BusinessMCP

Best Claude Skills for Security (2026)

Trail of Bits publishes the most serious security skills available: Semgrep for static analysis, Differential Review for security-focused code review of a change, and Supply Chain Risk Auditor for dependency risk. They are licensed CC BY-SA 4.0, which we note on each page.

Addy Osmani’s Security and Hardening covers the application checklist, and Secrets Management covers keeping credentials out of code and CI.

These are defensive skills. We deliberately leave out offensive and penetration-testing skills, which are dual-use.

New to skills? Start with our Claude Skills guide, then come back and pick from the list below.

5 security skills from 3 publishers, listed alphabetically. 15 of their 15 skills.sh security audits are a pass and none is a fail; 2 ship scripts, flagged on their pages. How we vet skills

Top security Claude skills at a glance
SkillPublisherLicenceAudits
Differential ReviewtrailofbitsCC-BY-SA-4.03/3 pass
Secrets ManagementwshobsonMIT3/3 pass
Security and HardeningaddyosmaniMIT3/3 pass
SemgreptrailofbitsCC-BY-SA-4.03/3 pass
Supply Chain Risk AuditortrailofbitsCC-BY-SA-4.03/3 pass

Run security skills on your own data

Open any skill above and press “Use in BusinessMCP” to import it after a free signup.

Get started free

Frequently asked questions

Does the CC BY-SA licence matter for internal use?

Using Trail of Bits’ skills internally is fine; the share-alike terms bite when you redistribute a modified version, which then has to carry the same licence and attribution.

Why do security skills mention SSH keys and credentials?

Because checking where secrets leak is the job. Our scan flags any mention of credential paths; in a security skill that is usually guidance about what to protect, which is why a flag is reviewed by a person rather than treated as proof of harm.