Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Awareness OverviewUnderstand the security risks inherent in AI-generated code and vibe coding. Use this skill when you need to understand why AI generates insecure code, statistics on vulnerabilities, real-world breach examples, or overall security awareness for AI-assisted development. Triggers include "vibe coding security", "AI code security", "AI vulnerabilities", "security risks AI code", "why AI insecure", "AI security awareness", "AI generated code risks".Votes: 0GitHub stars: 2
- Auth VulnerabilitiesUnderstand authentication and authorization defects in AI-generated code including insecure password storage, broken session management, and access control bypasses. Use this skill when you need to learn about auth vulnerabilities in AI code, understand why AI suggests MD5/plaintext passwords, recognize broken session patterns, or identify access control gaps. Triggers include "auth vulnerabilities AI", "password storage AI", "session management", "broken access control", "authentication defe...Votes: 0GitHub stars: 2
- Payment SecurityImplement secure payments using Clerk Billing and Stripe without ever touching card data. Use this skill when you need to set up subscription payments, handle webhooks, implement payment gating, understand PCI-DSS compliance, or integrate Stripe Checkout. Triggers include "payment", "Stripe", "Clerk Billing", "subscription", "PCI-DSS", "credit card", "payment security", "checkout", "webhook", "billing".Votes: 0GitHub stars: 2
- Input ValidationValidate and sanitize user input to prevent XSS, injection attacks, and ensure data quality. Use this skill when you need to validate forms, sanitize user input, prevent cross-site scripting, use Zod schemas, or handle any user-generated content. Triggers include "input validation", "validate input", "XSS", "cross-site scripting", "sanitize", "Zod", "injection prevention", "validateRequest", "safeTextSchema", "user input security".Votes: 0GitHub stars: 2
- Error HandlingImplement secure error handling to prevent information leakage and provide appropriate error responses. Use this skill when you need to handle errors in API routes, prevent stack trace exposure, implement environment-aware error messages, or use the error handler utilities. Triggers include "error handling", "handle errors", "error messages", "information leakage", "stack trace", "handleApiError", "production errors", "error responses".Votes: 0GitHub stars: 2
- Dependency SecurityManage dependencies and supply chain security to prevent vulnerable or malicious packages. Use this skill when you need to audit dependencies, update packages, check for vulnerabilities, understand supply chain attacks, or maintain dependency security. Triggers include "dependencies", "npm audit", "supply chain", "package security", "vulnerability", "npm update", "security audit", "outdated packages".Votes: 0GitHub stars: 2
- Csrf ProtectionImplement Cross-Site Request Forgery (CSRF) protection for API routes. Use this skill when you need to protect POST/PUT/DELETE endpoints, implement token validation, prevent cross-site attacks, or secure form submissions. Triggers include "CSRF", "cross-site request forgery", "protect form", "token validation", "withCsrf", "CSRF token", "session fixation".Votes: 0GitHub stars: 2
- Auth SecurityImplement secure authentication and authorization using Clerk. Use this skill when you need to authenticate users, protect routes, check permissions, implement subscription-based access control, or integrate Clerk with your application. Triggers include "authentication", "auth", "authorization", "Clerk", "protect route", "check user", "sign in", "session", "permissions", "subscription access".Votes: 0GitHub stars: 2
- Powerbi Cyber SecurityPower BI and Microsoft Fabric cybersecurity - tenant hardening, conditional access, OAuth flows, export controls, data exfiltration prevention, audit log threat detection, and compliance controls. Use when the user mentions: cyber security, cybersecurity, tenant hardening, conditional access, MFA, OAuth, export control, data exfiltration, threat detection, zero trust, SOC2, HIPAA, PCI-DSS, vulnerability, attack surface, hardening, incident response, access review, service principal, workspace...Votes: 0GitHub stars: 3
- Osv ScannerThis skill should be triggered when the user asks about dependency security, vulnerability scanning, or package safety. Examples: \"check my dependencies for vulnerabilities\", \"scan my packages\", \"are my dependencies safe\", \"dependency audit\", \"check for CVEs\", \"security audit\", \"vulnerable packages\", \"scan dependencies for vulnerabilities\".Votes: 0GitHub stars: 4
- Eisenhower PrioritizationPrioritize any workload using the Eisenhower Matrix. Use this skill whenever a user provides a brain dump of work—Jira summaries, meeting notes, sprint dumps, task lists, or prose descriptions of their workload. This skill categorizes tasks into four quadrants: Q1 (Urgent+Important: do now), Q2 (Important+NotUrgent: schedule strategically), Q3 (Urgent+NotImportant: delegate/automate), Q4 (Neither: delete). It surfaces high-leverage insights by identifying structural waste, flagging ambiguous ...Votes: 0GitHub stars: 4
- Devils AdvocateThis skill should be used when the user asks for "an adversarial review", "security review", "devil's advocate", "what could go wrong", "find the vulnerability", "threat analysis", "penetration test this", or "challenge this design". Use this skill when the user wants to identify security threats and architectural fragilities in code or architecture.Votes: 0GitHub stars: 4
- Cloud Security Baseline ReviewerReview the CONFIGURED security baseline of a cloud account, subscription or managed platform project (AWS, Azure, GCP, or hosts like Vercel and Supabase) against a named baseline, control by control: identity and owner access, network exposure, secrets and keys, encryption and public storage, audit logging, guardrail policies, posture services and incident readiness. Each control gets MET, GAP or UNVERIFIED from cited evidence (exported settings, posture-scanner findings, IaC or screenshots t...Votes: 0GitHub stars: 4
- Ai Task DecomposerBreak a broad goal, epic or approved spec into small, ordered tasks an AI agent can each finish, validate and get reviewed as ONE pull request (PR): each task has one intent, an observable acceptance criterion with the evidence that will prove it, the likely files or layers touched, a provisional change class, known risks, dependencies and order, and any human-approval boundary it will cross. Oversized or vague tasks are split again; unknowns become spike tasks or owner questions, never guess...Votes: 0GitHub stars: 4
- Integrating External Tools And ApisTurn APIs, queries and code into described, schema-bound LangChain tools that an agent can select, call and recover from safely.Votes: 0GitHub stars: 2
- Bad Frontmatter块标量正文里误写顶层列表项,整行会被解析器丢弃。Votes: 0GitHub stars: 112
- Speakers+++ Title = "Kathryn Bouskill" type = "speaker" image = "kathryn-bouskill.jpg" linktitle = "kathryn-bouskill" +++ <h3> Anthropologist Meta Infrastructure Team </h3> <p> Bouskill is a senior researcher at Meta where she works in Meta’s Reliability Engineering organization. An anthropologist by training, Bouskill has worked around the world on a range of issues related to technology, risk & security, and public health. She is an adjunct researcher at the RAND Corporation and professor at the Pa...Votes: 0GitHub stars: 194
- PhpModern PHP 8.5 practices: type system, OOP, security, architecture, async, testing, tooling. Use when writing or reviewing PHP code.Votes: 0GitHub stars: 54
- AwsAWS best practices: IAM, secrets, networking, security, compute, IaC, ops. Use when building, reviewing, or modifying AWS resources.Votes: 0GitHub stars: 54
- Reverse Skill RouterUse the reverse-skill repository from Codex for authorized reverse engineering, security analysis, CTF, and defensive testing tasks. Requires the reverse-skill repository to be available as the current workspace or an explicitly supplied local path.Votes: 0GitHub stars: 2