Security
7,261 rows, by stacks then stars
772 of these skill files have been read, by 666 distinct authors, and what they tell an agent counted. What Security authors agree on, and what they forbid
Dolphinllc/claude-security-skills/skills/defensive/genai/anthropic-sdk-security-scan Skill
1★ repoDefensive security skills for Claude Code and the Claude Agent SDK — web applications and generative AI systems.
Skill security vulnerability management
zavora-ai/skill-security-vulnerability-management Skill
no license1★Security vulnerability skill — CVE search, dependency audit, risk scoring, remediation plans
Github actions security review
Fyzel/claude-skills/skills/github-actions-security-review Skill
1★ repoA collection of Claude skills.
hlsitechio/claude-skills-security/appsec-stack-pack/angular-security Skill
1★ repoDefensive security audit skills for Claude — tech-stack-keyed and audit-domain-keyed packs for SaaS apps.
skshadan/kage/skills/kage Skill
no license1★ repoA Claude Code plugin that runs a full pentest engagement from inside your coding agent. Point it at a target and it works through recon, deep testing, exploit verification, chain-building, judging, and writes audit report.
hootbu/llm-wiki-mind/skills/vault-init Skill
1★ repoPersistent Obsidian wiki pattern for LLM agents: starter template + init script + Claude Code skills for continuous, cumulative knowledge archives.
ecosyste-ms/skills/skills/advisories Skill
1★ repoClaude Code skills for querying the ecosyste.ms APIs
Laucked-Security/claude-oswe/skills/audit Skill
1★ repoWhite-box, OSWE-style security audit for Claude Code: traces source→sink, chains findings to unauthenticated RCE, verifies each chain, and writes an evidence-backed Markdown + HTML report. PHP · Node · Python · Java · .NET.
kauaim/skills/prompt-injection-guard Skill
no license1★ repoFree, open-source skills for Claude Code and Claude Desktop — starting with a prompt-injection guard for safely ingesting untrusted documents.
Grenguar/node-aws-security-audit Skill
1★Security audits for Node.js on AWS — NextJS, Lambda, ECS, API Gateway, IAM, and OWASP Top 10. Score 0-100 with remediation code.
oktsec/audit Skill
1★Security audit for AI-built projects. 130+ checks across OWASP Top 10. Auto-detects stack, loads relevant checks, grades your project A-F with exact fixes.
meirdick/laravel-prod-ready/skills/laravel-prod-ready Skill
1★ repoLaravel production readiness audit skill — 6-dimension scored review (Security, Scalability, Reliability, Hardening, Code Quality, Ops) with actionable, copy-pasteable fixes. Works with Claude Code, Cursor, and other Agent Skills-compatible tools.
mnedelchev-vn/solidity-claude-setup/.claude/skills/smart-contract-analyzer Skill
1★ repoClaude Code skills purpose-built for Solidity security auditing and protocol research.
Nick2bad4u/Github-Security-CodeScanning-Alerts-Skill/skills/github-manage-security-alerts Skill
1★ repoA Copilot / AI skill for managing GitHub Code Scanning, Security, Dependabot, etc alerts.
AtlasPA/openclaw-vault Skill
no license1★Credential lifecycle security for OpenClaw workspaces. Audit exposure, inventory secrets, detect stale credentials. Free alert layer.
anthalehq/anthale-agent-skills/skills/prompt-injection-hardening Skill
1★ repoAnthale's official AI agent security skills
designgrappler/agent-os/claude/skills/audit-security Skill
1★ repoAgent OS is a management layer for complex, multi-agent AI projects. Instead of letting agents get lost in endless conversational loops, it enforces a disciplined workflow: upfront planning, shared context, scoped work tracks, and strict quality gates — so every agent stays focused, coordinated, and aligned from start to finish.
moonki080/qa-vibe-test-specialist Skill
1★Run CSTS/ISTQB/ISO-aligned QA, tests, and remediation loops for vibe-coded AI software
riz007/architect-os/skills/aos-audit Skill
1★ repoAI-native software engineering operating system for modern application architecture, scaffolding, and AI-assisted development.
zkeviny/MGC-Blackbox/mgc_skill/MGC_Script_Execution Skill
no license1★ repoA Safe Vault for AI Agents. No key exposure. Encrypted script execution — local or external.
pop123-ux/agent-security-skills/skills/api-security Skill
1★ repoProduction-grade security Agent Skills (SKILL.md) for Claude Code, Claude agents & OpenClaw: OWASP API Top 10 patterns + authentication/authorization patterns.
P1tak4s/production-readiness-audit Skill
1★Claude Agent Skill: scan, review & harden codebases for production — security, reliability, testing, data/compliance, ops, accessibility. Includes a dependency-free scanner, deep checklists, and templates.
AmirHosein-Lotfi/Seaworthy/skills/seaworthy Skill
1★ repoCatches the exact security mistakes that have actually breached real AI-built apps, before you deploy.
GeorgeMJZak/before-you-deploy/skills/pre-deploy-security-review-pl Skill
1★ repoA pre-deploy security review skill for any AI agent (Claude, Codex, Gemini). Runs the 'Before You Deploy Your Vibe-Coded App' 8-category review on your real code.
ysys143/pg-extension-lab/skills/pg-extension-lab Skill
1★ repoA harness for testing, benchmarking, and tuning PostgreSQL extensions in an isolated, reproducible environment.
Freedomzyi/vault-keeper-zy Skill
no license1★🤖 AI 驱动的 Obsidian 知识库自动化管家 · Zettelkasten + PARA + 渐进摘要 · 零手动维护
maherukhislam/postgres-auth-security-review/skills/postgres-auth-security-review Skill
1★ repoAn Agent Skill that reviews and writes PostgreSQL/Supabase authentication code against a researched set of common and uncommon security mistakes - before it ships.
SuperLogicAI/production-agent-design Skill
1★Architect high-reliability, logic-driven AI agents for production.
Mahermenix/vault-sync Skill
1★Your project's second mind — a Claude Code skill that turns every session into structured, linked Obsidian notes your AI can reference.
leksman/ai-security-guard Skill
1★Claude skill + drop-in code for hardening & auditing LLM features against prompt injection, privilege escalation, marker forgery, and data leaks
piyushomanwar16/vibe-app-security-audit/skills/vibe-app-security-audit Skill
1★ repoAgent skill: security audit & hardening for vibe-coded apps (5-phase loop: secrets, PII, pre-deploy, deep logic, attacker review).
Chill-AI-Space/vault-mcp/io.github.Chill-AI-Space/vault MCP server
1★ repoMCP server for credential isolation — bots use passwords and API keys without seeing them
RobThePCGuy/rag-vault/io.github.RobThePCGuy/rag-vault MCP server
no license1★ repoLocal RAG MCP server with hybrid search, PDF/DOCX support, and zero-config setup
Shrike-Security/shrike-mcp/io.github.Shrike-Security/shrike-mcp MCP server
1★ repoAI agent security scanner — prompt injection detection, SQL injection, PII isolation, threat intel.
Multi-workspace Slack MCP server with draft+confirm safety, vault auto-export, a
adelaidasofia/slack-mcp/io.github.adelaidasofia/slack-mcp MCP server
1★ repoMulti-workspace Slack MCP server with draft+confirm safety, vault auto-export, and triple-mode…
cyanheads/attack-surface-mcp-server/io.github.cyanheads/attack-surface-mcp-server MCP server
1★ repoPassive external attack-surface mapping: CT subdomains, DNS, TLS, HTTP posture, RDAP/WHOIS, Shodan.
cyanheads/pentest-mcp-server/io.github.cyanheads/pentest-mcp-server MCP server
1★ repoOffline methodology engine for authorized penetration testing, CTF, and security research.
ericlovold/sanction/io.github.ericlovold/sanction MCP server
no license1★ repoAuthorize an AI agent's spend & credential use before it acts — budgets, encrypted vault, audit.
lordbasilaiassistant-sudo/base-security-scanner-mcp/io.github.lordbasilaiassistant-sudo/base-security-scanner-mcp MCP server
no license1★ repoMCP server to scan smart contracts on Base for honeypots, rug pulls, and vulnerabilities.
PQC-Khepra MCP — CMMC Autopilot & AI Security Recorder
nouchix/PQC-Khepra-MCP/io.github.nouchix/pqc-khepra-mcp MCP server
no license1★ repoPost-quantum CMMC compliance scanner & AI agent attestation. FIPS 140-3, ML-DSA-65, 36K+ mappings.
rom-baro/arcwall-mcp/io.github.rom-baro/arcwall-security MCP server
no license1★ repoSecurity scanning for AI coding tools. Detects secrets, threat models, and runs pre-commit checks.
Runesmith-Studio/claude-vault Skill
0★Back up and migrate your Claude Code setup (~/.claude) safely across machines and accounts. Cross-platform, pure Python stdlib, MIT licensed.
PiyushSolanki038/security-code-review Skill
0★AI-powered security code review skill for Claude — finds SQLi, XSS, IDOR, auth bugs & more by reading your code, not payload lists
mihailShumilov/solana-incident-response-skill/skill Skill
0★ repoLive security incident-response & war-room playbook skill for Solana (Solana AI Kit).
x7dl8p/OpenSkill-Marketplace/skills/Security-Expert Skill
no license0★ repoA structured registry & a part of OpenSkills project, meant for reusable skill.md files to extend AI agents with deterministic, domain-specific capabilities.
safedep/skills/skills/safedep Skill
0★ repoSafeDep agent skills
skyblueso/gatekeeper Skill
0★Security scanner for GitHub repos, MCP servers, AI agent packages, and local projects. One command. Any repo. Letter grade A through F.
reasonless-throne486/sast-skills/sast-files/.agents/skills/sast-analysis Skill
0★ repoScan codebases for security flaws with LLM agent skills that turn Claude Code, Cursor, and other assistants into SAST scanners
alinafe82/cognitive-deadlift/skills/agent-security-boundary Skill
0★ repoAI coding skills, hooks, and plugins that keep developers thinking instead of autopiloting
grupomidiasystems/auditoria-seguranca-lovable-supabase/skill Skill
no license0★ repoChecklist público para auditoria de segurança em projetos Lovable + Supabase antes da publicação.
tga-cheetung/account-intelligence-vault/.claude/skills/account-vault Skill
0★ repoOne markdown file per target account. Agents read it before every score, email, and call. Every signal compounds. Public Claude Code skill + heartbeat + per-account schema that mirrors your CRM.
thiagoferal-ia/thiago-feral-skills/skills/supabase-owasp-audit Skill
0★ repoHub de Skills Thiago Feral
SkillMedev/security-compliance-hardening/skills/dependency-risk-audit Skill
0★ repoThreat models, secure reviews, and compliance evidence — ship with confidence.
giljr/claude Skill
no license0★Documenting discoveries, experiments, and lessons learned while pushing the boundaries of AI-assisted software development
kumard3/lumbox-skills/agent-email-patterns Skill
no license0★ repoOfficial agent skills for Lumbox — email infrastructure for AI agents (inboxes, OTP extraction, send/reply via REST + MCP).
siam-hossain9/secure-development-skill/plugins/secure-development/skills/secure-development Skill
0★ repoSecure Development — a Claude Code skill: 23 security reference domains + a phase-by-phase secure build lifecycle (secure-by-design).
edilkoke/vibeguard Skill
0★Scans AI-generated Next.js + Supabase code for the 21 most common security holes (exposed secrets, broken access control, injection) and blocks them in CI.
SSBrouhard/npm-package-release-hardening Skill
0★An agent skill that hardens npm packages before public release — catches shipped secrets, runtime-floor mismatches, and tarball junk. Works in any skills-compatible agent.
ayman-benmada/owasp-security-audit/skills/security-audit Skill
no license0★ repoOWASP Top 10 (2025) security audit plugin for Claude Code and Cursor. Stack-aware scanning that produces a complete vulnerability report.
omonuj/claude-horizon-skills/skills/fanout-cve-rollout/fanout-cve-iteration-loop Skill
no license0★ repoClaude Code Agent Skills for building, red-teaming and tuning agentic RL evaluation environments — a four-skill pattern (guardian, validation-debugger, score-tuner, iteration-loop) plus a 24-point adversarial reviewer.