Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Generate a client-ready security hygiene snapshot for a prospect domain. Free lead magnet for consulting practices. Outputs a markdown report covering SSL/TLS grade, HTTP security headers, email authentication (SPF/DMARC), and server fingerprint leaks. Use when the user says /security-snapshot, /snapshot [domain], "run a security check on X", or "generate a security report for [company]". Do NOT use for penetration testing, internal infrastructure audits, or application-layer vulnerability asses
.claude/skills/bilal140202-security-snapshot/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-04 | ✗→✓ | ▲ Improved | 55% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 167% | 0% |
| case-07 | ✗→✓ | ▲ Improved | -6% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 227% | 0% |
| case-14 | ✗→✓ | ▲ Improved | -34% | 0% |
When the user types /security-snapshot domain] or asks for a security check on a prospect, run the security snapshot generator and deliver a client-ready report.
Prospects rarely have budget for a full security audit upfront, but they will read a free one-page report that exposes real issues with their public-facing setup. This skill generates that report in under 3 minutes and opens the door for a paid follow-up on security work, AI implementation, or adjacent consulting.
bashpython3 "$HOME/.claude/skills/ai-brain-starter/scripts/security-snapshot.py" <domain> --company "<Display Name>"
The script ships with the starter repo. Output goes to $SNAPSHOTS_DIR if set, otherwise $VAULT_ROOT/security-snapshots/ if VAULT_ROOT is set, otherwise a security-snapshots/ folder next to wherever you run the command from. It takes 60-180 seconds because SSL Labs is slow. The script prints the saved report path to stdout and progress to stderr.
$SNAPSHOTS_DIR/<domain>/<YYYY-MM-DD>-snapshot.md (defaults to $VAULT_ROOT/security-snapshots/ when SNAPSHOTS_DIR is unset). Read the file before summarizing.The script produces the base report. If the user asks you to customize or rewrite any section before sending, follow the generic voice rules in templates/rules/voice-firewall.md:
--out to write to an internal folder).The script does not currently cover these because they need paid API keys or explicit authorization. Offer to add manually when relevant:
$SNAPSHOTS_DIR/
├── acme.com/
│ ├── 2026-04-16-snapshot.md
│ └── 2026-07-22-snapshot.md (if re-run later)
└── another-prospect.co/
└── 2026-04-18-snapshot.mdOne folder per domain. Re-running on the same day overwrites. Running weeks later creates a new dated file so you can track improvement (or lack of it) across conversations.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 10,463 | 10,656 | +2% | 1 | 1 | 0% | 734 | 2,162 | +195% | 0 | 0 | — |
case-02 | fail→fail | 15,828 | 10,927 | -31% | 1 | 1 | 0% | 1,372 | 1,904 | +39% | 0 | 0 | — |
case-03 | fail→fail | 12,694 | 12,010 | -5% | 1 | 1 | 0% | 965 | 1,930 | +100% | 0 | 0 | — |
case-04 | fail→pass | 14,703 | 10,226 | -30% | 1 | 1 | 0% | 1,413 | 2,189 | +55% | 0 | 0 | — |
case-05 | fail→fail | 13,020 | 15,896 | +22% | 1 | 1 | 0% | 1,624 | 2,096 | +29% | 0 | 0 | — |
case-06 | fail→pass | 8,848 | 10,485 | +19% | 1 | 1 | 0% | 778 | 2,078 | +167% | 0 | 0 | — |
case-07 | fail→pass | 12,881 | 5,508 | -57% | 1 | 1 | 0% | 2,180 | 2,045 | -6% | 0 | 0 | — |
case-08 | fail→fail | 12,853 | 14,746 | +15% | 1 | 1 | 0% | 1,577 | 2,856 | +81% | 0 | 0 | — |
case-09 | pass→pass | 6,056 | 6,245 | +3% | 1 | 1 | 0% | 1,009 | 2,124 | +111% | 0 | 0 | — |
case-19 | pass→pass | 9,769 | 2,738 | -72% | 1 | 1 | 0% | 1,451 | 1,570 | +8% | 0 | 0 | — |
case-10 | fail→pass | 13,569 | 17,007 | +25% | 1 | 1 | 0% | 817 | 2,671 | +227% | 0 | 0 | — |
case-11 | fail→fail | 7,170 | 5,156 | -28% | 1 | 1 | 0% | 1,220 | 2,085 | +71% | 0 | 0 | — |
case-12 | pass→pass | 11,443 | 6,320 | -45% | 1 | 1 | 0% | 1,465 | 1,665 | +14% | 0 | 0 | — |
case-13 | fail→fail | 5,871 | 7,663 | +31% | 1 | 1 | 0% | 989 | 1,554 | +57% | 0 | 0 | — |
case-14 | fail→pass | 12,334 | 1,681 | -86% | 1 | 1 | 0% | 2,158 | 1,424 | -34% | 0 | 0 | — |
case-15 | fail→pass | 5,210 | 2,450 | -53% | 1 | 1 | 0% | 915 | 1,633 | +78% | 0 | 0 | — |
case-16 | fail→pass | 10,343 | 2,467 | -76% | 1 | 1 | 0% | 1,833 | 1,601 | -13% | 0 | 0 | — |
case-17 | fail→pass | 8,135 | 3,040 | -63% | 1 | 1 | 0% | 1,266 | 1,754 | +39% | 0 | 0 | — |
case-18 | fail→pass | 10,801 | 12,907 | +19% | 1 | 1 | 0% | 1,536 | 1,619 | +5% | 0 | 0 | — |
case-20 | fail→pass | 9,117 | 4,023 | -56% | 1 | 1 | 0% | 1,322 | 1,809 | +37% | 0 | 0 | — |
case-21 | fail→pass | 13,338 | 3,638 | -73% | 1 | 1 | 0% | 2,046 | 1,698 | -17% | 0 | 0 | — |
case-22 | fail→fail | 5,263 | 2,457 | -53% | 1 | 1 | 0% | 756 | 1,491 | +97% | 0 | 0 | — |
case-23 | fail→fail | 10,934 | 6,429 | -41% | 1 | 1 | 0% | 1,415 | 2,011 | +42% | 0 | 0 | — |
case-24 | pass→pass | 8,587 | 1,761 | -79% | 1 | 1 | 0% | 1,357 | 1,407 | +4% | 0 | 0 | — |
case-25 | pass→pass | 10,260 | 3,025 | -71% | 1 | 1 | 0% | 1,641 | 1,619 | -1% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 25 cases were attempted. The headline lift of +44 percentage points is the difference between those two pass rates over the 25 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.