agentleFS
Sign inSign up

Claude skills and agent skills

Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.

Best matches · from page 3Worked for most · soon
BappozSkill

security

Bappoz/My-Claude-Skills/skills/engineering/security/SKILL.md

Segurança de aplicações production-grade: OWASP Top 10, autenticação/autorização, gestão de segredos, threat modeling (STRIDE), validação de input e secure defaults. Use quando o usuário mencionar: "segurança", "vulnerabilidade", "OWASP", "autenticação", "autorização", "SQL injection", "XSS", "CSRF", "segredos", "threat model", "é seguro?", "hardening", "pentest". Não auxilia ataques maliciosos — foco em defesa e testes autorizados.

13mo agoDiscuss
efficience-itSkill

security

efficience-it/claude-skills-php/.claude/skills/security/SKILL.md

Audit de sécurité rapide pour projet PHP/Symfony. Analyse les fichiers modifiés ou un périmètre donné. Détecte injections SQL, XSS, CSRF, exposition de données, permissions manquantes. Basé sur OWASP Top 10. Utiliser avant un commit ou pour auditer un périmètre.

16mo agoReads credentialsDiscuss
ksed8Skill

security

ksed8/cc-loopkit/.claude/skills/security/SKILL.md

Security audits and threat modeling — find and reason about vulnerabilities in auth, input handling, data access, secrets, and dependencies. Use when reviewing code for security, threat-modeling a feature, hardening an endpoint, handling auth/authz, or checking for injection, secret leakage, or unsafe data exposure. For a focused review of the current diff, prefer the `/security-review` command.

13mo agoDiscuss
michaelsvanbeekSkill

security

michaelsvanbeek/personal-agent-skills/skills/security/SKILL.md

Application security standards and hardening practices. Use when: reviewing code for vulnerabilities, implementing authentication, configuring CORS, adding input validation, managing secrets, scanning dependencies, setting CSP headers, reviewing IAM policies, auditing an existing application for OWASP top 10 vulnerabilities, or hardening an existing deployment. Covers OWASP top 10, secrets management, dependency auditing, and security headers.

16mo agoReads credentialsDiscuss
OpenAISkill

security-scan

openai/codex-security/plugins/codex-security/skills/security-scan/SKILL.md

Use for a standard, single-pass security audit of an entire repository or a scoped path, package, folder, or submodule with no diff to review. This is the default repository scan. Do not use for PR, commit, branch, or working-tree diffs, or for deep, multi-pass scans.

11k20d agoDiscuss
withkynamSkill

vc-security

withkynam/vibecode-pro-max-kit/.claude/skills/vc-security/SKILL.md

STRIDE + OWASP-based security audit with optional auto-fix. Scans code for vulnerabilities, categorizes by severity, and can iteratively fix findings using vc-autoresearch pattern.

1.1k3mo agoDiscuss
ArthurZakirovSkill

security

ArthurZakirov/SystemSmith/skills/security/SKILL.md

Mandatory credential protection skill for all agents. Prevents reading, exposing, or leaking credentials, secrets, API keys, tokens, passwords, and auth-capable config files.

05mo agoReads credentialsDiscuss
blueOctopusAISkill

security

blueOctopusAI/intel-hub/.claude/skills/security/skill.md

Security Auditor Evaluate security implications of tools, configurations, plugins, and the intelligence hub itself. ## Input `/security [target]` Targets: - No argument: full hub audit - A tool name: evaluate that specific tool

08mo agoReads credentialsDiscuss
bmarshall511Skill

security

bmarshall511/Trellis/.claude/skills/security/SKILL.md

Use when handling user input, authentication, authorisation, secrets, file uploads, or database queries. Also when adding a dependency, exposing an endpoint, or reviewing whether something is safe to ship.

050d agoDiscuss
CarriedWorldUniverseSkill

security

CarriedWorldUniverse/nexus/.agents/skills/security/SKILL.md

Secure-coding rules for nexus + the vulnerability/secret/SAST scan gate run at review and merge.

07d agoDiscuss
danielgefenSkill

security

danielgefen/sous/skills/security/SKILL.md

Adversarial security gate. Reviews the change for vulnerabilities and tries to exploit them against a local environment. A confirmed exploit blocks the merge. Runs after merge-risk, before qa. Usage - /sous:security <change-id>

036d agoDiscuss
Geoffe-GaSkill

security

Geoffe-Ga/well-worn-tools/.claude/skills/security/SKILL.md

Implement secure coding practices against common vulnerabilities. Use when handling user input, file paths, subprocess calls, SQL queries, API keys, or building web endpoints. Covers input validation, injection prevention, secret management, and XSS/CSRF protection across Python, TypeScript, Go, and Rust. Do NOT use for general error handling (use error-handling skill) or for remediating dependency vulnerability scanner failures and CVE / GHSA advisories (use cve-remediation skill).

03mo agoDiscuss
jack1415926Skill

security

jack1415926/claude-skills/skills/security/SKILL.md

Create security architecture diagrams using PlantUML syntax with identity, encryption, firewall, and compliance stencil icons. Best for IAM flows, zero-trust models, encryption pipelines, and threat detection architectures.

048d agoDiscuss
jessedegansSkill

security

jessedegans/jstack/skills/security/SKILL.md

Use when reviewing code for security vulnerabilities, before shipping to production, or when the user asks for a security audit. Runs OWASP Top 10 + STRIDE analysis with a strict false positive filter. Confidence gate at 8/10. No theoretical hand-waving.

06mo agoDiscuss
jorekaiSkill

security

jorekai/skills/skills/security/security/SKILL.md

Choose the next security skill for a new repository, a weekly sweep, or a leaked credential. Explains priorities, safeguards before each fix, and how to measure its result.

023d agoDiscuss
LeostrukaSkill

security

Leostruka/devin-bundle/skills/security/SKILL.md

Use when auditing code, dependencies, or infrastructure for security issues (SAST, dependency scanning, secret leak detection, OWASP-style checks), or when checking that a project or change follows secure defaults before committing or deploying.

046d agoReads credentialsDiscuss
lgzarturoSkill

security

lgzarturo/codeconductor/.agents/skills/security/SKILL.md

Provides expert knowledge for implementing and reviewing application security following OWASP Top 10 (2021), with stack-specific patterns for Spring Boot, Django, Next.js, and Astro.

015d agoReads credentialsDiscuss
lgzarturoSkill

security

lgzarturo/codeconductor/.cursor/skills/security/SKILL.md

Provides expert knowledge for implementing and reviewing application security following OWASP Top 10 (2021), with stack-specific patterns for Spring Boot, Django, Next.js, and Astro.

015d agoReads credentialsDiscuss
mj-devingSkill

Security

mj-deving/pai-skills/skills/Security/SKILL.md

Security assessment — network recon, web app testing, prompt injection testing, security news, and vulnerability scanning. USE WHEN recon, port scan, subdomain, DNS, WHOIS, pentest, threat model, OWASP, prompt injection, LLM security, security news, trivy, CVE, vulnerability scan, sops, encrypt secrets.

05mo agoDiscuss
muxammadmamajonovSkill

security

muxammadmamajonov/dot-claude/.claude/skills/security/SKILL.md

Threat-model, harden, and security-review any feature — STRIDE, secrets/auth/authz, pre-launch audit. Triggers — sessions, tokens, file upload, CVEs, CORS, 'is this secure', 'threat model', OWASP.

03mo agoReads credentialsDiscuss
CLAUDE.md vs AGENTS.md

About skills

What is a Claude skill?

A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.

How do I use one I find here?

Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.

What do the warnings mean?

We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.

Which skills worked for people?

Open a skill to see its discussion. Reports from people and their agents are coming.