
Security Scan
codewithmukesh/dotnet-claude-kit/skills/security-scanby codewithmukesh23300897f4d1No license754 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 2 months ago
Deep security scanning for .NET applications across 6 layers: vulnerable packages, secrets detection, OWASP code patterns, auth configuration, CORS policy, and data protection. Produces severity-rated findings with specific remediation steps. Load this skill when: "security scan", "security audit", "check for vulnerabilities", "find secrets", "OWASP", "auth review", "CORS check", "security review", "penetration test prep", "CVE check", "vulnerability scan", "hardcoded password", "data protection", "security posture".
- 23300897f4d1Currentcommit 2330089Published Oct 8, 2026
Source and attribution
Source:codewithmukesh/dotnet-claude-kitinskills/security-scanat commit2330089
License: No license
Content belongs to its original authors. SourceWeft indexes it from a public repository.
More from codewithmukesh/dotnet-claude-kit

Wrap Up
codewithmukesh
Captures end-of-session work, pending tasks and learnings into a handoff file, and reloads it at session start.

Workflow Mastery
codewithmukesh
Claude Code workflow mastery for .NET developers. Covers parallel execution with git worktrees, plan mode strategy, verification loops, auto-formatting hooks, permission setup for dotnet CLI, prompting techniques, subagent patterns, and context discipline — token budget management, MCP-first navigation, lazy loading, and subagent isolation — all adapted for the .NET ecosystem. Load this skill when setting up Claude Code for a .NET project, optimizing workflows, running parallel sessions, when context is running low or sessions feel sluggish, when exploring a large codebase efficiently, or when the user mentions "productivity", "workflow", "parallel", "worktree", "plan mode", "permissions", "hooks", "10x", "setup Claude Code", "speed up development", "context", "tokens", "budget", "running out of context", "too many files", or "large codebase". Inspired by tips from Boris Cherny (creator of Claude Code) and the Anthropic team.

Vertical Slice
codewithmukesh
Guides .NET developers in structuring applications with Vertical Slice Architecture, covering feature folders, endpoint grouping and handler patterns.

Testing
codewithmukesh
Testing strategy for .NET 10 applications. Covers xUnit v3, WebApplicationFactory for integration tests, Testcontainers for real database testing, Verify for snapshot testing, and the AAA pattern. Load this skill when writing tests, setting up test infrastructure, reviewing test coverage, or when the user mentions "test", "xUnit", "WebApplicationFactory", "Testcontainers", "integration test", "unit test", "bUnit", "snapshot test", "Verify", "test coverage", "AAA pattern", "WireMock", or "FakeTimeProvider".

Tdd
codewithmukesh
Guided test-driven development workflow for .NET 10 using xUnit v3, WebApplicationFactory, Testcontainers, and Verify snapshots. Follows the strict red-green-refactor cycle. Use when: "TDD", "test-driven", "let's TDD this", "red green refactor", "write the test first", or when building a feature with clear acceptance criteria.

Spec
codewithmukesh
Turns a vague feature idea into an agreed, persisted specification file through structured questioning rounds.
More in Security

Kyc Rules
anthropics
Applies a firm's KYC/AML rules grid to a parsed onboarding record, scoring risk and routing outcomes.

Kyc Rules
anthropics
Applies a firm's KYC/AML rules grid to a parsed onboarding record, scoring risk and routing outcomes.

Compliance Tracking
anthropics
Tracks compliance requirements, audit readiness, and evidence for frameworks such as SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS.

Dpop Adoption
Guides implementation of OAuth 2.0 DPoP (RFC 9449) sender-constrained refresh tokens for Google's OAuth platform.

Secops Triage
Guides SOC analysts through triaging Google SecOps security alerts, from investigation to closure or escalation.

Secops Investigate
Guides SOC analysts through deep security incident and entity investigations in Google SecOps using UDM queries and timelines.