agentleFS
Sign inSign up

Claude skills and agent skills

Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.

Best matches · from page 19Worked for most · soon
zad111ak-aiSkill

security-audit

zad111ak-ai/hermes-agent-skills/skills/security/security-audit/SKILL.md

Аудит безопасности кода перед деплоем: проверка секретов, SQL injection, path traversal, зависимостей. Не дай агенту уронить продакшн.

73mo agoReads credentialsDiscuss
AWSSkill

setup-security-agent

aws/agent-toolkit-for-aws/plugins/aws-agents-for-devsecops/skills/setup-security-agent/SKILL.md

Configure AWS Security Agent for the current workspace — provision or reuse an agent space, IAM service role, and S3 bucket. Use when the user asks to "set up security agent", "configure security scanner", "is security agent configured", or on first-time use before any scan or pentest.

2.7k4mo agoDiscuss
johnqtcgSkill

security-review

johnqtcg/awesome-skills/skills/security-review/SKILL.md

Exploitability-first standalone security review of code changes, diffs, PRs, or services. Use when asked for a security review, security audit, vulnerability assessment, or pre-merge security check (安全审查/安全评审/漏洞排查) — covers auth, input, secrets, API, data, concurrency, container, third-party, and dependency risk across Go, Node.js/TypeScript, Java, and Python, with mandatory evidence, false-positive suppression, scope-based depth (Lite/Standard/Deep), and CWE/OWASP-mapped machine-readable output. NOT for general-purpose Go code review — use go-review-lead for that (it dispatches go-security-review as its security dimension); this skill is the deeper security-only process with mandatory gates and audit-grade output.

303mo agoReads credentialsDiscuss
imMamdouhaboammarSkill

fable-security

imMamdouhaboammar/get-fable/skills/fable-security/SKILL.md

Conduct threat modeling, vulnerability assessments, secret sanitization, and security reviews across trust boundaries, auth flows, and untrusted inputs. Use when auditing authentication/authorization logic, inspecting APIs for injection/CORS/CSRF risks, checking for hardcoded credentials, or reviewing security-sensitive diffs — even if the user does not explicitly say \"fable-security\" (e.g. \"security audit this code\", \"check for vulnerabilities\", \"verify auth logic\", \"scan for leaked secrets\"). Do NOT use for general style reviews (use fable-review) or non-security bug fixes (use fable-tdd).

634d agoDiscuss
RobertIliseiSkill

security-audit

RobertIlisei/MARVIN/.claude/skills/security-audit/SKILL.md

OWASP Top 10 + STRIDE threat model pass on the current codebase, or on the current branch diff. Emits a findings report with severity, confidence, and exploit scenario. Use alongside Claude Code's built-in /security-review for spot checks, and whenever the diff touches auth, credentials, tool policy, shell execution, or data persistence. Adapted from Garry Tan's gstack /cso (garrytan/gstack); role framing stripped.

63mo agoReads credentialsDiscuss
vignesh2027Skill

security-chief

vignesh2027/Claude-Agentic-Skills2.0-version/security-chief/SKILL.md

Activates SecurityChief for cybersecurity analysis and threat intelligence. Use when you need STRIDE threat modeling for any system architecture, OWASP top 10 analysis, security log analysis and SIEM triage, incident response playbook execution, SOC2/ISO 27001/NIST CSF control mapping, or vulnerability assessment and remediation planning.

64mo agoDiscuss
khendzelSkill

janitor-security

khendzel/skills-janitor/skills/janitor-security/SKILL.md

Heuristic security scan of installed skills — prompt-injection phrases, hidden unicode instructions, credential-store access, network-pipe-to-shell and payload-smuggling patterns. Use when the user asks 'are my skills safe', wants to scan skills for prompt injection or malware patterns, or before trusting a newly installed skill. Trigger with '/janitor-security'.

1192mo agoPipes a download into a shellDiscuss
dralgorhythmSkill

security-auditor

dralgorhythm/claude-agentic-framework/.claude/skills/security-auditor/SKILL.md

Assess vulnerabilities and audit for security compliance using OWASP and STRIDE methodology — a user-invoked Security Auditor workflow.

1182mo agoDiscuss
zhaoxuya520Skill

supply-chain-security

zhaoxuya520/reverse-skill/skills/supply-chain-security/SKILL.md

Use for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

38k9d agoDiscuss
JamalMohafilSkill

security-review

JamalMohafil/claude-skills/security-review/SKILL.md

Run a security review of code changes exactly like Claude Code's /security-review command — but in ANY AI coding agent (Claude Code, Cursor, Codex, Windsurf, Gemini CLI, Cline…). Reviews the pending branch diff (or a specific PR, uncommitted changes, or a whole file/folder) for HIGH-CONFIDENCE, actually-exploitable vulnerabilities — SQL/command/template/NoSQL injection, path traversal, auth & authorization bypass, privilege escalation, hardcoded secrets, weak crypto, insecure deserialization / RCE, XSS, SSRF, and sensitive data exposure — then applies a strict two-pass false-positive filter (confidence ≥ 0.8) and writes a precise markdown report with file, line, severity, exploit scenario, and fix. Optionally fixes each confirmed finding. Use when the user says "security review", "/security-review", "audit my code/changes for vulnerabilities", "check this for security issues", "is this secure", "find vulnerabilities", or before merging/shipping.

2510d agoDiscuss
atherio-danpSkill

security-backend

atherio-danp/cde-dotnetcc/.claude/skills/security-backend/SKILL.md

Audit the .NET backend (apps/api) for security issues against OWASP Top 10 mapped to .NET/Minimal API/EF Core (Npgsql), plus tenant isolation, secret handling, and EU data residency. Use when reviewing backend changes for security, or running a backend security audit. Preloaded by the security-auditor-backend agent.

1093mo agoDiscuss
Aditya923-cSkill

security-osint

Aditya923-c/xpoz-agent-skills/skills/security-osint/SKILL.md

Monitor social platforms for security threats, vulnerability discussions, and breach intelligence using Xpoz. Use when asked to "find CVE discussions", "security threat monitoring", "OSINT social media", "vulnerability intelligence", "breach mentions", or "threat intel from Twitter/Reddit".

57mo agoReads credentialsDiscuss
hongyuancSkill

security-audit

hongyuanc/codex-game-studios/.agents/skills/security-audit/SKILL.md

Use when game code or data flows need a diagnostic security review before release or multiplayer exposure.

53mo agoDiscuss
KhaledSaeed18Skill

owasp-security

KhaledSaeed18/dotclaude/skills/security/owasp-security/SKILL.md

Review code being written or modified against the OWASP Top 10:2025 and ASVS secure-coding requirements, in any language or stack, catching vulnerability classes before they ship. Use when writing auth logic, handling user input, adding API endpoints, choosing cryptography, processing uploads, or touching any trust boundary. Complements secret-scan and dependency-audit with line-level review.

53mo agoDiscuss
TheBeardedBearSASSkill

security-flutter

TheBeardedBearSAS/claude-craft/.claude/skills/security-flutter/SKILL.md

Sécurité Flutter. Use when reviewing security, implementing auth, or hardening code.

1052mo agoDiscuss
MicrosoftSkill

security-report-check

microsoft/TypeScript/.github/skills/security-report-check/SKILL.md

Are you doing security research on this repo? This document covers what guarantees and non-guarantees are provided. Consult this document before reporting a security issue or conducting security research.

111k2y agoDiscuss
felvieiraSkill

security-review

felvieira/claude-skills-fv/skills/06-security-review/SKILL.md

Skill do Security Reviewer para auditoria de segurança e boas práticas. Use quando precisar revisar código para vulnerabilidades, validar implementação de auth, checar OWASP Top 10, revisar CORS/CSRF/XSS, garantir DRY e clean code, ou qualquer review de segurança. Trigger em: "segurança", "security review", "vulnerabilidade", "OWASP", "XSS", "CSRF", "CORS", "injection", "HttpOnly", "cookie seguro", "DRY", "code review", "boas práticas", "audit", "pentest", "sanitização".

2329d agoReads credentialsDiscuss
MagerkoSkill

launch-security

Magerko/claude-code-skills/skills/launch-security/SKILL.md

Пред-запусковый аудит безопасности приложения — секреты и ключи, аутентификация и сессии, доступ к чужим данным (IDOR, RLS), инъекции и XSS, загрузка файлов, заголовки и CORS, лимиты и расходы, утечки в ответах и логах, зависимости, прод-гигиена, вебхуки и платежи. Выдаёт отчёт с приоритетами; код не правит. Только ручной запуск.

2249d agoDiscuss
wgpsecSkill

ai-identity-security

wgpsec/AboutSecurity/skills/ai-security/ai-identity-security/SKILL.md

AI 系统身份与权限安全测试方法论。当目标系统涉及 Agent 身份认证、多 Agent 权限管理、 角色设定安全、会话管理、或 MCP/API 凭据管控时触发。 覆盖: 角色逃逸(假定场景/假定角色/遗忘法/目标劫持)、权限失控(Action 越权/MCP 未授权资源获取)、 多 Agent 身份伪造、会话劫持、凭据泄露与滥用。

1.8k4mo agoDiscuss
BrOrlandiSkill

security-review

BrOrlandi/my-claude-skills/security-review/SKILL.md

Scan code for security vulnerabilities (hardcoded secrets, env var exposure, injection, auth issues), generate SECURITY.md guidelines, or verify compliance with existing security rules. Use for security audits, pre-push reviews, API key checks, or when the user wants to create security guidelines.

219d agoReads credentialsDiscuss
CLAUDE.md vs AGENTS.md

About skills

What is a Claude skill?

A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.

How do I use one I find here?

Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.

What do the warnings mean?

We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.

Which skills worked for people?

Open a skill to see its discussion. Reports from people and their agents are coming.