Slash commands that package prompts into reusable one-liners for everyday Claude Code work. 140 curated, ranked by GitHub signal.
140 commands in Security
wshobson
Walk the receipt chain in ./receipts/ verifying every signature and hash link. Detects insertions, deletions, and tampering across the entire audit trail.
wshobson
Set up PreToolUse hook to block --no-verify and other git bypass flags in Claude Code projects
wshobson
Regulatory Compliance Check
wshobson
Dependency Audit and Security Analysis
wshobson
Audit project dependencies for vulnerabilities, outdated packages, license conflicts, and supply chain risks — then provide actionable remediation strategies.
wshobson
Orchestrate comprehensive multi-dimensional code review using specialized review agents across architecture, security, performance, testing, and best practices
wshobson
Orchestrate multi-agent incident response with modern SRE practices for rapid resolution and learning
wshobson
Multi-Agent Code Review Orchestration Tool
wshobson
Multi-Agent Code Review Orchestration Tool
wshobson
Dependency Vulnerability Scanning
wshobson
Orchestrate comprehensive security hardening with defense-in-depth strategy across all application layers
wshobson
Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks
wshobson
Verify a single Ed25519-signed receipt file. Returns exit 0 if valid, 1 if tampered, 2 if malformed.
wshobson
XSS Vulnerability Scanner for Frontend Code
davila7
Implement secure user authentication system with chosen method and security best practices
davila7
When user is asking for guidance for which role to assign to an identity given desired permissions, this agent helps them understand the role that will meet the requirements with least privilege access and how to apply that role.
davila7
Perform comprehensive analysis of $ARGUMENTS to identify code quality issues, security vulnerabilities, and optimization opportunities.
davila7
Comprehensive code quality review with security, performance, and architecture analysis
davila7
Containerize application with optimized Docker configuration, security, and multi-stage builds
davila7
Audit dependencies for security vulnerabilities, license compliance, and update recommendations
davila7
Google Workspace Admin SDK: Manage users, groups, and devices.
davila7
Google Workspace Alert Center: Manage Workspace security alerts.
davila7
Google Cloud Identity: Manage identity groups and memberships.
davila7
Google Model Armor: Filter user-generated content for safety.
davila7
Google Model Armor: Sanitize a model response through a Model Armor template.
davila7
Google Vault: Manage eDiscovery holds and exports.
davila7
Create optimized Next.js middleware with authentication, rate limiting, and routing logic
davila7
Perform penetration testing and vulnerability assessment on application
davila7
Administer IT — manage users, monitor security, configure Workspace.
davila7
Find and review Google Drive files shared outside the organization.
davila7
List and review Google Workspace security alerts from Alert Center.
davila7
Rollback deployment to previous version with safety checks, database considerations, and monitoring
davila7
Scan codebase for exposed secrets, credentials, and sensitive information
davila7
Perform comprehensive security assessment and vulnerability analysis
davila7
Harden application security configuration with comprehensive security controls
davila7
Configure comprehensive Kubernetes deployment with manifests, security, scaling, and production best practices
davila7
Implement comprehensive API rate limiting with advanced algorithms and user-specific policies
davila7
Conduct comprehensive Supabase security audit with RLS analysis and vulnerability assessment
davila7
Audit a project for software supply chain risk, including dependency vulnerabilities, lockfile issues, malicious package indicators, SBOM coverage, and license concerns.
phuryn
Draft a privacy policy covering data collection, usage, storage, and compliance requirements
phuryn
Static security audit of AI-built code — map trust boundaries, cross-reference documented intent, self-refute every finding, and report only evidence-backed risks
alirezarezvani
Score vendors on a multi-dimensional scorecard (reliability / support / security / commercial / strategic-fit), track SLA compliance, classify third-party risk. Direct invocation of the vendor-management skill.