SkillsNav
Home

Vulnerability Scan

78 skills · sorted by GitHub stars

varlock
Secure-by-default environment variable management for Claude Code sessions.
★ 3.6K reposecurity
ffuf-claude-skill
Web fuzzing with ffuf
★ 185 reposecurity
varlock-claude-skill
Secure environment variable management ensuring secrets are never exposed in Claude sessions, termin
★ 25 reposecurity
007
Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review,
security
active-directory-attacks
Provide comprehensive techniques for attacking Microsoft Active Directory environments. Covers recon
security
anti-reversing-techniques
AUTHORIZED USE ONLY: This skill contains dual-use security techniques. Before proceeding with any by
security
attack-tree-construction
Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, ident
security
audit-skills
Expert security auditor for AI Skills and Bundles. Performs non-intrusive static analysis to identif
security
auth-implementation-patterns
Build secure, scalable authentication and authorization systems using industry-standard patterns and
security
aws-compliance-checker
Automated compliance checking against CIS, PCI-DSS, HIPAA, and SOC 2 benchmarks
security
aws-iam-best-practices
IAM policy review, hardening, and least privilege implementation
security
aws-secrets-rotation
Automate AWS secrets rotation for RDS, API keys, and credentials
security
aws-security-audit
Comprehensive AWS security posture assessment using AWS CLI and security best practices
security
binary-analysis-patterns
Comprehensive patterns and techniques for analyzing compiled binaries, understanding assembly code,
security
broken-authentication
Identify and exploit authentication and session management vulnerabilities in web applications. Brok
security
bumblebee
Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised package
security
burp-suite-testing
Execute comprehensive web application security testing using Burp Suite's integrated toolset, includ
security
burpsuite-project-parser
Searches and explores Burp Suite project files (.burp) from the command line. Use when searching res
security
constant-time-analysis
Analyze cryptographic code to detect operations that leak secret data through execution timing varia
security
container-security-hardening
Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE
security
cred-omega
CISO operacional enterprise para gestao total de credenciais e segredos.
security
dependency-management-deps-audit
You are a dependency security expert specializing in vulnerability scanning, license compliance, and
security
differential-review
Security-focused code review for PRs, commits, and diffs.
security
ethical-hacking-methodology
Master the complete penetration testing lifecycle from reconnaissance through reporting. This skill
security
ffuf-web-fuzzing
Expert guidance for ffuf web fuzzing during penetration testing, including authenticated fuzzing wit
security
file-path-traversal
Identify and exploit file path traversal (directory traversal) vulnerabilities that allow attackers
security
file-uploads
Expert at handling file uploads and cloud storage. Covers S3, Cloudflare R2, presigned URLs, multipa
security
firmware-analyst
Expert firmware analyst specializing in embedded systems, IoT security, and hardware reverse enginee
security
frontend-security-coder
Expert in secure frontend coding practices specializing in XSS prevention, output sanitization, and
security
fsi-compliance-checker
Maps code, architecture, and infrastructure changes to specific control IDs in PCI-DSS v4.0 and MAS
security
gdpr-data-handling
Practical implementation guide for GDPR-compliant data processing, consent management, and privacy c
security
gha-security-review
Find exploitable vulnerabilities in GitHub Actions workflows. Every finding MUST include a concrete
security
html-injection-testing
Identify and exploit HTML injection vulnerabilities that allow attackers to inject malicious HTML co
security
idor-testing
Provide systematic methodologies for identifying and exploiting Insecure Direct Object Reference (ID
security
laravel-security-audit
Security auditor for Laravel applications. Analyzes code for vulnerabilities, misconfigurations, and
security
linux-privilege-escalation
Execute systematic privilege escalation assessments on Linux systems to identify and exploit misconf
security
malware-analyst
Expert malware analyst specializing in defensive malware research, threat intelligence, and incident
security
memory-forensics
Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for in
security
metasploit-framework
⚠️ AUTHORIZED USE ONLY > This skill is for educational purposes or authorized security assessments o
security
mtls-configuration
Configure mutual TLS (mTLS) for zero-trust service-to-service communication. Use when implementing z
security
pci-compliance
Master PCI DSS (Payment Card Industry Data Security Standard) compliance for secure payment processi
security
pentest-checklist
Provide a comprehensive checklist for planning, executing, and following up on penetration tests. En
security
pentest-commands
Provide a comprehensive command reference for penetration testing tools including network scanning,
security
privacy-by-design
Use when building apps that collect user data. Ensures privacy protections are built in from the sta
security
privilege-escalation-methods
Provide comprehensive techniques for escalating privileges from a low-privileged user to root/admini
security
production-audit
Audit a shipped repo for production-readiness gaps across RLS, webhooks, secrets, grants, Stripe ide
security
protocol-reverse-engineering
Comprehensive techniques for capturing, analyzing, and documenting network protocols for security re
security
red-team-tactics
Red team tactics principles based on MITRE ATT&CK. Attack phases, detection evasion, reporting.
security
red-team-tools
Implement proven methodologies and tool workflows from top security researchers for effective reconn
security
reverse-engineer
Expert reverse engineer specializing in binary analysis, disassembly, decompilation, and software an
security