
Claude Skills by seaworld008
github.com/seaworld008Regulatory compliance and audit agent. Maps business regulatory requirements (SOC2/PCI-DSS/HIPAA/ISO 27001), checks control implementations, designs audit trails, and implements Policy as Code. Use when compliance auditing is needed.
Audit Firestore and Cloud Storage rules for authorization, tenant isolation, field validation, and emulator coverage when data models or rules change.
Audit GitHub Actions workflows for unsafe triggers, expression injection, credential exposure, and supply-chain attack paths.
用于通过 Syft 生成 SBOM,并用 Grype 扫描容器镜像、文件系统、软件包、归档和 SBOM 漏洞。
Design or audit ISO 27001 ISMS controls, security risk treatment, and compliance evidence, including healthcare and medical-device contexts.
Use when checking URL availability, dead links, redirect chains, suspicious domains, documentation link health, or link-risk evidence before publishing.
用于通过 OSV-Scanner 检查锁文件、清单、SBOM、Git 历史和源码树中的开源依赖漏洞。
Audit codebases for exploitable security vulnerabilities with concrete attack paths, impact, and source evidence.
Security audit workflow for AI-generated application code, APIs, infrastructure changes, dependencies, secrets, auth flows, and pull requests before they ship.
Use when checking language or framework security best practices, producing security review reports, identifying insecure defaults, and recommending secure-by-default improvements.
用于基于 Git 历史分析安全所有权、敏感代码归属、bus factor、CODEOWNERS 现实差距和风险热点。
Perform authorized security assessments, vulnerability scans, and penetration tests with explicit targets, scope, evidence, and remediation guidance.
Review code changes for injection, XSS, authentication, authorization, cryptography, and other security defects with evidence-based severity.
Use when creating threat models from codebases, architectures, assets, trust boundaries, attacker capabilities, abuse paths, and mitigation plans.
用于通过 Semgrep 执行应用安全 SAST、源码扫描、自定义规则、密钥流程和供应链依赖分析。
用于只读查询 Sentry issues、events 和服务健康数据,汇总线上错误并辅助生产问题排查。
Audit external agent skills before installation for malicious instructions, unsafe scripts, excessive permissions, dependency risks, and data exfiltration.
Use before installing or trusting an external skill to inspect instructions, scripts, permissions, dependencies, provenance, and suspicious behavior for security and reliability risks.
用于通过 Trivy 扫描仓库、容器镜像、文件系统、rootfs、SBOM、Kubernetes、IaC、密钥、许可证和系统 CVE。
用于通过 Vuls 对 Linux、FreeBSD、容器、WordPress、库和网络设备执行 Agentless CVE 扫描。
代码库理解、功能发现、数据流追踪和上下文调查。
Review user corrections or session outcomes to propose durable workflow improvements. Persist memory or edit agent guidance only when requested.
变更前影响分析,评估依赖链和一致性风险。
缺陷调查、复现步骤、根因分析和影响评估。