Topic · Security
Best secure coding skills for Claude Code, Codex and other agents.
- skills
- 105
- official
- 10
Secure coding skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Hardens code against vulnerabilities. An agent skill from penpot/penpot. | penpot/ | 61k | 6 repos | ~4.7k | Automated safety check: Notes | MPL-2.0 | today |
| 2 | Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs. | microsoft/ | 22k | — | ~3.3k | Automated safety check: Pass | MIT | today |
| 3 | Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works. | usestrix/ | 67k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | today |
| 4 | Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 5 | Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report. | ruvnet/ | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | today |
| 6 | Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code. | ZeroDeng01/ | 1.7k | — | ~2.3k | Automated safety check: Pass | MIT | 2 days ago |
| 7 | Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented. | fengshao1227/ | 5.9k | — | ~621 | Automated safety check: Notes | MIT | 22 days ago |
| 8 | Reviews code or recent changes for bugs, security issues, performance problems and maintainability, reporting findings by severity with the reason and a fix. | pretend1111/ | 494 | 1 repo | ~502 | Automated safety check: Pass | Unknown | 5 mo ago |
| 9 | Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge. | TheDecipherist/ | 550 | — | ~1.3k | Automated safety check: Notes | MIT | 5 mo ago |
| 10 | Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams. | rfc-st/ | 378 | — | ~3.7k | Automated safety check: Pass | MIT | yesterday |
| 11 | RenoDX DevKit workflow for tracing swapchain/output passes, SwapChainPass, RGBA8U/UNORM limits, RGBA16F proxy resources, gamma-space float pipelines, HDR10-preferred SDR/HDR output toggles, rare… | clshortfuse/ | 4.4k | — | ~5.6k | Automated safety check: Pass | MIT | today |
| 12 | Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps. | zereight/ | 2k | 1 repo | ~859 | Automated safety check: Notes | MIT | yesterday |
| 13 | Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk. | bodadotsh/ | 859 | — | ~1k | Automated safety check: Warn | MIT | 7 days ago |
| 14 | Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks. | telagod/ | 244 | — | ~552 | Automated safety check: Notes | MIT | 2 mo ago |
| 15 | Shows how to replace unsafe hasattr and setattr loops over user-controlled kwargs with an explicit allowlist when configuring ONNX Runtime option objects. | microsoft/ | 22k | — | ~737 | Automated safety check: Pass | MIT | today |
| 16 | Gives the agent a five-step review routine that reads the full file first, labels each finding as bug, security, performance, style or suggestion, and ends with a summary. | FareedKhan-dev/ | 298 | — | ~809 | Automated safety check: Pass | MIT | 6 mo ago |
| 17 | A skill your agent uses when invalid data causes failures deep in execution, requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally… | sandgardenhq/ | 137 | 3 repos | ~970 | Automated safety check: Pass | Unknown | 16 days ago |
| 18 | Reviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries. | amElnagdy/ | 1.3k | — | ~2.4k | Automated safety check: Pass | MIT | 3 mo ago |
| 19 | Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data. | addyosmani/ | 102k | 1 repo | ~4.4k | Automated safety check: Notes | MIT | 4 days ago |
| 20 | Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related… | microsoft/ | 967 | — | ~3k | Automated safety check: Notes | MIT | today |
| 21 | Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis. | trailofbits/ | 7.4k | 3 repos | ~3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 22 | Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis. | trailofbits/ | 7.4k | 4 repos | ~5.9k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 23 | Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption. | wshobson/ | 40k | 10 repos | ~1.9k | Automated safety check: Pass | MIT | 2 days ago |
| 24 | Explains authorization in an Arandu Go application: write a Policy, get a security.Grant through security.Authorize, re-authorize each row, and keep tenant isolation. | arandu-io/ | 281 | — | ~1.4k | Automated safety check: Pass | MIT | 3 days ago |
| 25 | Generate secure coding prompts and guides for AI tools (Claude, ChatGPT, Cursor, Copilot). | cdppcorp/ | 359 | — | ~1.4k | Automated safety check: Pass | MIT | 6 mo ago |
| 26 | Writes and changes pages, layouts, forms and HTMX fragments in an Arandu Go app using its .kyse.go templates, escaping rules and Content-Security-Policy limits. | arandu-io/ | 281 | — | ~1.5k | Automated safety check: Pass | MIT | 3 days ago |
| 27 | Reviews AdvPL and TLPP source against SonarQube rules, ProtheusDOC requirements, security, performance and Protheus conventions, and reports findings by severity. | totvs/ | 141 | — | ~2.5k | Automated safety check: Pass | MIT | 2 days ago |
| 28 | Plans a change to the NGINX Ingress Controller before any code: acceptance criteria, security impact, affected layers, invariants, test surface and an ordered file list. | nginx/ | 5.1k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | today |
| 29 | Documents how quota-axi keeps its disk cache: location, strict file permissions, no stored secrets, and context-scoped identifiers that stop snapshots crossing accounts. | kunchenguid/ | 144 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 30 | Enforces Circuit Breaker security hardening conventions across backend, frontend, Docker, and nginx. | BlkLeg/ | 201 | — | ~2.1k | Automated safety check: Pass | MIT | 2 days ago |
| 31 | Security guidelines for writing secure code. An agent skill from semgrep/skills. | semgrep/ | 322 | — | ~1.2k | Automated safety check: Pass | Unknown | 2 mo ago |
| 32 | 32.Deploy Deploy to Vercel with production-ready checks, error tracking, and security headers setup. | AlexPEClub/ | 383 | — | ~1.2k | Automated safety check: Notes | No licence | 4 mo ago |
| 33 | Run a security vulnerability assessment based on KISA guidelines. | cdppcorp/ | 359 | — | ~2.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 34 | Lints Dockerfiles with Hadolint for security misconfigurations and best-practice violations, locally and in CI, with strict, balanced and permissive rule templates. | AgentSecOps/ | 219 | 1 repo | ~4.4k | Automated safety check: Pass | Unknown | 5 mo ago |
| 35 | Runs untrusted or AI-generated code in isolated Deno Sandbox microVMs using the @deno/sandbox SDK, with lifecycle, process and streaming guidance. | denoland/ | 100 | — | ~2.7k | Automated safety check: Pass | MIT | 2 mo ago |
| 36 | Reviews a diff, module or network surface for exploitable defects, mapping trust boundaries and sinks, then reports only findings with a verified reachable path and a fix. | codewhale-hq/ | 41k | — | ~844 | Automated safety check: Pass | MIT | today |
| 37 | Plans and builds full-stack features with frontend, backend and security handled together, including a written design and a security checklist before any code. | Jeffallan/ | 12k | — | ~1.5k | Automated safety check: Pass | MIT | 4 days ago |
| 38 | Guides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks. | Jeffallan/ | 12k | — | ~1.8k | Automated safety check: Pass | MIT | 4 days ago |
| 39 | Develops WordPress themes, plugins, Gutenberg blocks and WooCommerce features with nonce, escaping and capability checks, phpcs linting and caching tuned for speed. | Jeffallan/ | 12k | — | ~1.6k | Automated safety check: Pass | MIT | 4 days ago |
| 40 | A skill your agent uses when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options. | agentfront/ | 146 | — | ~7k | Automated safety check: Pass | Apache-2.0 | today |
| 41 | 41.Security Review or implement security measures for the Static Web Server (SWS) project — path traversal prevention, TLS, security headers, CORS, and input validation | static-web-server/ | 2.4k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 42 | Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 43 | Steers C++ code toward C++20, C++23 and C++26 idioms such as smart pointers, concepts, std::expected and std::print, with a security focus. | trailofbits/ | 7.4k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 44 | A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance. | jellydn/ | 123 | — | ~2.9k | Automated safety check: Notes | MIT | today |
| 45 | Quarkus security implementation patterns: JWT and OIDC authentication, @RolesAllowed RBAC and SecurityIdentity checks, Bean Validation and custom validators, parameterized Panache queries, BCrypt… | affaan-m/ | 274k | 1 repo | ~3.1k | Automated safety check: Pass | MIT | 2 days ago |
| 46 | Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and… | sangrokjung/ | 849 | 2 repos | ~7.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 47 | A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection. | openJiuwen-ai/ | 441 | — | ~1.7k | Automated safety check: Notes | Apache-2.0 | 7 days ago |
| 48 | A skill your agent uses when invalid data causes failures deep in execution - validates at every layer data passes through to make bugs structurally impossible rather than temporarily fixed | ed3dai/ | 250 | — | ~1.2k | Automated safety check: Pass | No licence | 1 mo ago |
Questions, answered from the data.
What is the best secure coding skill?
Security And Hardening from penpot/penpot ranks first of the 105 secure coding skills listed here, with the highest score: its repository has 61k GitHub stars, 6 other GitHub owners carry a copy, its SKILL.md loads about 4.7k tokens and it has informational notes only in the automated safety check. Next come ONNX Runtime Shape Inference Safety Audit and Fix Strix Security Findings.
Which secure coding skills are official?
10 of the 105 secure coding skills are official, published by the vendor's own GitHub organization: ONNX Runtime Shape Inference Safety Audit, CodeQL Security Scan, Python kwargs setattr Allowlist, Manage Headers, Sharp Edges Analysis and 5 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
Category
More topics in Security
- Security review611
- Web application vulnerabilities460
- Vulnerability scanning303
- Static analysis and SAST281
- Security operations248
- Supply chain security242
- Threat modeling207
- Penetration testing183
- Cryptography155
- Prompt injection and agent security154
- Red teaming and adversary simulation147
- Reverse engineering and malware132
- OSINT117
- Cloud security90
- Digital forensics86
- Smart contract auditing80
- Fuzzing75
- Bug bounty74
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails34