Analyze code changes (commits, PRs, files) for potential zero-day security vulnerabilities using LLM-powered analysis. This skill provides conversational access to the 0-Day Scanner Agent with real-time token monitoring and knowledge graph integration.
Multi-language AppSec review subagent. Use proactively when adding endpoints, modifying auth/RBAC, rendering dynamic content, handling outbound HTTP, updating dependencies, or completing a major feature. Reads the security-reviewer skill (.claude/skills/security-reviewer/SKILL.md) for its 8-point check and…
Runs after a tool call finishes for Edit, Write and MultiEdit tool calls, executing post-edit-quickscan.sh. From Security-Phoenix-demo/security-skills-claude-code.
Multi-language security review for web apps, APIs, and CLIs. Use whenever code is added or modified — new endpoints, auth/RBAC changes, template or DOM rendering, outbound HTTP, dependency updates, IaC/config changes, or end-of-feature reviews. Covers Python, JavaScript, TypeScript, Go, Rust, Java/Kotlin, Ruby…
Multi-language security review for web apps, APIs, and CLIs. Use whenever code is added or modified — new endpoints, auth/RBAC changes, template or DOM rendering, outbound HTTP, dependency updates, IaC/config changes, or end-of-feature reviews. Covers Python, JavaScript, TypeScript, Go, Rust, Java/Kotlin, Ruby…
Multi-language security review (8-point check) on recent changes. Routes to the bundled stronger reviewer when present, falls back to the lite reviewer otherwise.
Run comprehensive security assessment covering OWASP Top 10 2025 and ASVS Level 1 requirements. This skill provides automated, full-codebase security analysis with real-time token monitoring, knowledge graph integration, and automated test generation.
Search for threat intelligence, CVEs, malware analysis, breach reports, and security research across 300+ curated security domains (BleepingComputer, Hacker News, Krebs, Unit42, Talos, CISA, Mandiant, Rapid7, Securelist, etc.). Use this skill whenever the user asks to: research a CVE or vulnerability, find what…
Use this skill to query your Google NotebookLM notebooks directly from Claude Code for source-grounded, citation-backed answers from Gemini. Browser automation, library management, persistent auth. Drastically reduced hallucinations through document-only responses.
Use when the user wants to research vulnerabilities and create opengrep/semgrep SAST rules, conduct security research on CVEs or CWEs with web search, generate detection rules from vulnerability analysis, or build comprehensive security scanning coverage for a codebase.
Use when the user wants to create opengrep/semgrep SAST rules, detect vulnerabilities in code, generate security scanning rules from CVEs or vulnerability descriptions, or asks about writing pattern-matching or taint-analysis rules for static analysis.
Generate a full security-focused PRD (Product Requirements Document) from a plain-language feature description. Use this skill whenever someone wants to create a PRD, product spec, feature spec, requirements document, or says things like "write a PRD for", "create a spec for", "plan this feature", "document this…