agentleFS
Sign inSign up

Claude skills and agent skills

Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.

Best matches · from page 5Worked for most · soon
DonchitosSkill

security-audit

Donchitos/Claude-Code-Game-Studios/.claude/skills/security-audit/SKILL.md

Security audit — save tampering, cheat vectors, network exploits, data exposure, input validation. Before public or multiplayer release.

25k8d agoDiscuss
arcasilesgroupSkill

ai-security

arcasilesgroup/ai-engineering/skills/ai-security/SKILL.md

Six-phase security audit of a codebase — web apps, APIs, services, CLI tools, libraries, and daemons — with adversarial validation: the agent that verifies a finding is never the one that found it. Recon, parallel hunting across 8 attack classes, validation, reporting, schema-validated findings.json, and independent verification. Only exploitable issues with real impact are reported — never theoretical concerns or industry-standard behavior. Use when a milestone declares a security audit, when findings must be validated adversarially, or for trigger phrases "security review", "audit for vulnerabilities", "find security bugs", and "pen-test the code". Not for diagnosing a runtime failure — use /ai-debug. Not for judging a diff for correctness — use /ai-verify.

5829d agoDiscuss
kingxiaozheSkill

cm-security

kingxiaozhe/cm-workflow/skills/cm-security/SKILL.md

用户运行 cm-security,或要求代码安全扫描、漏洞检查、密钥泄露排查、依赖漏洞检查时使用。默认检查当前分支相对主分支及已跟踪未提交修改,结合业务地图复核;--all 检查全部已跟踪文件。只报告问题,不自动修复、安装、升级或发布。安装自检用 cm-check,功能测试与覆盖率用 cm-test。

5516d agoDiscuss
CloudflareSkill

security-audit

cloudflare/security-audit-skill/skills/security-audit/SKILL.md

Security guidance and vulnerability review for codebases, APIs, services, CLI tools, libraries, and daemons. Use for security questions, focused reviews, vulnerability research, security audits, or pen tests. Run the complete workflow only for explicit codebase audit or pen-test requests, full/comprehensive/end-to-end reviews, or requested report artifacts.

18k16d agoDiscuss
loulanyueSkill

security-scan

loulanyue/awesome-claude-notes/skills/security-scan/SKILL.md

Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions.

2726mo agoReads credentialsDiscuss
MindrallySkill

jwt-security

Mindrally/skills/jwt-security/SKILL.md

Guidelines for implementing JWT authentication with security best practices for token creation, validation, and storage

2588mo agoDiscuss
nirholasSkill

okx-security

nirholas/three.ws/.agents/skills/okx-security/SKILL.md

Use this skill for security scanning: check transaction safety, is this transaction safe, pre-execution check, security scan, token risk scanning, honeypot detection, DApp/URL phishing detection, message signature safety, malicious transaction detection, approval safety checks, token approval management. Triggers: 'is this token safe', 'check token security', 'honeypot check', 'scan this tx', 'scan this swap tx', 'tx risk check', 'is this URL a scam', 'check if this dapp is safe', 'phishing site check', 'is this signature safe', 'check this signing request', 'check my approvals', 'show risky approvals', 'revoke approval', 'check if this approve is safe', token authorization, ERC20 allowance, Permit2. Covers token-scan, dapp-scan, tx-scan (EVM+Solana pre-execution), sig-scan (EIP-712/personal_sign), approvals (ERC-20/Permit2). Chinese: 安全扫描, 代币安全, 蜜罐检测, 貔貅盘, 钓鱼网站, 交易安全, 签名安全, 代币风险, 授权管理, 授权查询, 风险授权, 代币授权. Do NOT use for wallet balance/send/history — use okx-agentic-wallet.

21711d agoDiscuss
raroqueSkill

vibe-security

raroque/vibe-security-skill/vibe-security/SKILL.md

Audits codebases for common security vulnerabilities that AI coding assistants introduce in "vibe-coded" applications. Checks for exposed API keys, broken access control (Supabase RLS, Firebase rules), missing auth validation, client-side trust issues, insecure payment flows, and more. Use this skill whenever the user asks about security, wants a code review, mentions "vibe coding", or when you're writing or reviewing code that handles authentication, payments, database access, API keys, secrets, or user data — even if they don't explicitly mention security. Also trigger when the user says things like "is this safe?", "check my code", "audit this", "review for vulnerabilities", or "can someone hack this?".

9967mo agoReads credentialsDiscuss
Strategic-AutomationSkill

llm-security

Strategic-Automation/violin/skills/llm-security/SKILL.md

Test LLM prompt injection and MCP tool/agent surfaces.

1388d agoDiscuss
Hassaan146Skill

ai-security

Hassaan146/claude-skills/ai-security/SKILL.md

Use when assessing AI/ML systems for prompt injection, jailbreak vulnerabilities, model inversion risk, data poisoning exposure, or agent tool abuse. Covers MITRE ATLAS technique mapping, injection signature detection, and adversarial robustness scoring.

182mo agoDiscuss
luongnv89Skill

security-setup

luongnv89/skills/skills/security-setup/SKILL.md

Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI. Use when hardening repos or adding security hooks. Don't use for incident response or cloud security reviews.

1274d agoReads credentialsDiscuss
GitHubSkill

security-review

github/awesome-copilot/skills/security-review/SKILL.md

AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching tools miss. Use this skill when asked to scan code for security vulnerabilities, find bugs, check for SQL injection, XSS, command injection, exposed API keys, hardcoded secrets, insecure dependencies, access control issues, or any request like "is my code secure?", "review for security issues", "audit this codebase", or "check for vulnerabilities". Covers injection flaws, authentication and access control bugs, secrets exposure, weak cryptography, insecure dependencies, and business logic issues across JavaScript, TypeScript, Python, Java, PHP, Go, Ruby, and Rust.

39k8d agoReads credentialsDiscuss
AnthropicSkill

claude-security

anthropics/claude-plugins-official/plugins/claude-security/skills/claude-security/SKILL.md

Claude Security: scan the codebase (the whole repository or a scoped part of it), scan changes (this branch's or a pull request's diff, or one commit), or suggest patches (findings turned into targeted patch files, each verified by a panel of agents, that you apply when you choose). Use when the user asks to scan, audit or check code with Claude Security, to scan their changes with Claude Security, or to fix or patch Claude Security findings.

37k7mo agoDiscuss
hardw00tSkill

api-security

hardw00t/ai-security-arsenal/skills/api-security/SKILL.md

Router skill for API penetration testing across REST, GraphQL, gRPC, and WebSocket. Covers OWASP API Top 10 (2023) including BOLA/BFLA/BOPLA, JWT attack chains, GraphQL introspection abuse, and mass assignment. Invoke when the user asks to pentest an API, analyze OpenAPI/Swagger, test auth/authorization, fuzz endpoints, or find API vulnerabilities.

1016mo agoDiscuss
hardw00tSkill

iac-security

hardw00t/ai-security-arsenal/skills/iac-security/SKILL.md

Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep. Orchestrates Checkov, tfsec, Terrascan, KICS, kubesec, kube-linter, Polaris, cfn-lint/cfn-nag, and OPA/Conftest. Use when auditing IaC for misconfigurations, scanning Terraform plans, validating K8s security policies, checking cloud infrastructure compliance, or authoring custom policy-as-code (Rego).

1016mo agoDiscuss
hardw00tSkill

llm-security

hardw00t/ai-security-arsenal/skills/llm-security/SKILL.md

LLM and AI application security testing skill for prompt injection (direct, indirect, multimodal), system-prompt extraction, RAG poisoning, memory poisoning, MCP server injection, skill-file injection, agentic tool misuse, computer-use UI injection, and excessive agency. Authorization required — this skill tests AI systems you are explicitly permitted to assess. Triggers on requests to test LLM / AI-agent / RAG / MCP / computer-use security, perform prompt injection, extract system prompts, poison RAG or memory, audit agent tool use, or evaluate AI guardrails.

1016mo agoDiscuss
RTFM-IT-Services-LLCSkill

msp-security

RTFM-IT-Services-LLC/msp-claude-skills/skills/msp-security/SKILL.md

Use this skill for security standards at your managed IT services (MSP) business, in both directions: the baseline every managed client must meet (MFA, endpoint protection, email security, backups, admin access, offboarding) and how the MSP secures itself (RMM hardening, the credential vault, admin separation, partner-delegated admin access into client tenants, our own devices). Trigger on "security baseline", "security standard", "harden this tenant", "is this client secure enough", "security assessment", "cyber insurance questionnaire", "can we say we're compliant", HIPAA, FTC Safeguards, WISP, CMMC, PCI, CIS Controls, "lock down our RMM", or any question about what controls a client or our MSP should have. msp-helpdesk owns incident response; msp-maintenance owns patch and backup cadence; this skill owns the standard they deliver against. Apply alongside msp-onboarding, msp-qbr, msp-legal, msp-pricing, msp-client-comms, and msp-sales.

992mo agoDiscuss
blockmaticSkill

w-security

blockmatic/basilic-skills/skills/workflow/w-security/SKILL.md

Review the change or tree against repository security docs and existing checks.

18d agoDiscuss
L-X-TSkill

ng-security

L-X-T/ng-agentic-skills/.agents/skills/ng-security/SKILL.md

Harden Angular applications against common web vulnerabilities. Use when reviewing or improving app security, preventing XSS, configuring Content Security Policy (CSP) or Trusted Types, working with sanitization / DomSanitizer / bypassSecurityTrust, securing HttpClient (XSRF/CSRF, XSSI), auth and token storage, SSR/SSRF (allowedHosts), or keeping dependencies patched.

1122d agoDiscuss
MaxMiksaSkill

security-audit

MaxMiksa/Auto-Company/.claude/skills/security-audit/SKILL.md

Use when reviewing code security, auditing dependencies for CVEs, checking configuration or secret security, assessing authentication and authorization patterns, identifying OWASP vulnerabilities (injection, XSS, CSRF), or addressing security concerns about implementations.

3.1k13mo agoDiscuss
CLAUDE.md vs AGENTS.md

About skills

What is a Claude skill?

A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.

How do I use one I find here?

Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.

What do the warnings mean?

We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.

Which skills worked for people?

Open a skill to see its discussion. Reports from people and their agents are coming.