agentleFS
Sign inSign up

Claude skills and agent skills

Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.

Best matches · from page 2Worked for most · soon
prangishviliAbeSkill

security

prangishviliAbe/agent-skills/security/SKILL.md

Audit application code and architecture, investigate suspected vulnerabilities, threat-model sensitive features, and implement security fixes. Use for explicit security reviews, exploitability analysis, incident triage, or changes to authentication, authorization, secrets, tenant isolation, injection defenses, file handling, and privileged AI tools.

74d agoDiscuss
cognitedataSkill

security

cognitedata/builder-skills/skills/security/SKILL.md

MUST be used whenever fixing security issues in a Flows app, or before shipping any feature that handles credentials, user input, or external data. This skill finds AND fixes security problems — it does not just report them. Do NOT skip this when the user asks for a security fix, security hardening, or vulnerability remediation — run every step in order. Triggers: security, security fix, security hardening, vulnerability, XSS, injection, credentials, secrets, auth, authentication, authorization, token, sensitive data, input validation, CORS, CSP, dependency audit.

66mo agoReads credentialsDiscuss
0xSeroSkill

security

0xSero/claude-skill-dir/security/SKILL.md

Security Analysis & Protection Expert Expert in security analysis, reverse engineering, intrusion detection, and system hardening. Specializes in using tools like Ghidra, forensics utilities, and security monitoring to ensure system safety

411mo agoDiscuss
daianepepes-labSkill

security

daianepepes-lab/claude-skills/security/SKILL.md

Audit and fix security vulnerabilities across web apps, APIs, databases, auth systems, and infrastructure. Use when asked to review security, fix vulnerabilities, implement auth, or harden a system.

46mo agoDiscuss
n-n-codeSkill

security

n-n-code/n-n-code-skills/.agents/skills/security/SKILL.md

Evidence-grounded threat modeling, vulnerability review, and secure implementation. Use for explicit security audits or primary risks involving authorization, untrusted input, external requests, parsers/uploads, secrets, sensitive data, isolation, or release integrity. Not for routine implementation or non-security red-teaming. Add `security-identity-access` for identity and tenant authorization.

425d agoDiscuss
plipowczanSkill

security

plipowczan/claude-piv-skeleton/.claude/skills/security/SKILL.md

Enforces security best practices

48mo agoDiscuss
pluginagentmarketplaceSkill

security

pluginagentmarketplace/custom-plugin-backend/skills/security/SKILL.md

Secure backend applications against OWASP threats. Implement authentication, encryption, scanning, compliance, and incident response procedures.

49mo agoReads credentialsDiscuss
yoonationSkill

security

yoonation/ai-grounded/.claude/skills/security/SKILL.md

Security patterns and frameworks. Use when reviewing code for vulnerabilities, designing authentication/authorization, writing IAM policies, handling secrets, or discussing threat models.

42mo agoReads credentialsDiscuss
vndeeSkill

security

vndee/engineering-skills/.claude/skills/security/SKILL.md

Use when implementing authentication, authorization, input validation, or security hardening in Go, Python, or React applications

36mo agoReads credentialsDiscuss
zhaoxuya520Skill

api-security

zhaoxuya520/reverse-skill/skills/api-security/SKILL.md

Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.

38k9d agoDiscuss
zhaoxuya520Skill

llm-security

zhaoxuya520/reverse-skill/skills/llm-security/SKILL.md

Use for authorized security assessment of LLM applications and AI agents, including prompt injection, tool abuse, RAG exposure, memory poisoning, and model supply-chain risks.

38k9d agoDiscuss
bchoxSkill

security

bchox/agent-practices/skills/security/SKILL.md

Use when the change touches auth, secrets, trust boundaries, or sensitive data.

213d agoDiscuss
ffsshhttiikkSkill

security

ffsshhttiikk/opencode-agents-skills/security/SKILL.md

Security best practices and patterns

27mo agoReads credentialsDiscuss
flywheel-productSkill

security

flywheel-product/ai-build-skills/security/SKILL.md

Audit a vibe-coded web app's security against a practical checklist — RLS/auth, exposed secrets, signups, storage, IDOR, webhooks, headers, XSS. Tuned for React/Vite + Supabase on Netlify/Vercel/Cloudflare, with adaptations for Firebase and custom Node/Next APIs. Use whenever asked to do a security review/audit, check for vulnerabilities, find exposed secrets/keys, verify RLS or auth, harden an app before launch, or when the user types /security. Supports `/security --fix` (apply safe fixes on a branch) and `/security --grep` (offline CI-friendly scan only).

23mo agoDiscuss
gingermindsSkill

security

gingerminds/claude-skills/skills/security/SKILL.md

Audits a project's dependency and infrastructure security — runs composer/npm audit, checks CMS/framework security advisories, reviews the Docker setup, ranks every finding by exploitable criticality, and either applies safe fixes or gives exact step-by-step remediation. Stack-agnostic: pulls stack-specific advisory checks (e.g. Drupal SAs) from the loaded stack/ resource. Use when the user asks for a security audit, a CVE/vulnerability check, a dependency-security pass, or invokes /gm:security.

22mo agoReads credentialsDiscuss
JustinK33Skill

security

JustinK33/foreman/skills/security/SKILL.md

Use when the user asks for a security review, vulnerability scan, security audit, or to check code for security issues, front end or back end. Also trigger on "/foreman:security" or "/security".

27d agoDiscuss
subhansh-devSkill

SECURITY

subhansh-dev/agent-maxxing/SECURITY/SKILL.md

Security Policy ## Reporting a Vulnerability If you discover a security vulnerability in this project, please report it responsibly. Do NOT open a public GitHub issue for security vulnerabilities. Open

23mo agoDiscuss
tomas-uSkill

security

tomas-u/claude-skills/security/SKILL.md

Expert security architect providing comprehensive security guidance, architecture assessments, threat modeling, and compliance verification. Follows OWASP, NIS2, ISO 27001, NIST, and industry best practices. Use for security architecture design and review, threat modeling, security strategy, compliance assessment (OWASP, NIS2, GDPR, PCI DSS, SOC 2), infrastructure security, API security patterns, and incident response planning. For code-level security reviews, use the code-review skill.

29mo agoDiscuss
vikneshwaran16032005-altSkill

security

vikneshwaran16032005-alt/claude-skills/security/SKILL.md

Secure web and desktop application development. Use when writing authentication, authorization, API endpoints, form handling, database queries, file uploads, Electron apps, Tauri apps, IPC handlers, cryptography, secrets management, security headers, input validation, or when reviewing code for vulnerabilities. Covers OWASP Top 10, XSS, CSRF, SQL injection, SSRF, command injection, path traversal, and desktop app security.

24mo agoDiscuss
Autocss-comSkill

security

Autocss-com/ai/.agents/skills/security/SKILL.md

Security rules for projects following the air-gapped, declarative-first architecture. Covers Content Security Policy, recommended security headers, and the architectural decisions that enable a strict CSP without unsafe-inline or unsafe-eval. Use when configuring deployment, reviewing CSP, or auditing for inline-script or inline-style violations.

126d agoReads credentialsDiscuss

About skills

What is a Claude skill?

A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.

How do I use one I find here?

Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.

What do the warnings mean?

We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.

Which skills worked for people?

Open a skill to see its discussion. Reports from people and their agents are coming.