Security-Scanner Agent fuer fabrikIQ und andere Projekte. Fuehrt umfassende Sicherheitspruefungen durch. Trigger bei: (1) Pre-commit Validation, (2) PR-Creation, (3) Weekly Security Audits, (4) Nach Dependency-Updates, (5) Vor Production Deployments. <example> Context: User moechte vor einem Commit sicherstellen, dass keine Secrets committed werden. user: "Ich will gleich committen. Pruefe mal auf Secrets." assistant: "Ich starte den security-scanner Agent, um den Code auf API Keys, Tokens und andere Secrets zu pruefen." <Task tool call to security-scanner agent> </example> <example> Context: Weekly Security Audit des fabrikIQ-Projekts. user: "Fuehre den woechentlichen Security-Scan durch." assistant: "Ich fuehre einen vollstaendigen Security-Scan durch: Secret Detection, Dependency Audit, OWASP Patterns, Security Headers und Rate Limiting." <Task tool call to security-scanner agent> </example> <example> Context: User hat Dependencies aktualisiert und will Vulnerabilities pruefen. user: "Ich habe npm update und pip install -U gemacht. Gibt es Sicherheitsprobleme?" assistant: "Ich scanne die aktualisierten Dependencies auf bekannte Vulnerabilities mit dem security-scanner Agent." <Task tool call to security-scanner agent> </example> <example> Context: PR-Review mit Security-Fokus. user: "Review den PR #42 auf Security-Probleme." assistant: "Ich analysiere die geaenderten Dateien im PR auf Security-Patterns: SQL Injection, XSS, Hardcoded Credentials und fehlende Input-Validation." <Task tool call to security-scanner agent> </example>
日本語の概要は準備中です。原文の説明を表示しています。
aibot88/sec_skill_store☆ 42026年5月27日 更新
AWS security service suitability, coverage and cost recommendations: WAF/origin overlap, AWS Network Firewall inspection coverage and policy review, VPC endpoint, Transit Gateway/Cloud WAN segmentation and DNS Firewall security-control suitability, certificate renewal ownership and monitoring, incident response triage ownership, centralized security log store (CloudWatch or Security Lake). Also factual configuration, findings, data sources and severity scoring for GuardDuty, Inspector, Security Hub V2/OCSF (Exposure, connectors, automation), Security Hub CSPM/ASFF (standards, controls), Macie, Detective, Security Lake, AWS Security Incident Response membership and case coverage, and Organizations security policies. Applies to advisory security-service choices even when one service is named. Implementation, rule or code authoring, deployment, scans and troubleshooting outside these factual procedures belong to specialist skills. Supports local AWS CLI and AWS MCP.
日本語の概要は準備中です。原文の説明を表示しています。
aws/agent-toolkit-for-aws☆ 2,8412026年10月10日 更新
Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks. Use when the user mentions 'container security,' 'Docker security,' 'Dockerfile audit,' 'Kubernetes security,' 'K8s security,' 'pod security,' 'container hardening,' 'kubectl audit,' 'image scanning,' 'distroless,' 'rootless containers,' 'pod security policy,' 'pod security standards,' 'PSS,' 'network policy,' 'OPA Gatekeeper,' 'Kyverno,' 'runtime security,' or needs to review container or orchestration security.
日本語の概要は準備中です。原文の説明を表示しています。
briiirussell/cybersecurity-skills☆ 4132026年5月27日 更新
Uses Postman to perform structured API security testing by building collections that test for OWASP API Security Top 10 vulnerabilities including authentication bypass, authorization flaws, injection, and data exposure. The tester creates environments with multiple user roles, writes test scripts for automated security validation, and integrates Postman with OWASP ZAP and Newman for CI/CD security testing. Activates for requests involving Postman security testing, API security collection, aut...
日本語の概要は準備中です。原文の説明を表示しています。
MustafaKemal0146/fetih☆ 52026年10月11日 更新
Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network communication, authentication, cryptography, and platform-specific security controls. The tester performs static analysis of application binaries, dynamic analysis at runtime, and API security testing to evaluate the complete mobile attack surface. Activates for requests involving mobile app pentest, iOS security assessment, Android security testing, or OWASP MASTG assessment.
日本語の概要は準備中です。原文の説明を表示しています。
mukul975/Anthropic-Cybersecurity-Skills☆ 3.4万2026年8月31日 更新
Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces. Covers running security audits (`audit_cluster.sh`), enforcing Network Policies (default-deny and Dataplane V2 logging), isolating high-risk pods inside GKE Sandbox (`gVisor`), enforcing Pod Security Standards (`restricted` labeling) and pod securityContext, and mounting Secret Manager secrets via CSI (`SecretProviderClass`). Use when auditing workload security posture, isolating namespaces, applying pod security standards, or configuring network policies and secret volume mounts. Don't use for Workload Identity (use gke-workload-identity), cluster-wide control plane security, RBAC hardening, Binary Authorization, Shielded Nodes, or enabling platform-level GKE add-ons (use gke-platform-security instead).
日本語の概要は準備中です。原文の説明を表示しています。
google/skills☆ 2.1万2026年10月10日 更新
Establish a security baseline for a website or web app. Use this skill when configuring HTTPS and TLS, setting security headers, planning secrets management, evaluating CSP policies, doing a basic security audit, or hardening a site before launch. Triggers on security headers, HTTPS, TLS, CSP, content security policy, HSTS, secrets management, vulnerability scan, security audit, harden, OWASP, security baseline. Also triggers when a security review is required for compliance or before going live.
日本語の概要は準備中です。原文の説明を表示しています。
rampstackco/claude-skills☆ 9462026年10月7日 更新
Use when you need to design, review, or improve security in Spring Boot applications — including SecurityFilterChain, OAuth2/JWT resource server patterns, form login basics, method security (@PreAuthorize), CSRF and CORS for APIs, session fixation, security headers, exception handling, password encoding, and sensitive-data-safe logging. This should trigger for requests such as Add Spring Boot security support; Review Spring Boot security configuration; Improve API authorization in Spring Boot; Add JWT resource server security in Spring Boot; Harden Spring Boot security headers and CSRF settings. Part of Plinth Toolkit
日本語の概要は準備中です。原文の説明を表示しています。
jabrena/plinth☆ 4482026年10月8日 更新
Translate technical security work into the language of non-security audiences — board, executives, engineering, customer success, customers, legal, procurement, sales. Covers incident communication, post-mortem narrative, audit-findings-for-stakeholders, risk justification, security spend justification, and customer-facing breach disclosure. Use when the user mentions 'security comms,' 'communicate this finding,' 'explain to my boss,' 'board update,' 'executive summary,' 'incident communication,' 'breach notification,' 'customer disclosure,' 'security memo,' 'post-mortem narrative,' 'risk justification,' 'why this matters to the business,' 'translate this finding,' 'stakeholder update,' or has technical security work that needs to land with a non-security audience.
日本語の概要は準備中です。原文の説明を表示しています。
briiirussell/cybersecurity-skills☆ 4132026年5月27日 更新
Use when identifying cybersecurity-specific regulations and incident reporting obligations. Covers NIS2, DORA, SEC cyber disclosure rules, CISA incident reporting, state breach notification laws, cyber insurance requirements, and security certification frameworks. USE FOR: NIS2, DORA, SEC cybersecurity rules, CISA, breach notification, incident reporting, SOC 2, ISO 27001, cyber insurance, FedRAMP, StateRAMP, CMMC, data breach response DO NOT USE FOR: implementing security controls (use security skills), security testing tools (use security/security-testing), general data privacy (use privacy-data-protection)
日本語の概要は準備中です。原文の説明を表示しています。
FDU-INS/Insurance-Skills☆ 762026年7月12日 更新
Use whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed SOC, IAM, cloud security, and AppSec. Triggers on "find me a pen-testing firm for our SOC 2 audit", "shortlist three vCISO services for our healthcare-tech startup", "we need an incident response retainer", or "pull contact info for these 8 security firm domains", even when described indirectly (we got breached, prepare us for the compliance audit, get us SOC 2 ready). Drives the ServiceGraph API (api.servicegraph.co) — a 100k+ US firm catalog filterable by industry, services, location, size, ratings. Skip in-house security hires, "how do I patch CVE-X" or "configure firewall Y" DIY questions, security-product reviews (CrowdStrike vs SentinelOne, etc.), generic security knowledge questions, consumer/personal security advice, non-US firms, individual freelancers and bug-bounty hunters.
日本語の概要は準備中です。原文の説明を表示しています。
nostrband/ServiceGraph☆ 612026年6月2日 更新
Cryptographic security for agentic systems — zero-trust agent networking, signed message envelopes (JWS/JWE), capability-based security (ocaps), Merkle tree audit trails, WASM sandboxing, and formal verification. Covers CLI dev tool security, mTLS between agents, permission boundaries (least privilege for AI agents), and supply chain security for skills/plugins. Activate on: "agent security", "zero trust agents", "secure agent communication", "capability-based security", "ocap", "signed messages between agents", "agent audit trail", "sandbox agent execution", "agent permissions", "mTLS agents", "cryptographic verification", "agent supply chain", "OWASP agentic", "prove agent did X", "tamper-proof agent logs". NOT for: application-level SAST scanning (use security-auditor), network firewall rules (use infrastructure), SOC2/HIPAA compliance (organizational), or prompt injection defense (use prompt-engineer).
日本語の概要は準備中です。原文の説明を表示しています。
curiositech/windags-skills☆ 132026年10月1日 更新
Use when you need to design, review, or improve security in Spring Boot applications — including SecurityFilterChain, OAuth2/JWT resource server patterns, form login basics, method security (@PreAuthorize), CSRF and CORS for APIs, session fixation, security headers, exception handling, password encoding, and sensitive-data-safe logging. This should trigger for requests such as Add Spring Boot security support; Review Spring Boot security configuration; Improve API authorization in Spring Boot; Add JWT resource server security in Spring Boot; Harden Spring Boot security headers and CSRF settings. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。
aibot88/sec_skill_store☆ 42026年5月27日 更新
Presents a risk framework for every configurable security control in NemoClaw. Use when evaluating security posture, reviewing sandbox security defaults, or assessing control trade-offs. Trigger keywords - nemoclaw security best practices, sandbox security controls risk framework, nemoclaw credential storage, credentials.json, api key security, openclaw security controls, nemoclaw security boundary, prompt injection, tool access control.
日本語の概要は準備中です。原文の説明を表示しています。
composio-community/nemoclaw-composio☆ 22026年4月30日 更新
Cryptographic security for agentic systems — zero-trust agent networking, signed message envelopes (JWS/JWE), capability-based security (ocaps), Merkle tree audit trails, WASM sandboxing, and formal verification. Covers CLI dev tool security, mTLS between agents, permission boundaries (least privilege for AI agents), and supply chain security for skills/plugins. Activate on: "agent security", "zero trust agents", "secure agent communication", "capability-based security", "ocap", "signed messages between agents", "agent audit trail", "sandbox agent execution", "agent permissions", "mTLS agents", "cryptographic verification", "agent supply chain", "OWASP agentic", "prove agent did X", "tamper-proof agent logs". NOT for: application-level SAST scanning (use security-auditor), network firewall rules (use infrastructure), SOC2/HIPAA compliance (organizational), or prompt injection defense (use prompt-engineer).
日本語の概要は準備中です。原文の説明を表示しています。
curiositech/port-daddy☆ 22026年10月8日 更新
Team Mode security research skill. Orchestrates 3 vulnerability hunters and 2 PoC engineers to audit a codebase in parallel, prove exploitability, classify root causes, and calibrate severity by actual exploitability. Use for security review, vulnerability research, exploitability audit, pre-release security check, threat model validation, and `/security-research`. Triggers: 'security-research', 'security research', 'security review', 'vulnerability audit', 'exploitability audit', '보안 리뷰', '취약점 감사'.
日本語の概要は準備中です。原文の説明を表示しています。
code-yeongyu/oh-my-openagent☆ 7万2026年10月11日 更新
Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framework, combining Burp Suite interception with Postman collections and custom scripts to test endpoint security at every privilege level. Activates for requests involving API security testing, REST API pentest, GraphQL security assessment, or API vulnerability testing.
日本語の概要は準備中です。原文の説明を表示しています。
mukul975/Anthropic-Cybersecurity-Skills☆ 3.4万2026年8月31日 更新
Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation. Use this whenever the user mentions Security Agent, security findings, pentest or penetration test results, code review findings, vulnerabilities found in their AWS account, "what did the security scan find", remediating or triaging security risks, or wants to start fixing reported vulnerabilities — even if they don't name the service explicitly. Trigger it for phrases like "get my security findings", "what vulnerabilities do we have", "let's fix the pentest results", or "triage the security report". The skill discovers scans, exports findings to a gitignored local directory (so sensitive exploit detail is never committed), produces a prioritized triage summary, and offers to start fixing the highest-risk issues.
日本語の概要は準備中です。原文の説明を表示しています。
aws/agent-toolkit-for-aws☆ 2,8412026年10月10日 更新
Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.
日本語の概要は準備中です。原文の説明を表示しています。
benchflow-ai/skillsbench☆ 1,8372026年7月24日 更新
Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Use this skill whenever a user asks about TSA Security Directives for pipelines, freight railroads, passenger rail, public transit, or bus operators; the TSA Cyber Risk Management Program (CRMP); Cybersecurity Implementation Plan (CIP); Cybersecurity Operational Implementation Plan (COIP); Cybersecurity Assessment Plan (CAP); incident reporting to CISA; designation of a Cybersecurity Coordinator; Critical Cyber Systems (CCS); OT/IT network segmentation; the TSA November 2024 NPRM; or any directive in the SD Pipeline-2021 series, SD 1580-21-01 (freight rail), or SD 1582-21-01 (public transit/passenger rail). Also trigger for questions like "are we covered by TSA directives?", "what does the TSA require for pipeline cybersecurity?", "how do I build a CIP?", "what must I report to CISA?", or any request involving transportation critical infrastructure cybersecurity compliance.
日本語の概要は準備中です。原文の説明を表示しています。
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance☆ 9502026年10月10日 更新
Expert New Zealand Information Security Manual (NZISM) advisor for NZ government agencies and their supply chains. Use for NZISM control guidance, gap analysis, agency security obligations, classification framework (Unclassified through Top Secret), security risk management, system certification, and GCSB/NCSC NZ compliance. Triggers on: NZISM controls, NZ government security, GCSB compliance, agency cybersecurity obligations, NZ classification markings, Restricted/Confidential/Secret system scoping, agency security policies, third-party supplier security, Certification and Accreditation (C&A), and any question about NZ government information security requirements or the NZISM framework.
日本語の概要は準備中です。原文の説明を表示しています。
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance☆ 9502026年10月10日 更新
Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Use this skill whenever a user asks about TSA Security Directives for pipelines, freight railroads, passenger rail, public transit, or bus operators; the TSA Cyber Risk Management Program (CRMP); Cybersecurity Implementation Plan (CIP); Cybersecurity Operational Implementation Plan (COIP); Cybersecurity Assessment Plan (CAP); incident reporting to CISA; designation of a Cybersecurity Coordinator; Critical Cyber Systems (CCS); OT/IT network segmentation; the TSA November 2024 NPRM; or any directive in the SD Pipeline-2021 series, SD 1580-21-01 (freight rail), or SD 1582-21-01 (public transit/passenger rail). Also trigger for questions like "are we covered by TSA directives?", "what does the TSA require for pipeline cybersecurity?", "how do I build a CIP?", "what must I report to CISA?", or any request involving transportation critical infrastructure cybersecurity compliance.
日本語の概要は準備中です。原文の説明を表示しています。
lawve-ai/awesome-legal-skills☆ 8512026年10月3日 更新
Expert New Zealand Information Security Manual (NZISM) advisor for NZ government agencies and their supply chains. Use for NZISM control guidance, gap analysis, agency security obligations, classification framework (Unclassified through Top Secret), security risk management, system certification, and GCSB/NCSC NZ compliance. Triggers on: NZISM controls, NZ government security, GCSB compliance, agency cybersecurity obligations, NZ classification markings, Restricted/Confidential/Secret system scoping, agency security policies, third-party supplier security, Certification and Accreditation (C&A), and any question about NZ government information security requirements or the NZISM framework.
日本語の概要は準備中です。原文の説明を表示しています。
lawve-ai/awesome-legal-skills☆ 8512026年10月3日 更新
Audit application source code against the OWASP Top 10 (2021) vulnerability categories — broken access control, cryptographic failures, injection, insecure design, security misconfiguration, vulnerable components, authentication failures, data integrity, logging failures, SSRF. Use when the user mentions 'OWASP,' 'OWASP Top 10,' 'security audit,' 'security review,' 'secure code review,' 'code security review,' 'vulnerability audit,' 'find vulnerabilities,' 'appsec review,' 'application security audit,' 'check for security issues,' 'broken access control,' 'IDOR,' 'SQL injection,' 'XSS,' 'SSRF,' or wants to check their codebase for common security weaknesses.
日本語の概要は準備中です。原文の説明を表示しています。
briiirussell/cybersecurity-skills☆ 4132026年5月27日 更新