goat-security
blundergoat/goat-flow/.agents/skills/goat-security/SKILL.md
Use when assessing security implications of code changes, architecture decisions, or new features.
One search for your own team's files and the public ecosystem. See how real projects write their agent instructions, and bring the good ideas home.
blundergoat/goat-flow/.agents/skills/goat-security/SKILL.md
Use when assessing security implications of code changes, architecture decisions, or new features.
microsoft/power-platform-skills/plugins/power-pages/skills/security-review/SKILL.md
Runs a guided, end-to-end security review of a Power Pages site and consolidates every finding into one HTML report covering source code and dependencies, the live site, browser headers, firewall, authentication, and role-based permissions. Use when the user wants a full security review, a release-readiness check before publishing, a code-and-config check during development, live site monitoring, or asks open-ended questions like "review my site security", "is my site safe to ship", "do a security check", "monitor my site" — even if they do not name the individual checks.
irahardianto/awesome-agv/.agents/skills/security-audit/SKILL.md
Orchestration reference for the /security-audit workflow. Contains dimension scope cards for parallel subagent dispatch, subagent prompt template, and security audit report template.
ddmsolutions/claude-skills/ai-security/SKILL.md
Use when assessing AI/ML systems for prompt injection, jailbreak vulnerabilities, model inversion risk, data poisoning exposure, or agent tool abuse. Covers MITRE ATLAS technique mapping, injection signature detection, and adversarial robustness scoring.
wlsdks/ontology-atlas/.agents/skills/security-audit/SKILL.md
Periodic security sweep of Atlas in four areas (MCP and CLI, the Tauri desktop shell, the web renderer and connectors, the supply chain and CI) that follows untrusted input to what it can reach, proves each reach with a planted input, and turns every confirmed finding into a fix slice with a regression test. Not for a single diff, which takes the reviewer's security lens.
wlsdks/ontology-atlas/.claude/skills/security-audit/SKILL.md
Periodic security sweep of Atlas in four areas — MCP and CLI, the Tauri desktop shell, the web renderer and connectors, and the supply chain and CI — that follows untrusted input to what it can reach, proves each reach with a planted input, and turns every confirmed finding into a fix slice with a regression test.
jaskaranhundal/usap-skills/.agents/skills/iac-security/SKILL.md
../../../cloud-infra/iac-security/SKILL.md
ldilov/harness-forge/.agents/skills/security-scan/SKILL.md
Auto-discoverable wrapper for `.hforge/library/skills/security-scan/SKILL.md`.
MBrekhof/xafskills/skills/xaf-security/SKILL.md
Configure DevExpress XAF security: roles, permissions, users, and background job authentication. Use when setting up role permissions in Updater.cs, implementing object-level security, exporting/importing roles, creating background job security contexts, or troubleshooting permission issues. Covers type-level vs object-level permissions, CurrentUserIdOperator, PermissionsReloadMode, and the role update caveat.
Wishmakingfairy/vibecheck/skills/security-scan/SKILL.md
This skill should be used when the user asks to \"run a security scan\", \"check for vulnerabilities\", \"security audit\", \"ship secure\", \"vibecheck scan\", or \"pre-deploy security check\". Runs 156 automated security checks across 15 categories and produces a categorized vulnerability report.
ktnyt/cclsp/.claude/skills/security-review/SKILL.md
Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling. Use when the Reviewer identifies security-sensitive changes in the MCP-LSP bridge.
arsudsandesh97/Revoact/skills/security-doc/SKILL.md
Generate a complete SECURITY.md file for any software project. Use whenever the user asks to create, write, generate, or draft a SECURITY.md — a comprehensive security documentation covering threat models, security controls, authentication, authorization, data protection, compliance requirements, and security best practices.
Kur1sulab/blackbox/pt-api-security/SKILL.md
API security testing - GraphQL, REST API, WebSocket, and Web-LLM attack techniques.
neronain/ClaudeSkills-Neronain/skills/engineering/security-scan/SKILL.md
Run full security scans on the codebase using Ruflo security tools
TheBeardedBearSAS/claude-craft/.claude/skills/security-react/SKILL.md
Sécurité React. Use when reviewing security, implementing auth, or hardening code.
hardw00t/ai-security-arsenal/skills/cloud-security/SKILL.md
Multi-cloud security assessment skill for AWS, Azure, and GCP. Use when performing cloud security audits, scanning for misconfigurations, testing IAM policies, auditing storage permissions, and identifying privilege escalation paths. Triggers on requests to audit cloud security, scan AWS/Azure/GCP, check cloud misconfigurations, or perform cloud penetration testing. Covers CIS benchmarks, CSPM, and cross-cloud identity federation.
Hassaan146/claude-skills/senior-security/SKILL.md
Use when the user asks for STRIDE threat modeling, DREAD risk scoring, data-flow-diagram threat analysis, or a quick secret scan — or when a security request needs routing to the right specialist skill (pen-testing, incident response, cloud posture, red team, AI security, threat hunting, secure code review). This skill owns threat modeling; everything else routes to a sibling.
striderZA/OpenCodeGameStudios/.agents/skills/security-audit/SKILL.md
Audit the game for security vulnerabilities: save tampering, cheat vectors, network exploits, data exposure, and input validation gaps. Produces a prioritised security report with remediation guidance. Run before any public release or multiplayer launch.
appsec-foundry/appsec-advisor/skills/security-score/SKILL.md
Deterministic quick Security Score (0-100) for a repository, computed from the scanner layer alone — no agents, no LLM, no threat model, nothing written into the target repository. Reports the score together with how many rules applied, the finding tally, and the weakest control domains. Use for a fast indication or a per-commit trend; it is not a risk rating and does not replace /appsec-advisor:create-threat-model.
kanfu-panda/pdlc-skills/skills/pdlc-security/SKILL.md
安全审计
Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.
CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.
A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.
Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.