security-audit

conduct comprehensive assessments to identify vulnerabilities

1untested
update-rules-e2eworkflowdefault
Continuous threat intel pipeline that keeps SIGMA rules fresh against emerging Android malware with human-in-the-loop final gate
2untested
forge-check-securityworkflow
OWASP parallel scanning (6 dimensions) with risk aggregation and gate enforcement.
3untested
security-auditskill
Pre-release security verification and vulnerability inventory before deployment.
4untested
webassessmentskill
Comprehensive web application penetration testing with structured threat modeling and prioritized exploitation
5untested
pro-workflowplugin
Structured external red-team assessments where 71 skills auto-select by vulnerability class
6untested
security-reviewcommand
Pre-release security scanning when compliance and threat coverage matter
7untested
securityskill
Severity classification separates critical auth issues from style nits—allows teams to merge without blocking on low-severity findings.
8untested
vuln-discoveryworkflow
Structured agent orchestration with deterministic phase transitions and fault isolation.
9untested
vuln-discoveryworkflow
Structured agent orchestration with deterministic phase transitions and fault isolation.
10untested
security-lensskill
Catching common OWASP vulnerabilities (injection, weak auth, hardcoded secrets, XSS) in code review without requiring a full security audit.
11untested
security-auditor-saasskill
Blocking deployment when OWASP Top 10 vectors would otherwise reach production.
12untested
java-securityskill
OWASP Top 10 and Spring Security vulnerability detection beats generic code review.
13untested
security-reviewersubagent
Detecting OWASP Top 10 issues and enforcing secure-by-default patterns.
14untested
secure-code-guardianskill
Finding exploitable code patterns and guiding remediation in production applications.
15untested
vuln-scannersubagent
When infrastructure-as-code must be scanned for compliance violations and CVE risks.
16untested
skill-security-auditorskill
Pre-install security gating for untrusted community skills before adding to Claude Code
17untested
security-auditskill
Teams needing pre-deployment security checks and automated remediation of common Clawdbot vulnerabilities.
18untested
ctf-attack-authworkflow
security testing
19untested
security-bounty-hunterskill
Identifying reportable security issues in open-source projects before bug-bounty submission
20untested
security-hygieneskill
Continuous security scanning without slowing deployment (automated pre-merge gate)
21untested
security-scanskill
Baseline security assessment before manual penetration testing.
22untested
hunt-sessionskill
Discovering session vulnerabilities when generic scanners miss domain-specific chains.
23untested
hunt-websocketskill
Discovering websocket vulnerabilities when generic scanners miss domain-specific chains.
24untested
security-reviewersubagent
Pre-deployment security hardening of LLM-powered Python tools.
25untested
hunt-subdomainskill
Discovering subdomain vulnerabilities when generic scanners miss domain-specific chains.
26untested
mcpmcp_server
Automated security scanning within AI-assisted code generation workflows
27untested
hunt-sharepointskill
Discovering sharepoint vulnerabilities when generic scanners miss domain-specific chains.
28untested
hunt-sqliskill
Discovering sqli vulnerabilities when generic scanners miss domain-specific chains.
29untested
java-security-checkskill
Finding hardcoded secrets, SQL/command injection, weak crypto, insecure deserialization, and Spring Security misconfigs in Java code.
30untested
hunt-ssrfskill
Discovering ssrf vulnerabilities when generic scanners miss domain-specific chains.
31untested
hunt-sstiskill
Discovering ssti vulnerabilities when generic scanners miss domain-specific chains.