Search

Secure coding

113 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Hardens code against vulnerabilities. An agent skill from penpot/penpot.

penpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0today
2

Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs.

microsoft/onnxruntime22k—~3.3kAutomated safety check: PassMITtoday
3

Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

usestrix/strix67k—~1.5kAutomated safety check: PassApache-2.0today
4

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

trailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0yesterday
5

Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

ruvnet/ruflo74k2 repos~823Automated safety check: PassMITtoday
6

Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code.

ZeroDeng01/sublinkPro1.7k—~2.3kAutomated safety check: PassMITtoday
7

Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

fengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT23 days ago
8

Reviews code or recent changes for bugs, security issues, performance problems and maintainability, reporting findings by severity with the reason and a fix.

pretend1111/claude-desktop-app4941 repo~502Automated safety check: PassUnknown5 mo ago
9

Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

TheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT5 mo ago
10

Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams.

rfc-st/humble379—~3.7kAutomated safety check: PassMITyesterday
11

RenoDX DevKit workflow for tracing swapchain/output passes, SwapChainPass, RGBA8U/UNORM limits, RGBA16F proxy resources, gamma-space float pipelines, HDR10-preferred SDR/HDR output toggles, rare…

clshortfuse/renodx4.4k—~5.6kAutomated safety check: PassMITtoday
12

Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

zereight/gitlab-mcp2k1 repo~859Automated safety check: NotesMIT2 days ago
13

Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

bodadotsh/npm-security-best-practices859—~1kAutomated safety check: WarnMIT8 days ago
14

Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks.

telagod/code-abyss243—~552Automated safety check: NotesMIT2 mo ago
15

Shows how to replace unsafe hasattr and setattr loops over user-controlled kwargs with an explicit allowlist when configuring ONNX Runtime option objects.

microsoft/onnxruntime22k—~737Automated safety check: PassMITtoday
16

Gives the agent a five-step review routine that reads the full file first, labels each finding as bug, security, performance, style or suggestion, and ends with a summary.

FareedKhan-dev/claude-code-from-scratch298—~809Automated safety check: PassMIT6 mo ago
17

Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

addyosmani/agent-skills103k1 repo~4.4kAutomated safety check: NotesMIT5 days ago
18

Reviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries.

amElnagdy/guard-skills1.3k—~2.4kAutomated safety check: PassMIT3 mo ago
19

A skill your agent uses when invalid data causes failures deep in execution, requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally…

sandgardenhq/sgai1373 repos~970Automated safety check: PassUnknown17 days ago
20

Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.

wshobson/agents40k11 repos~1.9kAutomated safety check: PassMIT3 days ago
21
21.Manage HeadersOfficial

Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related…

microsoft/power-platform-skills972—~3kAutomated safety check: NotesMITtoday
22

Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis.

trailofbits/skills7.4k3 repos~3kAutomated safety check: PassCC-BY-SA-4.0yesterday
23

Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis.

trailofbits/skills7.4k4 repos~5.9kAutomated safety check: NotesCC-BY-SA-4.0yesterday
24

Explains authorization in an Arandu Go application: write a Policy, get a security.Grant through security.Authorize, re-authorize each row, and keep tenant isolation.

arandu-io/arandu281—~1.4kAutomated safety check: PassMIT4 days ago
25

Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot).

cdppcorp/KESE-KIT361—~1.4kAutomated safety check: PassMIT6 mo ago
26

Writes and changes pages, layouts, forms and HTMX fragments in an Arandu Go app using its .kyse.go templates, escaping rules and Content-Security-Policy limits.

arandu-io/arandu281—~1.5kAutomated safety check: PassMIT4 days ago
27

Reviews AdvPL and TLPP source against SonarQube rules, ProtheusDOC requirements, security, performance and Protheus conventions, and reports findings by severity.

totvs/engpro-advpl-tlpp-skills143—~2.5kAutomated safety check: PassMIT3 days ago
28

Plans a change to the NGINX Ingress Controller before any code: acceptance criteria, security impact, affected layers, invariants, test surface and an ordered file list.

nginx/kubernetes-ingress5.1k—~1.7kAutomated safety check: PassApache-2.0today
29

Documents how quota-axi keeps its disk cache: location, strict file permissions, no stored secrets, and context-scoped identifiers that stop snapshots crossing accounts.

kunchenguid/quota-axi144—~1.3kAutomated safety check: PassMITtoday
30

Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx.

BlkLeg/CircuitBreaker201—~2.1kAutomated safety check: PassMIT3 days ago
31
31.Code SecurityOfficial

Security guidelines for writing secure code. An agent skill from semgrep/skills.

semgrep/skills322—~1.2kAutomated safety check: PassUnknown2 mo ago
32

Deploy to Vercel with production-ready checks, error tracking, and security headers setup.

AlexPEClub/ai-coding-starter-kit383—~1.2kAutomated safety check: NotesNo licence4 mo ago
33

Run a security vulnerability assessment based on KISA guidelines.

cdppcorp/KESE-KIT361—~2.3kAutomated safety check: PassMIT6 mo ago
34

Lints Dockerfiles with Hadolint for security misconfigurations and best-practice violations, locally and in CI, with strict, balanced and permissive rule templates.

AgentSecOps/SecOpsAgentKit2201 repo~4.4kAutomated safety check: PassUnknown5 mo ago
35
35.Deno Sandbox SDKOfficial

Runs untrusted or AI-generated code in isolated Deno Sandbox microVMs using the @deno/sandbox SDK, with lifecycle, process and streaming guidance.

denoland/skills100—~2.7kAutomated safety check: PassMIT2 mo ago
36

Reviews a diff, module or network surface for exploitable defects, mapping trust boundaries and sinks, then reports only findings with a verified reachable path and a fix.

codewhale-hq/Codewhale41k—~844Automated safety check: PassMITtoday
37

Plans and builds full-stack features with frontend, backend and security handled together, including a written design and a security checklist before any code.

Jeffallan/claude-skills12k—~1.5kAutomated safety check: PassMIT5 days ago
38

Guides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks.

Jeffallan/claude-skills12k—~1.8kAutomated safety check: PassMIT5 days ago
39

Develops WordPress themes, plugins, Gutenberg blocks and WooCommerce features with nonce, escaping and capability checks, phpcs linting and caching tuned for speed.

Jeffallan/claude-skills12k—~1.6kAutomated safety check: PassMIT5 days ago
40

A skill your agent uses when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options.

agentfront/frontmcp146—~7kAutomated safety check: PassApache-2.0yesterday
41

Review or implement security measures for the Static Web Server (SWS) project — path traversal prevention, TLS, security headers, CORS, and input validation

static-web-server/static-web-server2.4k—~1.5kAutomated safety check: NotesApache-2.0today
42

Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

trailofbits/skills7.4k—~3.3kAutomated safety check: NotesCC-BY-SA-4.0yesterday
43

Steers C++ code toward C++20, C++23 and C++26 idioms such as smart pointers, concepts, std::expected and std::print, with a security focus.

trailofbits/skills7.4k—~2.2kAutomated safety check: PassCC-BY-SA-4.0yesterday
44

A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

jellydn/my-ai-tools123—~2.9kAutomated safety check: NotesMITtoday
45

Quarkus security implementation patterns: JWT and OIDC authentication, @RolesAllowed RBAC and SecurityIdentity checks, Bean Validation and custom validators, parameterized Panache queries, BCrypt…

affaan-m/ECC275k1 repo~3.1kAutomated safety check: PassMIT3 days ago
46

Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

sangrokjung/claude-forge8502 repos~7.2kAutomated safety check: PassMIT1 mo ago
47

A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection.

openJiuwen-ai/agent-core442—~1.7kAutomated safety check: NotesApache-2.0today
48

A skill your agent uses when invalid data causes failures deep in execution - validates at every layer data passes through to make bugs structurally impossible rather than temporarily fixed

ed3dai/ed3d-plugins250—~1.2kAutomated safety check: PassNo licence1 mo ago