Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Malicious SkillSample skill for atkx:skill-eval holding one case of each kind of security gate failure. A fixture with a known verdict, never to be installed or run. Its hosts are all under example.invalid, and help comes from docs.example.invalid.Votes: 0GitHub stars: 8
- Good SkillSample skill for atkx:skill-eval: summarises a changelog file into three lines for a release announcement. A fixture with a known verdict, not a skill to install. Triggers on: "summarise the changelog", "tóm tắt changelog", "変更履歴を要約".Votes: 0GitHub stars: 8
- Skill EvalEvaluate an agent skill a project has written, for Claude Code, Codex or Cursor: a static check of its structure, metadata, size and safety, with a security gate for what the skill does and not only what it holds, a check against the project's own written conventions, trigger measurement on Claude Code, drafted trigger cases it lacks, a review of one run of it in this conversation, and one composite score with a grade above the figures behind it. Reads the skill and changes nothing in it. Use...Votes: 0GitHub stars: 8
- Run CasesExecute approved test cases against a deployed DEV or staging environment through the browser: refuse production and the local stack, recon the accounts and data, triage every case as automatable, semi-automatable, manual, or blocked, naming the person who clears any obstacle the run cannot clear itself, agree the scope with the person before any case runs, run in at most three rounds, and write only the results it observed into a run record the QA lead approves and `atk:qa --bug` reads. Use ...Votes: 0GitHub stars: 8
- OrchestrateInternal, invoked from the orchestration context: tier classification, delegation model table, and phase-owner dispatch rules for sizing and dispatching implementation work.Votes: 0GitHub stars: 207
- InitSets up Task Orchestrator for a project or for the user: creates (or finds) the project anchor root, writes the project: block into .taskorchestrator/config.yaml at the main checkout root, pushes it to the server, and seeds the bundled process rules. In project mode it also writes a project-level client.json when the server is a loopback HTTP server. With --user it creates a personal root and writes the user-level config.yaml and client.json instead. Use when a user says: initialize task orch...Votes: 0GitHub stars: 207
- Salt Code Policy Honesty Not CloneSalt Code (getsaltcode.com by Salt Security) provides 40 security policies as prompt-time context injection, not an execution firewall. Steal the 40-policy taxonomy, OpenAPI query-string auth diode, and MCP credential hygiene onto ThumbGate PreToolUse rails. Never install Salt Code MCP or route traffic to mcp.getsaltcode.com. Slash: /salt-code-policy-honesty-not-clone.Votes: 0GitHub stars: 27
- GraphifyUse for any question about a codebase, its architecture, file relationships, or project content — especially when graphify-out/ exists, where the question should be treated as a graphify query first. Turns any input (code, docs, papers, images, videos) into a persistent knowledge graph with god nodes, community detection, and query/path/explain tools.Votes: 0GitHub stars: 27
- Tailscale P2p Governance Not CloneTailscale PAM and HiveMind (2026-09) are decentralized sync & Zero-Trust network formats, not ThumbGate clones. Steal the P2P G-Set CRDT rule sync and PAM privileged execution diode onto existing ThumbGate PreToolUse rails; never vendor HiveMind, require root SSH, or expose public broker endpoints. Slash: /tailscale-p2p-governance-not-clone.Votes: 0GitHub stars: 27
- Siren Mcp GovernanceSiren MCP Marketing Diode & Autonomous Campaign Governance. Enforce pre-action review diodes on post_run, 300s buffer guards on schedule_post, $500 daily budget ceilings on create_campaign, brand safety scanning, and partner link attribution ("Video made with Siren" -> https://mysiren.ai). Slash: /siren-mcp-governance.Votes: 0GitHub stars: 27
- Salt Code Policy Honesty Not CloneSalt Code (getsaltcode.com by Salt Security) provides 40 security policies as prompt-time context injection, not an execution firewall. Steal the 40-policy taxonomy, OpenAPI query-string auth diode, and MCP credential hygiene onto ThumbGate PreToolUse rails. Never install Salt Code MCP or route traffic to mcp.getsaltcode.com. Slash: /salt-code-policy-honesty-not-clone.Votes: 0GitHub stars: 27
- Meko Datapack Honesty Not CloneMeko Data (YugabyteDB 2026) is an agent data store, not a ThumbGate clone. Steal the five-plane FORMAT (datapack / memory / learning / artifact / trace) onto existing ThumbGate rails; never vendor YugabyteDB, meko-skills, or depend on cloud.mekodata.ai. Slash: /meko-datapack-honesty-not-clone.Votes: 0GitHub stars: 27
- Infoq Architect Honesty Not CloneInfoQ's September 2026 architects newsletter is FORMAT, not a ThumbGate product. Steal code-as-truth, a typed host, the existing lease, and time-in-queue. Never register for InfoQ or QCon, install Vortex, or add Temporal. Slash: /infoq-architect-honesty-not-clone.Votes: 0GitHub stars: 27
- Aws Strands Harness Not CloneAWS Strands Harness (The New Stack 2026-10 / Marc Brooker) is an agent runtime architecture, not a ThumbGate clone. Steal the three context-management defaults (output shunting <= 350 lines, 75% compaction threshold, in-loop recovery) and inject ThumbGate's PreToolUse diode. Never vendor Bedrock-only dependencies. Slash: /aws-strands-harness-not-clone.Votes: 0GitHub stars: 27
- K2Build and troubleshoot Cloudflare K2 or K2 Streams durable logs. Use for stream setup, producing from Workers or HTTP, configuring retention and inputs, and consuming through subscriptions.Votes: 0GitHub stars: 2,994
- Neo4j Vector Index SkillCreate and manage Neo4j vector indexes, run vector similarity search (ANN/kNN),Votes: 0GitHub stars: 114
- Neo4j Spring Data SkillUse when building Spring Boot applications with Neo4j using Spring Data Neo4j (SDN 7.x/8.x) —Votes: 0GitHub stars: 114
- Neo4j Spark SkillUse when reading from or writing to Neo4j with Apache Spark or Databricks using theVotes: 0GitHub stars: 114
- Neo4j Snowflake Graph Analytics SkillRun Neo4j Graph Analytics algorithms (PageRank, Louvain, WCC, Dijkstra, KNN,Votes: 0GitHub stars: 114
- Neo4j Security SkillProgrammatic security management in Neo4j — RBAC/ABAC, user lifecycle (CREATE/ALTER/DROP USER),Votes: 0GitHub stars: 114