Agent skills
Skills you can use with AI coding agents, indexed from public GitHub repositories.
-
break-filter-js-from-html
Guidance for bypassing HTML/JavaScript sanitization filters in security testing contexts. This skill should be used when tasked with finding XSS filter bypasses, testing HTML sanitizers, or exploiting parser differentials between server-side filters and browsers. Applies to CTF challenges, authorized penetration testing, and security research involving HTML injection and JavaScript execution through sanitization bypasses.
majiayu000/claude-skill-registry 163
-
cookie-security-analyzer
Cookie Security Analyzer - Auto-activating skill for Security Fundamentals.
Triggers on: cookie security analyzer, cookie security analyzer
Part of the Security Fundamentals skill category.
majiayu000/claude-skill-registry 163
-
rn-security-audit
Security audit skill for React Native applications. Use when reviewing code for vulnerabilities, detecting leaked secrets (API keys, tokens, credentials), identifying exposed personal data (PII), checking insecure storage, validating authentication flows, reviewing network security, and ensuring compliance with mobile security best practices (OWASP MASVS). Covers both JavaScript/TypeScript and native iOS/Android code.
majiayu000/claude-skill-registry 163
-
security-design
Design security controls and threat mitigations. Use for features involving auth, data, or external exposure.
majiayu000/claude-skill-registry 163
-
slack-auth-security
OAuth flows, token management, and security best practices for Slack apps. Use when implementing app distribution, multi-workspace installations, token storage and rotation, managing scopes and permissions, or securing production Slack applications.
majiayu000/claude-skill-registry 163
-
mtls-service-mesh
Use when implementing service-to-service security, mTLS, or service mesh patterns. Covers mutual TLS, Istio, Linkerd, certificate management, and service mesh security configurations.
majiayu000/claude-skill-registry 163
-
web-resource-checker
Validates essential web resource files (sitemap.xml, robots.txt, llms.txt, security.txt) for compliance with their specifications. Use when user asks about "sitemap validation", "robots.txt check", "llms.txt", "security.txt", "RFC 9116", "RFC 9309", "web resource audit", "サイトマップ", "セキュリティ", or wants to verify crawler/LLM accessibility files.
majiayu000/claude-skill-registry 163
-
agentuity-cli-cloud-scp-download
Download a file using security copy. Requires authentication. Use for Agentuity cloud platform operations
majiayu000/claude-skill-registry 163
-
adversarial-code-review
Review code through hostile perspectives to find bugs, security issues, and unintended consequences the author missed. Use when reviewing PRs, auditing codebases, or before critical deployments.
majiayu000/claude-skill-registry 163
-
dependency-guardian
Automated dependency management with security scanning, update orchestration, and compatibility validation
majiayu000/claude-skill-registry 163
-
symfony:api-platform-security
Secure API Platform resources with security expressions, voters, and operation-level access control
majiayu000/claude-skill-registry 163
-
procurement-playbook
Use to manage legal, security, and procurement workflows for complex deals.
majiayu000/claude-skill-registry 163
-
legacy-codebase-analyzer
Comprehensive legacy codebase analysis skill for technical debt assessment, security vulnerability scanning, performance bottleneck detection, and modernization roadmap generation. Includes 7 Python tools for automated codebase inventory, architecture health analysis, and strategic modernization planning.
majiayu000/claude-skill-registry 163
-
violetconnect-bigcommerce
BigCommerce OAuth, embedded app JWT validation, and pre-registration patterns for VioletConnect
majiayu000/claude-skill-registry 163
-
dependency-vulnerability-checker
Dependency Vulnerability Checker - Auto-activating skill for Security Fundamentals.
Triggers on: dependency vulnerability checker, dependency vulnerability checker
Part of the Security Fundamentals skill category.
majiayu000/claude-skill-registry 163
-
goth-fundamentals
This skill should be used when the user asks to "set up goth", "install goth", "oauth in go", "authentication in golang", "goth package", "goth basics", or mentions "github.com/markbates/goth". Provides foundational guidance for the Goth multi-provider authentication library.
majiayu000/claude-skill-registry 163
-
http-interceptors
Angular 21+ functional HTTP interceptors for auth, error handling, loading states, retry logic, caching, and security best practices
majiayu000/claude-skill-registry 163
-
dependency-security
Dependency security scanning. Use when auditing npm packages for vulnerabilities.
majiayu000/claude-skill-registry 163
-
service-mesh-integrator
Configure service mesh solutions including Istio, Linkerd, and Consul for traffic management, security, and observability in microservices. Activates for service mesh setup, mTLS, traffic routing, and mesh configuration.
majiayu000/claude-skill-registry 163
-
prioritizing-improvements
Use when stakeholders pressure you to change technical priorities and you're tempted to compromise on security-first or call it synthesis - enforces risk-based prioritization over stakeholder preferences
majiayu000/claude-skill-registry 163
-
content-security-policy-generator
Content Security Policy Generator - Auto-activating skill for Security Fundamentals.
Triggers on: content security policy generator, content security policy generator
Part of the Security Fundamentals skill category.
majiayu000/claude-skill-registry 163
-
fastapi-security-expert
Expert in securing FastAPI applications with JWT tokens and Better Auth. Use this when implementing authentication middleware, route protection, and user isolation.
majiayu000/claude-skill-registry 163
-
supabase-auth-storage-realtime-core
Execute Supabase secondary workflow: Auth + Storage + Realtime.
Use when implementing secondary use case,
or complementing primary workflow.
Trigger with phrases like "supabase auth storage realtime",
"implement full stack features with supabase".
majiayu000/claude-skill-registry 163
-
auth
Modern authentication and security patterns for web applications. Expert in JWT tokens, OAuth2 flows, session management, RBAC, MFA, API security, and zero-trust architectures. Framework-agnostic patterns that work with any tech stack.
majiayu000/claude-skill-registry 163