Security
Threat models, hardening and the checks that matter before real users arrive.
Security and hardening
Threat model first, then hardening across input, auth, sessions and headers.
What it can touch: Edits code
46Kinstalls
npx skills@latest add addyosmani/agent-skills --skill security-and-hardeningSecurity review
Reviews code for confirmed security weaknesses with data-flow and framework context.
What it can touch: Runs commands · Subagents
17Kinstalls
npx skills@latest add getsentry/skills --skill security-reviewSecrets management
Guides secure credential storage, rotation and use in CI/CD environments.
What it can touch: Edits code · Runs commands · Network
12Kinstalls
npx skills@latest add wshobson/agents --skill secrets-managementFirestore Security Rules Creation
Authors and hardens Firestore rules from the app's data model and query patterns.
What it can touch: Edits code · Writes docs · Runs commands · Subagents · Network
10Kinstalls
npx skills@latest add firebase/agent-skills --skill firestore-rules-creationSecurity best practices
Applies language and framework security guidance when a security review is explicitly requested.
What it can touch: Writes docs · Edits code
9.4Kinstalls
npx skills@latest add openai/skills --skill security-best-practicesCodeQL
Runs and interprets CodeQL static analysis for security-focused code review.
What it can touch: Runs commands · Writes docs · Network
7.6Kinstalls
npx skills@latest add trailofbits/skills --skill codeqlSupply-chain risk auditor
Measures dependency and lockfile supply-chain risk for npm, PyPI and Go projects.
What it can touch: Runs commands · Network · Writes docs
7Kinstalls
npx skills@latest add trailofbits/skills --skill supply-chain-risk-auditorSecurity threat model
Writes a threat model grounded in your repo: trust boundaries, assets and abuse paths.
What it can touch: Writes docs
6.4Kinstalls
npx skills@latest add openai/skills --skill security-threat-modelAgentic Actions Auditor
Audits action-taking agents for unsafe execution, authority, and data-flow risks.
What it can touch: Runs commands · Writes docs
6.1Kinstalls
npx skills@latest add trailofbits/skills --skill agentic-actions-auditorAudit context building
Maps what each function assumes, guarantees and depends on before a security review.
What it can touch: Subagents
6Kinstalls
npx skills@latest add trailofbits/skills --skill audit-context-buildingSecure Code Guardian
Reviews and strengthens application code against common security weaknesses.
What it can touch: Edits code · Runs commands · Writes docs
4.6Kinstalls
npx skills@latest add jeffallan/claude-skills --skill secure-code-guardianGitHub Actions security review
Traces exploitable GitHub Actions workflow paths instead of flagging generic CI patterns.
What it can touch: Runs commands · Subagents
4.2Kinstalls
npx skills@latest add getsentry/skills --skill gha-security-reviewSecurity Ownership Map
Maps repository security ownership, sensitive-code concentration, and maintenance risk.
What it can touch: Runs commands · Uses git
3.4Kinstalls
npx skills@latest add openai/skills --skill security-ownership-mapSTRIDE threat modelling
Builds STRIDE threat models, scores risk with DREAD, scans secrets, and routes specialist work.
What it can touch: Edits code · Writes docs · Runs commands
1.2Kinstalls
npx skills@latest add alirezarezvani/claude-skills --skill senior-securitySecure Launch
A security checklist shaped to your project before it goes live, with approved fixes checked one by one.
What it can touch: Edits code · Runs commands
—not counted yet
npx skills@latest add AaravKashyap12/secure-launch --skill secure-launchSecurity review
Checks application code against a practical security checklist before production work.
What it can touch: Edits code · Runs commands
—not counted yet
npx skills@latest add affaan-m/everything-claude-code --skill security-review
No skill matches “”. Try a stage such as review or debugging, or submit a skill.