{"repo":"NovaCode37/claude-security-skills","free":true,"listed":false,"github":"https://github.com/NovaCode37/claude-security-skills","clone":"git clone https://github.com/NovaCode37/claude-security-skills.git","description":"Production-ready Claude Code skills for cybersecurity — secret scanning, SAST, prompt-injection testing, HTTP/JWT/dependency auditing. Zero dependencies.","language":"Python","stars":11,"topics":["ai-security","anthropic","appsec","claude","claude-code","claude-skills","cybersecurity","devsecops","jailbreak","jwt"],"license":"MIT","category":"security-tools","readme_excerpt":"Claude Security Skills Security skills for Claude Code. Install them once and ask Claude, in plain language, to scan a repo for leaked secrets, review Python code, red-team an LLM for prompt injection, or audit HTTP headers, JWTs, Dockerfiles, CORS, and dependencies. Claude picks the right skill, runs it, and explains what it found. Everything here runs on the Python standard library — no packages to install, nothing phoning home. The analysis runs offline; only the few skills that need to hit a URL use the network, and only when you ask them to. Other languages: Español · Русский The skills Skill What it does Engine ------- -------------- -------- secret-scanner Finds hardcoded API keys, tokens and private keys using vendor patterns plus Shannon-entropy analysis, tuned for few false positives Custom entropy engine sast-lite AST-based static analysis for Python: command injection, eval/exec, insecure deserialization, SQLi, weak crypto, disabled TLS — each tagged with a CWE Python ast walker prompt-injection-tester Red-teams your own LLM app with a categorized payload library and canary detection, then scores resilience 0–100 Canary harness http-sec-audit Checks HTTP security headers and cookie flags (CSP, HSTS, SameSite, …) and gives concrete fixes urllib + pure core jwt-inspector Decodes and audits JWTs (alg=none, weak expiry, claim hygiene) and cracks weak HMAC secrets offline HMAC + checks dependency-check Flags known-vulnerable and unpinned deps in requirements.txt , pack","default_branch":null,"files":null,"tree":[],"storefront":"/r/NovaCode37","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/NovaCode37/claude-security-skills/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}