Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Network Database SecurityAssess reachable database services — PostgreSQL/MySQL/MSSQL/MongoDB/Redis — for unauthenticated access, weak/default accounts, over-broad grants, and dangerous features (xp_cmdshell, COPY FROM PROGRAM, UDF, Redis file write) that turn a DB login into OS code execution. Load when recon shows 3306/5432/1433/6379/27017, leaked app config yields DB creds, or a database review is in scope. Signals: 0.0.0.0 bind, unauth Redis PONG, mysql.user host '%', FILE priv, secure_file_priv empty, xp_cmdshell.Votes: 0GitHub stars: 20
- Ai SwarmDrive PWN::Plugins::REPL::AISwarm from pwn_eval.Votes: 0GitHub stars: 86
- Ai Console UsageDrive PWN::Plugins::REPL::AIConsoleUsage from pwn_eval.Votes: 0GitHub stars: 86
- Ai Console CommandsDrive PWN::Plugins::REPL::AIConsoleCommands from pwn_eval.Votes: 0GitHub stars: 86
- Ai ConsoleDrive PWN::Plugins::REPL::AIConsole from pwn_eval.Votes: 0GitHub stars: 86
- Model CatalogDrive PWN::AI::ModelCatalog from pwn_eval.Votes: 0GitHub stars: 86
- JevgrepOperate Jevgrep (`jg`) as optional remote-agent discovery over explicitly scoped skills, wiki pages, or graph source documents. Use only when the user explicitly requests Jevgrep and separately approves transmitting source content and queries to the configured provider with potential cost. Preserve native catalog, exact/LSP/zvec retrieval and Graphify query/path/explain as defaults; Jevgrep does not query or rebuild durable graphs.Votes: 0GitHub stars: 46
- Jev Tool GuardUse `jev_guard_tool_call` immediately before a consequential tool invocation. Do not use it to bypass an approval already required by the user, platform, or policy.Votes: 0GitHub stars: 17
- Jev Task RouterUse `jev_route_task` before committing to an execution path when the task has meaningful ambiguity or risk.Votes: 0GitHub stars: 17
- Customs Trade Compliance通関書類、関税分類、関税最適化、制限当事者スクリーニング、複数の法域にわたる規制コンプライアンスのための成文化された専門知識。15年以上の経験を持つ貿易コンプライアンス専門家に情報。HS分類ロジック、インコターム適用、FTA利用、ペナルティ軽減を含みます。通関許可、関税分類、貿易コンプライアンス、輸入/輸出ドキュメント、または関税最適化を処理するときに使用します。Votes: 0GitHub stars: 17
- Read The Damn DocsUse when implementing, integrating, upgrading, debugging, or answering anything involving third-party APIs, libraries, frameworks, CLIs, cloud services, model/provider SDKs, fast-moving product behavior, user requests for latest/current/official behavior, unfamiliar repo docs/specs, errors that may indicate API drift, or high-stakes auth, security, billing, data, migration, deployment, compliance, or privacy behavior. Forces Codex to web-search for current official docs and read primary docs ...Votes: 0GitHub stars: 17
- Plow AheadUse when the user explicitly wants autonomous progress without routine clarification stops: "plow ahead", "do not stop", "use your best judgment", "keep going until done", "finish while I am away", "do not ask questions unless truly blocked", or similar. Convert ordinary ambiguity into stated assumptions, proceed through implementation and validation, stop only for true blockers, and end with a clear recap of decisions, changes, verification, and residual risk.Votes: 0GitHub stars: 17
- Top Web VulnerabilitiesThis skill should be used when the user asks to \"identify web application vulnerabilities\", \"explain common security flaws\", \"understand vulnerability categories\", \"learn about inject...Votes: 0GitHub stars: 8
- Security Scanning Security HardeningCoordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls.Votes: 0GitHub stars: 8
- Security AuditorExpert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat modeling, secure authentication (OAuth2/OIDC), OWASP standards, cloud security, and security automation. Handles DevSecOps integration, compliance (GDPR/HIPAA/SOC2), and incident response. Use PROACTIVELY for security audits, DevSecOps, or compliance implementation.Votes: 0GitHub stars: 8
- Mobile Security CoderExpert in secure mobile coding practices specializing in input validation, WebView security, and mobile-specific security patterns. Use PROACTIVELY for mobile security implementations or mobile security code reviews.Votes: 0GitHub stars: 8
- Backend Security CoderExpert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.Votes: 0GitHub stars: 8
- Api Security Best PracticesImplement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilitiesVotes: 0GitHub stars: 8
- Extracting Credentials From Memory DumpExtract cached credentials, password hashes, Kerberos tickets, and authenticationVotes: 0GitHub stars: 4
- PrCreate a feature branch, commit changes, push, and open a PR to main.Votes: 0GitHub stars: 2