jassics

60 mods across 2 repositories, 63 stars between them.

api-authz-test

25

jassics/awesome-claude-security

Skill Claude CodeCodex

Test an API's authorization — BOLA (object-level), BFLA (function-level), and BOPLA (property-level / mass assignment) — to confirm each request is authorized for the caller. Use to validate the top OWASP API risks on an authorized target.

6 25d ago A 60 tokens GPL-3.0

owasp-api-top10

26

jassics/awesome-claude-security

Skill Claude CodeCodex

Assess a REST or GraphQL API against the OWASP API Security Top 10 (2023), producing a per-category finding set with severity and remediation. Use when reviewing or pentesting an API. Authorized testing only.

6 25d ago A 50 tokens GPL-3.0

appsec-suite

27

jassics/awesome-claude-security

Plugin Claude Code

Application security suite: one-shot install of the appsec plugins (web, API, mobile, SAST/SCA).

6 25d ago A tokens not measured GPL-3.0

blue-team

28

jassics/awesome-claude-security

Plugin Claude Code

Blue-team role bundle: threat-informed defense across detection, response, hunting, and intel, plus purple-team validation. Auto-installs the defensive stack.

6 25d ago A tokens not measured GPL-3.0

blue-team-defender

29

jassics/awesome-claude-security

Agent

Coordinates defensive operations end to end — detection engineering, incident response, threat hunting, and threat intelligence — using threat-informed defense. Use to run or plan blue-team work spanning multiple defensive disciplines, not a single check.

6 25d ago A 48 tokens GPL-3.0

defend

30

jassics/awesome-claude-security

Command

Run a threat-informed defense cycle for a technique or threat — coverage check, hunt, detection, and purple-team validation.

6 25d ago A 24 tokens GPL-3.0

jassics/awesome-claude-security

Skill Claude CodeCodex

Plan and run a purple-team exercise: collaboratively emulate specific ATT&CK techniques and measure whether detection and response actually work, then close the gaps. Use to validate defensive coverage against real adversary behavior. Authorized environments only.

6 25d ago A 49 tokens GPL-3.0

blueops-suite

32

jassics/awesome-claude-security

Plugin Claude Code

Defensive operations suite: one-shot install of detection-engineering, dfir, and threat-intelligence.

6 25d ago A tokens not measured GPL-3.0

ciso-toolkit

33

jassics/awesome-claude-security

Plugin Claude Code

CISO executive toolkit: security strategy & roadmap, cyber-risk quantification, and board/executive decks. Auto-installs reporting, diagramming, and threat-modeling.

6 25d ago A tokens not measured GPL-3.0

ciso

34

jassics/awesome-claude-security

Agent

Acts as a security executive: sets strategy, quantifies and communicates cyber risk in business terms, prioritizes the program by risk and budget, and prepares board/ leadership communication. Use for security leadership, strategy, and executive communication — not hands-on technical work.

6 25d ago A 55 tokens GPL-3.0

board-deck

36

jassics/awesome-claude-security

Skill Claude CodeCodex

Produce a board / executive security presentation — risk posture and direction, top risks in business terms, program progress against strategy, the metrics that matter, and investment asks tied to risk. Use to prepare for a board or leadership meeting. Audience is non-technical decision-makers.

6 25d ago A 58 tokens GPL-3.0

jassics/awesome-claude-security

Skill Claude CodeCodex

Translate technical security risk into business and financial terms — top risk scenarios, likelihood × impact, a risk register, and (where useful) quantified loss ranges (FAIR-aware) — to support executive decisions on treat/transfer/accept. Use to communicate or prioritize cyber risk for leadership.

6 25d ago A 64 tokens GPL-3.0

security-strategy

38

jassics/awesome-claude-security

Skill Claude CodeCodex

Build or assess a security program strategy and roadmap — current-vs-target maturity, gaps, prioritized initiatives aligned to business objectives and risk appetite, with outcomes, metrics, and budget framing. Use for security program planning, a strategy refresh, or a maturity assessment.

6 25d ago A 56 tokens GPL-3.0

jassics/awesome-claude-security

Plugin Claude Code

Static security review of a Claude Code / AI-agent configuration (settings, permissions, hooks, MCP servers, agents, skills, CLAUDE.md) using the agentscanner CLI: scan, triage, and harden.

6 25d ago A tokens not measured GPL-3.0

agent-safety-lint

40

jassics/awesome-claude-security

Skill Claude CodeCodex

Check a Claude Code agent's runaway-risk controls — a missing or invalid maxTurns (unbounded turns/cost), an unattended (bypass/acceptEdits) or backgrounded agent with no turn bound, a hook or stdio MCP server with no timeout, and prose that tells the model to disregard turn limits or resist interruption — in YOUR OWN…

6 25d ago A 174 tokens GPL-3.0

jassics/awesome-claude-security

Skill Claude CodeCodex

Statically review a Claude Code / AI-agent setup for security misconfigurations — risky hooks, over-broad permissions, untrusted or cleartext MCP servers, hardcoded secrets, endpoint redirection, over-privileged agents/skills, and prompt-injection in steering files. Use when asked to audit a .claude/ directory…

6 25d ago A 114 tokens GPL-3.0

cloud-security

42

jassics/awesome-claude-security

Plugin Claude Code

Cloud security (AWS/Azure/GCP): posture review, IAM least-privilege review, and misconfiguration scanning.

6 25d ago A tokens not measured GPL-3.0

cloud-iam-review

43

jassics/awesome-claude-security

Skill Claude CodeCodex

Audit cloud IAM (AWS/Azure/GCP) for least privilege: over-permissioned identities, wildcard/admin grants, public or cross-account access, unused credentials, and privilege-escalation paths. Use to review identity risk — the top cause of cloud compromise.

6 25d ago A 58 tokens GPL-3.0

jassics/awesome-claude-security

Skill Claude CodeCodex

Scan a cloud environment (AWS/Azure/GCP) for high-impact misconfigurations and exposures — public storage, open ingress, unencrypted data, exposed secrets/ metadata, missing logging — and prioritize quick wins. Use for a fast exposure sweep on an authorized environment.

6 25d ago A 61 tokens GPL-3.0

jassics/awesome-claude-security

Skill Claude CodeCodex

Review a cloud environment's security posture (AWS/Azure/GCP) across IAM, network, data protection, logging/monitoring, and workload configuration, mapped to CIS benchmarks, and produce ranked findings. Use for a CSPM-style assessment of an account/subscription/project you're authorized to review.

6 25d ago A 64 tokens GPL-3.0

cloud-suite

46

jassics/awesome-claude-security

Plugin Claude Code

Cloud & infrastructure suite: one-shot install of cloud-security, k8s-security, and infrastructure-security.

6 25d ago A tokens not measured GPL-3.0

cto-security

47

jassics/awesome-claude-security

Plugin Claude Code

CTO security advisor: secure-by-design at scale (paved roads, guardrails, enablement) and technology-risk assessment for strategic decisions. Auto-installs threat-modeling, diagramming, reporting.

6 25d ago A tokens not measured GPL-3.0

jassics/awesome-claude-security

Agent

Advises technology leadership on security at strategic scale — secure-by-design programs (paved roads, guardrails, enablement) and technology-risk decisions (new tech, build/buy, vendor, M&A) — balancing security with engineering velocity. Use for tech-strategy security, not hands-on implementation.

6 25d ago A 67 tokens GPL-3.0