Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- honeybadgerScan a GitHub or GitLab repository for security issues before installing it as a skill, tool, or MCP server. Use when the user wants to check, vet, scan, or review a repository for safety before installation. Detects hardcoded secrets, known CVEs, supply chain risks, and build provenance.Votes: 0GitHub stars: 3
- MssqlExecute read-only SQL queries against multiple Microsoft SQL Server databases. Use when: (1) querying MSSQL/SQL Server databases, (2) exploring database schemas/tables, (3) running SELECT queries for data analysis, (4) checking database contents. Supports multiple database connections with descriptions for intelligent auto-selection. Blocks all write operations (INSERT, UPDATE, DELETE, DROP, etc.) for safety.Votes: 0GitHub stars: 158
- Cyhber DeployUse when preparing staging/production deploys, modifying CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins), changing IaC (Terraform, Kubernetes, Docker), handling authentication/authorization/sessions/secrets, detecting injection vulnerabilities, reviewing security groups/IAM/RBAC, hardcoded credentials, exposed endpoints, or requesting security reviewsVotes: 0GitHub stars: 19
- Trekify> *"Captain, I've routed all sensitive data through the privacy buffers."* Privacy through technobabble. Transform sensitive information into Star Trek terminology — **every substitution flagged with 🖖**.Votes: 0GitHub stars: 56
- RewardMotto: Rewards should feel earned and fitting.Votes: 0GitHub stars: 56
- PersonaIdentity layers for characters — WHO they are vs WHAT they doVotes: 0GitHub stars: 56
- Wp Security AuditRun a structured security audit on any WordPress site — core integrity, plugin/theme CVE cross-check, wp-config and file-permission hardening, malware/compromise detection, and triaged code review of risky plugins. Use this skill whenever the user asks to "audit WordPress security", "check my WP site for vulnerabilities", "is my WordPress site secure", "scan my site", "security check", "harden WordPress", "check my plugins for vulnerabilities", "was my site hacked", or shares a WordPress site...Votes: 0GitHub stars: 2
- Risk AssessmentFramework-directable information security risk assessment. Identifies threats, evaluates likelihood/impact via a 3x3 matrix, maps findings to any compliance framework, and recommends risk treatment options with prioritization guidance.Votes: 0GitHub stars: 2
- Project PlanningDeep project planning workflow—goals and non-goals, work breakdown, dependencies, critical path, risks and buffers, milestones, and communication rhythm. Use when kicking off initiatives, replanning after slips, or coordinating cross-team delivery.Votes: 0GitHub stars: 2
- ComplianceTrack compliance requirements and generate audit trail reports. Use when auditing controls, checking policies, generating audit trails.Votes: 0GitHub stars: 2
- Workspace Mingjing> **版本**:v2.0(增强版) > **角色**:明镜 (Ming Jing - The Aegis of Order) > **背景**:西南政法大学本科 + 哈佛法学院博士,盈科/四大经验 > **模式**:Skill Manifest(只引用,不承载内容) > **更新日期**:2026-05-01Votes: 0GitHub stars: 2
- Code SecurityCode security capability pack. Gives AI agents the judgment rules for SAST scanning (Semgrep), DAST testing (Nuclei), secret detection (Gitleaks/TruffleHog), IaC security linting (Checkov), and vulnerability triage (osv-scanner/Grype/Snyk). Research-grounded rules from tool documentation, OWASP guidelines, and real-world pipeline architecture. Use for any application security scanning, secret leak prevention, infrastructure hardening, or vulnerability prioritization task.Votes: 0GitHub stars: 3
- Snyk TriageValidate Snyk SAST / Code findings against repo evidence; emits per-finding verdicts (CONFIRMED / FALSE_POSITIVE / NEEDS_REVIEW / DUPLICATE / NOT_APPLICABLE). Use when a Snyk or Jira-exported scanner report is provided.Votes: 0GitHub stars: 504
- Entra Posture ReviewReview a Microsoft Entra ID tenant's identity posture from read-only Graph exports, checking Conditional Access basics, security defaults, standing Global Administrators, guests with roles, stale guests, long-lived app secrets, high-risk Graph application permissions, consent and invitation settings and legacy sign-ins. Use when asked \"who are our Global Admins?\", to baseline a tenant, before an ISO 27001 or Essential Eight audit, or after taking one over. Not for Intune devices (intune-bas...Votes: 0GitHub stars: 2
- Threat ModelingSecurity analysis and threat modeling prompt templates for STRIDE analysis, code review, OWASP compliance, and vulnerability assessment. Use for security planning, pre-deployment reviews, and ongoing threat assessment. Triggers include "STRIDE", "threat model", "security review", "code review", "OWASP", "payment security", "security analysis", "vulnerability assessment".Votes: 0GitHub stars: 2
- Prompt EngineeringComprehensive security prompt templates for implementing secure features with multiple security layers. Use for complex implementations like forms, authenticated endpoints, public APIs, admin features, file uploads, middleware composition, and security testing. Triggers include "secure form", "authenticated endpoint", "public endpoint", "admin action", "file upload", "composable middleware", "security testing", "new security control".Votes: 0GitHub stars: 2
- Built In ControlsSimple security prompt templates for quick implementations using existing Secure Vibe Coding OS utilities. Use for straightforward features like contact forms, authenticated updates, and public APIs. Triggers include "contact form", "simple form", "authenticated update", "user update", "public API", "read-only API", "quick secure implementation".Votes: 0GitHub stars: 2
- Auth AuthorizationAuthentication and authorization prompt templates for RBAC implementation, permissions systems, ownership verification, and authorization testing. Use when setting up roles, implementing access control, or testing authorization logic. Triggers include "RBAC", "role-based access", "permissions", "ownership", "authorization", "access control", "user roles", "auth testing".Votes: 0GitHub stars: 2
- Security PromptsLibrary of battle-tested security prompt templates for secure feature implementation. Use when implementing forms, endpoints, authentication, authorization, file uploads, or conducting security reviews. Triggers include "security prompt", "secure form", "RBAC", "threat model", "STRIDE", "admin endpoint", "file upload", "security testing", "code review", "OWASP".Votes: 0GitHub stars: 2
- Auth SecurityImplement secure authentication and authorization using Clerk. Use this skill when you need to authenticate users, protect routes, check permissions, implement subscription-based access control, or integrate Clerk with your application. Triggers include "authentication", "auth", "authorization", "Clerk", "protect route", "check user", "sign in", "session", "permissions", "subscription access".Votes: 0GitHub stars: 2