LR

lavendertalesun/r20-glebis-claude-skills-security

Security testing
40ย stars ๅ“่ณช 40 ใƒˆใƒฌใƒณใƒ‰ 40

๐Ÿ”’ Security & Compliance skill suite derived from glebis/claude-skills.

ๆฆ‚่ฆ

Source focus: cognitive toolkit, image gen, browser history, research skills Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response. This collection provides and , all with a consistent structured-output UI so you always know exactly where you are and what to do next. All commands display structured output with: - โ€” real-time step tracking - โ€” sorted by severity (๐Ÿ”ด๐ŸŸ ๐ŸŸก๐ŸŸข) - โ€” quick wins โ†’ medium-term โ†’ strategic - โ€” at-a-glance metrics after each command Every command follows this 5-step structure: This suite is derived from which focuses on: cognitive toolkit, image gen, browser history, research skills. Improvements in this adaptation: - Domain-specific command vocabulary for Security & Compliance - Enhanced structured output with visual progress tracking - Prioritised action plans with time estimates - Workflow orchestration for end-to-end processes - Consistent UI conventions across all commands

README

๐Ÿ”’ Security & Compliance Skills Suite

Derived from glebis/claude-skills

Adaptation of glebis/claude-skills for Security & Compliance use cases. Source focus: cognitive toolkit, image gen, browser history, research skills


What This Skill Suite Does

Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response.

This collection provides 10 specialised commands and 5 multi-step workflows, all with a consistent structured-output UI so you always know exactly where you are and what to do next.


Quick Install

# Clone this skill
cp -r . ~/.claude/skills/r00-glebis-claude-skills--security/

# Register in Claude Code
# In a Claude Code session:
/read ~/.claude/skills/r00-glebis-claude-skills--security/SKILL.md

Commands

Command Description
/owasp-scan OWASP Top-10 code scan with exploit description, CVSS score and remediation
/dep-cve Dependency CVE report with exploitability score and upgrade path
/gdpr-audit GDPR data-flow map, consent gaps and DPA checklist
/soc2-readiness SOC 2 Type II readiness gap analysis across all 5 Trust Service Criteria
/threat-model STRIDE threat model for architecture diagram with risk matrix
/pentest-report Structured penetration test report: executive summary, findings and remediation
/secret-detect Pre-commit secret detection hook config with entropy scanning
/iam-audit IAM least-privilege audit: over-permissioned roles, stale access and MFA gaps
/incident-playbook Security incident playbook: triage โ†’ contain โ†’ eradicate โ†’ recover โ†’ lessons
/privacy-policy GDPR/CCPA-compliant privacy policy generator from data inventory

Usage:

/owasp-scan 
/dep-cve --scope full --output md

Workflows (Multi-step)

Workflow Description
secure-sdlc Shift-left SDLC: threat model โ†’ code scan โ†’ DAST โ†’ pen test โ†’ sign-off
breach-response Data breach response: detect โ†’ assess โ†’ notify โ†’ remediate โ†’ post-mortem
compliance-audit Full compliance audit: scope โ†’ gap analysis โ†’ evidence โ†’ remediation plan
zero-trust-design Zero-trust architecture design: identity โ†’ network โ†’ workload โ†’ data layers
vendor-security Third-party vendor security assessment: questionnaire โ†’ risk score โ†’ decision

Usage:

/workflows:secure-sdlc  --scope full

UI Design

All commands display structured output with:

  • Progress panels โ€” real-time step tracking
  • Findings tables โ€” sorted by severity (๐Ÿ”ด๐ŸŸ ๐ŸŸก๐ŸŸข)
  • Action checklists โ€” quick wins โ†’ medium-term โ†’ strategic
  • Summary cards โ€” at-a-glance metrics after each command

Progress Display Example

โ•”โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•—
โ•‘  Security Audit  โ€”  api.domain.com               โ•‘
โ• โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•ฃ
โ•‘  OWASP scan      โœ“   14 checks run                โ•‘
โ•‘  CVE scan        โœ“   234 deps checked             โ•‘
โ•‘  IAM audit       โŸณ   Scanning roles โ€ฆ             โ•‘
โ•‘  GDPR check      โ–‘   Pending                      โ•‘
โ•šโ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•โ•

FINDINGS  (sort: severity desc)
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Sev  โ”‚ Finding                      โ”‚ CVSS     โ”‚ Status       โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚  ๐Ÿ”ด  โ”‚ SQL injection /api/search    โ”‚  9.8     โ”‚ โœ— Open       โ”‚
โ”‚  ๐Ÿ”ด  โ”‚ JWT none-alg accepted        โ”‚  9.1     โ”‚ โœ— Open       โ”‚
โ”‚  ๐ŸŸ   โ”‚ CORS wildcard on /api/*      โ”‚  6.5     โ”‚ โš  In-Review  โ”‚
โ”‚  ๐ŸŸก  โ”‚ Missing rate limiting        โ”‚  5.3     โ”‚ โš  In-Review  โ”‚
โ”‚  ๐ŸŸข  โ”‚ CSP header present           โ”‚   โ€”      โ”‚ โœ“ Pass       โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Interaction Pattern

Every command follows this 5-step structure:

โ‘  Scope Confirmation  โ€” verify target and options with user
โ‘ก Live Analysis       โ€” progress bar while working
โ‘ข Findings Table      โ€” structured results sorted by impact
โ‘ฃ Action Plan         โ€” prioritised, time-boxed recommendations
โ‘ค Next Steps          โ€” suggested follow-up commands

Source Repository

This suite is derived from glebis/claude-skills which focuses on: cognitive toolkit, image gen, browser history, research skills.

Improvements in this adaptation:

  • Domain-specific command vocabulary for Security & Compliance
  • Enhanced structured output with visual progress tracking
  • Prioritised action plans with time estimates
  • Workflow orchestration for end-to-end processes
  • Consistent UI conventions across all commands

License

MIT โ€” free to use, modify and distribute.

View this README on GitHub

ๆŽจๅฅจใƒ„ใƒผใƒซ

ๅˆฅใฎใ‚ญใƒผใƒฏใƒผใƒ‰ใ‚’่ฉฆใ™ใ‹ใ€ใƒ•ใ‚ฃใƒซใ‚ฟใ‚’ๅค–ใ—ใฆใใ ใ•ใ„ใ€‚

ใ‚คใƒณใ‚นใƒˆใƒผใƒซ

npx skillfish add lavendertalesun/r20-glebis-claude-skills-security