
Claude Skills by adriannoes
github.com/adriannoesSecurity audit and vulnerability scanner for AI agent skills before installation. Use when: (1) evaluating a skill from an untrusted source, (2) auditing a skill directory or git repo URL for malicious code, (3) pre-install security gate for Claude Code plugins, OpenClaw skills, or Codex skills, (4) scanning Python scripts for dangerous patterns like os.system, eval, subprocess, network exfiltration, (5) detecting prompt injection in SKILL.md files, (6) checking dependency supply chain risks,...
Identify ransomware network indicators including C2 beaconing patterns,
Test vector stores for embedding inversion, cross-tenant leakage, and poisoning.
Scan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.
Generate log2timeline and Plaso super-timelines and triage them in Timesketch.
Build a systematic threat hunt hypothesis framework that transforms threat
Wire Promptfoo and DeepTeam into CI/CD for automated regression red-teaming of LLM apps against OWASP LLM Top 10 and OWASP Agentic presets, failing the build when jailbreak or injection vulnerabilities regress.
Deploy Llama Guard, NeMo Guardrails, and LLM Guard input/output scanners as runtime defenses.
'Deobfuscates malicious JavaScript code used in web-based attacks, phishing
Systematically deobfuscate multi-layer PowerShell malware using AST analysis,
'Detects prompt injection attacks targeting LLM-based applications using
Identify poisoned training data and backdoored models across the ML pipeline.
Detect DCSync attacks where adversaries abuse Active Directory replication
Detect and prevent public-over-private name resolution in npm, PyPI, and Maven.
Detect DLL side-loading attacks where adversaries place malicious DLLs
Detect compromised O365 and Google Workspace email accounts by analyzing
Detect malicious email forwarding rules created by adversaries to maintain
Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics for fingerprints of offensive Entra ID tools such as ROADtools, AADInternals, and AzureHound.
'Detects and analyzes fileless malware that operates entirely in memory
Detect and defend against prompt injection hidden in documents, web pages, and images consumed by an agent.
Triage npm packages for install-script malware, exfiltration, and worming behavior.
Detect model stealing, model inversion, and membership inference performed through inference-API abuse by monitoring query patterns, applying output perturbation, and red-teaming your own model's extractability.
Detect bootkits such as BlackLotus and Bootkitty and Secure Boot bypass via DBX and binary checks.
Flag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation using edit-distance, keyboard-proximity, and known-target corpus matching with typomania, OSSGadget, and pypi-scan.
Map AWS and Azure attack paths and find exploitable misconfigurations with
Systematically remove malware, backdoors, and attacker persistence mechanisms
Extract and analyze browser history, cookies, cache, downloads, and bookmarks
Extract embedded configuration from Agent Tesla RAT samples including
'Extracts indicators of compromise (IOCs) from malware samples including
Deploy a Velociraptor server and agents and write VQL hunts across a fleet.
Produce and ingest CycloneDX and SPDX SBOMs and correlate them to vulnerability intelligence.
Produce Sigma-based EVTX timelines and summaries with Hayabusa.
Baseline the EFI System Partition and hunt malicious EFI binaries (ESPecter, BlackLotus, Bootkitty, Glupteba) by mounting the ESP, hashing and verifying boot loaders, scanning with YARA, and detecting anomalous non-EFI files.
Perform rapid Sigma and keyword hunting across Windows event logs with
Detect SSO and OAuth token replay and SaaS lateral movement.
'Implementing AWS Config rules for continuous compliance monitoring of
'This skill covers implementing code signing for build artifacts to ensure
The General Data Protection Regulation (EU) 2016/679 (GDPR) is the EU's
Configure GitHub Advanced Security with CodeQL to perform automated static
'Implements input and output validation guardrails for LLM-powered applications
'Implements Sigstore-based software signing and verification using Cosign
'This skill covers integrating OWASP ZAP (Zed Attack Proxy) for Dynamic
'This skill covers integrating Static Application Security Testing (SAST)
Identify, collect, and analyze ransomware attack artifacts to determine
'This skill covers implementing Okta as a centralized identity provider
Build multi-turn, Crescendo, and Tree-of-Attacks-with-Pruning (TAP) automated attack chains against conversational LLM agents using Microsoft PyRIT, with adversarial chat and scorer feedback loops.
Parse registry, prefetch, shellbags, and MFT with EZ Tools and Timeline Explorer.
Perform systematic alert triage in Elastic Security SIEM to rapidly classify,
Deploy and operate CAPEv2 sandbox for automated malware analysis with
Perform comprehensive cloud asset inventory and relationship mapping