Security skills review code for known-dangerous patterns as it is written and run a semantic vulnerability scan on a diff before it ships. Anthropic's security-guidance plugin pairs with the built-in /security-review command.
Anthropic's official security plugin: instant pattern warnings on edits for known-dangerous calls (unsafe deserialisation, raw innerHTML, hard-coded secrets) and a post-turn review that sends the diff to a fast model and feeds high-severity findings back to Claude to fix before you see the response.
Every security skill here is a community skill: an open-source skill folder maintained in a public repository. SkillGild lists and credits it, and the CLI clones it into your agent's skills folder, where it runs locally with your own model.
Open the skill, copy its install command (skillgild install <slug> --agent claude-code) and run it after skillgild login. Community skills are cloned from their public repository into ~/.claude/skills/; hosted skills get a small wrapper and run through the SkillGild MCP server. Use --agent codex, cursor or gemini-cli for other clients.
Are these security skills free?
Community skills are free under their own open-source licenses. Hosted SkillGild skills include free monthly runs; paid skills need a purchase or SkillGild Pro. Each listing shows its access and license.