원클릭으로
security-skills-claude-code
security-skills-claude-code에는 Security-Phoenix-demo에서 수집한 skills 6개가 있으며, 저장소 수준 직업 범위와 사이트 내 skill 상세 페이지를 제공합니다.
이 저장소의 skills
Multi-language security review for web apps, APIs, and CLIs. Use whenever code is added or modified — new endpoints, auth/RBAC changes, template or DOM rendering, outbound HTTP, dependency updates, IaC/config changes, or end-of-feature reviews. Covers Python, JavaScript, TypeScript, Go, Rust, Java/Kotlin, Ruby, C#/.NET, plus shared OWASP Top 10 and ASVS L1 logic. Triggers on phrases like "security review", "review this for security", "audit this code", "is this safe", "AppSec check", "threat-model this change", "supply chain risk", "before I merge", or whenever a senior engineer would pause to ask "what could go wrong here". Pairs with the `security-reviewer` subagent and the session-start / pre-bash / post-edit hooks shipped alongside it.
Multi-language security review for web apps, APIs, and CLIs. Use whenever code is added or modified — new endpoints, auth/RBAC changes, template or DOM rendering, outbound HTTP, dependency updates, IaC/config changes, or end-of-feature reviews. Covers Python, JavaScript, TypeScript, Go, Rust, Java/Kotlin, Ruby, C#/.NET, plus shared OWASP Top 10 and ASVS L1 logic. Triggers on phrases like "security review", "review this for security", "audit this code", "is this safe", "AppSec check", "threat-model this change", "supply chain risk", "before I merge", or whenever a senior engineer would pause to ask "what could go wrong here". Pairs with the `security-reviewer` subagent and the session-start / pre-bash / post-edit hooks shipped alongside it.
Search for threat intelligence, CVEs, malware analysis, breach reports, and security research across 300+ curated security domains (BleepingComputer, Hacker News, Krebs, Unit42, Talos, CISA, Mandiant, Rapid7, Securelist, etc.). Use this skill whenever the user asks to: research a CVE or vulnerability, find what security vendors are saying about a threat actor or malware family, search security blogs, look up threat intelligence on a topic, find recent breach or ransomware reports, collect CTI for a MITRE technique, or push research into NotebookLM. Triggers for phrases like "search security sources", "find threat intel on X", "what are vendors saying about Y", "research CVE-XXXX", "look up malware Z", "collect CTI", "push to NotebookLM", or any domain-scoped web research request in a security context.
Use when the user wants to research vulnerabilities and create opengrep/semgrep SAST rules, conduct security research on CVEs or CWEs with web search, generate detection rules from vulnerability analysis, or build comprehensive security scanning coverage for a codebase.
Use when the user wants to create opengrep/semgrep SAST rules, detect vulnerabilities in code, generate security scanning rules from CVEs or vulnerability descriptions, or asks about writing pattern-matching or taint-analysis rules for static analysis.
Generate a full security-focused PRD (Product Requirements Document) from a plain-language feature description. Use this skill whenever someone wants to create a PRD, product spec, feature spec, requirements document, or says things like "write a PRD for", "create a spec for", "plan this feature", "document this feature", or "I need a requirements doc". The skill produces: (1) a structured PRD in a security-focused template format, (2) a Confluence page pushed to your configured space via Atlassian MCP (called directly), (3) a cursor-compatible .md plan file for .cursor/plans/, (4) a downloadable formatted markdown, (5) optionally: Linear/Asana tasks from the batch plan, Slack notification to stakeholders, Notion page mirror. Always use this skill for PRD and feature planning tasks.