Explore skills
4,475 skills found
Category alert
Get new Segurança skills every Monday
dependency-audit
Performs a dependency audit for projects, checking for security vulnerabilities, license compliance, outdated packages, and transitive risks. It is used to generate vulnerability, compliance, and update priority reports.
review
Rigorous code review of all uncommitted changes. Analyzes architecture, code quality, security, and engineering best practices. Embeds questions and assumptions inline, then summarizes all proposed changes as a plan for user approval before any edits are made.
eu-cra
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the EU. Use this skill for gap analysis, product classification (Default / Class I / Class II), conformity assessment route selection, CE marking, SBOM requirements, vulnerability and incident reporting to
iso27001
Expert ISO 27001 compliance assistant for security and compliance teams. Use this skill whenever a user asks about ISO 27001 or ISO/IEC 27001, including any of the following: gap analysis, auditing, compliance assessments, control checklists, policy writing, document generation, Statement of Applicability (SoA), risk assessment, risk registers, risk treatment plans, Annex A controls, ISMS implemen
soc2
Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Use this skill whenever a user mentions SOC 2, Trust Services Criteria, SOC 2 Type 1 or Type 2, audit readiness, compliance gaps, control documentation, evidence collection, vendor risk questionnaires, or anything related to AICPA service
security-audit
Java security checklist covering OWASP Top 10, input validation, injection prevention, and secure coding. Works with Spring, Quarkus, Jakarta EE, and plain Java. Use when reviewing code security, before releases, or when user asks about vulnerabilities.
CP-7(2)_accessibility
Identifies potential accessibility problems for alternate processing sites in the event of an area-wide disruption or disaster, and outlines explicit mitigations.
handoff-templates
Agent-to-agent communication templates, covering formats for standard handoff, QA verdict (PASS/FAIL), escalation, bug reports, security findings, and status updates.
pentest-methodology
Ethical security testing methodology - 5-phase pipeline, OWASP checklist, proof levels, structured findings
agent-benchmark
A framework for measuring and tracking agent response quality over time, detecting regressions before they reach production. Use it when evaluating agent changes, auditing quality, or establishing performance baselines.
concurrency-security
TOCTOU prevention, distributed locking, idempotency keys, race condition detection for Node.js and serverless environments.
config-security-scan
Scans the .claude/ directory for security misconfigurations, exposed secrets, and unsafe permissions.