
lavendertalesun/r20-glebis-claude-skills-security
Security testing๐ Security & Compliance skill suite derived from glebis/claude-skills.
Overview
Source focus: cognitive toolkit, image gen, browser history, research skills Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response. This collection provides and , all with a consistent structured-output UI so you always know exactly where you are and what to do next. All commands display structured output with: - โ real-time step tracking - โ sorted by severity (๐ด๐ ๐ก๐ข) - โ quick wins โ medium-term โ strategic - โ at-a-glance metrics after each command Every command follows this 5-step structure: This suite is derived from which focuses on: cognitive toolkit, image gen, browser history, research skills. Improvements in this adaptation: - Domain-specific command vocabulary for Security & Compliance - Enhanced structured output with visual progress tracking - Prioritised action plans with time estimates - Workflow orchestration for end-to-end processes - Consistent UI conventions across all commands
README
๐ Security & Compliance Skills Suite
Derived from glebis/claude-skills
Adaptation of
glebis/claude-skillsfor Security & Compliance use cases. Source focus: cognitive toolkit, image gen, browser history, research skills
What This Skill Suite Does
Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response.
This collection provides 10 specialised commands and 5 multi-step workflows, all with a consistent structured-output UI so you always know exactly where you are and what to do next.
Quick Install
# Clone this skill
cp -r . ~/.claude/skills/r00-glebis-claude-skills--security/
# Register in Claude Code
# In a Claude Code session:
/read ~/.claude/skills/r00-glebis-claude-skills--security/SKILL.md
Commands
| Command | Description |
|---|---|
/owasp-scan |
OWASP Top-10 code scan with exploit description, CVSS score and remediation |
/dep-cve |
Dependency CVE report with exploitability score and upgrade path |
/gdpr-audit |
GDPR data-flow map, consent gaps and DPA checklist |
/soc2-readiness |
SOC 2 Type II readiness gap analysis across all 5 Trust Service Criteria |
/threat-model |
STRIDE threat model for architecture diagram with risk matrix |
/pentest-report |
Structured penetration test report: executive summary, findings and remediation |
/secret-detect |
Pre-commit secret detection hook config with entropy scanning |
/iam-audit |
IAM least-privilege audit: over-permissioned roles, stale access and MFA gaps |
/incident-playbook |
Security incident playbook: triage โ contain โ eradicate โ recover โ lessons |
/privacy-policy |
GDPR/CCPA-compliant privacy policy generator from data inventory |
Usage:
/owasp-scan
/dep-cve --scope full --output md
Workflows (Multi-step)
| Workflow | Description |
|---|---|
secure-sdlc |
Shift-left SDLC: threat model โ code scan โ DAST โ pen test โ sign-off |
breach-response |
Data breach response: detect โ assess โ notify โ remediate โ post-mortem |
compliance-audit |
Full compliance audit: scope โ gap analysis โ evidence โ remediation plan |
zero-trust-design |
Zero-trust architecture design: identity โ network โ workload โ data layers |
vendor-security |
Third-party vendor security assessment: questionnaire โ risk score โ decision |
Usage:
/workflows:secure-sdlc --scope full
UI Design
All commands display structured output with:
- Progress panels โ real-time step tracking
- Findings tables โ sorted by severity (๐ด๐ ๐ก๐ข)
- Action checklists โ quick wins โ medium-term โ strategic
- Summary cards โ at-a-glance metrics after each command
Progress Display Example
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Security Audit โ api.domain.com โ
โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฃ
โ OWASP scan โ 14 checks run โ
โ CVE scan โ 234 deps checked โ
โ IAM audit โณ Scanning roles โฆ โ
โ GDPR check โ Pending โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
FINDINGS (sort: severity desc)
โโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโฌโโโโโโโโโโโโโโโ
โ Sev โ Finding โ CVSS โ Status โ
โโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโผโโโโโโโโโโโโโโโค
โ ๐ด โ SQL injection /api/search โ 9.8 โ โ Open โ
โ ๐ด โ JWT none-alg accepted โ 9.1 โ โ Open โ
โ ๐ โ CORS wildcard on /api/* โ 6.5 โ โ In-Review โ
โ ๐ก โ Missing rate limiting โ 5.3 โ โ In-Review โ
โ ๐ข โ CSP header present โ โ โ โ Pass โ
โโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโดโโโโโโโโโโโโโโโ
Interaction Pattern
Every command follows this 5-step structure:
โ Scope Confirmation โ verify target and options with user
โก Live Analysis โ progress bar while working
โข Findings Table โ structured results sorted by impact
โฃ Action Plan โ prioritised, time-boxed recommendations
โค Next Steps โ suggested follow-up commands
Source Repository
This suite is derived from glebis/claude-skills which focuses on: cognitive toolkit, image gen, browser history, research skills.
Improvements in this adaptation:
- Domain-specific command vocabulary for Security & Compliance
- Enhanced structured output with visual progress tracking
- Prioritised action plans with time estimates
- Workflow orchestration for end-to-end processes
- Consistent UI conventions across all commands
License
MIT โ free to use, modify and distribute.
Recommended Tools
Try a different keyword or remove a filter.
Install
npx skillfish add lavendertalesun/r20-glebis-claude-skills-security