Turns Claude into a CMMC 2.0 / NIST SP 800-171 consultant for gap assessments, SSP drafting, SPRS scoring and POA&M management in the US defense supply chain.
A California privacy skill that walks through CCPA/CPRA applicability, consumer-rights workflows, opt-out/SPI/ADMT mechanics, and GDPR gap analysis.
Pressure-tests an ISO/IEC 42001 AI Management System with six forcing questions before certification or internal audit.
Guides Claude through expert-grade design, configuration, and troubleshooting of Cloudflare One Zero Trust / SASE deployments.
An OWASP-driven security review skill that hardens user input, auth, dependencies, and LLM features with concrete code patterns.
Uses the WinDiff CLI to diff two Windows builds and interpret new syscalls, structs, mitigation flags, and ETW/callback surface into a security-research report.
A zero-trust gatekeeper skill that scans every incoming file or URL and returns a pass/reject verdict plus a compliance scan report before any document processing happens.
Runs the liarjs CLI to cross-check a browser's JS fingerprint (canvas, WebGL, audio, fonts, WebRTC, timezone) against the TLS/HTTP/ASN view of the same request and scores the contradictions.
Designs and verifies auditable human approval gates, escalation paths, and safe state transitions for risky AI agent actions.
Plans assessments, policy mappings, and staged rollouts when migrating from Zscaler ZIA/ZPA, Palo Alto, or legacy VPN/SWG stacks to Cloudflare One.
A hands-on guide for hardening ROS2 robots end to end: SROS2/DDS encryption, network segmentation, secrets, container security, and cyber-physical safety.
A defensive security-audit skill that scans your whole repo for dependency CVEs and risky code patterns, triages them by severity and reachability, then fixes them without suppressing alerts.
Reads a liarjs fingerprint report and attributes each failing check to the component that actually produced the signal.
Takes a proven vulnerability through private vendor reporting, timeline coordination, CVE assignment, and public advisory publication.
A skill that reviews code against quality, security, performance, and maintainability checklists and returns a severity-ranked report.
A static-analysis skill that applies abstract interpretation to infer variable ranges and flag potential runtime errors — out-of-bounds, null dereference, divide-by-zero, integer overflow — without running the code.
Analyzes German cease-and-desist letters over unfair T&C clauses and drafts a narrowed cease-and-desist undertaking with cost and risk assessment.
Autonomously scans a codebase for personal data, runs an all-99-article GDPR gap analysis, and generates pre-filled DPA, ROPA and operational compliance documents.
Guides Claude in designing end-to-end security architectures using defense-in-depth, zero trust, STRIDE/PASTA threat modeling, and NIST CSF / CIS / ISO 27001 control mapping.
Auto-checks forms, schemas, auth flows and APIs for personal-data risks before Claude writes the code, mapped to US privacy regulations.