Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Security HardeningSecurity rules for authentication, authorization, RLS policies, CSP and headers, input validation and API routes. Use when building an auth flow, writing RLS policies, setting CSP or security headers, validating input, or auditing security.Votes: 0GitHub stars: 80
- CybersecuritySecurity engineering that protects applications, data, and users from real-world threatsUse when "security, authentication, authorization, encryption, OWASP, vulnerability, XSS, SQL injection, CSRF, secrets, password, JWT, OAuth, permissions, audit, compliance, security, authentication, authorization, encryption, vulnerabilities, OWASP, compliance, audit" mentioned.Votes: 0GitHub stars: 137
- Kit SecuritySecurity guardrails pack — injection, secrets, path traversal, auth defaults, deserialization, untrusted-content discipline. Use when asked for a security pass or when code touches user input, secrets, or auth.Votes: 0GitHub stars: 6
- 1sec SecurityInstall, configure, and manage 1-SEC — an open-source, all-in-one cybersecurity platform (16 modules, single binary)Votes: 0GitHub stars: 10
- Security HardeningWorld-class application security - OWASP Top 10, secure coding patterns, and the battle scars from security incidents that could have been preventedUse when "security, secure, vulnerability, injection, xss, csrf, authentication, authorization, owasp, encryption, secret, password, token, sanitize, validate, escape, encode, harden, security, owasp, injection, xss, csrf, authentication, authorization, encryption, secrets, hardening" mentioned.Votes: 0GitHub stars: 137
- Security ManagerUse when a task needs the judgment of a (physical/corporate) Security Manager — designing physical access controls, assessing a facility or event's security risk, responding to a security incident, or deciding how to allocate a security budget across prevention, detection, and response. Distinct from a cybersecurity/information-security role — this one covers physical and personnel security.Votes: 0GitHub stars: 15
- SecuritySecurity best practices, OWASP Top 10, and secure coding guidelinesVotes: 0GitHub stars: 105
- SecurityOne breach = game over. Threat modeling, OWASP Top 10, secure coding, security architecture, zero trust. The complete security skill for protecting your application from day one. Security isn't a feature you add later - it's a mindset that shapes every decision. This skill covers application security, not infrastructure security. Use when "security, owasp, xss, sql injection, csrf, authentication, authorization, secrets, api key, vulnerability, secure coding, security headers, rate limiting,...Votes: 0GitHub stars: 137
- Security PrivacyPre-flight security & privacy checklist for changes touching identity, data, logging, or external integrations; ensures secrets/PII hygiene and boundary-safe design.Votes: 0GitHub stars: 207
- SecSecurity Engineer for authentication, authorization, secrets, trust boundaries, unsafe inputs, data exposure, and practical security review.Votes: 0GitHub stars: 13
- Persona SecuritySecurity-first decision framework for threat modeling, vulnerability assessment, and compliance review. Use when user discusses security concerns, authentication design, encryption, OWASP compliance, XSS or CSRF prevention, or vulnerability remediation, or mentions 취약점, 보안, or 위협.Votes: 0GitHub stars: 3
- Go SecurityUse when identity, authorization, tenancy, tokens, secrets, injection, SSRF, abuse, or another trust boundary changes what an attacker can reach.Votes: 0GitHub stars: 7
- Security GuardSecurity specialist - finds vulnerabilities and ensures best practicesVotes: 0GitHub stars: 13
- SecurityBuild-time security discipline — threat-model before controls, Always/Ask-First/Never boundary tiers, SSRF, supply chain, LLM/agent security, privacy. INVOKE PROACTIVELY when building anything touching auth, user data, uploads, outbound fetches, dependencies, or model output — even when nobody says "security". The after-the-fact review pass belongs to /security-review; validation mechanics: [[code-standards]]; infra secrets: [[infra-standards]].Votes: 0GitHub stars: 3
- Security Review安全审查Votes: 0GitHub stars: 188
- 447 Control Set 10 Data Protection 69e07461<!-- Threat Modeling Skill | Version 3.0.2 (20260204a) | https://github.com/fr33d3m0n/threat-modeling | License: BSD-3-Clause --> --- description: Data & storage security (DB isolation, TLS, least privilege, RLS/CLS, backups, auditing) languages: - c - javascript - sql - yaml alwaysApply: false --- rule_id: codeguard-0-data-storageVotes: 0GitHub stars: 4
- 447 Control Set 10 Data Protection Cbab8bd5<!-- Threat Modeling Skill | Version 3.0.3 (20260209a) | https://github.com/fr33d3m0n/threat-modeling | License: BSD-3-Clause --> --- description: Data & storage security (DB isolation, TLS, least privilege, RLS/CLS, backups, auditing) languages: - c - javascript - sql - yaml alwaysApply: false --- rule_id: codeguard-0-data-storageVotes: 0GitHub stars: 4
- Security Review安全审查。Path C+ 自动触发或显式调用。检查认证/授权、输入验证、密钥管理、依赖漏洞。Votes: 0GitHub stars: 188
- Agent SecurityThreat-model and harden AI-agent trust boundaries, tools and data flows. Use when reviewing agent prompt injection, malicious retrieval/tool output, exfiltration, confused-deputy execution, tool poisoning or sandbox/credential boundaries. Do not use for general application security without a model/tool trust flow, or layering operational quality guardrails alone.Votes: 0GitHub stars: 2
- Security DevsecopsDevSecOps, secure software development lifecycle (SSDLC), and application security (AppSec) practices covering secret handling, input validation, dependency hygiene, authentication/authorization, and CI/CD security tooling (SAST, SCA, DAST, secret scanning, IaC scanning). Use when writing code that handles credentials, user input, database queries, or authentication, when setting up a CI/CD pipeline, or when reviewing code or infrastructure for security issues.Votes: 0GitHub stars: 248