SKILL.md packages that extend Claude Code, Cursor, Copilot, and other AI agents.
Tags

claude-skill-registry
Security review and best-practice guidance for web apps and agentic AI systems covering OWASP Top 10:2025, ASVS 5.0, and agent security patterns.

claude-skills
Provides concrete guidance and code examples to implement authentication, authorization, input validation, and other defenses against OWASP Top 10 vulnerabiliti

marketplace
Comprehensive guide and practical snippets to design and harden APIs: authentication, input validation, rate limiting, data protection, and testing patterns to

Anthropic Cybersecurity Skills
Use OWASP Threat Dragon to create data-flow diagrams, apply STRIDE/LINDDUN threat classifications, and generate threat-model reports to guide secure design revi

saas-security
Comprehensive SaaS security audit skill: run domain-based audits, generate checklists, classify risks, and produce prioritized remediation reports.

grapefruit
Automated, checklist-driven mobile security audit aligned to OWASP MASTG v2 for iOS and Android; exports structured markdown findings and remediation guidance.

anthropic-cybersecurity-skills
Structured workflow to test REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR), with techniques for discovery, exploitation checks, and rem

Anthropic Cybersecurity Skills
Guided workflow to identify, validate, and document reflected, stored, and DOM-based XSS using Burp Suite (scanner, repeater, intruder, DOM Invader).

codex_skill
Perform security-focused code reviews aligned to OWASP Top 10 and CWE patterns; produces grouped findings, risk summary, and remediation guidance.

skillsemgrep
Run Semgrep-based security scans to detect vulnerabilities, secrets, and OWASP Top 10 issues, and produce a categorized report with remediation suggestions.

comeonoliver
Auto-activating skill that generates and validates security HTTP headers and provides guidance for implementing secure header configurations.

comeonoliver
Automated guidance and code patterns for implementing robust input validation and secure-coding practices (OWASP-aligned).

antigravity-awesome-skills
Checklist-driven security review for web apps: secrets, input validation, auth, XSS/CSRF, rate limiting, dependency management.

claude-code
Run on-demand security, dependency and code-quality audits to find vulnerabilities, exposed secrets, and maintainability issues.

OStack SaaS
Comprehensive security audit agent that performs OWASP Top 10 analysis, STRIDE threat modeling, and attack surface mapping.

Python Refactoring Skills
Detect and fix security vulnerabilities in Python code, including SQL injection, hardcoded secrets, and weak cryptography using Bandit and Ruff.

Keygraph Shannon
Autonomous AI-driven pentesting tool for web apps and APIs. Performs real exploits to prove vulnerabilities with high success rates.

bb-huge
Advanced methodology for detecting Broken Object Level Authorization and Insecure Direct Object References in APIs.

gStack
Performs professional-grade infrastructure and code security audits, identifying vulnerabilities and producing detailed security posture reports.

awesome-omni-skill
Comprehensive guide for writing secure web apps, ensuring OWASP compliance and protection against XSS, CSRF, SSRF, and SQLi.

claude-skill-registry
Provides automated assistance for analyzing and improving password strength and security fundamentals.

Anthropic Cybersecurity Skills
Comprehensive guide for testing REST and GraphQL APIs for Broken Object Level Authorization (BOLA) and IDOR vulnerabilities.

agentic-skills
Audits LLM-powered features against the OWASP Top 10 for LLM Applications to identify and mitigate prompt injection and data leakage risks.

maverick
Comprehensive security auditing for codebases, offering full-scan reports and diff-based pre-push gates to prevent vulnerability leaks.