iac-security
jaskaranhundal/usap-skills/.agents/skills/iac-security/SKILL.md
../../../cloud-infra/iac-security/SKILL.md
Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.
jaskaranhundal/usap-skills/.agents/skills/iac-security/SKILL.md
../../../cloud-infra/iac-security/SKILL.md
ldilov/harness-forge/.agents/skills/security-scan/SKILL.md
Auto-discoverable wrapper for `.hforge/library/skills/security-scan/SKILL.md`.
MBrekhof/xafskills/skills/xaf-security/SKILL.md
Configure DevExpress XAF security: roles, permissions, users, and background job authentication. Use when setting up role permissions in Updater.cs, implementing object-level security, exporting/importing roles, creating background job security contexts, or troubleshooting permission issues. Covers type-level vs object-level permissions, CurrentUserIdOperator, PermissionsReloadMode, and the role update caveat.
Wishmakingfairy/vibecheck/skills/security-scan/SKILL.md
This skill should be used when the user asks to \"run a security scan\", \"check for vulnerabilities\", \"security audit\", \"ship secure\", \"vibecheck scan\", or \"pre-deploy security check\". Runs 156 automated security checks across 15 categories and produces a categorized vulnerability report.
ktnyt/cclsp/.claude/skills/security-review/SKILL.md
Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling. Use when the Reviewer identifies security-sensitive changes in the MCP-LSP bridge.
jellydn/my-ai-tools/skills/security-audit/SKILL.md
Use when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.
arsudsandesh97/Revoact/skills/security-doc/SKILL.md
Generate a complete SECURITY.md file for any software project. Use whenever the user asks to create, write, generate, or draft a SECURITY.md — a comprehensive security documentation covering threat models, security controls, authentication, authorization, data protection, compliance requirements, and security best practices.
Joshua-Palamuttam/workbench-template/.agents/skills/security-scan/SKILL.md
Security audit with Security Engineer posture — OWASP Top 10, secrets detection, dependency risks
Kur1sulab/blackbox/pt-api-security/SKILL.md
API security testing - GraphQL, REST API, WebSocket, and Web-LLM attack techniques.
LeahyCC/claude-skills/skills/api-security/SKILL.md
OWASP API Security Top 10 (2023) with production Next.js App Router code — access control, authentication, input validation, rate limiting, security headers, data exposure, supply chain, SSRF
neronain/ClaudeSkills-Neronain/skills/engineering/security-scan/SKILL.md
Run full security scans on the codebase using Ruflo security tools
TheBeardedBearSAS/claude-craft/.claude/skills/security-react/SKILL.md
Sécurité React. Use when reviewing security, implementing auth, or hardening code.
hardw00t/ai-security-arsenal/skills/cloud-security/SKILL.md
Multi-cloud security assessment skill for AWS, Azure, and GCP. Use when performing cloud security audits, scanning for misconfigurations, testing IAM policies, auditing storage permissions, and identifying privilege escalation paths. Triggers on requests to audit cloud security, scan AWS/Azure/GCP, check cloud misconfigurations, or perform cloud penetration testing. Covers CIS benchmarks, CSPM, and cross-cloud identity federation.
Hassaan146/claude-skills/senior-security/SKILL.md
Use when the user asks for STRIDE threat modeling, DREAD risk scoring, data-flow-diagram threat analysis, or a quick secret scan — or when a security request needs routing to the right specialist skill (pen-testing, incident response, cloud posture, red team, AI security, threat hunting, secure code review). This skill owns threat modeling; everything else routes to a sibling.
striderZA/OpenCodeGameStudios/.agents/skills/security-audit/SKILL.md
Audit the game for security vulnerabilities: save tampering, cheat vectors, network exploits, data exposure, and input validation gaps. Produces a prioritised security report with remediation guidance. Run before any public release or multiplayer launch.
appsec-foundry/appsec-advisor/skills/security-score/SKILL.md
Deterministic quick Security Score (0-100) for a repository, computed from the scanner layer alone — no agents, no LLM, no threat model, nothing written into the target repository. Reports the score together with how many rules applied, the finding tally, and the weakest control domains. Use for a fast indication or a per-commit trend; it is not a risk rating and does not replace /appsec-advisor:create-threat-model.
kanfu-panda/pdlc-skills/skills/pdlc-security/SKILL.md
安全审计
modelcontextprotocol/inspector/.claude/skills/security-advisory/SKILL.md
Take a privately reported vulnerability through this repo's security advisory flow — board it, verify who owns the code path, accept or reject, fix it in the private fork, ship to every affected release line, publish, then turn the card into public tracking. Use when a vulnerability is reported privately; when deciding whether an advisory is ours to fix; when looking up or creating its private fork; when answering a reporter; or when a GHSA-titled board card needs handling.
openai/codex-security/plugins/codex-security/skills/deep-security-scan/SKILL.md
Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated complete independent Standard scans with the Codex Security deep-scan tool, which aggregates their validated findings and prepares the canonical artifacts; then complete the same scan once. Do not use for PRs, commits, branch diffs, or working-tree diffs.
openai/codex-security/plugins/codex-security/skills/security-diff-scan/SKILL.md
Review a pull request, commit, branch diff, or working-tree patch for security vulnerabilities.
A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.
Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.
We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.
Open a skill to see its discussion. Reports from people and their agents are coming.