agentsclimarketplace

Shelves

Security

7,261 rows from 1,288 repositories

Assuming somebody is trying.

What Security skills agree on

772 skill files read, by 666 of the 889 authors on this shelf whose files we hold, 2026-09-06

The middle one of the 144 measured here is ~2.1k tokens long, counted with cl100k_base

Counted by distinct author, so one author publishing three of these counts once. Where a claim sits in fewer files than authors, that is said: a claim held by forty authors across three files is one file people copied, not forty people who agreed. Near-identical wordings are grouped and the other wordings are shown, so the grouping is yours to check.

What they tell the agent to do

  1. Use parameterized queries for database access82 of 666 in 79 filesalso worded as parameterize all database queries; Use parameterized queries for all database access
  2. Hash passwords with BCrypt55 of 666 in 39 filesalso worded as Hash passwords using bcrypt or argon2; hash passwords with bcrypt scrypt or argon2
  3. Implement rate limiting for public endpoints48 of 666 in 34 filesalso worded as implement rate limiting on authentication endpoints; implement rate limiting on API endpoints
  4. Use environment variables for secrets35 of 666also worded as use environment variables for all secrets; use environment variables for secrets management
  5. Scan dependencies for vulnerabilities35 of 666 in 24 filesalso worded as scan dependencies for known vulnerabilities; Scan dependencies for vulnerabilities in CI
  6. Validate and sanitize all user input35 of 666 in 32 filesalso worded as validate all user input on the server; validate and sanitize all user inputs
  7. Add security headers to all responses34 of 666 in 20 filesalso worded as set security headers for all responses; Enforce security headers on all responses
  8. Validate all external input at the system boundary26 of 666 in 25 filesalso worded as validate all external input at system boundaries; Validate all input at system boundaries
  9. Use parameterized queries to prevent SQL injection25 of 666 in 13 filesalso worded as use parameterized queries and avoid string concatenation; Prevent injection attacks using parameterized queries
  10. Store secrets in Vault or environment variables25 of 666 in 10 filesalso worded as Store secrets in environment variables; store secrets in environment variables or managers
  11. Run containers as a non-root user21 of 666 in 18 filesalso worded as Run containers as non-root users; Run containers as non-root users in production
  12. Validate all input using Bean Validation19 of 666 in 5 filesalso worded as Validate all input with Bean Validation; Use Bean Validation on all controller inputs
  13. Obtain written authorization before testing19 of 666 in 16 filesalso worded as obtain written authorization before starting; obtain written authorization before starting any activity
  14. Encrypt sensitive data at rest18 of 666also worded as Encrypt sensitive data at rest and in transit; Verify encryption for data at rest
  15. Categorize findings by severity18 of 666also worded as Classify findings by severity; Categorize findings by severity level

What they tell it not to do

  1. Do not use string concatenation for SQL queries47 of 666 in 45 filesalso worded as Do not use string concatenation for queries; Do not use string interpolation in SQL queries
  2. Never log sensitive data45 of 666 in 39 filesalso worded as Do not log sensitive data; Do not log sensitive data like passwords or tokens
  3. Never commit secrets to version control44 of 666 in 43 filesalso worded as Do not commit secrets to version control; Do not commit secrets to source control
  4. Never store passwords in plaintext38 of 666 in 21 filesalso worded as Store passwords in plaintext; Do not store passwords in plain text
  5. Do not hardcode secrets38 of 666 in 37 filesalso worded as do not hardcode secrets in source code; Never hardcode secrets in source code
  6. Never trust client-side validation26 of 666 in 24 filesalso worded as never trust client-side validation as a security boundary; Do not trust client-side validation alone
  7. Never expose stack traces to users26 of 666also worded as do not expose stack traces to users; Do not expose stack traces in production
  8. Never store secrets in application properties24 of 666 in 11 filesalso worded as Do not store secrets in environment variables; Do not store secrets in code
  9. Never use eval or innerHTML with user-provided data22 of 666 in 20 filesalso worded as never use eval or innerHTML with user input; never use eval or innerHTML with user data
  10. Do not run containers as root21 of 666 in 18 filesalso worded as Never run containers as root; Do not run containers as root in production

What they expect to be installed

  1. git80 of 666 in 78 files
  2. grep78 of 666 in 74 files
  3. npm audit59 of 666
  4. curl46 of 666
  5. bcrypt38 of 666 in 34 files
  6. npm37 of 666
  7. trivy36 of 666 in 33 files
  8. zod33 of 666 in 30 files
  9. python332 of 666 in 23 files
  10. pip-audit31 of 666

What they ask it to produce

  1. Security audit report114 of 666 in 107 filesalso worded as Security review report; Security report
  2. Security headers30 of 666 in 15 filesalso worded as Security headers configuration; Security header configurations
  3. Remediation recommendations27 of 666 in 23 filesalso worded as remediation guidance; Remediation plan
  4. Audit logs25 of 666 in 12 filesalso worded as security audit logs; Permission audit logs
  5. Threat model25 of 666 in 20 filesalso worded as threat models; threat model report
  6. Vulnerability scan reports25 of 666 in 23 filesalso worded as Vulnerability scan results; Security vulnerability report
  7. Parameterized queries22 of 666 in 10 filesalso worded as Parameterized SQL queries; parameterized database queries
  8. Security scan report19 of 666also worded as security findings report; Security scan reports

When Security authors say to reach for one

The situations these authors wrote into their own files, counted out of the same 666 authors, with the skills that name each one

How Security skills are built

6,415 skill directories by 1,120 authors, read from their repositories’ own file trees 2026-08-05

The middle bundle among those shipping files is 3 files, 20.5 KB beside SKILL.md

Counted by distinct author, same as above, so one author publishing forty template copies counts once. SKILL.md itself is not counted as a file, so a single-file skill is one where that file is the whole skill.

The shape

  1. SKILL.md is the whole skill442 of 1,120 authors, 2,819 of 6,415 skills
  2. files ship beside it678 of 1,120 authors, 3,596 of 6,415 skills
  3. executable scripts ship inside268 of 1,120 authors, 1,527 of 6,415 skills

The folders they converge on

  1. references/436 of 1,120 authors, 2,374 of 6,415 skills
  2. scripts/225 of 1,120 authors, 1,478 of 6,415 skills
  3. agents/99 of 1,120 authors, 325 of 6,415 skills
  4. assets/83 of 1,120 authors, 541 of 6,415 skills
  5. evals/57 of 1,120 authors, 143 of 6,415 skills
  6. templates/46 of 1,120 authors, 72 of 6,415 skills
  • Windiff version diff analysis

    ergrelet/windiff/.claude/skills/windiff-version-diff-analysis Skill

    392 repo

    Tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS, using a Web UI and/or LLMs.

  • Active directory attack

    hypnguyen1209/offensive-claude/skills/active-directory-attack Skill

    344 repo

    Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest

  • Owasp security

    agamm/claude-code-owasp/.claude/skills/owasp-security Skill

    325 repo

    Claude Code skill for OWASP security best practices (2025-2026). Includes Top 10:2025, ASVS 5.0, Agentic AI security, and 20+ language-specific security quirks.

  • Audit xcode security settings

    superagents-lab/xcode27-skills/audit-xcode-security-settings Skill

    no license276 repo

    Apple's official Agent Skills exported from Xcode 27 — SwiftUI, UIKit modernization, Swift Testing, C bounds-safety, and security hardening for AI coding agents.

  • Absolute audit

    maddhruv/absolute/skills/absolute-audit Skill

    206 repo

    Absolute Skills to 10x your Development Lifecycle

  • Attack flow

    wiz-sec-public/SITF/.claude/skills/attack-flow Skill

    no license177 repo

    A comprehensive framework for analyzing and defending against attacks targeting Software Development Life Cycle Infrastructure.

  • Mcp observatory

    KryptosAI/mcp-observatory/io.github.KryptosAI/mcp-observatory MCP server

    176 repo

    MCP security scanner. CI-native testing, attack simulation, health scoring, and SARIF.

  • Forensify

    alexgreensh/repo-forensics/plugins/repo-forensics/skills/forensify Skill

    no license153 repo

    Offline security scanner for AI-agent repos, skills, plugins, and MCP servers.

  • Sail

    pillar-labs/sail-skill/sail/skills/sail Skill

    no license130 repo

    SAIL V2 (Secure AI Lifecycle) as an agent skill — the full 91-risk catalog for AI/agent gap assessments, security roadmaps, and compliance checklists. Installs on Claude Code, Codex, ChatGPT, Antigravity, and any SKILL.md-compatible agent.

  • Agent security scanner mcp

    sinewaveai/agent-security-scanner-mcp/io.github.sinewaveai/agent-security-scanner-mcp MCP server

    120 repo

    Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.

  • Launchworthy

    Wunderlandmedia/launchworthy/skills/launchworthy Skill

    95 repo

    A Claude Code skill that plays bouncer at the door of production: audits AI-built apps (Lovable, Bolt, v0, Cursor) across 5 domains and hands you a scored punch list with copy-paste fixes. MIT.

  • Notebooklm mcp secure

    Pantheon-Security/notebooklm-mcp-secure/io.github.Pantheon-Security/notebooklm-mcp-secure MCP server

    78 repo

    Security-hardened NotebookLM MCP with post-quantum encryption

  • Command execution

    iammm0/secbot/skills/base/command-execution Skill

    no license74 repo

    Authorized security testing workspace. v2 TypeScript terminal product on release; v1 Python on pypi-release; Go branch is demo only.

  • cloud-audit

    gebalamariusz/cloud-audit/io.github.gebalamariusz/cloud-audit MCP server

    68 repo

    AWS security scanner with attack chain detection, IAM privilege escalation, and fixes

  • MCP ZAP Server

    dtkmn/mcp-zap-server/io.github.dtkmn/mcp-zap-server MCP server

    63 repo

    Safe, self-hosted OWASP ZAP operator for guided AI security scans and reports.

  • Memory Vault

    MihaiBuilds/memory-vault/io.github.MihaiBuilds/memory-vault MCP server

    60 repo

    Local-first AI memory layer with hybrid search. Postgres + pgvector. Self-hosted, MIT.

  • Kastell

    kastelldev/kastell/io.github.kastelldev/kastell MCP server

    56 repo

    Server security audit (413 checks), hardening, and fleet management across 4 cloud providers.

  • Secscan skill

    atgreen/secscan-skill Skill

    51

    Mirror of https://cave.moxielogic.com/atgreen/secscan-skill

  • Appsec engineer

    UnitOneAI/SecuritySkills/roles/appsec-engineer Skill

    49 repo

    Open-source security skills for AI coding agents. Grounded in OWASP, NIST, MITRE ATT&CK, CIS. Works with Claude Code, Gemini CLI, Cursor, Codex CLI, OpenClaw, Kiro.

  • Auditor skill

    solanabr/auditor-skill Skill

    48

    Claude Code / agentic security skill for Solana programs and software. Full audit-firm lifecycle, executable PoC + fix-patch delivery, a Rust pre-scanner + cross-audit memory, 1,346 checks across 20 checklists, and 131 real-world attack vectors.

  • Perseus Vault (formerly Mimir/Mneme), persistent memory engine for AI agents

    Perseus-Computing-LLC/perseus-vault/io.github.Perseus-Computing-LLC/perseus-vault MCP server

    47 repo

    Persistent, deterministic memory for AI agents. Local-first: SQLite, FTS5, AES-256-GCM, 55+ tools.

  • Wordpress plugin dev

    Zulut30/Wordpress-skills/skills/wordpress-plugin-dev Skill

    42 repo

    Professional Agent Skill for building, auditing, testing, and releasing modern WordPress plugins with Codex, Cursor, and Claude Code.

  • Mythos agent

    mythos-agent/mythos-agent/io.github.mythos-agent/mythos-agent MCP server

    39 repo

    Open-source AI security agent: SAST, DAST, and policy-as-code over MCP.

  • Openghost skill

    VAIBHAVSING/openghost/skills/openghost-skill Skill

    38 repo

    OpenGhost is an Agent Skill for authorized web app penetration testing: Enter lab url paste credential your agent and wait everything does with help of openghost

  • Solana Security Standard

    Copenhagen0x/solana-security-standard/io.github.Copenhagen0x/solana-security-mcp MCP server

    36 repo

    Scan Solana/Anchor code against the Solana Security Standard and serve the ruleset to MCP clients.

  • Security audit

    netresearch/security-audit-skill/skills/security-audit Skill

    no license35 repo

    Agent Skill for PHP security audits - OWASP patterns, vulnerability detection | Claude Code compatible

  • Acquire

    withqwerty/nutmeg/skills/acquire Skill

    no license31 repo

    Football data analytics toolkit for Claude Code. Covers Opta, StatsBomb, Wyscout, SportMonks, and free sources.

  • Agent email inbox

    MoizIbnYousaf/marketing-cli/skills/agent-email-inbox Skill

    29 repo

    Agent-native marketing CLI: 58 skills, 5 research agents, brand memory that compounds across sessions, and a local Studio dashboard. One npm install, then /cmo in your coding agent.

  • Markdown Vault MCP

    pvliesdonk/markdown-vault-mcp/io.github.pvliesdonk/markdown-vault-mcp MCP server

    27 repo

    Markdown vault MCP server with FTS5 + semantic search and frontmatter indexing

  • Aegis

    myclaude-sh/myclaude-creator-engine/.claude/skills/aegis Skill

    24 repo

    The creation pipeline for Claude Code products — research, create, validate, publish. 13 types, 20 quality patterns, zero coding required.

  • Claude pentest skills

    frendysanusi/claude-pentest-skills Skill

    no license23

    AI-powered web application penetration testing skills with Claude Code

  • Operant mcp

    operantlabs/operant-mcp/io.github.operantlabs/operant-mcp MCP server

    23 repo

    Security testing MCP server for penetration testing, forensics, and vulnerability assessment

  • Api breaker

    Orizon-eu/claude-code-pentest/api-breaker Skill

    22 repo

    6 Claude Code skills that automate the entire pentest lifecycle. From recon to exploit chains to bug bounty reports — just give it a domain. 43 scripts, zero dependencies, pure Python.

  • Bb huge

    ShulkwiSEC/bb-huge/skills/bb-huge Skill

    21 repo

    bb-huge 🤗 , Personal bug bounty findings hub and bug bounty orchestration for multiple agents

  • Api fetch wrapper

    ChronoAIProject/Ornn/examples/api-fetch-wrapper Skill

    19 repo

    Your all-in-one skills-as-a-service platform to manage your skills, auto-generate skills and use agent skills as simple as calling an API.

  • Vibe ship

    sudais-khalid/vibe-ship Skill

    18

    A Claude Code / Claude.ai Skill that turns any codebase into something deployable with docker compose up and shippable through CI/CD, hardened by default, generated in one pass.

  • Threat model authoring

    alpha-omega-security/threat-model/skills/threat-model-authoring Skill

    18 repo

    Agent skill for producing threat models for open-source projects

  • Ci speedup

    starslingdev/skills/skills/ci-speedup Skill

    17 repo

    Free, MIT-licensed agent skills from StarSling. ci-speedup audits your GitHub Actions workflows and reports, from real run history, why CI is slow.

  • Vault Cortex

    aliasunder/vault-cortex/io.github.aliasunder/vault-cortex MCP server

    17 repo

    Standalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1.

  • Api security

    ShieldNet-360/secure-vibe/dist/agent-skills/.agents/skills/api-security Skill

    15 repo

    SecureVibe — prevention-first security for AI-written code. Signed SKILL.md knowledge that makes AI coding assistants write secure code at generation time, plus a deterministic CI gate. Offline · keyless · Ed25519-signed. By ShieldNet360.

  • Prompt injection auditor

    screem500/prompt-injection-auditor Skill

    13

    Security audit skill for LLM agents - prompt injection scanner, attack catalog & defense checklist

  • Obsidian Vault MCP Server

    OleksandrKucherenko/mcp-obsidian-via-rest/io.github.OleksandrKucherenko/mcp-obsidian-via-rest MCP server

    13 repo

    Access Obsidian vaults via Local REST API - read, search, and interact with notes

  • Pulse8 ai cortex knowledge vault

    synpulse8-opensource/pulse8-ai-cortex-knowledge-vault/io.github.synpulse8-opensource/pulse8-ai-cortex-knowledge-vault MCP server

    12 repo

    Agent-native knowledge OS on Markdown: typed graph, hybrid search, and compiler over MCP.

  • Vulnicheck

    andrasfe/vulnicheck/io.github.andrasfe/vulnicheck MCP server

    11 repo

    HTTP MCP Server for comprehensive Python vulnerability scanning and security analysis.

  • Saas security

    vitormiziara/saas-security Skill

    10

    Claude skill for SaaS security auditing — 16 domains, 95 checks, OWASP-based

  • Hive Vault

    mlorentedev/hive/io.github.mlorentedev/hive-vault MCP server

    9 repo

    On-demand Obsidian vault access for AI coding assistants — 17 tools, 5 resources, 4 prompts.

  • Vault loop

    jessepwj/vault-loop/skill/vault-loop Skill

    8 repo

    Open-source prompt and Agent Skill for recurring knowledge-base update loops

  • Oc security audit

    miclivne/oc-security-audit/plugins/oc-security-audit/skills/oc-security-audit Skill

    no license8 repo

    Full-stack security audit skill for AI coding agents. OWASP WSTG testing + infrastructure, deployment, and privacy checks. Works with Claude Code, Codex, Cursor, Gemini CLI, Copilot.

  • B3sty skill

    b3sty191/b3sty-skill Skill

    no license8

    b3sty RedM/FiveM Lua Codex skill

  • App audit

    playbookTV/Ironclad/skills/app-audit Skill

    no license7 repo

    Agent-agnostic operating procedures for reviewing, debugging, testing, refactoring, and hardening software.

  • Snyk API & Web MCP Server

    snyk/saw-mcp/io.github.snyk/saw-mcp MCP server

    7 repo

    MCP server for Snyk API & Web — DAST scanning, findings management, and vulnerability triage

  • Auth security

    smicolon/ai-kit/packs/better-auth/skills/auth-security Skill

    no license6 repo

    Convention packs for any AI coding tool - agents, skills, commands, and rules for 15 tools including Claude Code, Cursor, Windsurf, and Copilot

  • Jpm integrations get started

    jpmorgan-payments/pdp-skills/skills/jpm-integrations-get-started Skill

    6 repo

    Agent skills that give GitHub Copilot, Claude Code, and other AI coding assistants procedural knowledge of J.P. Morgan Payments APIs. Walks external developers from onboarding and credential setup through OAuth implementation and live API integration with Checkout and Online Payments.

  • Aircrack ng

    jph4cks/redhound-arsenal/aircrack-ng Skill

    6 repo

    76 AI-agent security skills for Kali Linux tools — pentest, red team, forensics, OSINT, and more. Machine-readable skill definitions by Red Hound InfoSec.

  • Vault inspector

    rogerdigital/vault-inspector/skills/vault-inspector Skill

    6 repo

    An Obsidian vault health checker for finding broken links, orphan attachments, duplicate files, frontmatter drift, stale tags, and large files.

  • Pincer

    VouchlyAI/Pincer-MCP/io.github.VouchlyAI/pincer MCP server

    no license6 repo

    Secure grip for your agent's secrets - security-hardened MCP gateway with proxy token architecture

  • Security antipatterns python

    subhashdasyam/security-antipatterns-python Skill

    no license5

    Claude Code or Codex Skill that teaches AI coding agents to write secure Python. Catches SQL injection, pickle attacks, hardcoded secrets, and other OWASP Top 10 patterns in Django, Flask, and FastAPI code.

  • Eresus codeql heuristics

    EresusSecurity/appsec-skills/skills/eresus-codeql-heuristics Skill

    5 repo

    Production-ready AI AppSec skills for SAST, threat modeling, remediation, PR security review, and serialization abuse analysis.

  • Appsec playbook

    maxwellokumu/okaudit-claude-skills/application-security/appsec-playbook Skill

    no license5 repo

    Claude-ready IT audit skills for identity, compliance, appsec, privacy, network, logging, vendor risk, and audit leadership workflows

  • Web security reviewer

    goingli0324/web-security-reviewer Skill

    5

    Claude Code skill: defensive security review of your own code (Apps Script, frontend, backend)

All 7,261 in the catalog