Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- Secure Code GuardianUse when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities. Invoke for authentication, authorization, input validation, encryption, OWASP Top 10 prevention.Votes: 0GitHub stars: 10
- Supply Chain SecurityProfessional Supply Chain Security Expert skill. Implement enterprise-grade web application security controls and encryption standards.Votes: 0GitHub stars: 3
- Security And HardeningHarden authentication, input handling, storage, and integrations when implementing security controls or remediating concrete vulnerabilities.Votes: 0GitHub stars: 70
- Dygo Security EngineeringDesign, implement, or review security-sensitive dygo behavior across auth, sessions, Permissions, secrets, APIs, database writes, files, Jobs, and Studio. Use when security boundaries are a primary concern.Votes: 0GitHub stars: 16
- Security AuditChecklist for security-sensitive coding, ensuring MaiHouses guards and policies are respected.Votes: 0GitHub stars: 207
- Flutter SecurityEnforce OWASP Mobile security standards for Flutter apps. Use when storing sensitive data, making network calls, handling tokens/PII, or preparing release builds.Votes: 0GitHub stars: 549
- Java Application Security BasicsApplication-security judgement for Java 21+: password storage with current memory-hard KDF parameters, constant-time verification, secure randomness, authorisation inside the protected operation, adversarial validation, reversible-cryptography boundaries, and secret-safe types. Use when credentials, password hashes, salts, bearer tokens or peppers change; when MessageDigest, SecureRandom, Random, UUID, Cipher, Mac or PasswordEncoder serves a security purpose; when a controller annotation is t...Votes: 0GitHub stars: 2
- Security ArchitectPragmatic security architect for a non-security-expert owner. Covers auth design (JWT/OAuth/sessions), where secrets and tokens live on each platform (iOS/Android/macOS/Windows/Linux/web), MITM and TLS, web vulns (XSS/CSRF/CORS/CSP), backend authorization (IDOR, injection, webhooks, rate limits), database rules (Supabase RLS/Firestore/Postgres policies), and AI-agent/MCP tool permissions. Load when the user asks "is this secure?", "where should I store this secret/token?", designs a login or ...Votes: 0GitHub stars: 2
- Security ReviewDefend before attackers find the gaps - OWASP, STRIDE, and Microsoft SFIVotes: 0GitHub stars: 4
- Security AuditorUse when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation, SQL injection prevention, XSS protection, or any security-related code review.Votes: 0GitHub stars: 2,128
- Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.Votes: 0GitHub stars: 9
- Dev Security BasicsUse when code handles a request, a session, a secret, a file upload, a query built from input, or anything a user can address by id — and whenever the change touches auth, roles, money, personal data or deletion.Votes: 0GitHub stars: 6
- Common Llm SecurityViolated guardrail: a valid hash proves integrity, not trusted authorship or safety. Since the host ignores `allowed-tools`, permission boundaries are unenforced; do not execute privileged tools. Stop and restart only after independent source review, provenance/authorship verification, and confirmation that the host—not the skill text—enforces tool, network, filesystem, and write/delete/execute restrictions. Required evidence: - Pinned source revision and matching hash. - Verified publisher/a...Votes: 0GitHub stars: 571
- Android SecuritySecure data encryption, network configuration, and permissions in Android apps. Use when handling API keys, auth tokens, certificate pinning, EncryptedSharedPreferences, or securing exported components.Votes: 0GitHub stars: 549
- Security And HardeningHardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when auditing dependencies for known vulnerabilities, triaging package-manager audit findings, or assessing supply-chain risk in a...Votes: 0GitHub stars: 2
- Cybersecurity PrinciplesUse when explaining cybersecurity foundations, the Saltzer-Schroeder design principles, CIA triad, Zero Trust architecture, defense in depth, AAA model, threat intelligence, NIST CSF 2.0, CIS Controls, ISO 27001, modern IAM (FIDO2/passkeys/PAM), SASE, incident response, or building a security mental model. Use for any conceptual cybersecurity question, when grounding security decisions in first principles, when explaining why a security control exists, when evaluating security trade-offs, or ...Votes: 0GitHub stars: 2
- Security ReviewUse as a REVIEW LENS when judging another agent's diff for security defects — injection, broken authentication or authorization, secrets in code, unsafe deserialisation, SSRF, path traversal, missing validation, mass assignment, insecure defaults — before recommending approval. Invoke on every review of a ticket that touches auth, input handling, data access, outbound requests, files, crypto, or configuration, and on any high-risk ticket; it complements review-ticket, it does not replace it.Votes: 0GitHub stars: 2
- Security PaperclipSécurité Paperclip — isolation tenant, secrets, portes d'approbation, budgets stricts, capacités plugin minimales. À utiliser pour auditer ou durcir Paperclip.Votes: 0GitHub stars: 105
- Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when personal data or privacy compliance (GDPR, CCPA) is involved.Votes: 0GitHub stars: 3
- Security HardeningAI Agent一键安全加固系统,部署输入过滤器、命令拦截器、模型锁、持久防护和审计日志,防御prompt注入、社会工程学、危险命令执行和信息泄露。 Use when: "安全加固", "agent安全防护", "prompt注入防御", "security hardening", "protect my agent", "部署安全过滤器", "防止信息泄露", "secure my agent". 默认拒绝安全姿态,所有敏感操作需管理员验证,审计日志记录每次安全相关动作。Cross-references: skill-security-audit, secure-key-manager, security-drill. Built by UniqueClub 🌐 https://uniqueclub.aiVotes: 0GitHub stars: 28