Agent Skills (SKILL.md) that teach Claude Code repeatable workflows, from document editing to deployment runbooks. 525 curated, ranked by GitHub signal.
525 skills in Security
sickn33
This skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing authentication or authorization, handling user input or file uploads, or creating new API endpoints.
sickn33
Expert in secure frontend coding practices specializing in XSS prevention, output sanitization, and client-side security patterns.
sickn33
Postgres performance optimization and best practices from Supabase. Use this skill when writing, reviewing, or optimizing Postgres queries, schema designs, or database configurations.
NousResearch
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in, and reading/injecting secrets for commands.
NousResearch
Passive domain reconnaissance using Python stdlib. Subdomain discovery, SSL certificate inspection, WHOIS lookups, DNS records, domain availability checks, and bulk multi-domain analysis. No API keys required.
NousResearch
Read-only EVM client: wallets, tokens, gas across 8 chains.
NousResearch
Jailbreak LLMs: Parseltongue, GODMODE, ULTRAPLINIAN.
NousResearch
OBLITERATUS: abliterate LLM refusals (diff-in-means).
NousResearch
| Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories. Covers deleted commit recovery, force-push detection, IOC extraction, multi-source evidence collection, hypothesis formation/validation, and structured forensic reporting. Inspired by RAPTOR's 1800+ line OSS Forensics system.
NousResearch
OSINT username search across 400+ social networks. Hunt down social media accounts by username.
NousResearch
Autonomously remove your info from data-broker sites.
NousResearch
| Authorized web application penetration testing — reconnaissance, vulnerability analysis, proof-based exploitation, and professional reporting. Adapts Shannon's "No Exploit, No Report" methodology with hard guardrails for scope, authorization, and aux-client leakage. Active testing against running applications you own or have written authorization to test.
mattpocock
Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute. Use when user wants to prevent destructive git operations, add git safety hooks, or block git push/reset in Claude Code.
sickn33
Autonomous DevSecOps & FinOps Guardrails. Orchestrates Gemini 3 Flash to audit Linux Kernel patches, Terraform cost drifts, and K8s compliance.
sickn33
The AI native file format. EXIF for AI — stamps every file with trust scores, source provenance, and compliance metadata. Embeds into 20+ formats (DOCX, PDF, images, code). EU AI Act, SOX, HIPAA auditing.
sickn33
Automated compliance checking against CIS, PCI-DSS, HIPAA, and SOC 2 benchmarks
sickn33
IAM policy review, hardening, and least privilege implementation
sickn33
Automate AWS secrets rotation for RDS, API keys, and credentials
sickn33
Comprehensive AWS security posture assessment using AWS CLI and security best practices
sickn33
Build content moderation applications using the Azure AI Content Safety SDK for Java.
sickn33
Azure AI Content Safety SDK for Python. Use for detecting harmful content in text and images with multi-severity classification.
sickn33
Analyze text and images for harmful content with customizable blocklists.
sickn33
Authenticate Java applications with Azure services using Microsoft Entra ID (Azure AD).
sickn33
Authenticate to Azure services with various credential types.
sickn33
Azure Key Vault Certificates SDK for Rust. Use for creating, importing, and managing certificates.
sickn33
Azure Key Vault Keys SDK for Rust. Use for creating, managing, and using cryptographic keys. Triggers: "keyvault keys rust", "KeyClient rust", "create key rust", "encrypt rust", "sign rust".
sickn33
Manage cryptographic keys using Azure Key Vault Keys SDK for JavaScript (@azure/keyvault-keys). Use when creating, encrypting/decrypting, signing, or rotating keys.
sickn33
Azure Key Vault SDK for Python. Use for secrets, keys, and certificates management with secure storage.
sickn33
Azure Key Vault Secrets SDK for Rust. Use for storing and retrieving secrets, passwords, and API keys. Triggers: "keyvault secrets rust", "SecretClient rust", "get secret rust", "set secret rust".
sickn33
Manage secrets using Azure Key Vault Secrets SDK for JavaScript (@azure/keyvault-secrets). Use when storing and retrieving application secrets or configuration values.
sickn33
Azure Key Vault Keys SDK for .NET. Client library for managing cryptographic keys in Azure Key Vault and Managed HSM. Use for key creation, rotation, encryption, decryption, signing, and verification.
sickn33
Azure Key Vault Keys Java SDK for cryptographic key management. Use when creating, managing, or using RSA/EC keys, performing encrypt/decrypt/sign/verify operations, or working with HSM-backed keys.
sickn33
Azure Key Vault Secrets Java SDK for secret management. Use when storing, retrieving, or managing passwords, API keys, connection strings, or other sensitive configuration data.
sickn33
Expert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.
sickn33
Build production-ready Web3 applications, smart contracts, and decentralized systems. Implements DeFi protocols, NFT platforms, DAOs, and enterprise blockchain integrations.
sickn33
Adversarial code auditor that hunts down bugs, logic errors, and security flaws. Use for deep correctness passes, not style reviews.
sickn33
Run Bumblebee supply-chain inventory and exposure scans on macOS/Linux to detect compromised packages, extensions, and MCP host configs.
sickn33
Audit authorized codebases for exploitable vulnerabilities using scoped reconnaissance, adversarial review, validation, and structured reporting.
sickn33
Deep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. Checks every file line-by-line for production readiness.
sickn33
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
sickn33
You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
sickn33
Expert firmware analyst specializing in embedded systems, IoT security, and hardware reverse engineering.