Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Rule SecuritySecurity rules this project always applies: secret handling, input validation, parameterized queries, and Supabase RLS. Load before writing code that touches credentials, user input, queries, or auth.Votes: 0GitHub stars: 6
- SecuritySecurity best practices, OWASP Top 10, and secure coding guidelinesVotes: 0GitHub stars: 105
- SecSecurity Engineer for authentication, authorization, secrets, trust boundaries, unsafe inputs, data exposure, and practical security review.Votes: 0GitHub stars: 13
- Persona SecuritySecurity-first decision framework for threat modeling, vulnerability assessment, and compliance review. Use when user discusses security concerns, authentication design, encryption, OWASP compliance, XSS or CSRF prevention, or vulnerability remediation, or mentions 취약점, 보안, or 위협.Votes: 0GitHub stars: 3
- SecurityBuild-time security discipline — threat-model before controls, Always/Ask-First/Never boundary tiers, SSRF, supply chain, LLM/agent security, privacy. INVOKE PROACTIVELY when building anything touching auth, user data, uploads, outbound fetches, dependencies, or model output — even when nobody says "security". The after-the-fact review pass belongs to /security-review; validation mechanics: [[code-standards]]; infra secrets: [[infra-standards]].Votes: 0GitHub stars: 3
- Security CheckIndependently assess a change, product, workflow, or deployment for realistic security and privacy risk, reporting outcome separately from coverage. Use for trust-boundary or exposure changes and explicit security review.Votes: 0GitHub stars: 5
- Security PaperclipPaperclip security — tenancy isolation, secrets, approval gates, hard budgets, signed adapter channel. Use when auditing or hardening Paperclip.Votes: 0GitHub stars: 105
- Security ReviewUse when reviewing code or a diff for security issues before merging. Flags concrete, high-confidence vulnerabilities with fixes.Votes: 0GitHub stars: 9
- Security PaperclipSeguranca Paperclip — isolamento tenancy, secrets, gates aprovacao, orcamentos rigidos, canal adapter assinado. Use ao auditar ou fortalecer Paperclip.Votes: 0GitHub stars: 105
- Security Engineer RoleOperate as a security engineer who reduces real risk through threat models, targeted reviews, scalable tooling, and incident duty. Use when a system's security posture is your responsibility and you must prevent and respond, not just audit.Votes: 0GitHub stars: 7
- Security PaperclipSeguridad de Paperclip — aislamiento de tenencia, secretos, compuertas de aprobación, presupuestos duros, canal de adaptador firmado. Usar al auditar o endurecer Paperclip.Votes: 0GitHub stars: 105
- Security ReviewUse when reviewing code or a diff for security issues before merging. Flags concrete, high-confidence vulnerabilities with fixes.Votes: 0GitHub stars: 9
- Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.Votes: 0GitHub stars: 2
- Sifap SecurityProtects SIFAP authentication, authorization, secrets, CPF, financial data, logs, and untrusted agent context. Use when editing security-sensitive backend, frontend, configuration, or automation.Votes: 0GitHub stars: 2
- Sifap SecurityProtects SIFAP authentication, authorization, secrets, CPF, financial data, logs, and untrusted agent context. Use when editing security-sensitive backend, frontend, configuration, or automation.Votes: 0GitHub stars: 2
- Supply Chain SecurityProtect a project and its users from compromised dependencies, publishing credentials, and build pipelines. Use when publishing packages or auditing what your build actually trusts.Votes: 0GitHub stars: 7
- Security And HardeningThreat-models and hardens an application, API, data flow, dependency, or deployment against authentication and authorization flaws, injection, secrets exposure, unsafe deserialization, SSRF, abuse, privacy loss, and supply-chain risk. Use for security review, threat modeling, hardening, or sensitive changes. Not for generic code style review or an unexplained bug without a security hypothesis.Votes: 0GitHub stars: 95
- Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.Votes: 0GitHub stars: 46,327
- Security ArchitectPragmatic security architect for a non-security-expert owner. Covers auth design (JWT/OAuth/sessions), where secrets and tokens live on each platform (iOS/Android/macOS/Windows/Linux/web), MITM and TLS, web vulns (XSS/CSRF/CORS/CSP), backend authorization (IDOR, injection, webhooks, rate limits), database rules (Supabase RLS/Firestore/Postgres policies), and AI-agent/MCP tool permissions. Load when the user asks "is this secure?", "where should I store this secret/token?", designs a login or ...Votes: 0GitHub stars: 2
- Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.Votes: 0GitHub stars: 9