Israeli AppSec Scanner
Verified96/100Security scanning guidance for Israeli web applications covering OWASP Top 10, Israeli Privacy Protection Authority (PPA) compliance, dependency vulnerability scanning, secrets detection, and secure coding patterns for Hebrew/RTL apps.
Trust score 96/100 (Verified) · 170+ installs · 2 GitHub contributors · MIT license
Israeli developers build web applications without dedicated security scanning tools that account for the Israeli context: Hebrew input requiring special sanitization, Unicode bidirectional text attacks, Privacy Protection Law requirements, and leakage of Israeli service API keys. Without tailored scanning, vulnerabilities specific to Israeli applications remain undetected.
npx skills-il add skills-il/security-compliance@v1.2.0-israeli-appsec-scanner --skill israeli-appsec-scanner -a claude-codeInstall on Claude.ai, Claude Desktop, ChatGPT, Manus, or other platforms
- 1. Click "Download ZIP" to download the skill files.
- 2. Open Claude Desktop and go to Customize > Skills.
- 3. Click "+" and select "Upload a skill", then upload the ZIP file.
- 4. Start a new conversation. The skill will activate automatically when relevant.
When to Apply
- When you want to perform a comprehensive security scan on an Israeli application
- When you need to verify compliance with the Privacy Protection Law and 2017 regulations
- When you want to detect leaked API keys for Israeli services like Cardcom or Tranzila
- When testing a Hebrew-input application against XSS and SQL injection attacks
- When preparing an application for SOC 2 or PCI DSS audit
Try These Prompts
Run a full security scan of my application against OWASP Top 10 with focus on Hebrew input and RTL attacks
Scan my project for leaked API keys of Israeli services like Cardcom, Tranzila, and Supabase
Check if my application complies with the Israeli Privacy Protection Law and 2017 security regulations
Scan my codebase for hidden Unicode bidirectional characters that could alter code logic
Frequently Asked Questions
Changelog
Update: rewrote the database-registration section for Amendment 13 (registration only for data brokers over 10,000 and public bodies, no annual renewal, notification tier for sensitive databases over 100,000). Corrected breach reporting to immediate (not 72 hours). Updated the Trivy compromise range (v0.69.4 to v0.69.6).
May 28, 2026
Added OWASP Top 10 2025 cross-walk note (SSRF folded into A01, new A03 Supply Chain, new A10 Mishandling, A09 renamed to Security Logging and Alerting Failures). Trivy v0.69.4 supply-chain compromise warning. Expanded Amendment 13 breach-notification details (72h window, NIS 100K statutory damages, 100K-individual sensitive-data tier).
Apr 28, 2026
Added Reference Links section (OWASP, PPA, INCD, Trivy, Snyk, TruffleHog). Fixed portability_score.
Apr 15, 2026
Related Skills
Coordinate Israeli-built cybersecurity tools for security operations including threat triage, vulnerability management, compliance checking, and incident response. Use when user mentions security operations, "SOC", vulnerability scanning, threat triage, compliance assessment, or asks to coordinate Wiz, Snyk, Check Point, CyberArk, SentinelOne, Armis, Torq, or Pentera tools. Embeds Israeli security best practices including INCD guidelines and Israeli Privacy Protection Law compliance. Do NOT use for offensive security testing or creating exploits.
Guide Israeli ML teams through the AI governance and compliance stack: Ministry of Innovation December 2023 AI policy principles, Privacy Protection Law (PPL) and Amendment 13 applied to ML training data, sector-specific rules (Bank of Israel Directive 364, Ministry of Health AMAR medical-device AI), and EU AI Act exposure for Israeli exporters. Generates model cards, data statements, and DPIA templates tailored to Israeli context. Use when preparing AI governance docs, answering an enterprise customer's AI risk review, classifying a system under the EU AI Act, or building an internal responsible-AI checklist. Prevents costly compliance gaps when shipping AI to regulated markets. Do NOT use for general PPL policy (use israeli-privacy-shield), web app security (use israeli-appsec-scanner), or SOC/threat triage (use israeli-cybersecurity-ops).
Audit and ensure Israeli e-commerce legal compliance, Consumer Protection Law, return policies, price display, accessibility, and cookie consent. Use when user asks about "online store compliance Israel", "Chok Hagnat HaTzarchan", "consumer protection Israel", "return policy Israel", "IS 5568 ecommerce", "cookie consent Israel", or "חוק הגנת הצרכן". Covers cooling-off period validation, price display requirements, Hebrew terms of service generation, accessibility compliance (IS 5568), and business disclosure verification. Do NOT use for food-specific compliance (use israeli-food-business-compliance) or privacy/GDPR (use israeli-privacy-shield).
Use at your own risk. Terms of Use · Security
Want to build your own skill? Try the Skill Creator · Submit a Skill