agentleFS
Sign inSign up

Claude skills and agent skills

Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.

Best matches · from page 13Worked for most · soon
pop123-uxSkill

api-security

pop123-ux/agent-security-skills/skills/api-security/SKILL.md

Security Best Practices Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities. ## Description USE WHEN: - Designing new API endpoints - Securing existing

14mo agoReads credentialsDiscuss
shivae372Skill

security-scan

shivae372/claude-bootstrap/.claude/skills/security-scan/SKILL.md

Security audit skill. Invoke before deploying, after adding auth code, or when reviewing for vulnerabilities. Auto-activates on "security check", "check for vulnerabilities", "pre-deploy audit", "scan for secrets", "is this auth secure". Routes to security-scanner sub-agent.

16mo agoDiscuss
SVerITGSkill

security-scan

SVerITG/Metis_PH/.agents/skills/security-scan/skill.md

Audit the current session for security and data-safety issues

137d agoReads credentialsDiscuss
yasserstudioSkill

gpc-security

yasserstudio/gpc-skills/gpc-security/SKILL.md

Use when dealing with GPC credential security, secret management, audit logging, or access control. Make sure to use this skill whenever the user mentions credentials, service account key, secret rotation, key rotation, credential storage, audit log, audit trail, security best practices, .gpcrc.json security, secrets in CI, GPC_SERVICE_ACCOUNT safety, keychain, token cache, credential leak, key compromise, secure deployment — even if they don't explicitly say 'security.' Also trigger when someone asks about where GPC stores credentials, how to rotate service account keys, how to audit who did what with GPC, how to securely pass credentials in CI/CD, or how to handle a compromised service account key. Also trigger on app signing key custody: app-signing enroll, app-signing rotate, Play App Signing, self-hosted Cloud KMS key, cryptoKeyVersion, signing certificate lineage, signing key rotation. For auth setup, see gpc-setup. For CI configuration, see gpc-ci-integration.

16mo agoDeletes or force-pushesDiscuss
ZeroTokenClawSkill

security-scan

ZeroTokenClaw/agents-skills/security-scan/SKILL.md

对进入系统的文件或 URL 执行安全与合规扫描,输出 pass/reject 判定与扫描报告,作为所有文档处理的强制前置关卡。

110d agoDiscuss
drvossSkill

security-audit

drvoss/everything-copilot-cli/skills/workflow/security-audit/SKILL.md

Use when a codebase needs a formal security audit beyond a quick scan — applies OWASP Top 10 and STRIDE threat modeling from a CSO perspective to surface systemic vulnerabilities.

4753d agoReads credentialsDiscuss
zhao-wuyanSkill

security-audit

zhao-wuyan/ccw-command-explorer/.claude/skills/security-audit/SKILL.md

OWASP Top 10 and STRIDE security auditing with supply chain analysis. Triggers on "security audit", "security scan", "cso".

455mo agoDiscuss
kklimukSkill

security-review

kklimuk/docx-cli/.claude/skills/security-review/SKILL.md

Review code for security vulnerabilities. Use when the user says 'security review', 'security audit', 'check for vulnerabilities', 'pentest the code', 'OWASP check', or any variation of wanting a security assessment.

2143mo agoDiscuss
netresearchSkill

security-audit

netresearch/security-audit-skill/skills/security-audit/SKILL.md

Use when conducting security assessments — OWASP Top 10 / API / LLM, CWE Top 25, CVSS scoring — auditing PHP/TYPO3, APIs, frontend, Terraform/K8s/Docker IaC, AWS cloud, AI agent configs, or scanning dependencies.

438d agoDiscuss
daemon-blockint-techSkill

code-security

daemon-blockint-tech/Agentic-Enteprises-Skill/code-security/SKILL.md

Guides secure coding and security-focused code review across languages and infrastructure—OWASP-oriented vulnerability patterns (injection, XSS, auth, crypto, deserialization, SSRF, XXE), secrets handling, and IaC security (Terraform, Kubernetes, Docker, GitHub Actions). Use when writing or reviewing code that handles user input, authentication, files, databases, network requests, cryptography, or infrastructure config—or when the user asks to check for SQL injection, XSS, SSRF, hardcoded secrets, OWASP issues, Terraform security, or GitHub Actions security. Not for authorized penetration test engagements (ai-redteam, cybersecurity), compliance program mapping (compliance-engineer), YARA/malware rules (yara-rule-authoring), or CI pipeline setup only (devsecops).

84mo agoDiscuss
cenconq25Skill

security-audit

cenconq25/claude-code-app-studio/.claude/skills/security-audit/SKILL.md

Audit the app for vulnerabilities: insecure storage, improper TLS, OWASP MASVS coverage, dependency CVEs, exposed secrets, unsafe deep links, JS-bridge exploits, WebView attack surface. Produces a prioritized remediation report. Run before any public release.

405mo agoReads credentialsDiscuss
echozen88Skill

odoo-security

echozen88/odoo-claude-code/skills/odoo-security/SKILL.md

Odoo 19 Security Guide This skill provides comprehensive guidance on implementing security in Odoo 19 applications. ## Security Architecture ### Odoo Security Layers 1. **Authentication** - User login and session management 2. **Authorization

78mo agoReads credentialsDiscuss
cyber-sortedSkill

cybersorted

cyber-sorted/skills-pro/cybersorted/SKILL.md

Security and enterprise architecture advisory skill. Use this skill when the user needs help with cybersecurity strategy, threat modeling, risk assessment, compliance, security architecture, enterprise architecture, or governance. Trigger when the user mentions: security posture, threat model, STRIDE, PASTA, risk assessment, risk register, compliance mapping, SOC2, ISO 27001, NIST 800-53, CIS benchmarks, MITRE ATT&CK, zero trust, incident response, IR plan, security policy, architecture decision record, ADR, vendor risk, third-party risk, board briefing, security maturity, maturity assessment, gap analysis, security review, code review for security, IaC review, Terraform security, Kubernetes security, CI/CD security, API security, cloud configuration review, tabletop exercise, red team, blue team, penetration test planning, security architecture, network segmentation, defense in depth, least privilege, data classification, encryption strategy, key management, identity and access management, IAM, SIEM, SOC, vulnerability management, patch management, business continuity, disaster recovery, BCP, DRP, privacy by design, GDPR, CCPA, data protection, platform security, build vs buy security, DevSecOps, shift left security, supply chain security, SBOM, secure coding, secure by design, OWASP Top 10, OWASP ASVS, OWASP SAMM, input validation, output encoding, SQL injection prevention, XSS prevention, CSRF prevention, secrets management, dependency security, SAST, DAST, SCA, secure API design, penetration test, pentest, pen test, red team, offensive security, vulnerability assessment, exploit, Kerberoasting, Active Directory attack, privilege escalation, lateral movement, CVSS, CSTM, Cyber Scheme, web application testing, network penetration test, cloud penetration test, container security testing, physical security assessment, or any security and architecture advisory request. Supports roles: CISO, CTO, CPO, Security Architect, Security Engineer, Enterprise Architect, Secure Developer, Penetration Tester.

37mo agoDiscuss
hyperlogueSkill

security-model

hyperlogue/r3/.claude/skills/security-model/SKILL.md

r3's Host/origin/auth guards, isolated artifact preview and closed network policy, local and remote daemon configuration, publisher-side harness credentials, byte/path guards, migration storage, and dependency cooldown. Use when changing authentication, artifact or preview routes, resource serving, exposure settings, remote transport, or reviewing security impact.

355d agoDiscuss
KhaledSaeed18Skill

security-audit

KhaledSaeed18/node-express-boilerplate/.agents/skills/security-audit/SKILL.md

Run a project-specific security audit of this Express API — auth, CSRF, rate limiting, headers, validation, secrets, and dependencies. Use when the user asks for a security review, audit, hardening pass, or before a release.

333mo agoReads credentialsDiscuss
romaraytSkill

security-review

romarayt/raytsystem-public-os/.agents/skills/security-review/SKILL.md

Audit raytsystem changes for prompt injection, provenance bypass, path/symlink/hardlink escape, secret leakage, stale fencing, partial promotion, unsafe parsing, and unapproved side effects. Use for SECURITY REVIEW, adversarial testing, recovery review, or approval-boundary validation; remain independent and read-only.

1403mo agoDiscuss
georgekhananaevSkill

owasp-security

georgekhananaev/claude-skills-vault/.claude/skills/owasp-security/SKILL.md

Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, and Agentic AI security (2026).

284mo agoDiscuss
wulaosijiSkill

security-drill

wulaosiji/skills/security-drill/SKILL.md

AI Agent自动化安全演练与攻击模拟测试工具,运行定时攻击场景(prompt注入、社会工程学、命令绕过、信息泄露、模型降级),验证事件响应和加固控制有效性,输出通过/失败报告。 Use when: "安全演练", "攻防测试", "攻击模拟", "security drill", "attack simulation", "渗透测试", "incident response test", "red team exercise". 在隔离环境中模拟攻击,不修改真实系统,结果本地存储,支持每周定时执行。Cross-references: security-hardening, skill-security-audit, secure-key-manager. Built by UniqueClub 🌐 https://uniqueclub.ai

2822d agoDiscuss
henryvn27Skill

orca-security

henryvn27/orca-framework/skills/orca-security/SKILL.md

Review security-relevant behavior, install scripts, CI, data handling, and unsafe agent instructions.

56d agoDiscuss
ractiveSkill

security-audit

ractive/hyalo/.claude/skills/security-audit/SKILL.md

REQUIRED skill for any security-related request. Use this skill whenever the user wants to find anything dangerous, sensitive, or risky in their code, files, or repository. This includes but is not limited to: scanning for secrets/keys/tokens/credentials, checking dependencies for vulnerabilities, auditing destructive commands for missing safeguards, reviewing files for PII or internal data before open-sourcing, checking .env files or git history for leaked credentials, or any request where the concern is "is this safe/secure/exposed?" This skill provides a structured audit methodology and checklist you MUST follow — do not attempt security reviews without it. Skip this skill ONLY for pure feature work, refactoring, bug fixes, or non-security code review.

2724d agoReads credentialsDiscuss
CLAUDE.md vs AGENTS.md

About skills

What is a Claude skill?

A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.

How do I use one I find here?

Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.

What do the warnings mean?

We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.

Which skills worked for people?

Open a skill to see its discussion. Reports from people and their agents are coming.