Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
Browse security skills
Showing 1ā24 of 3,624 skills
Run a structured security audit on any WordPress site ā core integrity, plugin/theme CVE cross-check, wp-config and file-permission hardening, malware/compromise detection, and triaged code review of risky plugins. Use this skill whenever the user asks to "audit WordPress security", "check my WP site for vulnerabilities", "is my WordPress site secure", "scan my site", "security check", "harden WordPress", "check my plugins for vulnerabilities", "was my site hacked", or shares a WordPress site...
Draft, update, and publish SEO blog posts to Blogizi from a local repo using the Blogizi CLI and account API. Use when the user mentions Blogizi, blogizi draft/update/publish, posting markdown to a blog, SEO blog posts, or integrating with the Blogizi public API / Obsidian plugin workflow.
Use when a user wants to review the public security posture of an AI-generated, vibe-coded, or deployed website through an authorized passive scan, especially for security headers, exposed secrets, source maps, public files, and deployment mistakes.
Full Crusader security-proxy integration for Claude Code. Hunt web/API vulnerabilities (IDOR/BOLA, auth, injection, SSRF/OOB, races) over Crusader's native MCP, confirm with oracles, and turn confirmed bugs into shareable self-proving crusader://poc/ links. Use when testing an app, reproducing a reported bug, or whenever the user mentions Crusader, a proxy hunt, or packaging a proof-of-concept.
Perform codebase analysis and architecture mapping as the first phase of a security assessment. Explores the tech stack, frameworks, entry points, data flows, and trust boundaries. Outputs sast/architecture.md. Run this before any vulnerability detection skill. Use when asked to analyze a codebase for security or when sast/architecture.md does not yet exist.
Detect and test for OWASP API3:2023 Broken Object Property Level Authorization
'Detects and analyzes Bluetooth Low Energy (BLE) security attacks including
Detect and investigate Azure service principal abuse including privilege
'Detecting exposed AWS credentials in source code repositories, CI/CD
'This skill covers detecting cyber attacks targeting Supervisory Control
'Detect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition,
Detect and prevent API enumeration attacks including BOLA and IDOR exploitation
Deploy and configure Tailscale as a WireGuard-based zero trust mesh VPN
Deploy a Software-Defined Perimeter using the CSA v2.0 specification
'Deploys and configures osquery for real-time endpoint monitoring using
'Deploying Cloudflare Access with Cloudflare Tunnel to provide zero trust
'Deploys deception-based honeytokens in Active Directory including fake
'Executes containment strategies to stop active adversary operations
'Configuring Zscaler Private Access (ZPA) to replace traditional VPN
Writes security user stories and security-aware acceptance criteria that fit a Scrum backlog, converting threats, scan findings, and compliance requirements into INVEST-compliant stories with Given/When/Then criteria and regression tests. Use this (not general story writing) whenever the story or criteria concern a security control, vulnerability, or compliance requirement. Triggers on: "write a security story", "security acceptance criteria", "acceptance criteria for rate limiting/auth/valid...
Use when the user wants to check, understand, or harden the security of their Mac, or asks whether their laptop is secure and what to fix. Runs a full macOS security audit, explains each finding in plain language (what it is, why it matters, what changing it would affect), and applies only the fixes the user approves. Also produces SOC 2 / ISO 27001 / NIST / CIS evidence on request. Triggers on phrases like "is my Mac secure", "audit my laptop", "harden my Mac", "what security gaps do I have"...
This skill should be used when the user asks to \"pentest WordPress sites\", \"scan WordPress for vulnerabilities\", \"enumerate WordPress users, themes, or plugins\", \"exploit WordPress vu...
This skill should be used when the user asks to \"escalate privileges on Windows,\" \"find Windows privesc vectors,\" \"enumerate Windows for privilege escalation,\" \"exploit Windows miscon...
Advanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization.