Best Claude Code Security skills
1,284Ranked by quality score. Browse all 1,284 Security skills
Security skills fall into two groups. The first turns Claude into a reviewer: harnesses like Deepsec that hunt vulnerabilities in a codebase, defence-in-depth checklists, Sigma-rule threat hunting, and audits of authentication, secrets handling and input validation. The second gives Claude reference material a pentester would carry, such as the SecLists wordlists and OWASP testing guides, so its findings cite something more than intuition.
The reason to install one is that AI-generated code fails in predictable ways: string-built SQL, secrets in config, unchecked redirects, permissive CORS. A review skill that runs before you open a pull request catches the class of bug a rushed human reviewer skims past. They are also the right tool when you inherit a service and want a first pass at its attack surface before reading every line yourself.
A skill installs as ~/.claude/skills/<name>/SKILL.md, plus whatever scripts and lists the folder ships; the entry page shows the command. Security skills deserve the same scrutiny they apply to your code, since installing one runs a stranger's instructions with your credentials: read the SKILL.md, note which tools it requests, and prefer entries whose source repository is active. Then start a new session so Claude picks it up.
Top 20 Security skills
Defense in Depth
72Implement multi-layered testing and security best practices.
Free Code
67The free build of Claude Code. All telemetry removed, security-prompt guardrails stripped, all experimental features enabled.
Deepsec
67Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents
Google Workspace Model Armor
65Filter user-generated content for safety
Google Workspace Alert Center
65Manage security alerts
Google Workspace Cloud Identity
65Manage Cloud Identity groups and memberships
T3MP3ST
65autonomous red teaming platform; multi-agent offensive-security meta-harness
Fastapi Review
63Review a FastAPI application for architecture, async correctness, dependency injection, Pydantic schemas, security, performance, and testability.
Pal
63Multi-model AI integration — chat, debugging, code review, planning, security audit ·
Claude Code Security Review
63An AI-powered security review GitHub Action using Claude to analyze code changes for security vulnerabilities.
Anthropic-Cybersecurity-Skills
63734+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Works with Claude Code, GitHub Copilot, OpenAI…
Sanyuan Skills
61Expert code review skill: SOLID, security, performance, error handling, boundary conditions.
Skill Scanner
61Security Scanner for Agent Skills
Security Scan Report
59Generated: 2026-04-10 20:48 UTC Skills scanned: 134 Total findings: 836 Critical: 32 · High: 50 · Safe skills: 100/134
Security Guardian
57Comprehensive security analysis for RTK CLI tool, focusing on command injection, shell escaping, hook security, and malicious input handling.
Cve Mcp Server
57Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…
promptmap
57Security scanner for custom LLM apps. White-box and black-box prompt injection testing.
mcp-scan (Invariant Labs)
56MCP security scanner with proxy mode for real-time scanning without infrastructure changes.
Imcodes
56The IM for agents. Shared Agent Context & Memory, supervised execution, and cross-agent audit across AI providers.
MCP Security Checklist (SlowMist)
55Comprehensive checklist: input validation, rate limiting, RBAC, credential management, container hardening.
These are 20 of 1,284. See every Security skill, searchable and sortable by stars or name.