Search
Secure coding
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | 49.Reviewdog Automated code review and security linting integration for CI/CD pipelines using reviewdog. | AgentSecOps/ | 220 | 1 repo | ~3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 50 | Execute safe read-only SQL queries against PostgreSQL databases with multi-connection support and defense-in-depth write protection. | sickn33/ | 47k | 1 repo | ~1.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 51 | Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries. | dzhalaevd/ | 135 | — | ~5.1k | Automated safety check: Notes | Apache-2.0 | 5 days ago |
| 52 | Implements defense-in-depth controls at an AI agent's tool-invocation boundary using tool allowlisting, least-privilege identity binding, NeMo Guardrails policy enforcement, human-in-the-loop… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 53 | Reduces attack surface across OS, container, cloud, network, and database layers using CIS Benchmarks and zero-trust principles. | ancoleman/ | 526 | — | ~3.5k | Automated safety check: Pass | MIT | 10 mo ago |
| 54 | Java security checklist covering OWASP Top 10, input validation, injection prevention, and secure coding. | decebals/ | 751 | — | ~3.7k | Automated safety check: Notes | MIT | 1 mo ago |
| 55 | Establish a security baseline for a website or web app. An agent skill from rampstackco/claude-skills. | rampstackco/ | 940 | — | ~3k | Automated safety check: Pass | MIT | yesterday |
| 56 | 56.API Design A skill your agent uses when settling the contract of an API you expose, before implementation: resources/URLs, REST vs GraphQL, versioning, one RFC 9457 error envelope, pagination, idempotency —… | ericrisco/ | 167 | — | ~3.1k | Automated safety check: Pass | MIT | yesterday |
| 57 | Review Next.js security audit patterns for App Router and Server Actions. | IgorWarzocha/ | 122 | — | ~1.5k | Automated safety check: Notes | No licence | 8 mo ago |
| 58 | Expert in secure backend coding practices specializing in input validation, authentication, and API security. | aiskillstore/ | 430 | 7 repos | ~2.6k | Automated safety check: Pass | No licence | yesterday |
| 59 | A skill your agent uses when reviewing HTTP response headers for defense-in-depth security hardening on any web application. | thedaviddias/ | 74k | — | ~565 | Automated safety check: Pass | MIT | 2 days ago |
| 60 | Automatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management. | rand/ | 181 | — | ~1.9k | Automated safety check: Pass | MIT | 7 mo ago |
| 61 | Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts. | ancoleman/ | 526 | — | ~3.5k | Automated safety check: Notes | MIT | 10 mo ago |
| 62 | Run an enterprise security review of a system design or existing code before it ships. | ooiyeefei/ | 494 | — | ~1.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 63 | Design comprehensive security architectures using defense-in-depth, zero trust principles, threat modeling (STRIDE, PASTA), and control frameworks (NIST CSF, CIS Controls, ISO 27001). | ancoleman/ | 526 | — | ~6.3k | Automated safety check: Pass | MIT | 10 mo ago |
| 64 | HTTP security header audit (A+ to F) with fix recommendations | taracodlabs/ | 851 | — | ~956 | Automated safety check: Pass | Apache-2.0 | 25 days ago |
| 65 | A skill your agent uses when the user says 'audit API', 'check API security', 'API routes security', 'endpoint audit', 'check my routes', or needs to verify API route protection. | cwinvestments/ | 423 | — | ~3.9k | Automated safety check: Pass | Proprietary | 12 days ago |
| 66 | A skill your agent uses when the user says 'CSP', 'Content-Security-Policy', 'security headers', 'HSTS', 'X-Frame-Options', 'clickjacking', 'unsafe-inline', 'unsafe-eval', or needs to audit… | cwinvestments/ | 423 | — | ~3.9k | Automated safety check: Pass | Proprietary | 12 days ago |
| 67 | Security patterns and OWASP guidelines. An agent skill from aiskillstore/marketplace. | aiskillstore/ | 430 | 1 repo | ~1.2k | Automated safety check: Notes | No licence | yesterday |
| 68 | OWASP Top 10 security checklist, authentication patterns, input validation, and HTTP security headers reference. | modu-ai/ | 1.2k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | today |
| 69 | 69.Moai Ref SEO Search-visibility and crawlability reference for web output: canonical URL discipline, per-page title and meta description uniqueness, robots.txt and sitemap.xml as host-derived artifacts, JSON-LD… | modu-ai/ | 1.2k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | today |
| 70 | Analyze HTTP security headers of web domains to identify vulnerabilities and misconfigurations. | jeremylongshore/ | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | today |
| 71 | A skill your agent uses when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products… | jabrena/ | 446 | — | ~3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 72 | 72.Waf Web Application Firewall guidance, when to put one in front of an app and how to run it without breaking traffic. | TheDecipherist/ | 338 | — | ~1.4k | Automated safety check: Pass | MIT | 3 mo ago |
| 73 | Audit a target's HTTP security headers — CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and the Cross-Origin trio (COOP, COEP, CORP). | jeremylongshore/ | 2.8k | — | ~1.6k | Automated safety check: Pass | MIT | today |
| 74 | A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing… | jabrena/ | 446 | — | ~885 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 75 | A skill your agent uses when you need to design, review, or improve security in Spring Boot applications — including SecurityFilterChain, OAuth2/JWT resource server patterns, form login basics… | jabrena/ | 446 | — | ~719 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 76 | 76.Security Secure coding practices for agent-native apps: input validation, SQL injection, XSS, secrets, data scoping, and auth. | BuilderIO/ | 7.1k | — | ~5.2k | Automated safety check: Notes | No licence | today |
| 77 | Apply security-conscious thinking when generating or modifying code. | techygarg/ | 198 | — | ~1.5k | Automated safety check: Pass | MIT | 2 days ago |
| 78 | 78.Loop Full execution protocol for MODE: LOOP — the compound-engineering loop: brainstorm → plan → build → review → improve, iterating under defense-in-depth stop conditions with generator/critic… | ZaxbyHub/ | 490 | — | ~3.9k | Automated safety check: Pass | MIT | yesterday |
| 79 | Security-posture and third-party SaaS identification — security headers, CSP, HSTS, email auth, security.txt, plus payments/analytics/auth/CRM/support integrations. | transilienceai/ | 562 | — | ~447 | Automated safety check: Pass | MIT | 2 mo ago |
| 80 | Application security covering input validation, auth, headers, secrets management, and dependency auditing | rohitg00/ | 2.7k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | 4 mo ago |
| 81 | Cloudflare Workers security with authentication, CORS, rate limiting, input validation. | secondsky/ | 227 | — | ~1.9k | Automated safety check: Pass | MIT | 10 days ago |
| 82 | Applica regole di sicurezza (hardening) ogni volta che si costruisce, modifica o revisiona un sito web o un'app. | ccplugins/ | 968 | — | ~875 | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 83 | Configure and audit security review capabilities as one layer in a defense-in-depth pull-request program. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 84 | Apply Vercel security best practices for secrets, headers, and access control. | jeremylongshore/ | 2.8k | — | ~1.9k | Automated safety check: Notes | MIT | today |
| 85 | Reviews a design or change for security before it ships — authentication and authorization, data handling, secrets, dependencies, and the secure-development practices around it. | cbrock84/ | 2k | — | ~1.1k | Automated safety check: Pass | MIT | 21 days ago |
| 86 | STRIDE threat modeling, DREAD risk scoring, secret detection, and secure architecture design. | borghei/ | 881 | — | ~1.8k | Automated safety check: Pass | MIT | yesterday |
| 87 | Defense-in-depth security across Rust, TypeScript, and Bash for the Pump SDK — cryptographic key handling, memory zeroization, secure file I/O, input validation, privilege management, dependency… | nirholas/ | 133 | — | ~892 | Automated safety check: Pass | Unknown | 20 days ago |
| 88 | Security-first development guidance based on OWASP ASVS (Application Security Verification Standard). | OWASP/ | 187 | — | ~8.1k | Automated safety check: Pass | Unknown | 13 days ago |
| 89 | AI-enabled security excellence through transparent ISMS implementation, defense-in-depth, and strategic planning aligned with Hack23 business model | Hack23/ | 239 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 90 | Secure SDLC phases, security requirements, secure coding practices, and security testing integration for the CIA platform | Hack23/ | 239 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 91 | Threat modeling before coding, STRIDE methodology, defense in depth, security controls in SDLC | Hack23/ | 239 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 92 | A skill your agent uses when standing up the core AWS surface a small product needs: hardening a fresh account, a private S3 bucket, encrypted RDS Postgres, ECS Fargate vs EC2, CloudFront + OAC, or… | ericrisco/ | 167 | — | ~2.9k | Automated safety check: Notes | MIT | yesterday |
| 93 | 93.Compliance A skill your agent uses when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or… | ericrisco/ | 167 | — | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 94 | 94.Docker A skill your agent uses when authoring or auditing a Dockerfile, shrinking a bloated image, hardening a container that runs as root, picking a base image, or wiring a Compose dev loop with hot reload. | ericrisco/ | 167 | — | ~2.7k | Automated safety check: Notes | MIT | yesterday |
| 95 | 95.Go A skill your agent uses when writing, reviewing, testing, or shipping Go code and HTTP services: idioms, %w error wrapping, goroutine/context/errgroup concurrency, net/http 1.22 routing, log/slog… | ericrisco/ | 167 | — | ~3.9k | Automated safety check: Pass | MIT | yesterday |
| 96 | A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has… | ericrisco/ | 167 | — | ~2.8k | Automated safety check: Notes | MIT | yesterday |