
Claude Skills by costrict-plugins-repo
github.com/costrict-plugins-repoImplements GDPR (EU 2016/679) technical and organizational measures — privacy by design/default, DPIAs, data subject rights management, 72-hour breach notification, and cross-border transfer mechanisms (SCCs, BCRs, adequacy). Use when designing or auditing GDPR controls, building a DPIA, handling data subject access/erasure requests, or assessing cross-border data transfers.
'Automates GDPR Data Subject Access Request (DSAR) workflows including
Configures GitHub Advanced Security (code scanning with CodeQL, secret scanning, dependency review, and Dependabot alerts) to perform automated static analysis and vulnerability detection across repositories at enterprise scale, including custom CodeQL queries and CI workflow integration. Use when setting up or tuning code scanning, rolling out CodeQL across an organization, or shifting SAST left into pull request workflows.
'Hardens a Google Workspace tenant via Admin Console configuration:
Configures Google Workspace advanced phishing and malware protection settings in the Admin Console — pre-delivery message scanning, attachment protection, spoofing/impersonation detection, and Enhanced Safe Browsing enforcement. Use when hardening Gmail against phishing, spoofing, and malware, or when tuning Workspace email security policies.
Configures SAML 2.0 single sign-on for Google Workspace against a third-party
'Builds a FIDO2/WebAuthn relying party server with the python-fido2
'Configures HashiCorp Vault dynamic secrets engines for database credentials,
Implement the HIPAA Security Rule (45 CFR Part 164 Subpart C) to protect electronic protected health information (ePHI): conduct the required risk analysis, deploy the administrative, physical, and technical safeguards, handle required vs addressable implementation specifications, execute Business Associate Agreements, and stand up breach-notification readiness. Use when an organization is a HIPAA covered entity or business associate, when protecting ePHI, when preparing for an OCR audit or r...
'Deploys canary files, honeypot shares, and decoy systems to detect ransomware
'Deploys canary tokens and honeytokens (fake AWS credentials, DNS canaries,
'Deploys and configures Tofino industrial firewalls (Belden/Hirschmann)
Deploys SailPoint IdentityNow or IdentityIQ for identity governance and
Implements continuous, risk-adaptive identity verification for zero trust
'Designs security zones and conduits for industrial control systems
Signs and verifies container image provenance with Sigstore Cosign, covering key-based and keyless OIDC signing (Fulcio, Rekor transparency log), SLSA attestations, and enforcing signature verification through Kubernetes admission control. Use when signing images for supply chain security, setting up keyless OIDC signing, attaching attestations, or enforcing a verified-images-only policy at admission. Keywords: Cosign, Sigstore, Fulcio, Rekor, keyless, attestation, cosign verify, admission po...
'Implements ransomware-resistant backups using restic with S3-compatible
'Implements automated security scanning for Infrastructure as Code using
Guides implementation of an ISO/IEC 27001:2022 Information Security Management System (ISMS) end to end: gap analysis and scoping, risk assessment methodology, Annex A control selection, Statement of Applicability (SoA) creation, and continuous improvement. Use when scoping a new ISMS, preparing for ISO 27001 certification or audit, or selecting and documenting Annex A controls for a compliance program.
Implements Just-In-Time (JIT) access provisioning to eliminate standing privileges by granting temporary, time-bound access, covering approval workflows, automatic expiration/revocation, and PAM/IGA integration. Use when designing access approval workflows or replacing standing privileged accounts with time-bound, zero-trust-aligned grants.
Implements secure JWT (RFC 7519) signing and verification using HMAC-SHA256, RSA-PSS, ES256, and EdDSA, including token expiration, claims validation, and defenses against algorithm-confusion, none-algorithm, and key-injection attacks. Use when adding or hardening JWT-based authentication/authorization, or when auditing token verification code for common JWT vulnerabilities.
Installs Calico as the cluster CNI and writes standard Kubernetes NetworkPolicy under it, covering default-deny baselines, policy ordering and precedence, service-account-based selectors, and verifying that policy is genuinely being enforced. Use when adopting Calico as the enforcement CNI, establishing a default-deny baseline, or debugging why a NetworkPolicy is not taking effect under Calico. Keywords: Calico CNI, NetworkPolicy, default deny, policy order, Felix, service account selector. D...
Chooses and applies the correct Kubernetes Pod Security Standard (Privileged, Baseline, Restricted) for a workload: what each profile forbids, how to map existing workloads to a profile, which securityContext fields must change, and how to plan a PodSecurityPolicy-to-PSS migration without breaking running pods. Use when deciding which pod security profile a namespace or workload should run under, auditing which workloads would fail Restricted, planning a PSP migration, or mapping pod security...
'Implements input/output validation guardrails for LLM applications using
Configures Fluent Bit as an endpoint log forwarder and Fluentd as the central aggregator for centralized log collection, routing, filtering, and enrichment, covering input plugins for syslog/file-tailing/application logs and output routing to Elasticsearch, S3, and Splunk. Use when setting up centralized log aggregation across distributed infrastructure or generating Fluent Bit/Fluentd configuration files for a new log pipeline.
Builds an append-only log integrity chain using SHA-256 hash chaining, where each entry incorporates the previous entry's hash so tampering invalidates all subsequent hashes; covers log ingestion (syslog/JSON/plain text), chain verification, pinpoint tamper detection, and checkpoint anchoring to external timestamping services. Use for tamper-evident log storage for compliance or forensics, or to verify whether log entries were altered.
'Implements memory protection mechanisms including DEP (Data Execution
'Implements microsegmentation with Akamai Guardicore Segmentation to map
Deploys and configures Mimecast Targeted Threat Protection (TTP) modules -- URL Protect (click-time URL rewriting/analysis), Attachment Protect (sandbox detonation), Impersonation Protect (BEC/whaling detection), and Internal Email Protect -- for Microsoft 365 or Google Workspace. Use when defending against phishing, spearphishing, or business email compromise, or configuring TTP policies in the Mimecast Administration Console.
Implement MITRE ATT&CK coverage mapping to identify detection gaps, prioritize
'Implements Mobile Application Management (MAM) policies to protect enterprise
'Configures mutual TLS (mTLS) authentication between microservices using
'Implements NERC CIP controls for Bulk Electric System (BES) cyber systems: asset
Deploys Cisco Identity Services Engine (ISE) as a RADIUS policy server for 802.1X
'Implements 802.1X port-based network access control using RADIUS authentication,
Deploy and manage network honeypots using OpenCanary, T-Pot, or Cowrie
Deploys and configures Suricata as an inline network intrusion prevention system,
Writes portable upstream Kubernetes NetworkPolicy YAML - default-deny-all, DNS egress, namespace and pod selector rules - that works on any conformant CNI such as Calico or Cilium. Use when segmentation must stay CNI-portable, introducing a default-deny posture, or restricting east-west traffic between pods and namespaces without depending on a vendor CRD. Keywords: NetworkPolicy, default deny, podSelector, namespaceSelector, ingress, egress, CNI portable. Do not use for Calico-specific resou...
'Implements OT network segmentation using VLANs, OT-aware firewalls, data diodes,
Designs and implements network segmentation using firewall security zones, VLANs,
Queries Arkime (formerly Moloch) full packet capture via its API to search sessions,
Builds network traffic baselines from NetFlow/IPFIX CSV or JSON exports using Python
Configures and deploys Palo Alto Networks next-generation firewalls end-to-end,
Deploys OPA Gatekeeper via Helm as a Kubernetes admission controller and writes ConstraintTemplates with Rego plus instantiated Constraints to validate, mutate, or deny resource requests at admission time. Use when enforcing custom policy-as-code at admission on Kubernetes v1.24+, blocking non-compliant workloads before scheduling, or expressing a rule that built-in controls cannot. Keywords: Gatekeeper, ConstraintTemplate, Constraint, Rego, admission webhook, audit, mutation. Do not use for ...
'Develops OT-specific incident response playbooks using a SANS PICERL-based Python
'Deploy Nozomi Networks Guardian sensors for passive OT network traffic
Deploy privileged access management for database systems including Oracle,
'Implements passwordless authentication using Microsoft Entra ID with
Deploy FIDO2/WebAuthn passwordless authentication using security keys
'Implements a structured patch management program for OT/ICS environments