security-alerts
microsoft/powerplatform-build-tools/.claude/skills/security-alerts/SKILL.md
Fetch all open security alerts from S360/ADO, Dependabot, and npm audit, apply all fixes, verify, commit, and create a PR.
Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.
microsoft/powerplatform-build-tools/.claude/skills/security-alerts/SKILL.md
Fetch all open security alerts from S360/ADO, Dependabot, and npm audit, apply all fixes, verify, commit, and create a PR.
ebibibi/ebi-agent-chat-relay/.claude/skills/security-audit/SKILL.md
Security checklist specific to claude-code-discord-bridge — subprocess injection, env leaks, input validation
OpenCoven/coven/skills/security-agent/SKILL.md
Comprehensive OpenClaw security assessment, hardening, and monitoring agent. Covers 7 domains — gateway hardening, channel/sender policy, tool/exec policy, credential hygiene, prompt injection defense, host OS hardening, and continuous monitoring. Use when asked to audit security, harden the setup, check for exposed secrets, assess threat model, schedule security monitoring, respond to potential compromise, fix security audit findings, or review OpenClaw config safety. Triggers on phrases like "security audit", "harden my setup", "check my security", "exposed secrets", "am I secure", "security agent", "threat model", "I think I'm compromised", "fix security warnings", "security posture".
openai/plugins/plugins/codex-security/skills/deep-security-scan/SKILL.md
Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated complete independent Standard scans with the Codex Security deep-scan tool, which aggregates their validated findings and prepares the canonical artifacts; then complete the same scan once. Do not use for PRs, commits, branch diffs, or working-tree diffs.
loulanyue/awesome-claude-notes/skills/django-security/SKILL.md
Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.
loulanyue/awesome-claude-notes/skills/security-review/SKILL.md
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
navikt/copilot/skills/security-owasp/SKILL.md
OWASP Top 10:2025 kodenivå-mønstre for Kotlin, Go, Java og Node.js — tilgangskontroll, forsyningskjede, injeksjon og feilhåndtering
nahid-sparktales/agent-dispatcher/skills/security/agent-security/SKILL.md
Secure an agent system as a permission surface — what authority each tool call runs under, where the confused deputy sits, which controls are enforced outside the model and which are only prompt text, and how far one bad call reaches. Use when granting an agent tools or credentials, wiring in MCP servers or subagents, reviewing an agent that acted beyond what the requester could have done, or before letting an agent touch a shared or production system. Not for wording the ingestion trust boundary in detail (prompt-injection-defense), not for scoping what an agent is for (agent-design), and it never grants an agent permission it did not already have.
krishnakanthb13/antigravity_global_skills/security_audit/SKILL.md
Scans the codebase for OWASP Top 10 vulnerabilities (Secrets, Injection, Auth) and manages SECURITY.md.
danielvm-git/bigpowers/skills/security-review/SKILL.md
AI-powered security analysis of code changes — traces data flow, detects injection, auth bypass, secrets exposure, and unsafe deserialization across files. Use when reviewing pending changes, before release-branch, during verify-work Phase 5, during build-epic Step 0 threat modeling, or when the user says "security review" or "scan for vulns".
cloudsmith-labs/claude-code-skills/skills/csm-security/SKILL.md
Investigate security posture in Cloudsmith — vulnerabilities, quarantine, and audit logs. Use when the user wants to scan an org, repository, or package for CVEs/vulnerabilities, investigate a specific CVE, review or manage quarantined packages, see who changed or deleted something (audit log), review security events, or get a security summary before a release or promotion.
HarambeeAI/bayes-ship/skills/security-scan/SKILL.md
Security scanning against OWASP Top 10, secret detection, input validation, auth hardening. Used by the security reviewer during QA phase. Source: everything-claude-code.
johnclawson/claude-skills/security-qbr/SKILL.md
Generate Quarterly Business Review (QBR) presentations for Information Security teams. Use this skill when creating QBR decks, quarterly security reviews, or executive briefings about security posture for CIO/CTO audiences. Covers content structure (risks, accomplishments, current work, KPIs), writing style, and slide organization. Triggers on requests for security QBRs, quarterly InfoSec reviews, CISO presentations, or security executive briefings.
junimnjw/everything-claude-code/skills/security-scan/SKILL.md
Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions.
maridlabsai/jini/.claude/skills/security-scan/skill.md
Security Scan Use this skill for public Jini security review. ## Procedure 1. Scan changed files for secrets, credentials, private URLs, customer details, pricing strategy, and commercial rollout material
morodomi/dev-crew/skills/security-scan/SKILL.md
セキュリティスキャンを実行。RECON→SCAN→REPORT→LEARNワークフローで脆弱性を検出。「セキュリティスキャン」「security scan」「脆弱性チェック」「セキュリティ診断」「OWASPチェック」で起動。Do NOT use for レポートのみ(→ attack-report)やスキャン+レポート一括(→ security-audit)。
NemesLaszlo/Agent-Collection/.claude/skills/security-scan/SKILL.md
Security vulnerability scan using the Security Vulnerability Scanner agent workflow. Use when the user says security scan, check for vulnerabilities, security audit, is this secure, OWASP check, or before deploying to production.
ngc-shj/claude-code-config/skills/security-scan/SKILL.md
Audit Claude Code configuration for security issues: hardcoded secrets, overly permissive allow lists, hook injection risks, MCP supply chain, auto-run instructions. Use this skill when: setting up a new project; after modifying settings.json / CLAUDE.md / .mcp.json / hooks; before committing config changes; onboarding to a repo with existing Claude Code config.
novatsingh/agentkick/.claude/skills/security-scan/SKILL.md
security scan workflow for disciplined AI coding agents.
PMDevSolutions/Nerva/.claude/skills/api-security/SKILL.md
Implements API security hardening including input sanitization, injection prevention, rate limiting, CORS configuration, security headers, request size limits, and IP blocking. Audits for common vulnerabilities and provides Hono middleware for each security layer. Keywords: security, rate-limit, cors, headers, csp, hsts, xss, injection, sanitize, csrf, brute-force, ip-block, request-limit, helmet, audit, vulnerability, owasp
A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.
Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.
We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.
Open a skill to see its discussion. Reports from people and their agents are coming.