All authors
jassics avatar

Claude Skills by jassics

github.com/jassics
111 skillsA× 106B× 50 installs96 views
A2a Security ReviewA

Review agent-to-agent (A2A) / multi-agent-system trust: peer identity and authentication, message integrity, capability-negotiation trust, and delegation-chain privilege narrowing. Use when an orchestrator dispatches to sub-agents or peer agents (same or different trust domain) rather than calling a tool — distinct from `mcp-security-review`'s tool-boundary case.

ai-agentsrustgo
0
8
Agent Harness ReviewB

Test the agent execution harness/runtime itself — LangChain/LangGraph, AutoGen, CrewAI, custom ReAct-style loops, or computer-use/browser-use agents — for intermediate-state poisoning, unscoped action spaces, and missing resource limits. Use when the agent isn't built on Claude Code (see `claude-config-security` for that) and you need to verify the loop that feeds tool/environment output back into the model actually enforces a trust boundary.

ai-agentsrustgo
0
8
Agent Security ReviewA

Assess an autonomous / tool-using AI agent for security end-to-end: tool privileges, autonomy and approval boundaries, excessive agency, memory/state poisoning, and multi-agent trust. Use when reviewing the security of an AI agent or agentic workflow.

ai-agentsrustgo
0
8
Autonomy Boundary TestA

Test what an AI agent will actually do without human confirmation, including under injected-goal / prompt-injection scenarios, to validate its autonomy and approval boundaries. Use on an authorized agent to confirm excessive-agency controls hold in practice.

ai-agentsgotesting
0
8
Mcp Security ReviewA

Review the security of MCP (Model Context Protocol) servers/clients an agent uses: server trust tier, tool/resource description and result poisoning, confused-deputy risk, consent/scope UX, and supply-chain pinning. Use when an agent or assistant integrates one or more MCP servers, especially third-party or community ones.

ai-agentsrustgo
0
8
Tool Permission AuditA

Inventory the tools/functions an AI agent can call and audit their privileges, side effects, and approval requirements to find excessive-agency and least-privilege gaps. Use when reviewing an agent's tool/function surface.

ai-agentsgosecurity
0
8
Evals Ci GateA

Operationalize a safety/prompt-injection eval suite into an enforced CI gate — not just a one-off report — using the ready-to-copy promptfoo/garak template, a regression baseline, and a burn-in rollout. Use when a safety eval already exists (or is being designed) and needs to actually block regressions on every release rather than being run manually once.

ai-agentsgogit
0
8
Safety CaseA

Assemble a structured assurance / safety case for deploying an AI system — an explicit argument that it is acceptably safe for its context, backed by evidence (harm model, evals, guardrails, fairness, governance). Use to support a go/no-go deployment decision or an audit/sign-off.

ai-agentsgorails
0
8
Bias Fairness AssessmentA

Assess an AI model, feature, or dataset for bias and fairness across groups — representational and allocative harms, disparate performance, and skewed refusals — using appropriate fairness metrics, and recommend mitigations. Use when evaluating whether an AI system treats people equitably.

ai-agentsgosecurity
0
8
Guardrail ReviewA

Review or design the content-safety guardrails of an AI system — input/output classifiers, refusal and safe-completion behavior, escalation/human handoff, and coverage across harm categories, languages, and modalities. Use when assessing or building the safety controls around a model.

ai-agentsgorails
0
8
Harm ModelingA

Systematically enumerate the potential HARMS of an AI system — to users, third parties, vulnerable groups, and society — under normal use, misuse, and malfunction, then rank them and map mitigations. This is the AI-safety analog of threat modeling (which targets attackers). Use when designing or reviewing an AI feature for safety, not security.

ai-agentsgorails
0
8
Responsible Ai AssessmentA

Gap-assess an AI system or program against a responsible-AI / governance framework — NIST AI RMF, ISO/IEC 42001, EU AI Act, OECD principles — covering governance, transparency, accountability, human oversight, documentation, and monitoring, then produce a prioritized roadmap. Use for AI governance, audit readiness, or compliance gap analysis.

ai-agentsgorails
0
8
Safety EvaluationA

Design and run a safety evaluation suite for an AI model or feature across harm categories — refusals on disallowed content, robustness, over-refusal vs helpfulness, groundedness/truthfulness — with rubrics and pass/fail thresholds. Use to measure an AI system's safety, establish a baseline, or gate a release.

ai-agentsgosecurity
0
8
Safety Red TeamA

Responsibly red-team an AI system to find SAFETY failures — harmful outputs, jailbreaks that defeat safety guardrails, and foreseeable-misuse / dangerous- capability elicitation — so they can be mitigated. Use to stress-test safeguards before/after release. Controlled, authorized, mitigation-focused; not for producing or retaining harmful content.

ai-agentsgorails
0
8
Api Authz TestA

Test an API's authorization — BOLA (object-level), BFLA (function-level), and BOPLA (property-level / mass assignment) — to confirm each request is authorized for the caller. Use to validate the top OWASP API risks on an authorized target.

securityrustgo
0
8
Owasp Api Top10A

Assess a REST or GraphQL API against the OWASP API Security Top 10 (2023), producing a per-category finding set with severity and remediation. Use when reviewing or pentesting an API. Authorized testing only.

securitygotesting
0
8
Purple Team ExerciseA

Plan and run a purple-team exercise: collaboratively emulate specific ATT&CK techniques and measure whether detection and response actually work, then close the gaps. Use to validate defensive coverage against real adversary behavior. Authorized environments only.

ai-agentsgosecurity
0
8
Board DeckA

Produce a board / executive security presentation — risk posture and direction, top risks in business terms, program progress against strategy, the metrics that matter, and investment asks tied to risk. Use to prepare for a board or leadership meeting. Audience is non-technical decision-makers.

ai-agentsgosecurity
0
8
Cyber Risk QuantificationA

Translate technical security risk into business and financial terms — top risk scenarios, likelihood × impact, a risk register, and (where useful) quantified loss ranges (FAIR-aware) — to support executive decisions on treat/transfer/accept. Use to communicate or prioritize cyber risk for leadership.

securitygoexpress
0
8
Security StrategyA

Build or assess a security program strategy and roadmap — current-vs-target maturity, gaps, prioritized initiatives aligned to business objectives and risk appetite, with outcomes, metrics, and budget framing. Use for security program planning, a strategy refresh, or a maturity assessment.

ai-agentsgosecurity
0
8
Agent Safety LintA

Check a Claude Code agent's runaway-risk controls — a missing or invalid `maxTurns` (unbounded turns/cost), an unattended (bypass/acceptEdits) or backgrounded agent with no turn bound, a hook or stdio MCP server with no `timeout`, and prose that tells the model to disregard turn limits or resist interruption — in YOUR OWN repo's `.claude/agents/*.md` or a plugin you're authoring. Use when writing or reviewing a subagent definition, before shipping a plugin agent, or when asked "does this agen...

ai-agentsgoci/cd
0
8
Config Security ScanA

Statically review a Claude Code / AI-agent setup for security misconfigurations — risky hooks, over-broad permissions, untrusted or cleartext MCP servers, hardcoded secrets, endpoint redirection, over-privileged agents/skills, and prompt-injection in steering files. Use when asked to audit a `.claude/` directory, `settings.json`, `.mcp.json`, a plugin/marketplace, or `CLAUDE.md`, or to add a config-security gate to CI. Drives the `agentscanner` CLI.

ai-agentsrustgo
0
8
Cloud Iam ReviewA

Audit cloud IAM (AWS/Azure/GCP) for least privilege: over-permissioned identities, wildcard/admin grants, public or cross-account access, unused credentials, and privilege-escalation paths. Use to review identity risk — the top cause of cloud compromise.

ai-agentsrustgo
0
8
Cloud Misconfig ScanA

Scan a cloud environment (AWS/Azure/GCP) for high-impact misconfigurations and exposures — public storage, open ingress, unencrypted data, exposed secrets/ metadata, missing logging — and prioritize quick wins. Use for a fast exposure sweep on an authorized environment.

securitygoaws
0
8
Cloud Posture ReviewA

Review a cloud environment's security posture (AWS/Azure/GCP) across IAM, network, data protection, logging/monitoring, and workload configuration, mapped to CIS benchmarks, and produce ranked findings. Use for a CSPM-style assessment of an account/subscription/project you're authorized to review.

securitygorails
0
8
Secure By Design ProgramA

Establish or assess an org-wide secure-by-design program — paved roads / golden paths with secure defaults, automated guardrails, and developer enablement — so the secure way is the default, fast way. Use for engineering-org security strategy at scale (not a single system's design).

ai-agentsgorails
0
8
Tech Risk AssessmentA

Assess the security risk of a technology or product decision for leadership — new technology/vendor adoption, build-vs-buy, third-party/supply-chain, or M&A technical due diligence — and give a clear recommendation with trade-offs. Use to inform a strategic technology decision.

securityrustgo
0
8
Detection Coverage ReviewA

Assess detection coverage against the MITRE ATT&CK matrix: which tactics/techniques are covered, partially covered, or blind, weighted by data-source availability and threat relevance. Use to find and prioritize detection gaps for a SOC/program.

ai-agentsgosecurity
0
8
Detection Rule DevelopmentA

Develop or review a detection rule (Sigma, YARA, KQL/SPL/EQL) for a specific behavior or threat, mapped to MITRE ATT&CK, with test cases and false-positive tuning. Use when building, porting, or reviewing detections from a TTP, IOC, or incident finding.

ai-agentsgo
0
8
Threat HuntingA

Run a hypothesis-driven threat hunt: form a hypothesis (often from ATT&CK or threat intel), query telemetry for evidence, analyze findings, and convert results into detections. Use to proactively search for adversary activity that existing alerts may miss.

ai-agentsgosecurity
0
8
Pre Commit GateA

Aggregate a fast, diff-scoped security check before `git commit`/`git push` — secrets/gitignore hygiene, SAST/SCA on changed files, and IaC/Claude-config checks where relevant — into a single go/no-go verdict. Use before committing or pushing, not as a full-repo audit.

developmentpythonrust
0
8
Forensic TriageA

Perform forensic triage on a host or artifacts — collect and analyze disk, memory, and log evidence with proper handling, then build an incident timeline. Use to investigate a compromised system or scope an incident. Preserve evidence integrity.

ai-agentsgoshell
0
8
Incident ResponseA

Drive a security incident through the response lifecycle (NIST SP 800-61 / SANS PICERL): triage and scope, contain, eradicate, recover, and capture lessons learned. Use to coordinate or work an active incident. Authorized responders only.

ai-agentsgosecurity
0
8
Ioc DevelopmentA

Extract and operationalize indicators (IOCs) and behaviors (IOAs) from an incident or sample — atomic, computed, and behavioral — and prepare them for detection, blocking, and intel sharing. Use after/within an investigation to turn findings into defensive value.

ai-agentsgogit
0
8
Compliance AssessmentA

Gap-assess an organization or system against a compliance framework (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, NIST CSF/800-53), mapping controls to evidence, identifying gaps, and producing a prioritized remediation and audit-readiness plan. Use for compliance gap analysis, certification prep, or audit readiness.

ai-agentsgotesting
0
8
Policy ManagementA

Develop or review security governance documents — policies, standards, procedures, and guidelines — aligned to a framework and the organization's risk, with a clear hierarchy, ownership, and lifecycle. Use to write, assess, or rationalize a security policy set.

ai-agentsgosecurity
0
8
Risk AssessmentA

Run a structured security risk assessment and maintain a risk register — identify, analyze, evaluate, and treat risks (ISO 27005 / NIST SP 800-30) against the organization's risk criteria. Use for an enterprise/security risk assessment, risk register upkeep, or treatment decisions.

securitygosecurity
0
8
Host Hardening ReviewA

Review a host/OS (Linux or Windows) or its baseline image against CIS Benchmark hardening — accounts, services, network, logging, file permissions, and patching. Use to assess server/VM/golden-image hardening you're authorized to review.

ai-agentsgosecurity
0
8
Iac Security ReviewA

Review Infrastructure-as-Code (Terraform, CloudFormation, ARM/Bicep, Pulumi, Ansible, Helm) for security misconfigurations before deployment — public exposure, weak IAM, missing encryption, open networking, and hardcoded secrets. Use to shift-left and catch cloud/k8s misconfig at the code layer.

securityrustgo
0
8
Secrets Management ReviewB

Review how secrets are handled across code, IaC, CI/CD, containers, and config — hardcoding, sprawl, exposure, vaulting, rotation, and access scope. Use to assess secrets hygiene for a project or environment and find exposed credentials.

securitygoaws
0
8
K8s Cluster ReviewA

Review a Kubernetes cluster's security across control plane, RBAC, workload configuration, network policy, secrets, and admission control, mapped to the CIS Kubernetes Benchmark and the 4Cs model. Use for a comprehensive cluster security assessment of a cluster you're authorized to review.

securityrustgo
0
8
K8s Rbac ReviewA

Audit Kubernetes RBAC for least privilege and privilege-escalation paths — cluster-admin sprawl, wildcard/dangerous verbs, risky bindings, and service-account token exposure. Use to review who can do what in a cluster and find escalation to cluster-admin.

ai-agentsgonode
0
8
K8s Workload HardeningA

Review and harden Kubernetes workloads (pods/Deployments) against Pod Security Standards — privileged containers, host namespaces, hostPath, capabilities, securityContext, and admission enforcement. Use to assess or fix pod-level security for a workload or namespace.

ai-agentsrustgo
0
8
Ai Threat ModelA

Threat model an LLM / RAG / agentic AI system: map prompts, data sources, tools, identities, and trust boundaries, then enumerate AI-specific threats and mitigations. Use when designing or reviewing a GenAI feature's security.

ai-agentsrustgo
0
8
Owasp Llm Top10A

Assess an LLM-backed application against the OWASP Top 10 for LLM Applications, producing a per-category finding set with severity and mitigations. Use when reviewing a chatbot, copilot, RAG app, or any feature built on an LLM.

ai-agentsrustgo
0
8
Prompt Injection TestB

Test an LLM feature for direct and indirect prompt injection using a structured payload set, then record what succeeded and how to mitigate it. Use when assessing a chatbot, copilot, RAG app, or agent for input-handling weaknesses. Authorized testing only.

ai-agentsgotesting
0
8
Ml Pipeline Security ReviewA

Review the training / MLOps pipeline for security weaknesses — data-poisoning surface, feature-store and data-source trust, experiment-tracking and model-registry access control, secrets, and reproducibility/provenance. Use when assessing how models are built and promoted, not how they're served or consumed.

securityrustgo
0
8
Ml Supply Chain ReviewA

Review the provenance and integrity of models, datasets, and ML artifacts pulled from hubs/registries — unsafe deserialization (pickle, PyTorch/Keras/joblib), untrusted model sources, model/dataset tampering, and signing. Use when an app loads third-party model weights or datasets, or before promoting a model.

ai-agentsrustgo
0
8
Model Serving SecurityA

Harden a deployed model inference endpoint — authn/authz, rate limiting and abuse control, input validation, and exposure to model-extraction / inversion / membership-inference attacks. Use when reviewing how a model is served (REST/gRPC, Triton/TorchServe/KServe, or a hosted inference API), not how it was trained.

ai-agentsgogit
0
8
Masvs ReviewA

Review a mobile app (Android/iOS) against the OWASP MASVS control groups — storage, crypto, auth, network, platform, code quality, and resilience — producing a per-control finding set. Use for a structured mobile security assessment or design review. Authorized testing only.

securitygotesting
0
8