
Claude Skills by aibot88
github.com/aibot88Cross-Site Request Forgery detection — missing tokens, SameSite misconfiguration, and CORS-CSRF interaction
Supply chain and dependency security analysis across all package ecosystems
Incremental security scan for changed files only — optimized for PR and commit-level reviews
Docker-specific security checks — image hardening, secrets in layers, compose security, and runtime configuration
GraphQL injection, introspection abuse, query complexity attacks, and authorization bypass detection
HTTP Header Injection and Response Splitting detection via CRLF injection in headers
Infrastructure-as-Code security scanning — Dockerfile, Kubernetes, Terraform, and GitHub Actions misconfigurations
JWT implementation flaw detection — algorithm confusion, weak secrets, missing validation, and storage issues
LDAP Injection detection in search filters, DN construction, and bind operations
NoSQL Injection detection for MongoDB, Redis, CouchDB, and Elasticsearch
Master orchestration skill that coordinates the entire 4-phase security scanning pipeline
Path traversal and directory traversal detection — LFI, RFI, zip slip, and symlink attacks
Remote Code Execution detection via eval, exec, dynamic code loading, and code injection vectors
Codebase discovery and architecture mapping for security analysis
Final consolidated security assessment report generator with CVSS severity and remediation roadmap
Hardcoded secrets, API keys, tokens, credentials, and private key detection in source code
SQL Injection detection across all variants — classic, blind, time-based, second-order, and UNION-based
Server-Side Request Forgery detection — URL fetching with user input, DNS rebinding, cloud metadata access
Server-Side Template Injection detection across all major template engines
False positive elimination and confidence scoring for all security findings
WebSocket security flaw detection — missing origin validation, authentication bypass, and message injection
Cross-Site Scripting detection for Reflected, Stored, and DOM-based XSS across all frameworks
XML External Entity injection detection across all XML parsers and document formats
Wire CI/CD, E2E testing, and design-system compliance gates. Auto-dispatched by deliver-stage on ci-cd stages.
\"Create defensive prompt scaffolding with guardrails and safety measures. 創建帶護欄與安全措施之防禦提示架構。 Use when: building user-facing prompts, adding injection protection, implementing harm prevention layers.\"
Project-local Bun scaffolders shipped by THIS plugin (not the official `remix` CLI) for adding things incrementally to an existing project — `scripts/create-route.ts --name X --pattern //Y` (route + handler + router.map wiring, escaping Git Bash MSYS path mangling with `//`), `scripts/create-resource.ts --name X --param Yid [--only index,show,...]` (`resources()` block + 7-action controller mirror), `scripts/create-controller.ts --route admin.books` (stub for an existing RouteMap), `scripts/c...
Run a pre-trust security pass over skill packs and prompt bundles before they get shared, merged, or deployed.
Use Agentic Radar to statically scan agent workflows, map tools and MCP servers, generate shareable security reports, and optionally run adversarial runtime tests before rollout.
Generate a reviewable security report for a supported agent workflow before deployment by scanning its code, tools, MCP usage, and known vulnerability surface.
Audit a Claude Code setup before use by flagging hardcoded secrets, broad allow rules, risky hooks, and dangerous MCP server config.
Diagnose en fix scanner problemen. Gebruik bij "scanner", "scan", "OAuth", "tokens".
Find packages that are out of support even when they do not show up as a classic CVE finding yet.
Run Kubernetes security and compliance scans against manifests or live clusters before rollout or audit.
Probe a model or agent stack with adversarial test suites so safety failures show up before deployment or review.
Run MCP Scanner against a remote or local MCP server before trusting it, so the agent gets a bounded security review of tools, prompts, resources, dependencies, and supply-chain risk.
Catch insecure Python calls, weak crypto usage, shell injection risks, and similar patterns before merge or release.
Use Medusa Security before trusting a repository, dependency, or AI-agent codebase when an agent needs a focused scan for repo poisoning, prompt-injection, MCP, and AI supply-chain findings.
Check repositories and CI surfaces for Shai-Hulud 2.0 compromise indicators when the task is targeted supply-chain triage, not generic malware scanning.
Go プロジェクトの脆弱性スキャンを実行する。「脆弱性スキャン」「govulncheck」「セキュリティチェック」「脆弱性確認」「vuln」「CVE チェック」「セキュリティスキャン」などで起動。govulncheck を使用して既知の脆弱性を検出。
Packages and runs a local SAST pipeline scan to identify source code vulnerabilities. - User asks to scan the codebase, run a scan, or check for vulnerabilities - User mentions "scanit", "pipeline scan", "SAST scan", "scan my code" - User wants to know if their code has security issues before committing or deploying
Validate WCAG compliance and accessibility standards (ARIA, keyboard navigation). Use when auditing WCAG compliance or screen reader compatibility. Trigger with phrases like "scan accessibility", "check WCAG compliance", or "validate screen readers".
Detect API security vulnerabilities including injection, broken auth, and data exposure. Use when scanning APIs for security vulnerabilities. Trigger with phrases like "scan API security", "check for vulnerabilities", or "audit API security".
'Execute use when you need to work with security and compliance.
'Process use when you need to work with security and compliance.
Scan for data privacy issues and sensitive information exposure. Use when reviewing data handling practices. Trigger with 'scan privacy issues', 'check sensitive data', or 'validate data protection'.
Scan for GDPR compliance issues in data handling and privacy practices. Use when ensuring EU data protection compliance. Trigger with 'scan GDPR compliance', 'check data privacy', or 'validate GDPR'.
Detect exposed secrets, API keys, and credentials in code. Use when auditing for secret leaks. Trigger with 'scan for secrets', 'find exposed keys', or 'check credentials'.
'Execute this skill enables comprehensive vulnerability scanning using
'Execute this skill enables AI assistant to automatically scan for xss
Scan for input validation vulnerabilities and injection risks. Use when reviewing user input handling. Trigger with 'scan input validation', 'check injection vulnerabilities', or 'validate sanitization'.