1,051 free skills
Security skills
Skills for security — code auditing, penetration testing, secrets management, encryption, and dependency vulnerability scanning.
Sourced from real, public repositories — synced daily, never invented.
1,051 free skills
Skills for security — code auditing, penetration testing, secrets management, encryption, and dependency vulnerability scanning.
Sourced from real, public repositories — synced daily, never invented.
15 tools across six categories
13 of them never send your data anywhere
Free · No signup · No trial clock
SEE THE DIRECTORY

oauth-2-0-setup
seb1n/awesome-ai-agent-skills
Implement OAuth 2.0 authentication flows including authorization code with PKCE, client credentials, and device code for secure API integration. Use when the user requests oauth 2 0 setup or provides relevant inputs for this workflow.
corrinehu-kimi-searchzhihu
corrinehu/agent-skills
Search Zhihu (知乎) using agent-browser with proper authentication handling. Use when user asks to "search zhihu", "知乎搜索", "在知乎上找", or any Zhihu-related search requests. Handles login requirements, session persistence, and common error cases like 40362 restrictions.
deepsec
vercel-labs/deepsec
Run deepsec, an AI-powered cyber-security vulnerability scanner. Activates when the user invokes /deepsec, asks to run deepsec, or wants to scan their repo, branch, or uncommitted changes for vulnerabilities.
kafka-security-audit
lensesio/agentic-engineering-for-apache-kafka
Audit Kafka security configuration across the codebase and live cluster using the Lenses MCP server. Checks authentication (SASL), encryption (SSL/TLS), authorisation (ACLs), secrets management and environment tier mismatches. Use when user says "audit Kafka security", "check security config", "is my cluster secure" or asks about authentication, encryption or credentials. Do NOT use for configuring certificates, creating SASL users or setting up ACLs.
encryption-at-rest-checker
jeremylongshore/claude-code-plugins-plus-skills
Validate encryption at rest checker operations. Auto-activating skill
sgds-pattern-page-templates
govtechsg/sgds-web-component
Complete ready-to-use page templates built with SGDS components and utilities. Use this skill whenever a user asks to build a page, dashboard, login page, form page, settings page, list page, or any full-page UI — even if they don't say 'template'. Apply when starting a new app, building internal tools, dashboards, admin portals, authentication flows, or data table views.
supabase-usage
fcakyon/claude-codex-settings
This skill should be used when user asks to "query Supabase", "list Supabase tables", "get Supabase schema", "search Supabase records", "check Supabase database", "Supabase auth", "Supabase authentication", "RLS policy", "row level security", "Supabase foreign key", "table relationships", "Supabase join", "Supabase filter", "Supabase pagination", or needs guidance on Supabase database patterns, auth flows, RLS policies, or query best practices.
axiom-cryptokit-ref
charleswiltgen/axiom
Use when needing CryptoKit API details — hash functions (SHA2/SHA3), HMAC, AES-GCM/ChaChaPoly encryption, ECDSA/EdDSA signatures, ECDH key agreement, ML-KEM/ML-DSA post-quantum algorithms, HPKE encryption, Secure Enclave key types, key representations (raw/DER/PEM/x963), or Swift Crypto cross-platform parity. Covers complete CryptoKit API surface.
broken-access-control
scholarly360/owasp-top10-web-skills
>
security-ops
0xdarkmatter/claude-mods
Security audit orchestrator - parallel dependency scanning, SAST pattern detection, auth/config review. Dispatches 3 audit agents simultaneously, consolidates into OWASP-mapped severity report. Triggers on: security review, security audit, OWASP, XSS, SQL injection, CSRF, authentication, authorization, secrets management, input validation, secure coding, vulnerability scan, dependency audit.
security-audit
hexters/laravel-security-audit
Comprehensive security audit for Laravel/PHP projects. Scans for malware, webshells, vulnerable packages, crypto miners, misconfigurations, and applies hardening. Built from real-world incident response experience.
frontend-mobile-security-xss-scan
rmyndharis/antigravity-skills
You are a frontend security specialist focusing on Cross-Site Scripting (XSS) vulnerability detection and prevention. Analyze React, Vue, Angular, and vanilla JavaScript code to identify injection poi
web-security-audit
angelapaia/web-security-audit-skill
Auditoria de seguridad web completa tipo pentest black-box. Ejecuta 70+ tests contra cualquier URL (OWASP Top 10, CVEs, CORS, headers, BBDD, auth, rate limiting, inyeccion) y genera informe HTML profesional con vulnerabilidades, pruebas de concepto y plan de accion. Usa esta skill siempre que el usuario mencione auditoria de seguridad, pentest, revisar seguridad, buscar vulnerabilidades, ciberseguridad, test de penetracion, o quiera verificar que una web es segura antes de lanzar.
lightning
inco-fhevm/skills
>
authentication-failures
scholarly360/owasp-top10-web-skills
>
security
alicoder001/agent-skills
Security best practices for web applications. Use when handling user input, authentication, or sensitive data. Covers XSS, SQL injection, CSRF, environment variables, and secure coding patterns.
owasp
anmolnagpal/devops-skills
Security review requiring judgment about exploitability: injection and input handling, authentication and session management, authorization, secret storage and cryptography, and Agentic AI risks, against OWASP Top 10:2025 and ASVS 5.0. Use when user says 'review for security', 'is this secure', 'review this endpoint for injection', 'check for SQL injection or XSS', 'review auth/authorization', 'how are we storing secrets', 'check how we store secrets in this service', 'is this crypto correct', or when writing cryptography, session management, or AI agent code. Judges reachability and impact in this codebase; /clouddrove:appsec owns the deterministic checks a tool can answer (lockfile CVEs, missing headers, wildcard CORS).
implementing-disk-encryption-with-bitlocker
mukul975/anthropic-cybersecurity-skills
Implements full disk encryption using Microsoft BitLocker on Windows
insecure-design
scholarly360/owasp-top10-web-skills
>
secrets
ionfury/homelab
|
cryptographic-failures
scholarly360/owasp-top10-web-skills
>
injection
scholarly360/owasp-top10-web-skills
>
kotlin-ktor
pluginagentmarketplace/custom-plugin-kotlin
Ktor framework - routing, authentication, WebSockets
docker-scout
full-stack-skills/docker-skills
Guidance for Docker Scout — image vulnerability scanning, SBOM generation, and policy evaluation. Covers scout quickview for CVEs, scout cves for detailed vulnerability analysis, scout sbom for software bill of materials, policy evaluation with custom rules, CI/CD integration (GitHub Actions/Jenkins), and remediation guidance. Use when the user asks about docker scout, vulnerability scanning, CVE, SBOM, image analysis, security vulnerabilities, or needs to scan Docker images for security issues. 使用场景:docker scout、漏洞扫描、CVE、SBOM、镜像安全分析、安全漏洞、软件物料清单.
spot
crypto-com/crypto-agent-trading
Crypto.com Exchange Spot request using the Crypto.com Exchange API. Authentication requires API key and secret key. Supports production and UAT sandbox.
age-file-encryption
besoeasy/open-skills
Encrypt and decrypt files or streams using age — a simple, modern, and secure encryption tool with small explicit keys, passphrase support, SSH key support, post-quantum hybrid keys, and UNIX-style composability. No config options, no footguns.
security-misconfiguration
scholarly360/owasp-top10-web-skills
>
mishandling-exceptional-conditions
scholarly360/owasp-top10-web-skills
>
authentication-testing
mn-youssef/security-skills
Use when testing login, sessions, password reset, OAuth/OIDC/SAML/SSO, MFA, and JWTs for weaknesses that lead to account takeover — credential attacks, session fixation, reset-token poisoning, MFA bypass, and token forgery. On apps you own or are authorized to test.
owasp-top-10
microsoft/hve-core
OWASP Top 10 for Web Applications (2025) knowledge base for identifying, assessing, and remediating web application security risks.
authentication-flow-rules
oimiragieo/agent-studio
OAuth 2.1 compliant authentication flows (MANDATORY Q2 2026). PKCE required for ALL clients, Implicit Flow removed, modern token security.
security-scan
openai/codex-security
Use for a standard, single-pass security audit of an entire repository or a scoped path, package, folder, or submodule with no diff to review. This is the default repository scan. Do not use for PR, commit, branch, or working-tree diffs, or for deep, multi-pass scans.
software-supply-chain-failures
scholarly360/owasp-top10-web-skills
>
security-logging-alerting-failures
scholarly360/owasp-top10-web-skills
>
software-data-integrity-failures
scholarly360/owasp-top10-web-skills
>
api-security-testing
mn-youssef/security-skills
Use when testing REST, GraphQL, gRPC, or WebSocket APIs against the OWASP API Security Top 10 — object- and function-level authorization (BOLA/BFLA), excessive data exposure, mass assignment, unrestricted resource consumption, and GraphQL-specific abuse. For apps you own or are authorized to test.
docker-security
pluginagentmarketplace/custom-plugin-docker
Secure Docker containers and images with hardening, scanning, and secrets management
triaging-security-findings
bitwarden/ai-plugins
This skill should be used when the user asks to "triage security findings", "fix a Checkmarx finding", "review SonarCloud results", "dismiss a false positive", "check code scanning alerts", or needs to work with GitHub Advanced Security alerts, scanner annotations on PRs, or Grype vulnerability results.
quickstart
databricks/app-templates
Set up Databricks agent development environment. Use when: (1) First time setup, (2) Configuring Databricks authentication, (3) User says 'quickstart', 'set up', 'authenticate', or 'configure databricks', (4) No .env file exists.
oma-image
gracefullight/stock-checker
Multi-vendor AI image generation with authentication-aware parallel dispatch. Routes to Codex (gpt-image-2 via ChatGPT OAuth), Antigravity (gemini-2.5-flash-image aka nano-banana via `agy` CLI + Gemini Code Assist), and Pollinations (flux/zimage, free with signup). Use for image generation, image creation, visual asset generation, and AI art.
pentest-gemini-sub-htb
crtvrffnrt/skills
Controlled lab skill for Hack The Box, CTF, and private lab workflows from reconnaissance, enumeration, vulnerability research, exploitation, foothold, and privilege escalation through evidence consolidation.
checking-owasp-compliance
jeremylongshore/claude-code-plugins-plus-skills
Check compliance with OWASP Top 10 security risks and best practices.
sinatra-security
geoffjay/claude-plugins
Security best practices for Sinatra applications including input validation, CSRF protection, and authentication patterns. Use when hardening applications or conducting security reviews.
security-audit
ansteorra/kmp
Performs static and dynamic security audits on KMP (SQL injection, XSS, auth, IDOR, headers, dependencies). Use for security review, penetration testing, or vulnerability assessment.
secrets-management-audit
mn-youssef/security-skills
Use when hunting for exposed secrets and auditing how an app you own manages them — API keys, tokens, passwords, and private keys in source, git history, binaries, logs, config, and CI; plus vaulting, rotation, and least-privilege of the secrets themselves.
api-security
hardw00t/ai-security-arsenal
Router skill for API penetration testing across REST, GraphQL, gRPC, and WebSocket. Covers OWASP API Top 10 (2023) including BOLA/BFLA/BOPLA, JWT attack chains, GraphQL introspection abuse, and mass assignment. Invoke when the user asks to pentest an API, analyze OpenAPI/Swagger, test auth/authorization, fuzz endpoints, or find API vulnerabilities.
building-secure-contracts
oimiragieo/agent-studio
Smart contract and secure API contract security analysis — invariant checking, access control, reentrancy, and integer overflow patterns. Implements Checks-Effects-Interactions pattern, formal invariant verification, and OpenSCV vulnerability taxonomy for Solidity/EVM and Rust/Solana contracts.
boxlang-security
ortus-boxlang/skills
Use this skill when reviewing BoxLang code or applications for security vulnerabilities, configuring security settings, preventing injection attacks, handling file uploads safely, managing secrets, or applying secure coding patterns drawn from OWASP Top 10 and CFML/Java security history.
codebase-cleanup-deps-audit
rmyndharis/antigravity-skills
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
secrets-management
rmyndharis/antigravity-skills
Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions. Use when handling sensitive credentials, rotating secrets, or securing CI/CD environments.
security-scanning-security-dependencies
rmyndharis/antigravity-skills
You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across ecosystems to identify vulnerabilities, assess risks, and recommend remediation.
multi-agentic-threat-model
owasp/secure-agent-playbook
Comprehensive threat modeling for multi-agent systems using CSA MAESTRO 7-layer framework and OWASP Multi-Agentic System Threat Modeling Guide v1.0. Systematically analyzes threats across all architectural layers from foundation models to agent ecosystems.
ai-security-verification
owasp/secure-agent-playbook
Comprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework. Provides structured checklist to verify security and ethical considerations across 13 categories of AI-driven applications, from training data governance to human oversight.
walrus-data-security
mystenlabs/walrus-skills
>
swift-dependencies
nonameplum/agent-skills
A dependency management library for Swift with controlled, testable dependencies
dv-connect
microsoft/dataverse-skills
One-step setup for a Dataverse environment — installs tools, authenticates, registers the MCP server, and writes `.env`. Use when starting a new project, switching environments, fixing authentication, or troubleshooting an MCP connection that won't come up.
propose-security-hardening
openai/codex-security
Develop evidence-backed structural and architectural security hardening proposals from vulnerability disclosures, supplied findings, incident or assessment documents, source code, or a completed Codex Security scan. Use when a user asks for systemic improvements, alternatives beyond per-finding patches, before-and-after security architecture views, engineering tradeoff analysis, or an implementation-ready plan for a selected hardening option. Also use automatically after a Codex Security scan with reportable findings when the top-level scan workflow requests final-report hardening guidance.
firebase-auth-internal-app
tanabee/skills
Integrate Firebase Auth (authentication + domain restriction) into internal applications. Includes domain restriction via Blocking Functions and user registration to Firestore.
encrypt-decrypt-backup
b-open-io/bsv-skills
This skill should be used when the user asks to "encrypt backup", "decrypt .bep file", "bitcoin-backup CLI", "backup wallet", "Touch ID password cache", "upgrade backup iterations", or needs to encrypt/decrypt BSV backup files using the bbackup CLI.
using-firebase
spillwavesolutions/using-firebase
Comprehensive Firebase development guidance for GCP-hosted applications. Covers Firestore database operations (CRUD, queries, transactions, data modeling), Cloud Functions (1st and 2nd generation, TypeScript and Python, all trigger types), Firebase CLI operations, emulator setup and data persistence, security rules (Firestore and Storage), authentication integration, hosting configuration, and GCP service integration. Use when working with Firebase projects, deploying Cloud Functions, querying Firestore, setting up triggers (Firestore, Auth, Storage, HTTP, Callable, Scheduled, Pub/Sub), managing security rules, configuring hosting rewrites/headers, managing secrets, or integrating with GCP services like BigQuery and Cloud Tasks. Triggers include firebase, firestore, cloud functions, firebase functions, firebase hosting, firebase auth, firebase storage, firebase emulator, firebase deploy, firebase init, firebase rules, callable function, scheduled function, onDocumentCreated, onRequest, onCall, onSchedule.