Browse Secure Claude Skills
Search verified agent skills and review security grades before installing · full A–Z index
- SecuritySécurité. Use when reviewing security, implementing auth, or hardening code.Votes: 0GitHub stars: 105
- SecuritySecurity best practices for secure coding, authentication, authorization, and data protection. Use when developing features that handle sensitive data, user authentication, or require security review.Votes: 0GitHub stars: 151
- Common Security StandardsEnforce universal security protocols for safe, resilient software. Use when implementing authentication, encryption, authorization, input validation, secret management, or any security-sensitive feature across any language or framework.Votes: 0GitHub stars: 549
- Common Security StandardsEnforce universal security protocols for safe, resilient software. Use when implementing authentication, encryption, authorization, input validation, secret management, or any security-sensitive feature across any language or framework.Votes: 0GitHub stars: 549
- Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when personal data or privacy compliance (GDPR, CCPA) is involved.Votes: 0GitHub stars: 3
- SecurityDefensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries, attack surface); reviewing code for vulnerabilities (injection, IDOR, secrets, the OWASP classes); hardening operations (secrets management, detection, patching, incident response); or judging whether a security control/program is real or theater. Also invoke BEFORE any offensive-flavored request ...Votes: 0GitHub stars: 239
- Security PolicyApplication and AI-agent security - secrets management, authentication and authorization (least privilege), credential flows (sign-in, sign-up that establishes the session, password reset, 2FA, breached-password checks against Have I Been Pwned, refusing a password that repeats the username, email or display name in any casing, and rate limiting per IP and per account), cookie attributes and consent gating before non-essential storage, OWASP Top 10 mitigations (SSRF through a vetted fetch, op...Votes: 0GitHub stars: 2
- CybersecuritySecurity engineering that protects applications, data, and users from real-world threatsUse when "security, authentication, authorization, encryption, OWASP, vulnerability, XSS, SQL injection, CSRF, secrets, password, JWT, OAuth, permissions, audit, compliance, security, authentication, authorization, encryption, vulnerabilities, OWASP, compliance, audit" mentioned.Votes: 0GitHub stars: 137
- 1sec SecurityInstall, configure, and manage 1-SEC — an open-source, all-in-one cybersecurity platform (16 modules, single binary)Votes: 0GitHub stars: 10
- Security HardeningWorld-class application security - OWASP Top 10, secure coding patterns, and the battle scars from security incidents that could have been preventedUse when "security, secure, vulnerability, injection, xss, csrf, authentication, authorization, owasp, encryption, secret, password, token, sanitize, validate, escape, encode, harden, security, owasp, injection, xss, csrf, authentication, authorization, encryption, secrets, hardening" mentioned.Votes: 0GitHub stars: 137
- Security ManagerUse when a task needs the judgment of a (physical/corporate) Security Manager — designing physical access controls, assessing a facility or event's security risk, responding to a security incident, or deciding how to allocate a security budget across prevention, detection, and response. Distinct from a cybersecurity/information-security role — this one covers physical and personnel security.Votes: 0GitHub stars: 15
- SecurityOne breach = game over. Threat modeling, OWASP Top 10, secure coding, security architecture, zero trust. The complete security skill for protecting your application from day one. Security isn't a feature you add later - it's a mindset that shapes every decision. This skill covers application security, not infrastructure security. Use when "security, owasp, xss, sql injection, csrf, authentication, authorization, secrets, api key, vulnerability, secure coding, security headers, rate limiting,...Votes: 0GitHub stars: 137
- Security PrivacyPre-flight security & privacy checklist for changes touching identity, data, logging, or external integrations; ensures secrets/PII hygiene and boundary-safe design.Votes: 0GitHub stars: 207
- Go SecurityUse when identity, authorization, tenancy, tokens, secrets, injection, SSRF, abuse, or another trust boundary changes what an attacker can reach.Votes: 0GitHub stars: 7
- 447 Control Set 10 Data Protection 69e07461<!-- Threat Modeling Skill | Version 3.0.2 (20260204a) | https://github.com/fr33d3m0n/threat-modeling | License: BSD-3-Clause --> --- description: Data & storage security (DB isolation, TLS, least privilege, RLS/CLS, backups, auditing) languages: - c - javascript - sql - yaml alwaysApply: false --- rule_id: codeguard-0-data-storageVotes: 0GitHub stars: 4
- 447 Control Set 10 Data Protection Cbab8bd5<!-- Threat Modeling Skill | Version 3.0.3 (20260209a) | https://github.com/fr33d3m0n/threat-modeling | License: BSD-3-Clause --> --- description: Data & storage security (DB isolation, TLS, least privilege, RLS/CLS, backups, auditing) languages: - c - javascript - sql - yaml alwaysApply: false --- rule_id: codeguard-0-data-storageVotes: 0GitHub stars: 4
- Agent SecurityThreat-model and harden AI-agent trust boundaries, tools and data flows. Use when reviewing agent prompt injection, malicious retrieval/tool output, exfiltration, confused-deputy execution, tool poisoning or sandbox/credential boundaries. Do not use for general application security without a model/tool trust flow, or layering operational quality guardrails alone.Votes: 0GitHub stars: 2
- Security Scan Certification 2026 09 19T10 45 07 461ZLightweight security hygiene for agent configs (skills/hooks/MCP/settings). Use before enabling automation, after config changes, and before release.Votes: 0GitHub stars: 54
- Common Security StandardsAssumption: your application receives PII through APIs, processes it in an application service, and must later decrypt it for authorized use. Implement this flow: 1. Validate and sanitize PII at every trust boundary: API, UI, CSV, and webhook. 2. Encrypt PII in the application before persistence using authenticated AES-256 encryption, preferably AES-256-GCM. 3. Store encryption keys only in a secret manager or environment-backed key-management system—never hardcode or commit them. 4. Use TLS ...Votes: 0GitHub stars: 549
- Agentprivacy Perimeter HardeningDevice security, OS hardening, network configuration, and physical security for 0xagentprivacy swordsman infrastructure. Activates when securing the execution environment beneath the cryptographic layer, designing supply chain integrity checks, hardening operating systems for agent execution, or building the physical and logical security foundation that cryptography assumes but does not provide. Triggers: "device security", "OS hardening", "supply chain", "firmware", "boot integrity", "networ...Votes: 0GitHub stars: 4