agentleFS
Sign inSign up

Claude skills and agent skills

Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.

Best matches · from page 12Worked for most · soon
MicrosoftSkill

security-alerts

microsoft/powerplatform-build-tools/.claude/skills/security-alerts/SKILL.md

Fetch all open security alerts from S360/ADO, Dependabot, and npm audit, apply all fixes, verify, commit, and create a PR.

3036mo agoDiscuss
ebibibiSkill

security-audit

ebibibi/ebi-agent-chat-relay/.claude/skills/security-audit/SKILL.md

Security checklist specific to claude-code-discord-bridge — subprocess injection, env leaks, input validation

588mo agoReads credentialsDiscuss
OpenCovenSkill

security-agent

OpenCoven/coven/skills/security-agent/SKILL.md

Comprehensive OpenClaw security assessment, hardening, and monitoring agent. Covers 7 domains — gateway hardening, channel/sender policy, tool/exec policy, credential hygiene, prompt injection defense, host OS hardening, and continuous monitoring. Use when asked to audit security, harden the setup, check for exposed secrets, assess threat model, schedule security monitoring, respond to potential compromise, fix security audit findings, or review OpenClaw config safety. Triggers on phrases like "security audit", "harden my setup", "check my security", "exposed secrets", "am I secure", "security agent", "threat model", "I think I'm compromised", "fix security warnings", "security posture".

562mo agoDiscuss
OpenAISkill

deep-security-scan

openai/plugins/plugins/codex-security/skills/deep-security-scan/SKILL.md

Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated complete independent Standard scans with the Codex Security deep-scan tool, which aggregates their validated findings and prepares the canonical artifacts; then complete the same scan once. Do not use for PRs, commits, branch diffs, or working-tree diffs.

6.8k5mo agoDiscuss
loulanyueSkill

django-security

loulanyue/awesome-claude-notes/skills/django-security/SKILL.md

Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.

2726mo agoReads credentialsDiscuss
loulanyueSkill

security-review

loulanyue/awesome-claude-notes/skills/security-review/SKILL.md

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

2726mo agoReads credentialsDiscuss
naviktSkill

security-owasp

navikt/copilot/skills/security-owasp/SKILL.md

OWASP Top 10:2025 kodenivå-mønstre for Kotlin, Go, Java og Node.js — tilgangskontroll, forsyningskjede, injeksjon og feilhåndtering

5417d agoDiscuss
nahid-sparktalesSkill

agent-security

nahid-sparktales/agent-dispatcher/skills/security/agent-security/SKILL.md

Secure an agent system as a permission surface — what authority each tool call runs under, where the confused deputy sits, which controls are enforced outside the model and which are only prompt text, and how far one bad call reaches. Use when granting an agent tools or credentials, wiring in MCP servers or subagents, reviewing an agent that acted beyond what the requester could have done, or before letting an agent touch a shared or production system. Not for wording the ingestion trust boundary in detail (prompt-injection-defense), not for scoping what an agent is for (agent-design), and it never grants an agent permission it did not already have.

5210d agoDiscuss
krishnakanthb13Skill

security_audit

krishnakanthb13/antigravity_global_skills/security_audit/SKILL.md

Scans the codebase for OWASP Top 10 vulnerabilities (Secrets, Injection, Auth) and manages SECURITY.md.

503mo agoReads credentialsDiscuss
danielvm-gitSkill

security-review

danielvm-git/bigpowers/skills/security-review/SKILL.md

AI-powered security analysis of code changes — traces data flow, detects injection, auth bypass, secrets exposure, and unsafe deserialization across files. Use when reviewing pending changes, before release-branch, during verify-work Phase 5, during build-epic Step 0 threat modeling, or when the user says "security review" or "scan for vulns".

24030d agoDiscuss
cloudsmith-labsSkill

csm-security

cloudsmith-labs/claude-code-skills/skills/csm-security/SKILL.md

Investigate security posture in Cloudsmith — vulnerabilities, quarantine, and audit logs. Use when the user wants to scan an org, repository, or package for CVEs/vulnerabilities, investigate a specific CVE, review or manage quarantined packages, see who changed or deleted something (audit log), review security events, or get a security summary before a release or promotion.

13mo agoDiscuss
HarambeeAISkill

security-scan

HarambeeAI/bayes-ship/skills/security-scan/SKILL.md

Security scanning against OWASP Top 10, secret detection, input validation, auth hardening. Used by the security reviewer during QA phase. Source: everything-claude-code.

16mo agoDiscuss
johnclawsonSkill

security-qbr

johnclawson/claude-skills/security-qbr/SKILL.md

Generate Quarterly Business Review (QBR) presentations for Information Security teams. Use this skill when creating QBR decks, quarterly security reviews, or executive briefings about security posture for CIO/CTO audiences. Covers content structure (risks, accomplishments, current work, KPIs), writing style, and slide organization. Triggers on requests for security QBRs, quarterly InfoSec reviews, CISO presentations, or security executive briefings.

17mo agoDiscuss
junimnjwSkill

security-scan

junimnjw/everything-claude-code/skills/security-scan/SKILL.md

Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions.

17mo agoReads credentialsDiscuss
maridlabsaiSkill

security-scan

maridlabsai/jini/.claude/skills/security-scan/skill.md

Security Scan Use this skill for public Jini security review. ## Procedure 1. Scan changed files for secrets, credentials, private URLs, customer details, pricing strategy, and commercial rollout material

14mo agoDiscuss
morodomiSkill

security-scan

morodomi/dev-crew/skills/security-scan/SKILL.md

セキュリティスキャンを実行。RECON→SCAN→REPORT→LEARNワークフローで脆弱性を検出。「セキュリティスキャン」「security scan」「脆弱性チェック」「セキュリティ診断」「OWASPチェック」で起動。Do NOT use for レポートのみ(→ attack-report)やスキャン+レポート一括(→ security-audit)。

115d agoDiscuss
NemesLaszloSkill

security-scan

NemesLaszlo/Agent-Collection/.claude/skills/security-scan/SKILL.md

Security vulnerability scan using the Security Vulnerability Scanner agent workflow. Use when the user says security scan, check for vulnerabilities, security audit, is this secure, OWASP check, or before deploying to production.

16mo agoDiscuss
ngc-shjSkill

security-scan

ngc-shj/claude-code-config/skills/security-scan/SKILL.md

Audit Claude Code configuration for security issues: hardcoded secrets, overly permissive allow lists, hook injection risks, MCP supply chain, auto-run instructions. Use this skill when: setting up a new project; after modifying settings.json / CLAUDE.md / .mcp.json / hooks; before committing config changes; onboarding to a repo with existing Claude Code config.

131d agoReads credentialsDiscuss
novatsinghSkill

security-scan

novatsingh/agentkick/.claude/skills/security-scan/SKILL.md

security scan workflow for disciplined AI coding agents.

15mo agoDiscuss
PMDevSolutionsSkill

api-security

PMDevSolutions/Nerva/.claude/skills/api-security/SKILL.md

Implements API security hardening including input sanitization, injection prevention, rate limiting, CORS configuration, security headers, request size limits, and IP blocking. Audits for common vulnerabilities and provides Hono middleware for each security layer. Keywords: security, rate-limit, cors, headers, csp, hsts, xss, injection, sanitize, csrf, brute-force, ip-block, request-limit, helmet, audit, vulnerability, owasp

14mo agoReads credentialsDiscuss
CLAUDE.md vs AGENTS.md

About skills

What is a Claude skill?

A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.

How do I use one I find here?

Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.

What do the warnings mean?

We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.

Which skills worked for people?

Open a skill to see its discussion. Reports from people and their agents are coming.