Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Entra Posture ReviewReview a Microsoft Entra ID tenant's identity posture from read-only Graph exports, checking Conditional Access basics, security defaults, standing Global Administrators, guests with roles, stale guests, long-lived app secrets, high-risk Graph application permissions, consent and invitation settings and legacy sign-ins. Use when asked \"who are our Global Admins?\", to baseline a tenant, before an ISO 27001 or Essential Eight audit, or after taking one over. Not for Intune devices (intune-bas...Votes: 0GitHub stars: 2
- Osv ScannerThis skill should be triggered when the user asks about dependency security, vulnerability scanning, or package safety. Examples: \"check my dependencies for vulnerabilities\", \"scan my packages\", \"are my dependencies safe\", \"dependency audit\", \"check for CVEs\", \"security audit\", \"vulnerable packages\", \"scan dependencies for vulnerabilities\".Votes: 0GitHub stars: 4
- Eisenhower PrioritizationPrioritize any workload using the Eisenhower Matrix. Use this skill whenever a user provides a brain dump of work—Jira summaries, meeting notes, sprint dumps, task lists, or prose descriptions of their workload. This skill categorizes tasks into four quadrants: Q1 (Urgent+Important: do now), Q2 (Important+NotUrgent: schedule strategically), Q3 (Urgent+NotImportant: delegate/automate), Q4 (Neither: delete). It surfaces high-leverage insights by identifying structural waste, flagging ambiguous ...Votes: 0GitHub stars: 4
- Devils AdvocateThis skill should be used when the user asks for "an adversarial review", "security review", "devil's advocate", "what could go wrong", "find the vulnerability", "threat analysis", "penetration test this", or "challenge this design". Use this skill when the user wants to identify security threats and architectural fragilities in code or architecture.Votes: 0GitHub stars: 4
- Bad Frontmatter块标量正文里误写顶层列表项,整行会被解析器丢弃。Votes: 0GitHub stars: 112
- Secure Coding PracticesAudit code against a 14-domain secure coding checklist derived from OWASP's living sources — the Developer Guide, Cheat Sheet Series, and Proactive Controls — with the original OWASP Secure Coding Practices Quick Reference Guide noted only as the archived historical origin. Covers 14 critical domains including input validation, output encoding, authentication, session management, access control, cryptographic practices, error handling & logging, data protection, communication security, system...Votes: 0GitHub stars: 2
- Owasp Security AuditPerform OWASP-aligned security audits of source code, API handlers, mobile apps, Kubernetes manifests, LLM/agent code, and deployment configuration. Covers the OWASP Top 10 (2025), ASVS 5.0.0 (V1-V17 chapter numbering), MASVS, API Security Top 10 (2023), Kubernetes Top 10 (2022), and the OWASP LLM Top 10 (2026) plus Agentic Applications Top 10 (2026). Use this skill whenever the user asks for a security review, vulnerability audit, threat assessment, compliance check, or hardening guidance — ...Votes: 0GitHub stars: 2
- Verify Libre SecopsInstall the LibreSecOps-Claude-Code plugin pack the way a user does, into a clean Claude Code config and a clean Grok Build home, prove every plugin validates, installs and loads its components, and keep the transcripts. Use when proving a LibreSecOps-Claude-Code PR's Done-when, checking that a plugin change still installs in both CLIs, or reproducing an install bug.Votes: 0GitHub stars: 4
- Candidate ScreenSurface details about likely committer and <governance-body> candidates — deliberately more people than would be picked — as an alphabetical list with a short summary, in a verified-private repository. Never a ranking or a readiness verdict.Votes: 0GitHub stars: 108
- CalibrateDerive committer and <governance-body> reference levels from the project's own past nomination decisions on <private-list>, deliberately relaxed below what was elected, and propose them as a numbers-only config diff.Votes: 0GitHub stars: 108
- PaperclipPaperclip is a self-hosted Node.js server and web dashboard that runs a team of AI coding agents (Claude Code, Codex, Gemini CLI, OpenCode, OpenClaw) as a company, with an org chart, goals, tasks, monthly budgets and approval gates. Use when someone wants to install or run Paperclip, hire agents, assign tasks to them, cap agent spend, or script it through the paperclipai CLI or its REST API. Phrases: "set up Paperclip", "run my agents like a company", "too many Claude Code tabs", "give each a...Votes: 0GitHub stars: 155
- Restaking EigenlayerDetect restaking / AVS bugs — EigenLayer / Symbiotic / Karak operator slashing edge cases, withdrawal-queue gaming, cascading-slashing across AVSs, LST depeg solvency, AVS opt-in granularity. Activate on EigenLayer / Symbiotic / Karak imports, StrategyManager, DelegationManager, EigenPod, AVS registration, slasher contracts.Votes: 0GitHub stars: 36
- ReentrancyDetect reentrancy vulnerabilities — classic, cross-function, and cross-contract (especially read-only reentrancy). Activate whenever Solidity/Vyper code performs external calls, low-level call/transfer/send, ERC-721 safeTransfer with a receiver hook, or any pattern where control flow leaves the contract before state finalization.Votes: 0GitHub stars: 36
- Erc4337 Account AbstractionDetect ERC-4337 account-abstraction bugs — validateUserOp storage-rule violations, paymaster postOp DoS, session-key scope bypasses, signature aggregation issues, EIP-7702 delegation risks. Activate on `validateUserOp`, `validatePaymasterUserOp`, `postOp`, `UserOperation`, `EntryPoint`, `IAccount`, `IPaymaster`, session-key modules, ERC-7579 modules, EIP-7702 authorization payloads.Votes: 0GitHub stars: 36
- Cross Chain MessagingDetect cross-chain messaging bugs — replay protection gaps, untrusted-remote acceptance, default-config inheritance, validator-set misconfig, force-include vulnerabilities, chainId / domain-separator omissions. Activate on `_lzReceive`, `ccipReceive`, `handle` (Hyperlane), `receiveMessage`, `verifyVAA`, IRouterClient, IMailbox, EndpointV2, OApp/OFT, LayerZero / CCIP / Hyperlane / Wormhole / Axelar / Polyhedra integration code.Votes: 0GitHub stars: 36
- CosmwasmDetect bug classes specific to CosmWasm (Rust) contracts — missing info.sender authorization in execute handlers, unbounded map iteration → gas/DoS, reply/submessage reply_id confusion, migrate admin backdoors, addr_validate vs raw string addresses, unchecked info.funds, Uint128 overflow, query reentrancy, and migration/version state. Activate on any `.rs` file with `use cosmwasm_std`, `#[entry_point]`, `ExecuteMsg`, `InstantiateMsg`, `QueryMsg`, `cw_storage_plus`, or `DepsMut`.Votes: 0GitHub stars: 36
- Access ControlDetect missing or incorrect access control — missing modifiers, wrong role checks, privileged function exposure, public initializers, and role-escalation paths. Activate on any function that mutates state, transfers funds, mints tokens, sets admin parameters, upgrades implementations, or pauses/unpauses.Votes: 0GitHub stars: 36
- Angular Upgrade Angular Upgrade Validation GateValidates each Angular major hop with repository-specific build, test, and lint checks before allowing the next upgrade step.Votes: 0GitHub stars: 4
- Angular Security Angular Dependency Vulnerability TriageTriage Angular dependency vulnerabilities by separating real blockers from low-risk advisories.Votes: 0GitHub stars: 4
- Firestore Rules Creation"Designs, authors, refactors, and hardens production-grade CloudVotes: 0GitHub stars: 16