
Claude Skills by jassics
github.com/jassicsReview agent-to-agent (A2A) / multi-agent-system trust: peer identity and authentication, message integrity, capability-negotiation trust, and delegation-chain privilege narrowing. Use when an orchestrator dispatches to sub-agents or peer agents (same or different trust domain) rather than calling a tool — distinct from `mcp-security-review`'s tool-boundary case.
Test the agent execution harness/runtime itself — LangChain/LangGraph, AutoGen, CrewAI, custom ReAct-style loops, or computer-use/browser-use agents — for intermediate-state poisoning, unscoped action spaces, and missing resource limits. Use when the agent isn't built on Claude Code (see `claude-config-security` for that) and you need to verify the loop that feeds tool/environment output back into the model actually enforces a trust boundary.
Assess an autonomous / tool-using AI agent for security end-to-end: tool privileges, autonomy and approval boundaries, excessive agency, memory/state poisoning, and multi-agent trust. Use when reviewing the security of an AI agent or agentic workflow.
Test what an AI agent will actually do without human confirmation, including under injected-goal / prompt-injection scenarios, to validate its autonomy and approval boundaries. Use on an authorized agent to confirm excessive-agency controls hold in practice.
Review the security of MCP (Model Context Protocol) servers/clients an agent uses: server trust tier, tool/resource description and result poisoning, confused-deputy risk, consent/scope UX, and supply-chain pinning. Use when an agent or assistant integrates one or more MCP servers, especially third-party or community ones.
Inventory the tools/functions an AI agent can call and audit their privileges, side effects, and approval requirements to find excessive-agency and least-privilege gaps. Use when reviewing an agent's tool/function surface.
Operationalize a safety/prompt-injection eval suite into an enforced CI gate — not just a one-off report — using the ready-to-copy promptfoo/garak template, a regression baseline, and a burn-in rollout. Use when a safety eval already exists (or is being designed) and needs to actually block regressions on every release rather than being run manually once.
Assemble a structured assurance / safety case for deploying an AI system — an explicit argument that it is acceptably safe for its context, backed by evidence (harm model, evals, guardrails, fairness, governance). Use to support a go/no-go deployment decision or an audit/sign-off.
Assess an AI model, feature, or dataset for bias and fairness across groups — representational and allocative harms, disparate performance, and skewed refusals — using appropriate fairness metrics, and recommend mitigations. Use when evaluating whether an AI system treats people equitably.
Review or design the content-safety guardrails of an AI system — input/output classifiers, refusal and safe-completion behavior, escalation/human handoff, and coverage across harm categories, languages, and modalities. Use when assessing or building the safety controls around a model.
Systematically enumerate the potential HARMS of an AI system — to users, third parties, vulnerable groups, and society — under normal use, misuse, and malfunction, then rank them and map mitigations. This is the AI-safety analog of threat modeling (which targets attackers). Use when designing or reviewing an AI feature for safety, not security.
Gap-assess an AI system or program against a responsible-AI / governance framework — NIST AI RMF, ISO/IEC 42001, EU AI Act, OECD principles — covering governance, transparency, accountability, human oversight, documentation, and monitoring, then produce a prioritized roadmap. Use for AI governance, audit readiness, or compliance gap analysis.
Design and run a safety evaluation suite for an AI model or feature across harm categories — refusals on disallowed content, robustness, over-refusal vs helpfulness, groundedness/truthfulness — with rubrics and pass/fail thresholds. Use to measure an AI system's safety, establish a baseline, or gate a release.
Responsibly red-team an AI system to find SAFETY failures — harmful outputs, jailbreaks that defeat safety guardrails, and foreseeable-misuse / dangerous- capability elicitation — so they can be mitigated. Use to stress-test safeguards before/after release. Controlled, authorized, mitigation-focused; not for producing or retaining harmful content.
Test an API's authorization — BOLA (object-level), BFLA (function-level), and BOPLA (property-level / mass assignment) — to confirm each request is authorized for the caller. Use to validate the top OWASP API risks on an authorized target.
Assess a REST or GraphQL API against the OWASP API Security Top 10 (2023), producing a per-category finding set with severity and remediation. Use when reviewing or pentesting an API. Authorized testing only.
Plan and run a purple-team exercise: collaboratively emulate specific ATT&CK techniques and measure whether detection and response actually work, then close the gaps. Use to validate defensive coverage against real adversary behavior. Authorized environments only.
Produce a board / executive security presentation — risk posture and direction, top risks in business terms, program progress against strategy, the metrics that matter, and investment asks tied to risk. Use to prepare for a board or leadership meeting. Audience is non-technical decision-makers.
Translate technical security risk into business and financial terms — top risk scenarios, likelihood × impact, a risk register, and (where useful) quantified loss ranges (FAIR-aware) — to support executive decisions on treat/transfer/accept. Use to communicate or prioritize cyber risk for leadership.
Build or assess a security program strategy and roadmap — current-vs-target maturity, gaps, prioritized initiatives aligned to business objectives and risk appetite, with outcomes, metrics, and budget framing. Use for security program planning, a strategy refresh, or a maturity assessment.
Check a Claude Code agent's runaway-risk controls — a missing or invalid `maxTurns` (unbounded turns/cost), an unattended (bypass/acceptEdits) or backgrounded agent with no turn bound, a hook or stdio MCP server with no `timeout`, and prose that tells the model to disregard turn limits or resist interruption — in YOUR OWN repo's `.claude/agents/*.md` or a plugin you're authoring. Use when writing or reviewing a subagent definition, before shipping a plugin agent, or when asked "does this agen...
Statically review a Claude Code / AI-agent setup for security misconfigurations — risky hooks, over-broad permissions, untrusted or cleartext MCP servers, hardcoded secrets, endpoint redirection, over-privileged agents/skills, and prompt-injection in steering files. Use when asked to audit a `.claude/` directory, `settings.json`, `.mcp.json`, a plugin/marketplace, or `CLAUDE.md`, or to add a config-security gate to CI. Drives the `agentscanner` CLI.
Audit cloud IAM (AWS/Azure/GCP) for least privilege: over-permissioned identities, wildcard/admin grants, public or cross-account access, unused credentials, and privilege-escalation paths. Use to review identity risk — the top cause of cloud compromise.
Scan a cloud environment (AWS/Azure/GCP) for high-impact misconfigurations and exposures — public storage, open ingress, unencrypted data, exposed secrets/ metadata, missing logging — and prioritize quick wins. Use for a fast exposure sweep on an authorized environment.
Review a cloud environment's security posture (AWS/Azure/GCP) across IAM, network, data protection, logging/monitoring, and workload configuration, mapped to CIS benchmarks, and produce ranked findings. Use for a CSPM-style assessment of an account/subscription/project you're authorized to review.
Establish or assess an org-wide secure-by-design program — paved roads / golden paths with secure defaults, automated guardrails, and developer enablement — so the secure way is the default, fast way. Use for engineering-org security strategy at scale (not a single system's design).
Assess the security risk of a technology or product decision for leadership — new technology/vendor adoption, build-vs-buy, third-party/supply-chain, or M&A technical due diligence — and give a clear recommendation with trade-offs. Use to inform a strategic technology decision.
Assess detection coverage against the MITRE ATT&CK matrix: which tactics/techniques are covered, partially covered, or blind, weighted by data-source availability and threat relevance. Use to find and prioritize detection gaps for a SOC/program.
Develop or review a detection rule (Sigma, YARA, KQL/SPL/EQL) for a specific behavior or threat, mapped to MITRE ATT&CK, with test cases and false-positive tuning. Use when building, porting, or reviewing detections from a TTP, IOC, or incident finding.
Run a hypothesis-driven threat hunt: form a hypothesis (often from ATT&CK or threat intel), query telemetry for evidence, analyze findings, and convert results into detections. Use to proactively search for adversary activity that existing alerts may miss.
Aggregate a fast, diff-scoped security check before `git commit`/`git push` — secrets/gitignore hygiene, SAST/SCA on changed files, and IaC/Claude-config checks where relevant — into a single go/no-go verdict. Use before committing or pushing, not as a full-repo audit.
Perform forensic triage on a host or artifacts — collect and analyze disk, memory, and log evidence with proper handling, then build an incident timeline. Use to investigate a compromised system or scope an incident. Preserve evidence integrity.
Drive a security incident through the response lifecycle (NIST SP 800-61 / SANS PICERL): triage and scope, contain, eradicate, recover, and capture lessons learned. Use to coordinate or work an active incident. Authorized responders only.
Extract and operationalize indicators (IOCs) and behaviors (IOAs) from an incident or sample — atomic, computed, and behavioral — and prepare them for detection, blocking, and intel sharing. Use after/within an investigation to turn findings into defensive value.
Gap-assess an organization or system against a compliance framework (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, NIST CSF/800-53), mapping controls to evidence, identifying gaps, and producing a prioritized remediation and audit-readiness plan. Use for compliance gap analysis, certification prep, or audit readiness.
Develop or review security governance documents — policies, standards, procedures, and guidelines — aligned to a framework and the organization's risk, with a clear hierarchy, ownership, and lifecycle. Use to write, assess, or rationalize a security policy set.
Run a structured security risk assessment and maintain a risk register — identify, analyze, evaluate, and treat risks (ISO 27005 / NIST SP 800-30) against the organization's risk criteria. Use for an enterprise/security risk assessment, risk register upkeep, or treatment decisions.
Review a host/OS (Linux or Windows) or its baseline image against CIS Benchmark hardening — accounts, services, network, logging, file permissions, and patching. Use to assess server/VM/golden-image hardening you're authorized to review.
Review Infrastructure-as-Code (Terraform, CloudFormation, ARM/Bicep, Pulumi, Ansible, Helm) for security misconfigurations before deployment — public exposure, weak IAM, missing encryption, open networking, and hardcoded secrets. Use to shift-left and catch cloud/k8s misconfig at the code layer.
Review how secrets are handled across code, IaC, CI/CD, containers, and config — hardcoding, sprawl, exposure, vaulting, rotation, and access scope. Use to assess secrets hygiene for a project or environment and find exposed credentials.
Review a Kubernetes cluster's security across control plane, RBAC, workload configuration, network policy, secrets, and admission control, mapped to the CIS Kubernetes Benchmark and the 4Cs model. Use for a comprehensive cluster security assessment of a cluster you're authorized to review.
Audit Kubernetes RBAC for least privilege and privilege-escalation paths — cluster-admin sprawl, wildcard/dangerous verbs, risky bindings, and service-account token exposure. Use to review who can do what in a cluster and find escalation to cluster-admin.
Review and harden Kubernetes workloads (pods/Deployments) against Pod Security Standards — privileged containers, host namespaces, hostPath, capabilities, securityContext, and admission enforcement. Use to assess or fix pod-level security for a workload or namespace.
Threat model an LLM / RAG / agentic AI system: map prompts, data sources, tools, identities, and trust boundaries, then enumerate AI-specific threats and mitigations. Use when designing or reviewing a GenAI feature's security.
Assess an LLM-backed application against the OWASP Top 10 for LLM Applications, producing a per-category finding set with severity and mitigations. Use when reviewing a chatbot, copilot, RAG app, or any feature built on an LLM.
Test an LLM feature for direct and indirect prompt injection using a structured payload set, then record what succeeded and how to mitigate it. Use when assessing a chatbot, copilot, RAG app, or agent for input-handling weaknesses. Authorized testing only.
Review the training / MLOps pipeline for security weaknesses — data-poisoning surface, feature-store and data-source trust, experiment-tracking and model-registry access control, secrets, and reproducibility/provenance. Use when assessing how models are built and promoted, not how they're served or consumed.
Review the provenance and integrity of models, datasets, and ML artifacts pulled from hubs/registries — unsafe deserialization (pickle, PyTorch/Keras/joblib), untrusted model sources, model/dataset tampering, and signing. Use when an app loads third-party model weights or datasets, or before promoting a model.
Harden a deployed model inference endpoint — authn/authz, rate limiting and abuse control, input validation, and exposure to model-extraction / inversion / membership-inference attacks. Use when reviewing how a model is served (REST/gRPC, Triton/TorchServe/KServe, or a hosted inference API), not how it was trained.
Review a mobile app (Android/iOS) against the OWASP MASVS control groups — storage, crypto, auth, network, platform, code quality, and resilience — producing a per-control finding set. Use for a structured mobile security assessment or design review. Authorized testing only.