An AI-powered security scanner that reads your code like a human security researcher. It traces how data moves through your app and catches bugs that simple pattern-matching tools miss.
This skill checks for SQL injection, cross-site scripting, command injection, exposed API keys, hardcoded secrets, and weak cryptography. It works across JavaScript, Python, Java, PHP, Go, Ruby, and Rust.
You can scan a single file or your whole codebase. Every finding includes a severity rating and a suggested fix. You always review and approve before any changes are made.
Global
mkdir -p ~/.claude/skills/security-reviewProject
mkdir -p .claude/skills/security-reviewSource Repository
Azure Compliancemicrosoft/azure-skills
Audit Azure compliance and Key Vault expiration with azqr scans
Firebase Security Rules Auditorfirebase/agent-skills
Find weak spots in Firestore rules and get clear fixes
Golang Securitysamber/cc-skills-golang
Find and fix security flaws in Go code using expert guidance and automated tools
Clerk Nextjs Patternsclerk/skills
Secure your Next.js app with Clerk middleware, server actions, and caching
Persona It Admingoogleworkspace/cli
Keep your digital workspace safe with IT admin security workflows
Two Factor Authentication Best Practicesbetter-auth/skills
Secure user logins with two-factor authentication using Better Auth
Gws Modelarmor Create Templategoogleworkspace/cli
Create new templates for Google Model Armor to protect AI apps from harmful content
Gws Modelarmor Sanitize Promptgoogleworkspace/cli
Clean user prompts safely with Google Model Armor templates