agentleFS
Sign inSign up

Claude skills and agent skills

Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.

Best matches · from page 11Worked for most · soon
SentrySkill

security-review

getsentry/warden/packages/warden/src/builtin-skills/security-review/SKILL.md

Finds exploitable application security vulnerabilities in code changes. Use for Warden security scans, appsec review, OWASP-style checks, authentication or authorization bugs, injection, XSS, SSRF, path traversal, secrets, unsafe crypto, webhook verification, open redirects, or sensitive data exposure.

4098mo agoDiscuss
1398281322-a11ySkill

api-security

1398281322-a11y/java-backend-guardrails/skills/java-backend-guardrails/api-security/SKILL.md

Use when hardening APIs: HTTPS, HMAC 签名, timestamp+nonce 防重放, CORS, 脱敏, JWT none 算法, 密钥不进 URL. For SQL injection and resource 越权 WHERE, use backend-safe-check.

230d agoDiscuss
alex-voloshin-devSkill

security-scan

alex-voloshin-dev/ai-skills/.agents/skills/security-scan/SKILL.md

Security scan workflow — dependency audit, OWASP checklist, secrets scan, vulnerability report. Applies software-engineer role with security focus. Use standalone or as part of code review.

25mo agoDiscuss
DonTiziSkill

security-scan

DonTizi/CodeGeass/.claude/skills/security-scan/SKILL.md

Deep security analysis of codebase. Scans for secrets, vulnerabilities, and insecure patterns.

28mo agoReads credentialsDiscuss
ffsshhttiikkSkill

app-security

ffsshhttiikk/opencode-agents-skills/app-security/SKILL.md

Expert-level knowledge and advanced techniques for App Security

27mo agoDiscuss
INERATESkill

security-law

INERATE/atelier/skills/security-law/SKILL.md

The Atelier Security Law — OWASP-grade defense for every request path (injection, XSS, CSRF, tenant isolation, rate limiting, transport). Load before writing ANY endpoint, form, or data-processing code — not just auth. Auth token/session mechanics live in [[auth-law]]; this is everything else.

29d agoDiscuss
JustineDevsSkill

llm-security

JustineDevs/premortem/.cursor/skills/llm-security/SKILL.md

LLM and AI agent security testing for prompt injection, RAG poisoning, MCP injection, and guardrail evaluation. Authorization required.

24mo agoDiscuss
ronjunevaldozSkill

kmp-security

ronjunevaldoz/kmp-agent-skills/skills/kmp-security/SKILL.md

Mobile app security for Kotlin Multiplatform beyond Android-only R8 obfuscation — certificate/SSL pinning (expect/actual, no cross-platform Ktor support exists natively), root/jailbreak/tamper detection via freeRASP's real KMP variant, encrypted local storage via KSafe, iOS/ Kotlin-Native release-binary symbol stripping, and an OWASP Mobile Top 10 2024 coverage map across this collection. Does NOT cover Android-specific R8/ProGuard obfuscation — that's kmp-proguard-r8's own scope, cross- referenced here rather than duplicated. Does NOT cover secrets-in-source scanning (gitleaks pre-commit) — that's kmp-setup-hooks Option F.

22mo agoDiscuss
ronmkrSkill

security-scan

ronmkr/PromptBook/skills/technical/security-scan/SKILL.md

Scan your The Agent Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions.

24mo agoReads credentialsDiscuss
Rootx202Skill

api-security

Rootx202/appsec-skills/api-security/SKILL.md

Focused API security auditor for REST, GraphQL, and webhook endpoints in any stack. Use when the user is building or reviewing an API layer, mentions rate limiting, API keys, webhooks, CORS, or specifically wants "API security" checked — as opposed to a full-project audit.

23mo agoDiscuss
seikaikyoSkill

security-scan

seikaikyo/dash-skills/skills/security-scan/SKILL.md

用外部掃描工具對 repo 做相依漏洞、機密外洩、SAST 三層檢查,並把結果對回 OWASP Top 10:2025 分類。適用:面試或對外發布前的作品體檢、接手不熟的 repo、想確認自己的修正經得起獨立工具驗證。不適用:判斷認證邏輯對不對、權限有沒有寫錯這類要讀懂程式意圖的問題,那要人或 agent 讀碼。

29mo agoDiscuss
TorpedoDSkill

security-scan

TorpedoD/claude-sentinel/skills/security-scan/SKILL.md

12-tool security audit — SAST, secrets, SBOM, SCA, AI-skill safety, and hidden-instruction detection via a single slash command

25mo agoReads credentialsDiscuss
tranhieuttSkill

security-audit

tranhieutt/software_development_department/.claude/skills/security-audit/SKILL.md

name: security-audit type: workflow description: "Conducts a comprehensive security audit covering web application vulnerabilities, API security, OWASP Top 10, and security hardening recommendations. Use when auditing a codebase

715mo agoReads credentialsDiscuss
axisroboSkill

arch-security

axisrobo/ea-harness/.agents/skills/arch-security/SKILL.md

Deep-dive security audit of a technical architecture diagram. Focused exclusively on authentication, authorization, credential protection, network boundaries, and data classification. Does NOT score overall quality — produces a prioritized security finding list. Use after arch-validate when you want a security specialist's deep cut.

136d agoDiscuss
mizchiSkill

security-expert

mizchi/skills/security-expert/SKILL.md

Security specialist perspective for the weekly review. Focuses on XSS/CSRF, authorization boundaries, input validation, secrets handling, and dependency CVEs.

3483mo agoReads credentialsDiscuss
wgpsecSkill

ai-data-security

wgpsec/AboutSecurity/skills/ai-security/ai-data-security/SKILL.md

AI 系统数据安全测试方法论。当需要评估 LLM/AI 系统的数据泄露风险、训练数据安全、 或 RAG/向量库数据完整性时触发。覆盖: System Prompt 泄露(元 Prompt/角色扮演/关键字定位)、 训练数据推导与提取、成员推断攻击、模型反演攻击、RAG 数据投毒、API 信息泄露、 级联幻觉攻击、外部数据源信息泄露。

1.8k4mo agoDiscuss
kousenSkill

security-review

kousen/claude-code-training/skills/security-review/SKILL.md

Read-only security audit of code for SQL injection, XSS, auth/authz flaws, input validation gaps, sensitive data exposure, and insecure cryptography. Surfaces findings without modifying code.

34510mo agoDiscuss
ww-w-aiSkill

bkend-security

ww-w-ai/bkit-gemini/skills/bkend-security/SKILL.md

bkend.ai security policies and encryption expert skill. Covers API key management (Public vs Secret), Row Level Security (RLS) with 4 roles (admin/user/guest/self), data encryption (Argon2id, AES-256-GCM, TLS 1.2+), and security best practices.

666mo agoReads credentialsDiscuss
shawnpangSkill

security-review

shawnpang/startup-founder-skills/skills/security-review/SKILL.md

When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model", "security audit", "pen test prep".

3317mo agoDiscuss
GitHubSkill

mcp-security-audit

github/awesome-copilot/skills/mcp-security-audit/SKILL.md

Audit MCP (Model Context Protocol) server configurations for security issues. Use this skill when: - Reviewing .mcp.json files for security risks - Checking MCP server args for hardcoded secrets or shell injection patterns - Validating that MCP servers use pinned versions (not @latest) - Detecting unpinned dependencies in MCP server configurations - Auditing which MCP servers a project registers and whether they're on an approved list - Checking for environment variable usage vs. hardcoded credentials in MCP configs - Any request like "is my MCP config secure?", "audit my MCP servers", or "check .mcp.json" keywords: [mcp, security, audit, secrets, shell-injection, supply-chain, governance]

39k8d agoReads credentialsDiscuss
CLAUDE.md vs AGENTS.md

About skills

What is a Claude skill?

A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.

How do I use one I find here?

Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.

What do the warnings mean?

We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.

Which skills worked for people?

Open a skill to see its discussion. Reports from people and their agents are coming.