
Claude Skills by ayalaphiscan
github.com/ayalaphiscanProgetta e installa un'infrastruttura di sicurezza a 4 livelli dove il cuore (dati e chiavi) è offline, lo scudo è invisibile agli scanner e il server reale è nascosto. Trigger - "fortezza", "scatola chiusa", "invisibile", "nascosto", "reverse proxy", "air gap", "cassaforte", "WireGuard". EN - Designs and installs a 4-layer security infrastructure where the core (data and keys) is offline and detached, the shield is invisible to scanners and the real server is hidden. Use for a self-hosted Cl...
Implementa autenticazione sicura quando un sito/app richiede registrazione, login o account utente. Copre verifica email con codice, 2FA/TOTP, passkey, hashing password, sessioni e recupero account. Trigger - "login", "registrazione", "verifica email", "2FA", "passkey". EN - Implements secure authentication when a site/app needs sign-up, login or user accounts. Covers email verification codes, two-factor authentication (2FA/TOTP), passkeys and security keys, password hashing, sessions and acc...
Aggiunge a un sito/app un agente di difesa che rileva e blocca richieste malevole (SQL injection, XSS, path traversal, brute force, bot) con rate limiting, blocklist IP e modalità lockdown che preserva i dati. Trigger - "blocca attacchi", "firewall", "WAF", "lockdown", "sotto attacco". EN - Adds a defense agent that detects and blocks malicious requests (SQL injection, XSS, path traversal, brute force, bots) with rate limiting, IP blocklist and a data-preserving lockdown mode. Triggers - "blo...
Applica regole di sicurezza (hardening) ogni volta che si costruisce, modifica o revisiona un sito web o un'app. Copre security headers, CSP, HTTPS, validazione input, cookie, CORS, upload, gestione errori e OWASP Top 10. Trigger - "crea un sito", "metti in sicurezza", "hardening", "security headers". EN - Applies security hardening whenever a website or app is built, modified or reviewed. Covers security headers, CSP, HTTPS, input validation, cookies, CORS, uploads, error handling and the OW...
Protegge dati di pagamento e abbonamenti quando un sito/app gestisce checkout, carte, subscription o fatturazione. Copre Stripe/PayPal sicuri, verifica firma webhook, PCI-DSS, GDPR e ciclo di vita abbonamenti. Trigger - "pagamenti", "checkout", "abbonamento", "Stripe", "PayPal". EN - Protects payment and subscription data when a site/app handles checkout, cards, subscriptions or billing. Covers secure Stripe/PayPal integration, webhook signature verification, PCI-DSS, GDPR, data minimization ...
Aggiunge alle repository GitHub workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti nel codice, analisi statica CodeQL e Dependabot. Trigger - "sicurezza repo", "scansione repository", "dependabot", "secret scanning". EN - Adds automated security workflows to GitHub repositories - vulnerable dependency scanning, secret/key detection in code, CodeQL static analysis and Dependabot. Triggers - "repo security", "security GitHub Actions", "repository scanning", ...