FirzusSkillFirzus/agent-skills/skills/engineering/security-review/SKILL.md
Perform source-only security audits of codebases, APIs, services, and applications. Use for security questions, focused vulnerability reviews, or explicitly requested full audits.
gener8vSkillgener8v/gener8v.claude-skills/skills/security-review/SKILL.md
OWASP-informed, code-level security review of delivered code: injection, authentication and authorization, data exposure, configuration, dependencies, cryptography and logging, with attack scenarios for Medium+ findings and compliance constraints (CC-XXX) treated as Critical. Use after a delivery, especially one touching input handling, auth, sensitive data or external integrations, such as 'security review TICKET-007' or 'check what this delivery shipped for injection or auth bypass before we merge'. Not for a whole-codebase OWASP posture assessment (owasp-top10-review) or prompt-injection risk in LLM features (owasp-llm-top10-review).
Kur1sulabSkillKur1sulab/blackbox/pt-mobile-security/SKILL.md
Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes,
me-cedricSkillme-cedric/agent-compass/skills/verify-security/SKILL.md
Security verification gate. Scans code for vulnerabilities, detects dangerous patterns, and ensures security decisions are documented. Use when the user mentions security scans, vulnerability detection, security audits, code security, OWASP, injection detection, or sensitive-data leaks. Auto-triggers for new modules, security-related changes, offensive/defensive tasks, and completed refactors.
peopleforresterSkillpeopleforrester/claude-dotfiles/skills/quality/security-review/SKILL.md
Security-focused code audit. Checks OWASP Top 10, secrets exposure, and vulnerability patterns. Invokes the security-reviewer agent.
yasserstudioSkillyasserstudio/perfex-crm-skills/skills/perfex-security/SKILL.md
Use whenever a Perfex CRM task touches security-sensitive code — issuing or consuming single-use tokens (password reset, magic link, confirmation), race-safe atomic UPDATE with `affected_rows()` check, handling user-controlled redirect URLs (`?next=`, `?redirect=`, `?return_to=`), rate-limiting an AJAX endpoint that leaks boolean state, cross-module model loads, logging PII, adding `target="_blank"` links, or excluding a webhook from CSRF. Also trigger when the user says "my magic link works twice", "password reset is racy", "someone can enumerate users by email", "open redirect in my module", "CSRF blocking my webhook", "rate limit this endpoint", or mentions "TOCTOU", "enumeration", `html_purify`, or `app_generate_hash()`. Every rule here exists because its absence caused a real Perfex production incident.
EastSwordSkillEastSword/dfyx_skills_lib/security_reporter/SKILL.md
安全报告编写助手是一款专注于网络安全领域的智能报告生成工具,当用户提出需要针对给出的漏洞信息给出分析报告时,需要基于漏洞编号、名称或安全扫描工具报告,自动生成符合行业标准的漏洞分析报告,包含漏洞背景、漏洞描述、漏洞原理、漏洞利用条件和修复要求等核心内容,帮助安全从业者快速生成标准化、专业的安全报告。
354685856-snSkill354685856-sn/claude-code-skills/security-check/SKILL.md
安全与合规检查 - 检查代码是否符合安全规范
arcobaleno64Skillarcobaleno64/council-forge/.github/skills/security-audit/SKILL.md
Generative vulnerability-discovery harness for an entire codebase, driven by parallel sub-agents and adversarial validation. Unlike the deterministic CI gates (repo_security_scan, regex_safety_audit, prompt_injection_scan) which prevent KNOWN bad patterns from recurring, this skill DISCOVERS unknown, exploitable vulnerabilities through a six-phase pipeline: recon, multi-angle hunting, adversarial validation, reporting, structured findings, and independent verification. Use this skill when asked to run a deep security audit, hunt for exploitable vulnerabilities, perform the quarterly threat-model discovery exercise, or find security bugs that pattern matching misses. Outputs findings.json conforming to report-schema.json and hands confirmed findings into the threat-model staging layer. Trigger on 'security audit', 'vulnerability hunt', 'quarterly threat model exercise', 'find exploitable bugs', or /security-audit.
ayman-benmadaSkillayman-benmada/owasp-security-audit/skills/security-audit/SKILL.md
Review source code, configuration, or architecture against the OWASP Top 10:2025 when the user requests an application security audit, OWASP review, vulnerability assessment, API security review, or security hardening assessment. Also use when asked to investigate access control, injection, authentication, secrets, cryptography, logging, supply chain, or error handling in an application. Produce evidence-backed findings with separate severity and confidence.
bcmyguestSkillbcmyguest/personal-skills/skills/security-audit/SKILL.md
Ruthlessly audit a codebase for its 1-3 most serious SECURITY vulnerabilities, verify each one adversarially, and report it with a CVE reference (for known-vulnerable dependencies) or a minimal proof-of-concept (for novel bugs). Use whenever the user invokes /security-audit or asks to "security audit this", "find the worst vulnerabilities here", "is this exploitable", "find the scariest security holes", "what's the biggest security risk in this repo", or wants a sharp, high-signal security review that stops at the top few issues rather than an exhaustive checklist. Spins up a small, capped multi-agent workflow of Sonnet agents to hunt attack surface and prove exploitability. For performance/cost problems use efficiency-audit instead.
BenLaurensonSkillBenLaurenson/claude-skills/security-audit/SKILL.md
Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.
blamejsSkillblamejs/exceptd-skills/skills/cloud-security/skill.md
Cloud security for mid-2026 — CSPM/CWPP/CNAPP posture, CSA CCM v4, AWS/Azure/GCP shared responsibility, cloud workload identity federation, runtime security with eBPF, AI workloads on cloud
blamejsSkillblamejs/exceptd-skills/skills/mlops-security/skill.md
MLOps pipeline security for mid-2026 — training data integrity, model registry signing, deployment pipeline provenance, inference serving hardening, drift detection, feedback loop integrity; covers MLflow / Kubeflow / Vertex AI / SageMaker / Azure ML / Hugging Face
carlokopSkillcarlokop/skills/security-audit/SKILL.md
Read-only security audit van React, marketing, Node en de database. Schrijft een rapport naar docs/reports/. Gebruik bij security audit, security-audit, beveiligingsaudit, of een verzoek om IDOR, RBAC, CORS, CSRF, SQL-injectie, RLS of Clerk-auth statisch te reviewen zonder code te wijzigen.
chinng-intaSkillchinng-inta/portal4agents-plugin/skills/security-watch/SKILL.md
Monitor CVEs and security advisories through the Chinng AI-Agent Portal. Use for incremental vulnerability checks, package watchlists, and actionable security summaries.
conjure-3301Skillconjure-3301/skills/security_audit/SKILL.md
Security audit of Substrate runtime built in Rust. Scans current dir by default, or a specific PR with --pr. Add --deep for adversarial reasoning.
conjure-3301Skillconjure-3301/skills/session-security/SKILL.md
Session fixation, hijacking, predictable IDs, weak invalidation, JWT pitfalls, 2FA step-up bypass
conjure-3301Skillconjure-3301/skills/solana-security/SKILL.md
Solana program security covering account validation (signer/owner/key/writable), PDA bump canonicalization, type confusion via missing discriminators, CPI privilege escalation, account closing and revival attacks, Anchor framework constraints, remaining_accounts bypass, arithmetic overflow in release mode, and sysvar spoofing
Design-of-ManSkillDesign-of-Man/claude-skills/skills/owasp-security/SKILL.md
Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, LLM Top 10 (2025), and Agentic AI security (2026).