Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Security AuditUse when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.Votes: 0GitHub stars: 123
- Tfc Run LogsRetrieve plan and apply logs from Terraform Cloud runs. Use when debugging failed plans/applies or reviewing TFC run output. Requires TFE_TOKEN.Votes: 0GitHub stars: 58
- Prose SynthesizeProse synthesize: turn unstructured notes into a structured, actionable plan. Use when given brain dumps, stream-of-consciousness, or scattered thoughts needing order.Votes: 0GitHub stars: 58
- Code Dep AuditAudit dependencies for security vulnerabilities, outdated packages, and license compliance. Use when checking supply chain security, preparing releases, or responding to CVEs.Votes: 0GitHub stars: 58
- HeartbeatAmbient fleet-health check that surfaces anything worth attention (default), or an on-demand priority brief - the 3 things to focus on, why now, and what moved (var=brief)Votes: 0GitHub stars: 17
- Ce HandoffCreate a session handoff for another agent, or resume, find, and read any user-selected continuity source. Use when work or conversation must continue without access to the current session history.Votes: 0GitHub stars: 25,340
- Hunting Mobile Secret And Storage ExposureHunt a mobile app for a real credential shipped in the binary or written to storage another party can read, scoped strictly to mobile-specific sinks. Covers a live secret embedded in the app package or its resources, sensitive data written to world-or-sandbox-readable storage without encryption, a secret placed outside the platform keystore where a weaker guard protects it, data cached or logged where another app or a device-level reader reaches it, and a backup or debug path that carries sen...Votes: 0GitHub stars: 5
- Auditing Ota And Firmware Update Channel TrustAudit an over-the-air or firmware update channel for a device that accepts an image it should reject: an update whose signature is not verified so an attacker installs arbitrary firmware, an update fetched over an unauthenticated transport an on-path attacker can swap, a rollback to an older signed image with known vulnerabilities because the device does not enforce version monotonicity, an update server or manifest URL the device trusts without authentication, and an unencrypted image that l...Votes: 0GitHub stars: 5
- Mutation GateSupplies the approval rule another RHDH skill applies when it is already about to change something outside the session: how to state each operation, what approval binds to, what to report afterwards, and how to keep credentials out of a plan preview. Cited by name from the skill doing the work. Not an entry point — it performs no forge, Jira, or repository action itself, and a request to open, comment, transition, push, or post belongs to the skill that owns that target.Votes: 0GitHub stars: 18
- Top Web VulnerabilitiesProvide a comprehensive, structured reference for the 100 most critical web application vulnerabilities organized by category. This skill enables systematic vulnerability identification, impact assessment, and remediation guidance across the full spectrum of web security threats.Votes: 0GitHub stars: 2
- Security Scanning Security HardeningCoordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls.Votes: 0GitHub stars: 2
- Backend Security CoderExpert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.Votes: 0GitHub stars: 2
- Requesting Code ReviewStructured code review against requirements, quality, and security standards. Invoke after meaningful code changes or before merge. Triggers on: "review my code", "code review", "check this before merge", "security review", "is this secure", "look over my changes", "second pair of eyes", "check the diff". Routed by using-superpowers or executing-plans after implementation.Votes: 0GitHub stars: 3
- Privacy Data SecurityDesign and operate privacy and data security programs for SEC-registered firms under Reg S-P, Reg S-ID, and SEC cybersecurity expectations. Use when the user asks about privacy notices, the Safeguards Rule, identity theft prevention programs, breach notification obligations, vendor security due diligence, incident response planning, data classification, or state privacy law compliance. Also trigger when users mention 'customer data was exposed', 'do we need to notify clients of a breach', 'cy...Votes: 0GitHub stars: 178
- AlpineAlpine Linux reference — the minimal, security-oriented distribution for containers. Covers apk package management, Docker optimization, multi-stage builds, musl vs glibc compatibility, OpenRC system admin, security hardening, and common troubleshooting.Votes: 0GitHub stars: 12