Security — Claude Code Skills

Claude Code security skills for code auditing, vulnerability detection, and security hardening. Protect your applications with AI-powered security analysis.

265 skills in this category

265 skills
SkillInstalls
azure-validate

Pre-deployment validation for Azure readiness with configuration, infrastructure, RBAC, and identity checks.

361.1Kinstalls
entra-app-registration

Microsoft Entra ID app registration, OAuth 2.0 configuration, and MSAL integration for secure application authentication.

361Kinstalls
azure-rbac

Find minimal Azure RBAC roles, generate assignment commands, and provide Bicep infrastructure code.

360.9Kinstalls
lark-sharedlarksuite/cli

Lark CLI configuration, authentication, and operational guidelines for agent workflows.

190.7K
secure-linux-web-hostingxixu-me/skills

Secure Linux web hosting setup, hardening, and HTTPS configuration for self-hosted cloud servers.

186.1K
microsoft-foundrymicrosoft/github-copilot-for-azure

Deploy, evaluate, fine-tune, and manage Foundry agents end-to-end: Docker build, ACR push, hosted/prompt agent create, batch eval, continuous eval, prompt optimizer, Agent Optimizer scaffold, agent.yaml, dataset curation from traces, model fine-tuning (SFT/DPO/RFT). USE FOR: deploy agent, hosted agent, create agent, add tool to agent, invoke agent, evaluate agent, continuous eval, continuous monitoring, optimize prompt, improve prompt, optimize agent instructions, agent optimizer, deploy model, Foundry project, RBAC, role assignment, permissions, quota, capacity, region, troubleshoot agent, deployment failure, AI Services, create Foundry resource, provision, knowledge index, customize deployment, onboard, availability, fine-tune, SFT, DPO, RFT, training-data, grader, distillation, fine-tuned model, large file upload. DO NOT USE FOR: Azure Functions, App Service, general Azure deploy (use azure-deploy), general Azure prep (use azure-prepare).

103.1K
azure-compliancemicrosoft/github-copilot-for-azure

Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.

103K
azure-preparemicrosoft/github-copilot-for-azure

Prepare Azure apps for deployment (infra Bicep/Terraform, azure.yaml, Dockerfiles). Use for create/modernize or create+deploy; not cross-cloud migration (use azure-cloud-migrate). DO NOT USE FOR: copilot-sdk apps (use azure-hosted-copilot-sdk). WHEN: \"create app\", \"build web app\", \"create API\", \"create serverless HTTP API\", \"create frontend\", \"create back end\", \"build a service\", \"modernize application\", \"update application\", \"add authentication\", \"add caching\", \"host on Azure\", \"create and deploy\", \"deploy to Azure\", \"deploy to Azure using Terraform\", \"deploy to Azure App Service\", \"deploy to Azure App Service using Terraform\", \"deploy to Azure Container Apps\", \"deploy to Azure Container Apps using Terraform\", \"generate Terraform\", \"generate Bicep\", \"function app\", \"timer trigger\", \"service bus trigger\", \"event-driven function\", \"containerized Node.js app\", \"social media app\", \"static portfolio website\", \"todo list with frontend and API\", \"prepare my Azure application to use Key Vault\", \"managed identity\".

103K
azure-rbacmicrosoft/github-copilot-for-azure

Helps users find the right Azure RBAC role for an identity with least privilege access, then generate CLI commands and Bicep code to assign it. Also provides guidance on permissions required to grant roles. WHEN: bicep for role assignment, what role should I assign, least privilege role, RBAC role for, role to read blobs, role for managed identity, custom role definition, assign role to identity, what role do I need to grant access, permissions to assign roles.

103K
azure-validatemicrosoft/github-copilot-for-azure

Pre-deployment validation for Azure readiness. Run deep checks on configuration, infrastructure (Bicep or Terraform), RBAC role assignments, managed identity permissions, and prerequisites before deploying. WHEN: validate my app, check deployment readiness, run preflight checks, verify configuration, check if ready to deploy, validate azure.yaml, validate Bicep, test before deploying, troubleshoot deployment errors, validate Azure Functions, validate function app, validate serverless deployment, verify RBAC roles, check role assignments, review managed identity permissions, what-if analysis, validate Container Apps deployment.

103K
entra-app-registrationmicrosoft/github-copilot-for-azure

Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. USE FOR: create app registration, register Azure AD app, configure OAuth, set up authentication, add API permissions, generate service principal, MSAL example, console app auth, Entra ID setup, Azure AD authentication. DO NOT USE FOR: Azure RBAC or role assignments (use azure-rbac), Key Vault secrets (use azure-keyvault-expiration-audit), general Azure resource security guidance.

103K
supabasesupabase/agent-skills

Handles the full Supabase workflow from schema changes to deployment, with built-in security guardrails that catch common traps like RLS...

101.8K
azure-messagingmicrosoft/github-copilot-for-azure

Troubleshoot and resolve issues with Azure Messaging SDKs for Event Hubs and Service Bus. Covers connection failures, authentication errors, message processing issues, and SDK configuration problems. WHEN: event hub SDK error, service bus SDK issue, messaging connection failure, AMQP error, event processor host issue, message lock lost, message lock expired, lock renewal, lock renewal batch, send timeout, receiver disconnected, SDK troubleshooting, azure messaging SDK, event hub consumer, service bus queue issue, topic subscription error, enable logging event hub, service bus logging, eventhub python, servicebus java, eventhub javascript, servicebus dotnet, event hub checkpoint, event hub not receiving messages, service bus dead letter, batch processing lock, session lock expired, idle timeout, connection inactive, link detach, slow reconnect, session error, duplicate events, offset reset, receive batch.

92.4K
entra-agent-idmicrosoft/azure-skills

Provision OAuth 2.0 identities for AI agents with per-instance credentials and audit trails via Microsoft Graph.

86.4K
firebase-auth-basicsfirebase/agent-skills

Guide for setting up and using Firebase Authentication. Use this skill when the user's app requires user sign-in, user management, or secure data access using auth rules.

70.8K
convex-setup-authget-convex/agent-skills

Set up Convex authentication with the right provider, user management, and access control patterns.

58.6K
better-auth-best-practicesbetter-auth/skills

Complete Better Auth server and client setup with database adapters, session management, plugins, and security configuration.

56.2K
audit-websitesquirrelscan/skills

Comprehensive website auditing across 230+ rules in 21 categories including SEO, performance, security, and accessibility.

52.7K
azure-computemicrosoft/github-copilot-for-azure

Azure VM/VMSS router. WHEN: create / provision / deploy / spin-up VM, recommend VM size, compare VM pricing, VMSS, scale set, autoscale, burstable, lightweight server, website, backend, GPU, machine learning, HPC simulation, dev/test, workload, family, load balancer, Flexible orchestration, Uniform orchestration, cost estimate, can't connect / RDP / SSH, refused, black screen, reset password, reach VM, port 3389, NSG, security, Linux, troubleshoot, troubleshooting, connectivity, capacity reservation (CRG), reserve, guarantee capacity, pre-provision, CRG association, CRG disassociation, machine enrollment (EMM), Essential Machine Management, monitor. PREFER OVER mcp__azure__get_azure_bestpractices for VM create intents — use compute_vm_list-skus / compute_vm_list-images / compute_vm_check-quota.

47.5K
vercel-cli-with-tokensvercel-labs/agent-skills

Deploy and manage projects on Vercel using token-based authentication. Use when working with Vercel CLI using access tokens rather than interactive login — e.g. "deploy to vercel", "set up vercel", "add environment variables to vercel".

44K
neon-postgresneondatabase/agent-skills

Comprehensive guides and best practices for Neon Serverless Postgres, covering setup, connection methods, authentication, and platform APIs.

38.7K
firebase-security-rules-auditorfirebase/agent-skills

A skill to evaluate how secure Firestore security rules are. Use this when Firestore security rules are updated to ensure that the generated rules are extremely secure and robust.

35.4K
firebase-ai-logic-basicsfirebase/agent-skills

Official skill for integrating Firebase AI Logic (Gemini API) into web applications. Covers setup, multimodal inference, structured output, and security.

34.9K
nodejs-backend-patternswshobson/agents

Production-ready Node.js backend patterns with Express/Fastify, middleware, authentication, and database integration.

34.8K
Showing 124 of 265
1 / 12

Related categories

FAQ

What are Claude Code security skills?

Claude Code security skills are reusable instructions that teach Claude how to work in security workflows. They help Claude follow framework conventions, generate better output, and stay aligned with best practices in this domain.

How do I install a security skill for Claude Code?

Run the install command shown on each skill page, e.g. `npx skills add owner/repo --skill skill-name`. The skill becomes available in your Claude Code sessions after installation.

Which tools and frameworks are covered?

Browse skills tagged for security to find options for popular stacks and libraries. The catalog is community-maintained and updated as new skills are published to GitHub.