Best Claude Skills for Security (2026)
Trail of Bits publishes the most serious security skills available: Semgrep for static analysis, Differential Review for security-focused code review of a change, and Supply Chain Risk Auditor for dependency risk. They are licensed CC BY-SA 4.0, which we note on each page.
Addy Osmani’s Security and Hardening covers the application checklist, and Secrets Management covers keeping credentials out of code and CI.
These are defensive skills. We deliberately leave out offensive and penetration-testing skills, which are dual-use.
New to skills? Start with our Claude Skills guide, then come back and pick from the list below.
5 security skills from 3 publishers, listed alphabetically. 15 of their 15 skills.sh security audits are a pass and none is a fail; 2 ship scripts, flagged on their pages. How we vet skills
| Skill | Publisher | Licence | Audits |
|---|---|---|---|
| Differential Review | trailofbits | CC-BY-SA-4.0 | 3/3 pass |
| Secrets Management | wshobson | MIT | 3/3 pass |
| Security and Hardening | addyosmani | MIT | 3/3 pass |
| Semgrep | trailofbits | CC-BY-SA-4.0 | 3/3 pass |
| Supply Chain Risk Auditor | trailofbits | CC-BY-SA-4.0 | 3/3 pass |

Semgrep
trailofbits
Runs a Semgrep security scan over a codebase: detects languages, selects rulesets, presents the plan for explicit approval, then runs every approved ruleset through scripts/run-scans.sh, which batches the semgrep…

Supply Chain Risk Auditor
trailofbits
Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script…

Differential Review
trailofbits
Performs security-focused differential review of code changes. Adapts analysis depth to codebase size, uses git blame for context, calculates blast radius by counting callers, checks test coverage of modified code, and…

Security and Hardening
addyosmani
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe…

Secrets Management
wshobson
Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions. Use when handling sensitive credentials, rotating secrets, or securing CI/CD environments.
Run security skills on your own data
Open any skill above and press “Use in BusinessMCP” to import it after a free signup.
Get started freeFrequently asked questions
Does the CC BY-SA licence matter for internal use?
Using Trail of Bits’ skills internally is fine; the share-alike terms bite when you redistribute a modified version, which then has to carry the same licence and attribution.
Why do security skills mention SSH keys and credentials?
Because checking where secrets leak is the job. Our scan flags any mention of credential paths; in a security skill that is usually guidance about what to protect, which is why a flag is reviewed by a person rather than treated as proof of harm.