npx claudepluginhub zate/cc-plugins --plugin securityThis skill uses the workspace's default tool permissions.
This skill is an index to modular remediation guides. Use the specialized skills below for focused remediation guidance.
Detects OWASP Top 10 2021 security vulnerabilities like broken access control and injection, with remediation patterns for audits and code reviews.
Provides OWASP Top 10 guidelines, secure Python/Flask coding patterns, prevention strategies, and remediation for access control and cryptographic vulnerabilities.
Provides application security best practices and patterns for authentication, authorization, OWASP Top 10, API security, data protection, and infrastructure.
Share bugs, ideas, or general feedback.
This skill is an index to modular remediation guides. Use the specialized skills below for focused remediation guidance.
remediation-injectionCovers: SQL Injection, Command Injection, XSS CWEs: CWE-89, CWE-78, CWE-79 Use when: Fixing injection vulnerabilities, code review feedback
remediation-cryptoCovers: Weak Cryptography, Insecure Randomness, TLS Issues CWEs: CWE-327, CWE-330, CWE-295 Use when: Fixing crypto vulnerabilities, upgrading algorithms
remediation-authCovers: Hardcoded Credentials, JWT Security, Deserialization, Access Control CWEs: CWE-798, CWE-347, CWE-502, CWE-862 Use when: Fixing auth issues, secrets management, authorization
remediation-configCovers: Path Traversal, Debug Mode, Security Headers CWEs: CWE-22, CWE-489, CWE-693 Use when: Fixing deployment issues, hardening configuration
| Vulnerability Type | Skill to Use |
|---|---|
| SQL Injection | remediation-injection |
| Command Injection | remediation-injection |
| XSS | remediation-injection |
| Weak hashing (MD5/SHA1) | remediation-crypto |
| Insecure randomness | remediation-crypto |
| TLS disabled | remediation-crypto |
| Hardcoded secrets | remediation-auth |
| JWT issues | remediation-auth |
| Unsafe deserialization | remediation-auth |
| Missing access control | remediation-auth |
| Path traversal | remediation-config |
| Debug in production | remediation-config |
| Missing headers | remediation-config |
| OWASP 2021 | Primary Skill |
|---|---|
| A01 Broken Access Control | remediation-auth |
| A02 Cryptographic Failures | remediation-crypto |
| A03 Injection | remediation-injection |
| A04 Insecure Design | Multiple |
| A05 Security Misconfiguration | remediation-config |
| A06 Vulnerable Components | N/A |
| A07 Auth Failures | remediation-auth |
| A08 Data Integrity Failures | remediation-auth |
| A09 Logging Failures | remediation-config |
| A10 SSRF | remediation-injection |
vulnerability-patterns - Detection patternsasvs-requirements - ASVS compliance mappingaudit-report - Report formatting