发现security & testing类别的 Claude 技能。浏览 105 个技能,找到适合您 AI 工作流程的完美功能。
Automates comprehensive security audits, vulnerability scanning, and secret detection for complex multi-service architectures.
Identifies authorization vulnerabilities and privilege escalation paths within your source code using the STRIDE threat modeling framework.
Systematically identifies, groups, and resolves failing tests to restore codebase stability and achieve a green test suite.
Implements secure handling, storage, and rotation of sensitive credentials across major CI/CD platforms and cloud providers.
Implements secure smart contract development patterns and identifies critical vulnerabilities in Solidity code to ensure robust blockchain applications.
Configures and automates Static Application Security Testing (SAST) tools for comprehensive vulnerability detection in application code.
Implements comprehensive Python testing strategies using pytest, fixtures, mocking, and test-driven development best practices.
Implements comprehensive smart contract testing suites using Hardhat and Foundry to ensure blockchain security and gas efficiency.
Systematically traces bugs through call stacks to identify and fix the original source of errors rather than just their symptoms.
Performs multi-dimensional codebase reviews using specialized AI agents to identify security, performance, and architectural issues.
Manages persistent security preferences, tool thresholds, and scan exclusions for integrated application security workflows.
Analyzes serverless applications for security vulnerabilities including overprivileged IAM policies, event injection, and insecure configuration.
Identifies security weaknesses and maps vulnerabilities to CWE identifiers using the PASTA threat modeling methodology.
Enforces a strict Red-Green-Refactor workflow to ensure all production code is verified by failing tests first.
Analyzes source code to identify and mitigate linkability threats where user data can be correlated across services, sessions, or contexts.
Analyzes source code for detectability threats and timing side channels to prevent unauthorized inference of system interactions.
Master the Bash Automated Testing System (Bats) to create robust, production-grade unit tests for shell scripts and CI/CD pipelines.
Performs comprehensive security audits, network reconnaissance, and vulnerability management directly from the command line using Shodan, OSV, and KEV integrations.
Automates end-to-end testing and UI debugging for local web applications using Playwright and managed server lifecycles.
Maps and inventories every application entry point to identify potential security exposure and undocumented interfaces.
Teaches application security through interactive, guided walkthroughs using your own codebase as the primary teaching material.
Implements production-grade Kubernetes security policies including NetworkPolicy, RBAC, and Pod Security Standards to ensure cluster-wide defense-in-depth.
Conducts exhaustive, multi-framework security audits and generates comprehensive, compliance-ready reports.
Enforces a rigorous four-phase framework to identify root causes and eliminate guess-and-check thrashing during the software debugging process.
Analyzes source code to identify and remediate identity spoofing vulnerabilities and authentication weaknesses based on the STRIDE threat model.
Implement robust testing strategies for JavaScript and TypeScript applications using modern frameworks like Jest and Vitest.
Analyzes WebSocket implementations for security vulnerabilities like CSWSH, missing authentication, and inadequate message validation.
Analyzes application architecture to identify components, trust boundaries, and data sensitivity for formal threat modeling.
Audits application and infrastructure configurations to identify and remediate security vulnerabilities based on OWASP standards.
Visualizes the current security posture of a project by aggregating scan results and tracking code changes since the last audit.
Scroll for more results...