Help us improve
Share bugs, ideas, or general feedback.
From cc-polymath
Auto-discovers security skills for authentication, authorization, input validation, security headers, vulnerability assessment, and secrets management in app security and OWASP tasks.
npx claudepluginhub rand/cc-polymath --plugin cc-polymathHow this skill is triggered — by the user, by Claude, or both
Slash command
/cc-polymath:discover-securityThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Provides automatic access to comprehensive application security, vulnerability assessment, and security best practices skills.
Provides application security best practices and patterns for authentication, authorization, OWASP Top 10, API security, data protection, and infrastructure.
Guides application security reviews and implementation covering OWASP Top 10, input validation, auth, secrets management, and antipatterns.
Provides OWASP Top 10 guidelines, secure Python/Flask coding patterns, prevention strategies, and remediation for access control and cryptographic vulnerabilities.
Share bugs, ideas, or general feedback.
Provides automatic access to comprehensive application security, vulnerability assessment, and security best practices skills.
This skill auto-activates when you're working with:
The Security category contains 6 specialized skills:
For complete descriptions and workflows:
Read ../security/INDEX.md
This loads the full Security category index with:
Load individual skills as needed:
Read ../security/authentication.md Read ../security/authorization.md
Read ../security/input-validation.md Read ../security/security-headers.md
Read ../security/vulnerability-assessment.md Read ../security/secrets-management.md
Sequence: Authentication → Authorization → Input validation → Security headers
Read ../security/authentication.md # User login Read ../security/authorization.md # Access control Read ../security/input-validation.md # XSS/SQL injection prevention Read ../security/security-headers.md # Browser protection
Sequence: Vulnerability assessment → Input validation → Headers → Secrets
Read ../security/vulnerability-assessment.md # OWASP Top 10 testing Read ../security/input-validation.md # Injection testing Read ../security/security-headers.md # Header configuration Read ../security/secrets-management.md # Credential security
Sequence: Authentication → Authorization → Input validation → Secrets
Read ../security/authentication.md # JWT/OAuth2 Read ../security/authorization.md # API access control Read ../security/input-validation.md # Request validation Read ../security/secrets-management.md # API key management
Sequence: Vulnerability assessment → Secrets → Input validation
Read ../security/vulnerability-assessment.md # Security scanning Read ../security/secrets-management.md # CI/CD secrets Read ../security/input-validation.md # SAST validation
Full security implementation from scratch:
Read ../security/authentication.md Read ../security/authorization.md
Read ../security/input-validation.md Read ../security/security-headers.md
Read ../security/secrets-management.md Read ../security/vulnerability-assessment.md
Choose Authentication when:
Choose Authorization when:
Choose Input Validation when:
Choose Security Headers when:
Choose Vulnerability Assessment when:
Choose Secrets Management when:
Security skills commonly combine with:
API skills (discover-api):
Database skills (discover-database):
Frontend skills (discover-frontend):
Infrastructure skills (discover-infrastructure, discover-cloud):
Testing skills (discover-testing):
Read ../security/INDEX.md for full category overviewThis gateway skill (~200 lines, ~2K tokens) enables progressive loading:
Total context: 2K + 3K + skill(s) = 5-12K tokens vs 30K+ for entire index.
"Implement user authentication": Read ../security/authentication.md
"Add role-based access control": Read ../security/authorization.md
"Prevent SQL injection": Read ../security/input-validation.md
"Configure Content Security Policy": Read ../security/security-headers.md
"Test for OWASP vulnerabilities": Read ../security/vulnerability-assessment.md
"Integrate HashiCorp Vault": Read ../security/secrets-management.md
"Secure API with JWT": Read ../security/authentication.md Read ../security/authorization.md
Next Steps: Run Read ../security/INDEX.md to see full category details, or load specific skills using the bash commands above.