security

Reduce your security risks by design.

23 skills that add layers of protection to your Claude setup: scanning inbound links and attachments, detecting prompt injection attempts, auditing MCP configs, tracing redirect chains, and keeping API keys in an encrypted vault. Defense-in-depth designed for non-engineers.

Inbound links + attachments scannedVirusTotal-backed file checksPrompt injection detection4-scope encrypted vaultMCP config auditing
23skills in this category
3featured picks
85total in the full pack
Featured picks

Start here

Full catalog

All 23 security skills

email-safety-scan

Tiered safety scanner for URLs AND email attachments.

securityupdated 2026-06

mcp-config-auditor

Audits `.mcp.json` and Claude Code MCP config files across a workspace for plaintext secrets, hardcoded API keys (instea…

securityupdated 2026-05

prompt-injection-detector

Scans web page content, document text, OCR output, or any untrusted text for prompt-injection patterns (hidden instructi…

securityupdated 2026-05

auth-flow-guardian

Blocks password entry on look-alike auth domains.

securityupdated 2026-05

browser-permission-auditor

Reviews installed Chrome, Edge, and Firefox extensions for risky permissions.

securityupdated 2026-05

clipboard-leak-warning

Scans the system clipboard for secrets, PII, or credentials BEFORE you paste anything sensitive into an AI chat (Claude,…

securityupdated 2026-05

dependency-vulnerability-scan

Scans `package.json`/`package-lock.json`, `requirements.txt`/`Pipfile.lock`, `go.mod`/`go.sum`, `Gemfile.lock`, `Cargo.l…

securityupdated 2026-06

dns-email-auth-auditor

Audits a sending domain's email-authentication DNS records — SPF, DKIM (probes common selectors), DMARC, MTA-STS, BIMI, …

securityupdated 2026-05

email-attachment-scan

Scans file attachments for malware.

securityupdated 2026-05

email-link-safety-scan

Tiered URL safety scanner.

securityupdated 2026-05

form-autofill-guard

Inspects HTML forms for fields hidden via type=hidden, display:none, visibility:hidden, off-screen positioning, zero-siz…

securityupdated 2026-05

hallucination-detector

Scans LLM-generated output (code, suggestions, docs) for references to files, functions, classes, or packages that do NO…

securityupdated 2026-05

link-safety-scan

Tiered URL safety scanner for ANY source — emails, web research, pasted links, social DMs, chat messages, search results…

securityupdated 2026-05

mass-send-guard

Detects bulk/mass-send patterns before any outbound message.

securityupdated 2026-05

oauth-scope-auditor

Audits OAuth consent screens for over-broad scope requests.

securityupdated 2026-05

outgoing-message-sanitizer

Single-call safety check before any outbound message — email, Slack, LinkedIn DM, SMS, Teams, public post.

securityupdated 2026-05

outlook-header-analyzer

Diagnoses what happened to an email by parsing its raw message headers.

securityupdated 2026-05

password-breach-checker

Checks if a password (or list of passwords) appears in known data breaches via the Have I Been Pwned (HIBP) Pwned Passwo…

securityupdated 2026-05

pii-redactor

Redacts personally identifiable information (PII) from text — emails, phone numbers, US SSNs, credit cards (Luhn-validat…

securityupdated 2026-05

referrer-leak-warning

Warns when clicking or rendering a link will leak the current URL via the HTTP Referer header.

securityupdated 2026-05

secret-leak-scanner

Scans files, folders, git diffs, clipboard text, or any string for leaked credentials — API keys, OAuth tokens, AWS keys…

securityupdated 2026-05

social-engineering-detector

Analyzes a message (email body, SMS, Slack DM, voicemail transcript, LinkedIn message) for social-engineering and manipu…

securityupdated 2026-05

url-redirect-tracer

Follows HTTP redirects from a shortened URL (bit.ly, tinyurl, t.co, etc.) up to N hops without executing JavaScript, sho…

securityupdated 2026-05

All 23 security skills, installed and healthy.

Get set up in minutesAll 86 skills