Skill Claude CodeCodex
Draft or repair a disabled Synapsor Safe Action when a developer asks to make one application data change safe for an AI agent.
16,944 tagged Security, measured the same way as everything else here.
Browse within: cybersecurity 484bug-bounty 276agent 229generative-ai 179LangChain 176hacking 175autonomous-pentesting 134cloud-security 121skills 121claude-ai 118redteam 113LLM 108security-audit 105cors-exploitation 88
Skill Claude CodeCodex
Draft or repair a disabled Synapsor Safe Action when a developer asks to make one application data change safe for an AI agent.
Skill Claude CodeCodex
Apply security guidelines when designing, building, or reviewing AI chatbots, LLM-powered apps, autonomous/tool-using agents, and mobile apps (React Native/Expo, Flutter) — covering agent controls (authorization checks, plan validation, execution limits, audit logging), LLM/prompt security (prompt injection, RAG…
Skill Claude Code
Govern consequential Codex tool calls with Custodian before execution, including writes, network access, credentials, destructive commands, production changes, and money movement.
Skill Claude CodeCodex
Comprehensive security audit for web applications and APIs. Performs a full-stack security review covering authentication, authorization, rate limiting, input validation, secrets management, security headers, cost controls (AI/API spend), email abuse prevention, dependency vulnerabilities, and data exposure risks.…
Skill Claude CodeCodex
Use when asked to check, audit, or review a web application's security, authentication, permissions, access control, error handling, API/endpoint surface, or database management — including "is my app secure", "check my auth", "review my permissions", "find vulnerabilities", or a pre-launch/pre-handover review.
Skill Claude CodeCodex
Classify AI system risk under EU AI Act (Reg 2024/1689), generate Article 50 disclosures, and design conformity audit trails.
dacuma-labs/agent-security-audit
Skill Claude CodeCodex
Audits AI agent projects for security risks in prompts, tools, memory, RAG, and permissions. Use when: the user asks to review agent security, harden an agentic system, check for prompt injection risks, audit tool permissions, or secure an AI assistant before deployment. Do NOT use for: projects with no agentic…
may215/antigravity-awesome-group-skills
Skill Claude CodeCodex
Group skill: Comprehensive security audit — threat modeling, SAST, dependency check, auth review, API security, pen testing, secrets check, GDPR, hardening, and compliance report.
ASER-ho/coding-agent-safety-gate
Skill Claude CodeCodex
A set of safety rules for keeping an AI coding assistant within an approved workspace, task, file scope, and security boundary.
taimurijlal/Claude-Code-Security
Skill Claude CodeCodex
Creates a STRIDE threat model of the current project with ASCII diagrams and outputs a threat.md file. Use when analyzing system security, designing architectures, or identifying threats in applications.
Skill Claude Code ✓ vendor
Fleet-wide Azure Key Vault health check — pulse check for availability, API latency, throttling (429s), auth failures (401/403), and vault saturation across all vaults, then deep-dives into the top 7 most interesting vaults with metrics and resource logs. Tracks known issues across sessions via persistent report. On…
Skill Claude CodeCodex
Audit a repo for PII leakage, secrets, and sensitive data before commits or publishing. Runs gitleaks if available, scans git history, checks working tree for known and novel patterns, and optionally wires up a pre-commit hook. Use before making a private repo public, after importing external data into a project, or…
Skill Claude Code
Reviews code diffs after implementation, auto-fixes safe issues, and runs specialist security and architecture reviewers on large diffs. Also triages issues and PRs when the user mentions them. Not for exploring ideas or debugging.
Skill Claude CodeCodex
Run a comprehensive code audit on any codebase. Analyzes security vulnerabilities, hardcoded secrets, dependency CVEs, test coverage, code structure, and AI-generated code patterns. Generates CODEAUDITREPORT.md with findings, severity ratings, and remediation guidance. Intelligently selects and orchestrates the best…
Skill Claude Code
Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.
Skill Claude CodeCodex
Product readiness auditor that crawls any codebase, maps what exists, identifies gaps, incomplete code, vulnerabilities, and dead ends, then produces a prioritized remediation plan. Trigger this skill when the user says 'inspect this project', 'audit my code', 'what's broken', 'product readiness check', 'MVP audit'…
Skill Claude CodeCodex
Analyze Istio, Consul, and Linkerd service mesh configurations for security vulnerabilities with NIST 800-53 control mappings. Use when users need to audit mesh security, identify misconfigurations, check mTLS settings, review ACL policies, or prepare for FedRAMP assessments. Triggers on keywords like "mesh config"…
Skill Claude CodeCodex needs its repo
Security audit orchestration for Soroban/Stellar Rust smart contracts. Use when user asks to "audit this codebase", "run soroban auditor", or "check for security vulnerabilities". Utilizes AST squeezing, pre-computed guard/state/integration/divergence/invariant/unsafe maps, parallel agent spawning, a verification…
Skill Claude Code
Implement authentication and authorization in web applications. Use when adding login, signup, sessions, JWT tokens, OAuth, SSO, API key auth, role-based access control (RBAC), permissions, protected routes, middleware guards, password hashing, MFA/2FA, refresh token rotation, CSRF protection, or integrating auth…
Skill Claude CodeCodex
Executa uma auditoria profunda de segurança (AppSec) em projetos de software, gerando um relatório técnico priorizado com no mínimo 30 riscos ou pontos de validação. Use este skill SEMPRE que o usuário quiser: Fazer auditoria de segurança, pentest defensivo ou hardening de um projeto; Encontrar vulnerabilidades em…
kleberbernardo/claude-code-skills
Skill Claude Code
Auditoria e correção de segurança nível enterprise — AppSec, Cloud Security, DevSecOps, Infra Security. Detecta e corrige riscos do básico ao avançado, incluindo vibe coding e código gerado por IA.
Skill Claude CodeCodex
Harden ALB-backed services (LiteLLM, generic APIs) behind CloudFront + WAF. Creates CloudFront distribution with secret origin header, WAF Web ACL with path whitelist, and locks down ALB Security Group to CloudFront-only. Use when deploying any internet-facing ALB service that should not be directly accessible.
oscal-compass/agentic-agile-authoring
Skill Claude Code
Convert a compliance-document PDF (law, regulation, industry standard) into a validated OSCAL Catalog JSON. Use when the user wants to turn a compliance PDF into an OSCAL Catalog, ingest a new framework into the OSCAL ecosystem, or regenerate a catalog from a revised PDF while keeping control IDs stable.
Skill Claude CodeCodex
Security auditing skill for web applications and codebases. Scans for OWASP Top 10, dependency vulnerabilities, secrets exposure, XSS/CSRF/injection flaws, auth weaknesses, and misconfigurations. Use when task involves security scan, vulnerability assessment, pen test review, threat modeling, or hardening a codebase.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: