
Claude Skills by jassics
github.com/jassicsRun a MAESTRO threat model — the Cloud Security Alliance's layered framework for multi-agent / agentic AI systems — enumerating threats at each layer of the agent stack and across agent-to-agent and cross-layer trust boundaries. Use when threat modeling a multi-agent or agentic AI system where agent-to-agent trust, orchestration logic, and delegated tool use matter more than a single data flow.
Run the PASTA (Process for Attack Simulation and Threat Analysis) seven-stage, risk-centric threat model that ties technical threats to business impact. Use for a deeper, attacker-simulation threat model where business risk alignment matters (vs. the faster STRIDE pass).
Rank a set of enumerated threats or findings by risk (likelihood × impact) and map each to a prioritized mitigation. Use after STRIDE/PASTA enumeration or any time you have a threat/finding list that needs prioritization.
Run a STRIDE threat model over a system: build/ingest a DFD, then enumerate Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, and Elevation of privilege threats per element and trust-boundary crossing, with mitigations. Use when threat modeling an application, service, or design.
Manage the vulnerability remediation lifecycle: assign owners and SLAs, track fix/verify/close states, handle risk acceptances and exceptions, and report program metrics (SLA compliance, MTTR, aging, recurrence). Use when turning a prioritized list into tracked, accountable work.
Rank a set of vulnerabilities by real-world risk using CVSS (severity), EPSS (exploit probability), CISA KEV (known exploited), and asset/exposure context — so remediation effort goes to what actually matters first. Use when a triaged finding list needs a defensible "fix this first" order.
Triage raw vulnerability-scanner output (Nessus/Qualys/Trivy/Grype/OpenVAS, cloud or container scans): normalize, deduplicate, validate, and cut false positives so the list is trustworthy before prioritization. Use when handed a scan export or a pile of findings that needs to become an actionable backlog.
Test a web app's authorization: IDOR/BOLA, missing function-level access control, privilege escalation (horizontal and vertical), and forced browsing. Use to validate OWASP A01 on an authorized target — the most prevalent web risk.
Test a web app for injection flaws — SQL/NoSQL, OS command, LDAP, template injection, and cross-site scripting (XSS). Use to validate OWASP A03 on an authorized target by probing where untrusted input reaches an interpreter or sink.
Assess a web application against the OWASP Top 10 (2021), producing a per-category finding set with severity and remediation. Use when reviewing or pentesting a web app for the most common, highest-impact web risks. Authorized testing only.
One or two sentences naming the SITUATION, INPUTS, and OUTCOME so Claude knows exactly when to fire this skill. This text is always in context — be specific but tight. Example: "Assess an API endpoint against the OWASP API Top 10 and produce a ranked findings table. Use when reviewing a REST/GraphQL API for authz, rate-limiting, or schema-abuse issues."