Atoll Tourisme. Use when reviewing security, implementing auth, or hardening code.
Sécurité & RGPD - Atoll Tourisme. Use when reviewing security, implementing auth, or hardening code.
基于NFR安全要求,生成STRIDE/OWASP威胁模型和测试场景。L3级别专用,当设计和需求确认后使用。
Plan security testing strategies including OWASP testing, penetration test scoping, SAST/DAST integration, and threat-ba...
Comprehensive security testing framework aligned with OWASP Top 10 and CWE/SANS Top 25. Performs static analysis (SAST),...
Test for security vulnerabilities using OWASP principles. Use when conducting security audits, testing auth, or implemen...
Identify security vulnerabilities through SAST, DAST, penetration testing, and dependency scanning. Use for security tes...
Use when selecting and configuring security testing tools for your CI/CD pipeline. Covers SAST, DAST, SCA, container sca...
Automate vulnerability scans.
Security testing patterns including SAST, DAST, penetration testing, and vulnerability assessment techniques. Use when i...
Test security features and verify implementation before deployment. Use this skill when you need to test CSRF protection...
Scans code for security vulnerabilities and unsafe patterns. Use when the user asks about security, mentions OWASP, cred...
Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mi...
Perform repository-grounded threat modeling by enumerating trust boundaries, assets, attacker capabilities, abuse paths,...
Conducts systematic security analyses using methodologies like STRIDE to identify vulnerabilities in software architectu...
Security scanning toolkit for BFF boundaries and CI/CD. Use when setting up or running gitleaks, semgrep, bandit, trivy,...
Secure boot and firmware update workflows for Zephyr RTOS. Covers MCUboot integration, production image signing, DFU pro...
Runtime security validation including secret scanning, PII detection, prompt injection defense, audit logging, and outpu...
Pre-merge security validation detecting secrets, user-specific paths, insecure SSH configurations, and security-weakenin...
Security protocols and vendor management expertise from Marcus covering emergency response codes, vendor relations, and...
Security-first visual testing combining URL validation, PII detection, and visual regression with parallel viewport supp...
Vite security audit patterns. Load when reviewing Vite apps (vite.config.ts present). Covers VITE_* exposure, build-time...
Workflow for auditing security vulnerabilities using Trunk (Trivy and OSV-scanner). Use when checking for project vulner...
Security researcher reports security vulnerabilities or inquires about bug bounty programs.
Use when creating backlog tasks from security findings, integrating security scans into workflow states, or managing sec...
Document security research, CTF solutions, and malware analysis. Includes REPORT.md and STATUS.md templates.
Run an OWASP ZAP baseline security scan locally using Docker. Checks for the ZAP baseline script, executes the scan, and...
Input Validation security skill