Best Security Skills for Claude Code
Skills for finding and fixing security problems in your own code: diff review for vulnerability classes, hardening input handling and authentication, secure full-stack implementation patterns, and structured audit reports. Every skill is scored on the same six-dimension rubric, including the security dimension that carries the site-wide veto.
Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, ins…
Excellent reviewer skill: intent-summarization checkpoint, two-stage spec-then-quality review architecture, prioritized report with verdict, allowed-tools scoped to read-only; only lacks an explicit When-Not trigger boundary.
Builds security-focused full-stack web applications by implementing integrated frontend and backe…
Top-tier full-stack skill: description explicitly differentiates from frontend/backend-only skills, security checklist gate before coding, ten scoped references, and a three-perspective annotated example.
Use when implementing authentication/authorization, securing user input, or preventing OWASP Top …
Excellent secure-coding skill: explicit validation checkpoints with concrete attack payloads, complete hardened login flow, JWT secret from env, and the only description in this batch that includes a When-Not redirection clause.
Identifies security vulnerabilities, generates structured audit reports with severity ratings, an…
Well-gated security audit skill: written-authorization and rules-of-engagement checks before any active testing, mandatory manual review, CVSS classification, and stakeholder confirmation; pentest reference contains offensive payloads but targets placeholders and is authorization-gated.
Hardens code against vulnerabilities. Use when handling user input, authentication, data storage,…
Deep and current security skill covering STRIDE threat modeling, SSRF with TOCTOU caveat, supply-chain hygiene, privacy, and OWASP LLM risks; slightly overlong single file and a missing security-checklist.md reference are the only flaws.
Score comparison
How the top 5 compare across the six evaluation dimensions (0–10). Full written rationale for every score is on each skill's page.
| Skill | Overall | Trigger | Structure | Workflow | Content | Engineering | Security |
|---|---|---|---|---|---|---|---|
| code-reviewer | 9.4 | 8.5 | 9.3 | 9.2 | 10.0 | 10.0 | 10.0 |
| fullstack-guardian | 9.3 | 8.5 | 10.0 | 8.8 | 9.0 | 10.0 | 10.0 |
| secure-code-guardian | 9.3 | 9.5 | 9.3 | 8.8 | 9.0 | 9.0 | 10.0 |
| security-reviewer | 9.0 | 8.5 | 9.3 | 8.8 | 9.0 | 9.0 | 9.5 |
| security-and-hardening | 8.5 | 8.0 | 6.0 | 8.8 | 10.0 | 8.0 | 10.0 |
FAQ
What is a security skill for Claude Code?
A package that gives your agent a security practice: reading a diff for injection, authentication and access-control mistakes; hardening a handler that takes user input; or writing an audit report with severity, evidence, and remediation steps. It fires when you review or ship code that touches a trust boundary.
Do these replace a SAST scanner or dependency audit?
No. They read code the way a reviewer does — strong on logic-level problems (a missing authorization check, a trust decision made in the wrong layer), weak at matching known-CVE signatures across a large dependency tree. Run both: scanners for known patterns, these for reasoning about the code in front of you.
How does Skill123 test security claims?
Statically, every skill gets a capability manifest — what data it reads, what side effects it has, which hosts it contacts, whether it touches credentials — and that manifest is compared against what its trigger description promises. The gap between the two is the strongest signal we have. A confirmed backdoor, credential theft, or exfiltration finding vetoes the total score at 39/100 no matter how good the engineering is.
Have these skills been adversarially tested?
Partially — and the honest answer matters on this page. security-and-hardening went through the dynamic injection harness and scored 7.5/10 PARTIAL: its restricted-toolset tier held 4/4, but the declared-capabilities tier dropped the adversarial-overreach probe. That is exactly why we publish the number. A skill with "security" in its name is not automatically resistant to being talked past its own rules. The other four carry static scores only.
Every skill here was scored on the same six-dimension rubric — the full scorecard with written rationale is on each skill's page. See more in the Developer Tools skill collection, or browse all evaluated skills.
