code-review
745Skill Claude Code
Review code changes for security, performance, and style issues.
16,964 tagged Security, measured the same way as everything else here.
Browse within: cybersecurity 490bug-bounty 284agent 228generative-ai 179LangChain 176hacking 175autonomous-pentesting 139cloud-security 123skills 121claude-ai 118redteam 115LLM 107security-audit 106cors-exploitation 90
Skill Claude Code
Review code changes for security, performance, and style issues.
Skill Claude CodeCodex
Skill "ekyc-suite" from wefi-ai/eKYC-Suite, covering ekyc suite, what is ekyc suite?, quick reference, external endpoints and security & privacy.
Skill Claude CodeCodex
Turn a large codebase into a short, ranked reading list of security-relevant code paths worth a human researcher's time, using the flyto-indexer MCP tools. Use when asked to find, prioritize, or triage potential vulnerabilities / taint flows / attack surface in a repository indexed (or indexable) by flyto-indexer …
Skill Claude CodeCodex
Runtime deny for EU AI Act Article 5 and Article 50 on this prompt or output via ComplyEdge TrustLint MCP. Use when the user wants agent I/O compliance enforcement, not system classification, FRIA forms, or C2PA watermarking.
jonnybottles/patch-tuesday-mcp
Skill Claude CodeCodex
Monthly Patch Tuesday identity/security triage using the single msrcsearch tool with product watchlists.
levelsofself/mcp-nervous-system
Skill Claude CodeCodex
Use this skill when building, managing, or auditing multi-agent AI systems. Provides governance patterns for behavioral enforcement, drift detection, audit trails, role management, and accountability across autonomous AI agents. Compatible with any orchestration framework.
Skill Claude Code
Backend security auditor for Django and DRF on an OWASP Top 10 (2025), API Security Top 10 (2023), and ASVS 5.0 foundation. Use when backend code is written or reviewed and touches authentication, sessions, cookies, JWT, OAuth2/OIDC, API keys, password hashing, permissions, access control, IDOR, SSRF, path traversal…
Skill Claude CodeCodex
Single-CVE applicability triage that evaluates whether a CVE actually applies to the user's environment by reasoning about discriminating conditions against a skill-maintained environment profile; triggers when a user asks whether they are affected by a CVE, whether a CVE applies to them, or wants to assess a CVE…
Skill Claude CodeCodex
Astro security review — render-mode attack surface (SSG/SSR/hybrid), set:html and MDX content collections (XSS + author trust), API routes and middleware (auth, scope), adapter-specific runtime models (Cloudflare/Vercel/Netlify/Node), env-var hygiene (PUBLIC prefix), and Decap CMS pairing (OAuth backend, token…
Skill Claude Code
Binary exploitation (pwn): stack/heap/format-string/ROP, glibc heap (House-of-, leakless, FSOP/FSOPAgain), seccomp bypass, sandbox escape, Linux & Windows kernel exploitation (KASLR/SMEP/SMAP, token steal, cred swap, PreviousMode), BROP. Dispatch on binary/checksec signals.
Skill Claude CodeCodex
Clerk authentication integration for Astro/Next.js. Use when implementing authentication, handling Clerk middleware, testing with Playwright, or debugging auth issues. Trigger phrases include "Clerk auth", "sign in", "authentication", "middleware", "E2E testing with Clerk".
Skill Claude CodeCodex
Finds and ranks open-source packages worth auditing for passive CVE/VulDB research. Use when the user asks for vulnerability research targets, CVE hunting candidates, packages to audit, projects to fuzz, or /omv-find. Supports npm, Python, Go, Rust, Java, Ruby, PHP, C#, Swift, Dart, Elixir, Perl, R, and Lua, with…
smartbrainactivity/smartbrain-skill-auditor
Skill Claude CodeCodex
A universal, dependency-free Node.js tool to statically audit AI Skills and local agents for malicious patterns.
Skill Claude CodeCodex
Govern release-affecting, policy-changing, externally mutating, destructive, or otherwise high-risk work through typed effects, mandatory evidence, independent safety gates, and an explicit go/no-go decision. Do not use for ordinary answers, read-only inspection, tiny reversible edits, or a task made "multi-skill"…
0xlayerghost/solidity-agent-kit
Skill Claude CodeCodex
When this skill is triggered, DO NOT directly implement all strategies. Follow this workflow.
Skill Claude Code
Run an independent security audit of this repository before trusting it. Use when the user asks whether this project is safe, what it sends over the network, what it does to their computer, whether it is malware or spyware, or asks for a security review of this codebase.
Skill Claude CodeCodex
Code-quality gate and coding guardrail for AI coding agents. Always invoke when you finish editing and prepare to hand control back, even if the user did not explicitly ask. Trigger on commit, push, PR, or quality questions like any slop, is this clean, review my changes, score my code, any duplicates, or is this…
Skill Claude CodeCodex
Use when querying or changing Drata/GRC data through the drata CLI, including compliance status, frameworks, certificates, Trust Center documents, controls, monitoring tests, evidence, risks, vendors, policies, personnel compliance, and background-check questions. Prefer versionless CLI commands, JSON output…
Skill Claude Code
Reviews code for quality, bugs, security, and best practices. Use when changing code or before merge. Checks security, authentication, and validation; ensures new code follows project rules and conventions.
Skill Claude CodeCodex
Run CH015 security design review workflows for PRDs and specs to produce security opinions or review findings mapped to standards and regulatory requirements.
Skill Claude CodeCodex
Pre-execution planning and priority-scored task list before running tools.
adamoutler/joplin-server-vector-memory
Skill Claude CodeCodex
Run the skillsafe scan on the adamoutler/joplin-server-vector-memory package, then operate and improve/complete all issues identified. Use this when asked to scan or fix skillsafe issues.
Skill Claude CodeCodex
Cage, run, and audit MCP servers with mcpvessel: install an MCP server into an isolated container, serve it to Claude Code, and watch what it does with the network and the user's secrets. Use this whenever the user mentions mcpvessel by name, or wants to add, install, set up, try, run, or sandbox an MCP server, or…
nsasoft/nsauditor-ai-agent-skill
Skill Claude CodeCodex
Use this skill whenever the user wants network security scanning, auditing, vulnerability assessment, host reconnaissance, or cloud-account security/compliance auditing with NSAuditor AI (via the nsauditor-ai MCP server: scanhost, scancloud, getfindings, probeservice, getvulnerabilities, listplugins). Triggers include…
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: