mdskills

Security skills

Auth, vulnerability scanning, secrets, compliance, OWASP. All free to download, install any skill with one command.

91 skills in Security

Service Mesh Expert

Skill

Expert service mesh architect specializing in Istio, Linkerd, and cloud-native networking patterns. Masters traffic management, security policies, observability integration, and multi-cluster mesh con

7.014kby sickn33

Security Requirement Extraction

Skill

Derive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases.

5.013kby sickn33

Slack Bot Builder

Skill

Build Slack apps using the Bolt framework across Python, JavaScript, and Java. Covers Block Kit for rich UIs, interactive components, slash commands, event handling, OAuth installation flows, and Workflow Builder integration. Focus on best practices for production-ready Slack apps. Use when: slack bot, slack app, bolt framework, block kit, slash command.

8.014kby sickn33

Address Github Comments

Skill

Use when you need to address review or issue comments on an open GitHub Pull Request using the gh CLI.

6.013kby sickn33

Firebase

Skill

Firebase gives you a complete backend in minutes - auth, database, storage, functions, hosting. But the ease of setup hides real complexity. Security rules are your last line of defense, and they're often wrong. Firestore queries are limited, and you learn this after you've designed your data model. This skill covers Firebase Authentication, Firestore, Realtime Database, Cloud Functions, Cloud Storage, and Firebase Hosting. Key insight: Firebase is optimized for read-heavy, denormalized data. I

4.013kby sickn33

Security Best Practices

Skill

Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.

8.09.9kby openai

Pipedream MCP Server

Skill

For the best experience, use Pipedream's hosted MCP server which provides: - 2,800+ APIs and 10,000+ tools through a single server - Built-in authentication: no manual token management required - Multiple tool modes: sub-agent and full configuration - Automatic app discovery - Enterprise-grade reliability and security 🚀 Get started: Pipedream MCP Documentation This reference implementation shows

7.011kby PipedreamHQ

Gh Address Comments

Skill

Help address review/issue comments on the open GitHub PR for the current branch using gh CLI; verify gh auth first and prompt the user to authenticate if not logged in.

7.09.9kby openai

secretctl

Skill

Stop pasting API keys into AI chat. When you paste sk-proj-xxx into Claude Code, that secret is now in your conversation history, Anthropic's logs, and potentially exposed to prompt injection attacks. secretctl fixes this. Your AI gets command results, never secret values. Every day, developers paste secrets into AI coding assistants: This is a security incident waiting to happen. - Secrets in con

9.0452by forest6511

decide.fyi

Skill

All servers: 100 vendors, US region, individual plans, stateless, no auth, 100 req/min. Start local dev server: In a separate terminal: Use workflow endpoints when you want one request to return: - decision classification (yes | no | tie) from /api/decide - policy result from the relevant notary endpoint - recommended Zendesk action + tags + private note with requestid - POST https://refund.decide

8.0400by decidefyi

Security Scanning Security Hardening

Skill

Coordinate multi-layer security scanning and hardening across application, infrastructure, and compliance controls.

8.014kby sickn33

Nextjs Supabase Auth

Skill

Expert integration of Supabase Auth with Next.js App Router Use when: supabase auth next, authentication next.js, login supabase, auth middleware, protected route.

5.013kby sickn33

GhidrAssistMCP

Skill

A powerful Ghidra extension that provides an MCP (Model Context Protocol) server, enabling AI assistants and other tools to interact with Ghidra's reverse engineering capabilities through a standardized API. GhidrAssistMCP bridges the gap between AI-powered analysis tools and Ghidra's comprehensive reverse engineering platform. By implementing the Model Context Protocol, this extension allows exte

9.0936by jtang613

Security Review

Skill

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

8.014kby sickn33

Azure Identity Dotnet

Skill

5.013kby sickn33

Better Auth Best Practices

Skill

Skill for integrating Better Auth - the comprehensive TypeScript authentication framework.

7.0473by better-auth

PermitLint — Lint Agent Permissions

Skill

Statically audit Claude Code permission settings and Codex approval, sandbox, and policy configuration without executing project code.

by miki

Codebase Cleanup Deps Audit

Skill

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

7.014kby sickn33

Twilio Communications

Skill

Build communication features with Twilio: SMS messaging, voice calls, WhatsApp Business API, and user verification (2FA). Covers the full spectrum from simple notifications to complex IVR systems and multi-channel authentication. Critical focus on compliance, rate limits, and error handling. Use when: twilio, send SMS, text message, voice call, phone verification.

9.014kby sickn33