
Claude Skills by costrict-plugins-repo
github.com/costrict-plugins-repo'Reverse engineers .NET malware using dnSpy decompiler and debugger to
'Reverse engineers iOS applications using Frida dynamic instrumentation
'Reverse engineers malware binaries using NSA''s Ghidra disassembler
Reverse engineer ransomware encryption routines to identify cryptographic
Reverse engineer Rust-compiled malware using IDA Pro and Ghidra with
Scan container images for known vulnerabilities using Anchore Grype with
'This skill covers integrating Aqua Security''s Trivy scanner into CI/CD
Trivy is a comprehensive open-source vulnerability scanner by Aqua Security
Tenable Nessus is the industry-leading vulnerability scanner used to
Perform security risk analysis on Kubernetes resource manifests using
'Performs advanced network reconnaissance using Nmap''s scripting engine,
'Securing API Gateway endpoints with AWS WAF by configuring managed rule
'This skill guides practitioners through hardening AWS Identity and Access
'Securing AWS Lambda execution roles by implementing least-privilege
'This skill instructs security practitioners on deploying Microsoft Defender
'Securing container registry images by implementing vulnerability scanning
Harbor is an open-source container registry that provides security features
'This skill covers hardening GitHub Actions workflows against supply
Secure Helm chart deployments by validating chart integrity, scanning
'This skill covers hardening and securing process historian servers (OSIsoft
'This skill covers hardening managed Kubernetes clusters on EKS, AKS,
'This skill covers implementing secure remote access to OT/ICS environments
'This skill covers security hardening for serverless compute platforms
'Tests Android inter-process communication (IPC) through intents for
'Tests API authentication mechanisms for weaknesses including broken
'Tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR)
'Tests APIs for mass assignment (auto-binding) vulnerabilities where
Systematically assessing REST and GraphQL API endpoints against the OWASP
Identifying and exploiting Cross-Origin Resource Sharing misconfigurations
Systematically testing web applications for broken access control vulnerabilities
Identifying flaws in application business logic that allow price manipulation,
Test web application email functionality for SMTP header injection vulnerabilities
Test web applications for HTTP Host header injection vulnerabilities
Test JWT implementations for critical vulnerabilities including algorithm
Identify and test open redirect vulnerabilities in web applications by
Identifying sensitive data exposure vulnerabilities including API key
Test web applications for XML injection vulnerabilities including XXE,
Identifying and validating cross-site scripting vulnerabilities using
'Tests web applications for Cross-Site Scripting (XSS) vulnerabilities
Discovering and exploiting XML External Entity injection vulnerabilities
Assessing JSON Web Token implementations for cryptographic weaknesses,
'Tests authentication and authorization mechanisms in mobile application
'Tests OAuth 2.0 and OpenID Connect implementations for security flaws
Test and validate ransomware recovery procedures including backup restore
'Tests WebSocket API implementations for security vulnerabilities including
Threat actor infrastructure tracking involves monitoring and mapping
'Triages security alerts in Splunk Enterprise Security by classifying
Classify and prioritize security incidents using structured IR playbooks
'Performs initial triage of security incidents to determine severity,
Triage and prioritize vulnerabilities using CISA's Stakeholder-Specific