Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Error HandlingImplement secure error handling to prevent information leakage and provide appropriate error responses. Use this skill when you need to handle errors in API routes, prevent stack trace exposure, implement environment-aware error messages, or use the error handler utilities. Triggers include "error handling", "handle errors", "error messages", "information leakage", "stack trace", "handleApiError", "production errors", "error responses".Votes: 0GitHub stars: 2
- Dependency SecurityManage dependencies and supply chain security to prevent vulnerable or malicious packages. Use this skill when you need to audit dependencies, update packages, check for vulnerabilities, understand supply chain attacks, or maintain dependency security. Triggers include "dependencies", "npm audit", "supply chain", "package security", "vulnerability", "npm update", "security audit", "outdated packages".Votes: 0GitHub stars: 2
- Csrf ProtectionImplement Cross-Site Request Forgery (CSRF) protection for API routes. Use this skill when you need to protect POST/PUT/DELETE endpoints, implement token validation, prevent cross-site attacks, or secure form submissions. Triggers include "CSRF", "cross-site request forgery", "protect form", "token validation", "withCsrf", "CSRF token", "session fixation".Votes: 0GitHub stars: 2
- Auth SecurityImplement secure authentication and authorization using Clerk. Use this skill when you need to authenticate users, protect routes, check permissions, implement subscription-based access control, or integrate Clerk with your application. Triggers include "authentication", "auth", "authorization", "Clerk", "protect route", "check user", "sign in", "session", "permissions", "subscription access".Votes: 0GitHub stars: 2
- Powerbi Cyber SecurityPower BI and Microsoft Fabric cybersecurity - tenant hardening, conditional access, OAuth flows, export controls, data exfiltration prevention, audit log threat detection, and compliance controls. Use when the user mentions: cyber security, cybersecurity, tenant hardening, conditional access, MFA, OAuth, export control, data exfiltration, threat detection, zero trust, SOC2, HIPAA, PCI-DSS, vulnerability, attack surface, hardening, incident response, access review, service principal, workspace...Votes: 0GitHub stars: 3
- Osv ScannerThis skill should be triggered when the user asks about dependency security, vulnerability scanning, or package safety. Examples: \"check my dependencies for vulnerabilities\", \"scan my packages\", \"are my dependencies safe\", \"dependency audit\", \"check for CVEs\", \"security audit\", \"vulnerable packages\", \"scan dependencies for vulnerabilities\".Votes: 0GitHub stars: 4
- Eisenhower PrioritizationPrioritize any workload using the Eisenhower Matrix. Use this skill whenever a user provides a brain dump of work—Jira summaries, meeting notes, sprint dumps, task lists, or prose descriptions of their workload. This skill categorizes tasks into four quadrants: Q1 (Urgent+Important: do now), Q2 (Important+NotUrgent: schedule strategically), Q3 (Urgent+NotImportant: delegate/automate), Q4 (Neither: delete). It surfaces high-leverage insights by identifying structural waste, flagging ambiguous ...Votes: 0GitHub stars: 4
- Devils AdvocateThis skill should be used when the user asks for "an adversarial review", "security review", "devil's advocate", "what could go wrong", "find the vulnerability", "threat analysis", "penetration test this", or "challenge this design". Use this skill when the user wants to identify security threats and architectural fragilities in code or architecture.Votes: 0GitHub stars: 4
- Cloud Security Baseline ReviewerReview the CONFIGURED security baseline of a cloud account, subscription or managed platform project (AWS, Azure, GCP, or hosts like Vercel and Supabase) against a named baseline, control by control: identity and owner access, network exposure, secrets and keys, encryption and public storage, audit logging, guardrail policies, posture services and incident readiness. Each control gets MET, GAP or UNVERIFIED from cited evidence (exported settings, posture-scanner findings, IaC or screenshots t...Votes: 0GitHub stars: 4
- Ai Task DecomposerBreak a broad goal, epic or approved spec into small, ordered tasks an AI agent can each finish, validate and get reviewed as ONE pull request (PR): each task has one intent, an observable acceptance criterion with the evidence that will prove it, the likely files or layers touched, a provisional change class, known risks, dependencies and order, and any human-approval boundary it will cross. Oversized or vague tasks are split again; unknowns become spike tasks or owner questions, never guess...Votes: 0GitHub stars: 4
- Integrating External Tools And ApisTurn APIs, queries and code into described, schema-bound LangChain tools that an agent can select, call and recover from safely.Votes: 0GitHub stars: 2
- Bad Frontmatter块标量正文里误写顶层列表项,整行会被解析器丢弃。Votes: 0GitHub stars: 112
- Speakers+++ Title = "Kathryn Bouskill" type = "speaker" image = "kathryn-bouskill.jpg" linktitle = "kathryn-bouskill" +++ <h3> Anthropologist Meta Infrastructure Team </h3> <p> Bouskill is a senior researcher at Meta where she works in Meta’s Reliability Engineering organization. An anthropologist by training, Bouskill has worked around the world on a range of issues related to technology, risk & security, and public health. She is an adjunct researcher at the RAND Corporation and professor at the Pa...Votes: 0GitHub stars: 194
- PhpModern PHP 8.5 practices: type system, OOP, security, architecture, async, testing, tooling. Use when writing or reviewing PHP code.Votes: 0GitHub stars: 54
- AwsAWS best practices: IAM, secrets, networking, security, compute, IaC, ops. Use when building, reviewing, or modifying AWS resources.Votes: 0GitHub stars: 54
- Reverse Skill RouterUse the reverse-skill repository from Codex for authorized reverse engineering, security analysis, CTF, and defensive testing tasks. Requires the reverse-skill repository to be available as the current workspace or an explicitly supplied local path.Votes: 0GitHub stars: 2
- Ctf Sandbox OrchestratorDefault entrypoint and master ctf-sandbox-orchestrator workflow for CTF, exploit, reverse engineering, DFIR, pwnable, crypto, stego, mobile, AI-agent, cloud, container, Active Directory, Windows-host, and identity challenges. Use first when the user presents challenge infrastructure, binaries, prompts, hosts, or identities that should be treated as sandbox-internal by default and Codex needs to choose, route, and load the right downstream analysis path with concise evidence.Votes: 0GitHub stars: 2
- Web Extension ReverseReverse engineer browser extensions (Chrome/Edge MV2/MV3, Firefox) for an authorized review: unpack .crx/.xpi, assess the permission surface, trace background/service-worker and content-script logic, and recover credential, signing, or traffic-handling behavior. Load on "analyze this extension", extension supply-chain or malicious-extension investigation, or keys hidden in chrome.storage. Signals: .crx, .xpi, manifest.json, chrome-extension://, <all_urls>, webRequestBlocking, declarativeNetRe...Votes: 0GitHub stars: 20
- Tradecraft Attack ChainOrchestrate a full multi-stage kill chain — recon → initial access → privilege escalation → lateral movement → objective — with phase gates, per-phase playbooks, and operating discipline. Load on pentest tasks that span stages: "get from external to domain admin", "full internal pentest", "I have a webshell, route me to the objective", red-team exercise planning. Single-stage tasks go straight to their domain skill; bug bounty never uses this.Votes: 0GitHub stars: 20
- Network Email SecurityEmail security review: dissect phishing samples (headers, URLs, attachments), assess a domain's spoofability via SPF/DKIM/DMARC alignment, recognize BEC patterns, and audit tenant anti-phishing controls incl. OAuth consent abuse. Load on phishing email analysis, .eml header review, "can this domain be spoofed", DMARC/SPF checks, or BEC investigation. Signals: Received chain, Authentication-Results, dmarc p=none, ~all vs -all, reply-to mismatch, lookalike domains.Votes: 0GitHub stars: 20