Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- SecurityEnforces security best practicesVotes: 0GitHub stars: 28
- Common Security StandardsUniversal security protocols for safe, resilient software. Use when implementing authentication, encryption, authorization, or any security-sensitive feature. (triggers: **/*.ts, **/*.tsx, **/*.go, **/*.dart, **/*.java, **/*.kt, **/*.swift, **/*.py, security, encrypt, authenticate, authorize)Votes: 0GitHub stars: 43
- Common Security StandardsEnforce universal security protocols for safe, resilient software. Use when implementing authentication, encryption, authorization, input validation, secret management, or any security-sensitive feature across any language or framework.Votes: 0GitHub stars: 549
- Common Security StandardsEnforce universal security protocols for safe, resilient software. Use when implementing authentication, encryption, authorization, input validation, secret management, or any security-sensitive feature across any language or framework.Votes: 0GitHub stars: 549
- Go SecurityUse when identity, authorization, tenancy, tokens, secrets, injection, SSRF, abuse, or another trust boundary changes what an attacker can reach.Votes: 0GitHub stars: 7
- Security GuardSecurity specialist - finds vulnerabilities and ensures best practicesVotes: 0GitHub stars: 13
- Common Security StandardsAssumption: your application receives PII through APIs, processes it in an application service, and must later decrypt it for authorized use. Implement this flow: 1. Validate and sanitize PII at every trust boundary: API, UI, CSV, and webhook. 2. Encrypt PII in the application before persistence using authenticated AES-256 encryption, preferably AES-256-GCM. 3. Store encryption keys only in a secret manager or environment-backed key-management system—never hardcode or commit them. 4. Use TLS ...Votes: 0GitHub stars: 549
- Dependency SecurityVet, pin and update third-party dependencies deliberately.Votes: 0GitHub stars: 3
- Security DocumentationCreate security policies, guidelines, compliance documentation, and security best practices. Use when documenting security policies, compliance requirements, or security guidelines.Votes: 0GitHub stars: 327
- Security ReviewThe security trigger and review procedure for this project. Use when deciding whether work needs a security pass, and to run one -- "does this need security review?", auth changes, new input surfaces, new tools.Votes: 0GitHub stars: 3
- Ios SecuritySecure iOS apps with Keychain, biometrics, and data protection. Use when implementing Keychain storage, Face ID/Touch ID, or data protection in iOS.Votes: 0GitHub stars: 549
- Security And HardeningHardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when auditing dependencies for known vulnerabilities, triaging package-manager audit findings, or assessing supply-chain risk in a...Votes: 0GitHub stars: 100,830
- security-scannerScans code for security vulnerabilities and suggests fixes. Use when checking for security issues, validating input handling, or performing security audits.Votes: 0GitHub stars: 14
- Ios SecurityFor iOS security best practices, focus on a few non-negotiables: - Store tokens, credentials, and PII in the Keychain using `SecItemAdd`, `SecItemUpdate`, and `SecItemDelete` with `kSecClassGenericPassword`. Do not store secrets in `UserDefaults`. - Use biometrics through `LocalAuthentication` and `LAContext`. Check `canEvaluatePolicy` before prompting, and handle cases like `userCancel` and `authenticationFailed`. - Protect files written to disk with `Data.WritingOptions.completeFileProtecti...Votes: 0GitHub stars: 549
- SecuritySecurity category index for Apple platforms. Routes to the privacy-manifests skill. General secure-storage/biometrics/ATS guidance was retired in the 2026 blind-test audit — current models cover it natively.Votes: 0GitHub stars: 693
- Security Auditor 1.0.0Use when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation, SQL injection preventiVotes: 0GitHub stars: 2
- SecuritySecure coding practices for agent-native apps: input validation, SQL injection, XSS, secrets, data scoping, and auth. Use when writing any action, route, or component that touches user data or external input.Votes: 0GitHub stars: 6,969
- Android SecurityStandards for Data Encryption, Network Security, and Permissions. Load whenever API keys, auth tokens, cleartext traffic, android:exported, EncryptedSharedPreferences, certificate pinning, or root detection come up — even if the user just asks 'is this secure'. (triggers: network_security_config.xml, AndroidManifest.xml, EncryptedSharedPreferences, cleartextTrafficPermitted, intent-filter, api key, token storage, certificate pinning, root detection, secure storage)Votes: 0GitHub stars: 43
- Flutter SecurityEnforce OWASP Mobile security standards for Flutter apps. Use when storing sensitive data, making network calls, handling tokens/PII, or preparing release builds.Votes: 0GitHub stars: 549
- Java Application Security BasicsApplication-security judgement for Java 21+: password storage with current memory-hard KDF parameters, constant-time verification, secure randomness, authorisation inside the protected operation, adversarial validation, reversible-cryptography boundaries, and secret-safe types. Use when credentials, password hashes, salts, bearer tokens or peppers change; when MessageDigest, SecureRandom, Random, UUID, Cipher, Mac or PasswordEncoder serves a security purpose; when a controller annotation is t...Votes: 0GitHub stars: 2