1,051 free skills
Security skills
Skills for security — code auditing, penetration testing, secrets management, encryption, and dependency vulnerability scanning.
Sourced from real, public repositories — synced daily, never invented.
1,051 free skills
Skills for security — code auditing, penetration testing, secrets management, encryption, and dependency vulnerability scanning.
Sourced from real, public repositories — synced daily, never invented.
15 tools across six categories
13 of them never send your data anywhere
Free · No signup · No trial clock
SEE THE DIRECTORY

privacy-by-design-rails
codeminer42/skills
Use when building Rails features that handle personal data, adding encryption to models, implementing consent flows, building DSAR endpoints, or adding anonymization/pseudonymization. Also use when reviewing code for compliance with privacy laws like GDPR and LGPD, or when asked about privacy-by-design patterns in Rails.
smart-contract-audit
forefy/.context
Comprehensive smart contract security audit framework with multi-expert analysis. Use for full audits of Ethereum / EVM Solidity and Vyper, Solana / SVM Anchor Rust, TON / FunC / Tact, or Sui / Move projects.
create-secret
harness/harness-skills
>-
authentication
cheehoolabs/spureeskills
Obtain and refresh JWT access tokens, and manage API keys for the Spuree V1 API
owasp-agentic
microsoft/hve-core
OWASP Agentic Security Top 10 knowledge base for identifying, assessing, and remediating AI agent system security risks.
ck:devops
binjuhor/shadcn-lar
Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm). Use for serverless, containers, CI/CD, GitOps, security audit.
dependency-management-deps-audit
rmyndharis/antigravity-skills
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
neon-js-react
neondatabase/neon-js
Sets up the full Neon SDK with authentication AND database queries in React apps (Vite, CRA). Creates typed client, generates database types, and configures auth UI. Use for auth + database integration.
auth-patterns
yonatangross/orchestkit
Authentication and authorization patterns. Use when implementing login flows, JWT tokens, session management, password security, OAuth 2.1, Passkeys/WebAuthn, or role-based access control.
config-encryption-auditor
archieindian/openclaw-superpowers
Scans OpenClaw config directories for plaintext API keys, tokens, and secrets in unencrypted files — flags exposure risks and suggests encryption or environment variable migration.
wallet-encrypt-decrypt
b-open-io/bsv-skills
This skill should be used when the user asks to "encrypt message with BSV key", "decrypt with private key", "ECDH encryption", "AES-256-GCM BSV", "EncryptedMessage", "BRC-2 encryption", or needs to encrypt/decrypt data using BSV keys and @bsv/sdk.
studio-cli
automattic/studio
Use the Studio CLI to manage local WordPress sites, authentication, and preview sites. Invoke this skill when you need to run Studio CLI commands, manage sites, or troubleshoot site issues.
neon-auth-react
neondatabase/neon-js
Sets up Neon Auth in React applications (Vite, CRA). Configures authentication adapters, creates auth client, and sets up UI components. Use when adding auth-only to React apps (no database needed).
security-review
dedalus-erp-pas/hexagone-foundation-skills
Audit de sécurité couvrant l'authentification, l'injection SQL, l'exposition de secrets, le CSRF et les vulnérabilités du Top 10 OWASP.
gemini-auth
adaptationio/skrillz
Setup and manage Gemini CLI authentication methods including OAuth, API keys, and Vertex AI. Use when configuring Gemini access, switching auth methods, or troubleshooting authentication issues.
aliyun-fc-serverless-devs-test
cinience/alicloud-skills
Smoke test for aliyun-fc-serverless-devs. Validate minimal authentication, API reachability, and one read-only query path.
aliyun-fc-agentrun-test
cinience/alicloud-skills
Smoke test for aliyun-fc-agentrun. Validate minimal authentication, API reachability, and one read-only query path.
owasp-llm
microsoft/hve-core
OWASP Top 10 for LLM Applications (2025) knowledge base for identifying, assessing, and remediating large language model security risks.
gemini-cli
biggora/claude-plugins-registry
Use this skill whenever the user wants to install, configure, or use the Gemini CLI (gemini-cli) tool. Trigger this skill for tasks such as: installing gemini-cli via npm/npx/brew, setting up authentication (API key, Google OAuth, Vertex AI), running non-interactive/headless prompts with -p flag, configuring settings.json, creating GEMINI.md context files, writing custom slash commands (.toml files), connecting MCP servers, creating extensions, automating tasks with shell scripts, using --output-format json/stream-json, managing chat sessions, using /memory commands, --auto-approve mode, Application Default Credentials (ADC), or any scripting/automation involving gemini-cli. Also trigger when user asks about integrating Gemini models into CLI workflows, CI/CD pipelines, or programmatic use of the Gemini API through the CLI tool.
implementing-homomorphic-encryption
mukul975/privacy-data-protection-skills
>-
security-auth
ajianaz/skills-collection
Comprehensive security and authentication workflow that orchestrates security architecture, identity management, access control, and compliance implementation. Handles everything from authentication system design and authorization frameworks to security auditing and threat protection.
security-auditor
dralgorhythm/claude-agentic-framework
Assess vulnerabilities and audit for security compliance using OWASP and STRIDE methodology — a user-invoked Security Auditor workflow.
authentication
sailscastshq/boring-stack
>
network-pentest
hardw00t/ai-security-arsenal
Internal network and Active Directory penetration testing skill for corporate environments. Use when performing authorized internal network assessments, AD attack path analysis, lateral movement, privilege escalation, and post-exploitation across Windows/Linux estates. Covers BloodHound, Impacket, NetExec/CrackMapExec, Responder, Rubeus, mimikatz, certipy. Triggers on requests to pentest internal networks, attack AD, perform lateral movement, Kerberoast, DCSync, or escalate privileges.
owasp-review
archive228/loopkit
Security-review a diff against the OWASP Top 10. Use before merging anything that touches auth, input handling, queries, or external calls.
owasp-mcp
microsoft/hve-core
OWASP MCP Top 10 knowledge base for identifying, assessing, and remediating Model Context Protocol security risks.
owasp-cicd
microsoft/hve-core
OWASP CI/CD Top 10 knowledge base for identifying, assessing, and remediating CI/CD pipeline security risks.
elasticsearch-expert
erni/agent-skills
Use this skill when working with Elasticsearch in any capacity — designing index mappings, writing or optimizing queries (Query DSL, ES|QL, KQL), planning cluster architecture, configuring ingest pipelines, tuning performance, troubleshooting cluster health, implementing search features, or building AI-powered search with retrievers. Also activate for Elasticsearch security tasks — authentication, RBAC, API key management, audit logging, DLS/FLS, or security troubleshooting. Activate whenever the user mentions Elasticsearch, OpenSearch, Elastic Stack, Kibana queries, Lucene-based search, vector/semantic/hybrid search with Elasticsearch, retrievers, LogsDB, TSDB, Elasticsearch Serverless, ES|QL CATEGORIZE/CHANGE_POINT, or any index/shard/mapping/analyzer/security topic.
privacy-reviewer
majesticlabs-dev/majestic-marketplace
Review PII handling, encryption, and GDPR/CCPA compliance in Rails applications.
backend-dev
ajianaz/skills-collection
Comprehensive backend development workflow that orchestrates expert analysis, architecture design, implementation, and deployment using the integrated toolset. Handles everything from API design and database architecture to security implementation and DevOps automation.
owasp-infrastructure
microsoft/hve-core
OWASP Infrastructure Top 10 knowledge base for identifying, assessing, and remediating internal IT infrastructure security risks.
dotnet-core-expert
alexander-danilenko/cortex-ai-skills
Use when building .NET 8 applications with minimal APIs, clean architecture, or cloud-native microservices. Invoke for Entity Framework Core, CQRS with MediatR, JWT authentication, AOT compilation.
wiring-audit
nickcrew/claude-cortex
User-triggered audit that finds wiring drift between a project's UI surfaces and backend capabilities — orphan surfaces (UI calls endpoints/hooks/procedures that no longer exist), unwired capabilities (backend routes/exports that nothing surfaces), shape drift (both exist but contracts mismatch), method drift (URL matches, HTTP verb does not), validation drift (frontend vs backend rules diverged), permission drift (UI exposes what backend forbids or vice versa), stale labels (UI text references renamed backend concepts), and unsurfaced configuration (env vars or flags that gate behavior with no UI or CLI to control them). This skill should be used when the user asks to "audit our wiring," "find UI/backend drift," "find unwired capabilities," "find stale surfaces," "check for contract violations," "find unused endpoints," "find unused hooks," "what mismatches between UI and backend," or any similar request whose deliverable is a prioritized findings report rather than a descriptive snapshot. Generic across UI frameworks but optimized for React applications (hooks, fetch, react-query, SWR, tRPC, server actions, react-router, Next.js). Not for descriptive architectural snapshots (use architectural-analysis), security audits (use security-auditor), or performance audits (use the performance-optimization skills).
implementing-saaskit-python
scalekit-inc/authstack
Implements Scalekit SaaSKit authentication in Python web frameworks (Django, FastAPI, or Flask) using scalekit-sdk-python. Use when adding auth to a Django, FastAPI, or Flask project, or when the user mentions Python web authentication with Scalekit.
OAuth2
oriolrius/pki-manager-web
Expert guidance for OAuth 2.0 protocol including authorization flows, grant types, token management, OpenID Connect, security best practices, and implementation patterns. Use this when implementing authentication/authorization, working with OAuth providers, securing APIs, or integrating with third-party services.
crypto-audit
kalshamsi/claude-security-skills
Use when reviewing code for weak encryption, hardcoded cryptographic keys, insecure TLS/SSL configuration, broken hashing, bad randomness, or any cryptographic implementation concern — regardless of language.
secure-code-guardian
alexander-danilenko/cortex-ai-skills
Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities. Invoke for authentication, authorization, input validation, encryption, OWASP Top 10 prevention.
mcp-oauth-setup
majesticlabs-dev/majestic-marketplace
Implement MCP server authentication with OAuth Dynamic Client Registration (RFC 7591), Authorization Server Metadata Discovery (RFC 8414), and per-agent credential support. Use when building admin UIs that let users connect to third-party MCP servers using OAuth (Linear, Sentry, Granola), bearer tokens (Render, custom APIs), or API keys. Covers metadata discovery, client registration, PKCE authorization, token exchange, token refresh, tool sync, and credential storage patterns.
stash-encryption
cipherstash/stack
Implement field-level encryption with @cipherstash/stack using the EQL v3 typed schema. Covers the types.* column catalog, the generic EncryptionClient, encrypt/decrypt and model operations, searchable encryption, encrypted JSON, bulk operations, identity-aware encryption, multi-tenant keysets, and the rollout/cutover lifecycle.
owasp-docker
microsoft/hve-core
OWASP Docker Top 6 knowledge base for identifying, assessing, and remediating Docker container security risks.
atmos-terraform
cloudposse/atmos
Terraform and OpenTofu orchestration: plan/apply/deploy, workspace management, backend config, varfile generation, authentication, binary selection (terraform/tofu), mixed-binary setups
weak-encryption-anti-pattern
igbuend/grimbard
Security anti-pattern for weak encryption (CWE-326, CWE-327). Use when generating or reviewing code that encrypts data, handles encryption keys, or uses cryptographic modes. Detects DES, ECB mode, static IVs, and custom crypto implementations.
vuln-research
lu1sdv/skillsmd
>
fix-security-vulnerability
getsentry/sentry-javascript
Analyze and propose fixes for Dependabot security alerts
dependency-vuln-triager
sisodiabhumca/agent-skills
Use to triage dependency vulnerability scanner output (npm audit, pip-audit, OSV, GitHub advisories) and produce a ranked, deduplicated action list. Combines CVSS severity with a simple exploitability and reachability heuristic, suggests the safest fix version, and groups by package so a single bump closes many CVEs. Vendor-neutral — works on any JSON SBOM-like input.
moai-ref-owasp-checklist
modu-ai/moai-adk
>
lgpd-encryption-keys
goul4rt/lgpd-skills
Configure encryption at rest, in transit, and key management aligned with LGPD Art. 46 (security duty) and the ANPD's Guia de Segurança da Informação para ATPP. Use when user asks 'criptografia LGPD', 'KMS', 'TDE', 'encryption at rest', 'rotação de chaves', 'pgcrypto', 'column-level encryption'. Tailored for Prisma/PostgreSQL/Better Auth stack.
stash-supabase
cipherstash/stack
Integrate CipherStash encryption with Supabase using @cipherstash/stack-supabase. Covers the encryptedSupabase wrapper over native EQL v3 column domains, transparent encryption/decryption on insert/update/select, encrypted scalar filters (eq, gt/gte/lt/lte, in, or), ordering on encrypted columns, EQL 3.0.5 PostgREST query-domain limitations, identity-aware encryption, and the complete query builder API. Use when adding encryption to a Supabase project, querying encrypted columns, or building secure Supabase applications.
exempt-vuln
harness/harness-skills
>-
api-security
goldenwing-360/claude-security-skills
Apply the OWASP API Security Top 10 to REST and GraphQL endpoints. Covers broken object-level authorization (BOLA), mass assignment, excessive data exposure, unrestricted resource consumption, SSRF, broken function-level authorization, and GraphQL depth and complexity limits. Invoke when designing a new API, reviewing one before scaling, or after API abuse (scraping, account takeover).
django-allauth
codeatcode/oss-ai-skills
Django authentication - local accounts, social OAuth, registration, email verification, MFA, session management
api-baas-firebase
agents-inc/skills
Firebase backend-as-a-service — Firestore, Authentication, Cloud Functions v2, Storage, Hosting, Admin SDK, security rules, emulator suite
owasp-check
manastalukdar/ai-devstudio
OWASP Top 10 vulnerability scanning and remediation
fhevm-encrypted-inputs
z-korp/fhevm-cookbook
Use when implementing or reviewing how encrypted user inputs enter FHEVM contracts. Covers client-side encryption, FHE.fromExternal, inputProof binding, and the distinction between external ciphertexts and onchain handles.
spice-secrets
spiceai/skills
Configure secret stores in Spice — environment variables, Kubernetes, AWS Secrets Manager, Azure Key Vault, HashiCorp Vault, and OS keyring. Use this skill whenever the user needs to manage credentials, API keys, passwords, or tokens in Spice, reference secrets in spicepod.yaml params with ${ store:KEY } syntax, set up .env files, configure secret store precedence, or understand how the `secrets:` section works. Also use when the user asks how to pass database passwords or API keys securely to Spice datasets or models.
fhevm-control-flow
z-korp/fhevm-cookbook
Use when replacing if/else, require, or any conditional logic that depends on encrypted values in FHEVM. Covers FHE.select as the inline branching primitive, fallback semantics on encrypted conditions, and async public decryption when logic must branch back to plaintext state.
authentication-pattern
igbuend/grimbard
Security pattern for implementing authentication in software systems. Use when designing or reviewing authentication mechanisms, implementing login systems, verifying user identity, protecting system access, or addressing OWASP authentication flaws. Provides guidance on enforcers, verifiers, evidence providers, subject registration, credential management, and security considerations.
secure-api
mulesoft/mulesoft-dx
|
k8s-security
rohitg00/kubectl-mcp-server
Audit Kubernetes RBAC, enforce policies, and manage secrets. Use for security reviews, permission audits, policy enforcement with Kyverno/Gatekeeper, and secret management.
requesting-gcloud-bq-auth
syou6162/agent-skills
gcloudやbqコマンド実行時に認証エラー(Reauthentication required等)を検出した場合に使用。エージェントが自動で認証コマンドを実行することを防ぎ、ユーザーに認証を依頼します。