
Claude Skills by costrict-plugins-repo
github.com/costrict-plugins-repoPatch management is the systematic process of identifying, testing, deploying,
Implements PCI DSS 4.0.1's 12 requirements across 6 control objectives
Configures and operates the Kubernetes Pod Security Admission (PSA) controller that enforces Pod Security Standards: namespace enforce/audit/warn labels, cluster-wide defaults via AdmissionConfiguration, exemptions for usernames, runtime classes and namespaces, version pinning, and troubleshooting pods the controller rejected. Use when wiring PSA up on a cluster, setting cluster-wide default enforcement, exempting system namespaces, debugging why a pod was rejected or why enforcement is not f...
'Implements policy-as-code enforcement with Open Policy Agent (OPA)
Deploy CyberArk Privileged Access Management to discover, vault, rotate,
Design and implement Privileged Access Workstations (PAWs) using the
'Implements privileged session monitoring and recording using PAM
Deploy and configure Proofpoint Email Protection as a secure email gateway
'Implement network segmentation based on the Purdue Enterprise Reference
'Designs a ransomware-resilient backup strategy using the 3-2-1-1-0
'Analyzes ransomware kill switch mechanisms, including mutex-based execution
Deploy and configure Rapid7 InsightVM Security Console and Scan Engines,
Hardens Kubernetes RBAC by designing least-privilege Roles and ClusterRoles, auditing RoleBindings, eliminating cluster-admin sprawl, separating service accounts, and integrating an external OIDC identity provider. Use when tightening cluster access control, removing excessive ClusterRoleBindings, or hardening service-account permissions against escalation and lateral movement. Keywords: RBAC, Role, ClusterRole, RoleBinding, least privilege, service account, OIDC, cluster-admin. Do not use fo...
Generates, stores, rotates, and manages RSA key pairs following NIST
Deploy Runtime Application Self-Protection (RASP) agents to detect and
Implements eBPF-based runtime observability and in-kernel enforcement in Kubernetes with Cilium Tetragon, monitoring process execution, file access, network connections, and syscalls, and blocking dangerous calls at the kernel level. Use when deploying Tetragon to detect or block syscalls such as ptrace, mount, and unshare, enforcing kernel-level policy, or adding low-overhead runtime detection to a cluster. Keywords: Tetragon, Cilium, eBPF, TracingPolicy, kprobe, enforcement, process lineage...
Implement SAML 2.0 Single Sign-On using Okta as the Identity Provider,
Implement automated user lifecycle provisioning and deprovisioning using
'This skill covers implementing Gitleaks for detecting and preventing
'Deploy HashiCorp Vault for centralized secrets management, covering dynamic
Integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked
'Implements security chaos engineering experiments that deliberately
'Create, validate, and share STIX 2.1 threat intelligence objects (indicators,
'Implements security monitoring using Datadog Cloud SIEM, Cloud Security
Write custom Semgrep SAST rules in YAML to detect application-specific
Write multi-event correlation rules in Splunk SPL and Sigma format that
Tune SIEM detection rules in Splunk and Elastic to reduce false positives
'Implements SIEM detection use cases by designing correlation rules,
'Implements Sigstore-based software signing and verification using Cosign
'Implements Security Orchestration, Automation, and Response (SOAR) workflows
Automates phishing incident response by calling the Splunk SOAR (Phantom)
Build automated incident response playbooks in Cortex XSOAR (Demisto)
Implements a STIX 2.1/TAXII 2.1 threat-intelligence feed consumer and
Implements supply chain integrity verification for container builds with the in-toto framework: generating signing keys, defining a supply chain layout, recording pipeline steps as signed link metadata, verifying before deployment, enforcing at Kubernetes admission, and integrating with SLSA. Use when attesting CI/CD pipeline steps, proving an image followed the approved build process, or enforcing provenance at admission. Keywords: in-toto, layout, link metadata, step, inspection, SLSA, prov...
Configure rsyslog for centralized log collection with TLS encryption,
Deploy and configure a TAXII 2.1 server (Medallion) with Docker, publish
Build out a full CTI program around the six-phase threat intelligence
'Implements threat modeling using the MITRE ATT&CK framework to map adversary
'Implements an integrated incident ticketing system connecting SIEM alerts
'Implements USB device control policies to restrict unauthorized removable
Deploy and configure Velociraptor for scalable endpoint forensic artifact
Deploy and operate Greenbone/OpenVAS vulnerability management using the
Design a vulnerability remediation SLA program covering asset tiering,
Build an automated SLA breach alerting system for vulnerability remediation,
Configure ModSecurity WAF with the OWASP Core Rule Set (CRS) for web
Implements the Schnorr identification protocol and a simplified Zero-Knowledge Password Proof (ZKPP) over the discrete logarithm problem, letting a prover authenticate by demonstrating knowledge of a secret without ever revealing it to the server. Use when designing or building password-less or password-secret-free authentication, or when a server must verify a user's credential without learning or storing the underlying secret.
Deploy CyberArk Secure Cloud Access (SCA) to eliminate standing privileges in AWS, Azure, and GCP by provisioning ephemeral, scoped roles on a just-in-time basis governed by the TEA framework (Time, Entitlements, Approvals). Use when designing or implementing zero standing privilege / just-in-time privileged access models with CyberArk, or when replacing persistent cloud admin roles with time-bound, approval-gated sessions.
Configure NextDNS as an encrypted (DoH/DoT) zero trust DNS resolver that blocks malicious, phishing, and cryptojacking domains via real-time threat intelligence, detects DNS rebinding and CNAME cloaking, and enforces organizational DNS policy across endpoints. Use when deploying DNS-layer threat blocking and acceptable-use enforcement, or when extending zero trust controls (including Windows 11 Zero Trust DNS) to the DNS resolution path.
Secures SaaS apps (Microsoft 365, Google Workspace, Salesforce, Slack) via CASB/SSPM deployment, conditional access policies, OAuth app governance, and session-level DLP controls enforcing identity verification and device compliance. Use when adding MFA/device-compliance conditional access, discovering shadow IT, governing OAuth consent grants, or applying session controls to sensitive SaaS data.
Guides zero trust implementation across AWS, Azure, and GCP per NIST SP 800-207 and BeyondCorp principles, covering identity-centric access, micro-segmentation, continuous verification, device trust assessment, and Identity-Aware Proxy deployment. Use when migrating from perimeter security to identity-centric access, removing VPN dependency, or designing micro-segmentation for multi-cloud workloads.