mycelium-hqSkillmycelium-hq/ai-brain-starter/skills/security-snapshot/SKILL.md
Use when the user says /security-snapshot, /snapshot <domain>, "run a security check on X", "generate a security report for [company]", or wants a security hygiene snapshot or free lead-magnet report on a prospect''s public domain: SSL/TLS grade, HTTP security headers, SPF/DMARC email authentication, server fingerprint leaks. Passive, unauthenticated scans only. NOT for penetration testing, internal infrastructure audits, or application-layer vulnerability assessment.
bis-codeSkillbis-code/claude-toolkit/.claude/skills/security-review/SKILL.md
Run an OWASP-focused security analysis on code changes.
borkwebSkillborkweb/skills/skills/core/review-security/SKILL.md
Deep security review of a diff or a specific file, grounded in 20 evidence-based pattern libraries extracted from 400+ real-world bugs in major open-source projects (Linux kernel, OpenSSL, Chromium, Firefox, curl, Go, Rust, Kubernetes, Next.js, etc.). Use when the user says "security review", "security audit", "audit this for vulnerabilities", "threat model this", "check for CVEs", "check for injection/auth/crypto issues", or when a diff touches buffer handling, parsers, authentication, authorization, cryptography, state machines, CI/CD, dependencies, or trust boundaries. Also usable as a reference library — `/review` links here when a diff touches a security-sensitive area.
kauffjSkillkauffj/agent-config/skills/review-security/SKILL.md
Review changed code for authorization gaps, input validation failures, data exposure, and injection vulnerabilities
mgiovaniSkillmgiovani/cc-arsenal/skills/review-security/SKILL.md
Perform an OWASP Top 10-focused static security review of a PR, commit, or
StormixSkillStormix/transcripts-mcp/.agents/skills/security-review/SKILL.md
Finds exploitable application security vulnerabilities in code changes. Use for Warden security scans, appsec review, OWASP-style checks, authentication or authorization bugs, injection, XSS, SSRF, path traversal, secrets, unsafe crypto, webhook verification, open redirects, or sensitive data exposure.
BejeweledMeSkillBejeweledMe/codex-pro-agent-skills/skills/security-review/SKILL.md
Assess security claims for a scoped design, application change, release, repository, or OSS dependency. Use for abuse-path review, application-verification evidence, supplier posture, and security findings or release recommendations; ordinary maintainability review belongs to software-engineering.
rambozSkillramboz/jig/skills/security-review/SKILL.md
Team baseline for security review — a best-effort heuristic security pass over a diff or change-set. Auto-triggers for review this for security, any vulnerabilities here, security pass on this diff, is this code secure, check this for security issues, or security review this. Uses installed scanners when available; installs nothing. Defers to any other installed skill whose description identifies it as handling security review, SAST, or vulnerability analysis, including `adobe-security-*`; prefer it over this slim baseline. Do not use for spec-compliance review (use `/jig:independent-review`), general PR craft (use `/jig:pr-review`), or secret prevention (`jig-secret-scan`).
5hirishSkill5hirish/duct/.agents/skills/security-audit/SKILL.md
Run deep local security audits for backend and app changes to catch secrets exposure, DB compromise vectors, and user privacy risks before PRs.
AlexandruTeodorofSkillAlexandruTeodorof/Alex-Skills/security-audit/SKILL.md
Performs comprehensive OWASP ASVS v5 security audits on any codebase (supersedes OWASP Top 10). ALWAYS invoke when the user asks to: review code for security issues, perform a security audit, find vulnerabilities or security weaknesses, check for security improvements, check for CVEs, do a pentest review, or uses words like "audit", "vulnerabilities", "security review", "security check", "secure code", "harden", or "penetration test". Also invoke for any general "code review" request — security is part of every good code review.
alizafarbatiSkillalizafarbati/opencode-agents-mcp/skills/security-audit/SKILL.md
Expert security architect specializing in threat modeling, red teaming, cloud security, zero-trust architecture, and enterprise security assessment.
AL-JANEFSkillAL-JANEF/janefskills/skills/security/security-audit/SKILL.md
Audit-grade multi-layer security pass: Semgrep SAST, Gitleaks secret scanning, and dependency audit as deterministic ground truth, then specialist review, variant analysis, fix verification, timing review, and an honest coverage verdict naming what was and was not covered. Use for "full security pass", security audit, pre-launch review, or any serious security assessment. Defensive only.
art12slavikSkillart12slavik/skill-security-audit/SKILL.md
Run a structured security audit of Linux servers and self-hosted stacks, then harden what's found. Covers Ubuntu/Debian hardening (SSH, sudo, firewall, kernel sysctls, systemd isolation, patching), Docker and container escape paths, exposed datastores (Redis, Postgres, Qdrant, MongoDB), secrets handling, and AI agent risks such as webhook authentication, tool permissions, and prompt injection reaching real tool calls. Use whenever the user asks to audit, review, harden, or lock down a server, VPS, container stack, or agent deployment — and for narrower questions that are really audit questions, like "is my Redis exposed", "is this server safe", "чи безпечний мій сервер", "проведи аудит серверів", "закрий вразливості", or "why is this port open" — or when they paste a docker-compose.yml, sshd_config, or firewall ruleset and ask whether it looks right. Prefer this over ad-hoc checking, since it enforces read-only diagnostics, consistent severity ratings, and a repeatable report.
cvszSkillcvsz/zomega/skills/security-tests/SKILL.md
zomega Skill 082: security-tests
## Owner
`zomega-security`
## Objective
Execute `security-tests` as a production engineering operation with traceable evidence.
## Procedure
1. Validate the supplied objective, scope, environment, and constraints
dawn840705Skilldawn840705/claude-code-studios/skills/security-audit/SKILL.md
Audit the game for security vulnerabilities: save tampering, cheat vectors, network exploits, data exposure, and input validation gaps. Produces a prioritised security report with remediation guidance. Run before any public release or multiplayer launch.
drafaelSkilldrafael/coding-harness/skills/owasp-security/SKILL.md
Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, and Agentic AI security (2026).
evgenii-studitskikhSkillevgenii-studitskikh/Claude-Code-SaaS-Studio/.claude/skills/security-audit/SKILL.md
Audit the SaaS codebase (or a diff) against the path-scoped rules and an OWASP-style SaaS checklist: auth/session, RLS/tenant isolation, secrets, input validation, Stripe webhook verification, dependency vulnerabilities. Produces a severity-ranked findings report.
farditaSkillfardita/ai-config/skills/security-audit/SKILL.md
Security audit of a codebase — web apps, APIs, services, CLI tools, libraries, daemons, and more. Use when asked to find security bugs, do a security review, audit for vulnerabilities, or pen-test the code. Focuses on exploitable issues with real impact, not theoretical concerns or industry-standard behavior.
GabrielYMCSkillGabrielYMC/security-audit/SKILL.md
Pre-deployment security audit for web projects, especially vibe-coded ones. Use this skill whenever the user asks to review their project for security issues, wants a vulnerability scan before deploying, mentions 'security check', 'is my app secure', 'check for vulns', or any pre-launch safety concern. Also trigger for 'I built this with AI, is it safe?', 'review before production', or 'check for hardcoded secrets'. Covers secrets, auth, input validation, data protection, infrastructure, headers, and AI/LLM security. Works on any scope: full repo, single module, single file, or code snippet.
iabhisekbosepmSkilliabhisekbosepm/claude-god-setup/.claude/skills/security-audit/SKILL.md
Run a full security audit: OWASP Top 10, secrets detection, input validation, auth, dependency vulnerabilities.