Free 40-page Claude guide — setup, 120 prompt codes, MCP servers, AI agents. Download free →
CLSkills
Security

Security

Audit vulnerabilities and harden your application

86 skills

Securitybeginner

Dependency Audit

Audit dependencies for known vulnerabilities

securityauditdependencies
Securitybeginner

Secret Scanner

Scan codebase for leaked secrets and credentials

securitysecretsscanning
Securityintermediate

CSP Generator

Generate Content Security Policy headers

securitycspheaders
Securityintermediate

Input Sanitizer

Add input sanitization to prevent injection attacks

securitysanitizationinjection
Securityintermediate

Auth Middleware

Create authentication middleware

securityauthmiddleware
Securityadvanced

RBAC Setup

Implement role-based access control

securityrbacauthorization
Securityintermediate

CSRF Protection

Add CSRF protection to forms and APIs

securitycsrfprotection
Securitybeginner

Security Headers

Configure security headers (HSTS, X-Frame-Options, etc.)

securityheadersconfiguration
Securityadvanced

Encryption Helper

Set up encryption for sensitive data at rest

securityencryptiondata
Securityadvanced

API Key Rotation

Implement API key rotation mechanism

securityapi-keysrotation
Securityintermediate

SQL Injection Guard

Review and fix SQL injection vulnerabilities

securitysql-injectionaudit
Securityintermediate

XSS Prevention

Audit and fix XSS vulnerabilities

securityxssprevention
Securitybeginner

Secure Cookie Setup

Configure secure cookie settings

securitycookiesconfiguration
Securityadvanced

Penetration Test Checklist

Generate security testing checklist for the app

securitypentestingchecklist
Securityintermediate

atlassian-admin

Atlassian Administrator for managing and organizing Atlassian products (Jira, Confluence, Bitbucket, Trello), users, permissions, security, integrations, system configuration, and org-wide governance.

communityalirezarezvani
Securityintermediate

ciso-advisor

Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and board

communityalirezarezvani
Securityintermediate

google-workspace-cli

Google Workspace administration via the gws CLI. Install, authenticate, and automate Gmail, Drive, Sheets, Calendar, Docs, Chat, and Tasks. Run security audits, execute 43 built-in recipes, and use 10

communityalirezarezvani
Securityintermediate

security-pen-testing

Use when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. Covers static analysis, dependency scanning, sec

communityalirezarezvani
Securityintermediate

senior-secops

Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST scans, generates CVE remediation plans, check

communityalirezarezvani
Securityintermediate

senior-security

Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP guidance, cryptography patterns, and security sc

communityalirezarezvani
Securityintermediate
communityalirezarezvani
Securityintermediate

tech-stack-evaluator

Technology stack evaluation and comparison with TCO analysis, security assessment, and ecosystem health scoring. Use when comparing frameworks, evaluating technology stacks, calculating total cost of

communityalirezarezvani
Securityintermediate

anti-reversing-techniques

AUTHORIZED USE ONLY: This skill contains dual-use security techniques. Before proceeding with any bypass or analysis: > 1.

communityantigravity
Securityintermediate

api-security-best-practices

Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities

communityantigravity
Securityintermediate

attack-tree-construction

Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.

communityantigravity
Securityintermediate

audit-context-building

Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.

communityantigravity
Securityintermediate

audit-skills

Expert security auditor for AI Skills and Bundles. Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated payloads across Windows, ma

communityantigravity
Securityintermediate

auth-implementation-patterns

Build secure, scalable authentication and authorization systems using industry-standard patterns and modern best practices.

communityantigravity
Securityintermediate

aws-compliance-checker

Automated compliance checking against CIS, PCI-DSS, HIPAA, and SOC 2 benchmarks

communityantigravity
Securityintermediate

aws-iam-best-practices

IAM policy review, hardening, and least privilege implementation

communityantigravity
Securityintermediate

aws-secrets-rotation

Automate AWS secrets rotation for RDS, API keys, and credentials

communityantigravity
Securityintermediate

aws-security-audit

Comprehensive AWS security posture assessment using AWS CLI and security best practices

communityantigravity
Securityintermediate

azure-communication-common-java

Azure Communication Services common utilities for Java. Use when working with CommunicationTokenCredential, user identifiers, token refresh, or shared authentication across ACS services.

communityantigravity
Securityintermediate

azure-identity-dotnet

Azure Identity SDK for .NET. Authentication library for Azure SDK clients using Microsoft Entra ID. Use for DefaultAzureCredential, managed identity, service principals, and developer credentials.

communityantigravity
Securityintermediate

azure-identity-java

Authenticate Java applications with Azure services using Microsoft Entra ID (Azure AD).

communityantigravity
Securityintermediate

azure-identity-py

Azure Identity SDK for Python authentication. Use for DefaultAzureCredential, managed identity, service principals, and token caching.

communityantigravity
Securityintermediate

azure-identity-rust

Azure Identity SDK for Rust authentication. Use for DeveloperToolsCredential, ManagedIdentityCredential, ClientSecretCredential, and token-based authentication.

communityantigravity
Securityintermediate

azure-identity-ts

Authenticate to Azure services with various credential types.

communityantigravity
Securityintermediate

azure-security-keyvault-keys-dotnet

Azure Key Vault Keys SDK for .NET. Client library for managing cryptographic keys in Azure Key Vault and Managed HSM. Use for key creation, rotation, encryption, decryption, signing, and verification.

communityantigravity
Securityintermediate

backend-security-coder

Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.

communityantigravity
Securityintermediate

broken-authentication

Identify and exploit authentication and session management vulnerabilities in web applications. Broken authentication consistently ranks in the OWASP Top 10 and can lead to account takeover, identity

communityantigravity
Securityintermediate

browser-extension-builder

You extend the browser to give users superpowers. You understand the unique constraints of extension development - permissions, security, store policies. You build extensions that people install and a

communityantigravity
Securityintermediate

burp-suite-testing

Execute comprehensive web application security testing using Burp Suite's integrated toolset, including HTTP traffic interception and modification, request analysis and replay, automated vulnerability

communityantigravity
Securityintermediate

burpsuite-project-parser

Searches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with regex patterns, extracting security audit findings, dumping proxy histo

communityantigravity
Securityintermediate

cc-skill-security-review

This skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing authentication or authorization, handling user input or file uploads, or cre

communityantigravity
Securityintermediate

clerk-auth

Expert patterns for Clerk auth implementation, middleware, organizations, webhooks, and user sync Use when: adding authentication, clerk auth, user authentication, sign in, sign up.

communityantigravity
Securityintermediate

codebase-cleanup-deps-audit

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, ou

communityantigravity
Securityintermediate

content-strategy

Plan a content strategy, topic clusters, editorial roadmap, and content mix for traffic, authority, and lead generation. Use when deciding what to publish, what topics to prioritize, or how to structu

communityantigravity
Securityintermediate

dependency-management-deps-audit

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, ou

communityantigravity
Securityintermediate

frontend-security-coder

Expert in secure frontend coding practices specializing in XSS prevention, output sanitization, and client-side security patterns.

communityantigravity
Securityintermediate

gmail-automation

Lightweight Gmail integration with standalone OAuth authentication. No MCP server required.

communityantigravity
Securityintermediate

google-calendar-automation

Lightweight Google Calendar integration with standalone OAuth authentication. No MCP server required.

communityantigravity
Securityintermediate

google-docs-automation

Lightweight Google Docs integration with standalone OAuth authentication. No MCP server required.

communityantigravity
Securityintermediate

google-drive-automation

Lightweight Google Drive integration with standalone OAuth authentication. No MCP server required. Full read/write access.

communityantigravity
Securityintermediate

google-sheets-automation

Lightweight Google Sheets integration with standalone OAuth authentication. No MCP server required. Full read/write access.

communityantigravity
Securityintermediate

google-slides-automation

Lightweight Google Slides integration with standalone OAuth authentication. No MCP server required. Full read/write access.

communityantigravity
Securityintermediate

hubspot-integration

Authentication for single-account integrations

communityantigravity
Securityintermediate

laravel-security-audit

Security auditor for Laravel applications. Analyzes code for vulnerabilities, misconfigurations, and insecure practices using OWASP standards and Laravel security best practices.

communityantigravity
Securityintermediate

linkerd-patterns

Production patterns for Linkerd service mesh - the lightweight, security-first service mesh for Kubernetes.

communityantigravity
Securityintermediate

linux-privilege-escalation

Execute systematic privilege escalation assessments on Linux systems to identify and exploit misconfigurations, vulnerable services, and security weaknesses that allow elevation from low-privilege use

communityantigravity
Securityintermediate

m365-agents-dotnet

Microsoft 365 Agents SDK for .NET. Build multichannel agents for Teams/M365/Copilot Studio with ASP.NET Core hosting, AgentApplication routing, and MSAL-based auth.

communityantigravity
Securityintermediate

metasploit-framework

⚠️ AUTHORIZED USE ONLY > This skill is for educational purposes or authorized security assessments only. > You must have explicit, written permission from the system owner before using this tool. > Mi

communityantigravity
Securityintermediate

microsoft-azure-webjobs-extensions-authentication-events-dotnet

Microsoft Entra Authentication Events SDK for .NET. Azure Functions triggers for custom authentication extensions.

communityantigravity
Securityintermediate

nodejs-best-practices

Node.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.

communityantigravity
Securityintermediate

odoo-security-rules

Expert in Odoo access control: ir.model.access.csv, record rules (ir.rule), groups, and multi-company security patterns.

communityantigravity
Securityintermediate

pci-compliance

Master PCI DSS (Payment Card Industry Data Security Standard) compliance for secure payment processing and handling of cardholder data.

communityantigravity
Securityintermediate

privacy-by-design

Use when building apps that collect user data. Ensures privacy protections are built in from the start—data minimization, consent, encryption.

communityantigravity
Securityintermediate

saas-mvp-launcher

Use when planning or building a SaaS MVP from scratch. Provides a structured roadmap covering tech stack, architecture, auth, payments, and launch checklist.

communityantigravity
Securityintermediate

scanning-tools

Master essential security scanning tools for network discovery, vulnerability assessment, web application testing, wireless security, and compliance validation. This skill covers tool selection, confi

communityantigravity
Securityintermediate

security-bluebook-builder

Build a minimal but real security policy for sensitive apps. The output is a single, coherent Blue Book document using MUST/SHOULD/CAN language, with explicit assumptions, scope, and security gates.

communityantigravity
Securityintermediate

security-scanning-security-dependencies

You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilitie

communityantigravity
Securityintermediate

security-scanning-security-hardening

Coordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls.

communityantigravity
Securityintermediate

security-scanning-security-sast

'Static Application Security Testing (SAST) for code vulnerability

communityantigravity
Securityintermediate

semgrep-rule-creator

Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.

communityantigravity
Securityintermediate

seo-authority-builder

'Analyzes content for E-E-A-T signals and suggests improvements to

communityantigravity
Securityintermediate

slack-bot-builder

The Bolt framework is Slack's recommended approach for building apps. It handles authentication, event routing, request verification, and HTTP request processing so you can focus on app logic.

communityantigravity
Securityintermediate

smtp-penetration-testing

Conduct comprehensive security assessments of SMTP (Simple Mail Transfer Protocol) servers to identify vulnerabilities including open relays, user enumeration, weak authentication, and misconfiguratio

communityantigravity
Securityintermediate

solidity-security

Master smart contract security best practices, vulnerability prevention, and secure Solidity development patterns.

communityantigravity
Securityintermediate

ssh-penetration-testing

Conduct comprehensive SSH security assessments including enumeration, credential attacks, vulnerability exploitation, tunneling techniques, and post-exploitation activities. This skill covers the comp

communityantigravity
Securityintermediate

stride-analysis-patterns

Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.

communityantigravity
Securityintermediate

supply-chain-risk-auditor

Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security engagements.

communityantigravity
Securityintermediate

threat-mitigation-mapping

Map identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control effectiveness.

communityantigravity
Securityintermediate

threat-modeling-expert

Expert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security requirement extraction. Use PROACTIVELY for security archi

communityantigravity
Securityintermediate

top-web-vulnerabilities

Provide a comprehensive, structured reference for the 100 most critical web application vulnerabilities organized by category. This skill enables systematic vulnerability identification, impact assess

communityantigravity
Securityintermediate

vulnerability-scanner

Advanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization.

communityantigravity
Securityintermediate

xss-html-injection

Execute comprehensive client-side injection vulnerability assessments on web applications to identify XSS and HTML injection flaws, demonstrate exploitation techniques for session hijacking and creden

communityantigravity