Agent skills
Skills you can use with AI coding agents, indexed from public GitHub repositories.
-
crack-hashcat
Advanced password recovery and hash cracking tool supporting multiple algorithms and attack modes. Use when: (1) Performing authorized password auditing and security assessments, (2) Recovering passwords from captured hashes in forensic investigations, (3) Testing password policy strength and complexity, (4) Validating encryption implementations, (5) Conducting security research on cryptographic hash functions, (6) Demonstrating password weakness in penetration testing reports.
majiayu000/claude-skill-registry 163
-
optimization-phase
Standard Operating Procedure for /optimize phase. Covers performance benchmarking, accessibility audit, security review, and code quality checks.
majiayu000/claude-skill-registry 163
-
package-audit
Scan for security vulnerabilities using pnpm audit, Snyk, and automated tools. Use when checking security, before deployments, or resolving CVEs.
majiayu000/claude-skill-registry 163
-
security-prompts-threat-modeling
Security analysis and threat modeling prompt templates for STRIDE analysis, code review, OWASP compliance, and vulnerability assessment. Use for security planning, pre-deployment reviews, and ongoing threat assessment. Triggers include "STRIDE", "threat model", "security review", "code review", "OWASP", "payment security", "security analysis", "vulnerability assessment".
majiayu000/claude-skill-registry 163
-
risk-assessor
Perform comprehensive risk assessments on OSCAL systems including threat modeling, vulnerability analysis, risk scoring, and POA&M generation. Use this skill to evaluate security posture and prioritize remediation efforts.
majiayu000/claude-skill-registry 163
-
access-management
RBAC/ABAC implementation patterns, least privilege access, row-level security, column masking, and access review workflows.
majiayu000/claude-skill-registry 163
-
dependency-auditor
Automated security auditing of project dependencies to identify known vulnerabilities.
majiayu000/claude-skill-registry 163
-
expo-api-audit
Comprehensive audit of Expo/React Native app API integration layer. Use when asked to: (1) Review API interactions, auth handling, or token management, (2) Find hardcoded data or screens bypassing API, (3) Verify user interactions properly sync to backend, (4) Analyze offline behavior and caching, (5) Audit Orval/OpenAPI code generation, (6) Check for API security issues. Supports TanStack Query, Zustand, axios, Expo Router, expo-secure-store, and expo-constants patterns.
majiayu000/claude-skill-registry 163
-
checking-owasp-compliance
Check compliance with OWASP Top 10 security risks and best practices. Use when performing comprehensive security audits. Trigger with 'check OWASP compliance', 'audit web security', or 'validate OWASP'.
majiayu000/claude-skill-registry 163
-
langchain-agents
Expert guidance for building LangChain agents with proper tool binding, memory, and configuration. Use when creating agents, configuring models, or setting up tool integrations in LangConfig.
majiayu000/claude-skill-registry 163
-
cloud-security-posture
Cloud Security Posture - Auto-activating skill for Security Advanced.
Triggers on: cloud security posture, cloud security posture
Part of the Security Advanced skill category.
majiayu000/claude-skill-registry 163
-
cloud-security-configuration
Implement comprehensive cloud security across AWS, Azure, and GCP with IAM, encryption, network security, compliance, and threat detection.
majiayu000/claude-skill-registry 163
-
supabase-security-basics
Execute apply Supabase security best practices for secrets and access control.
Use when securing API keys, implementing least privilege access,
or auditing Supabase security configuration.
Trigger with phrases like "supabase security", "supabase secrets",
"secure supabase", "supabase API key security".
majiayu000/claude-skill-registry 163
-
enforce-security-vigilance
Enforce continuous security vigilance and threat monitoring.
majiayu000/claude-skill-registry 163
-
break-filter-js-from-html
Guidance for bypassing HTML/JavaScript sanitization filters in security testing contexts. This skill should be used when tasked with finding XSS filter bypasses, testing HTML sanitizers, or exploiting parser differentials between server-side filters and browsers. Applies to CTF challenges, authorized penetration testing, and security research involving HTML injection and JavaScript execution through sanitization bypasses.
majiayu000/claude-skill-registry 163
-
expo-api-audit
Comprehensive audit of Expo/React Native app API integration layer. Use when asked to: (1) Review API interactions, auth handling, or token management, (2) Find hardcoded data or screens bypassing API, (3) Verify user interactions properly sync to backend, (4) Analyze offline behavior and caching, (5) Audit Orval/OpenAPI code generation, (6) Check for API security issues. Supports TanStack Query, Zustand, axios, Expo Router, expo-secure-store, and expo-constants patterns.
majiayu000/claude-skill-registry 163
-
security-guidance
Comprehensive security best practices, vulnerability scanning, and security guidance for development workflows with automated security checks and compliance monitoring.
majiayu000/claude-skill-registry 163
-
access-management
RBAC/ABAC implementation patterns, least privilege access, row-level security, column masking, and access review workflows.
majiayu000/claude-skill-registry 163
-
voice-dna-creator
Analyze writing samples to create a comprehensive voice DNA profile. Use when the user wants to capture their unique writing voice, needs to create a voice profile for AI content, or is setting up a new writing system.
majiayu000/claude-skill-registry 163
-
astro-security
Security patterns for Astro lead generation websites on Cloudflare. Forms, headers, bot protection, GDPR. Use for any production lead gen site.
majiayu000/claude-skill-registry 163
-
cursor-agent
A comprehensive skill for using the Cursor CLI agent for various software engineering tasks (updated for 2026 features, includes tmux automation guide).
majiayu000/claude-skill-registry 163
-
mongodb-security-admin
Master MongoDB security, authentication, authorization, encryption, and backup. Learn role-based access control, TLS/SSL, encryption, and disaster recovery. Use when securing deployments, managing users, or implementing compliance.
majiayu000/claude-skill-registry 163
-
fullstack-security
Security and performance - hardening, optimization, auditing
majiayu000/claude-skill-registry 163
-
web-application-pentesting
Lead web application penetration testing coordinator that orchestrates comprehensive security assessments by spawning specialized vulnerability testing subagents. Delegates all vulnerability testing to specialized subagents in .claude/agents directory.
majiayu000/claude-skill-registry 163