r03-anthropics-skills-security
🔒 Security & Compliance skill suite derived from anthropics/skills.
- 评测生成时间(北京时间)
- 本报告引擎
- v3.10.0
- 当前引擎
- v3.16.0
本报告与当前引擎使用不同规则;原分数不会自动更新,不同版本的分数不宜直接对比。
进入后确认来源与额度,提交才会创建任务。
综合采用结论
具备基础能力,但文档或工程质量仍需完善
- 基础评测完成+25/25确定性评分与静态安全扫描已完成
- README 有效证据+11/254,363 个去重后的有效字符
- 独立证据来源+8/202 类非重复证据,重复文件不叠加
- 仓库元数据+10/10已取得仓库状态与采用数据
- 活跃记录+5/5已取得最近提交时间
- AI 复核+15/15已完成结构化 AI 证据复核
安全审计命令执行流程
README描述了每个命令遵循的5步交互模式,属于单一任务的连续处理步骤,适合用flow图表示。
左右滑动查看完整图示
- • README中'Interaction Pattern'列出5步结构
- • README中'Progress Display Example'展示分析过程
- • README中'Findings Table'展示结果表格
- README中'Commands'表格列出10个命令,如/owasp-scan、/dep-cve
- README中'Workflows'表格列出5个工作流,如secure-sdlc、breach-response
- README中'Quick Install'提供cp命令,但未说明文件结构
- README中'Progress Display Example'展示输出格式
- README中'Interaction Pattern'定义5步结构
- 问题与用途描述
- 有效 README
- 可执行示例
- 输出或结果说明
- 未发现已知高风险模式
- 缺少安装或接入步骤
- 缺少输入、参数或工具说明
- 缺少错误处理或排障
- 安装步骤不完整,缺少实际文件结构或SKILL.md内容
- 命令和参数说明不足,仅给出示例用法,无详细参数定义
安全审计与合规检查的流程框架参考、需要结构化输出和进度跟踪的安全工具设计、作为开发安全相关Skill的模板、快速了解安全命令集和交互模式
直接用于生产环境的安全扫描或合规审计、需要精确参数和可靠输出的自动化集成、依赖具体实现细节的二次开发
也有自己的公开项目?先看完证据,再用当前规则生成独立报告。
评测我的项目 →静态扫描不是安全保证,生产接入前仍应人工复核权限和数据边界。
- 01补充安装或接入步骤
- 02补充输入、参数或工具说明
- 03补充错误处理或排障
方法、证据与局限展开收起
GitHub Repository API
2 个文件 · 8,086 字符
v3.10.0 · AI 复核已启用(deepseek-chat)
- 静态评测不会安装或执行项目代码
- 安全扫描基于高信号文件与已知模式,不能替代人工审计
- 流行度只反映采用程度,不代表安全或工程质量
30 天热度趋势
README
🔒 Security & Compliance Skills Suite
Derived from anthropics/skills
Adaptation of
anthropics/skillsfor Security & Compliance use cases. Source focus: official Anthropic skill templates, webapp testing, comms
What This Skill Suite Does
Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response.
This collection provides 10 specialised commands and 5 multi-step workflows, all with a consistent structured-output UI so you always know exactly where you are and what to do next.
Quick Install
# Clone this skill
cp -r . ~/.claude/skills/r00-anthropics-skills--security/
# Register in Claude Code
# In a Claude Code session:
/read ~/.claude/skills/r00-anthropics-skills--security/SKILL.md
Commands
| Command | Description |
|---|---|
/owasp-scan | OWASP Top-10 code scan with exploit description, CVSS score and remediation |
/dep-cve | Dependency CVE report with exploitability score and upgrade path |
/gdpr-audit | GDPR data-flow map, consent gaps and DPA checklist |
/soc2-readiness | SOC 2 Type II readiness gap analysis across all 5 Trust Service Criteria |
/threat-model | STRIDE threat model for architecture diagram with risk matrix |
/pentest-report | Structured penetration test report: executive summary, findings and remediation |
/secret-detect | Pre-commit secret detection hook config with entropy scanning |
/iam-audit | IAM least-privilege audit: over-permissioned roles, stale access and MFA gaps |
/incident-playbook | Security incident playbook: triage → contain → eradicate → recover → lessons |
/privacy-policy | GDPR/CCPA-compliant privacy policy generator from data inventory |
Usage:
/owasp-scan <target>
/dep-cve --scope full --output md
Workflows (Multi-step)
| Workflow | Description |
|---|---|
secure-sdlc | Shift-left SDLC: threat model → code scan → DAST → pen test → sign-off |
breach-response | Data breach response: detect → assess → notify → remediate → post-mortem |
compliance-audit | Full compliance audit: scope → gap analysis → evidence → remediation plan |
zero-trust-design | Zero-trust architecture design: identity → network → workload → data layers |
vendor-security | Third-party vendor security assessment: questionnaire → risk score → decision |
Usage:
/workflows:secure-sdlc <target> --scope full
UI Design
All commands display structured output with:
- Progress panels — real-time step tracking
- Findings tables — sorted by severity (🔴🟠🟡🟢)
- Action checklists — quick wins → medium-term → strategic
- Summary cards — at-a-glance metrics after each command
Progress Display Example
╔══════════════════════════════════════════════════╗
║ Security Audit — api.domain.com ║
╠══════════════════════════════════════════════════╣
║ OWASP scan ✓ 14 checks run ║
║ CVE scan ✓ 234 deps checked ║
║ IAM audit ⟳ Scanning roles … ║
║ GDPR check ░ Pending ║
╚══════════════════════════════════════════════════╝
FINDINGS (sort: severity desc)
┌──────┬──────────────────────────────┬──────────┬──────────────┐
│ Sev │ Finding │ CVSS │ Status │
├──────┼──────────────────────────────┼──────────┼──────────────┤
│ 🔴 │ SQL injection /api/search │ 9.8 │ ✗ Open │
│ 🔴 │ JWT none-alg accepted │ 9.1 │ ✗ Open │
│ 🟠 │ CORS wildcard on /api/* │ 6.5 │ ⚠ In-Review │
│ 🟡 │ Missing rate limiting │ 5.3 │ ⚠ In-Review │
│ 🟢 │ CSP header present │ — │ ✓ Pass │
└──────┴──────────────────────────────┴──────────┴──────────────┘
Interaction Pattern
Every command follows this 5-step structure:
① Scope Confirmation — verify target and options with user
② Live Analysis — progress bar while working
③ Findings Table — structured results sorted by impact
④ Action Plan — prioritised, time-boxed recommendations
⑤ Next Steps — suggested follow-up commands
Source Repository
This suite is derived from anthropics/skills which focuses on: official Anthropic skill templates, webapp testing, comms.
Improvements in this adaptation:
- Domain-specific command vocabulary for Security & Compliance
- Enhanced structured output with visual progress tracking
- Prioritised action plans with time estimates
- Workflow orchestration for end-to-end processes
- Consistent UI conventions across all commands
License
MIT — free to use, modify and distribute.