SkillsLib.ai

Security

Comprehensive security audits detecting vulnerabilities and verifying fixes

4.4(47 reviews)
500+ downloads
Updated Oct 2026
Verified SafeSecurity VerifiedThis skill was analyzed by our AI security scanner for harmful content including data exfiltration, system manipulation, credential theft, and prompt injection. No threats were detected.

What You Can Do

Run comprehensive security audits on sensitive code before deployment. Claude scans for OWASP Top 10 vulnerabilities including injection attacks, broken authentication, data exposure, and misconfigurations, then verifies that fixes are properly implemented. You get detailed reports with severity levels, exact locations, and remediation guidance.

Features

Injection attack detection

identifies SQL injection, command injection, XSS, and LDAP injection vulnerabilities

Authentication & authorization review

catches broken authentication, session issues, privilege escalation, and insecure access patterns

Data protection scanning

detects hardcoded secrets, missing encryption, insecure cryptography, and sensitive data exposure

Security misconfiguration checks

flags default credentials, verbose error messages, missing security headers, and configuration weaknesses

Dependency vulnerability scanning

identifies known vulnerable packages, outdated libraries, and supply chain risks

Severity classification

categorizes findings as CRITICAL, HIGH, MEDIUM, or LOW with exact file and line references

Fix verification workflow

confirms that identified vulnerabilities are properly remediated before deployment

Remediation guidance

provides actionable steps to fix each vulnerability, not just identification

Example Output

Input: Review authentication code for security vulnerabilities

Output:

code
SECURITY AUDIT REPORT

[CRITICAL] Hardcoded Database Credentials (auth.js:15)
- Issue: Database password stored in plaintext
- Remediation: Move to environment variables

[HIGH] Missing CSRF Protection (login.js:42)
- Issue: Form submission not validated with CSRF tokens
- Remediation: Implement token validation middleware

[MEDIUM] Weak Password Hashing (user.js:8)
- Issue: Using md5 instead of bcrypt
- Remediation: Replace with bcrypt with 12+ salt rounds

VERIFICATION REPORT
✓ Credentials moved to .env
✓ CSRF middleware implemented
✓ Password hashing upgraded to bcrypt

What's Included

  • security.md: Complete workflow instructions with agent sequence and execution details
  • OWASP Top 10 checklist: Comprehensive vulnerability categories and detection patterns
  • Vulnerability report template: Structured format with severity levels, locations, and remediation steps
  • Dependency scanning framework: Process for identifying known vulnerable packages
  • Fix verification checklist: Testing and validation steps to confirm remediation

Who It's For

  • Security engineers — conducting comprehensive security audits and vulnerability assessments
  • DevSecOps engineers — integrating security checks into CI/CD pipelines before deployment
  • Backend developers — reviewing authentication, authorization, and data protection code
  • Full-stack developers — auditing sensitive features handling user data or payments
  • Engineering leads — pre-deployment security reviews before production releases

Best For

  • Security code reviews of authentication and authorization systems
  • Vulnerability scanning in payment processing or financial code
  • Dependency audit and supply chain risk assessment
  • Pre-deployment security validation for sensitive features
  • OWASP compliance checking and remediation verification

You might also like

Site Monitoring Compliance & Deviation Auditor
$45
Site Monitoring Compliance & Deviation Auditor

This skill enables you to automatically audit your websites against compliance standards and detect deviations from expected baselines. You can track regulatory requirements, identify policy violations, and generate compliance reports with actionable remediation steps. Monitor multiple sites simultaneously and maintain detailed audit trails for compliance documentation.

Chemical Process Safety Analyzer
$40
Chemical Process Safety Analyzer

Analyze chemical processes systematically to identify hazards, assess risks, and generate safety recommendations. You can perform HAZOP analyses, evaluate compliance with industry standards, conduct root-cause analysis of incidents, and develop emergency response procedures. The skill guides you through structured safety reviews that reduce the likelihood of accidents and regulatory violations.

Injectable Formulation Development & Troubleshooting
$40
Injectable Formulation Development & Troubleshooting

You'll develop systematic approaches to injectable formulation design, from API selection through sterilization strategy. Claude helps you troubleshoot failed batches by analyzing root causes, recommends regulatory pathways (505(b)(2), ANDA, NDA), and provides science-backed solutions for stability, compatibility, and manufacturability challenges.

$50
Integration Architecture Assessor

This skill helps you systematically assess integration needs across your systems, design architecture patterns that scale with your organization, and identify technical and operational risks before implementation. You'll receive architecture recommendations aligned to your business constraints, clear integration roadmaps, and risk mitigation strategies that reduce deployment surprises. Get structured decision records suitable for architecture review boards and engineering teams.

Chemical Process Hazard Analysis and Control Design
$30
Chemical Process Hazard Analysis and Control Design

You can conduct comprehensive hazard analyses for chemical processes using industry-standard methodologies like HAZOP and LOPA. The skill helps you assess risks quantitatively, identify control gaps, design engineered safeguards, and generate formal documentation for regulatory compliance and process safety management.

Git Commit Message Writer
$45
CI/CD4.3(47)
Git Commit Message Writer

Claude analyzes your code diffs and generates standardized commit messages that follow the Conventional Commits specification. The skill automatically determines the correct commit type, scope, and description based on the changes you've made, ensuring your messages are parseable by automation tools while remaining human-readable for code reviewers.

Structured NLP Analysis and Annotation with Claude
$35
NLP3.3(6)
Structured NLP Analysis and Annotation with Claude

You can transform raw text into structured, labeled datasets for machine learning, analysis, and research. This skill performs named entity recognition, sentiment classification, part-of-speech tagging, and dependency parsing—generating consistent, validated annotations at scale. Use it to prepare corpora, extract entities, classify documents, or perform linguistic analysis without manual annotation.

IoT Firmware Analysis & Device Debugger
$40
IoT Firmware Analysis & Device Debugger

Rapidly analyze firmware logs and diagnose hardware issues that cause device failures, connectivity problems, and performance degradation. You'll identify root causes from stack traces, crash dumps, and sensor data, then generate specific optimization recommendations. This skill transforms raw device logs into actionable debugging plans that reduce time-to-resolution from hours to minutes.

$35.00