Agent skills
Skills you can use with AI coding agents, indexed from public GitHub repositories.
-
secure-nextjs-api-routes
A comprehensive security middleware system for Next.js 13+ App Router API routes that provides authentication, rate limiting, CSRF protection, audit logging, and security headers in a composable, production-ready pattern. Use when building secure Next.js APIs that need protection against common web vulnerabilities.
majiayu000/claude-skill-registry 163
-
jwt-token-validator
Jwt Token Validator - Auto-activating skill for Security Fundamentals.
Triggers on: jwt token validator, jwt token validator
Part of the Security Fundamentals skill category.
majiayu000/claude-skill-registry 163
-
secops-engineer
Senior Security Engineer with 12+ years application security experience. Use when implementing authentication/authorization, configuring JWT/OAuth2, conducting security reviews, implementing rate limiting, ensuring GDPR compliance, or performing security scanning.
majiayu000/claude-skill-registry 163
-
reverse-engineering-firmware-analysis
Extended firmware analysis for embedded/IoT images with deep extraction, emulation, and vulnerability assessment.
majiayu000/claude-skill-registry 163
-
atlas-agent-security
Security audits, vulnerability analysis, and security best practices enforcement
majiayu000/claude-skill-registry 163
-
cursor-install-auth
Install Cursor IDE and configure authentication. Triggers on "install cursor",
"setup cursor", "cursor authentication", "cursor login", "cursor license". Use when working with cursor install auth functionality. Trigger with phrases like "cursor install auth", "cursor auth", "cursor".
majiayu000/claude-skill-registry 163
-
IoT UART Console (picocom)
Use picocom to interact with IoT device UART consoles for pentesting operations including device enumeration, vulnerability discovery, bootloader manipulation, and gaining root shells. Use when the user needs to interact with embedded devices, IoT hardware, or serial consoles.
majiayu000/claude-skill-registry 163
-
x-cmd-security
This skill provides comprehensive security assessment and vulnerability management tools through x-cmd CLI, including network reconnaissance with Shodan, vulnerability scanning with OSV, and known exploited vulnerability tracking with KEV. This skill should be used when users need to perform security assessments, vulnerability research, network reconnaissance, or security monitoring from command line interfaces.
majiayu000/claude-skill-registry 163
-
performing-security-testing
Test automate security vulnerability testing covering OWASP Top 10, SQL injection, XSS, CSRF, and authentication issues.
Use when performing security assessments, penetration tests, or vulnerability scans.
Trigger with phrases like "scan for vulnerabilities", "test security", or "run penetration test".
majiayu000/claude-skill-registry 163
-
plugin-auditor
Audit automatically audits AI assistant code plugins for security vulnerabilities, best practices, AI assistant.md compliance, and quality standards when user mentions audit plugin, security review, or best practices check. specific to AI assistant-code-plugins repositor... Use when assessing security or running audits. Trigger with phrases like 'security scan', 'audit', or 'vulnerability'.
majiayu000/claude-skill-registry 163
-
moai-security
Auth0 security specialist covering attack protection, multi-factor authentication, token security, sender constraining, and compliance. Use when implementing Auth0 security features, configuring attack defenses, setting up MFA, or meeting regulatory requirements.
majiayu000/claude-skill-registry 163
-
network-security-scanner
Network Security Scanner - Auto-activating skill for Security Advanced.
Triggers on: network security scanner, network security scanner
Part of the Security Advanced skill category.
majiayu000/claude-skill-registry 163
-
zero-trust-config-helper
Zero Trust Config Helper - Auto-activating skill for Security Advanced.
Triggers on: zero trust config helper, zero trust config helper
Part of the Security Advanced skill category.
majiayu000/claude-skill-registry 163
-
rn-security-audit
Security audit skill for React Native applications. Use when reviewing code for vulnerabilities, detecting leaked secrets (API keys, tokens, credentials), identifying exposed personal data (PII), checking insecure storage, validating authentication flows, reviewing network security, and ensuring compliance with mobile security best practices (OWASP MASVS). Covers both JavaScript/TypeScript and native iOS/Android code.
majiayu000/claude-skill-registry 163
-
csp-config-generator
This skill should be used when the user requests to generate, create, or configure Content Security Policy (CSP) headers for Next.js applications to prevent XSS attacks and control resource loading. It analyzes the application to determine appropriate CSP directives and generates configuration via next.config or middleware. Trigger terms include CSP, Content Security Policy, security headers, XSS protection, generate CSP, configure CSP, strict CSP, nonce-based CSP, CSP directives.
majiayu000/claude-skill-registry 163
-
validating-csrf-protection
Validate CSRF protection implementations for security gaps. Use when reviewing form security or state-changing operations. Trigger with 'validate CSRF', 'check CSRF protection', or 'review token security'.
majiayu000/claude-skill-registry 163
-
fullstack-security
Security and performance - hardening, optimization, auditing
majiayu000/claude-skill-registry 163
-
mongodb-security-admin
Master MongoDB security, authentication, authorization, encryption, and backup. Learn role-based access control, TLS/SSL, encryption, and disaster recovery. Use when securing deployments, managing users, or implementing compliance.
majiayu000/claude-skill-registry 163
-
cloudflare-security-hardening
Use this skill whenever the user wants to harden security for Cloudflare Workers/Pages APIs (e.g. Hono + TypeScript), including WAF-style protections, rate limiting, IP restrictions, secrets handling, and secure headers.
majiayu000/claude-skill-registry 163
-
integrations
External API integrations with OAuth2, async HTTP, and proper error handling
majiayu000/claude-skill-registry 163
-
security-review
セキュリティ脆弱性を自動検出する。認証情報のハードコード、コマンドインジェクション、危険なシェル構文などをチェック。
majiayu000/claude-skill-registry 163
-
violetconnect-woocommerce
WooCommerce REST API authentication and credential-based onboarding patterns for VioletConnect
majiayu000/claude-skill-registry 163
-
iot-security-reviewer
Expert IoT security review covering network security, authentication, encryption, secure boot, and attack surface analysis. Use when reviewing device security, implementing authentication, hardening firmware, conducting security audits, or analyzing embedded systems for vulnerabilities. Particularly valuable for ESP32/RP2350 projects, BLE/WiFi devices, MQTT systems, and mobile IoT applications.
majiayu000/claude-skill-registry 163
-
api-security-testing
API security testing guide covering OWASP API Security Top 10, JWT attacks, OAuth vulnerabilities, GraphQL security, and API fuzzing techniques.
majiayu000/claude-skill-registry 163