Claude Skills

Code Vuln Audit

zebbern/claude-code-guide

Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection. Use when the user mentions security scans, vulnerability detection, secret leaks, API keys, OWASP, npm audit, pip-audit, hardcoded passwords, or code security checks.

★ 4,399 MIT Synced 2 weeks ago View SKILL.md

At a glance

Manual install Python Actively maintained MIT
Install git clone --depth 1 https://github.com/zebbern/claude-code-guide cp -r claude-code-guide/skills/code-vuln-audit ~/.claude/skills/code-vuln-audit
Can use Not declared by the author

Setup, runtime and requirements describe zebbern/claude-code-guide, the repo this skill ships in.

Also in zebbern/claude-code-guide

View the repo

Simulates academic peer review, evaluating papers across Originality, Methodology, Results, and Writing to provide Major/Minor Revision reco...

This skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodH...

This skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQ...

Generate multiple radically different interface designs for a module using parallel sub-agents. Use when user wants to design an API, explor...

Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. Use for security au...

Authentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and co...

This skill should be used when the user asks to "pentest AWS", "test AWS security", "enumerate IAM", "exploit cloud infrastructure", "AWS pr...

This skill should be used when the user asks to "test for broken authentication vulnerabilities", "assess session management security", "per...

This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web...

Caching strategies — invalidation, TTL guidelines, cache keys, cache layers, and when not to cache. Use when implementing or reviewing cachi...

Generate publication-quality PNG chart images from data, supporting line, bar, area, candlestick, pie, and heatmap charts. Triggers when the...

This skill should be used when the user asks to "perform cloud penetration testing", "assess Azure or AWS or GCP security", "enumerate cloud...