Back to categories
Category

Agent Skills in category: security

260 skills match this category. Browse curated collections and explore related Agent Skills.

csrf-protection

Implement Cross-Site Request Forgery (CSRF) protection for API routes. Use this skill when you need to protect POST/PUT/DELETE endpoints, implement token validation, prevent cross-site attacks, or secure form submissions. Triggers include "CSRF", "cross-site request forgery", "protect form", "token validation", "withCsrf", "CSRF token", "session fixation".

csrftoken-validationapi-securitysession-management
harperaa
harperaa
1

rate-limiting

Implement rate limiting to prevent brute force attacks, spam, and resource abuse. Use this skill when you need to protect endpoints from automated attacks, prevent API abuse, limit request frequency, or control infrastructure costs. Triggers include "rate limiting", "rate limit", "brute force", "prevent spam", "API abuse", "resource exhaustion", "DoS", "withRateLimit", "too many requests", "429 error".

rate-limitingbrute-forceAPI abuseDoS
harperaa
harperaa
1

security-headers

Configure security headers to defend against clickjacking, XSS, MIME confusion, and SSL stripping attacks. Use this skill when you need to set up Content-Security-Policy, X-Frame-Options, HSTS, configure middleware headers, or understand browser security features. Triggers include "security headers", "CSP", "content security policy", "X-Frame-Options", "HSTS", "clickjacking", "MIME confusion", "middleware headers".

security-headerscontent-security-policyX-Frame-OptionsHSTS
harperaa
harperaa
1

security-testing-verification

Test security features and verify implementation before deployment. Use this skill when you need to test CSRF protection, rate limiting, input validation, verify security headers, run security audits, or check the pre-deployment security checklist. Triggers include "test security", "security testing", "verify security", "security checklist", "pre-deployment", "test CSRF", "test rate limit", "security verification".

security-testingcsrfrate-limitingsecurity-headers
harperaa
harperaa
1

password-generator

Generate secure passwords and passphrases with customizable rules. Check password strength, generate bulk passwords, and create memorable passphrases.

password-securitypassword-strengthsecure-passwordspassphrase-generation
dkyazzentwatwa
dkyazzentwatwa
3

hash-calculator

Calculate cryptographic hashes (MD5, SHA1, SHA256, SHA512) for text and files. Compare hashes, verify integrity, and batch process directories.

hashingdata-integritycryptographyfile-verification
dkyazzentwatwa
dkyazzentwatwa
3

data-anonymizer

Detect and mask PII (names, emails, phones, SSN, addresses) in text and CSV files. Multiple masking strategies with reversible tokenization option.

data-protectionPII-maskingtokenizationcsv
dkyazzentwatwa
dkyazzentwatwa
3

varlock

Secure environment variable management with Varlock. Use when handling secrets, API keys, credentials, or any sensitive configuration. Ensures secrets are never exposed in terminals, logs, traces, or Claude's context. Trigger phrases include "environment variables", "secrets", ".env", "API key", "credentials", "sensitive", "Varlock".

secrets-managementenvironment-variablesAPI keycredentials
wrsmith108
wrsmith108
4

dapr-security-scanner

Scans DAPR projects for security issues including plain-text secrets, missing ACLs, insecure configurations, and security best practice violations. Automatically triggers on component file modifications.

daprsecurity-scanningsecrets-managementconfiguration-analysis
Sahib-Sawhney-WH
Sahib-Sawhney-WH
1

dapr-middleware-validator

Automatically validate DAPR HTTP middleware configuration files. Checks for correct middleware types, proper secret references, pipeline ordering, and security best practices. Use when configuring OAuth2, Bearer tokens, OPA policies, rate limiting, or other middleware.

daprmiddlewarevalidationOAuth
Sahib-Sawhney-WH
Sahib-Sawhney-WH
1

fullstack-security

Security and performance - hardening, optimization, auditing

hardeningperformance-optimizationsecurity-auditingfullstack
pluginagentmarketplace
pluginagentmarketplace
1

security

Production-grade security testing skill with OWASP Top 10, vulnerability scanning, penetration testing guidance, and compliance validation

OWASPvulnerability-scanningpenetration-testingcompliance-validation
pluginagentmarketplace
pluginagentmarketplace
1

security-auditor

Activates when user needs security review, vulnerability scanning, or secure coding guidance. Triggers on "security review", "find vulnerabilities", "is this secure", "check for injection", "security audit", "OWASP", "secure this code", or security-related questions.

vulnerability-scanningsecurity-auditsecure-codingOWASP
always-further
always-further
1

ios-security

iOSセキュリティ実装ガイド。認証・認可、データ暗号化、Keychain、証明書ピンニング、App Transport Security、脱獄検知、難読化など、セキュアなiOSアプリケーション開発のベストプラクティス。

iosmobile-securityauthenticationencryption
Gaku52
Gaku52
1

agent-safety

Ensure agent safety - guardrails, content filtering, monitoring, and compliance

agent-safetycontent-filteringguardrailsmonitoring
pluginagentmarketplace
pluginagentmarketplace
1

security-patterns

Security architecture, authentication, authorization, and compliance patterns

security-architectureauthenticationauthorizationcompliance
pluginagentmarketplace
pluginagentmarketplace
1

aws-iam-setup

Configure AWS IAM users, roles, policies, and identity federation

awsiamidentity-managementauthorization
pluginagentmarketplace
pluginagentmarketplace
1

aws-security-best-practices

Implement comprehensive AWS security controls and compliance

AWScloud-securitycomplianceaccess-control
pluginagentmarketplace
pluginagentmarketplace
1

Page 4 of 15 · 260 results