Internal security review pass of the agentic-workflow review pack — composed in-turn by review-change and product-audit; not a menu entry. Checks secrets, input validation, injection, authn/authz, PII exposure, and dependency risk on the changed surface. Findings only; never edits code.
Guideline for designing, implementing, and verifying secure Python applications following OWASP Top 10 best practices. Use when the user wants to: (1) review Python code for security vulnerabilities, (2) design a secure Python application architecture, (3) implement security features (authentication, authorization, cryptography, input validation), (4) audit Python dependencies for known vulnerabilities, (5) create security checklists or verification plans, (6) fix security bugs or harden existing Python code, (7) set up security testing and static analysis (bandit, safety, semgrep), or (8) handle any Python security concern including injection prevention, secure deserialization, SSRF protection, secrets management, and secure deployment.
Sensitive data patterns for security testing: API keys, credit cards, emails, SSNs, phone numbers, IPs, and more. Use for data discovery and validation.
[AUTO-INVOKE] MUST be invoked BEFORE writing or modifying any Solidity contract (.sol files). Covers private key handling, access control, reentrancy prevention, gas safety, and pre-audit checklists. Trigger: any task involving creating, editing, or reviewing .sol source files.
Auditoria de segurança Security by Design. Use quando o usuário pedir "audite a segurança", "security review", "verifique vulnerabilidades", ou antes de subir feature pra produção. Cobre OWASP Top 10, gestão de secrets, AuthN/AuthZ, supply chain e logs.
Use when the user asks for a security review, security audit, vulnerability scan, secret scan, dependency or CVE check, OWASP review, pentest review, compliance evidence, or asks "is this safe to ship". Runs real scanners (Semgrep, gitleaks, TruffleHog, Trivy, osv-scanner) over code, full git history, dependencies, IaC, and Supabase/Firebase row-level security, verifies each finding against source, and writes one severity-ranked report.
Audit host security using built-in system tools (netstat, lsof, ss, ufw, systemctl, ps, who, last). Check open ports, running services, listening processes, firewall rules, and recent logins. No external CLI needed. Use when user says "security audit", "check open ports", "harden server", or "what's listening on my machine".
Commands, step-by-step procedures, and mechanical execution for performing deep security audits, vulnerability assessments, and report generation on codebases and configurations. You MUST load this skill when performing security audits or validation.
Audit a surface for security problems, score them honestly, and turn each into a task with a fix. Use before declaring work done, after wiring an integration, before a deploy handoff, or when the user says \"/security-audit\", \"check security\", \"audit this\", \"is this safe\". Builds the checklist from general application-security concerns plus the per-integration items in the integrations registry. Reports findings with severity, file:line and evidence; states which fixes it applied and which need a human decision; never prints secrets.
Audits the application against OWASP Top 10:2025 / ASVS for the project's stack — code review by appsec-engineer, tooling (vulnerability, secret and SAST scanners), CVSS-scored findings with fixes in docs/security/security-audit-<date>.md; modes full, quick, api, auth, infra, <path>. Required before release; use for 'security audit', 'is this secure', 'OWASP check', 'review the auth code'.
Whole-repo leak-surface security audit of corp-llm-gateway against its zero-leak criterion and the 6 CLAUDE.md invariants — sanitizer coverage, NEVER-gate, auth/tokens, placeholder bijection, egress/DLP. Produces CONFIRMED/SUSPECTED findings with file:line + fixes. Use for "security audit", "sec-audit", "find leak paths", "do the invariants still hold". For reviewing a pending diff instead, use the built-in security-review.
Security audit methodology. OWASP Top 10 + STRIDE threat model with zero-noise false positive filtering. Checks API key exposure, database rules, XSS vectors, CSRF, auth bypass. Use when handling user data or preparing for production.
Комплексный аудит безопасности приложений, API, репозиториев, AI/agent-систем, MCP-интеграций, инфраструктуры и цепочки поставок. Использовать при явном запросе — «аудит безопасности», «security audit», «проверь на уязвимости», «security review», «threat model», «hardening», «проверка перед продакшеном», «prompt injection», «MCP security», — а также при secure-design review или планировании авторизованного пентеста. Не использовать для обычного code review, отладки или рефакторинга без запроса о безопасности.
Use this skill when implementing or reviewing security in a Spring Boot application. Covers authentication, authorization, input validation, secure configuration, and API security best practices.
A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.
How do I use one I find here?
Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.
What do the warnings mean?
We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.
Which skills worked for people?
Open a skill to see its discussion. Reports from people and their agents are coming.