agentleFS
Sign inSign up

Claude skills and agent skills

Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.

Best matchesWorked for most · soon
BankrBotSkill

Security

BankrBot/skills/ethskills-security/SKILL.md

Solidity vulnerabilities, defensive code patterns, and a pre-deployment audit checklist. Covers reentrancy, oracle manipulation, token decimals, SafeERC20, ERC-4626 inflation, infinite approvals, and MEV.

1.2k5mo agoDiscuss
alinaqiSkill

security

alinaqi/maggy/skills/security/SKILL.md

OWASP security patterns, secrets management, security testing

7074mo agoReads credentialsDiscuss
boshu2Skill

security

boshu2/agentops/skills/security/SKILL.md

Review code or scan for security vulnerabilities, secrets, dependencies and prompt risks. Use when: concrete exposure needs assessment; never silently change policy.

4463mo agoDiscuss
notqueSkill

security

notque/vexjoy-agent/skills/review/security/SKILL.md

Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks.

4254d agoReads credentialsDiscuss
garagonSkill

security

garagon/nanostack/security/SKILL.md

Use before shipping to production. Performs OWASP Top 10 audit and STRIDE threat modeling against the codebase. Supports --quick, --standard, --thorough modes. Also use when the user asks to check security, audit code, or review for vulnerabilities. Triggers on /security.

2066mo agoReads credentialsDiscuss
TheBeardedBearSASSkill

security

TheBeardedBearSAS/claude-craft/.claude/skills/security/SKILL.md

Security guidelines and OWASP Top 10. Use when reviewing security, implementing authentication or authorization, hardening code, or discussing vulnerabilities.

1052mo agoDiscuss
ilang-aiSkill

security

ilang-ai/autocode/skills/security/SKILL.md

Auto-apply security basics and block deploys that would leak secrets. Never ask the user about security choices — just do it, and run a real secret scan before going live.

10310d agoDiscuss
travisjneumanSkill

security

travisjneuman/.claude/skills/security/SKILL.md

Information security expertise for cybersecurity frameworks (NIST, ISO 27001), security architecture, incident response, vulnerability management, identity management, and cloud security. Use when designing security programs, responding to incidents, or assessing vulnerabilities.

997mo agoReads credentialsDiscuss
davidmatousekSkill

security

davidmatousek/tachi/.claude/skills/security/SKILL.md

Claude-powered SAST and SCA security scan skill. Invoked automatically as the Security Scan step (Step 7) of /aod.build (after Design Quality Gate, before Code Simplification) or standalone via /security. Analyzes all code files and dependency manifests changed on the feature branch relative to main for OWASP Top 10 vulnerability patterns and known CVE findings. Produces a human-readable security-scan.md report and machine-readable .security/ compliance artifacts (scan-log.jsonl, vulnerabilities.jsonl, SARIF 2.1.0, CycloneDX 1.5 SBOM). Blocks build progression on CRITICAL/HIGH findings with an explicit acknowledgment gate. Use --no-security in /aod.build to skip. Invoke /security directly for standalone analysis outside the build pipeline.

9049d agoDiscuss
AIBiz-AutomatyzacjeSkill

security

AIBiz-Automatyzacje/claude-code-starter/.claude/skills/security/SKILL.md

Systematyczny audyt bezpieczeństwa dla React 19 + Supabase + Edge Functions. Używaj przy review bezpieczeństwa, przed deployem, przy pracy z auth/authz, walidacją inputów, RLS policies, XSS, OWASP Top 10.

8727d agoReads credentialsDiscuss
AsiaOstrichSkill

security

AsiaOstrich/universal-dev-standards/.claude/skills/security-assistant/SKILL.md

引導安全審查與弱點評估,遵循 OWASP 標準。 Use when: 安全稽核、弱點檢查、安全程式碼審查、威脅建模。 Not for: 自動化的相依套件、CVE 與機密掃描——請用 /scan;處理正在發生的資安事件——請用 /incident。 Keywords: security, OWASP, vulnerability, authentication, authorization, 資訊安全, 弱點, 認證, 授權, 威脅建模.

753d agoDiscuss
AsiaOstrichSkill

security

AsiaOstrich/universal-dev-standards/skills/security-assistant/SKILL.md

Guide security review and vulnerability assessment following OWASP standards. Use when: security audit, vulnerability check, secure coding review, threat modeling. Not for: automated dependency, CVE, and secret scanning — use /scan; handling a breach in progress — use /incident. Keywords: security, OWASP, vulnerability, authentication, authorization.

753d agoDiscuss
korchard333Skill

security

korchard333/claude-power-platform-community/.claude/skills/security/SKILL.md

Dataverse Security Model. Use when: designing security roles, column-level security, business units, teams (owner/access/AAD group), record sharing, hierarchy security, minimum viable privileges, security role management via Web API.

466mo agoDiscuss
DGouronSkill

security

DGouron/review-flow/.claude/skills/security/SKILL.md

Code scan to detect secrets before commit. Use before git add/commit/push or on demand. Checks for tokens, API keys, credentials, and other sensitive data.

425mo agoReads credentialsDiscuss
flavien-iaSkill

security

flavien-ia/hypervibe-harness/skills/security/SKILL.md

Audit the security of a Next.js/T3 project. Checks for exposed secrets, unprotected routes, input validation, dependency vulnerabilities, headers, CORS, and common web security issues. Use when the user wants to verify their app is safe before going live.

3934d agoReads credentialsDiscuss
galandoSkill

security

galando/piv-speckit/.claude/skills/security/SKILL.md

Enforces security best practices

288mo agoDiscuss
LazyIsEfficientSkill

security

LazyIsEfficient/agentic-os/.claude/skills/security/SKILL.md

Scan and redact PII and sensitive data (emails, phone numbers, SSNs, API keys, IP addresses, credentials, amounts, company/person names) from repository files. Includes a pre-commit hook to block commits containing PII. Use when asked to audit code for sensitive data, sanitize files before publishing, or install PII detection hooks. For application security hardening see security-engineering.

153mo agoDiscuss
manu14357Skill

security

manu14357/Zelaxy/.agents/skills/security/SKILL.md

Maintain and improve security across the Zelaxy platform. Use for: secret encryption boundaries, auth modes (session/API key/internal JWT/cron), CSP and middleware hardening, webhook verification, tenant isolation, and security test coverage.

154mo agoDiscuss
kpbraySkill

security

kpbray/power-bi-agent-skills/.github/skills/security/SKILL.md

Implements Row-Level Security (RLS) and Object-Level Security (OLS) for Power BI models. Use for data access control, dynamic security, and multi-tenant scenarios.

98mo agoDiscuss
tartinerlabsSkill

security

tartinerlabs/skills/skills/security/SKILL.md

Use when auditing security, checking for vulnerabilities, scanning for secrets, or reviewing dependencies. Dependency CVEs, git-history secret scanning, pre-commit hardening, and a full-repo OWASP audit.

82mo agoReads credentialsDiscuss

About skills

What is a Claude skill?

A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.

How do I use one I find here?

Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.

What do the warnings mean?

We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.

Which skills worked for people?

Open a skill to see its discussion. Reports from people and their agents are coming.