security-audit
Wang200935/security-agent-skills/skills/cloud-security/security-audit/SKILL.md
Security audit of a codebase — web apps, APIs, services, CLI tools, libraries,
Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.
Wang200935/security-agent-skills/skills/cloud-security/security-audit/SKILL.md
Security audit of a codebase — web apps, APIs, services, CLI tools, libraries,
xsourabhsharma/ai-security-audit-pro/skills/security-audit/SKILL.md
Defensive web and web-application security auditing for local projects, localhost, staging, and authorized public/private websites. Use when the user asks to audit, scan, review, find vulnerabilities, check OWASP issues, inspect security headers, assess APIs, or produce a security report for a website or web app.
thejefflarson/soundcheck/.claude/skills/security-review/SKILL.md
Runs a full OWASP/CWE security audit via isolated subagents. Use when the user
louisbrulenaudet/monorepo-template/.agents/skills/review-security/SKILL.md
Security-focused review. USE WHEN: user runs /review-security or explicitly asks for this review. DO NOT USE WHEN: implementing features or fixing bugs unless the user asked for a review.
mhylle/claude-skills-collection/skills/security-review/SKILL.md
Comprehensive security audit for code changes. Use this skill when implementing authentication, authorization, user input handling, API endpoints, secrets/credentials, payment features, or file uploads. Provides security checklists, vulnerability patterns, and remediation guidance. Integrates with implement-phase as a security quality gate.
AndrewDryga/emisar/.claude/skills/security-engineer/SKILL.md
Put on the security-engineer hat for emisar — threat-model and harden anything touching auth, runner trust, MCP, policies, approvals, audit, or untrusted input. Use when reviewing or building auth/session/MFA, the runner socket, the MCP API, policy evaluation, approval flows, audit logging, secret handling, or any code that ingests runner/LLM input. emisar IS a security product — this hat is mandatory there.
NoorQureshi/ronin/skills/ai-ml/ai-mcp-security/SKILL.md
Assess Model Context Protocol (MCP) servers and agent tool integrations — tool poisoning, prompt injection via tool descriptions/results, over-broad scopes, and unauth tool exposure. Load when the target uses MCP servers, agent tool/function integrations, or connectors. Signals: mcp.json, MCP server, tool schemas, connector marketplace, agent with external tools.
harperaa/secure-claude-skills/security-overview/SKILL.md
Understand the defense-in-depth security architecture of Secure Vibe Coding OS. Use this skill when you need to understand the overall security approach, the 5-layer security stack, OWASP scoring, or when to use other security skills. Triggers include "security architecture", "defense in depth", "security layers", "how does security work", "OWASP score", "security overview", "security principles".
awarexone/AXguard/security-triage/SKILL.md
Domain reasoning for triaging AXguard findings — keep/drop gates, confidence, and severity promotion before remediation.
caiaffa/claude-code-ultimate-engineering-system/skills/security-review/SKILL.md
Review code, APIs, infrastructure, IAM, secrets, and data handling for practical application and platform security risks.
getlarge/themoltnet/skills/security-review/SKILL.md
MANDATORY procedure for any pr_review task whose rubric is `pr-security-v1` or whose prompt asks for a security review. Read this skill FIRST before reading the PR diff. Defines the sequential recon → hunt → self-validate → trace → dedup → report pipeline a single agent must run against a PR. Without it, the review will be incomplete and the structured output will be rejected.
yusupsupriyadi/claude-code-mastering/.claude/skills/security-review/SKILL.md
Performs comprehensive security review of code changes. Automatically activates when reviewing authentication, authorization, data handling, input validation, encryption, or when user mentions security audit, vulnerability, or penetration testing. Keywords: security, auth, authentication, authorization, jwt, token, vulnerability, injection, xss, csrf, owasp
nahisaho/MUSUBI/.claude/skills/security-auditor/SKILL.md
security-auditor skill
0xmortuex/claude-code-skills/skills/security-sweep/SKILL.md
Review the working changes (or a named set of files) for real, exploitable security problems — injection, authz gaps, secret leaks, unsafe deserialization, SSRF, path traversal, and the like — and report only findings you can justify with a concrete attack path. Use this whenever the user asks for a security review, a "security check", wants to know if a change is safe to ship, is touching auth/crypto/file-uploads/user-input/database queries, or says things like "any vulnerabilities here", "is this exploitable", "audit this endpoint". Also use before shipping code that handles untrusted input or secrets.
alexpate/devtool-skills/skills/security-page/SKILL.md
Build a credible security/trust page for a developer tool before SOC 2 — concrete controls, encryption specifics, subprocessor list, responsible disclosure, data lifecycle, and honest scoping of what you can claim. Use when the user wants a security page, trust page, or trust center, asks "do we need SOC 2", got a vendor security questionnaire, or is losing deals to security review. Also use when they mention a DPA, subprocessors, security.txt, responsible disclosure, or "enterprise readiness", even if they never say "security page".
Bobagi/claude-skills/security-sweep/SKILL.md
Varredura de segurança agnóstica a projeto que ENCONTRA, TESTA ao vivo (adversarialmente) e CORRIGE vulnerabilidades — não só reporta. Cobre race conditions/TOCTOU, IDOR/autorização, enumeração de usuário, injeção (SQL/command), SSRF, upload, XSS, segredos, sessão/auth, crypto, exposição de dados e lógica de negócio, contra uma rubric versionada que cresce a cada uso. Use quando o usuário pedir "varredura de segurança", "faça um pentest", "está seguro?", "audite a segurança", "verifique vulnerabilidades", ou ao final de QUALQUER feature que toque autenticação, dinheiro, permissões, input do usuário, upload ou dados sensíveis.
bt2go/claude-skills/skills/security-pass/SKILL.md
Use when the user wants a security check of a diff, an endpoint, or code handling input, auth or secrets.
conjure-3301/skills/cicd-security/SKILL.md
CI/CD security testing for GitHub Actions injection, workflow poisoning, artifact tampering, secret extraction, and OIDC token theft
Dimks777/aiclub/skills/skill-security/SKILL.md
Аудит безопасности скиллов OpenClaw. Сканирование, trust score, проверка перед установкой.
ficaviolaodorata520/met-museum-mcp-server/skills/security-pass/SKILL.md
Review an MCP server for common security gaps: LLM-facing surfaces as injection vector (tools, resources, prompts, descriptions), scope blast radius, destructive ops without consent, upstream auth shape, input sinks (URL / path / roots / shell / sampling / schema strictness / ReDoS), tenant isolation, leakage through errors and telemetry, unbounded resources, and HTTP-mode deployment surface. Use before a release, after a batch of handler changes, or when the user asks for a security review, audit, or hardening pass. Produces grouped findings and a numbered options list.
A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.
Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.
We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.
Open a skill to see its discussion. Reports from people and their agents are coming.