
Claude Skills by 26zl
github.com/26zl'This skill covers implementing Okta as a centralized identity provider
Use when the MCP server may be out of sync with bash sources after editing tools_db.py, profiles.py, lib/common.sh MODULE_DESCRIPTIONS, lib/installers.sh ALL_DOCKER_IMAGES, or scripts/verify.sh _PIPX_BIN_NAMES. Triggers on "check mcp sync", "validate mcp", "is the python in sync".
Use when creating a brand new module file in modules/ for a new tool category. Generates the boilerplate with correct array prefix, install_module_<name>() function, and ensures it integrates with install.sh, profiles, and MCP server. Triggers on "new module", "add a module for X", "scaffold module".
'Monitors dark web forums, marketplaces, paste sites, and ransomware
Configure and execute access recertification campaigns in Saviynt Enterprise
Conduct systematic access reviews and certifications to ensure users
Use BloodHound and SharpHound to enumerate Active Directory relationships
Enumerate and audit Active Directory forest trust relationships using
Conduct a focused Active Directory penetration test to enumerate domain
Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks
Use AI and LLM-based reasoning to correlate findings across multiple
Perform systematic alert triage in Elastic Security SIEM to rapidly classify,
'Uses Microsoft RESTler to perform stateful REST API fuzzing by automatically
'Tests API rate limiting implementations for bypass vulnerabilities by
'Uses Postman to perform structured API security testing by building
'Simulates ARP spoofing attacks in authorized lab or pentest environments
Develop and apply a multi-factor asset criticality scoring model to weight
Configure and execute authenticated vulnerability scans using OpenVAS/Greenbone
Authenticated (credentialed) vulnerability scanning uses valid system
Deploy and operate CAPEv2 sandbox for automated malware analysis with
Perform comprehensive security posture assessment of AWS accounts using
'Simulates bandwidth throttling and network degradation attacks using
'Analyze binary exploitation techniques including buffer overflows and
Detect and exploit blind Server-Side Request Forgery vulnerabilities
Assess Bluetooth Low Energy device security by scanning, enumerating
Monitor for brand impersonation attacks across domains, social media,
Perform comprehensive cloud asset inventory and relationship mapping
Conduct forensic investigations in cloud environments by collecting and
Perform forensic investigation of AWS environments using CloudTrail logs
Execute cloud-native incident containment across AWS, Azure, and GCP
Hunt for threats in AWS environments using Detective behavior graphs,
'Performing authorized AWS penetration testing using Pacu, the open-source
Perform forensic acquisition and analysis of cloud storage services including
'Detects container escape attempts by analyzing namespace configurations,
'This skill covers hardening container images by minimizing attack surface,
Scan container images, filesystems, and Kubernetes manifests for vulnerabilities,
Analyze and bypass Content Security Policy implementations to achieve
Extract stored credentials from compromised endpoints using the LaZagne
A cryptographic audit systematically reviews an application's use of
Leverage the CISA Known Exploited Vulnerabilities catalog alongside EPSS
Testing web applications for path traversal vulnerabilities that allow
'Conducts disk forensics investigations using forensic imaging, file
Execute a phased DMARC rollout from p=none monitoring through p=quarantine
Docker Bench for Security is an open-source script that checks dozens
'Performs interactive dynamic malware analysis using the ANY.RUN cloud
'Performs entitlement review and access certification campaigns using
Perform systematic SIEM false positive reduction through rule tuning,
Recover files from disk images and unallocated space using Foremost's
'Performs firmware image extraction and analysis using binwalk to identify
'Analyzes firmware images for embedded malware, backdoors, and unauthorized