CCM
/Skills
SkillsMCPMarketplacesDigestToolsAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Sales & MarketingWeb & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web Crawling
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Skill index
  • MCP index
  • Marketplace index
  • Plugins Reference

Community

  • About
  • Tools
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by mertbuilds.com

Independent project, not affiliated with Anthropic
aradotso avatar

Npm Security Best Practices

aradotso/security-skills
770 installs6 stars
Summary

This walks you through hardening npm, pnpm, and Bun against supply chain attacks like dependency confusion and malicious postinstall scripts. You get actual .npmrc and pnpm-workspace.yaml configs that disable lifecycle scripts, block git dependencies, and enforce a 30-day minimum package age before installation. It covers real incidents like the event-stream attack and the Nx compromise, then shows how to use tools like Socket, npq, and allow-scripts for selective script execution. The Renovate config with minimumReleaseAge is especially useful if you want automated updates with a built-in cooldown period. It's thorough without being academic, which is rare for security guidance.

Install to Claude Code

npx -y skills add aradotso/security-skills --skill npm-security-best-practices --agent claude-code

Installs into .claude/skills of the current project.

CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
inference shell
inference shell
create and run specialised agents in minutes
build now →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
inference shell
inference shell
create and run specialised agents in minutes
build now →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
Files
SKILL.md

Select a file.

Featured
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
inference shell
inference shell
create and run specialised agents in minutes
build now →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
Categories
Security
First SeenJul 14, 2026
View on GitHub

More from aradotso/security-skills

All 58 skills →
  • Malware Awareness Bitdefender Crack Fraud767
  • Security Detections Mcp754
  • Malware Repository Warning748
  • Malware Detection And Reporting747
  • Malware Analysis Warning731
  • Malware Distribution Awareness717
  • Kali Pentest Ai Agent697
  • Bitdefender Malware Analysis686
  • Skill File Security681
  • Bitdefender Malware Investigation677
  • Zen Ai Pentest Framework676
  • Edgesecurityaccess Wireguard Vpn670
  • Sparkfinderoven Security Compliance Skills661
  • Securityclaw Autonomous Soc Agent659
  • Security Compliance Skills Suite Claude652
  • Pentestify Security Report Generator639
  • Awesome Claude Code Security Compliance Suite633
  • Sparkfinderoven R01 Security Compliance Skills630
  • Sparkfinderoven Claude Security Compliance Suite625
  • S800 Vehicle Network Security Testing623
  • Sparkfinderoven Security Compliance Suite622
  • Esaa Security Audit617
  • Foundry Security Spec586
  • Anthropic Cybersecurity Skills1.3k

Recommended

More Security →
aradotso avatar
security-detections-mcp

aradotso/security-skills

security detections mcp
754
6
sickn33 avatar
frontend-security-coder

sickn33/antigravity-awesome-skills

frontend security coder
735
43.1k
ruvnet avatar
security-scan

ruvnet/ruflo

Run full security scans on the codebase using Ruflo security tools. Use when reviewing PRs for security regressions, auditing auth/input-handling code, before production deploys, or when the user asks for a security check at quick/standard/deep depth.
723
67.2k
boshu2 avatar
security-suite

boshu2/agentops

Run composable security analysis.
720
417
sickn33 avatar
web-security-testing

sickn33/antigravity-awesome-skills

web security testing
709
43.1k
sickn33 avatar
api-security-testing

sickn33/antigravity-awesome-skills

api security testing
701
43.1k