agentleFS
Sign inSign up

Claude skills and agent skills

Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.

Best matches · from page 16Worked for most · soon
awarexoneSkill

session-security

awarexone/AXguard/session-security/SKILL.md

Analyze session management security — use when reviewing cookie flags, session fixation, timeout, logout, concurrent sessions, or server-side session stores (A07:2021 / CWE-287 / CWE-352 adjacency).

1716d agoDiscuss
dawn840705Skill

security-audit

dawn840705/codex-code-studios/skills/security-audit/SKILL.md

Audit the game for security vulnerabilities: save tampering, cheat vectors, network exploits, data exposure, and input validation gaps. Produces a prioritised security report with remediation guidance. Run before any public release or multiplayer launch.

1734d agoDiscuss
jackson-video-resourcesSkill

security-audit

jackson-video-resources/skills/skills/security-audit/SKILL.md

Before you ship, run this. Catches the obvious: secrets in code, unsafe SQL, missing auth, OWASP top 10.

175mo agoReads credentialsDiscuss
BenkapnerSkill

security-check

Benkapner/claude-code-basecamp/skills/security-check/SKILL.md

Scan projects for credential leaks, secrets in code, insecure patterns, LLM API key exposure, PII leakage to external AI services, and .env/.gitignore misconfigurations. Especially useful for data and API integrations, regardless of implementation language.

1617d agoReads credentialsDiscuss
YehudaFrankelSkill

security-check

YehudaFrankel/clankbrain/.claude/skills/03-security/SKILL.md

Security audit — checks auth, SQL injection, exposed endpoints, and sensitive data. Triggers on "security check", "is this secure", "check for vulnerabilities", "check auth", "audit security", "security audit".

166mo agoDiscuss
9thLevelSoftwareSkill

security-review

9thLevelSoftware/legion/skills/security-review/SKILL.md

OWASP Top 10 and STRIDE threat modeling security review for code and architecture

765mo agoReads credentialsDiscuss
mit-networkSkill

security-review

mit-network/everything-claude-code/.agents/skills/security-review/SKILL.md

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

766mo agoReads credentialsDiscuss
PerryLinkSkill

security-audit

PerryLink/dsh-skill-pack-security/skills/security-audit/SKILL.md

仓库/软件安全审计总览:范围界定→资产清单→风险分级→逐项验证→报告模板的分阶段流程,按需转调 secret-scan、dependency-audit、supply-chain-review、prompt-injection-review 四个专项技能。用户要求整体审计仓库、规划审计步骤或汇总多类发现出报告时用;只查密钥/依赖等单一主题时直接加载对应专项技能,不用本总览。

1547d agoReads credentialsDiscuss
XPOZpublicSkill

security-osint

XPOZpublic/xpoz-agent-skills/skills/security-osint/SKILL.md

Monitor social platforms for security threats, vulnerability discussions, and breach intelligence using Xpoz. Use when asked to "find CVE discussions", "security threat monitoring", "OSINT social media", "vulnerability intelligence", "breach mentions", or "threat intel from Twitter/Reddit".

1522d agoReads credentialsDiscuss
edutrulSkill

drupal-security

edutrul/drupal-ai/.claude/skills/drupal-security/SKILL.md

Drupal security for routes, controllers, forms, and queries. Add route permissions, access checks, CSRF protection, XSS prevention, SQL injection prevention, and secure file upload validation.

716mo agoReads credentialsDiscuss
mbwsimsSkill

security-review

mbwsims/claude-universe/skills/security-review/SKILL.md

Use when the user wants a security-focused review of specific files or changes: "security review this code", "check for exploits", "find security bugs", "pen test this", or "/security-review". This is for exploitability review of targeted code, not a broad whole-project scan or a general-purpose code review.

716mo agoDiscuss
MicrosoftSkill

security-planning

microsoft/hve-core/.github/skills/project-planning/security-planning/SKILL.md

Security planning and plan-drift analysis for STRIDE, standards, controls, backlog handoff, current findings, and TM7 generation.

1.5k7d agoDiscuss
aws-samplesSkill

security-check

aws-samples/sample-agentic-coding-harness-benchmarks/.claude/skills/security-check/SKILL.md

Run the Cipher security-engineer persona over the repository's pending changes to catch and fix security problems before any commit or enhancement. Reviews the working diff against a catalog of real-world security anti-patterns (SSRF, broken access control, weak/default secrets, token trust boundaries, missing CSRF, injection, secret/PII log leakage, dependency CVEs, LLM agent execution safety, timing oracles, proxy body integrity), reports findings with severity, and applies fixes. Invoke before committing, before opening a PR, and whenever a new enhancement is added.

1417d agoReads credentialsDiscuss
s-hiraokuSkill

security-audit

s-hiraoku/synapse-a2a/.agents/skills/security-audit/SKILL.md

General-purpose security auditing guide. Covers OWASP Top 10, dependency vulnerabilities, authentication, authorization, input validation, and secret management. Use this when performing a security review or audit.

135mo agoDiscuss
tanviet12Skill

vbs-scan-security

tanviet12/vbsec/skills/antigravity/vbs-scan-security/SKILL.md

Use when scanning code for security vulnerabilities. Use when user says "scan security", "kiểm tra bảo mật", "security audit", "review security", or invokes `/vbs-scan-security`. For large scans (>20 main-language files OR >30 total OR >14 days) processes chunks sequentially. Outputs bilingual reports (vi/en). Optional `--auto-fix` (agentic patch + verify loop) and `--sca` (live CVE lookup via OSV.dev).

2813d agoReads credentialsDiscuss
tanviet12Skill

vbs-scan-security

tanviet12/vbsec/skills/codex/vbs-scan-security/SKILL.md

Use when scanning code for security vulnerabilities. Use when user says "scan security", "kiểm tra bảo mật", "security audit", "review security", or invokes `/vbs-scan-security`. For large scans (>20 main-language files OR >30 total OR >14 days) processes chunks sequentially. Outputs bilingual reports (vi/en). Optional `--auto-fix` (agentic patch + verify loop) and `--sca` (live CVE lookup via OSV.dev).

2813d agoReads credentialsDiscuss
tanviet12Skill

vbs-scan-security

tanviet12/vbsec/skills/vbs-scan-security/SKILL.md

Use when scanning code for security vulnerabilities. Use when user says "scan security", "kiểm tra bảo mật", "security audit", "review security", or invokes `/vbs-scan-security`. Auto-delegates to sub-agents for large scans (>20 main-language files OR >30 total OR >14 days). Outputs bilingual reports (vi/en). Optional `--auto-fix` (agentic patch + verify loop) and `--sca` (live CVE lookup via OSV.dev).

2813d agoReads credentialsDiscuss
sageoxSkill

security-review

sageox/ox/.claude/skills/security-review/SKILL.md

ox 6-phase AI security review pipeline. Combines deterministic OSS scanners (OpenGrep, govulncheck, OSV-Scanner, Syft+Grype, gitleaks) with parallel Claude hunter/validator subagents to find CLI input handling bugs, secret/credential redaction bypasses, daemon IPC authz holes, supply-chain risks, and LLM trust-boundary issues. Diff-scoped (vs origin/main by default). Never blocks merge. Use when asked to "security review", "/security-review", "review this for security", "audit this PR", "check for vulns", or before merging anything touching auth, lockfiles, daemon IPC, public command surfaces, or secrets/tokens/redaction code.

614mo agoReads credentialsDiscuss
TabooHarmonySkill

roblox-security

TabooHarmony/roblox-brain/skills/core/roblox-security/SKILL.md

Use when auditing Roblox code for exploit vectors, authority models, remotes, economy, and DataStore flows.

617d agoDiscuss
arpitexploresSkill

super-security

arpitexplores/skills-super/super-security/SKILL.md

Security audits, threat modelling, testing, and remediation across apps, APIs, and infrastructure.

25mo agoDiscuss
CLAUDE.md vs AGENTS.md

About skills

What is a Claude skill?

A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.

How do I use one I find here?

Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.

What do the warnings mean?

We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.

Which skills worked for people?

Open a skill to see its discussion. Reports from people and their agents are coming.