Claude
Skills
Sign in
← All categories

security

23 skills · 0 free · cap $19/skill or unlock all for $99

bumblebee

Included

Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs.

securityscripts

production-audit

Included

Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe idempotency, mobile UX, and deployment health.

security

audit-skills

Included

Expert security auditor for AI Skills and Bundles. Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated payloads across Windows, macOS, Linux/Unix, and Mobile (Android/iOS).

security

skill-audit

Included

Pre-install security scanner for AI agent skills. 7.5% of 14,706 skills are malicious. Audit before you trust.

security

agent-skill-trust-check

Included

Static pre-install trust review for SKILL.md, OpenClaw, Hermes, MCP, and agent-skill marketplace packages before they request local, account, payment, or external access.

security

network-security-setup

Included

Configure Claude Code sandbox network isolation with trusted domains, custom access policies, and environment variables

security

container-security-hardening

Included

Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls. Use for Dockerfile security reviews, container CVEs, image scanning, distroless images, or production hardening.

security

aws-compliance-checker

Included

Automated compliance checking against CIS, PCI-DSS, HIPAA, and SOC 2 benchmarks

security

aws-secrets-rotation

Included

Automate AWS secrets rotation for RDS, API keys, and credentials

security

aws-iam-best-practices

Included

IAM policy review, hardening, and least privilege implementation

security

aws-security-audit

Included

Comprehensive AWS security posture assessment using AWS CLI and security best practices

security

aws-compliance-checker

Included

Automated compliance checking against CIS, PCI-DSS, HIPAA, and SOC 2 benchmarks

security

aws-iam-best-practices

Included

IAM policy review, hardening, and least privilege implementation

security

aws-secrets-rotation

Included

Automate AWS secrets rotation for RDS, API keys, and credentials

security

aws-security-audit

Included

Comprehensive AWS security posture assessment using AWS CLI and security best practices

security

harden

Included

Applies NIST/CWE security hardening to Python and Rust code. Use when auditing code for vulnerabilities or proposing concrete security remediations.

security

web-pentest

Included

Authorized web application penetration testing — reconnaissance, vulnerability analysis, proof-based exploitation, and professional reporting. Adapts Shannon's "No Exploit, No Report" methodology with hard guardrails for scope, authorization, and aux-client leakage. Active testing against running applications you own or have written authorization to test.

securityscripts

oss-forensics

Included

Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories. Covers deleted commit recovery, force-push detection, IOC extraction, multi-source evidence collection, hypothesis formation/validation, and structured forensic reporting. Inspired by RAPTOR's 1800+ line OSS Forensics system.

securityscripts

Security Architect

Included

Comprehensive security architecture combining threat modeling, security-first design, secure coding review, and compliance validation. Consolidated from threat-modeling, security-first-design, secure-coding-review, and compliance-validator.

security

audit-expert

Included

Expert-level security auditing, compliance, code review, and vulnerability assessment

security

security-expert

Included

Expert-level application security, OWASP Top 10, penetration testing, and security best practices

security

Security Monitoring

Included

Automate security monitoring, threat detection, incident response, and compliance workflows

security

codeql-expert

Included

Expert-level CodeQL for static analysis, vulnerability detection, and security code scanning

security

More categories