Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- CybersecurityPerform an advanced offensive security audit and attack simulation on the current features.Votes: 0GitHub stars: 22
- Supply Chain SecuritySecure the software supply chain from the consume side: ingest the SBOM, triage CVEs by reachability, pin dependencies with a deliberate update cadence, verify SLSA provenance, and defend against malicious packages.Votes: 0GitHub stars: 7
- Ios SecurityHere’s a quick-start iOS security example that covers secure token storage, biometric unlock, and protected file writes: ```swift import Foundation import LocalAuthentication import Security enum SecureStore { static func saveToken(_ token: String, account: String = "authToken") throws { let data = Data(token.utf8) let query: [String: Any] = [ kSecClass as String: kSecClassGenericPassword, kSecAttrAccount as String: account, kSecValueData as String: data ] SecItemDelete(query as CFDictionary)...Votes: 0GitHub stars: 549
- Secret Configuration Security`analysis-agent`/`task-agent`/`review-agent`: use when secrets, KMS/env config, rotation, logging, redaction, or rollback changes; skip non-sensitive config.Votes: 0GitHub stars: 7
- Security InfraInfrastructure security, headers, encryption, and compliance. Use when: (1) Configuring security headers (CSP, CORS, HSTS), (2) Setting up HTTPS/TLS, (3) Data encryption at rest/transit, (4) Implementing compliance (GDPR, PCI-DSS), (5) Secrets management. Auto-detects: helmet, csp, cors, hsts, https, tls, ssl, encrypt, gdpr, pci-dss, compliance, secret, vault, kmsVotes: 0GitHub stars: 24
- Information Security Manager Iso27001../../../ra-qm-team/information-security-manager-iso27001/SKILL.mdVotes: 0GitHub stars: 43
- Sql Injection GuardProfessional SQL Injection Guard Expert skill. Implement enterprise-grade web application security controls and encryption standards.Votes: 0GitHub stars: 3
- Secure Code GuardianUse when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities — including custom security implementations such as hashing passwords with bcrypt/argon2, sanitizing SQL queries with parameterized statements, configuring CORS/CSP headers, validating input with Zod, and setting up JWT tokens. Invoke for authentication, authorization, input validation, encryption, OWASP Top 10 prevention, secure session management, and security hardening. For p...Votes: 0GitHub stars: 11,720
- Security Review安全审查 — T 阶段 (Path C+)Votes: 0GitHub stars: 188
- SecurityUse when applying security best practices — authentication, authorization, CSRF protection, input sanitization, rate limiting, or secure coding — stack-agnostic.Votes: 0GitHub stars: 10
- Mobile SecurityProfessional Mobile Security Expert skill. Implement enterprise-grade web application security controls and encryption standards.Votes: 0GitHub stars: 3
- Mobile Security EngineerMobile application security covering certificate pinning implementation, secure local storage patterns, jailbreak and root detection, code obfuscation and tamper detection, API security for mobile clients, biometric authentication, secure key management, network security, reverse engineering defense, and compliance with OWASP MASVS. Use when the user asks about mobile security engineer, mobile security engineer best practices, or needs guidance on mobile security engineer implementation. Do N...Votes: 0GitHub stars: 595
- CollectionSenior Security Engineer with 12+ years application security experience. Use when implementing authentication/authorization, configuring JWT/OAuth2, conducting security reviews, implementing rate limiting, ensuring GDPR compliance, or performing security scanning.Votes: 0GitHub stars: 24
- Code Safetytrigger: secrets, eval/exec, unsanitized SQL, hallucinated dependencies. avoid: committing credentials, adding unverified packages, executing dynamic code. Install scan-secrets for the enforced counterpart of the secret slice (a commit-time gate), and verify-dependency-exists for the dependency slice (opt-in: disabled by default, needs a curated allowlist); the eval/exec and unsanitized-SQL guidance stays advisory (a gate can decide only the non-literal slice: agentic-code-security's code pack).Votes: 0GitHub stars: 8
- SecurityFind the security defect in code before it ships: secrets in source or in schema files, Supabase RLS and access policies, session and sign-out scope, a user id read from the payload or a header instead of the verified session, and unvalidated external input.Votes: 0GitHub stars: 6
- Security PaperclipPaperclip-Sicherheit — Tenancy-Isolation, Secrets, Approval-Gates, harte Budgets, signierter Adapter-Channel. Verwenden Sie dies beim Auditing oder Härten von Paperclip.Votes: 0GitHub stars: 105
- Security ChecksSecurity-review checklist, threat model, severity classification, and supply chain verification — language-agnostic, with per-section slots a stack fills in. Load when conducting security reviews.Votes: 0GitHub stars: 15
- Cloud SecurityProfessional Cloud Security Expert skill. Implement enterprise-grade web application security controls and encryption standards.Votes: 0GitHub stars: 3
- Security Guidance离线环境下的本地安全审查与加固建议Votes: 0GitHub stars: 9
- Security ReviewCheck for: auth flaws, authz failures/IDOR, injection, CSRF, insecure endpoints, exposed secrets, unsafe env usage, weak validation, data leakage, dependency risks. Do NOT modify code. Report: findings, severity, affected files, exploit scenario, recommended fix.Votes: 0GitHub stars: 2