agentleFS
Sign inSign up

Claude skills and agent skills

Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.

Best matches · from page 18Worked for most · soon
talayashSkill

security-review

talayash/agentrium/.claude/skills/security-review/SKILL.md

Security audit checklist and patterns for Tauri desktop apps with PTY spawning

4120d agoDiscuss
wolverin0Skill

security-review

wolverin0/claude-skills/skills/security-review/SKILL.md

Review security-sensitive code changes involving auth, user input, secrets, APIs, payments, files, RLS, or third-party integrations.

4138d agoDiscuss
GoogleSkill

gke-workload-security

google/skills/skills/cloud/gke-workload-security/SKILL.md

Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces. Covers running cluster security audits (`audit_cluster.sh`), configuring Workload Identity Federation (impersonation, KSA/GSA binding, and pod setup), enforcing Network Policies (default-deny and Dataplane V2 logging), isolating high-risk pods inside GKE Sandbox (`gVisor`), enforcing Pod Security Standards (`restricted` labeling), and mounting Secret Manager secrets via CSI (`SecretProviderClass`). Use when auditing cluster security posture, isolating namespaces, applying pod security standards, setting up Workload Identity, or configuring network policies and secret volume mounts. Don't use for cluster-wide control plane security, RBAC hardening, Binary Authorization, Shielded Nodes, or enabling platform-level GKE add-ons (use gke-platform-security instead).

20k10d agoDiscuss
DIL8654Skill

security-audit

DIL8654/claude-code-dotnet-template/.claude/skills/security-audit/SKILL.md

Review .NET services for safe defaults in input handling, authentication, authorization, secret management, logging exposure, and configuration hygiene. Use before release, during reviews, or when hardening an API or integration.

86mo agoDiscuss
greglas75Skill

security-audit

greglas75/zuvo/skills/security-audit/SKILL.md

Application security audit covering OWASP Top 10, injection, XSS, SSRF, auth/authz, multi-tenant isolation, secrets, headers, dependencies, business logic, infrastructure, and AI/LLM + MCP tool-invocation security (S15, incl. tool poisoning and confused-deputy). Uses Sentry 3-tier confidence model. Supports Next.js, NestJS, Express, FastAPI, Django, Flask. Dual scoring: static posture + runtime exploitability. Flags: zuvo:security-audit [path] | full | --live-url <url> | --static | --quick | --persist-backlog

825d agoReads credentialsDiscuss
lilangMaxSkill

security-audit

lilangMax/ClaudeCodeGameStudios/.claude/skills/security-audit/SKILL.md

Audit the game for security vulnerabilities: save tampering, cheat vectors, network exploits, data exposure, and input validation gaps. Produces a prioritised security report with remediation guidance. Run before any public release or multiplayer launch.

85mo agoDiscuss
Asher-PlihalSkill

server-security

Asher-Plihal/claude-skills/server-security/SKILL.md

Audit the security posture of Asher's production Linux server (Ubuntu 24.04 at goldlobster@100.117.45.128 — Cloudflare-tunneled server-stack + Tailscale-only AI gateway). Trigger this skill aggressively whenever Asher says anything in the neighborhood of "run a security check", "test the server", "audit the server", "verify security posture", "run the security checklist", "check the firewall", "check for drift", "is X exposed", "am I still secure", "did anything change on the server", "review the hardening", "check my containers", or any variation that implies inspecting listening ports, running containers, SSH/Tailscale state, Cloudflare Access, secrets hygiene, or systemd hardening on this server. Prefer triggering when in doubt — Phase 1 of this skill is completely read-only and cannot harm the server just by running. The skill runs a bundled script, interprets the output against an expected-state baseline, produces a severity-ranked report, and then waits for Asher's approval before fixing anything.

15mo agoReads credentialsDiscuss
GA14-hubSkill

security-secrets

GA14-hub/claude-code-kit-ja/.claude/skills/security-secrets/SKILL.md

コードベースから秘密情報(APIキー・トークン・パスワード等)の漏洩を検出する。

18mo agoReads credentialsDiscuss
goodnessibehSkill

senior-security

goodnessibeh/ai-dev-boilerplate/.claude/skills/senior-security/SKILL.md

Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.

16mo agoReads credentialsDiscuss
Helg-gitSkill

web3-security

Helg-git/claude-skills/web3-security/SKILL.md

Web3 安全审计专家 - 智能合约漏洞检测与防护

18mo agoDiscuss
junimnjwSkill

perl-security

junimnjw/everything-claude-code/skills/perl-security/SKILL.md

Comprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies.

17mo agoDeletes or force-pushesDiscuss
lwhsuSkill

port-security

lwhsu/freebsd-claude-skills/skills/port-security/SKILL.md

Handle a FreeBSD port security advisory. This skill should be used when the user needs to create a VuXML entry and update a port for a security vulnerability, or mentions CVE, security advisory, or VuXML.

157d agoDiscuss
OpenOps-StudioSkill

security-gate

OpenOps-Studio/vibe-driven-dev/skills/safety/security-gate/SKILL.md

Evaluates project artifacts and state for security risks. Triggered explicitly before the 'scaffold' and 'qa' stages to ensure no hardcoded secrets, unsafe dependency assumptions, or major architectural security flaws pass into execution.

16mo agoReads credentialsDiscuss
pinkpixel-devSkill

tauri-security

pinkpixel-dev/tauri-skills/skills/tauri-security/SKILL.md

Guidance for Tauri v2 capabilities, scope configuration, and ACL-based permission control.

153d agoDiscuss
romaintoso78Skill

perl-security

romaintoso78/claude-skills/skills/perl-security/SKILL.md

Comprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies.

13mo agoDeletes or force-pushesDiscuss
OpenAISkill

security-best-practices

openai/skills/skills/.curated/security-best-practices/SKILL.md

Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.

27k7mo agoDiscuss
myths-labsSkill

security-review

myths-labs/muse/skills/toolkit/security-review/SKILL.md

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

356mo agoReads credentialsDiscuss
CTOexpertSkill

cybersorted

CTOexpert/claude-skills/cybersorted/SKILL.md

Security and enterprise architecture advisory skill. Use this skill when the user needs help with cybersecurity strategy, threat modeling, risk assessment, compliance, security architecture, enterprise architecture, or governance. Trigger when the user mentions: security posture, threat model, STRIDE, PASTA, risk assessment, risk register, compliance mapping, SOC2, ISO 27001, NIST 800-53, CIS benchmarks, MITRE ATT&CK, zero trust, incident response, IR plan, security policy, architecture decision record, ADR, vendor risk, third-party risk, board briefing, security maturity, maturity assessment, gap analysis, security review, code review for security, IaC review, Terraform security, Kubernetes security, CI/CD security, API security, cloud configuration review, tabletop exercise, red team, blue team, penetration test planning, security architecture, network segmentation, defense in depth, least privilege, data classification, encryption strategy, key management, identity and access management, IAM, SIEM, SOC, vulnerability management, patch management, business continuity, disaster recovery, BCP, DRP, privacy by design, GDPR, CCPA, data protection, platform security, build vs buy security, DevSecOps, shift left security, supply chain security, SBOM, secure coding, secure by design, OWASP Top 10, OWASP ASVS, OWASP SAMM, input validation, output encoding, SQL injection prevention, XSS prevention, CSRF prevention, secrets management, dependency security, SAST, DAST, SCA, secure API design, penetration test, pentest, pen test, red team, offensive security, vulnerability assessment, exploit, Kerberoasting, Active Directory attack, privilege escalation, lateral movement, CVSS, CSTM, Cyber Scheme, web application testing, network penetration test, cloud penetration test, container security testing, physical security assessment, or any security and architecture advisory request. Supports roles: CISO, CTO, CPO, Security Architect, Security Engineer, Enterprise Architect, Secure Developer, Penetration Tester.

07mo agoDiscuss
diegocconsoliniSkill

security-hooks

diegocconsolini/ClaudeSkillCollection/security-hooks/SKILL.md

Use this skill to install ready-made Claude Code hooks for security — a ConfigChange compliance audit trail (logs every settings/skill change), plus PreToolUse guards and optional HTTP notifications for security-relevant events. Covers command, http, and prompt hook types.

712mo agoDiscuss
joris887Skill

security-audit

joris887/exosuit/.claude/skills/security-audit/SKILL.md

Security review for code touching authentication, credentials, file access, or user data. Includes CWE checklist ranked by AI vulnerability frequency, phantom package detection, ASVS-aligned controls, and supply chain checks. MANDATORY for auth code, credential handling, file operations with user data, network comms, or database queries with user input.

742d agoDiscuss
CLAUDE.md vs AGENTS.md

About skills

What is a Claude skill?

A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.

How do I use one I find here?

Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.

What do the warnings mean?

We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.

Which skills worked for people?

Open a skill to see its discussion. Reports from people and their agents are coming.