1,051 free skills
Security skills
Skills for security — code auditing, penetration testing, secrets management, encryption, and dependency vulnerability scanning.
Sourced from real, public repositories — synced daily, never invented.
1,051 free skills
Skills for security — code auditing, penetration testing, secrets management, encryption, and dependency vulnerability scanning.
Sourced from real, public repositories — synced daily, never invented.
15 tools across six categories
13 of them never send your data anywhere
Free · No signup · No trial clock
SEE THE DIRECTORY

secure-auth
jamditis/claude-skills-journalism
Secure authentication patterns (OWASP, NIST). Use for login, registration, password reset, sessions, JWT, OAuth, MFA, passkeys.
security-hardening
rohitg00/awesome-claude-code-toolkit
Application security covering input validation, auth, headers, secrets management, and dependency auditing
codeql-expert
personamanagmentlayer/pcl
Expert-level CodeQL for static analysis, vulnerability detection, and security code scanning
openrouter-oauth
openrouterteam/skills
Implement "Sign In with OpenRouter" using OAuth PKCE — framework-agnostic, no SDK or client registration required. Use when the user wants to add OpenRouter login, authentication, sign-in buttons, OAuth, or AI model inference API keys for browser-based apps. No client registration, no backend, no secrets required.
performing-sca-dependency-scanning-with-snyk
mukul975/anthropic-cybersecurity-skills
This skill covers implementing Software Composition Analysis (SCA) using
building-vulnerability-aging-and-sla-tracking
mukul975/anthropic-cybersecurity-skills
Implement a vulnerability aging dashboard and SLA tracking system that measures time-to-remediation against severity-based deadlines (e.g. 14 days critical, 30 days high, 60 days medium, 90 days low), with automated escalations and compliance metrics reporting. Use when designing SLA policies, building aging/remediation dashboards, or proving compliance with remediation timelines.
django-expert
personamanagmentlayer/pcl
Expert-level Django development for robust Python web applications with ORM, admin, and authentication
1password
julianobarbosa/claude-code-skills
Guide for implementing 1Password secrets management - CLI operations, service accounts, Developer Environments, and Kubernetes integration. Use when retrieving secrets, managing vaults, configuring CI/CD pipelines, integrating with External Secrets Operator, managing Developer Environments, or automating secrets workflows with 1Password.
oauth-oidc-implementer
curiositech/some_claude_skills
Expert in implementing OAuth 2.0 and OpenID Connect (OIDC) authentication flows. Specializes in secure token handling, social login integration, API authorization, and identity provider configuration.
security-audit
s-hiraoku/synapse-a2a
>-
authentication-patterns
rohitg00/awesome-claude-code-toolkit
Authentication and authorization patterns including OAuth2, JWT, RBAC, session management, and PKCE flows
auditing-mcp-servers-for-tool-poisoning
mukul975/anthropic-cybersecurity-skills
Audit MCP servers for tool poisoning, tool shadowing, rug pulls, SSRF, and unauthenticated exposure using Invariant Labs' mcp-scan for static/runtime scanning plus manual SSRF/auth checks and description pinning. Use before adding a new MCP server to an agent stack, when reviewing an internal MCP server, detecting rug pulls, or investigating an agent's unexpected tool-driven behavior.
engineering-mobile-app-builder
peterhdd/agent-skills
Build native and cross-platform mobile applications for iOS and Android with optimized performance and platform integration. Use when you need SwiftUI or Jetpack Compose development, React Native or Flutter cross-platform apps, offline-first architecture, biometric authentication, push notifications, deep linking, app startup optimization, or mobile-specific UX patterns and gesture handling.
alicloud-network-cdn-test
cinience/alicloud-skills
Smoke test for alicloud-network-cdn. Validate minimal authentication, API reachability, and one read-only query path.
security-audit
decebals/claude-code-java
Java security checklist covering OWASP Top 10, input validation, injection prevention, and secure coding. Works with Spring, Quarkus, Jakarta EE, and plain Java. Use when reviewing code security, before releases, or when user asks about vulnerabilities.
alicloud-data-analytics-dataanalysisgbi-test
cinience/alicloud-skills
Smoke test for alicloud-data-analytics-dataanalysisgbi. Validate minimal authentication, API reachability, and one read-only query path.
alicloud-compute-fc-agentrun-test
cinience/alicloud-skills
Smoke test for alicloud-compute-fc-agentrun. Validate minimal authentication, API reachability, and one read-only query path.
auditing-python-security
wdm0006/python-skills
Audits Python libraries for security vulnerabilities using Bandit, pip-audit, Semgrep, and detect-secrets. Identifies SQL injection, command injection, hardcoded credentials, secrets exposed through tracebacks, weak cryptography, and insecure deserialization. Use when reviewing library security, setting up security scanning in CI, or implementing secure coding patterns.
supabase-evidence
yoanbernabeu/supabase-pentest-skills
Initialize and manage the evidence collection directory for professional security audits with documented proof of findings.
detecting-broken-object-property-level-authorization
mukul975/anthropic-cybersecurity-skills
Detect and test for OWASP API3:2023 Broken Object Property Level Authorization
alicloud-compute-fc-serverless-devs-test
cinience/alicloud-skills
Smoke test for alicloud-compute-fc-serverless-devs. Validate minimal authentication, API reachability, and one read-only query path.
building-identity-federation-with-saml-azure-ad
mukul975/anthropic-cybersecurity-skills
Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync, pass-through auth, third-party IdP) and the SAML authentication flow. Use when extending on-premises authentication authority to cloud resources or designing hybrid identity SSO architecture for Entra ID.
alicloud-backup-bdrc-test
cinience/alicloud-skills
Smoke test for alicloud-backup-bdrc. Validate minimal authentication, API reachability, and one read-only query path.
sgds-templates
govtechsg/sgds-web-component
Complete ready-to-use page templates built with SGDS components and utilities. Use this skill whenever a user asks to build a page, dashboard, login page, form page, settings page, list page, or any full-page UI — even if they don't say 'template'. Apply when starting a new app, building internal tools, dashboards, admin portals, authentication flows, or data table views.
fastmcp-server
davila7/claude-code-templates
Complete guide for building MCP servers with FastMCP 3.0 - tools, resources, authentication, providers, middleware, and deployment. Use when creating Python MCP servers or integrating AI models with external tools and data.
security-audit
aakash-dhar/claude-skills
Scans code for security vulnerabilities including injection attacks, authentication flaws, exposed secrets, insecure dependencies, and data exposure. Use when the user says "security review", "is this secure?", "check for vulnerabilities", "audit this", or before deploying to production.
vulnerability-scanner
vudovn/ag-kit
Advanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization.
oma-backend
gracefullight/stock-checker
Backend specialist for APIs, databases, authentication with clean architecture (Repository/Service/Router pattern). Use for API, endpoint, REST, database, server, migration, and auth work.
azure-virtual-network
microsoftdocs/agent-skills
Expert knowledge for Azure Virtual Network development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, and deployment. Use when configuring VNets with peering, Accelerated Networking, Azure CNI, NSGs/service endpoints, or VNet encryption, and other Azure Virtual Network related development tasks. Not for Azure Virtual Network Manager (use azure-virtual-network-manager), Azure Virtual WAN (use azure-virtual-wan), Azure Application Network (use azure-application-network), Azure Networking (use azure-networking).
api-review
bobmatnyc/claude-mpm-skills
API security checklist for reviewing endpoints before deployment. Use when creating or modifying API routes to ensure proper authentication, authorization, and input validation.
neon-auth
neondatabase/ai-rules
Sets up Neon Auth for your application. Configures authentication, creates auth routes, and generates UI components. Use when adding authentication to Next.js, React SPA, or Node.js projects.
prompt-agent
prompt-security/clawsec
Security audit enforcement for AI agents. Automated security scans and health verification.
cpg-analysis
alinaqi/maggy
Deep code property graph analysis with Joern CPG (AST+CFG+PDG) and CodeQL for control flow, data flow, taint analysis, and security auditing
security
thebeardedbearsas/claude-craft
Security guidelines and OWASP Top 10. Use when reviewing security, implementing authentication or authorization, hardening code, or discussing vulnerabilities.
secrets-manager
itsmostafa/aws-agent-skills
AWS Secrets Manager for secure secret storage and rotation. Use when storing credentials, configuring automatic rotation, managing secret versions, retrieving secrets in applications, or integrating with RDS.
spring-security
full-stack-skills/spring-skills
Provides comprehensive guidance for Spring Security including authentication, authorization, OAuth2, JWT, and security best practices. Use when the user asks about Spring Security, needs to implement security in Spring applications, configure authentication, or work with security features.
github-actions-oidc-aws
loxosceles/ai-dev
Secure GitHub Actions to AWS authentication using OIDC without long-lived credentials. CRITICAL PATTERN. Apply when setting up CI/CD pipelines that deploy to AWS.
draft-security-advisory
frappe/skills
Turn a vulnerability report into a publication-ready GitHub Security Advisory.
review
gracefullight/stock-checker
OWASP security, performance, accessibility, code quality review (includes Fix-Verify Loop)
usdt-m-futures
htx-exchange/htx-skills-hub
HTX USDT-M Futures trading using the HTX API. Authentication requires API key and secret key for certain endpoints. Supports mainnet.
security-testing
proffesor-for-testing/agentic-qe
Scans for security vulnerabilities including XSS, SQL injection, CSRF, and auth flaws using OWASP Top 10 methodology. Use when conducting SAST/DAST scans, auditing authentication flows, testing authorization rules, or implementing security test automation.
github-workflow-standards
community-access/accessibility-agents
Core standards for all GitHub workflow agents. Covers authentication, smart defaults, repository discovery, dual MD+HTML output, screen-reader-compliant HTML accessibility standards, safety rules, progress announcements, parallel execution, and output quality. Apply when building any GitHub workflow agent - issues, PRs, briefings, analytics, community reports, team management.
azure-container-storage
microsoftdocs/agent-skills
Expert knowledge for Azure Container Storage development including troubleshooting, decision making, limits & quotas, security, and configuration. Use when configuring Elastic SAN-backed pools, CMK encryption, LRS/ZRS redundancy, volume resizing, or Prometheus/Grafana monitoring, and other Azure Container Storage related development tasks. Not for Azure Blob Storage (use azure-blob-storage), Azure Files (use azure-files), Azure Elastic SAN (use azure-elastic-san), Azure NetApp Files (use azure-netapp-files).
skill-scanner
bvinci1-design/skill-scanner
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
hunt-llm-ai
elementalsouls/claude-bughunter
Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). Patterns: direct injection ('ignore previous instructions'), indirect injection via documents/web pages/email the model reads, ASCII smuggling (Unicode Tags block U+E0000-U+E007F, invisible to humans, decoded by the model), tool-use exfiltration (model has fetch/browse tool, attacker injects OOB URL, model exfils chat history/secrets), markdown-image zero-click exfil, system-prompt extraction, IDOR-via-AI (cross-tenant data). Targets: chatbots, RAG, summarizers, agentic copilots, MCP tools. Detection: any LLM-backed endpoint, doc upload triggering AI processing, autonomous agent with tools. Validate: OOB/Collaborator callback for exfil, verbatim-reproducible system-prompt leak (run twice), verifiable cross-tenant leak or RCE. Confabulation is NOT a finding. Use when hunting AI features, chatbots, RAG, agentic systems, MCP.
nutmeg-acquire
withqwerty/nutmeg
Fetch, scrape, or download football data from any source. Also handles API key setup and credential management. Use when the user wants to get data from StatsBomb, Opta, FBref, Understat, SportMonks, Wyscout, Kaggle, or any football data source. Also use when they ask about API keys, authentication, setting up access to a provider, or what data is available free vs paid.
byted-mediakit-shared
volcengine/mediakit-cli
1. mediakit-cli: supports a variety of operations such as audio/video processing, editing, and images, with some capabilities covering both cloud and local modes; 2. mediakit-cli shared: environment checks, initialization config, command structure, authentication config, async task responses, and error handling.
azure-queue-storage
microsoftdocs/agent-skills
Expert knowledge for Azure Queue Storage development including best practices, limits & quotas, security, configuration, and integrations & coding patterns. Use when using Entra ID/RBAC auth, client-side encryption, monitoring/alerts, scaling limits, or .NET/Java/Python SDKs, and other Azure Queue Storage related development tasks. Not for Azure Blob Storage (use azure-blob-storage), Azure Table Storage (use azure-table-storage), Azure Service Bus (use azure-service-bus), Azure Event Hubs (use azure-event-hubs).
cve-poc-generator
transilienceai/communitytools
CVE research, standalone PoC script and report generation. Given a CVE ID, researches NVD and advisories, generates a safe Python PoC, and writes a detailed vulnerability report.
security-testing-patterns
nickcrew/claude-cortex
Security testing patterns including SAST, DAST, penetration testing, and vulnerability assessment techniques. Use when implementing security testing pipelines, conducting security audits, or validating application security controls.
clerk-validator
shipshitdev/skills
Validate Clerk authentication configuration and detect deprecated patterns. Ensures proper proxy.ts usage (Next.js 16), ClerkProvider setup, and modern auth patterns. Use before any Clerk work or when auditing existing auth implementations.
azure-expressroute
microsoftdocs/agent-skills
Expert knowledge for Azure ExpressRoute development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when configuring ExpressRoute circuits/gateways, BGP routing, Global Reach, FastPath, or IPsec/MACsec encryption, and other Azure ExpressRoute related development tasks. Not for Azure Virtual Network (use azure-virtual-network), Azure VPN Gateway (use azure-vpn-gateway), Azure Virtual WAN (use azure-virtual-wan), Azure Internet Peering (use azure-internet-peering).
implementing-api-security-testing-with-42crunch
mukul975/anthropic-cybersecurity-skills
Implements API security testing on the 42Crunch platform, combining
wordpress-penetration-testing
zebbern/claude-code-guide
This skill should be used when the user asks to "pentest WordPress sites", "scan WordPress for vulnerabilities", "enumerate WordPress users, themes, or plugins", "exploit WordPress vulnerabilities", or "use WPScan". It provides comprehensive WordPress security assessment methodologies.
detecting-anomalous-authentication-patterns
mukul975/anthropic-cybersecurity-skills
Detects anomalous authentication patterns using UEBA analytics, statistical
dotnet-security-owasp
wshaddix/dotnet-skills
Securing .NET code or reviewing for vulnerabilities. OWASP Top 10 mitigations, pattern warnings.
integrating-dast-with-owasp-zap-in-pipeline
mukul975/anthropic-cybersecurity-skills
Integrates OWASP ZAP (Zed Attack Proxy) into GitHub Actions and GitLab CI pipelines, covering baseline, full, and API scan configuration against running applications, ZAP finding interpretation, scan policy tuning, and DAST quality gates. Use when testing running web apps or REST/GraphQL APIs for XSS, SQLi, CSRF, and auth/authz flaws, or when SAST alone is insufficient and runtime DAST is required for compliance or release gating.
azure-ad-sso
julianobarbosa/claude-code-skills
Azure AD OAuth2/OIDC SSO integration for Kubernetes applications. Use when implementing Single Sign-On, configuring Azure AD App Registrations, restricting access by groups, or integrating tools (DefectDojo, Grafana, ArgoCD, Harbor, SonarQube) with Azure AD authentication.
security-review
dedalus-erp-pas/foundation-skills
Audit de sécurité couvrant l'authentification, l'injection SQL, l'exposition de secrets, le CSRF et les vulnérabilités du Top 10 OWASP. À utiliser quand l'utilisateur veut auditer la sécurité du code, rechercher des vulnérabilités, vérifier l'authentification/autorisation, détecter des secrets exposés ou des injections, ou mentionne « security review » / « audit de sécurité » / « OWASP ».
multitenant
thebeardedbearsas/claude-craft
Architecture multitenant avec approche tiered (Shared/Dedicated Schema/DB), RBAC/ABAC, field-level encryption. Use when working with multitenant applications, tenant isolation, data segregation.