agentleFS
Sign inSign up

Claude skills and agent skills

Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.

Best matches · from page 15Worked for most · soon
EndikaSkill

security-bar

Endika/eskills/skills/security-bar/SKILL.md

Use when reviewing changes for security to apply my checklist on top of security-review — input handling, secrets, authz, Supabase RLS, egress limits, server-side PIN enforcement, and the agent-harness surface (config secrets, hook injection, MCP risk, over-broad permissions).

014d agoDiscuss
eugenezhangco-specSkill

security-scan

eugenezhangco-spec/athena/.claude/skills/security-scan/SKILL.md

Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions.

05mo agoReads credentialsDiscuss
hereshecodesSkill

api-security

hereshecodes/secureskills/skills/api-security/SKILL.md

Use when building REST APIs, GraphQL endpoints, or webhooks

07mo agoDiscuss
Jawahars07Skill

security-vet

Jawahars07/ballast/skills/security-vet/SKILL.md

Mandatory pre-install security vetting of any third-party skill, plugin, npm or pip package, editor extension, or cloned repo - reconnaissance, static scan, written verdict of SAFE / SAFE WITH CAVEATS / HOLD, explicit user approval, then a defensive install proportionate to the risk. Use BEFORE installing anything you did not write.

020d agoReads credentialsDiscuss
leaf76Skill

security-scan

leaf76/agent-skills/security-scan/SKILL.md

Comprehensive security scanning and vulnerability assessment for code, dependencies, and infrastructure. Includes SAST, DAST, dependency scanning, and security hardening recommendations. Use before deployments, after major changes, or for regular security audits.

045d agoDiscuss
lgzarturoSkill

security-grc

lgzarturo/codeconductor/.agents/skills/security-grc/SKILL.md

Map controls to SOC2, ISO 27001, PCI, or internal policy for the org you work for. Evidence and control design — not audit theater.

015d agoDiscuss
lgzarturoSkill

security-web

lgzarturo/codeconductor/.agents/skills/security-web/SKILL.md

Review and harden web apps (authz, XSS, CSRF, SSRF, injection) on code you maintain. Complements the OWASP `security` skill. No exploit kits.

015d agoDiscuss
pankaj-mahaurSkill

security-scan

pankaj-mahaur/Agent-Daemon/skills/security-scan/SKILL.md

Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions.

05mo agoReads credentialsDiscuss
prasadmogulothuSkill

rls-security

prasadmogulothu/agent-skills/rls-security/SKILL.md

Generate row-level-security policies plus a cross-user isolation test, so users can only access their own rows. Written for Postgres/Supabase; adaptable to other databases. Use for any per-user or multi-tenant data.

03mo agoDiscuss
TheurgicDuke771Skill

security-scan

TheurgicDuke771/DataQ/.claude/skills/security-scan/SKILL.md

Run the end-of-week security scan (CONTRIBUTING rule 36) — Dependabot + secret-scanning alerts, local pip-audit/pnpm-audit mirror of the CI gates, betterleaks sweep, OWASP spot check on endpoints added this week, Key Vault access audit, and the credential-rotation register. Use weekly, before a deploy, or when the user asks "run the security scan" / "any open vulns?".

03d agoDiscuss
UfukCetinkaya57Skill

security-scan

UfukCetinkaya57/backend-governance/.claude/skills/security-scan/SKILL.md

Sistematik guvenlik tarama proseduru - otomatik pattern arama ve risk tespiti

03mo agoDiscuss
vivy-yiSkill

account-security

vivy-yi/xiaohongshu-skills/skills/05-平台规则/account-security/SKILL.md

Use when protecting Xiaohongshu account from unauthorized access, preventing account theft, recovering compromised accounts, or implementing security measures to safeguard account and follower base

4558mo agoDiscuss
fdiblenSkill

rseng-security

fdiblen/rseng-agent-skills/skills/rseng-security/SKILL.md

Covers securing research software and its supply chain: secrets and sensitive-file hygiene (env files, keys, credentials and the never-commit file catalog) with leak response, dependency vulnerability scanning and pinning, OpenSSF Scorecard and Best Practices badge, SLSA provenance levels, SBOMs, signed releases and repository hardening. Use PROACTIVELY when setting up CI or releases, when an API key, password, credential or token is committed or appears in code or history, when the user asks how secure their project or dependencies are, or mentions Scorecard, SLSA, SBOM, CVEs or secret scanning. For the agent itself see rseng-agent-security; for GDPR and personal-data obligations see rseng-regulatory-compliance; for sensitive-data storage practice see rseng-data-management.

202mo agoReads credentialsDiscuss
Gabson0xSkill

security-arsenal

Gabson0x/bountyforge/skills/security-arsenal/SKILL.md

Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, conditionally-valid-with-chain table, temp email creation scripts, XXE/deserialization/host header injection payloads. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass, bypass techniques, temp email setup for multi-account testing, or to check if a finding is submittable. Also use when asked about what NOT to submit.

43114d agoReads credentialsDiscuss
NVIDIASkill

fix-security-issue

NVIDIA/OpenShell/.agents/skills/fix-security-issue/SKILL.md

Implement a fix for a reviewed security issue. Takes a directly requested issue number or scans for issues labeled `topic:security` and `agent:implementation-requested`. Reads the security review from the issue comments and implements the remediation plan. Trigger keywords - fix security issue, remediate security, implement security fix, patch vulnerability.

8.8k6d agoDiscuss
Hassaan146Skill

cloud-security

Hassaan146/claude-skills/cloud-security/SKILL.md

Use when assessing cloud infrastructure for security misconfigurations, IAM privilege escalation paths, S3 public exposure, open security group rules, or IaC security gaps. Covers AWS, Azure, and GCP posture assessment with MITRE ATT&CK mapping.

182mo agoDiscuss
hoangsonwwSkill

security-review

hoangsonww/AI-Agents-Orchestrator/.agents/skills/security-review/SKILL.md

Review code changes for security vulnerabilities, authentication gaps, injection risks, and unsafe patterns. Use before merging PRs or after security-sensitive changes.

836mo agoDiscuss
EyadkellehSkill

security-fuzzing

Eyadkelleh/awesome-skills-security/skills/security-fuzzing/SKILL.md

Essential fuzzing payloads: SQL injection, command injection, special characters. Curated essentials for vulnerability testing.

3844mo agoDiscuss
awarexoneSkill

cloud-security

awarexone/AXguard/cloud-security/SKILL.md

Review cloud and CORS misconfiguration in app code and IaC-adjacent configs — metadata URLs, public buckets, wildcard origins (CWE-918 / CWE-942 / A05:2021 / A10:2021).

1716d agoDiscuss
awarexoneSkill

oauth-security

awarexone/AXguard/oauth-security/SKILL.md

Analyze OAuth/OIDC integration security — use when reviewing redirect URIs, state/nonce, token handling, PKCE, or confused-deputy risks in authorization code flows (CWE-601 / A07:2021 / API2:2023).

1716d agoDiscuss
CLAUDE.md vs AGENTS.md

About skills

What is a Claude skill?

A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.

How do I use one I find here?

Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.

What do the warnings mean?

We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.

Which skills worked for people?

Open a skill to see its discussion. Reports from people and their agents are coming.