agentleFS
Sign inSign up

Claude skills and agent skills

Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.

Best matches · from page 4Worked for most · soon
ngnthanhdevSkill

security

ngnthanhdev/claude_template_code/.claude/skills/security/SKILL.md

The single security skill — diff/PR audit method with a high-confidence bar (BOLA/IDOR, mass assignment, DTO validation, injection, secrets, rate limiting), STRIDE threat modeling before large features, backend auth hardening (guards, Passport, RBAC, CORS/CSRF, OWASP ASVS), and mobile hardening (MASVS: token storage, deep links, WebView, build config). Load the SKILL.md for routing, then read ONLY the references/ file matching the job.

041d agoDiscuss
ReaperOAKSkill

security

ReaperOAK/ForgeOS/.claude/skills/security/SKILL.md

Security best practices including STRIDE threat modeling, OWASP Top 10, agentic guardrails, and vulnerability assessment guidelines.

04mo agoDiscuss
soreavisSkill

security

soreavis/ai-docent/skills/security/SKILL.md

Multi-session defensive security coach: prompt injection, data leaks, agent safety, and incident response, taught with inert examples. Use only when asked to start or continue this course.

014d agoDiscuss
syntropic137Skill

security

syntropic137/harness-app-template/.claude/skills/security/SKILL.md

Use when reviewing security concerns: secrets in code, SAST coverage, input validation, authn/authz boundaries, sensitive-data handling, dependency CVEs, SSRF, hand-rolled escaping, threat modeling for high-stakes changes, defense in depth, agentic-AI / LLM tool-call attack surface (prompt injection, indirect injection, MCP abuse)

04mo agoReads credentialsDiscuss
syntropic137Skill

security

syntropic137/software-leverage-points/skills/security/SKILL.md

Use when reviewing security concerns: secrets in code, SAST coverage, input validation, authn/authz boundaries, sensitive-data handling, dependency CVEs, SSRF, hand-rolled escaping, threat modeling for high-stakes changes, defense in depth, agentic-AI / LLM tool-call attack surface (prompt injection, indirect injection, MCP abuse)

033d agoReads credentialsDiscuss
ThuPhuong1010Skill

security

ThuPhuong1010/claude-factory/.claude/skills/security/SKILL.md

Security patterns. Trigger khi code auth, handle user input, thiết kế hệ thống có dữ liệu nhạy cảm.

06mo agoDiscuss
SentrySkill

sentry-security

getsentry/sentry/.agents/skills/sentry-security/SKILL.md

Sentry-specific security review based on real vulnerability history. Use when reviewing Sentry endpoints, serializers, or views for security issues. Trigger keywords: "sentry security review", "check for IDOR", "access control review", "org scoping", "cross-org", "security audit endpoint".

45k3mo agoDiscuss
hypnguyen1209Skill

ai-security

hypnguyen1209/offensive-claude/skills/ai-security/SKILL.md

Use when attacking an AI/ML system or model — prompt injection & jailbreaks (Crescendo, Skeleton Key, Best-of-N), RAG/vector poisoning, agentic/MCP exploitation (CVE-2025-54136), ML supply-chain RCE (pickle CVE-2025-32434), model extraction / membership inference / adversarial suffixes (GCG)

38210d agoDiscuss
mizchiSkill

sql-security

mizchi/skills/sql-security/SKILL.md

SQL injection screening for host code (MoonBit / TS / Rust) plus secretlint setup notes. Flags single-line template-literal or string-concat SQL builders, regardless of value source — the scanner is line-based and does NOT trace data flow, so a clean scan is not proof of safety (multi-line template literals are missed) and every hit needs a manual review or an explicit `// sql-security: ok` opt-out.

3483mo agoDiscuss
AWSSkill

aws-security

aws/agent-toolkit-for-aws/plugins/aws-core/skills/aws-security/SKILL.md

Covers AWS security services and workflows — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules, and security posture summaries; Security Hub CSPM (V1/ASFF) controls and compliance standards; GuardDuty threat findings; Inspector vulnerability findings; Macie sensitive data findings; Detective investigation; and Security Lake configuration and data aggregation. Applicable when questions involve security posture, Exposure findings, CSPM failed controls, threat findings, vulnerability findings, sensitive data findings, automation rules, or cross-service security configuration across AWS environments. Procedures use standard AWS CLI syntax and work with or without the AWS MCP server.

2.7k4mo agoDiscuss
MicrosoftSkill

dv-security

microsoft/Dataverse-skills/.github/plugins/dataverse/skills/dv-security/SKILL.md

Security-role assignment, user access, application users, business units, and admin self-elevation in Dataverse environments. Use when the user wants to give someone access, grant a role, become an admin, or add a service principal.

23312d agoDiscuss
wgpsecSkill

mcp-security

wgpsec/AboutSecurity/skills/ai-security/mcp-security/SKILL.md

MCP (Model Context Protocol) 协议安全测试方法论。当目标环境使用 MCP Server 集成外部工具、 需要评估 MCP 工具描述安全性、或测试 Agent 通过 MCP 调用工具时的安全边界时触发。 覆盖: 工具描述投毒、地毯式骗局(动态篡改)、指令覆盖(Shadow Tool)、隐藏指令(ANSI/Unicode)、 跨 Server 攻击、Token 窃取、Schema 操纵、上下文溢出。

1.8k4mo agoDiscuss
rodrigohighermindSkill

hm-security

rodrigohighermind/highermind-code-skills/hm-security/SKILL.md

Auditoria de segurança profunda (L1/L2/L3). Use antes de deploy externo, após adicionar auth/dados sensíveis/fluxo financeiro, ou periodicamente como manutenção. Cobre 14 domínios — CIS Docker, OWASP Top 10, OWASP API Top 10, ASVS AuthN/Session, dados/compliance (LGPD/GDPR/PCI), supply chain, AI/LLM (prompt injection, tool calling, multi-tenant LLM), file upload, business logic, secrets scan com 20+ patterns, Supabase/PostgREST RLS regime absoluto. Barra Tempest / Trail of Bits / Cure53.

1924mo agoReads credentialsDiscuss
ruvnetSkill

security-audit

ruvnet/ruflo/.agents/skills/security-audit/SKILL.md

Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment processing, user data handling, API endpoint creation, file upload handling, database queries, external API integration. Skip when: read-only operations on public data, internal development tooling, static documentation, styling changes.

73k21d agoDiscuss
jiten-singh-shahiSkill

sf-security

jiten-singh-shahi/salesforce-claude-code/.cursor/skills/sf-security/SKILL.md

Use when implementing Salesforce Apex security — CRUD/FLS enforcement, sharing keywords, SOQL injection prevention, AppExchange review prep. Do NOT use for general Apex or LWC patterns.

156mo agoDiscuss
hardw00tSkill

sca-security

hardw00t/ai-security-arsenal/skills/sca-security/SKILL.md

Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to suppress unexploitable findings. Use when scanning package dependencies (npm, PyPI, Maven, Cargo, Go, RubyGems, Composer), reviewing PR lockfile diffs, generating SBOMs, auditing licenses, hunting malicious packages, or auditing the software supply chain. Triggers on requests to scan dependencies, check vulnerable packages, generate SBOM, license compliance, typosquat/dependency-confusion review, or reachability-based vuln triage.

1016mo agoDiscuss
PostHogSkill

security-audit

PostHog/posthog/.agents/skills/security-audit/SKILL.md

Focused security audit of code, calibrated to surface real exploitable bugs and suppress theoretical findings. Use when the user asks to "audit", "security-audit", "find vulnerabilities", "check for IDOR/SSRF/XSS/injection", or wants a security review of a file, directory, branch diff, or PR. Covers access control, injection, auth/secrets, sensitive data, business logic, web boundary, and AI agent/LLM trifecta risks. Produces calibrated findings with data flow, exploit request, fix, and confidence — no theoretical or defense-in-depth nits.

40k5d agoReads credentialsDiscuss
awarexoneSkill

cicd-security

awarexone/Agentic-Bug-Hunter/skills/cicd-security/SKILL.md

CI/CD pipeline security hunting — GitHub Actions workflow injection, secret exfiltration, self-hosted runner poisoning, dependency confusion, OIDC token theft, and supply chain attacks. Covers sisakulint scanning, manual workflow analysis, and chaining CI/CD bugs into critical findings. Use when a target has public repos, GitHub Actions, CircleCI, Jenkins, or GitLab CI.

5.2k4mo agoPipes a download into a shellDiscuss
zhaoxuya520Skill

email-security

zhaoxuya520/reverse-skill/skills/email-security/SKILL.md

Use for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research.

38k9d agoDiscuss
affaan-mSkill

security-review

affaan-m/ECC/.agents/skills/security-review/SKILL.md

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

246k30d agoReads credentialsDiscuss
CLAUDE.md vs AGENTS.md

About skills

What is a Claude skill?

A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.

How do I use one I find here?

Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.

What do the warnings mean?

We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.

Which skills worked for people?

Open a skill to see its discussion. Reports from people and their agents are coming.