security-check
igmarin/rails-agent-skills/skills/security-check/SKILL.md
Use when auditing a Rails app for XSS, CSRF, SQLi, IDOR, secrets, or auth bypass. Never print secrets. Trigger words: security, audit, XSS, CSRF, SQL injection, vulnerability.
Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.
igmarin/rails-agent-skills/skills/security-check/SKILL.md
Use when auditing a Rails app for XSS, CSRF, SQLi, IDOR, secrets, or auth bypass. Never print secrets. Trigger words: security, audit, XSS, CSRF, SQL injection, vulnerability.
0xlayerghost/solidity-agent-kit/skills/defi-security/SKILL.md
[AUTO-INVOKE] MUST be invoked BEFORE deploying DeFi contracts (DEX, lending, staking, LP, token). Covers anti-whale, anti-MEV, flash loan protection, launch checklists, and emergency response. Trigger: any deployment or security review of DeFi-related contracts.
carreiras/claude-skills/security-lgpd/SKILL.md
Guia completo de conformidade com a LGPD (Lei Geral de Proteção de Dados — Lei 13.709/2018) para desenvolvimento de software e operações de TI no Brasil. Use esta skill sempre que o usuário mencionar LGPD, proteção de dados pessoais, dados sensíveis, consentimento, base legal, titular de dados, ANPD, DPO (Encarregado), ROPA (Registro de Atividades de Tratamento), DPIA (Relatório de Impacto), DSR (requisição de titular), incidente de dados, vazamento de dados, anonimização, pseudonimização, retenção de dados, transferência internacional, privacy by design, privacy by default, ou quando o usuário perguntar "isso está em conformidade com a LGPD?", "preciso de consentimento para isso?", "como implementar LGPD no sistema?", "quais dados posso coletar?", "como responder uma solicitação de titular?", ou qualquer variação relacionada à privacidade de dados pessoais de usuários brasileiros ou de sistemas operando no Brasil.
gonimar/claude-web-studio/skills/team-security/SKILL.md
Full security cycle: threat-model refresh → security-audit (code) → dependency-audit → harden (perimeter/containers) → optional pentest of the project's own app → consolidated report and stories. Use before release or after adding auth/payments/uploads/multiplayer.
Shehabov/ai-dev-crew/.claude/skills/team-security/SKILL.md
The security catalogue and sweep security-analyst runs to hold the security gate, on every change, build and commit, and before any release. Seven passes in a fixed order, stopping on a critical in the first two: secrets and keys in the tree and in history; exposure of data stores, storage, endpoints, environment variables and CORS; authentication and access control, including client-side checks and IDOR; injection of every kind and dangerous functions such as eval; dependencies, including packages that do not exist and known CVEs; data handling, covering client storage, data in URLs and logs, security headers, CSRF and rate limiting; failure handling, errors and logging. Covers the threat model from PROJECT.md, the commands and evidence for each pass, severities and what blocks, the finding format, and written acceptance of critical and high findings by the Product Lead. Use when sweeping a change, rating a finding, or deciding whether the security gate can pass.
zloether/okta-skills/skills/okta-security/SKILL.md
Read Okta ThreatInsight configuration, security events providers (Shared Signals Framework / SSF receivers), SSF stream status, and bot protection settings. Use when asked about suspicious IP handling, whether ThreatInsight blocks or audits requests, SSF/CAEP integrations for cross-app session signal sharing, or bot detection enforcement.
cohen-liel/hivemind/.claude/skills/security-review/SKILL.md
Security review checklist for web applications. Use when reviewing code for security vulnerabilities, auth issues, input validation, or any security-sensitive code.
ethosagent/ethos/.agents/skills/security-audit/SKILL.md
Subsystem-scoped security audit of the Ethos codebase. Use when asked to "audit the gateway", "review the trust boundaries of X", "security review of subsystem Y", "check personality isolation", "audit the skill loader", "audit the channel adapter", or any focused security-posture question against a named subsystem. NOT for per-PR diff review (that's a different motion). NOT for "audit Ethos" without a subsystem named — split the audit before starting. Produces an evidence-led report at plan/audits <subsystem>-audit-YYYY-MM-DD.{html,md}. Read-only — never edits the codebase during the audit. Does not commit; the user decides what to do with findings.
TheBeardedBearSAS/claude-craft/.claude/skills/security-symfony/SKILL.md
Sécurité & RGPD - Atoll Tourisme. Use when reviewing security, implementing auth, or hardening code.
jim60105/copilot-prompt/skills/security-audit/SKILL.md
Security audit of a codebase — web apps, APIs, services, CLI tools, libraries, daemons, and more. Use when asked to find security bugs, do a security review, audit for vulnerabilities, or pen-test the code. Focuses on exploitable issues with real impact, not theoretical concerns or industry-standard behavior.
adromero/claude-skills/skills/security-scan/SKILL.md
On-demand security audit — OWASP Top 10, dependency CVEs, secrets detection, and static analysis across the current project or specified files.
anatolykoptev/n8n-mcp-agent/skills/n8n-security/SKILL.md
Security checklist for n8n workflows. Use when creating webhooks, handling credentials, processing user input, or preparing workflows for production.
anton-karlovskiy/claude-code-demo/.claude/skills/web-security/SKILL.md
Enforce web security and avoid security vulnerabilities
beelabstudio/ai/skills/security/security-scan/SKILL.md
Scan a Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions. Use when auditing a .claude/ directory — CLAUDE.md, settings.json, MCP servers, hooks, or agent definitions — before committing config changes or onboarding to a repo with existing agent configs.
Biznomad/claude-skills/security-scan/SKILL.md
Deep security audit for GitHub repos, skills, and MCP servers before installation. Scans for malware, prompt injection, supply chain attacks, credential harvesting, and suspicious code patterns. Use when cloning repos, installing skills, adding MCP servers, or when the PostToolUse hook triggers a SECURITY SCAN REQUIRED alert.
blamejs/exceptd-skills/skills/api-security/skill.md
API security for mid-2026 — OWASP API Top 10 2023, AI-API specific (rate limits, prompt-shape egress, MCP HTTP transport), GraphQL + gRPC + REST + WebSocket attack surfaces, API gateway posture, BOLA/BFLA/SSRF/Mass Assignment
conjure-3301/skills/api-security/SKILL.md
Test APIs against the OWASP API Security Top 10 (2023) — BOLA, broken authentication, broken object property level authorization, unrestricted resource consumption, BFLA, sensitive business flow abuse, SSRF, security misconfiguration, improper inventory, unsafe consumption of upstream APIs
dajneem23/my-evm-security-skills/SKILL.md
Security assessment and hardening workflow for EVM smart contracts. Use when Codex needs to audit Solidity or Vyper code, review protocol architecture for abuse paths, validate access control and value-accounting invariants, assess upgradeable/proxy deployments, evaluate oracle/bridge/DEX integration risk, or produce prioritized remediation guidance with reproducible proof-of-concept tests.
danwykesdev/skills/security/SKILL.md
Create or review threat models, data classification, tenancy controls, upload security, API secret handling, and public route security.
dataGriff/skills/skills/api-security/SKILL.md
Review, harden, and design HTTP APIs against the OWASP API Security Top 10 (2023): object- and property-level authorization (BOLA/IDOR, mass assignment, over-exposure), authentication and JWT/OAuth2 token validation, unrestricted resource consumption and rate limiting, SSRF, misconfiguration (CORS, TLS, headers, error leakage), and endpoint inventory. Produces evidence-backed findings ranked by severity with concrete fixes. Use when the user asks for an API security review, audit, or threat model, asks "is my API secure" or to prepare for a pen test, mentions BOLA, IDOR, broken auth, mass assignment, rate limiting, or the OWASP API Top 10, wants security requirements for a new API design, or asks to fix an authentication or authorization bug in an API.
A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.
Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.
We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.
Open a skill to see its discussion. Reports from people and their agents are coming.