--- name: awesome-security description: Application security, penetration testing, ethical hacking, OWASP, authentication patterns, OAuth2, JWT, encryption, TLS, compliance, GDPR, HIPAA, SOC2, PCI-DSS, secrets management, web application security, supply chain security, vulnerability assessment, code audit, binary analysis, malware analysis, threat modeling, API security, network security, cloud security, incident response, forensics. Use when securing applications, performing security audits, implementing authentication, or assessing vulnerabilities. --- # Security Skills Router Routes to 126 specialized security skills from antigravity-awesome-skills. ## Instructions When this skill is invoked: 1. Match the user's request against the skill index below 2. Read the full SKILL.md file using the Read tool from the path shown 3. If multiple skills match, pick the most specific one 4. Apply the loaded skill's guidance to help the user 5. If no clear match exists, list the top 3-5 candidates and ask **Skill files location** (check in order): - `/home/n8n/plugins/antigravity-awesome-skills/skills/{id}/SKILL.md` - `~/.claude/antigravity-awesome-skills/skills/{id}/SKILL.md` - `~/antigravity-awesome-skills/skills/{id}/SKILL.md` ## Skill Index | ID | Description | |----|-------------| | `accessibility-compliance-accessibility-audit` | You are an accessibility expert specializing in WCAG compliance, inclusive de... | | `active-directory-attacks` | This skill should be used when the user asks to "attack Active Directory", "e... | | `agent-memory-systems` | Memory is the cornerstone of intelligent agents | | `ai-product` | Every product will be AI-powered | | `antigravity-workflows` | Orchestrate multiple Antigravity skills through guided workflows for SaaS MVP... | | `api-fuzzing-bug-bounty` | This skill should be used when the user asks to "test API security", "fuzz AP... | | `api-security-best-practices` | Implement secure API design patterns including authentication, authorization,... | | `attack-tree-construction` | Build comprehensive attack trees to visualize threat paths | | `auth-implementation-patterns` | Master authentication and authorization patterns including JWT, OAuth2, sessi... | | `aws-penetration-testing` | This skill should be used when the user asks to "pentest AWS", "test AWS secu... | | `azure-cosmos-db-py` | Build Azure Cosmos DB NoSQL services with Python/FastAPI following production... | | `azure-identity-dotnet` | Azure Identity SDK for .NET | | `azure-keyvault-py` | Azure Key Vault SDK for Python | | `azure-keyvault-secrets-rust` | Azure Key Vault Secrets SDK for Rust | | `azure-keyvault-secrets-ts` | Manage secrets using Azure Key Vault Secrets SDK for JavaScript (@azure/keyva... | | `azure-security-keyvault-keys-dotnet` | Azure Key Vault Keys SDK for .NET | | `azure-security-keyvault-keys-java` | Azure Key Vault Keys Java SDK for cryptographic key management | | `azure-security-keyvault-secrets-java` | Azure Key Vault Secrets Java SDK for secret management | | `backend-security-coder` | Expert in secure backend coding practices specializing in input validation, a... | | `broken-authentication` | This skill should be used when the user asks to "test for broken authenticati... | | `burp-suite-testing` | This skill should be used when the user asks to "intercept HTTP traffic", "mo... | | `cc-skill-security-review` | Use this skill when adding authentication, handling user input, working with ... | | `cicd-automation-workflow-automate` | You are a workflow automation expert specializing in creating efficient CI/CD... | | `clerk-auth` | Expert patterns for Clerk auth implementation, middleware, organizations, web... | | `cloud-architect` | Expert cloud architect specializing in AWS/Azure/GCP multi-cloud infrastructu... | | `cloud-penetration-testing` | This skill should be used when the user asks to "perform cloud penetration te... | | `code-review-checklist` | Comprehensive checklist for conducting thorough code reviews covering functio... | | `code-reviewer` | Elite code review expert specializing in modern AI-powered code analysis, sec... | | `codebase-cleanup-deps-audit` | You are a dependency security expert specializing in vulnerability scanning, ... | | `computer-use-agents` | Build AI agents that interact with computers like humans do - viewing screens... | | `database-admin` | Expert database administrator specializing in modern cloud databases, automat... | | `database-migration` | Execute database migrations across ORMs and platforms with zero-downtime stra... | | `database-migrations-sql-migrations` | SQL database migrations with zero-downtime strategies for PostgreSQL, MySQL, ... | | `dependency-management-deps-audit` | You are a dependency security expert specializing in vulnerability scanning, ... | | `deployment-engineer` | Expert deployment engineer specializing in modern CI/CD pipelines, GitOps wor... | | `deployment-pipeline-design` | Design multi-stage CI/CD pipelines with approval gates, security checks, and ... | | `design-orchestration` | Orchestrates design workflows by routing work through brainstorming, multi-ag... | | `devops-troubleshooter` | Expert DevOps troubleshooter specializing in rapid incident response, advance... | | `docker-expert` | Docker containerization expert with deep knowledge of multi-stage builds, ima... | | `dotnet-backend` | Build ASP.NET Core 8+ backend services with EF Core, auth, background jobs, a... | | `ethical-hacking-methodology` | This skill should be used when the user asks to "learn ethical hacking", "und... | | `file-path-traversal` | This skill should be used when the user asks to "test for directory traversal... | | `find-bugs` | Find bugs, security vulnerabilities, and code quality issues in local branch ... | | `firebase` | Firebase gives you a complete backend in minutes - auth, database, storage, f... | | `firmware-analyst` | Expert firmware analyst specializing in embedded systems, IoT security, and h... | | `form-cro` | Optimize any form that is NOT signup or account registration — including lead... | | `framework-migration-deps-upgrade` | You are a dependency management expert specializing in safe, incremental upgr... | | `frontend-mobile-security-xss-scan` | You are a frontend security specialist focusing on Cross-Site Scripting (XSS)... | | `frontend-security-coder` | Expert in secure frontend coding practices specializing in XSS prevention, ou... | | `gdpr-data-handling` | Implement GDPR-compliant data handling with consent management, data subject ... | | `graphql-architect` | Master modern GraphQL with federation, performance optimization, and enterpri... | | `html-injection-testing` | This skill should be used when the user asks to "test for HTML injection", "i... | | `hugging-face-jobs` | This skill should be used when users want to run any workload on Hugging Face... | | `hybrid-cloud-architect` | Expert hybrid cloud architect specializing in complex multi-cloud solutions a... | | `idor-testing` | This skill should be used when the user asks to "test for insecure direct obj... | | `incident-responder` | Expert SRE incident responder specializing in rapid problem resolution, moder... | | `incident-response-incident-response` | Use when working with incident response incident response | | `incident-response-smart-fix` | [Extended thinking: This workflow implements a sophisticated debugging and re... | | `incident-runbook-templates` | Create structured incident response runbooks with step-by-step procedures, es... | | `internal-comms-anthropic` | A set of resources to help me write all kinds of internal communications, usi... | | `internal-comms-community` | A set of resources to help me write all kinds of internal communications, usi... | | `k8s-manifest-generator` | Create production-ready Kubernetes manifests for Deployments, Services, Confi... | | `k8s-security-policies` | Implement Kubernetes security policies including NetworkPolicy, PodSecurityPo... | | `kubernetes-architect` | Expert Kubernetes architect specializing in cloud-native infrastructure, adva... | | `legal-advisor` | Draft privacy policies, terms of service, disclaimers, and legal notices | | `linkerd-patterns` | Implement Linkerd service mesh patterns for lightweight, security-focused ser... | | `loki-mode` | Multi-agent autonomous startup system for Claude Code | | `m365-agents-dotnet` | Microsoft 365 Agents SDK for .NET | | `m365-agents-py` | Microsoft 365 Agents SDK for Python | | `malware-analyst` | Expert malware analyst specializing in defensive malware research, threat int... | | `memory-forensics` | Master memory forensics techniques including memory acquisition, process anal... | | `metasploit-framework` | This skill should be used when the user asks to "use Metasploit for penetrati... | | `mobile-security-coder` | Expert in secure mobile coding practices specializing in input validation, We... | | `mtls-configuration` | Configure mutual TLS (mTLS) for zero-trust service-to-service communication | | `multi-agent-brainstorming` | Use this skill when a design or idea requires higher confidence, risk reducti... | | `network-engineer` | Expert network engineer specializing in modern cloud networking, security arc... | | `nextjs-supabase-auth` | Expert integration of Supabase Auth with Next.js App Router | | `nodejs-best-practices` | Node.js development principles and decision-making | | `notebooklm` | Use this skill to query your Google NotebookLM notebooks directly from Claude... | | `observability-engineer` | Build production-ready monitoring, logging, and tracing systems | | `openapi-spec-generation` | Generate and maintain OpenAPI 3.1 specifications from code, design-first spec... | | `payment-integration` | Integrate Stripe, PayPal, and payment processors | | `pci-compliance` | Implement PCI DSS compliance requirements for secure handling of payment card... | | `pentest-checklist` | This skill should be used when the user asks to "plan a penetration test", "c... | | `plaid-fintech` | Expert patterns for Plaid API integration including Link token flows, transac... | | `popup-cro` | Create and optimize popups, modals, overlays, slide-ins, and banners to incre... | | `postmortem-writing` | Write effective blameless postmortems with root cause analysis, timelines, an... | | `quant-analyst` | Build financial models, backtest trading strategies, and analyze market data | | `red-team-tactics` | Red team tactics principles based on MITRE ATT&CK | | `red-team-tools` | This skill should be used when the user asks to "follow red team methodology"... | | `research-engineer` | An uncompromising Academic Research Engineer | | `reverse-engineer` | Expert reverse engineer specializing in binary analysis, disassembly, decompi... | | `risk-manager` | Monitor portfolio risk, R-multiples, and position limits | | `risk-metrics-calculation` | Calculate portfolio risk metrics including VaR, CVaR, Sharpe, Sortino, and dr... | | `sast-configuration` | Configure Static Application Security Testing (SAST) tools for automated vuln... | | `scanning-tools` | This skill should be used when the user asks to "perform vulnerability scanni... | | `secrets-management` | Implement secure secrets management for CI/CD pipelines using Vault, AWS Secr... | | `security-auditor` | Expert security auditor specializing in DevSecOps, comprehensive cybersecurit... | | `security-bluebook-builder` | Build security Blue Books for sensitive apps | | `security-compliance-compliance-check` | You are a compliance expert specializing in regulatory requirements for softw... | | `security-requirement-extraction` | Derive security requirements from threat models and business context | | `security-scanning-security-dependencies` | You are a security expert specializing in dependency vulnerability analysis, ... | | `security-scanning-security-hardening` | Coordinate multi-layer security scanning and hardening across application, in... | | `security-scanning-security-sast` | Static Application Security Testing (SAST) for code vulnerability analysis ac... | | `seo-authority-builder` | Analyzes content for E-E-A-T signals and suggests improvements to build autho... | | `service-mesh-expert` | Expert service mesh architect specializing in Istio, Linkerd, and cloud-nativ... | | `smtp-penetration-testing` | This skill should be used when the user asks to "perform SMTP penetration tes... | | `solidity-security` | Master smart contract security best practices to prevent common vulnerabiliti... | | `sql-injection-testing` | This skill should be used when the user asks to "test for SQL injection vulne... | | `ssh-penetration-testing` | This skill should be used when the user asks to "pentest SSH services", "enum... | | `stride-analysis-patterns` | Apply STRIDE methodology to systematically identify threats | | `stripe-integration` | Implement Stripe payment processing for robust, PCI-compliant payment flows i... | | `terraform-specialist` | Expert Terraform/OpenTofu specialist mastering advanced IaC automation, state... | | `threat-mitigation-mapping` | Map identified threats to appropriate security controls and mitigations | | `threat-modeling-expert` | Expert in threat modeling methodologies, security architecture review, and ri... | | `top-web-vulnerabilities` | This skill should be used when the user asks to "identify web application vul... | | `twilio-communications` | Build communication features with Twilio: SMS messaging, voice calls, WhatsAp... | | `ui-visual-validator` | Rigorous visual validation expert specializing in UI testing, design system c... | | `using-neon` | Guides and best practices for working with Neon Serverless Postgres | | `varlock-claude-skill` | Secure environment variable management ensuring secrets are never exposed in ... | | `vulnerability-scanner` | Advanced vulnerability analysis principles | | `web-design-guidelines` | Review UI code for Web Interface Guidelines compliance | | `wiki-onboarding` | Generates two complementary onboarding guides — a Principal-Level architectur... | | `wiki-researcher` | Conducts multi-turn iterative deep research on specific topics within a codeb... | | `wordpress-penetration-testing` | This skill should be used when the user asks to "pentest WordPress sites", "s... | | `xss-html-injection` | This skill should be used when the user asks to "test for XSS vulnerabilities... |