All authors
jassics avatar

Claude Skills by jassics

github.com/jassics
111 skillsA× 106B× 50 installs96 views
Mobile PentestA

Run a MASTG-based mobile penetration test (Android/iOS) combining static and dynamic analysis: storage inspection, traffic interception, platform-interaction abuse, and resilience checks. Use to actively test a mobile app you're authorized to assess.

developmentgotesting
0
8
Multimodal Injection TestA

Test a multimodal AI feature for cross-modal prompt injection and adversarial inputs — instructions hidden in images, OCR'd text, file metadata, or audio that the model treats as commands. Use on an authorized vision/audio/document-accepting app to validate non-text input handling.

ai-agentsrustgo
0
8
Multimodal Security ReviewA

Review a multimodal AI application's input handling and trust boundaries across every modality it accepts (image, audio, video, document), covering injection, unsafe parsing, provenance, and output handling. Use when assessing the security of a vision/audio/document-accepting feature.

ai-agentsrustgo
0
8
Network PentestA

Run an authorized network penetration test: host discovery, port/service enumeration, vulnerability identification, exploitation, and lateral movement/pivoting — within an agreed scope and rules of engagement. Use to actively test internal/external network security you're authorized to assess.

securityrustgo
0
8
Network Segmentation ReviewA

Review network segmentation and firewall/ACL design for security: zone separation, ruleset hygiene, lateral-movement containment, and zero-trust / microsegmentation. Use to assess or design network architecture defensively (not active testing).

ai-agentsrustgo
0
8
Protocol Security ReviewA

Assess the network protocols and services in use for security weaknesses — cleartext protocols, weak/outdated crypto and TLS, insecure or legacy services, and man-in-the-middle exposure. Use to review what's running on the network and how securely it communicates.

ai-agentsrustgo
0
8
Exposure DiscoveryA

Discover an organization's public exposures — leaked credentials and secrets, exposed services and storage, source-code/config leaks, and breach data — from public sources. Use to find what's already exposed about a target (offense) or to reduce your own exposure (defense). Authorized scope.

securitygogit
0
8
Osint FootprintingA

Map a target organization's external footprint and attack surface from public sources — domains, subdomains, IP ranges, exposed services, technologies, and organizational details. Use at the start of an engagement (or for attack-surface management) to see what an attacker sees. Authorized scope, public sources.

ai-agentsgotesting
0
8
People OsintA

Gather people- and organization-focused OSINT for an authorized social-engineering assessment — org structure, roles, contact patterns, and public footprint that inform realistic phishing/pretext scenarios. Use only within an authorized engagement; focus on assessing susceptibility and improving awareness.

ai-agentsgosecurity
0
8
ReconA

Run scope-bounded reconnaissance for a penetration test: enumerate the authorized attack surface (hosts, domains, services, technologies, exposure) and organize it for testing. Use at the start of an engagement, strictly within the agreed scope.

ai-agentsgotesting
0
8
Rag Security ReviewA

Assess a Retrieval-Augmented Generation application end-to-end — ingestion, embedding, vector store, retrieval, prompt assembly, and generation — for poisoning, data leakage, isolation, and citation-integrity issues. Use when reviewing the security of any RAG / knowledge-base-backed LLM feature.

ai-agentsrustgo
0
8
Retrieval Poisoning TestB

Test whether content planted in a RAG corpus (or otherwise retrieved) can steer the model's answers or trigger actions — i.e. indirect prompt injection and data poisoning via the retrieval path. Use on an authorized RAG app to validate ingestion/retrieval trust boundaries.

ai-agentsrustgo
0
8
Vector Store Isolation TestA

Test that retrieval enforces per-user / per-tenant authorization so one user cannot retrieve another's documents through the RAG system. Use on an authorized multi-tenant or multi-user RAG app to validate access control on retrieval.

ai-agentsrustgo
0
8
Adversary EmulationA

Plan and run an objectives-based adversary-emulation engagement: select a relevant threat actor, build an ATT&CK-mapped emulation plan across the attack lifecycle, execute within rules of engagement, and assess detection/response. Use for full-scope red-team work. Strictly authorized engagements only.

securitygosecurity
0
8
Ai Use Case IntakeA

Intake a proposed AI use case and risk-classify it (EU AI Act tier / NIST AI RMF context), then gate it with the controls and documentation required before it can proceed. Use for AI governance intake, an AI use-case review board, or deciding what rigor a new AI project needs.

ai-agentsgotesting
0
8
Sast ReviewA

Run or ingest static application security testing (SAST) results on a codebase, triage them to remove false positives, and confirm the real issues with code evidence and remediation. Use when reviewing source code for security flaws or cleaning up noisy scanner output.

ai-agentspythonrust
0
8
Sca ReviewA

Analyze a project's dependencies (software composition analysis): generate/inspect an SBOM, find known-vulnerable and risky components, and prioritize upgrades. Use when reviewing third-party/open-source risk in a codebase or build.

securitygoapi
0
8
Secure ReviewA

Manual, adversarial secure code review focused on exploitable vulnerabilities — OWASP Top 10, injection, authn/authz, business-logic abuse, crypto, SSRF, deserialization, secrets, race conditions. Reviews the current git diff by default, or a path/PR. Supports phase-scoped commands (auth, bizlogic, injection, headers, pii, deadcode, all) and poc/fix/chain/triage follow-ups. Complements `sast-review` (scanner triage) with human-style reasoning over the full change, especially business-logic fl...

securitygobash
0
8
Safe Function LintA

Scan Python or React/JS code for outdated, banned, or vulnerable functions/methods (eval, pickle.loads, subprocess shell=True, dangerouslySetInnerHTML, md5 for passwords, etc.) and propose the exact safe alternative for each hit. Use when reviewing a diff/PR, before a commit, or when the user asks "is this function safe", "any vulnerable functions here", or wants a secure-coding pass on Python or React code.

ai-agentspythongo
0
8
Secret GuardB

Detect hardcoded secrets, cloud keys (AWS/GCP/Azure), tokens, .env files, and sensitive config before they're committed or pushed, and verify .gitignore covers the patterns that must never be tracked. Use when the user is about to commit/push, asks "did I leak a secret", "check for hardcoded keys", "is my .gitignore missing anything", or when reviewing any diff that touches config/env files. This is the manual/interactive counterpart to the enforced git hooks this plugin installs — see README...

securitygoaws
0
8
Security InvestigationA

Drive a security investigation from a lead or hypothesis to an evidence-backed conclusion — correlate telemetry across sources, enrich with intel, reconstruct a timeline, scope impact, and reach a defensible verdict. Use for a deeper analytical investigation (beyond single-alert triage), e.g. an escalated or complex case.

ai-agentsgosecurity
0
8
Prd Security InjectionA

Read a PRD, feature brief, or an AI coding assistant's plan/prompt that has no security content, and inject concrete, testable security requirements and an acceptance checklist back into it — before code is written. Use for "vibe coded" or fast/AI-assisted features where security was never mentioned in the prompt, PRD, or design doc, not for reviewing a design that already exists (that's `security-design-review`).

securityrustgo
0
8
Secure Architecture MaturityA

Assess an architecture's control completeness against OWASP ASVS and an organization's security-practice maturity against OWASP SAMM. Use when a design review needs to state *how much* verification is enough (ASVS level) and whether secure-architecture practice is repeatable or one-off (SAMM maturity) — not just a single design's threats and controls.

ai-agentsgotesting
0
8
Security Design ReviewA

Review a system or architecture design for security — trust boundaries, control selection, secure-by-design principles, defense-in-depth, and security requirements — and produce prioritized design recommendations. Use when assessing or shaping an architecture/design (not testing a running system).

securityrustgo
0
8
Architecture DiagramA

Produce a security architecture, network, or trust-boundary diagram of a system, highlighting components, zones, controls, and exposure. Use when documenting a design review, network segmentation, or cloud architecture from a security perspective.

ai-agentsrustgo
0
8
Attack TreeA

Build an attack tree for a stated attacker goal or asset, decomposing it into AND/OR sub-goals and leaf attack steps, then render it. Use when threat modeling, planning an engagement, or explaining how an asset could be compromised.

ai-agentsgonode
0
8
InfographicA

Create a shareable single-page infographic / one-pager summarizing a security posture, assessment result, metric set, or program update for a non-technical or executive audience. Use when the ask is "make this presentable / visual / board-ready" rather than a full report.

ai-agentsgosecurity
0
8
MindmapA

Turn a security topic into a structured mindmap — recon surface, an attack chain, a framework breakdown, or study notes. Use when organizing or explaining a topic radially rather than as a flow or report.

ai-agentsgonode
0
8
Threat Model DfdA

Draw a Data Flow Diagram with trust boundaries for threat modeling: external entities, processes, data stores, data flows, and the boundaries between them. Use when starting a STRIDE/PASTA threat model or documenting how data moves through a system.

ai-agentsrustgo
0
8
Secure PipelineA

Review or design the security of a CI/CD pipeline: shift-left scanning gates (SAST/SCA/secret/IaC), software supply-chain integrity (SBOM, pinning, signing/ provenance), and pipeline hardening (least-privilege runners, isolation, protected branches). Use to build security into the SDLC or assess a pipeline's controls.

securityrustgo
0
8
Export To DriveA

Export a finished security artifact (report, executive summary, diagram, spreadsheet of findings) to Google Drive — right folder, clear naming, and shareable with the intended audience. Use when a deliverable needs to be handed to stakeholders who live in Drive/Docs/Sheets rather than a wiki or tracker.

ai-agentsgosecurity
0
8
Publish Finding To JiraA

Turn a security finding (vuln, pentest issue, review item) into a well-formed Jira issue — mapped severity→priority, remediation/repro in the body, labels and components set, and dedup-checked against existing issues. Use when findings need to become tracked, assignable work in Jira.

ai-agentsgosecurity
0
8
Publish Report To ConfluenceA

Publish a security report, runbook, threat model, or assessment writeup to Confluence — correct space/parent, consistent page structure, labels, and links back to related issues/pages. Use when a finished document needs to live in the team wiki, not just a local file.

ai-agentsgosecurity
0
8
Asvs ReferenceA

Look up the right OWASP ASVS (Application Security Verification Standard) v5.0 chapter and verification level (L1/L2/L3) for a control, requirement, or finding. Use when a design review, secure-code review, or pentest finding needs a consistent ASVS citation, or when scoping how deep a verification effort should go.

ai-agentsgotesting
0
8
Attack LookupA

Look up MITRE ATT&CK tactics, techniques, and mitigations, and map an observed behavior, finding, or detection to the right technique ID(s). Use whenever work needs a consistent ATT&CK reference — detection coverage, threat reports, red-team TTP planning, or tagging a finding.

ai-agentsrustgo
0
8
Framework MappingA

Map a finding, control, or requirement across security frameworks — CWE, NIST CSF & SP 800-53, CIS Controls, ISO/IEC 27001 — so one piece of work can be expressed in whichever framework the audience uses. Use when a finding needs a CWE, or when aligning controls/gaps across compliance frameworks.

ai-agentsgosql
0
8
Owasp ReferenceA

Look up and map to the right OWASP Top 10 family — Web, API, LLM, or Mobile — and give the canonical category ID/name for a finding. Use when you need a consistent OWASP reference for tagging findings, scoping a review, or aligning a report across the appsec/genai plugins.

ai-agentsgotesting
0
8
Secure Coding KbA

Look up the safe idiom and known-risky API/library for a language or framework (Python, JS/TS/Node, Java, Go, C/C++, Ruby) before or while writing code — a design/build-time cheat-sheet, distinct from post-hoc scanning. Use when writing or reviewing code, scoping a PRD's tech stack, or advising an AI-assisted/vibe-coded change on which APIs and libraries to avoid up front.

developmentpythongo
0
8
CvssA

Score a vulnerability with CVSS v4.0: derive the metric vector (Base, plus Threat/Environmental refinement where context supports it), compute the exact score via the official algorithm, and explain each metric choice. Use whenever a finding needs a defensible severity rather than a guess.

ai-agentspythongo
0
8
Executive SummaryA

Distill technical security results into a concise, business-oriented summary for leadership or a board. Use when the audience is executives/non-technical stakeholders and the ask is risk and decisions, not technical detail.

ai-agentsrustgo
0
8
FindingA

Write up a single security finding in a consistent, actionable format: title, severity (CVSS), affected assets, evidence, impact, reproduction, and remediation. Use whenever you've identified one issue and need it documented for a report or ticket.

ai-agentsgoapi
0
8
Pentest ReportA

Assemble a complete penetration test / security assessment report from a set of findings and engagement scope. Use at the end of an engagement to produce the deliverable document. Composes individual findings and an executive summary.

securitygotesting
0
8
Alert TriageA

Triage a SIEM/EDR alert end-to-end — validate it's real, enrich and scope it, reach a consistent verdict, and decide escalate vs. close with documented rationale. Use when working a SOC alert queue and you need a repeatable, defensible triage.

ai-agentsgo
0
8
Artifact Provenance VerificationA

Assess and establish build artifact provenance and integrity — SLSA provenance level, signing/attestation (Sigstore/cosign, in-toto), and verification at deploy/admission. Use when you need to prove an artifact (container image, package, binary) came from the expected source and build, untampered.

ai-agentsrustgo
0
8
Dependency Supply Chain ReviewA

Review third-party dependencies for supply-chain trust risk — typosquatting, dependency confusion, maintainer/abandonment risk, unpinned versions, and malicious install scripts — not just known-CVE counts. Use when assessing how much a project trusts code it didn't write, or vetting a new dependency.

ai-agentsrustgo
0
8
Pipeline Integrity ReviewA

Review a CI/CD pipeline for supply-chain tampering risk — build isolation, runner/agent trust, secret exposure, mutable dependencies, and poisoned-pipeline (PPE) / unauthorized-workflow paths. Use when hardening GitHub Actions, GitLab CI, Jenkins, or similar against build-system compromise.

securityrustgo
0
8
Pipeline Timeout LintA

Check GitHub Actions workflows for the two runaway-risk controls that have no safe platform default — a job with no `timeout-minutes`, and a workflow with no `concurrency` group. Use when authoring or reviewing a `.github/workflows/*.yml` file, before merging a new/changed pipeline, or when asked "will this pipeline run forever", "does this workflow have a timeout", or "check my CI config for runaway risk". Narrower and faster than the full `pipeline-integrity-review` audit (which covers supp...

ai-agentspythonrust
0
8
Cti AnalysisA

Run the cyber threat intelligence lifecycle for a question or dataset — direction, collection, processing, analysis with structured techniques, and dissemination — to produce an assessed, actionable intelligence product. Use to turn raw threat data into decision-useful intelligence for a defined audience.

ai-agentsgosecurity
0
8
Ioc EnrichmentA

Enrich and pivot on indicators of compromise — resolve context, infrastructure, and relationships, assess confidence and relevance, and decide block vs. monitor. Use to add analytic value to raw IOCs from an incident, feed, or hunt.

ai-agentsgo
0
8
Threat Actor ProfilingA

Profile a threat actor or campaign — their TTPs (mapped to MITRE ATT&CK), targeting, tooling, infrastructure, and likely intent — to support threat-informed defense. Use to understand who might target you and how, and to prioritize defenses.

ai-agentsgosecurity
0
8