Agent skill

Secure Me

by asgeirtj in asgeirtj/system_prompts_leaks

Find compromised passwords in the user's personal accounts, prepare official reset flows, hand over before the user enters and submits each new credential, and help verify the change and authorized…

CC0-1.0Auto-check passed

Install Secure Me

skills CLI
$ npx skills add asgeirtj/system_prompts_leaks --skill secure-me -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install asgeirtj/system_prompts_leaks secure-me --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/asgeirtj/system_prompts_leaks.git skills-src && mkdir -p .claude/skills && cp -r skills-src/OpenAI/dots/skills/secure-me .claude/skills/secure-me && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secure-me
GitHub stars
69k
Token cost
~1.3k tokens
SKILL.md length
789 words
Files
1
Skills in repo
128
Repo updated
First seen
Licence
CC0-1.0

At a glance

Find compromised passwords in the user's personal accounts, prepare official reset flows, hand over before the user enters and submits each new credential, and help verify the change and authorized…

  • SKILL.md covers Find compromised passwords, Prepare the change and hand over, Verify and finish and Examples
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Secure Me is an agent skill from asgeirtj/system_prompts_leaks. Find compromised passwords in the user's personal accounts, prepare official reset flows, hand over before the user enters and submits each new credential, and help verify the change and authorized password-manager save.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Documented system prompts from Anthropic - Claude Fable 5.1, Opus 5.5, Claude Design, Claude Code. OpenAI - ChatGPT GPT-6-Astra, Codex. Google - Gemini 3.8 Flash, 3.1 Pro… The licence is CC0-1.0.

Example prompts

  • “/secure-me”

What it can do on your machine

Read from SKILL.md and the folder at commit 60d44cc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secure Me loads about 1.3k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 789 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from asgeirtj/system_prompts_leaks at commit 60d44cc, republished under its CC0-1.0 licence (© asgeirtj). 789 words, ~1,321 tokens.

Download SKILL.mdSave it as .claude/skills/secure-me/SKILL.md (or your agent's skills folder).
name
secure-me
description
Find compromised passwords in the user's personal accounts, prepare official reset flows, hand over before the user enters and submits each new credential, and help verify the change and authorized password-manager save.

dot Secure Me

Find exposed passwords, prepare each provider's official reset flow, and help the user verify what was changed and saved. The user enters, confirms, and submits every new credential.

Find compromised passwords

  • Start with the chosen password manager, such as Chrome, and check its current security report and what the available tools can inspect. Use the user's existing account choices and connections. Report which accounts were covered and any gaps.
  • Look for a current compromised-password warning, a verified provider notice, or a disclosure the user confirms. Check whether the warning concerns an old vault entry or a password already changed. An email address in an old breach is not enough to conclude that the current password was exposed. Separate confirmed and uncertain findings.
  • Include other accounts the manager reports as using the same exposed password, without extracting or comparing secret values. Missing, weak, or reused passwords alone are outside this cleanup. Start with compromised email, identity-provider, and password-manager accounts that could unlock others, then financial and other sensitive accounts.

Prepare the change and hand over

  • If the user asked for a check, report affected accounts and explain the next step. If they asked for help fixing them, prepare the official flow account by account. Follow <confirmation_policy>: ask the user to take over before any new credential is entered. The user must enter it, confirm it, and submit the change themselves, even if they asked the user's dot to fix everything.
  • Keep passwords and authentication codes inside a protected manager or official provider flow. Never ask for them or a vault export in chat, or expose them in page inspection, screenshots, logs, or notes. Say "I can't see your passwords" only when the integration enforces that. The user's dot only needs account references and non-secret status.
  • Reach the provider's genuine account settings independently of a warning email. Prepare its supported change or reset flow, show the user how to generate a unique password in their manager, and make sure they can recover it before they submit. Keep the last working session open. The user also handles any required sign-in, biometric, or multifactor step.
  • After the user completes the change, follow <confirmation_policy> for saving the specific credential in the chosen manager. If that save is already explicitly authorized and a protected tool can do it without exposing the secret, use it; otherwise ask immediately before saving or guide the user through it. Check the exact account and domain. If the provider accepted the change but the save failed, stop work on other accounts until this one can be recovered.
Show full SKILL.md (360 more words)Show less

Verify and finish

  • Track changed, saved, and sign-in verified separately. Use provider or manager status where it is available and label anything reported only by the user. Where supported, guide a fresh sign-in without risking lockout; an already open session is not proof. Say which checks still need the user.
  • Keep a minimal private checkpoint with account references, findings, authorization, results, and next steps; never include secrets. After an interruption or unclear response, inspect the current provider and manager status before suggesting another reset.
  • Report how many distinct accounts were changed, saved, and verified, and what remains. If nothing was flagged, say which sources you checked. If there is evidence of stolen sessions or a compromised device, explain that a password change may leave that risk unresolved.
  • Keep the completion message short. A little celebration is fine after the work is verified. Only add personal details supported by evidence, and stay within the requested cleanup.

Examples

  • User: "Chrome says four passwords were exposed. Help me fix them and save the replacements in Chrome."
    • dot: "I found four current warnings. I'll open each official reset page. You'll need to enter, confirm, and submit each new password. I'll keep track of what's changed and saved"
    • dot: When the evidence supports it: "All four changes and Chrome saves are confirmed 🎉 Three fresh sign-ins worked but the fourth still needs you."
  • User: "A breach alert says my email was leaked. Do I need to reset this password?"
    • dot: "The alert names your email, but I haven't found evidence that your current password was exposed. I'll take a look at your password manager's current report before recommending a reset"
  • User: "The site accepted my new password, but Chrome didn't save it. Can we do the next one?"
    • dot: "Let's recover this account in Chrome first. Keep the site open and I'll guide you through the protected save. Then we'll continue."
  • User: "Just do the last reset for me. I can send you the code."
    • dot: "Don't share the code with me. I can open the official page and show you what to do, but you'll need to enter, confirm, and submit the new password yourself"

© asgeirtj, CC0-1.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in OpenAI/dots/skills/secure-me of asgeirtj/system_prompts_leaks.

Open the folder on GitHubat commit 60d44cc

Compare with similar skills

Secure Me next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secure Me compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secure Me this skillasgeirtj/system_prompts_leaks69k—~1.3kAutomated safety check: PassCC0-1.0
Password Field Securitythedaviddias/Front-End-Checklist74k—~458Automated safety check: PassMIT
Detecting Email Account Compromisemukul975/Anthropic-Cybersecurity-Skills34k—~823Automated safety check: PassApache-2.0
Container Security Hardeningsickn33/agentic-awesome-skills47k1 repos~1kAutomated safety check: NotesMIT
Security and Hardeningaddyosmani/agent-skills104k1 repos~4.4kAutomated safety check: NotesMIT
Security Scanaffaan-m/ECC276k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Password Field Security

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing headers, forms, cookies, or third-party integrations related to Secure password input fields.

    74k GitHub stars~458 tokensUpdated 4 days ago
    Auto-check passed
  • Detecting Email Account Compromise

    mukul975/Anthropic-Cybersecurity-Skills

    Detect compromised O365 and Google Workspace email accounts by analyzing Unified Audit Logs and Azure AD sign-in logs for impossible travel, inbox rule creation/deletion (Set-InboxRule…

    34k GitHub stars~823 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Container Security Hardening

    sickn33/agentic-awesome-skills

    Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls.

    47k GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check: notes
  • Security and Hardening

    addyosmani/agent-skills

    Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

    104k GitHub starsUsed in 1 repo~4.4k tokens
    SecurityAuto-check: notes
  • Security Scan

    affaan-m/ECC

    Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield.

    276k GitHub starsUsed in 5 repos~1.1k tokens
    Agent WorkflowsAuto-check passed
  • Quarkus Security

    affaan-m/ECC

    Quarkus security implementation patterns: JWT and OIDC authentication, @RolesAllowed RBAC and SecurityIdentity checks, Bean Validation and custom validators, parameterized Panache queries, BCrypt…

    276k GitHub starsUsed in 1 repo~3.1k tokens
    Backend & APIsAuto-check passed

More from asgeirtj/system_prompts_leaks

All 128 skills in this repo
  • Fleet Manager for Agent Sessions

    asgeirtj/system_prompts_leaks

    Shows one digest of coding-agent sessions across your connected machines and lets you open, read, steer, approve, stop and close them, over Herdr, tmux or MSP.

    69k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Muse Code Product Doctor

    asgeirtj/system_prompts_leaks

    Diagnoses a Muse Code installation's own failures from binary and session evidence, instead of treating the report as an ordinary repository bug.

    69k GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • DOCX

    asgeirtj/system_prompts_leaks

    A skill your agent uses whenever the user wants to create, read, edit, or manipulate Word documents (.docx) or Word templates (.dotx).

    69k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Agents Project Coordinator

    asgeirtj/system_prompts_leaks

    Runs a goal as a project in which the agent coordinates separate agent threads, judging when to split the work, and interviews you first when nothing can be verified.

    69k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Muse Plugin Creator

    asgeirtj/system_prompts_leaks

    Creates and validates a new native Muse plugin package in the current workspace, limited to five capability families, and leaves installation to you.

    69k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Deep Research

    asgeirtj/system_prompts_leaks

    A skill your agent uses when the user's prompt requires (1) researching a topic across multiple sources, comparing options or alternatives, analyzing trends or history, understanding markets or…

    69k GitHub stars~3.3k tokensUpdated today
    Auto-check passed

Questions about Secure Me

What does Secure Me do?

Find compromised passwords in the user's personal accounts, prepare official reset flows, hand over before the user enters and submits each new credential, and help verify the change and authorized…. Secure Me is an agent skill from asgeirtj/system_prompts_leaks. Find compromised passwords in the user's personal accounts, prepare official reset flows, hand over before the user enters and submits each new credential, and help verify the change and authorized password-manager save.

How do I install Secure Me in Claude Code?

Run `npx skills add asgeirtj/system_prompts_leaks --skill secure-me -a claude-code`. Or copy the skill folder (OpenAI/dots/skills/secure-me in asgeirtj/system_prompts_leaks) into .claude/skills/secure-me in your project. Claude Code loads it when a task matches its description.

How do I install Secure Me in Codex?

Run `npx skills add asgeirtj/system_prompts_leaks --skill secure-me -a codex`. Or copy the skill folder (OpenAI/dots/skills/secure-me in asgeirtj/system_prompts_leaks) into .agents/skills/secure-me in your project. Codex loads it when a task matches its description.

Can I use Secure Me in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add asgeirtj/system_prompts_leaks --skill secure-me -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secure-me, .gemini/skills/secure-me, .github/skills/secure-me and .opencode/skills/secure-me in your project.

What does Secure Me need to run?

SKILL.md names no scripts, command-line tools or credentials: Secure Me is instructions for the agent only.

Does Secure Me access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Secure Me safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Secure Me use?

Secure Me is published under the CC0-1.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secure Me use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secure Me?

Skills that share tags, products or a category with Secure Me: Password Field Security (thedaviddias/Front-End-Checklist, 74k stars), Detecting Email Account Compromise (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Container Security Hardening (sickn33/agentic-awesome-skills, 47k stars) and Security and Hardening (addyosmani/agent-skills, 104k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secure Me?

asgeirtj (a GitHub user) maintains it in asgeirtj/system_prompts_leaks, which has 69,280 GitHub stars. The repository holds 128 skills in this directory. The repository was last updated on October 10, 2026.

Source: asgeirtj/system_prompts_leaks on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.