Use automatically when the user works on auth, payments, API keys, environment variables, Supabase RLS, permissions, user data, uploads, public endpoints, webhooks, admin panels, dependencies, production config, or asks whether something is secure enough.
Unified security authority and governance engine for the agency: CVE vulnerability triage, automated remediation playbooks, Cloud WAF architectures (GCP/Cloudflare 6 pillars), static application security testing (SAST), and runtime defense guardrails — routed through six modes. Trigger when asked to: 'run a security audit', 'check for CVEs', 'audit cloud WAF', 'remediate vulnerabilities', 'SAST review', 'test cloud armor', or 'harden infrastructure security'. Not for day-to-day web development coding (webdev) or routine deployment pipelines (devops).
Your chill security buddy. Audits and actively stress-tests a web app like a real attacker would — then writes up findings with severity, repro steps, and fixes. Covers secrets archaeology, dependency supply chain, CI/CD pipeline, auth, authz, OWASP Top 10, LLM/prompt-injection, rate limit + DoS fuzzing, CSRF/CORS/headers, SSRF, file upload, and session hygiene. Produces a prioritized report, not theater. Use when: "security dude", "security audit", "stress test", "pentest this", "find vulnerabilities", "attack my app", "threat model".
Security scanner for SvelteKit + TS repos — finds and fixes one exploitable issue per run, verified before/after with typecheck, lint, and tests. Use when auditing security, checking for XSS/authz/token leaks, hardening before release, or reviewing auth/session/broadcast code for leakage. Covers core checks (XSS, secrets, authn/authz, CSP) plus opt-in module packs for auth, validation, realtime, data, and feature-flags when active in .claude/tend/config.yaml. Not for style/architecture review or performance work — see tend-refactor or tend-perf for those.
Audit and centralise security controls using the spine pattern — every control enforced at exactly one chokepoint and defended by a test. 22 vertebrae with checkable control ids - authentication, sessions/tokens, authorization and tenant isolation, credentials/secrets/.env files, injection, error disclosure, rate limiting and abuse, security headers/CORS/CSRF middleware, cryptography, SSRF/egress, uploads, webhooks, queues, data protection, AI/agent and MCP security, logging, supply chain, deployment hardening, account recovery, business-logic races, incident readiness. Use for security audits, hardening, pre-merge security review, consolidating rate limiters or middleware, auditing env and credentials, responding to a leaked secret, or mapping controls to OWASP Top 10, API Security Top 10 and LLM Top 10. Builds on the spine skill.
Security and crash-prevention skill for React Native and Expo mobile apps. MUST be loaded when the task touches: auth flows, token handling, login/logout, session management, secure storage, API request construction, deep links, push notification handlers, WebViews, input validation, error handling, crash prevention, error boundaries, secrets, environment variables, certificate pinning, TLS configuration, biometric authentication, rate limiting, brute-force protection, dependency auditing, LLM/AI feature integration, or production hardening. Also load when reviewing AI-generated code that touches networking, storage, or auth. This skill exists because mobile clients are untrusted devices and the backend is the only trust boundary — do not skip loading it because the task "looks small". Version 1.1.0.
Audit and harden basic security on a Debian/Ubuntu server over SSH — system updates, non-root sudo user, SSH key authentication, sshd hardening, UFW firewall, unattended-upgrades, fail2ban, sudo and home directory permissions. Use this whenever the user mentions auditing a server, hardening SSH, locking down a VPS, checking server security, configuring ufw, setting up fail2ban, securing a new server, or asks "is my server secure" / "what should I do to my new VPS" — even when they don't use the word "audit". Always produces a read-only audit report first, then applies fixes only after explicit confirmation, with a fail-safe automatic rollback for SSH configuration changes so the user cannot get locked out.
Dev-time security audit of KarvyLoop's OWN source (twin of /code-review, but for security). Use when asked to "audit the security of these changes", "审这轮改动的安全", "security review this endpoint/diff", or before landing anything that touches the untrusted-input frontier (new API endpoints, URL/file fetch, tool authorization, sandbox, LLM output that reaches a persistent store or the shell). Runs a multi-agent adversarial audit — parallel discovery agents, then ≥3 refutation passes per finding (keep only if ≥2/3 say REAL) — and REPORTS ONLY; it never edits code. Not a KarvyLoop product feature.
Find Next.js-specific security issues across App Router, Pages Router, and Server Actions. Covers the middleware-bypass class, NEXT_PUBLIC environment leakage, RSC over-fetch, CSP for App Router, open redirects, and next/image SSRF via permissive remotePatterns. Invoke when reviewing a Next.js app before launch, after a major version upgrade, or when adding authenticated routes.
Run AgentHub's security sweep with parallel finders, adversarial verification, adjudication, and a report before fixes. Use for a whole-repository audit or a security review of a named path or theme.
Deep adversarial security audit engine for full-stack web applications. Use this skill when the user wants to audit a codebase for security vulnerabilities, broken access control, injection risks, authentication weaknesses, payment security, file upload exploits, IDOR, CSRF, SSRF, RLS bypass, business logic abuse, rate limiting gaps, or deployment security issues. Trigger whenever the user says "audit my security", "find vulnerabilities", "pen test my app", "is this secure", "check for IDOR", "harden my auth", "review my payment flow for exploits", "can someone bypass this", "what can an attacker do", or shares code and asks about security, exploits, or hardening. Also trigger proactively when reviewing any app that handles auth, payments, file uploads, admin routes, or user-generated content — even if the user doesn't use the word "security".
Use this skill to perform a security audit, scan for vulnerabilities, check OWASP Top 10 issues, or review code for security problems. Triggered by "security audit", "check security", "find vulnerabilities".
Perform standalone security audits covering OWASP Top 10, dependency scanning, secret detection, input validation, and authentication review. Use when: the user asks for a security review, vulnerability assessment, audit, or wants to check for security issues in code or dependencies. Do NOT use when: the user wants a general code review (use pr-review), is asking about deploying to production, or wants penetration testing guidance.
Use when auditing code for security vulnerabilities, reviewing auth, permissions or Firestore/Storage rules, before a release or store submission, after a pentest or bug report, when handling secrets, tokens or PII, or when asked "is this secure", "find security holes", "check for vulnerabilities", or "review my rules". Deepest on Flutter + Firebase (Firestore, Storage, Cloud Functions, App Check); the method works on any stack.
Run a security audit (dependencies, secrets, auth, inputs). Use when the user asks for a security review, dependency audit, or to check for vulnerabilities and hardcoded secrets.
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching tools miss. Use this skill when asked to scan code for security vulnerabilities, find bugs, check for SQL injection, XSS, command injection, exposed API keys, hardcoded secrets, insecure dependencies, access control issues, or any request like \"is my code secure?\", \"review for security issues\", \"audit this codebase\", or \"check for vulnerabilities\". Covers injection flaws, authentication and access control bugs, secrets exposure, weak cryptography, insecure dependencies, and business logic issues across JavaScript, TypeScript, Python, Java, PHP, Go, Ruby, and Rust.
A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.
How do I use one I find here?
Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.
What do the warnings mean?
We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.
Which skills worked for people?
Open a skill to see its discussion. Reports from people and their agents are coming.