Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Devils AdvocateThis skill should be used when the user asks for "an adversarial review", "security review", "devil's advocate", "what could go wrong", "find the vulnerability", "threat analysis", "penetration test this", or "challenge this design". Use this skill when the user wants to identify security threats and architectural fragilities in code or architecture.Votes: 0GitHub stars: 4
- Cloud Security Baseline ReviewerReview the CONFIGURED security baseline of a cloud account, subscription or managed platform project (AWS, Azure, GCP, or hosts like Vercel and Supabase) against a named baseline, control by control: identity and owner access, network exposure, secrets and keys, encryption and public storage, audit logging, guardrail policies, posture services and incident readiness. Each control gets MET, GAP or UNVERIFIED from cited evidence (exported settings, posture-scanner findings, IaC or screenshots t...Votes: 0GitHub stars: 4
- Ai Task DecomposerBreak a broad goal, epic or approved spec into small, ordered tasks an AI agent can each finish, validate and get reviewed as ONE pull request (PR): each task has one intent, an observable acceptance criterion with the evidence that will prove it, the likely files or layers touched, a provisional change class, known risks, dependencies and order, and any human-approval boundary it will cross. Oversized or vague tasks are split again; unknowns become spike tasks or owner questions, never guess...Votes: 0GitHub stars: 4
- Integrating External Tools And ApisTurn APIs, queries and code into described, schema-bound LangChain tools that an agent can select, call and recover from safely.Votes: 0GitHub stars: 2
- Speakers+++ Title = "Kathryn Bouskill" type = "speaker" image = "kathryn-bouskill.jpg" linktitle = "kathryn-bouskill" +++ <h3> Anthropologist Meta Infrastructure Team </h3> <p> Bouskill is a senior researcher at Meta where she works in Meta’s Reliability Engineering organization. An anthropologist by training, Bouskill has worked around the world on a range of issues related to technology, risk & security, and public health. She is an adjunct researcher at the RAND Corporation and professor at the Pa...Votes: 0GitHub stars: 194
- Ctf Sandbox OrchestratorDefault entrypoint and master ctf-sandbox-orchestrator workflow for CTF, exploit, reverse engineering, DFIR, pwnable, crypto, stego, mobile, AI-agent, cloud, container, Active Directory, Windows-host, and identity challenges. Use first when the user presents challenge infrastructure, binaries, prompts, hosts, or identities that should be treated as sandbox-internal by default and Codex needs to choose, route, and load the right downstream analysis path with concise evidence.Votes: 0GitHub stars: 2
- Tradecraft Attack ChainOrchestrate a full multi-stage kill chain — recon → initial access → privilege escalation → lateral movement → objective — with phase gates, per-phase playbooks, and operating discipline. Load on pentest tasks that span stages: "get from external to domain admin", "full internal pentest", "I have a webshell, route me to the objective", red-team exercise planning. Single-stage tasks go straight to their domain skill; bug bounty never uses this.Votes: 0GitHub stars: 20
- JevgrepOperate Jevgrep (`jg`) as optional remote-agent discovery over explicitly scoped skills, wiki pages, or graph source documents. Use only when the user explicitly requests Jevgrep and separately approves transmitting source content and queries to the configured provider with potential cost. Preserve native catalog, exact/LSP/zvec retrieval and Graphify query/path/explain as defaults; Jevgrep does not query or rebuild durable graphs.Votes: 0GitHub stars: 46
- Read The Damn DocsUse when implementing, integrating, upgrading, debugging, or answering anything involving third-party APIs, libraries, frameworks, CLIs, cloud services, model/provider SDKs, fast-moving product behavior, user requests for latest/current/official behavior, unfamiliar repo docs/specs, errors that may indicate API drift, or high-stakes auth, security, billing, data, migration, deployment, compliance, or privacy behavior. Forces Codex to web-search for current official docs and read primary docs ...Votes: 0GitHub stars: 17
- Plow AheadUse when the user explicitly wants autonomous progress without routine clarification stops: "plow ahead", "do not stop", "use your best judgment", "keep going until done", "finish while I am away", "do not ask questions unless truly blocked", or similar. Convert ordinary ambiguity into stated assumptions, proceed through implementation and validation, stop only for true blockers, and end with a clear recap of decisions, changes, verification, and residual risk.Votes: 0GitHub stars: 17
- Extracting Credentials From Memory DumpExtract cached credentials, password hashes, Kerberos tickets, and authenticationVotes: 0GitHub stars: 4
- Secure Coding PracticesAudit code against a 14-domain secure coding checklist derived from OWASP's living sources — the Developer Guide, Cheat Sheet Series, and Proactive Controls — with the original OWASP Secure Coding Practices Quick Reference Guide noted only as the archived historical origin. Covers 14 critical domains including input validation, output encoding, authentication, session management, access control, cryptographic practices, error handling & logging, data protection, communication security, system...Votes: 0GitHub stars: 2
- Owasp Security AuditPerform OWASP-aligned security audits of source code, API handlers, mobile apps, Kubernetes manifests, LLM/agent code, and deployment configuration. Covers the OWASP Top 10 (2025), ASVS 5.0.0 (V1-V17 chapter numbering), MASVS, API Security Top 10 (2023), Kubernetes Top 10 (2022), and the OWASP LLM Top 10 (2026) plus Agentic Applications Top 10 (2026). Use this skill whenever the user asks for a security review, vulnerability audit, threat assessment, compliance check, or hardening guidance — ...Votes: 0GitHub stars: 2
- Verify Libre SecopsInstall the LibreSecOps-Claude-Code plugin pack the way a user does, into a clean Claude Code config and a clean Grok Build home, prove every plugin validates, installs and loads its components, and keep the transcripts. Use when proving a LibreSecOps-Claude-Code PR's Done-when, checking that a plugin change still installs in both CLIs, or reproducing an install bug.Votes: 0GitHub stars: 4
- Candidate ScreenSurface details about likely committer and <governance-body> candidates — deliberately more people than would be picked — as an alphabetical list with a short summary, in a verified-private repository. Never a ranking or a readiness verdict.Votes: 0GitHub stars: 108
- CalibrateDerive committer and <governance-body> reference levels from the project's own past nomination decisions on <private-list>, deliberately relaxed below what was elected, and propose them as a numbers-only config diff.Votes: 0GitHub stars: 108
- PaperclipPaperclip is a self-hosted Node.js server and web dashboard that runs a team of AI coding agents (Claude Code, Codex, Gemini CLI, OpenCode, OpenClaw) as a company, with an org chart, goals, tasks, monthly budgets and approval gates. Use when someone wants to install or run Paperclip, hire agents, assign tasks to them, cap agent spend, or script it through the paperclipai CLI or its REST API. Phrases: "set up Paperclip", "run my agents like a company", "too many Claude Code tabs", "give each a...Votes: 0GitHub stars: 155
- Audit SecurityA project-agnostic, WHOLE-PROJECT security audit - the "subscribe to a security firm" skill. It runs the real scanners (osv-scanner for dependency CVEs, gitleaks for secrets in the working tree AND full git history, semgrep for SAST, trivy for IaC), then performs its OWN LLM-driven whole-repository security review (a full local sweep, NOT a git-diff/PR lens - it replaces Anthropic's diff-scoped /security-review), builds a threat model so findings are ranked by what is actually worth attacking...Votes: 0GitHub stars: 2
- Addyosmani Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.Votes: 0GitHub stars: 2
- Addyosmani Code Review And QualityConducts multi-axis code review. Use before merging any change. Use when reviewing code written by yourself, another agent, or a human. Use when you need to assess code quality across multiple dimensions before it enters the main branch.Votes: 0GitHub stars: 2