agentleFS
Sign inSign up

Claude skills and agent skills

Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.

Best matches · from page 8Worked for most · soon
SentrySkill

security-review

getsentry/sentry-python/.agents/skills/security-review/SKILL.md

Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.

2.2k7mo agoDiscuss
rtk-aiSkill

security-guardian

rtk-ai/rtk/.claude/skills/security-guardian/SKILL.md

CLI security expert for RTK - command injection, shell escaping, hook security

82k8d agoDeletes or force-pushesDiscuss
bybren-llcSkill

security-audit

bybren-llc/safe-agentic-workflow/.agents/skills/security-audit/SKILL.md

RLS validation, security audits, OWASP compliance, and vulnerability scanning. Use when validating RLS policies, auditing API routes for auth, scanning for vulnerabilities, reviewing for exposed credentials, or performing pre-deployment security review. Do NOT use for routine feature development.

4052mo agoReads credentialsDiscuss
bybren-llcSkill

security-audit

bybren-llc/safe-agentic-workflow/.claude/skills/security-audit/SKILL.md

RLS validation, security audits, OWASP compliance, and vulnerability scanning. Use when validating RLS policies, auditing API routes, or scanning for security issues.

4052mo agoReads credentialsDiscuss
n24q02mSkill

security-sweep

n24q02m/better-code-review-graph/skills/security-sweep/SKILL.md

Graph-driven security sweep -- scan for dangerous sinks, then rank each finding by whether an entry point can actually reach it, and triage the rest into suppressions.

696mo agoDiscuss
code-yeongyuSkill

security-research

code-yeongyu/oh-my-openagent/.agents/skills/security-research/SKILL.md

Team Mode security research skill. Orchestrates 3 vulnerability hunters and 2 PoC engineers to audit a codebase in parallel, prove exploitability, classify root causes, and calibrate severity by actual exploitability. Use for security review, vulnerability research, exploitability audit, pre-release security check, threat model validation, and `/security-research`. Triggers: 'security-research', 'security research', 'security review', 'vulnerability audit', 'exploitability audit', '보안 리뷰', '취약점 감사'.

70k11d agoDiscuss
hypnguyen1209Skill

cloud-security

hypnguyen1209/offensive-claude/skills/cloud-security/SKILL.md

Use when attacking AWS/Azure/GCP cloud — IAM/identity privilege escalation, IMDS/metadata SSRF, Entra device-code & PRT theft, GCP impersonation chains, Kubernetes/container escape, IaC/CI-CD federation abuse

38210d agoDiscuss
rusel95Skill

ios-security

rusel95/ios-agent-skills/skills/ios-security/SKILL.md

Use for any iOS security question — whether you're asking about a specific vulnerability, checking if a pattern is secure, or running a full audit. Triggers on: Keychain vs UserDefaults decisions, ATS/NSAllowsArbitraryLoads configuration, certificate pinning implementation, WebView security (UIWebView, WKWebView), hardcoded secrets or API keys, jailbreak/tamper detection, biometric authentication, MASVS controls, OWASP mobile security, App Store rejection risks, and compliance requirements (HIPAA, PCI DSS, GDPR). Also use when someone asks 'is this secure?', 'what should I use instead?', or 'how do I fix this?' about any iOS storage, network, or cryptography pattern.

116mo agoDiscuss
vitormiziaraSkill

saas-security

vitormiziara/saas-security/SKILL.md

Comprehensive SaaS security skill covering code auditing, checklist generation, and vulnerability reporting. TRIGGER this skill whenever the user asks to: audit code for security issues, review a codebase for vulnerabilities, generate a security checklist, check for OWASP compliance, review authentication or authorization logic, check for injection risks, race conditions, or insecure configurations, or asks anything related to SaaS security hardening. Also trigger proactively when the user shares code and asks for a review — always include a security perspective using this skill.

116mo agoDiscuss
agammSkill

owasp-security

agamm/claude-code-owasp/.claude/skills/owasp-security/SKILL.md

Reviews code for security vulnerabilities and guides secure implementation using OWASP Top 10:2025, ASVS 5.0, the OWASP Top 10 for LLM Applications (2026), and the OWASP Top 10 for Agentic Applications (2026). Use when reviewing code or a diff for security issues, implementing authentication, authorization, sessions, or cryptography, handling untrusted input, files, or URLs, hardening config, dependencies, or CI, or building LLM and AI agent features.

3686d agoDiscuss
codecharmhqSkill

ai-security

codecharmhq/claude-code-skills/ai-security/SKILL.md

Use when hardening AI-powered features against prompt injection, auditing LLM outputs before production use, or designing AI systems with defense-in-depth against model exploitation

15mo agoDiscuss
ngothanhtungSkill

ck:security

ngothanhtung/claude-code-skills/.claude/skills/ck-security/SKILL.md

STRIDE + OWASP-based security audit with optional red-team persona discovery loop and auto-fix. Scans code for vulnerabilities from multiple attacker perspectives (auth attacker, supply chain, insider, infrastructure), categorizes by severity, and can iteratively fix findings using ck:autoresearch pattern.

142d agoDiscuss
WelluxSkill

ai-security

Wellux/claude-code-deprecated/.claude/skills/ai-security/SKILL.md

LLM and AI agent security: prompt injection, jailbreaks, agent defense, guardrails. Invoke for: "prompt injection", "LLM security", "agent security", "jailbreak defense", "AI safety audit", "system prompt leakage", "adversarial inputs", "AI pipeline security", "tool call validation", "LLM guardrails", "model security", "is my prompt safe".

16mo agoDiscuss
EvilFreelancerSkill

iac-security

EvilFreelancer/secs/.agents/skills/iac-security/SKILL.md

Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep. Orchestrates Checkov, tfsec, Terrascan, KICS, kubesec, kube-linter, Polaris, cfn-lint/cfn-nag, and OPA/Conftest. Use when auditing IaC for misconfigurations, scanning Terraform plans, validating K8s security policies, checking cloud infrastructure compliance, or authoring custom policy-as-code (Rego).

1053d agoDiscuss
xu-xiangSkill

security-review

xu-xiang/everything-claude-code-zh/.agents/skills/security-review/SKILL.md

当涉及添加身份验证(Authentication)、处理用户输入、操作机密(Secrets)、创建 API 终端节点或实现支付/敏感功能时,请使用此技能。提供全面的安全检查清单和模式。

1.9k7mo agoReads credentialsDiscuss
techforum-repoSkill

aem-security

techforum-repo/aem-claude-code/.claude/skills/aem-security/SKILL.md

AEM security review — admin resolver, query injection, path validation, exposed endpoints, hardcoded secrets

97mo agoDiscuss
codeaholicguySkill

security-review

codeaholicguy/ai-devkit/skills/security-review/SKILL.md

AI DevKit · Review code, skills, and prompts for security vulnerabilities — OWASP Top 10, prompt injection, business logic flaws, and insecure defaults. Use when reviewing PRs, auditing modules, reviewing AI skills/prompts, or preparing for release.

1.6k16d agoDiscuss
nahid-sparktalesSkill

auth-security

nahid-sparktales/agent-dispatcher/skills/security/auth-security/SKILL.md

Attack and harden an existing auth surface — session fixation and rotation, token verification, horizontal and vertical privilege escalation, password reset and account recovery, MFA bypass. Use when reviewing login, session, token, reset, invite, impersonation or role-elevation code, when someone reports seeing another user's data or an account takeover, or when auth changes are about to ship. Not for designing the login mechanism or permission model in the first place (authentication, authorization), not for infrastructure IAM, and never run against a system you have not been told you may test.

5210d agoDiscuss
jdanigoSkill

security-scan

jdanigo/hydraia/skills/security-scan/SKILL.md

Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions.

819d agoReads credentialsDiscuss
ShaheerKhawajaSkill

security-scan

ShaheerKhawaja/ProductionOS/.claude/skills/security-scan/SKILL.md

ProductionOS security scanner. Auto-activates when editing auth, payment, credential, or admin files. Runs OWASP Top 10 checks, dependency audit, and secret detection.

86mo agoReads credentialsDiscuss
CLAUDE.md vs AGENTS.md

About skills

What is a Claude skill?

A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.

How do I use one I find here?

Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.

What do the warnings mean?

We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.

Which skills worked for people?

Open a skill to see its discussion. Reports from people and their agents are coming.