security
ThuPhuong1010/claude-factory/.claude/skills/security/SKILL.md
Security patterns. Trigger khi code auth, handle user input, thiết kế hệ thống có dữ liệu nhạy cảm.
One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.
ThuPhuong1010/claude-factory/.claude/skills/security/SKILL.md
Security patterns. Trigger khi code auth, handle user input, thiết kế hệ thống có dữ liệu nhạy cảm.
getsentry/sentry/.agents/skills/sentry-security/SKILL.md
Sentry-specific security review based on real vulnerability history. Use when reviewing Sentry endpoints, serializers, or views for security issues. Trigger keywords: "sentry security review", "check for IDOR", "access control review", "org scoping", "cross-org", "security audit endpoint".
hypnguyen1209/offensive-claude/skills/ai-security/SKILL.md
Use when attacking an AI/ML system or model — prompt injection & jailbreaks (Crescendo, Skeleton Key, Best-of-N), RAG/vector poisoning, agentic/MCP exploitation (CVE-2025-54136), ML supply-chain RCE (pickle CVE-2025-32434), model extraction / membership inference / adversarial suffixes (GCG)
mizchi/skills/sql-security/SKILL.md
SQL injection screening for host code (MoonBit / TS / Rust) plus secretlint setup notes. Flags single-line template-literal or string-concat SQL builders, regardless of value source — the scanner is line-based and does NOT trace data flow, so a clean scan is not proof of safety (multi-line template literals are missed) and every hit needs a manual review or an explicit `// sql-security: ok` opt-out.
aws/agent-toolkit-for-aws/plugins/aws-core/skills/aws-security/SKILL.md
Covers AWS security services and workflows — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules, and security posture summaries; Security Hub CSPM (V1/ASFF) controls and compliance standards; GuardDuty threat findings; Inspector vulnerability findings; Macie sensitive data findings; Detective investigation; and Security Lake configuration and data aggregation. Applicable when questions involve security posture, Exposure findings, CSPM failed controls, threat findings, vulnerability findings, sensitive data findings, automation rules, or cross-service security configuration across AWS environments. Procedures use standard AWS CLI syntax and work with or without the AWS MCP server.
microsoft/Dataverse-skills/.github/plugins/dataverse/skills/dv-security/SKILL.md
Security-role assignment, user access, application users, business units, and admin self-elevation in Dataverse environments. Use when the user wants to give someone access, grant a role, become an admin, or add a service principal.
wgpsec/AboutSecurity/skills/ai-security/mcp-security/SKILL.md
MCP (Model Context Protocol) 协议安全测试方法论。当目标环境使用 MCP Server 集成外部工具、 需要评估 MCP 工具描述安全性、或测试 Agent 通过 MCP 调用工具时的安全边界时触发。 覆盖: 工具描述投毒、地毯式骗局(动态篡改)、指令覆盖(Shadow Tool)、隐藏指令(ANSI/Unicode)、 跨 Server 攻击、Token 窃取、Schema 操纵、上下文溢出。
ruvnet/ruflo/.agents/skills/security-audit/SKILL.md
Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment processing, user data handling, API endpoint creation, file upload handling, database queries, external API integration. Skip when: read-only operations on public data, internal development tooling, static documentation, styling changes.
jiten-singh-shahi/salesforce-claude-code/.cursor/skills/sf-security/SKILL.md
Use when implementing Salesforce Apex security — CRUD/FLS enforcement, sharing keywords, SOQL injection prevention, AppExchange review prep. Do NOT use for general Apex or LWC patterns.
hardw00t/ai-security-arsenal/skills/sca-security/SKILL.md
Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to suppress unexploitable findings. Use when scanning package dependencies (npm, PyPI, Maven, Cargo, Go, RubyGems, Composer), reviewing PR lockfile diffs, generating SBOMs, auditing licenses, hunting malicious packages, or auditing the software supply chain. Triggers on requests to scan dependencies, check vulnerable packages, generate SBOM, license compliance, typosquat/dependency-confusion review, or reachability-based vuln triage.
zhaoxuya520/reverse-skill/skills/email-security/SKILL.md
Use for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research.
Donchitos/Claude-Code-Game-Studios/.claude/skills/security-audit/SKILL.md
Security audit — save tampering, cheat vectors, network exploits, data exposure, input validation. Before public or multiplayer release.
arcasilesgroup/ai-engineering/skills/ai-security/SKILL.md
Six-phase security audit of a codebase — web apps, APIs, services, CLI tools, libraries, and daemons — with adversarial validation: the agent that verifies a finding is never the one that found it. Recon, parallel hunting across 8 attack classes, validation, reporting, schema-validated findings.json, and independent verification. Only exploitable issues with real impact are reported — never theoretical concerns or industry-standard behavior. Use when a milestone declares a security audit, when findings must be validated adversarially, or for trigger phrases "security review", "audit for vulnerabilities", "find security bugs", and "pen-test the code". Not for diagnosing a runtime failure — use /ai-debug. Not for judging a diff for correctness — use /ai-verify.
kingxiaozhe/cm-workflow/skills/cm-security/SKILL.md
用户运行 cm-security,或要求代码安全扫描、漏洞检查、密钥泄露排查、依赖漏洞检查时使用。默认检查当前分支相对主分支及已跟踪未提交修改,结合业务地图复核;--all 检查全部已跟踪文件。只报告问题,不自动修复、安装、升级或发布。安装自检用 cm-check,功能测试与覆盖率用 cm-test。
cloudflare/security-audit-skill/skills/security-audit/SKILL.md
Security guidance and vulnerability review for codebases, APIs, services, CLI tools, libraries, and daemons. Use for security questions, focused reviews, vulnerability research, security audits, or pen tests. Run the complete workflow only for explicit codebase audit or pen-test requests, full/comprehensive/end-to-end reviews, or requested report artifacts.
Mindrally/skills/jwt-security/SKILL.md
Guidelines for implementing JWT authentication with security best practices for token creation, validation, and storage
nirholas/three.ws/.agents/skills/okx-security/SKILL.md
Use this skill for security scanning: check transaction safety, is this transaction safe, pre-execution check, security scan, token risk scanning, honeypot detection, DApp/URL phishing detection, message signature safety, malicious transaction detection, approval safety checks, token approval management. Triggers: 'is this token safe', 'check token security', 'honeypot check', 'scan this tx', 'scan this swap tx', 'tx risk check', 'is this URL a scam', 'check if this dapp is safe', 'phishing site check', 'is this signature safe', 'check this signing request', 'check my approvals', 'show risky approvals', 'revoke approval', 'check if this approve is safe', token authorization, ERC20 allowance, Permit2. Covers token-scan, dapp-scan, tx-scan (EVM+Solana pre-execution), sig-scan (EIP-712/personal_sign), approvals (ERC-20/Permit2). Chinese: 安全扫描, 代币安全, 蜜罐检测, 貔貅盘, 钓鱼网站, 交易安全, 签名安全, 代币风险, 授权管理, 授权查询, 风险授权, 代币授权. Do NOT use for wallet balance/send/history — use okx-agentic-wallet.
Strategic-Automation/violin/skills/llm-security/SKILL.md
Test LLM prompt injection and MCP tool/agent surfaces.
Hassaan146/claude-skills/ai-security/SKILL.md
Use when assessing AI/ML systems for prompt injection, jailbreak vulnerabilities, model inversion risk, data poisoning exposure, or agent tool abuse. Covers MITRE ATLAS technique mapping, injection signature detection, and adversarial robustness scoring.
anthropics/claude-plugins-official/plugins/claude-security/skills/claude-security/SKILL.md
Claude Security: scan the codebase (the whole repository or a scoped part of it), scan changes (this branch's or a pull request's diff, or one commit), or suggest patches (findings turned into targeted patch files, each verified by a panel of agents, that you apply when you choose). Use when the user asks to scan, audit or check code with Claude Security, to scan their changes with Claude Security, or to fix or patch Claude Security findings.
Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.
CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.
A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.
Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.