Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Supply Chain SecurityProfessional Supply Chain Security Expert skill. Implement enterprise-grade web application security controls and encryption standards.Votes: 0GitHub stars: 3
- Security And HardeningHarden authentication, input handling, storage, and integrations when implementing security controls or remediating concrete vulnerabilities.Votes: 0GitHub stars: 70
- Security ArchitectPragmatic security architect for a non-security-expert owner. Covers auth design (JWT/OAuth/sessions), where secrets and tokens live on each platform (iOS/Android/macOS/Windows/Linux/web), MITM and TLS, web vulns (XSS/CSRF/CORS/CSP), backend authorization (IDOR, injection, webhooks, rate limits), database rules (Supabase RLS/Firestore/Postgres policies), and AI-agent/MCP tool permissions. Load when the user asks "is this secure?", "where should I store this secret/token?", designs a login or ...Votes: 0GitHub stars: 2
- Security ReviewDefend before attackers find the gaps - OWASP, STRIDE, and Microsoft SFIVotes: 0GitHub stars: 4
- Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.Votes: 0GitHub stars: 9
- Security And HardeningHardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when auditing dependencies for known vulnerabilities, triaging package-manager audit findings, or assessing supply-chain risk in a...Votes: 0GitHub stars: 2
- Cybersecurity PrinciplesUse when explaining cybersecurity foundations, the Saltzer-Schroeder design principles, CIA triad, Zero Trust architecture, defense in depth, AAA model, threat intelligence, NIST CSF 2.0, CIS Controls, ISO 27001, modern IAM (FIDO2/passkeys/PAM), SASE, incident response, or building a security mental model. Use for any conceptual cybersecurity question, when grounding security decisions in first principles, when explaining why a security control exists, when evaluating security trade-offs, or ...Votes: 0GitHub stars: 2
- Security ReviewUse as a REVIEW LENS when judging another agent's diff for security defects — injection, broken authentication or authorization, secrets in code, unsafe deserialisation, SSRF, path traversal, missing validation, mass assignment, insecure defaults — before recommending approval. Invoke on every review of a ticket that touches auth, input handling, data access, outbound requests, files, crypto, or configuration, and on any high-risk ticket; it complements review-ticket, it does not replace it.Votes: 0GitHub stars: 2
- Security PaperclipSécurité Paperclip — isolation tenant, secrets, portes d'approbation, budgets stricts, capacités plugin minimales. À utiliser pour auditer ou durcir Paperclip.Votes: 0GitHub stars: 105
- Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when personal data or privacy compliance (GDPR, CCPA) is involved.Votes: 0GitHub stars: 3
- Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.Votes: 0GitHub stars: 45,848
- SecuritySecurity standards for .NET applications based on OWASP guidelines.Votes: 0GitHub stars: 8
- Code Safetytrigger: secrets, eval/exec, unsanitized SQL, hallucinated dependencies. avoid: committing credentials, adding unverified packages, executing dynamic code. Install scan-secrets (commit, agent write) for secrets and verify-dependency-exists (opt-in; needs an allowlist) for dependencies. Advisory: eval/exec and SQL guidance; a gate decides only the non-literal slice (agentic-code-security code pack: Python eval/exec, SQL built from strings in Python and JS).Votes: 0GitHub stars: 3
- Security And HardeningSecure-coding practices while building features that handle input, auth, sessions or data. Use when the user says 'add login', 'handle file uploads', 'secure this endpoint', 'store user data safely' or 'add a webhook'. For a pre-launch audit use security.Votes: 0GitHub stars: 3
- Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.Votes: 0GitHub stars: 274
- SecuritySecurity standards for Flutter applications based on OWASP Mobile.Votes: 0GitHub stars: 8
- SecurityApply security best practices to code, architecture, and workflows. Trigger whenever the user mentions authentication, authorization, API keys, secrets, encryption, vulnerabilities, OWASP, SQL injection, XSS, CSRF, data exposure, penetration testing, security review, or asks "is this secure?". Also trigger proactively when reviewing code that handles user data, passwords, tokens, or network requests. When to trigger: during any code review pass when the diff touches auth, payments, user input...Votes: 0GitHub stars: 3
- Ag 8 SegurancaMaquina autonoma de seguranca (wrapper SENTINEL). Security + load testing + LGPD compliance. 6 dimensoes, modo hybrid, convergencia SSS >= 80. Security Certificate.Votes: 0GitHub stars: 4
- Security ReviewFinds and fixes security vulnerabilities in application code. Use when asked about injection, XSS, CSRF, authentication or authorization flaws, secret handling, unsafe deserialization, or when hardening an endpoint. Triggers include "vulnerability", "SQL injection", "취약점", "보안", "인증 우회".Votes: 0GitHub stars: 2
- Security First ScrumUse this skill for ALL greenfield .NET 8 Web API / React / Blazor / Cosmos DB / PostgreSQL / Databricks development on Azure. Trigger whenever you are starting a new feature, writing any .NET controller, service, repository, React component, Blazor page, Databricks pipeline, or any Azure infrastructure. This skill replaces the CLAUDE.md ruleset: it enforces the Security-First Scrum framework — three laws (Security First, People First, Agile/Scrum), eight inviolable security principles, onion ...Votes: 0GitHub stars: 2