mcpbeat

Security Skills

1 645 security skills from 285 authors. They hunt for leaked secrets, vulnerabilities and permissions nobody meant to grant. Half of them fit into 2 028 tokens or less — that is what one costs your context window when the agent loads it. 196 ship runnable scripts rather than instructions alone. We also found 192 copies of these same skills sitting in other people's repositories — counted once here, not 192 times.

1 645 unique 285 authors 884 updated this month 119 from vendors

2 028
tokens, median
what a typical one costs in context
196
ship scripts
code that runs, not instructions alone
0
need a server
declared in the skill header
192
copies elsewhere
counted once here, not once per repository

673–720 of 1 645

page 15 of 35
Django Security
loulanyue

Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.

4k tokens
Kotlin Ktor Patterns
loulanyue

Ktor server patterns including routing DSL, plugins, authentication, Koin DI, kotlinx.serialization, WebSockets, and testApplication testing.

5k tokens
Laravel Security
loulanyue

Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.

2k tokens
Perl Security
loulanyue

Comprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies.

3k tokens
Security Review
loulanyue

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

5k tokens zh
Security Scan
loulanyue

Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions.

1k tokens
Springboot Security
loulanyue

Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.

2k tokens
X API
loulanyue

X/Twitter API integration for posting tweets, threads, reading timelines, search, and analytics. Covers OAuth auth patterns, rate limits, and platform-native content posting. Use when the user wants to interact with X programmatically.

1k tokens
Security Review Construction
datadrivenconstruction

Security review checklist for construction software systems. Use when building integrations, APIs, data pipelines, or dashboards for construction projects.

4k tokens
Audit Xcode Security Settings
superagents-lab

|

18k tokens scripts
LLM Security
semgrep

Security guidelines for LLM applications based on OWASP Top 10 for LLM 2025. Use when building LLM apps, reviewing AI security, implementing RAG systems, or asking about LLM vulnerabilities like 'prompt injection' or 'check LLM security'. IMPORTANT: Always consult this skill when building chatbots, AI agents, RAG pipelines, tool-using LLMs, agentic systems, or any application that calls an LLM API (OpenAI, Anthropic, Gemini, etc.) — even if the user doesn't explicitly mention security. Also use when users import 'openai', 'anthropic', 'langchain', 'llamaindex', or similar LLM libraries.

57k tokens
Vulnerability Scanning & Assessment
Masriyan

Dependency auditing, CVE detection, configuration security review, CVSS scoring, and prioritized vulnerability reporting

18k tokens scripts
Threat Hunting & IOC Analysis
Masriyan

IOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation

17k tokens scripts
Exploit Development & Payload Engineering
Masriyan

Proof-of-concept development, payload crafting, shellcode analysis, and exploitation technique research for authorized security testing

9k tokens scripts
Network Security & Traffic Analysis
Masriyan

Network traffic analysis, PCAP parsing, IDS/IPS rule creation, firewall configuration auditing, and network anomaly detection

9k tokens scripts
Web Application Security Testing
Masriyan

OWASP Top 10 testing, injection vulnerability detection, API security assessment, authentication testing, and web vulnerability reporting for authorized assessments

13k tokens scripts
Blue Team Defense & Hardening
Masriyan

System hardening, detection engineering, security baseline monitoring, patch management, defense-in-depth architecture, and security posture improvement

12k tokens scripts
Cryptographic Analysis & Assessment
Masriyan

SSL/TLS auditing, cipher suite analysis, hash algorithm identification, encryption implementation review, and cryptographic weakness detection in code

12k tokens scripts
AI & LLM Security
Masriyan

LLM and AI application security testing — prompt injection, jailbreak resistance, OWASP LLM Top 10 (2025), RAG and agent/tool-use security, model supply chain, and AI red teaming for authorized assessments

6k tokens scripts
Mobile Application Security
Masriyan

Android and iOS application security testing — static and dynamic analysis, APK/IPA inspection, OWASP MASVS/MASTG verification, secure-storage and transport review, and mobile malware triage for authorized assessments

4k tokens scripts
ICS / SCADA Security
Masriyan

Operational Technology and industrial control system security — Purdue model segmentation, industrial protocol analysis (Modbus, DNP3, S7, EtherNet/IP), PLC/HMI exposure, IEC 62443 alignment, and MITRE ATT&CK for ICS, for authorized and safety-conscious assessments

4k tokens scripts
GRC & Compliance
Masriyan

Governance, risk, and compliance — risk assessment and scoring, control mapping across NIST CSF 2.0 / ISO 27001:2022 / SOC 2 / CIS Controls v8, gap analysis, audit evidence preparation, and security policy generation

6k tokens scripts
Aikido Security
membranedev

| Aikido Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with Aikido Security data.

2k tokens
Bright Security
membranedev

| Bright Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with Bright Security data.

2k tokens
Continuum Security Slne
membranedev

| Continuum Security SLNE integration. Manage data, records, and automate workflows. Use when the user wants to interact with Continuum Security SLNE data.

2k tokens
Contrast Security
membranedev

| Contrast Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with Contrast Security data.

2k tokens
Duo Security
membranedev

| Duo Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with Duo Security data.

2k tokens
Security Journey
membranedev

| Security Journey integration. Manage data, records, and automate workflows. Use when the user wants to interact with Security Journey data.

2k tokens
Threat Stack
membranedev

| Threat Stack integration. Manage data, records, and automate workflows. Use when the user wants to interact with Threat Stack data.

2k tokens
Tinfoil Security
membranedev

| Tinfoil Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with Tinfoil Security data.

2k tokens
Ubiq Security
membranedev

| Ubiq Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with Ubiq Security data.

2k tokens
Very Good Security
membranedev

| Very Good Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with Very Good Security data.

2k tokens
Whitehat Security
membranedev

| WhiteHat Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with WhiteHat Security data.

2k tokens
Cliproxy Newapi Stack
majiayu000

在已经过独立验证的 CLIProxyAPI upstream 之上部署 NewAPI 计费层,把 Codex/Claude/Gemini/Qwen 等订阅账号包装成可计费的 OpenAI 兼容 API。本 Skill 不负责新建裸 CLIProxyAPI;负责 NewAPI Docker 部署、容器到宿主桥接、模型计费倍率、参数化额度修正、多账号 OAuth 凭据热加载和双路径验证。当用户说“给现有 cliproxy 加 NewAPI”“配置 NewAPI 渠道接已运行的 cliproxy”“NewAPI 价格不对”“给现有部署加账号”“172.17.0.1 容器网络”或“408 冷却放大故障”时触发。

11k tokens scripts zh
Auth Security
majiayu000

OAuth 2.1 + JWT authentication security best practices. Use when implementing auth, API authorization, token management. Follows RFC 9700 (2025).

11k tokens scripts
Disk Cleaner
majiayu000

当用户要扫描磁盘空间、找出可安全删除的缓存/编译产物/安装包、或交互式释放空间时使用。

2k tokens zh
Ip Check
majiayu000

检测一个 IP 或住宅/机房代理节点的质量——注册库、地理库一致性、ASN/org、风控信誉、黑名单、住宅真实性、BGP 宣告、目标服务(Grok/Claude/ChatGPT)解锁与延迟三角测量。判定该 IP 能否安全用于 AI 服务(避免被地理库误判到别国导致区域锁)。当用户说"查这个 IP"、"这个节点在哪"、"这个代理能用吗"、"IP 质量检测"、"验收住宅 IP"、"为什么被判定在 X 国"、"check ip"、给出 socks5 代理凭证问归属或解锁时使用。

8k tokens scripts zh
Security Threat Model
majiayu000

Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation. Use when touching authentication, authorization, payments, secrets, user data, uploads, webhooks, admin tools, innerHTML/eval/exec, dependency upgrades, or cross-tenant access.

622 tokens
Server Security
majiayu000

服务器安全审计与加固。扫描 SSH、防火墙、端口暴露、文件权限、暴力破解等安全问题,生成报告并提供一键修复。当用户说服务器安全、安全审计、安全检查、安全加固时使用

3k tokens
Entra App Registration vendor
microsoft

Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. USE FOR: create app registration, register Azure AD app, configure OAuth, set up authentication, add API permissions, generate service principal, MSAL example, console app auth, Entra ID setup, Azure AD authentication. DO NOT USE FOR: Key Vault secrets (use azure-keyvault-expiration-audit), general Azure resource security guidance.

21k tokens
Auth vendor
vercel

Authentication integration guidance — Clerk (native Vercel Marketplace), Descope, and Auth0 setup for Next.js applications. Covers middleware auth patterns, sign-in/sign-up flows, and Marketplace provisioning. Use when implementing user authentication.

3k tokens
Security
telagod

Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries, attack surface); reviewing code for vulnerabilities (injection, IDOR, secrets, the OWASP classes); hardening operations (secrets management, detection, patching, incident response); or judging whether a security control/program is real or theater. Also invoke BEFORE any offensive-flavored request (pentest, exploit, credential testing) to apply the authorization gate. Also invoke when designing, reviewing, or hardening an LLM/agent system that reads untrusted content or holds tool/MCP access (prompt injection, excessive agency, MCP supply chain).

14k tokens
Architecting Security
telagod

安全架构与治理:威胁建模 (STRIDE/PASTA/LINDDUN)、零信任身份架构、IAM/SSO/MFA/PAM、合规框架 (SOC2/PCI/HIPAA/GDPR)、DLP、隐私工程、安全控制设计。Use when designing security architecture, threat modeling new systems, implementing zero-trust identity, designing IAM/SSO/PAM, building compliance evidence chains, or planning privacy-by-design.

9k tokens zh
Analyzing Security
telagod

Scans code for security vulnerabilities, detects dangerous patterns, and ensures security decisions are documented. Use when running security scans, auditing code, or checking for OWASP issues, injection risks, or sensitive data leaks. Automatically triggered on new modules, security-related changes, or post-refactor.

4k tokens scripts zh
Defending Applications
telagod

Application security defense knowledge for builders. Covers Web/API/GraphQL hardening (XSS/SQLi/SSRF/IDOR/BOLA/Mass Assignment/deserialization/upload/path traversal), authentication/authorization (OAuth 2.0/OIDC/JWT/Session/Cookie/SAML/SSO), and LLM application security (prompt injection, jailbreak, RAG poisoning, agent privilege escalation, output filtering). Use when designing or reviewing application-layer defenses, fixing CVE-class bugs in your own code, hardening auth flows, or threat-modeling LLM-powered features. For offensive testing see securing-systems/pentest, for incident response see securing-systems/blue-team, for infra-layer hardening see provisioning-infrastructure.

7k tokens zh
Detecting And Responding
telagod

蓝队与紫队工程:检测规则编写、SIEM/EDR 调优、事件响应、数字取证、威胁狩猎、ATT&CK 映射、紫队演练闭环。Use when writing Sigma/YARA detection rules, tuning SIEM noise, responding to security incidents, conducting forensic analysis, hunting threats, or running purple team exercises.

8k tokens zh
Orchestrating Adversarial Reviews
telagod

Multi-agent adversarial-verification orchestration for high-confidence conclusions. Fan-out finders, then verify every finding through a three-prism panel (exploitability / correctness / refutation) that defaults to disbelief, gate fixes behind load-bearing proof tests that catch agents who falsely claim "done/fixed", and roll out behind a build-first exit-code guard. Use when a fan-out task must produce trustworthy results — security audit, code review, research synthesis, migration — and a single agent's self-report cannot be trusted. Composes with securing-systems (what to look for) and shipping-changes (change closed loop); orchestration engine is the Workflow tool.

2k tokens zh
Securing Systems
telagod

Security engineering router for penetration testing, code auditing, red/blue/purple team operations, threat intelligence, and vulnerability research. For specialized application security, cloud security, detection engineering, or security architecture, route to dedicated skills (defending-applications, securing-cloud-and-supply-chain, detecting-and-responding, architecting-security).

16k tokens zh