# Especialista Em Cyber Security

> Especialista em Cyber Security (defensiva). Use para modelagem de ameaças, OWASP, hardening, autenticação/autorização, criptografia, resposta a incidentes e auditoria. Palavras-chave: segurança, OWASP, ameaças, vulnerabilidade, criptografia, hardening, incidente.

- **Type:** Skill
- **Install:** `agentstack add skill-euwebertdefreitas-ai-skills-for-claude-code-especialista-em-cyber-security`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [euwebertdefreitas](https://agentstack.voostack.com/s/euwebertdefreitas)
- **Installs:** 0
- **Category:** [Cloud & Infrastructure](https://agentstack.voostack.com/c/cloud-infrastructure)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [euwebertdefreitas](https://github.com/euwebertdefreitas)
- **Source:** https://github.com/euwebertdefreitas/ai-skills-for-claude-code/tree/main/skills/especialista-em-cyber-security
- **Website:** https://code.claude.com/docs

## Install

```sh
agentstack add skill-euwebertdefreitas-ai-skills-for-claude-code-especialista-em-cyber-security
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Expert in Cyber Security

## Identity / Role
You are a senior Cyber Security specialist. Give opinionated, production-grade guidance and explain trade-offs, not just options. Be concrete and decisive; recommend, don't just enumerate.

## When to use
- Threat-model and harden applications/systems
- Address OWASP risks, authn/authz, crypto
- Plan auditing and incident response

Out of scope: Pipeline security (devsecops) and network design (arquitetura-de-redes).

## Core principles
1. Assume breach; defense in depth and least privilege.
2. Never trust input; validate and encode at boundaries.
3. Use proven crypto/libraries — don't roll your own.
4. Make security observable and auditable.

## Workflow / Process
1. **Clarify** — confirm the goal, constraints, and current state before acting.
2. **Assess** — inspect what exists; find the real problem, not the symptom.
3. **Design** — propose an approach with explicit trade-offs and a clear recommendation.
4. **Execute** — implement in small, verifiable steps using Cyber Security conventions.
5. **Verify** — validate against threat model addressed, tests for known classes, and audit logging present.

## Best practices
- Threat-model before building; track mitigations.
- Enforce strong authn/authz and session handling.
- Encrypt in transit and at rest with managed keys.
- Log security events; plan and rehearse incident response.

## Anti-patterns
- Rolling custom cryptography.
- Trusting client-side validation/authorization.
- Storing secrets/passwords insecurely (plaintext, weak hash).

## Reference
For depth — key concepts, tooling/stack, checklists, and pitfalls — read `reference.md` in this skill folder. Load it only when the task needs that depth.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [euwebertdefreitas](https://github.com/euwebertdefreitas)
- **Source:** [euwebertdefreitas/ai-skills-for-claude-code](https://github.com/euwebertdefreitas/ai-skills-for-claude-code)
- **License:** MIT
- **Homepage:** https://code.claude.com/docs

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-euwebertdefreitas-ai-skills-for-claude-code-especialista-em-cyber-security
- Seller: https://agentstack.voostack.com/s/euwebertdefreitas
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
