AI security
Assessing AI/ML systems for prompt injection, jailbreak vulnerabilities, model inversion risk, data poisoning exposure, or agent tool abuse.
Code, agents, infrastructure, and the tools to ship.
skills to explore
PUBLIC SKILLS, ONE SEARCHABLE SHELFIndexed 25 Sep 2026 ↗
1–16 of 16 skills
Assessing AI/ML systems for prompt injection, jailbreak vulnerabilities, model inversion risk, data poisoning exposure, or agent tool abuse.
Security leadership for growth-stage companies. Risk quantification in dollars, compliance roadmap (SOC 2/ISO 27001/HIPAA/GDPR), security architecture strategy, incident response leadership, and board-level security reporting.
/cs:ciso-review <plan> — Risk-paranoid interrogation of any plan that touches data, compliance, or production access.
Assessing cloud infrastructure for security misconfigurations, IAM privilege escalation paths, S3 public exposure, open security group rules, or IaC security gaps.
A security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection.
ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies.
Planning or executing authorized red team engagements, attack path analysis, or offensive security simulations.
Perform language and framework specific security best-practice reviews and suggest improvements.
PreToolUse security-anti-pattern hook for Claude Code. Catches 12 common security risks (command injection, XSS, SQL injection, unsafe deserialization, GitHub Actions workflow injection, eval/new Function code injection) BEFORE the Edit/Write/MultiEdit operation completes.
Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization.
Perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments.
Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model.
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices.
STRIDE threat modeling, DREAD risk scoring, data-flow-diagram threat analysis, or a quick secret scan — or when a security request needs routing to the right specialist skill (pen-testing, incident response, cloud posture, red team, AI security, threat hunting, secure code review).
Security audit and vulnerability scanner for AI agent skills before installation. Use when: (1) evaluating a skill from an untrusted source, (2) auditing a skill directory or git repo URL for malicious code, (3) pre-install security gate for Claude Code plugins, OpenClaw skills, or Codex skills, (4) scanning Python scripts for dangerous patterns like os.system, eval…
Hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry.
Source-linked, not execution-tested. Check the publisher’s setup instructions and permissions before use.