danielvm-gitSkilldanielvm-git/bigpowers/skills/security-review/SKILL.md
AI-powered security analysis of code changes — traces data flow, detects injection, auth bypass, secrets exposure, and unsafe deserialization across files. Use when reviewing pending changes, before release-branch, during verify-work Phase 5, during build-epic Step 0 threat modeling, or when the user says "security review" or "scan for vulns".
cloudsmith-labsSkillcloudsmith-labs/claude-code-skills/skills/csm-security/SKILL.md
Investigate security posture in Cloudsmith — vulnerabilities, quarantine, and audit logs. Use when the user wants to scan an org, repository, or package for CVEs/vulnerabilities, investigate a specific CVE, review or manage quarantined packages, see who changed or deleted something (audit log), review security events, or get a security summary before a release or promotion.
HarambeeAISkillHarambeeAI/bayes-ship/skills/security-scan/SKILL.md
Security scanning against OWASP Top 10, secret detection, input validation, auth hardening. Used by the security reviewer during QA phase. Source: everything-claude-code.
johnclawsonSkilljohnclawson/claude-skills/security-qbr/SKILL.md
Generate Quarterly Business Review (QBR) presentations for Information Security teams. Use this skill when creating QBR decks, quarterly security reviews, or executive briefings about security posture for CIO/CTO audiences. Covers content structure (risks, accomplishments, current work, KPIs), writing style, and slide organization. Triggers on requests for security QBRs, quarterly InfoSec reviews, CISO presentations, or security executive briefings.
maridlabsaiSkillmaridlabsai/jini/.claude/skills/security-scan/skill.md
Security Scan
Use this skill for public Jini security review.
## Procedure
1. Scan changed files for secrets, credentials, private URLs, customer details, pricing strategy, and commercial rollout material
morodomiSkillmorodomi/dev-crew/skills/security-scan/SKILL.md
セキュリティスキャンを実行。RECON→SCAN→REPORT→LEARNワークフローで脆弱性を検出。「セキュリティスキャン」「security scan」「脆弱性チェック」「セキュリティ診断」「OWASPチェック」で起動。Do NOT use for レポートのみ(→ attack-report)やスキャン+レポート一括(→ security-audit)。
NemesLaszloSkillNemesLaszlo/Agent-Collection/.claude/skills/security-scan/SKILL.md
Security vulnerability scan using the Security Vulnerability Scanner agent workflow. Use when the user says security scan, check for vulnerabilities, security audit, is this secure, OWASP check, or before deploying to production.
novatsinghSkillnovatsingh/agentkick/.claude/skills/security-scan/SKILL.md
security scan workflow for disciplined AI coding agents.
shivae372Skillshivae372/claude-bootstrap/.claude/skills/security-scan/SKILL.md
Security audit skill. Invoke before deploying, after adding auth code, or when reviewing for vulnerabilities. Auto-activates on "security check", "check for vulnerabilities", "pre-deploy audit", "scan for secrets", "is this auth secure". Routes to security-scanner sub-agent.
ZeroTokenClawSkillZeroTokenClaw/agents-skills/security-scan/SKILL.md
对进入系统的文件或 URL 执行安全与合规扫描,输出 pass/reject 判定与扫描报告,作为所有文档处理的强制前置关卡。
zhao-wuyanSkillzhao-wuyan/ccw-command-explorer/.claude/skills/security-audit/SKILL.md
OWASP Top 10 and STRIDE security auditing with supply chain analysis. Triggers on "security audit", "security scan", "cso".
kklimukSkillkklimuk/docx-cli/.claude/skills/security-review/SKILL.md
Review code for security vulnerabilities. Use when the user says 'security review', 'security audit', 'check for vulnerabilities', 'pentest the code', 'OWASP check', or any variation of wanting a security assessment.
netresearchSkillnetresearch/security-audit-skill/skills/security-audit/SKILL.md
Use when conducting security assessments — OWASP Top 10 / API / LLM, CWE Top 25, CVSS scoring — auditing PHP/TYPO3, APIs, frontend, Terraform/K8s/Docker IaC, AWS cloud, AI agent configs, or scanning dependencies.
daemon-blockint-techSkilldaemon-blockint-tech/Agentic-Enteprises-Skill/code-security/SKILL.md
Guides secure coding and security-focused code review across languages and infrastructure—OWASP-oriented vulnerability patterns (injection, XSS, auth, crypto, deserialization, SSRF, XXE), secrets handling, and IaC security (Terraform, Kubernetes, Docker, GitHub Actions). Use when writing or reviewing code that handles user input, authentication, files, databases, network requests, cryptography, or infrastructure config—or when the user asks to check for SQL injection, XSS, SSRF, hardcoded secrets, OWASP issues, Terraform security, or GitHub Actions security. Not for authorized penetration test engagements (ai-redteam, cybersecurity), compliance program mapping (compliance-engineer), YARA/malware rules (yara-rule-authoring), or CI pipeline setup only (devsecops).
cyber-sortedSkillcyber-sorted/skills-pro/cybersorted/SKILL.md
Security and enterprise architecture advisory skill. Use this skill when the user needs help with cybersecurity strategy, threat modeling, risk assessment, compliance, security architecture, enterprise architecture, or governance. Trigger when the user mentions: security posture, threat model, STRIDE, PASTA, risk assessment, risk register, compliance mapping, SOC2, ISO 27001, NIST 800-53, CIS benchmarks, MITRE ATT&CK, zero trust, incident response, IR plan, security policy, architecture decision record, ADR, vendor risk, third-party risk, board briefing, security maturity, maturity assessment, gap analysis, security review, code review for security, IaC review, Terraform security, Kubernetes security, CI/CD security, API security, cloud configuration review, tabletop exercise, red team, blue team, penetration test planning, security architecture, network segmentation, defense in depth, least privilege, data classification, encryption strategy, key management, identity and access management, IAM, SIEM, SOC, vulnerability management, patch management, business continuity, disaster recovery, BCP, DRP, privacy by design, GDPR, CCPA, data protection, platform security, build vs buy security, DevSecOps, shift left security, supply chain security, SBOM, secure coding, secure by design, OWASP Top 10, OWASP ASVS, OWASP SAMM, input validation, output encoding, SQL injection prevention, XSS prevention, CSRF prevention, secrets management, dependency security, SAST, DAST, SCA, secure API design, penetration test, pentest, pen test, red team, offensive security, vulnerability assessment, exploit, Kerberoasting, Active Directory attack, privilege escalation, lateral movement, CVSS, CSTM, Cyber Scheme, web application testing, network penetration test, cloud penetration test, container security testing, physical security assessment, or any security and architecture advisory request. Supports roles: CISO, CTO, CPO, Security Architect, Security Engineer, Enterprise Architect, Secure Developer, Penetration Tester.
hyperlogueSkillhyperlogue/r3/.claude/skills/security-model/SKILL.md
r3's Host/origin/auth guards, isolated artifact preview and closed network policy, local and remote daemon configuration, publisher-side harness credentials, byte/path guards, migration storage, and dependency cooldown. Use when changing authentication, artifact or preview routes, resource serving, exposure settings, remote transport, or reviewing security impact.
romaraytSkillromarayt/raytsystem-public-os/.agents/skills/security-review/SKILL.md
Audit raytsystem changes for prompt injection, provenance bypass, path/symlink/hardlink escape, secret leakage, stale fencing, partial promotion, unsafe parsing, and unapproved side effects. Use for SECURITY REVIEW, adversarial testing, recovery review, or approval-boundary validation; remain independent and read-only.
georgekhananaevSkillgeorgekhananaev/claude-skills-vault/.claude/skills/owasp-security/SKILL.md
Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, and Agentic AI security (2026).
wulaosijiSkillwulaosiji/skills/security-drill/SKILL.md
AI Agent自动化安全演练与攻击模拟测试工具,运行定时攻击场景(prompt注入、社会工程学、命令绕过、信息泄露、模型降级),验证事件响应和加固控制有效性,输出通过/失败报告。 Use when: "安全演练", "攻防测试", "攻击模拟", "security drill", "attack simulation", "渗透测试", "incident response test", "red team exercise". 在隔离环境中模拟攻击,不修改真实系统,结果本地存储,支持每周定时执行。Cross-references: security-hardening, skill-security-audit, secure-key-manager. Built by UniqueClub 🌐 https://uniqueclub.ai
henryvn27Skillhenryvn27/orca-framework/skills/orca-security/SKILL.md
Review security-relevant behavior, install scripts, CI, data handling, and unsafe agent instructions.