Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Security DevsecopsDevSecOps, secure software development lifecycle (SSDLC), and application security (AppSec) practices covering secret handling, input validation, dependency hygiene, authentication/authorization, and CI/CD security tooling (SAST, SCA, DAST, secret scanning, IaC scanning). Use when writing code that handles credentials, user input, database queries, or authentication, when setting up a CI/CD pipeline, or when reviewing code or infrastructure for security issues.Votes: 0GitHub stars: 248
- Security Scan Certification 2026 09 19T10 45 07 461ZLightweight security hygiene for agent configs (skills/hooks/MCP/settings). Use before enabling automation, after config changes, and before release.Votes: 0GitHub stars: 54
- Common Security StandardsAssumption: your application receives PII through APIs, processes it in an application service, and must later decrypt it for authorized use. Implement this flow: 1. Validate and sanitize PII at every trust boundary: API, UI, CSV, and webhook. 2. Encrypt PII in the application before persistence using authenticated AES-256 encryption, preferably AES-256-GCM. 3. Store encryption keys only in a secret manager or environment-backed key-management system—never hardcode or commit them. 4. Use TLS ...Votes: 0GitHub stars: 549
- Senior Security../../../engineering-team/senior-security/SKILL.mdVotes: 0GitHub stars: 43
- Agentprivacy Perimeter HardeningDevice security, OS hardening, network configuration, and physical security for 0xagentprivacy swordsman infrastructure. Activates when securing the execution environment beneath the cryptographic layer, designing supply chain integrity checks, hardening operating systems for agent execution, or building the physical and logical security foundation that cryptography assumes but does not provide. Triggers: "device security", "OS hardening", "supply chain", "firmware", "boot integrity", "networ...Votes: 0GitHub stars: 4
- Secure Software EngineeringUse when designing or implementing software securely: define security requirements, threat-model a feature, choose secure defaults, design authentication and authorization, handle untrusted data and secrets, evaluate dependencies, or review security-sensitive changes. Use for prevention during requirements, design, implementation, and review; not for post-build security assessments or scanning an existing codebase.Votes: 0GitHub stars: 36
- Security CheckIndependently assess a change, product, workflow, or deployment for realistic security and privacy risk, reporting outcome separately from coverage. Use for trust-boundary or exposure changes and explicit security review.Votes: 0GitHub stars: 5
- Security Scan Certification 2026 09 13T02 57 18 796ZLightweight security hygiene for agent configs (skills/hooks/MCP/settings). Use before enabling automation, after config changes, and before release.Votes: 0GitHub stars: 54
- Dependency SecurityVet, pin and update third-party dependencies deliberately.Votes: 0GitHub stars: 3
- Security PaperclipPaperclip security — tenancy isolation, secrets, approval gates, hard budgets, signed adapter channel. Use when auditing or hardening Paperclip.Votes: 0GitHub stars: 105
- Security Best PracticesSub-skill of mcp-builder: Security Best Practices.Votes: 0GitHub stars: 17
- Security DocumentationCreate security policies, guidelines, compliance documentation, and security best practices. Use when documenting security policies, compliance requirements, or security guidelines.Votes: 0GitHub stars: 327
- Security ReviewUse when reviewing code or a diff for security issues before merging. Flags concrete, high-confidence vulnerabilities with fixes.Votes: 0GitHub stars: 9
- SecurityOrchestrate all security skills - code audit, infra audit, auth review, secret rotation, and pentest. Use for a full security assessment.Votes: 0GitHub stars: 8
- Security PaperclipSeguranca Paperclip — isolamento tenancy, secrets, gates aprovacao, orcamentos rigidos, canal adapter assinado. Use ao auditar ou fortalecer Paperclip.Votes: 0GitHub stars: 105
- Security AwarenessTeaches AI agents to recognize and avoid security threats during normal activity. Covers phishing detection, credential protection, domain verification, and social engineering defense. Use when building agents that access email, credential vaults, web browsers, or sensitive data.Votes: 0GitHub stars: 207
- Security ReviewThe security trigger and review procedure for this project. Use when deciding whether work needs a security pass, and to run one -- "does this need security review?", auth changes, new input surfaces, new tools.Votes: 0GitHub stars: 3
- Security ChecksSecurity review checklists, threat model, severity classification, and supply chain verification for Java/Spring Boot applications. Load when conducting security reviews.Votes: 0GitHub stars: 15
- Ios SecuritySecure iOS apps with secure storage, biometrics, and data protection. Use when implementing secure storage, Face ID/Touch ID, or data protection in iOS.Votes: 0GitHub stars: 17
- Security Engineer RoleOperate as a security engineer who reduces real risk through threat models, targeted reviews, scalable tooling, and incident duty. Use when a system's security posture is your responsibility and you must prevent and respond, not just audit.Votes: 0GitHub stars: 7