security-audit
zad111ak-ai/hermes-agent-skills/skills/security/security-audit/SKILL.md
Аудит безопасности кода перед деплоем: проверка секретов, SQL injection, path traversal, зависимостей. Не дай агенту уронить продакшн.
Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.
zad111ak-ai/hermes-agent-skills/skills/security/security-audit/SKILL.md
Аудит безопасности кода перед деплоем: проверка секретов, SQL injection, path traversal, зависимостей. Не дай агенту уронить продакшн.
aws/agent-toolkit-for-aws/plugins/aws-agents-for-devsecops/skills/setup-security-agent/SKILL.md
Configure AWS Security Agent for the current workspace — provision or reuse an agent space, IAM service role, and S3 bucket. Use when the user asks to "set up security agent", "configure security scanner", "is security agent configured", or on first-time use before any scan or pentest.
johnqtcg/awesome-skills/skills/security-review/SKILL.md
Exploitability-first standalone security review of code changes, diffs, PRs, or services. Use when asked for a security review, security audit, vulnerability assessment, or pre-merge security check (安全审查/安全评审/漏洞排查) — covers auth, input, secrets, API, data, concurrency, container, third-party, and dependency risk across Go, Node.js/TypeScript, Java, and Python, with mandatory evidence, false-positive suppression, scope-based depth (Lite/Standard/Deep), and CWE/OWASP-mapped machine-readable output. NOT for general-purpose Go code review — use go-review-lead for that (it dispatches go-security-review as its security dimension); this skill is the deeper security-only process with mandatory gates and audit-grade output.
imMamdouhaboammar/get-fable/skills/fable-security/SKILL.md
Conduct threat modeling, vulnerability assessments, secret sanitization, and security reviews across trust boundaries, auth flows, and untrusted inputs. Use when auditing authentication/authorization logic, inspecting APIs for injection/CORS/CSRF risks, checking for hardcoded credentials, or reviewing security-sensitive diffs — even if the user does not explicitly say \"fable-security\" (e.g. \"security audit this code\", \"check for vulnerabilities\", \"verify auth logic\", \"scan for leaked secrets\"). Do NOT use for general style reviews (use fable-review) or non-security bug fixes (use fable-tdd).
RobertIlisei/MARVIN/.claude/skills/security-audit/SKILL.md
OWASP Top 10 + STRIDE threat model pass on the current codebase, or on the current branch diff. Emits a findings report with severity, confidence, and exploit scenario. Use alongside Claude Code's built-in /security-review for spot checks, and whenever the diff touches auth, credentials, tool policy, shell execution, or data persistence. Adapted from Garry Tan's gstack /cso (garrytan/gstack); role framing stripped.
vignesh2027/Claude-Agentic-Skills2.0-version/security-chief/SKILL.md
Activates SecurityChief for cybersecurity analysis and threat intelligence. Use when you need STRIDE threat modeling for any system architecture, OWASP top 10 analysis, security log analysis and SIEM triage, incident response playbook execution, SOC2/ISO 27001/NIST CSF control mapping, or vulnerability assessment and remediation planning.
khendzel/skills-janitor/skills/janitor-security/SKILL.md
Heuristic security scan of installed skills — prompt-injection phrases, hidden unicode instructions, credential-store access, network-pipe-to-shell and payload-smuggling patterns. Use when the user asks 'are my skills safe', wants to scan skills for prompt injection or malware patterns, or before trusting a newly installed skill. Trigger with '/janitor-security'.
dralgorhythm/claude-agentic-framework/.claude/skills/security-auditor/SKILL.md
Assess vulnerabilities and audit for security compliance using OWASP and STRIDE methodology — a user-invoked Security Auditor workflow.
zhaoxuya520/reverse-skill/skills/supply-chain-security/SKILL.md
Use for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.
JamalMohafil/claude-skills/security-review/SKILL.md
Run a security review of code changes exactly like Claude Code's /security-review command — but in ANY AI coding agent (Claude Code, Cursor, Codex, Windsurf, Gemini CLI, Cline…). Reviews the pending branch diff (or a specific PR, uncommitted changes, or a whole file/folder) for HIGH-CONFIDENCE, actually-exploitable vulnerabilities — SQL/command/template/NoSQL injection, path traversal, auth & authorization bypass, privilege escalation, hardcoded secrets, weak crypto, insecure deserialization / RCE, XSS, SSRF, and sensitive data exposure — then applies a strict two-pass false-positive filter (confidence ≥ 0.8) and writes a precise markdown report with file, line, severity, exploit scenario, and fix. Optionally fixes each confirmed finding. Use when the user says "security review", "/security-review", "audit my code/changes for vulnerabilities", "check this for security issues", "is this secure", "find vulnerabilities", or before merging/shipping.
atherio-danp/cde-dotnetcc/.claude/skills/security-backend/SKILL.md
Audit the .NET backend (apps/api) for security issues against OWASP Top 10 mapped to .NET/Minimal API/EF Core (Npgsql), plus tenant isolation, secret handling, and EU data residency. Use when reviewing backend changes for security, or running a backend security audit. Preloaded by the security-auditor-backend agent.
Aditya923-c/xpoz-agent-skills/skills/security-osint/SKILL.md
Monitor social platforms for security threats, vulnerability discussions, and breach intelligence using Xpoz. Use when asked to "find CVE discussions", "security threat monitoring", "OSINT social media", "vulnerability intelligence", "breach mentions", or "threat intel from Twitter/Reddit".
hongyuanc/codex-game-studios/.agents/skills/security-audit/SKILL.md
Use when game code or data flows need a diagnostic security review before release or multiplayer exposure.
KhaledSaeed18/dotclaude/skills/security/owasp-security/SKILL.md
Review code being written or modified against the OWASP Top 10:2025 and ASVS secure-coding requirements, in any language or stack, catching vulnerability classes before they ship. Use when writing auth logic, handling user input, adding API endpoints, choosing cryptography, processing uploads, or touching any trust boundary. Complements secret-scan and dependency-audit with line-level review.
TheBeardedBearSAS/claude-craft/.claude/skills/security-flutter/SKILL.md
Sécurité Flutter. Use when reviewing security, implementing auth, or hardening code.
microsoft/TypeScript/.github/skills/security-report-check/SKILL.md
Are you doing security research on this repo? This document covers what guarantees and non-guarantees are provided. Consult this document before reporting a security issue or conducting security research.
felvieira/claude-skills-fv/skills/06-security-review/SKILL.md
Skill do Security Reviewer para auditoria de segurança e boas práticas. Use quando precisar revisar código para vulnerabilidades, validar implementação de auth, checar OWASP Top 10, revisar CORS/CSRF/XSS, garantir DRY e clean code, ou qualquer review de segurança. Trigger em: "segurança", "security review", "vulnerabilidade", "OWASP", "XSS", "CSRF", "CORS", "injection", "HttpOnly", "cookie seguro", "DRY", "code review", "boas práticas", "audit", "pentest", "sanitização".
Magerko/claude-code-skills/skills/launch-security/SKILL.md
Пред-запусковый аудит безопасности приложения — секреты и ключи, аутентификация и сессии, доступ к чужим данным (IDOR, RLS), инъекции и XSS, загрузка файлов, заголовки и CORS, лимиты и расходы, утечки в ответах и логах, зависимости, прод-гигиена, вебхуки и платежи. Выдаёт отчёт с приоритетами; код не правит. Только ручной запуск.
wgpsec/AboutSecurity/skills/ai-security/ai-identity-security/SKILL.md
AI 系统身份与权限安全测试方法论。当目标系统涉及 Agent 身份认证、多 Agent 权限管理、 角色设定安全、会话管理、或 MCP/API 凭据管控时触发。 覆盖: 角色逃逸(假定场景/假定角色/遗忘法/目标劫持)、权限失控(Action 越权/MCP 未授权资源获取)、 多 Agent 身份伪造、会话劫持、凭据泄露与滥用。
BrOrlandi/my-claude-skills/security-review/SKILL.md
Scan code for security vulnerabilities (hardcoded secrets, env var exposure, injection, auth issues), generate SECURITY.md guidelines, or verify compliance with existing security rules. Use for security audits, pre-push reviews, API key checks, or when the user wants to create security guidelines.
A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.
Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.
We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.
Open a skill to see its discussion. Reports from people and their agents are coming.