1,051 free skills
Security skills
Skills for security — code auditing, penetration testing, secrets management, encryption, and dependency vulnerability scanning.
Sourced from real, public repositories — synced daily, never invented.
1,051 free skills
Skills for security — code auditing, penetration testing, secrets management, encryption, and dependency vulnerability scanning.
Sourced from real, public repositories — synced daily, never invented.
15 tools across six categories
13 of them never send your data anywhere
Free · No signup · No trial clock
SEE THE DIRECTORY

fhenix-encrypted-arithmetic
nickthelegend/fhenix-skills
Encrypted math on euint8..128 — add, sub, mul, div, rem, square. Covers unchecked wrap-around (no overflow revert, by design), the div/rem-by-zero behavior, same-type operand rule, and direct-call vs library-binding syntax.
fix-security-vulnerability
getsentry/sentry-changelog
Analyze and propose fixes for Dependabot security alerts
dependency-vuln-report
razbakov/skills
Runs dependency vulnerability scans and produces a complete report with exact installed versions, reason for risk, and remediation priority for each finding. Use when the user asks for dependency scan, npm audit, bun audit, package vulnerabilities, CVE review, or security status of dependencies.
vulnerability-management
0motionguy/gicm
Dependency scanning, CVE tracking, patch management, and security posture measurement.
vulnerability-intelligence
liberty91ltd/cti-skills
Use when prioritising CVEs, the user asks "should we patch X first?" / "is CVE-YYYY-NNNNN being exploited?", or wants weaponisation, EPSS, and KEV context combined into a patch-now-vs-later recommendation.
dependency-auditor
fernandogarzaaa/project-aether
Dependency Auditor
security-scanning-security-dependencies
atilamedeiros/skills
You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across ecosystems to identify vulnerabilities, assess risks, and recommend remediation.
dependabot-check
erp-core-dev/eagles-ai-platform
Check and update vulnerable dependencies
owasp
jcchikikomori/skills-md
OWASP Top 10:2025 security risks (A01-A10), input handling, auth, output encoding, and a secure coding checklist. Use when reviewing code for security or running a security audit.
owasp-secure-code
cincinnati-associates/infosec-claude-skills
>
security-authentication
fatonh/symfony-skills
>
authentication
abanoub-ashraf/manus-skills-import
Implement iOS authentication patterns including Sign in with Apple (ASAuthorizationAppleIDProvider, ASAuthorizationController, ASAuthorizationAppleIDCredential), credential state checking, identity token validation, ASWebAuthenticationSession for OAuth and third-party auth flows, ASAuthorizationPasswordProvider for AutoFill credential suggestions, and biometric authentication with LAContext. Use when implementing Sign in with Apple, handling Apple ID credentials, building OAuth login flows, integrating Password AutoFill, checking credential revocation state, or validating identity tokens server-side.
authentication
acumenrev/ios-agent-skills
Implement iOS authentication patterns including Sign in with Apple (ASAuthorizationAppleIDProvider, ASAuthorizationController, ASAuthorizationAppleIDCredential), credential state checking, identity token validation, ASWebAuthenticationSession for OAuth and third-party auth flows, ASAuthorizationPasswordProvider for AutoFill credential suggestions, and biometric authentication with LAContext. Use when implementing Sign in with Apple, handling Apple ID credentials, building OAuth login flows, integrating Password AutoFill, checking credential revocation state, or validating identity tokens server-side.
security-audit
krishnakanthb13/antigravity-awesome-skills
Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.
authentication
joabgonzalez/ai-agents-skills
Auth patterns: password hashing, JWT, sessions, and OAuth. Trigger: When implementing login, registration, token handling, or OAuth flows.
security-audit
tmolavi/mcp-agent-skills-hub
Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.
authentication
tyroneross/build-loop
Use when wiring auth to a new project, debugging login errors (redirect_uri_mismatch, invalid_grant, session callback, refresh_token), or adding social/magic link flows. Covers Better Auth (Drizzle/Neon), Supabase Auth (SSR), Google OAuth, and Resend transactional email.
authentication
wh4l3x/claude-code-pentest-arsenal
Authentication security testing - auth bypass, JWT attacks, OAuth flaws, password attacks, 2FA bypass, CAPTCHA bypass, and bot detection evasion.
backend-security-coder
afnanpvt/ai-agent-skills
Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.
api-security-testing
tmolavi/mcp-agent-skills-hub
API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.
conducting-api-security-testing
razor25000/cybersecurityskills
Conducts security testing of REST, GraphQL, and gRPC APIs to identify
API Tester
53able/agency-agents
Expert API testing specialist focused on comprehensive API validation, performance testing, and quality assurance across all systems and third-party integrations
api-security
roodlicht/accans-sec-skills
API security review against OWASP API Top 10 2023. Covers auth (OAuth2/JWT/API-keys), object-level authorization (BOLA/IDOR), schema validation, rate-limiting, CORS, SSRF, and GraphQL-specific concerns (introspection, query depth, batching).
testing-api-tester
itzfaisal/agency-agents
Expert API testing specialist focused on comprehensive API validation, performance testing, and quality assurance across all systems and third-party integrations
api-tester
elihuvillaraus/skills
Expert API testing specialist focused on comprehensive API validation, performance testing, and quality assurance across all systems and third-party integrations. Breaks your API before your users do. Activar cuando se necesite un API Tester en el equipo o pipeline.
api-security
wh4l3x/claude-code-pentest-arsenal
API security testing - GraphQL, REST API, WebSocket, and Web-LLM attack techniques.
backend-security-coder
tmolavi/mcp-agent-skills-hub
Expert in secure backend coding practices specializing in input
devops
docaohieu2808/claude-skills
Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm). Use for serverless, containers, CI/CD, GitOps, security audit.
external-dns
julianobarbosa/tiger-900
Comprehensive guide for configuring, troubleshooting, and implementing External-DNS across Azure DNS, AWS Route53, Cloudflare, and Google Cloud DNS. Use when implementing automatic DNS management in Kubernetes, configuring provider-specific authentication (managed identities, IRSA, API tokens), troubleshooting DNS synchronization issues, setting up secure production-grade external-dns deployments, optimizing performance, avoiding rate limits, or implementing GitOps patterns with ArgoCD.
azure-messaging
microsoft/skills
Troubleshoot and resolve issues with Azure Messaging SDKs for Event Hubs and Service Bus. Covers connection failures, authentication errors, message processing issues, and SDK configuration problems. WHEN: event hub SDK error, service bus SDK issue, messaging connection failure, AMQP error, event processor host issue, message lock lost, message lock expired, lock renewal, lock renewal batch, send timeout, receiver disconnected, SDK troubleshooting, azure messaging SDK, event hub consumer, service bus queue issue, topic subscription error, enable logging event hub, service bus logging, eventhub python, servicebus java, eventhub javascript, servicebus dotnet, event hub checkpoint, event hub not receiving messages, service bus dead letter, batch processing lock, session lock expired, idle timeout, connection inactive, link detach, slow reconnect, session error, duplicate events, offset reset, receive batch.
microsoft-azure-webjobs-extensions-authentication-events-dotnet
microsoft/skills
Microsoft Entra Authentication Events SDK for .NET. Azure Functions triggers for custom authentication extensions. Use for token enrichment, custom claims, attribute collection, and OTP customization in Entra ID. Triggers: "Authentication Events", "WebJobsAuthenticationEventsTrigger", "OnTokenIssuanceStart", "OnAttributeCollectionStart", "custom claims", "token enrichment", "Entra custom extension", "authentication extension".
azure-identity-ts
microsoft/skills
Authenticate to Azure services using Azure Identity library for JavaScript (@azure/identity). Use when configuring authentication with DefaultAzureCredential, managed identity, service principals, or interactive browser login.
search-company-knowledge
openai/plugins
Search across company knowledge bases (Confluence, Jira, internal docs) to find and explain internal concepts, processes, and technical details. When an agent needs to: (1) Find or search for information about systems, terminology, processes, deployment, authentication, infrastructure, architecture, or technical concepts, (2) Search internal documentation, knowledge base, company docs, or our docs, (3) Explain what something is, how it works, or look up information, or (4) Synthesize information from multiple sources. Searches in parallel and provides cited answers.
3gpp-portal-authentication
jr2804/prompts
EOL authentication, AJAX login patterns, 3GPP portal data fetching, and session management. Use when accessing protected 3GPP portal resources that require EOL login, fetching TDoc metadata, or working with 3GPP portal APIs.
aurakit
rohitg00/buildwithclaude
Sonnet Amplified fullstack engine. 34 modes, SEC-01~15 OWASP security, 13 runtime hooks, 75% token reduction. Install: npx @smorky85/aurakit
auth-patterns
rohitg00/buildwithclaude
This skill should be used when the user asks about "authentication in Next.js", "NextAuth", "Auth.js", "middleware auth", "protected routes", "session management", "JWT", "login flow", or needs guidance on implementing authentication and authorization in Next.js applications.
npm-research
ofershap/mcp-server-npm-plus
Research npm packages with bundle size, vulnerability scanning, and download trends via MCP. Use when comparing or auditing packages.
auth
oakoss/open-saas-kit
Better Auth authentication. Use for auth, login, logout, session, user, signup, register, protect, middleware, password, oauth, social
reverse-engineering
tangjunyi23/iotagent
Binary reverse engineering and code analysis for IoT firmware using Ghidra and Joern. Use when performing binary analysis with Ghidra headless mode (decompiling, cross-references, imports, dangerous calls), CPG-based vulnerability hunting with Joern (taint analysis, data flow tracking, pattern matching), or any reverse engineering task on ARM/MIPS/x86 embedded binaries. Triggers on tasks requiring decompilation, interprocedural analysis, or static vulnerability scanning of firmware binaries.
php
jcchikikomori/skills-md
PHP coding standards following PSR, strict types, OWASP security principles, and team coding conventions.
gdpr-dev
devcoder-re/dev-skills
GDPR compliance for European developers. Use when building features that handle personal data: user registration, profiles, authentication, email sending, analytics, error tracking, payments, search indexes, background jobs, or any feature that stores, processes, or transmits information about people. Provides stack-aware gotchas, anti-patterns to avoid, and schema design principles. Does not ask questions — applies principles proactively based on what is being built.
byteplus-cloud
straits-ai/byteplus-cloud-skill
Plan, provision, deploy, inspect, and troubleshoot applications on BytePlus using the official bp CLI, BytePlus Cloud Control Terraform provider, Edge Functions nest CLI/MCP, and product SDKs. Use for BytePlus architecture selection, authentication, infrastructure changes, application deployment, ModelArk Seed/Seedream/Seedance, Seed Speech TTS, TOS, ECS, VPC, VKE, veFaaS, API Gateway, databases, monitoring, or migration work.
slack-connector-functions
leaveanest/slack-utils
Use when building or modifying Slack Deno SDK workflows in this repository and the user asks to integrate an external SaaS, create/update/read records in another tool, send external email/SMS, schedule meetings, manage issues/tasks/incidents, or avoid implementing OAuth/API authentication by using Slack Platform connector functions.
django-expert
sufficientdaikon/archon
Expert-level Django development for robust Python web applications with ORM, admin, and authentication
django-drf-scaffold
kiro-kenya/kiro-resources
Scaffold or improve a secure, production-oriented Django and Django REST Framework backend. Use when creating a Django project, starting a DRF API, configuring a custom user model, adding Djoser or Simple JWT authentication, defining authorization, setting up multi-tenancy, or establishing maintainable Django backend architecture and tests.
flask-auth-security
jcorpac/ai-skills-library
Implementing professional session-based and token-based authentication.
flask-security-hardening
mohamed-adel222/teamify
Implement security, audit logging, payload/file encryption, hashing-based integrity, and login anomaly detection in a Flask + SQLAlchemy backend. Use when the user asks to add LoginLog, admin audit endpoints, Fernet encryption for messages/comments, secure file upload/download with SHA-256 verification, or anomaly/alerting on failed logins.
flask-api-development
underwater-ai/uwater_app
Develop lightweight Flask APIs with routing, blueprints, database integration, authentication, and request/response handling. Use when building RESTful APIs, microservices, or lightweight web services with Flask.
rails-auth
ssrjkk/claude-skills
Auth with Rails. authentication.
devops
mchien15/wrenai
Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm). Use for serverless, containers, CI/CD, GitOps, security audit.
devops
malibujack/claudekit-skills
Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm). Use for serverless, containers, CI/CD, GitOps, security audit.
gcp-cloudbuild
thomashartm/dev-claude-skills
Manage Google Cloud Build jobs and triggers. Use when the user wants to list Cloud Build triggers/jobs, view trigger details and configurations, check build history, monitor running builds, or start new builds. Handles authentication verification and project context. Triggers on phrases like "list cloud build jobs", "show build triggers", "build history", "running builds", "start build", "deploy with cloud build", "cloudbuild status".
auth-design
seancdavis/agent-skills
Personal conventions for auth on Netlify projects using Netlify Identity. Use when implementing user authentication, protecting routes/pages/functions, managing sessions, or gating access by safelist. Covers the three-tier access framework, the approved-users-table opinion (and why-not app_metadata.roles), the `getUserWithApproval` API shape, data scoping, and the Identity-doesn't-work-with-netlify-dev gotcha. The Identity SDK itself is covered by Netlify's netlify-identity skill.
devops-reliability-engineer
dbillion/harvestconnect
Expert DevOps reliability engineer specializing in Netlify deployment with GitHub Actions, Koyeb backend deployment with environment integration, and connecting frontend to backend through proper configuration and secrets management.
firebase
igunublue/awesome-ai-skills
Firebase gives you a complete backend in minutes - auth, database, storage, functions, hosting. But the ease of setup hides real complexity. Security rules are your last line of defense, and they're often wrong. Firestore queries are limited, and you learn this after you've designed your data model. This skill covers Firebase Authentication, Firestore, Realtime Database, Cloud Functions, Cloud Storage, and Firebase Hosting. Key insight: Firebase is optimized for read-heavy, denormalized data. I
firebase-buddy
i-onlabs/claude-code-skills
Firebase patterns and troubleshooting for vibecoders. Use when user mentions Firebase, Firestore, Firebase Auth, Firebase hosting, security rules, or is working on projects using Firebase backend. Also use for errors like "permission denied", "missing index", or authentication issues in Firebase projects.
firebase
andrewhaward2310/.agents
Firebase gives you a complete backend in minutes - auth, database, storage, functions, hosting. But the ease of setup hides real complexity. Security rules are your last line of defense, and they're often wrong. Firestore queries are limited, and you learn this after you've designed your data model. This skill covers Firebase Authentication, Firestore, Realtime Database, Cloud Functions, Cloud Storage, and Firebase Hosting. Key insight: Firebase is optimized for read-heavy, denormalized data. I
firebase-security-expert
roedyrustam/vibes-plug
Firebase security expert to audit Security Rules (Firestore/Realtime Database/Storage), authentication, API keys, data leakage prevention, and App Check configuration / Ahli keamanan Firebase untuk audit Security Rules (Firestore/Realtime Database/Storage), autentikasi, API keys, pencegahan kebocoran data, dan konfigurasi App Check.
firebase-auth-basics
ionmidori/sydbioedilizia
Guide for setting up and using Firebase Authentication. Use this skill when the user's app requires user sign-in, user management, or secure data access using auth rules.
firebase
googyosoo/antigravity-skills
Firebase gives you a complete backend in minutes - auth, database, storage, functions, hosting. But the ease of setup hides real complexity. Security rules are your last line of defense, and they're often wrong. Firestore queries are limited, and you learn this after you've designed your data model. This skill covers Firebase Authentication, Firestore, Realtime Database, Cloud Functions, Cloud Storage, and Firebase Hosting. Key insight: Firebase is optimized for read-heavy, denormalized data. I