Audit application code and architecture, investigate suspected vulnerabilities, threat-model sensitive features, and implement security fixes. Use for explicit security reviews, exploitability analysis, incident triage, or changes to authentication, authorization, secrets, tenant isolation, injection defenses, file handling, and privileged AI tools.
MUST be used whenever fixing security issues in a Flows app, or before shipping any feature that handles credentials, user input, or external data. This skill finds AND fixes security problems — it does not just report them. Do NOT skip this when the user asks for a security fix, security hardening, or vulnerability remediation — run every step in order. Triggers: security, security fix, security hardening, vulnerability, XSS, injection, credentials, secrets, auth, authentication, authorization, token, sensitive data, input validation, CORS, CSP, dependency audit.
Security Analysis & Protection Expert
Expert in security analysis, reverse engineering, intrusion detection, and system hardening. Specializes in using tools like Ghidra, forensics utilities, and security monitoring to ensure system safety
Audit and fix security vulnerabilities across web apps, APIs, databases, auth systems, and infrastructure. Use when asked to review security, fix vulnerabilities, implement auth, or harden a system.
Evidence-grounded threat modeling, vulnerability review, and secure implementation. Use for explicit security audits or primary risks involving authorization, untrusted input, external requests, parsers/uploads, secrets, sensitive data, isolation, or release integrity. Not for routine implementation or non-security red-teaming. Add `security-identity-access` for identity and tenant authorization.
Security patterns and frameworks. Use when reviewing code for vulnerabilities, designing authentication/authorization, writing IAM policies, handling secrets, or discussing threat models.
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.
Use for authorized security assessment of LLM applications and AI agents, including prompt injection, tool abuse, RAG exposure, memory poisoning, and model supply-chain risks.
Audit a vibe-coded web app's security against a practical checklist — RLS/auth, exposed secrets, signups, storage, IDOR, webhooks, headers, XSS. Tuned for React/Vite + Supabase on Netlify/Vercel/Cloudflare, with adaptations for Firebase and custom Node/Next APIs. Use whenever asked to do a security review/audit, check for vulnerabilities, find exposed secrets/keys, verify RLS or auth, harden an app before launch, or when the user types /security. Supports `/security --fix` (apply safe fixes on a branch) and `/security --grep` (offline CI-friendly scan only).
Audits a project's dependency and infrastructure security — runs composer/npm audit, checks CMS/framework security advisories, reviews the Docker setup, ranks every finding by exploitable criticality, and either applies safe fixes or gives exact step-by-step remediation. Stack-agnostic: pulls stack-specific advisory checks (e.g. Drupal SAs) from the loaded stack/ resource. Use when the user asks for a security audit, a CVE/vulnerability check, a dependency-security pass, or invokes /gm:security.
Use when the user asks for a security review, vulnerability scan, security audit, or to check code for security issues, front end or back end. Also trigger on "/foreman:security" or "/security".
Security Policy
## Reporting a Vulnerability
If you discover a security vulnerability in this project, please report it responsibly. Do NOT open a public GitHub issue for security vulnerabilities. Open
Expert security architect providing comprehensive security guidance, architecture assessments, threat modeling, and compliance verification. Follows OWASP, NIS2, ISO 27001, NIST, and industry best practices. Use for security architecture design and review, threat modeling, security strategy, compliance assessment (OWASP, NIS2, GDPR, PCI DSS, SOC 2), infrastructure security, API security patterns, and incident response planning. For code-level security reviews, use the code-review skill.
Secure web and desktop application development. Use when writing authentication, authorization, API endpoints, form handling, database queries, file uploads, Electron apps, Tauri apps, IPC handlers, cryptography, secrets management, security headers, input validation, or when reviewing code for vulnerabilities. Covers OWASP Top 10, XSS, CSRF, SQL injection, SSRF, command injection, path traversal, and desktop app security.
Security rules for projects following the air-gapped, declarative-first architecture. Covers Content Security Policy, recommended security headers, and the architectural decisions that enable a strict CSP without unsafe-inline or unsafe-eval. Use when configuring deployment, reviewing CSP, or auditing for inline-script or inline-style violations.
A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.
How do I use one I find here?
Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.
What do the warnings mean?
We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.
Which skills worked for people?
Open a skill to see its discussion. Reports from people and their agents are coming.