Security
7,261 rows from 1,288 repositories
Assuming somebody is trying.
What Security skills agree on
772 skill files read, by 666 of the 889 authors on this shelf whose files we hold, 2026-09-06
The middle one of the 144 measured here is ~2.1k tokens long, counted with cl100k_base
Counted by distinct author, so one author publishing three of these counts once. Where a claim sits in fewer files than authors, that is said: a claim held by forty authors across three files is one file people copied, not forty people who agreed. Near-identical wordings are grouped and the other wordings are shown, so the grouping is yours to check.
What they tell the agent to do
- Use parameterized queries for database access82 of 666 in 79 filesalso worded as parameterize all database queries; Use parameterized queries for all database access
- Hash passwords with BCrypt55 of 666 in 39 filesalso worded as Hash passwords using bcrypt or argon2; hash passwords with bcrypt scrypt or argon2
- Implement rate limiting for public endpoints48 of 666 in 34 filesalso worded as implement rate limiting on authentication endpoints; implement rate limiting on API endpoints
- Use environment variables for secrets35 of 666also worded as use environment variables for all secrets; use environment variables for secrets management
- Scan dependencies for vulnerabilities35 of 666 in 24 filesalso worded as scan dependencies for known vulnerabilities; Scan dependencies for vulnerabilities in CI
- Validate and sanitize all user input35 of 666 in 32 filesalso worded as validate all user input on the server; validate and sanitize all user inputs
- Add security headers to all responses34 of 666 in 20 filesalso worded as set security headers for all responses; Enforce security headers on all responses
- Validate all external input at the system boundary26 of 666 in 25 filesalso worded as validate all external input at system boundaries; Validate all input at system boundaries
- Use parameterized queries to prevent SQL injection25 of 666 in 13 filesalso worded as use parameterized queries and avoid string concatenation; Prevent injection attacks using parameterized queries
- Store secrets in Vault or environment variables25 of 666 in 10 filesalso worded as Store secrets in environment variables; store secrets in environment variables or managers
- Run containers as a non-root user21 of 666 in 18 filesalso worded as Run containers as non-root users; Run containers as non-root users in production
- Validate all input using Bean Validation19 of 666 in 5 filesalso worded as Validate all input with Bean Validation; Use Bean Validation on all controller inputs
- Obtain written authorization before testing19 of 666 in 16 filesalso worded as obtain written authorization before starting; obtain written authorization before starting any activity
- Encrypt sensitive data at rest18 of 666also worded as Encrypt sensitive data at rest and in transit; Verify encryption for data at rest
- Categorize findings by severity18 of 666also worded as Classify findings by severity; Categorize findings by severity level
What they tell it not to do
- Do not use string concatenation for SQL queries47 of 666 in 45 filesalso worded as Do not use string concatenation for queries; Do not use string interpolation in SQL queries
- Never log sensitive data45 of 666 in 39 filesalso worded as Do not log sensitive data; Do not log sensitive data like passwords or tokens
- Never commit secrets to version control44 of 666 in 43 filesalso worded as Do not commit secrets to version control; Do not commit secrets to source control
- Never store passwords in plaintext38 of 666 in 21 filesalso worded as Store passwords in plaintext; Do not store passwords in plain text
- Do not hardcode secrets38 of 666 in 37 filesalso worded as do not hardcode secrets in source code; Never hardcode secrets in source code
- Never trust client-side validation26 of 666 in 24 filesalso worded as never trust client-side validation as a security boundary; Do not trust client-side validation alone
- Never expose stack traces to users26 of 666also worded as do not expose stack traces to users; Do not expose stack traces in production
- Never store secrets in application properties24 of 666 in 11 filesalso worded as Do not store secrets in environment variables; Do not store secrets in code
- Never use eval or innerHTML with user-provided data22 of 666 in 20 filesalso worded as never use eval or innerHTML with user input; never use eval or innerHTML with user data
- Do not run containers as root21 of 666 in 18 filesalso worded as Never run containers as root; Do not run containers as root in production
What they expect to be installed
- git80 of 666 in 78 files
- grep78 of 666 in 74 files
- npm audit59 of 666
- curl46 of 666
- bcrypt38 of 666 in 34 files
- npm37 of 666
- trivy36 of 666 in 33 files
- zod33 of 666 in 30 files
- python332 of 666 in 23 files
- pip-audit31 of 666
What they ask it to produce
- Security audit report114 of 666 in 107 filesalso worded as Security review report; Security report
- Security headers30 of 666 in 15 filesalso worded as Security headers configuration; Security header configurations
- Remediation recommendations27 of 666 in 23 filesalso worded as remediation guidance; Remediation plan
- Audit logs25 of 666 in 12 filesalso worded as security audit logs; Permission audit logs
- Threat model25 of 666 in 20 filesalso worded as threat models; threat model report
- Vulnerability scan reports25 of 666 in 23 filesalso worded as Vulnerability scan results; Security vulnerability report
- Parameterized queries22 of 666 in 10 filesalso worded as Parameterized SQL queries; parameterized database queries
- Security scan report19 of 666also worded as security findings report; Security scan reports
When Security authors say to reach for one
The situations these authors wrote into their own files, counted out of the same 666 authors, with the skills that name each one
- Implementing authentication or authorization58 of 666 in 41 files
- User requests security audit40 of 666 in 39 files
- Oma qa
- Review security
- Security auditor
- Pdlc security
- Security
- Audit xcode security settings
- and 5 more on this shelf
- User asks for a security review40 of 666 in 39 files
- User asks to find vulnerabilities30 of 666
- Managing secrets27 of 666 in 13 files
- Springboot security
- Quarkus security
- Discover security
- and 11 more on this shelf
- Security audit24 of 666
- Adding authentication23 of 666 in 8 files
- Springboot security
- Quarkus security
- Dpearson2699 ios security
- and 11 more on this shelf
- Security review22 of 666
How Security skills are built
6,415 skill directories by 1,120 authors, read from their repositories’ own file trees 2026-08-05
The middle bundle among those shipping files is 3 files, 20.5 KB beside SKILL.md
Counted by distinct author, same as above, so one author publishing forty template copies counts once. SKILL.md itself is not counted as a file, so a single-file skill is one where that file is the whole skill.
The shape
- SKILL.md is the whole skill442 of 1,120 authors, 2,819 of 6,415 skills
- files ship beside it678 of 1,120 authors, 3,596 of 6,415 skills
- executable scripts ship inside268 of 1,120 authors, 1,527 of 6,415 skills
The folders they converge on
- references/436 of 1,120 authors, 2,374 of 6,415 skills
- scripts/225 of 1,120 authors, 1,478 of 6,415 skills
- agents/99 of 1,120 authors, 325 of 6,415 skills
- assets/83 of 1,120 authors, 541 of 6,415 skills
- evals/57 of 1,120 authors, 143 of 6,415 skills
- templates/46 of 1,120 authors, 72 of 6,415 skills
ergrelet/windiff/.claude/skills/windiff-version-diff-analysis Skill
392★ repoTool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS, using a Web UI and/or LLMs.
hypnguyen1209/offensive-claude/skills/active-directory-attack Skill
344★ repoOffensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest
agamm/claude-code-owasp/.claude/skills/owasp-security Skill
325★ repoClaude Code skill for OWASP security best practices (2025-2026). Includes Top 10:2025, ASVS 5.0, Agentic AI security, and 20+ language-specific security quirks.
superagents-lab/xcode27-skills/audit-xcode-security-settings Skill
no license276★ repoApple's official Agent Skills exported from Xcode 27 — SwiftUI, UIKit modernization, Swift Testing, C bounds-safety, and security hardening for AI coding agents.
maddhruv/absolute/skills/absolute-audit Skill
206★ repoAbsolute Skills to 10x your Development Lifecycle
wiz-sec-public/SITF/.claude/skills/attack-flow Skill
no license177★ repoA comprehensive framework for analyzing and defending against attacks targeting Software Development Life Cycle Infrastructure.
KryptosAI/mcp-observatory/io.github.KryptosAI/mcp-observatory MCP server
176★ repoMCP security scanner. CI-native testing, attack simulation, health scoring, and SARIF.
alexgreensh/repo-forensics/plugins/repo-forensics/skills/forensify Skill
no license153★ repoOffline security scanner for AI-agent repos, skills, plugins, and MCP servers.
pillar-labs/sail-skill/sail/skills/sail Skill
no license130★ repoSAIL V2 (Secure AI Lifecycle) as an agent skill — the full 91-risk catalog for AI/agent gap assessments, security roadmaps, and compliance checklists. Installs on Claude Code, Codex, ChatGPT, Antigravity, and any SKILL.md-compatible agent.
sinewaveai/agent-security-scanner-mcp/io.github.sinewaveai/agent-security-scanner-mcp MCP server
120★ repoSecurity layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.
Wunderlandmedia/launchworthy/skills/launchworthy Skill
95★ repoA Claude Code skill that plays bouncer at the door of production: audits AI-built apps (Lovable, Bolt, v0, Cursor) across 5 domains and hands you a scored punch list with copy-paste fixes. MIT.
Pantheon-Security/notebooklm-mcp-secure/io.github.Pantheon-Security/notebooklm-mcp-secure MCP server
78★ repoSecurity-hardened NotebookLM MCP with post-quantum encryption
iammm0/secbot/skills/base/command-execution Skill
no license74★ repoAuthorized security testing workspace. v2 TypeScript terminal product on release; v1 Python on pypi-release; Go branch is demo only.
gebalamariusz/cloud-audit/io.github.gebalamariusz/cloud-audit MCP server
68★ repoAWS security scanner with attack chain detection, IAM privilege escalation, and fixes
dtkmn/mcp-zap-server/io.github.dtkmn/mcp-zap-server MCP server
63★ repoSafe, self-hosted OWASP ZAP operator for guided AI security scans and reports.
MihaiBuilds/memory-vault/io.github.MihaiBuilds/memory-vault MCP server
60★ repoLocal-first AI memory layer with hybrid search. Postgres + pgvector. Self-hosted, MIT.
kastelldev/kastell/io.github.kastelldev/kastell MCP server
56★ repoServer security audit (413 checks), hardening, and fleet management across 4 cloud providers.
atgreen/secscan-skill Skill
51★Mirror of https://cave.moxielogic.com/atgreen/secscan-skill
UnitOneAI/SecuritySkills/roles/appsec-engineer Skill
49★ repoOpen-source security skills for AI coding agents. Grounded in OWASP, NIST, MITRE ATT&CK, CIS. Works with Claude Code, Gemini CLI, Cursor, Codex CLI, OpenClaw, Kiro.
solanabr/auditor-skill Skill
48★Claude Code / agentic security skill for Solana programs and software. Full audit-firm lifecycle, executable PoC + fix-patch delivery, a Rust pre-scanner + cross-audit memory, 1,346 checks across 20 checklists, and 131 real-world attack vectors.
Perseus Vault (formerly Mimir/Mneme), persistent memory engine for AI agents
Perseus-Computing-LLC/perseus-vault/io.github.Perseus-Computing-LLC/perseus-vault MCP server
47★ repoPersistent, deterministic memory for AI agents. Local-first: SQLite, FTS5, AES-256-GCM, 55+ tools.
Zulut30/Wordpress-skills/skills/wordpress-plugin-dev Skill
42★ repoProfessional Agent Skill for building, auditing, testing, and releasing modern WordPress plugins with Codex, Cursor, and Claude Code.
mythos-agent/mythos-agent/io.github.mythos-agent/mythos-agent MCP server
39★ repoOpen-source AI security agent: SAST, DAST, and policy-as-code over MCP.
VAIBHAVSING/openghost/skills/openghost-skill Skill
38★ repoOpenGhost is an Agent Skill for authorized web app penetration testing: Enter lab url paste credential your agent and wait everything does with help of openghost
Copenhagen0x/solana-security-standard/io.github.Copenhagen0x/solana-security-mcp MCP server
36★ repoScan Solana/Anchor code against the Solana Security Standard and serve the ruleset to MCP clients.
netresearch/security-audit-skill/skills/security-audit Skill
no license35★ repoAgent Skill for PHP security audits - OWASP patterns, vulnerability detection | Claude Code compatible
withqwerty/nutmeg/skills/acquire Skill
no license31★ repoFootball data analytics toolkit for Claude Code. Covers Opta, StatsBomb, Wyscout, SportMonks, and free sources.
MoizIbnYousaf/marketing-cli/skills/agent-email-inbox Skill
29★ repoAgent-native marketing CLI: 58 skills, 5 research agents, brand memory that compounds across sessions, and a local Studio dashboard. One npm install, then /cmo in your coding agent.
pvliesdonk/markdown-vault-mcp/io.github.pvliesdonk/markdown-vault-mcp MCP server
27★ repoMarkdown vault MCP server with FTS5 + semantic search and frontmatter indexing
myclaude-sh/myclaude-creator-engine/.claude/skills/aegis Skill
24★ repoThe creation pipeline for Claude Code products — research, create, validate, publish. 13 types, 20 quality patterns, zero coding required.
frendysanusi/claude-pentest-skills Skill
no license23★AI-powered web application penetration testing skills with Claude Code
operantlabs/operant-mcp/io.github.operantlabs/operant-mcp MCP server
23★ repoSecurity testing MCP server for penetration testing, forensics, and vulnerability assessment
Orizon-eu/claude-code-pentest/api-breaker Skill
22★ repo6 Claude Code skills that automate the entire pentest lifecycle. From recon to exploit chains to bug bounty reports — just give it a domain. 43 scripts, zero dependencies, pure Python.
ShulkwiSEC/bb-huge/skills/bb-huge Skill
21★ repobb-huge 🤗 , Personal bug bounty findings hub and bug bounty orchestration for multiple agents
ChronoAIProject/Ornn/examples/api-fetch-wrapper Skill
19★ repoYour all-in-one skills-as-a-service platform to manage your skills, auto-generate skills and use agent skills as simple as calling an API.
sudais-khalid/vibe-ship Skill
18★A Claude Code / Claude.ai Skill that turns any codebase into something deployable with docker compose up and shippable through CI/CD, hardened by default, generated in one pass.
alpha-omega-security/threat-model/skills/threat-model-authoring Skill
18★ repoAgent skill for producing threat models for open-source projects
starslingdev/skills/skills/ci-speedup Skill
17★ repoFree, MIT-licensed agent skills from StarSling. ci-speedup audits your GitHub Actions workflows and reports, from real run history, why CI is slow.
aliasunder/vault-cortex/io.github.aliasunder/vault-cortex MCP server
17★ repoStandalone MCP server for Obsidian vaults — hybrid search, notes & files, memory, tasks, OAuth 2.1.
ShieldNet-360/secure-vibe/dist/agent-skills/.agents/skills/api-security Skill
15★ repoSecureVibe — prevention-first security for AI-written code. Signed SKILL.md knowledge that makes AI coding assistants write secure code at generation time, plus a deterministic CI gate. Offline · keyless · Ed25519-signed. By ShieldNet360.
screem500/prompt-injection-auditor Skill
13★Security audit skill for LLM agents - prompt injection scanner, attack catalog & defense checklist
OleksandrKucherenko/mcp-obsidian-via-rest/io.github.OleksandrKucherenko/mcp-obsidian-via-rest MCP server
13★ repoAccess Obsidian vaults via Local REST API - read, search, and interact with notes
Pulse8 ai cortex knowledge vault
synpulse8-opensource/pulse8-ai-cortex-knowledge-vault/io.github.synpulse8-opensource/pulse8-ai-cortex-knowledge-vault MCP server
12★ repoAgent-native knowledge OS on Markdown: typed graph, hybrid search, and compiler over MCP.
andrasfe/vulnicheck/io.github.andrasfe/vulnicheck MCP server
11★ repoHTTP MCP Server for comprehensive Python vulnerability scanning and security analysis.
vitormiziara/saas-security Skill
10★Claude skill for SaaS security auditing — 16 domains, 95 checks, OWASP-based
mlorentedev/hive/io.github.mlorentedev/hive-vault MCP server
9★ repoOn-demand Obsidian vault access for AI coding assistants — 17 tools, 5 resources, 4 prompts.
jessepwj/vault-loop/skill/vault-loop Skill
8★ repoOpen-source prompt and Agent Skill for recurring knowledge-base update loops
miclivne/oc-security-audit/plugins/oc-security-audit/skills/oc-security-audit Skill
no license8★ repoFull-stack security audit skill for AI coding agents. OWASP WSTG testing + infrastructure, deployment, and privacy checks. Works with Claude Code, Codex, Cursor, Gemini CLI, Copilot.
b3sty191/b3sty-skill Skill
no license8★b3sty RedM/FiveM Lua Codex skill
playbookTV/Ironclad/skills/app-audit Skill
no license7★ repoAgent-agnostic operating procedures for reviewing, debugging, testing, refactoring, and hardening software.
snyk/saw-mcp/io.github.snyk/saw-mcp MCP server
7★ repoMCP server for Snyk API & Web — DAST scanning, findings management, and vulnerability triage
smicolon/ai-kit/packs/better-auth/skills/auth-security Skill
no license6★ repoConvention packs for any AI coding tool - agents, skills, commands, and rules for 15 tools including Claude Code, Cursor, Windsurf, and Copilot
jpmorgan-payments/pdp-skills/skills/jpm-integrations-get-started Skill
6★ repoAgent skills that give GitHub Copilot, Claude Code, and other AI coding assistants procedural knowledge of J.P. Morgan Payments APIs. Walks external developers from onboarding and credential setup through OAuth implementation and live API integration with Checkout and Online Payments.
jph4cks/redhound-arsenal/aircrack-ng Skill
6★ repo76 AI-agent security skills for Kali Linux tools — pentest, red team, forensics, OSINT, and more. Machine-readable skill definitions by Red Hound InfoSec.
rogerdigital/vault-inspector/skills/vault-inspector Skill
6★ repoAn Obsidian vault health checker for finding broken links, orphan attachments, duplicate files, frontmatter drift, stale tags, and large files.
VouchlyAI/Pincer-MCP/io.github.VouchlyAI/pincer MCP server
no license6★ repoSecure grip for your agent's secrets - security-hardened MCP gateway with proxy token architecture
subhashdasyam/security-antipatterns-python Skill
no license5★Claude Code or Codex Skill that teaches AI coding agents to write secure Python. Catches SQL injection, pickle attacks, hardcoded secrets, and other OWASP Top 10 patterns in Django, Flask, and FastAPI code.
EresusSecurity/appsec-skills/skills/eresus-codeql-heuristics Skill
5★ repoProduction-ready AI AppSec skills for SAST, threat modeling, remediation, PR security review, and serialization abuse analysis.
maxwellokumu/okaudit-claude-skills/application-security/appsec-playbook Skill
no license5★ repoClaude-ready IT audit skills for identity, compliance, appsec, privacy, network, logging, vendor risk, and audit leadership workflows
goingli0324/web-security-reviewer Skill
5★Claude Code skill: defensive security review of your own code (Apps Script, frontend, backend)