agentleFS
Sign inSign up

Claude skills and agent skills

Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.

Best matches · from page 17Worked for most · soon
csiddhant796-blipSkill

senior-security

csiddhant796-blip/claude-skills-collection/senior-security/SKILL.md

Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP guidance, cryptography patterns, and security scanning tools. Use when the user asks about security reviews, threat analysis, vulnerability assessments, secure coding practices, security audits, attack surface analysis, CVE remediation, or security best practices.

25mo agoDiscuss
eeshsaxenaSkill

security-sweep

eeshsaxena/agent-skills/skills/security-sweep/SKILL.md

Catch the common, high-impact security mistakes before they ship. Use when reviewing code that handles input, auth, secrets, queries, or file paths.

257d agoDiscuss
hackIDLESkill

mesh-security

hackIDLE/skills/skills/mesh-security/SKILL.md

Analyze Istio, Consul, and Linkerd service mesh configurations for security vulnerabilities with NIST 800-53 control mappings. Use when users need to audit mesh security, identify misconfigurations, check mTLS settings, review ACL policies, or prepare for FedRAMP assessments. Triggers on keywords like "mesh config", "istio security", "consul ACL", "linkerd policy", "service mesh audit", or "NIST compliance".

27mo agoDiscuss
po4ykaSkill

rust-security

po4yka/rust-skills/skills/rust-security/SKILL.md

Use when running cargo-audit or cargo-deny, editing deny.toml, triaging a RUSTSEC advisory or CVE in a dependency, vetting a new or updated crate for typosquat, malicious crate, or compromised-release risk, or hardening a Rust parser that reads untrusted files, archives, or binary formats. Not for authentication, secret storage, cryptographic design, or TLS policy (TLS belongs to rust-networking). Triggers on "cargo audit", "cargo deny", "RUSTSEC", "supply chain", "yanked", "path traversal", "decompression bomb".

242d agoDeletes or force-pushesDiscuss
racciolySkill

security-pass

raccioly/websec-validator/skills/security-pass/SKILL.md

Defensive security self-assessment of the operator's OWN codebase. Local and read-only by default — it reads the repo, runs static scanners, and writes a briefing; no live system is touched. Active probes are opt-in, run only against a TEST instance the human owns and supplies, and require explicit per-run human approval; production and third-party targets are out of scope. Use when the user wants to security-review their own app, harden it, check for BOLA/IDOR/JWT/SSRF/mass-assignment issues, pentest their own code, or "see if my app is safe" before shipping.

23mo agoDiscuss
ronmkrSkill

perl-security

ronmkr/PromptBook/skills/technical/perl-security/SKILL.md

Comprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies.

24mo agoDeletes or force-pushesDiscuss
suryastSkill

skill-security

suryast/free-ai-agent-skills/skill-security/SKILL.md

Security audit tool for AI agent skills. Scans for credential harvesting, code injection, network exfiltration, obfuscation. ALWAYS run before installing any new skill from external sources. Triggers on: new skill installation, skill audit, security scan, skill review, before loading external skill.

27mo agoReads credentialsDiscuss
loulanyueSkill

laravel-security

loulanyue/awesome-claude-notes/skills/laravel-security/SKILL.md

Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.

2726mo agoDiscuss
GitHubSkill

developer-security

github/gh-aw/.github/skills/developer-security/SKILL.md

Security best practices for gh-aw workflows and Go code: template injection prevention, shell script security, supply chain hardening, and static analysis integration.

5.2k4mo agoDiscuss
naviktSkill

security-review

navikt/copilot/skills/security-review/SKILL.md

Bruk før commit, push eller pull request for å sjekke at koden er trygg å merge

5417d agoDiscuss
wpankSkill

solidity-security

wpank/ai/skills/devops/solidity-security/SKILL.md

Smart contract security patterns, vulnerability prevention, gas optimization, and audit preparation for Solidity development. Use when writing, auditing, or hardening smart contracts against reentrancy, overflow, access control, oracle manipulation, and front-running attacks.

118mo agoDiscuss
ruvnetSkill

V3 Security Overhaul

ruvnet/RuView/.claude/skills/v3-security-overhaul/SKILL.md

Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.

95k7mo agoDiscuss
madsnorgaardSkill

drupal-security

madsnorgaard/drupal-agent-resources/.claude/skills/drupal-security/SKILL.md

Drupal security expertise. Auto-activates when writing forms, controllers, queries, or handling user input. Prevents XSS, SQL injection, and access bypass vulnerabilities.

479mo agoReads credentialsDiscuss
Aurite-aiSkill

verify-security

Aurite-ai/agent-verifier/skills/verify-security/SKILL.md

Verify code for security issues including hardcoded secrets, input validation, error exposure, and dependency vulnerabilities. Use when asked to "verify security", "check for secrets", or "scan for vulnerabilities".

447mo agoReads credentialsDiscuss
MicrosoftSkill

security-review

microsoft/devsquad-copilot/.github/plugins/devsquad/skills/security-review/SKILL.md

Security assessment workflow in two modes: architectural (design) and code (implementation). Use when a security trigger is detected during planning (architectural mode) or implementation/review (code mode). Covers STRIDE, OWASP, dependency scanning, Azure compliance, and GitHub security alerts. Do not use for general code quality (use devsquad.review), for threat modeling as a standalone activity, or for compliance audits.

445mo agoDiscuss
emaraschioSkill

security-audit

emaraschio/cursor-commands/.cursor/skill-contracts/security-audit/SKILL.md

Security audit of codebase or change

955d agoDiscuss
kensaurusSkill

audit-security

kensaurus/cursor-kenji/skills/audit-security/SKILL.md

Audit and fix app code against OWASP (injection, headers, dependencies). Use when "review security" or "check vulnerabilities". Auth gates → audit-auth-flows. Plan-only → plan-security-audit. RLS → plan-rls-audit. LLM → audit-llm-security.

98d agoReads credentialsDiscuss
sergeeeySkill

security-audit

sergeeey/Claude-cod-top-2026/skills/extensions/security-audit/SKILL.md

name: security-audit description: > [STATUS: review] [CONFIDENCE: high] [REVIEWED: 2026-03-13] MUST CHECK before any commit touching auth, payments, PII, user data, SQL, .env. USE for financial applications, compliance

95mo agoReads credentialsDiscuss
ruvnetSkill

V3 Security Overhaul

ruvnet/ruflo/.agents/skills/v3-security-overhaul/SKILL.md

Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.

73k21d agoDiscuss
0xGhostCATSkill

llm-ai-security

0xGhostCAT/claude-ai-cyber-security-skills/skills/25-llm-ai-security/SKILL.md

Hunt vulnerabilities in LLM-powered applications — direct/indirect prompt injection, system prompt extraction, ASCII smuggling, RCE via code tools, agentic AI exploits (ASI01-ASI10), data exfiltration via response channels, IDOR in chat history, jailbreak chains, RAG poisoning. Use when target has a chatbot, AI assistant, copilot, or agentic AI features.

414mo agoDeletes or force-pushesDiscuss
CLAUDE.md vs AGENTS.md

About skills

What is a Claude skill?

A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.

How do I use one I find here?

Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.

What do the warnings mean?

We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.

Which skills worked for people?

Open a skill to see its discussion. Reports from people and their agents are coming.