Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Entra Posture ReviewReview a Microsoft Entra ID tenant's identity posture from read-only Graph exports, checking Conditional Access basics, security defaults, standing Global Administrators, guests with roles, stale guests, long-lived app secrets, high-risk Graph application permissions, consent and invitation settings and legacy sign-ins. Use when asked \"who are our Global Admins?\", to baseline a tenant, before an ISO 27001 or Essential Eight audit, or after taking one over. Not for Intune devices (intune-bas...Votes: 0GitHub stars: 2
- Devils AdvocateThis skill should be used when the user asks for "an adversarial review", "security review", "devil's advocate", "what could go wrong", "find the vulnerability", "threat analysis", "penetration test this", or "challenge this design". Use this skill when the user wants to identify security threats and architectural fragilities in code or architecture.Votes: 0GitHub stars: 4
- Secure Coding PracticesAudit code against a 14-domain secure coding checklist derived from OWASP's living sources — the Developer Guide, Cheat Sheet Series, and Proactive Controls — with the original OWASP Secure Coding Practices Quick Reference Guide noted only as the archived historical origin. Covers 14 critical domains including input validation, output encoding, authentication, session management, access control, cryptographic practices, error handling & logging, data protection, communication security, system...Votes: 0GitHub stars: 2
- Owasp Security AuditPerform OWASP-aligned security audits of source code, API handlers, mobile apps, Kubernetes manifests, LLM/agent code, and deployment configuration. Covers the OWASP Top 10 (2025), ASVS 5.0.0 (V1-V17 chapter numbering), MASVS, API Security Top 10 (2023), Kubernetes Top 10 (2022), and the OWASP LLM Top 10 (2026) plus Agentic Applications Top 10 (2026). Use this skill whenever the user asks for a security review, vulnerability audit, threat assessment, compliance check, or hardening guidance — ...Votes: 0GitHub stars: 2
- Verify Libre SecopsInstall the LibreSecOps-Claude-Code plugin pack the way a user does, into a clean Claude Code config and a clean Grok Build home, prove every plugin validates, installs and loads its components, and keep the transcripts. Use when proving a LibreSecOps-Claude-Code PR's Done-when, checking that a plugin change still installs in both CLIs, or reproducing an install bug.Votes: 0GitHub stars: 4
- Candidate ScreenSurface details about likely committer and <governance-body> candidates — deliberately more people than would be picked — as an alphabetical list with a short summary, in a verified-private repository. Never a ranking or a readiness verdict.Votes: 0GitHub stars: 108
- CalibrateDerive committer and <governance-body> reference levels from the project's own past nomination decisions on <private-list>, deliberately relaxed below what was elected, and propose them as a numbers-only config diff.Votes: 0GitHub stars: 108
- PaperclipPaperclip is a self-hosted Node.js server and web dashboard that runs a team of AI coding agents (Claude Code, Codex, Gemini CLI, OpenCode, OpenClaw) as a company, with an org chart, goals, tasks, monthly budgets and approval gates. Use when someone wants to install or run Paperclip, hire agents, assign tasks to them, cap agent spend, or script it through the paperclipai CLI or its REST API. Phrases: "set up Paperclip", "run my agents like a company", "too many Claude Code tabs", "give each a...Votes: 0GitHub stars: 155
- Msp SecurityUse this skill for security standards at your managed IT services (MSP) business, in both directions: the baseline every managed client must meet (MFA, endpoint protection, email security, backups, admin access, offboarding) and how the MSP secures itself (RMM hardening, the credential vault, admin separation, partner-delegated admin access into client tenants, our own devices). Trigger on "security baseline", "security standard", "harden this tenant", "is this client secure enough", "securit...Votes: 0GitHub stars: 105
- Workers Best PracticesCloudflare Workers best practices for production applications. Use when writing, reviewing, or configuring Workers.Votes: 0GitHub stars: 2,994
- Zeroize AuditDetects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-level analysis, and control-flow verification. Use for auditing C/C++/Rust code handling secrets, keys, passwords, or other sensitive data.Votes: 0GitHub stars: 7,287
- Vulnerability Triage BrocardsThis skill should be used when the user asks to "triage a vulnerability report", "assess a CVE", "evaluate a bug bounty submission", "decide if a finding is valid", "review a security finding", "dismiss a vulnerability", "should we fix this CVE", "prioritize a vulnerability report", or needs to determine whether an incoming vulnerability report warrants investigation. Applies 7 brocards (rules of thumb) to systematically accept, dismiss, or request more information on vulnerability reports, o...Votes: 0GitHub stars: 7,287
- TemplatesUse this template for domain-specific security testing (cryptographic testing, web security methodologies, etc.).Votes: 0GitHub stars: 7,287
- Constant Time TestingMeasures timing side channels in cryptographic implementations by running them, using dudect for statistical analysis and Timecop over Valgrind for dynamic tracing. Covers the formal, symbolic, dynamic, and statistical tool categories and how to read a result. Use when testing whether a running implementation is constant-time, measuring timing variance on a compiled binary, or investigating a suspected timing attack. Not for statically inspecting compiler output — the constant-time-analysis p...Votes: 0GitHub stars: 7,287
- Supply Chain Risk AuditorAudits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script execution. Use when asked to audit dependencies, assess supply-chain or third-party package risk, or review a dependency tree before an engagement.Votes: 0GitHub stars: 7,287
- Sharp EdgesIdentifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes. Use when reviewing API designs, configuration schemas, cryptographic library ergonomics, or evaluating whether code follows 'secure by default' and 'pit of success' principles. Triggers: footgun, misuse-resistant, secure defaults, API usability, dangerous configuration.Votes: 0GitHub stars: 7,287
- Modern CppGuides C++ code toward modern idioms (C++20/23/26). Use when writing new C++ code, modernizing legacy patterns, or working on security-critical C++. Replaces raw pointers with smart pointers, SFINAE with concepts, printf with std::print, error codes with std::expected.Votes: 0GitHub stars: 7,287
- Let Fate DecideDraws the 12 Houses of the Zodiac Tarot spread to inject entropy into planning when prompts are vague, ambiguous, or casually delegated. Interprets the spread to guide next steps. Use when the user says 'let fate decide', 'YOLO', 'whatever', 'idk', or other nonchalant phrases, makes Yu-Gi-Oh references, or when you are about to arbitrarily pick between multiple reasonable approaches. Prefer over asking clarifying questions when the user's tone is casual or playful rather than precision-seeking.Votes: 0GitHub stars: 7,287
- Firebase Apk ScannerScans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. Use when analyzing APK files for Firebase vulnerabilities, performing mobile app security audits, or testing Firebase endpoint security. For authorized security research only.Votes: 0GitHub stars: 7,287
- Token Integration AnalyzerToken integration and implementation analyzer based on Trail of Bits' token integration checklist. Analyzes token implementations for ERC20/ERC721 conformity, checks for 20+ weird token patterns, assesses contract composition and owner privileges, performs on-chain scarcity analysis, and evaluates how protocols handle non-standard tokens. Use when integrating or accepting arbitrary ERC20/ERC721 tokens, auditing a token implementation for standards conformity, or assessing risk from weird toke...Votes: 0GitHub stars: 7,287