Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- honeybadgerScan a GitHub or GitLab repository for security issues before installing it as a skill, tool, or MCP server. Use when the user wants to check, vet, scan, or review a repository for safety before installation. Detects hardcoded secrets, known CVEs, supply chain risks, and build provenance.Votes: 0GitHub stars: 3
- Honeybadger DevHow to add a scanner, lockfile parser, or rule to HoneyBadger, plus the test-fixture and self-check requirements. Use when extending scanners or contributing to honeybadger.Votes: 0GitHub stars: 3
- Report ReviewUse when a peer worktree session (southpaw·orthodox·spare 등) sends the central control session a draft it is about to show the user or publish — 완료 보고·결정 요청·분석 결과, 또는 PR 생성 전 커밋 메시지·PR 본문 초안. Triggers on "유저 보고 검수해줘", "이 보고 내보내도 돼?", "커밋 메시지·PR 본문 봐줘", 피어가 보낸 `[보고 검수]`·`[PR 문안 검수]` 머리의 메시지. Does NOT trigger on 계획 문서 리뷰(plan-review 스킬), PR 리뷰(review 스킬), 하위 세션에 관문을 알리는 일(control-brief 스킬), 이 세션이 유저에게 직접 답하는 일.Votes: 0GitHub stars: 15
- MssqlExecute read-only SQL queries against multiple Microsoft SQL Server databases. Use when: (1) querying MSSQL/SQL Server databases, (2) exploring database schemas/tables, (3) running SELECT queries for data analysis, (4) checking database contents. Supports multiple database connections with descriptions for intelligent auto-selection. Blocks all write operations (INSERT, UPDATE, DELETE, DROP, etc.) for safety.Votes: 0GitHub stars: 158
- Cyhber DeployUse when preparing staging/production deploys, modifying CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins), changing IaC (Terraform, Kubernetes, Docker), handling authentication/authorization/sessions/secrets, detecting injection vulnerabilities, reviewing security groups/IAM/RBAC, hardcoded credentials, exposed endpoints, or requesting security reviewsVotes: 0GitHub stars: 19
- SlackxUse the `slackx` CLI to cache and read Slack threads, channel history, DMs, users, and channels from a local SQLite database. It fetches threads via `conversations.replies`, channel history via `conversations.history`, and workspace users/channels, storing everything locally so subsequent reads are instant and incremental. Trigger when the user wants to read, cache, refresh, or poll a Slack thread or channel, render a thread with human-readable author names, search the workspace and cache mat...Votes: 0GitHub stars: 10
- Review ImplementationReview a code implementation for correctness, quality, test coverage, security, performance, and spec alignment.Votes: 0GitHub stars: 10
- Quick Pr ReviewRapidly review and approve a GitHub pull request to unblock others. Approves unless there are significant risks or significant public interface changes.Votes: 0GitHub stars: 10
- Audit SecurityScan the codebase for code-level security vulnerabilities including hardcoded secrets, injection risks, missing auth checks, and insecure patterns, then produce a prioritized remediation plan.Votes: 0GitHub stars: 10
- Audit SdlcRun multiple audit skills against the project and produce a unified findings report with prioritized action items.Votes: 0GitHub stars: 10
- Assess Pr RiskEstimate how risky a GitHub pull request is and how confident that estimate is, then recommend the next action for a human reviewer. Self-contained: it gathers its evidence from the diff, the codebase, and churn of the touched files, so it can run in parallel with the other review skills. Use when the user asks "how risky is this PR", "assess PR risk", "risk and confidence for this PR", "should I review this deeply", or wants to decide what to do next with a PR.Votes: 0GitHub stars: 10
- Trekify> *"Captain, I've routed all sensitive data through the privacy buffers."* Privacy through technobabble. Transform sensitive information into Star Trek terminology — **every substitution flagged with 🖖**.Votes: 0GitHub stars: 56
- RewardMotto: Rewards should feel earned and fitting.Votes: 0GitHub stars: 56
- PersonaIdentity layers for characters — WHO they are vs WHAT they doVotes: 0GitHub stars: 56
- Wp Security AuditRun a structured security audit on any WordPress site — core integrity, plugin/theme CVE cross-check, wp-config and file-permission hardening, malware/compromise detection, and triaged code review of risky plugins. Use this skill whenever the user asks to "audit WordPress security", "check my WP site for vulnerabilities", "is my WordPress site secure", "scan my site", "security check", "harden WordPress", "check my plugins for vulnerabilities", "was my site hacked", or shares a WordPress site...Votes: 0GitHub stars: 2
- Role ModelUse when routing model requests through an externally running role-model runtime, inspecting role-model aliases, or diagnosing the role-model provider route.Votes: 0GitHub stars: 117
- Risk AssessmentFramework-directable information security risk assessment. Identifies threats, evaluates likelihood/impact via a 3x3 matrix, maps findings to any compliance framework, and recommends risk treatment options with prioritization guidance.Votes: 0GitHub stars: 2
- Project PlanningDeep project planning workflow—goals and non-goals, work breakdown, dependencies, critical path, risks and buffers, milestones, and communication rhythm. Use when kicking off initiatives, replanning after slips, or coordinating cross-team delivery.Votes: 0GitHub stars: 2
- ComplianceTrack compliance requirements and generate audit trail reports. Use when auditing controls, checking policies, generating audit trails.Votes: 0GitHub stars: 2
- Cross Team Comm通过 Tailscale、SSH、Gateway API 与 sessions_send 实现跨团队、跨实例的 OpenClaw 协作通信。Votes: 0GitHub stars: 2