security-sweep
n24q02m/better-code-review-graph/skills/security-sweep/SKILL.md
Graph-driven security sweep -- scan for dangerous sinks, then rank each finding by whether an entry point can actually reach it, and triage the rest into suppressions.
One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.
n24q02m/better-code-review-graph/skills/security-sweep/SKILL.md
Graph-driven security sweep -- scan for dangerous sinks, then rank each finding by whether an entry point can actually reach it, and triage the rest into suppressions.
code-yeongyu/oh-my-openagent/.agents/skills/security-research/SKILL.md
Team Mode security research skill. Orchestrates 3 vulnerability hunters and 2 PoC engineers to audit a codebase in parallel, prove exploitability, classify root causes, and calibrate severity by actual exploitability. Use for security review, vulnerability research, exploitability audit, pre-release security check, threat model validation, and `/security-research`. Triggers: 'security-research', 'security research', 'security review', 'vulnerability audit', 'exploitability audit', '보안 리뷰', '취약점 감사'.
hypnguyen1209/offensive-claude/skills/cloud-security/SKILL.md
Use when attacking AWS/Azure/GCP cloud — IAM/identity privilege escalation, IMDS/metadata SSRF, Entra device-code & PRT theft, GCP impersonation chains, Kubernetes/container escape, IaC/CI-CD federation abuse
rusel95/ios-agent-skills/skills/ios-security/SKILL.md
Use for any iOS security question — whether you're asking about a specific vulnerability, checking if a pattern is secure, or running a full audit. Triggers on: Keychain vs UserDefaults decisions, ATS/NSAllowsArbitraryLoads configuration, certificate pinning implementation, WebView security (UIWebView, WKWebView), hardcoded secrets or API keys, jailbreak/tamper detection, biometric authentication, MASVS controls, OWASP mobile security, App Store rejection risks, and compliance requirements (HIPAA, PCI DSS, GDPR). Also use when someone asks 'is this secure?', 'what should I use instead?', or 'how do I fix this?' about any iOS storage, network, or cryptography pattern.
vitormiziara/saas-security/SKILL.md
Comprehensive SaaS security skill covering code auditing, checklist generation, and vulnerability reporting. TRIGGER this skill whenever the user asks to: audit code for security issues, review a codebase for vulnerabilities, generate a security checklist, check for OWASP compliance, review authentication or authorization logic, check for injection risks, race conditions, or insecure configurations, or asks anything related to SaaS security hardening. Also trigger proactively when the user shares code and asks for a review — always include a security perspective using this skill.
agamm/claude-code-owasp/.claude/skills/owasp-security/SKILL.md
Reviews code for security vulnerabilities and guides secure implementation using OWASP Top 10:2025, ASVS 5.0, the OWASP Top 10 for LLM Applications (2026), and the OWASP Top 10 for Agentic Applications (2026). Use when reviewing code or a diff for security issues, implementing authentication, authorization, sessions, or cryptography, handling untrusted input, files, or URLs, hardening config, dependencies, or CI, or building LLM and AI agent features.
codecharmhq/claude-code-skills/ai-security/SKILL.md
Use when hardening AI-powered features against prompt injection, auditing LLM outputs before production use, or designing AI systems with defense-in-depth against model exploitation
ngothanhtung/claude-code-skills/.claude/skills/ck-security/SKILL.md
STRIDE + OWASP-based security audit with optional red-team persona discovery loop and auto-fix. Scans code for vulnerabilities from multiple attacker perspectives (auth attacker, supply chain, insider, infrastructure), categorizes by severity, and can iteratively fix findings using ck:autoresearch pattern.
Wellux/claude-code-deprecated/.claude/skills/ai-security/SKILL.md
LLM and AI agent security: prompt injection, jailbreaks, agent defense, guardrails. Invoke for: "prompt injection", "LLM security", "agent security", "jailbreak defense", "AI safety audit", "system prompt leakage", "adversarial inputs", "AI pipeline security", "tool call validation", "LLM guardrails", "model security", "is my prompt safe".
EvilFreelancer/secs/.agents/skills/iac-security/SKILL.md
Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep. Orchestrates Checkov, tfsec, Terrascan, KICS, kubesec, kube-linter, Polaris, cfn-lint/cfn-nag, and OPA/Conftest. Use when auditing IaC for misconfigurations, scanning Terraform plans, validating K8s security policies, checking cloud infrastructure compliance, or authoring custom policy-as-code (Rego).
techforum-repo/aem-claude-code/.claude/skills/aem-security/SKILL.md
AEM security review — admin resolver, query injection, path validation, exposed endpoints, hardcoded secrets
codeaholicguy/ai-devkit/skills/security-review/SKILL.md
AI DevKit · Review code, skills, and prompts for security vulnerabilities — OWASP Top 10, prompt injection, business logic flaws, and insecure defaults. Use when reviewing PRs, auditing modules, reviewing AI skills/prompts, or preparing for release.
nahid-sparktales/agent-dispatcher/skills/security/auth-security/SKILL.md
Attack and harden an existing auth surface — session fixation and rotation, token verification, horizontal and vertical privilege escalation, password reset and account recovery, MFA bypass. Use when reviewing login, session, token, reset, invite, impersonation or role-elevation code, when someone reports seeing another user's data or an account takeover, or when auth changes are about to ship. Not for designing the login mechanism or permission model in the first place (authentication, authorization), not for infrastructure IAM, and never run against a system you have not been told you may test.
vince-winkintel/gitlab-cli-skills/glab-security/SKILL.md
Configure GitLab project security scan profiles with glab. Use when enabling, disabling, or checking GitLab security scan profiles such as SAST, dependency scanning, secret detection, container scanning, or dependency-scanning auto-remediation. Triggers on GitLab security config, security scan profile, enable SAST, dependency scanning, secret detection, glab security.
zhaoxuya520/reverse-skill/skills/database-security/SKILL.md
Use for authorized database security assessment covering PostgreSQL/MySQL/MSSQL/Mongo/Redis exposure, authz, UDF/command paths, and misconfiguration review.
zhaoxuya520/reverse-skill/skills/hardware-security/SKILL.md
Use for authorized hardware and embedded interface security research including UART/JTAG discovery, debug pad triage, secure boot overview, and offline firmware extraction support.
KimYx0207/SkillSemgrep/SKILL.md
Runs Semgrep security scans on the current project to detect vulnerabilities, secrets leakage, and OWASP Top 10 issues. Use when the user asks for security scanning, vulnerability detection, code auditing, secrets checking, or says things like 安全扫描, 代码扫描, 扫漏洞, 安全检查, 漏洞检测, 扫一下安全.
altafino/FableClaudeMDForOpus/.claude/skills/kit-security/SKILL.md
Security guardrails pack — injection, secrets, path traversal, auth defaults, deserialization, untrusted-content discipline. Use when asked for a security pass or when code touches user input, secrets, or auth.
redpanda-data/skills/skills/rpk-security/SKILL.md
Manage Redpanda authentication and authorization from the CLI using the `rpk security` command group (`user`, `acl`, `role`, `secret` subcommands; `rpk acl` is a deprecated alias). Use when creating or deleting SASL/SCRAM users, granting or revoking Kafka ACLs on topics, groups, the cluster, or transactional IDs, creating or assigning RBAC roles (Enterprise), managing secrets for Redpanda Cloud clusters, or configuring SASL/PLAIN, OAUTHBEARER/OIDC, GSSAPI/Kerberos, or mTLS principal mapping. Also covers Enterprise security config keys like Audit Logging, GBAC, Schema ID Validation, and FIPS mode, plus bootstrapping a new cluster with a superuser. For Schema Registry-specific ACL patterns, see /redpanda:rpk-registry; for the Enterprise license itself, see /redpanda:rpk-cluster.
sergeyklay/.agents/.agents/skills/scan-security/SKILL.md
Run a Snyk SAST + SCA security audit on the repository, remediate findings that pass the project's verification gates, and write a prioritized report to .audit/. Optional scope argument: all (default), code, deps, or changed.
Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.
CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.
A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.
Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.