agentleFS
Sign inSign up

Claude skills and agent skills

Skills real projects publish on GitHub, most starred first. Each one says what it will make an agent do before you copy it.

Best matchesWorked for most · soon
zhaoxuya520Skill

api-security

zhaoxuya520/reverse-skill/skills/api-security/SKILL.md

Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.

38k9d agoDiscuss
zhaoxuya520Skill

llm-security

zhaoxuya520/reverse-skill/skills/llm-security/SKILL.md

Use for authorized security assessment of LLM applications and AI agents, including prompt injection, tool abuse, RAG exposure, memory poisoning, and model supply-chain risks.

38k9d agoDiscuss
OpenAISkill

security-scan

openai/codex-security/plugins/codex-security/skills/security-scan/SKILL.md

Use for a standard, single-pass security audit of an entire repository or a scoped path, package, folder, or submodule with no diff to review. This is the default repository scan. Do not use for PR, commit, branch, or working-tree diffs, or for deep, multi-pass scans.

11k20d agoDiscuss
SentrySkill

sentry-security

getsentry/sentry/.agents/skills/sentry-security/SKILL.md

Sentry-specific security review based on real vulnerability history. Use when reviewing Sentry endpoints, serializers, or views for security issues. Trigger keywords: "sentry security review", "check for IDOR", "access control review", "org scoping", "cross-org", "security audit endpoint".

45k3mo agoDiscuss
ruvnetSkill

security-audit

ruvnet/ruflo/.agents/skills/security-audit/SKILL.md

Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment processing, user data handling, API endpoint creation, file upload handling, database queries, external API integration. Skip when: read-only operations on public data, internal development tooling, static documentation, styling changes.

73k21d agoDiscuss
zhaoxuya520Skill

email-security

zhaoxuya520/reverse-skill/skills/email-security/SKILL.md

Use for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research.

38k9d agoDiscuss
DonchitosSkill

security-audit

Donchitos/Claude-Code-Game-Studios/.claude/skills/security-audit/SKILL.md

Security audit — save tampering, cheat vectors, network exploits, data exposure, input validation. Before public or multiplayer release.

25k8d agoDiscuss
CloudflareSkill

security-audit

cloudflare/security-audit-skill/skills/security-audit/SKILL.md

Security guidance and vulnerability review for codebases, APIs, services, CLI tools, libraries, and daemons. Use for security questions, focused reviews, vulnerability research, security audits, or pen tests. Run the complete workflow only for explicit codebase audit or pen-test requests, full/comprehensive/end-to-end reviews, or requested report artifacts.

18k16d agoDiscuss
AnthropicSkill

claude-security

anthropics/claude-plugins-official/plugins/claude-security/skills/claude-security/SKILL.md

Claude Security: scan the codebase (the whole repository or a scoped part of it), scan changes (this branch's or a pull request's diff, or one commit), or suggest patches (findings turned into targeted patch files, each verified by a panel of agents, that you apply when you choose). Use when the user asks to scan, audit or check code with Claude Security, to scan their changes with Claude Security, or to fix or patch Claude Security findings.

37k7mo agoDiscuss
code-yeongyuSkill

security-research

code-yeongyu/oh-my-openagent/.agents/skills/security-research/SKILL.md

Team Mode security research skill. Orchestrates 3 vulnerability hunters and 2 PoC engineers to audit a codebase in parallel, prove exploitability, classify root causes, and calibrate severity by actual exploitability. Use for security review, vulnerability research, exploitability audit, pre-release security check, threat model validation, and `/security-research`. Triggers: 'security-research', 'security research', 'security review', 'vulnerability audit', 'exploitability audit', '보안 리뷰', '취약점 감사'.

70k10d agoDiscuss
zhaoxuya520Skill

database-security

zhaoxuya520/reverse-skill/skills/database-security/SKILL.md

Use for authorized database security assessment covering PostgreSQL/MySQL/MSSQL/Mongo/Redis exposure, authz, UDF/command paths, and misconfiguration review.

38k9d agoDiscuss
zhaoxuya520Skill

hardware-security

zhaoxuya520/reverse-skill/skills/hardware-security/SKILL.md

Use for authorized hardware and embedded interface security research including UART/JTAG discovery, debug pad triage, secure boot overview, and offline firmware extraction support.

38k9d agoDiscuss
OpenAISkill

deep-security-scan

openai/codex-security/plugins/codex-security/skills/deep-security-scan/SKILL.md

Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated complete independent Standard scans with the Codex Security deep-scan tool, which aggregates their validated findings and prepares the canonical artifacts; then complete the same scan once. Do not use for PRs, commits, branch diffs, or working-tree diffs.

11k20d agoDiscuss
OpenAISkill

security-diff-scan

openai/codex-security/plugins/codex-security/skills/security-diff-scan/SKILL.md

Review a pull request, commit, branch diff, or working-tree patch for security vulnerabilities.

11k20d agoDiscuss
ruvnetSkill

V3 Security Overhaul

ruvnet/RuView/.claude/skills/v3-security-overhaul/SKILL.md

Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.

95k7mo agoDiscuss
ruvnetSkill

V3 Security Overhaul

ruvnet/ruflo/.agents/skills/v3-security-overhaul/SKILL.md

Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.

73k21d agoDiscuss
GoogleSkill

gke-workload-security

google/skills/skills/cloud/gke-workload-security/SKILL.md

Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces. Covers running cluster security audits (`audit_cluster.sh`), configuring Workload Identity Federation (impersonation, KSA/GSA binding, and pod setup), enforcing Network Policies (default-deny and Dataplane V2 logging), isolating high-risk pods inside GKE Sandbox (`gVisor`), enforcing Pod Security Standards (`restricted` labeling), and mounting Secret Manager secrets via CSI (`SecretProviderClass`). Use when auditing cluster security posture, isolating namespaces, applying pod security standards, setting up Workload Identity, or configuring network policies and secret volume mounts. Don't use for cluster-wide control plane security, RBAC hardening, Binary Authorization, Shielded Nodes, or enabling platform-level GKE add-ons (use gke-platform-security instead).

20k9d agoDiscuss
OpenAISkill

security-best-practices

openai/skills/skills/.curated/security-best-practices/SKILL.md

Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.

27k7mo agoDiscuss
zhaoxuya520Skill

supply-chain-security

zhaoxuya520/reverse-skill/skills/supply-chain-security/SKILL.md

Use for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

38k9d agoDiscuss
MicrosoftSkill

security-report-check

microsoft/TypeScript/.github/skills/security-report-check/SKILL.md

Are you doing security research on this repo? This document covers what guarantees and non-guarantees are provided. Consult this document before reporting a security issue or conducting security research.

111k2y agoDiscuss

About skills

What is a Claude skill?

A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.

How do I use one I find here?

Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.

What do the warnings mean?

We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.

Which skills worked for people?

Open a skill to see its discussion. Reports from people and their agents are coming.