security-audit
laolaoshiren/claude-code-skills-zh/skills/security-audit/SKILL.md
代码安全审计 - 漏洞扫描、依赖检查、安全最佳实践
One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.
laolaoshiren/claude-code-skills-zh/skills/security-audit/SKILL.md
代码安全审计 - 漏洞扫描、依赖检查、安全最佳实践
duriantaco/skylos/.agents/skills/skylos-security/SKILL.md
Investigate and harden Skylos security behavior. Use when the user asks to validate a security finding, reproduce a scanner bypass, assess false negatives, review LLM evidence filters, analyze CI/cloud policy trust boundaries, classify severity, or add regression tests for security-sensitive analyzer behavior.
jim60105/copilot-prompt/skills/api-security/SKILL.md
Guideline for designing, implementing, and verifying secure APIs following OWASP API Security Top 10 (2023) best practices. Use when the user wants to: (1) review API code or design for security vulnerabilities, (2) design a secure REST, GraphQL, or gRPC API architecture, (3) implement API authentication and authorization (OAuth2, JWT, API keys, mTLS), (4) configure rate limiting, input validation, or CORS, (5) audit API endpoints for BOLA, BFLA, or mass assignment vulnerabilities, (6) create API security checklists or verification plans, (7) fix API security bugs or harden existing APIs, (8) set up API security testing (OWASP ZAP, Schemathesis, Burp Suite), or (9) handle any API security concern including SSRF prevention, resource consumption limits, business flow protection, API inventory management, and secure third-party API consumption.
thejefflarson/soundcheck/.claude/skills/ipc-security/SKILL.md
Detects IPC receivers that accept input without verifying caller identity. Use
thejefflarson/soundcheck/.claude/skills/mcp-security/SKILL.md
Detects MCP tool handlers vulnerable to malicious inputs, hardcoded secrets,
thejefflarson/soundcheck/.claude/skills/rag-security/SKILL.md
Detects RAG pipelines that ingest external documents into LLM context without
alinaqi/maggy/skills/security-audit/SKILL.md
Structured, adversarial, multi-phase security audit of a codebase — recon → coverage-led hunting → finder≠validator validation → machine-readable findings → target-neutral report
ceptln/quota-burner/skills/security-fix/SKILL.md
Use to find and fix one batch of concrete security issues: vulnerable dependencies, injection risks, secrets in code, unsafe patterns.
awarexone/AXguard/api-security/SKILL.md
Analyze REST/RPC/API security design — use for BOLA/BFLA, mass assignment, auth on endpoints, rate limits, inventory gaps, and unsafe outbound API consumption (OWASP API Top 10 2023).
awarexone/AXguard/jwt-security/SKILL.md
Analyze JWT implementation flaws — use when reviewing alg confusion, none algorithm, missing verify, weak secrets, or claim validation gaps (A07:2021 / API2:2023 / auth.jwt rules).
awarexone/AXguard/mcp-security/SKILL.md
Review Model Context Protocol servers/clients and tool bridges for trust, supply-chain, and over-privileged tool exposure before ship.
jessefmoore/offensive-claude-code/skills/ai-security/SKILL.md
AI/ML security assessment — prompt injection, jailbreak detection, RAG poisoning, model extraction, adversarial examples, supply chain risks in ML pipelines
GoldenWing-360/claude-security-skills/ios-security/SKILL.md
Harden iOS and macOS apps against the platform-specific failure modes. Covers Keychain accessibility tiers, App Transport Security, certificate pinning tradeoffs, file protection classes, biometric authentication, jailbreak detection as a signal rather than a defense, and third-party SDK review. Invoke when shipping a native app that holds credentials, before App Store submission, or after a mobile security advisory.
GoldenWing-360/claude-security-skills/mcp-security/SKILL.md
Audit Model Context Protocol server configurations and apply least-privilege scoping. Covers MCP inventory, capability risk-tiering, secret detection in configuration, malicious or compromised package indicators, and the lifecycle from install through rotation to revocation. Invoke before granting an MCP write access to production, after an MCP security advisory, or as periodic audit.
GoldenWing-360/claude-security-skills/rag-security/SKILL.md
Secure the trust boundaries RAG adds beyond a plain LLM app. Covers retrieval-time document authorization, tenant isolation in vector databases, indirect injection via retrieved content, ingestion poisoning, citation and embedding leakage, stale-permission drift, and grounding integrity. Invoke when building or reviewing a RAG feature, when indexing access-controlled or multi-tenant corpora, or after a cross-tenant leak or injection incident.
samber/cc-skills-golang/skills/golang-security/SKILL.md
Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory safety, PII in logs, STRIDE/DREAD threat modeling, plus `gosec` SAST, race detection, and fuzz testing. Apply when writing, reviewing, or auditing Go code for security, or when touching crypto, file or network I/O, secrets, user input, or authentication. Not for non-exploitable defensive bugs such as nil panics or slice aliasing (→ See `samber/cc-skills-golang@golang-safety` skill), dependency vulnerability scanning with govulncheck (→ See `samber/cc-skills-golang@golang-dependency-management` skill), or wiring security scanners into CI pipelines (→ See `samber/cc-skills-golang@golang-continuous-integration` skill).
bex-co/bex/.claude/skills/security-audit/SKILL.md
Security audit of a codebase — web apps, APIs, services, CLI tools, libraries, daemons, and more. Use when asked to find security bugs, do a security review, audit for vulnerabilities, or pen-test the code. Focuses on exploitable issues with real impact, not theoretical concerns or industry-standard behavior.
delorenj/skills/aws-security/SKILL.md
Covers AWS security services and workflows — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules, and security posture summaries; Security Hub CSPM (V1/ASFF) controls and compliance standards; GuardDuty threat findings; Inspector vulnerability findings; Macie sensitive data findings; Detective investigation; and Security Lake configuration and data aggregation. Applicable when questions involve security posture, Exposure findings, CSPM failed controls, threat findings, vulnerability findings, sensitive data findings, automation rules, or cross-service security configuration across AWS environments. Procedures use standard AWS CLI syntax and work with or without the AWS MCP server.
jiten-singh-shahi/salesforce-claude-code/.cursor/skills/security-scan/SKILL.md
Use when scanning Salesforce org Claude Code configuration for security vulnerabilities, deploy misconfigurations, and injection risks in CLAUDE.md, hooks, and MCP servers. Do NOT use for Apex code review — use sf-security.
getsentry/sentry-python/.agents/skills/security-review/SKILL.md
Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.
Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.
CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.
A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.
Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.