Security audit
A prioritised security audit of a vibe-coded app (exposed secrets, RLS or Firebase rules, authentication, input validation, CORS, dependencies) as a blocking/important/minor table with fixes.
Real example
Taken from the skill's “Example” section (in French: the skill answers in your language).
Stack analysée
Next.js (frontend + API routes), Supabase (base de données + authentification).
Priorité · Zone · Problème · Catégorie OWASP · Correctif
Bloquant · Table taches · RLS désactivée ou policy USING (true) : tout le monde lit toutes les tâches · A01 Broken Access Control · Active RLS et ajoute USING (auth.uid() = user_id) sur SELECT
…
Install in two minutes
- 1
claude.ai or Claude Desktop
Settings, capabilities (skills) section, then import the .zip file.
- 2
Claude Code
Unzip the folder into
~/.claude/skills/: the/securite-app-vibecommand appears. - 3
Ask as usual
Claude triggers the skill on its own when your request matches.
The skill helps you learn and produce your own work; it never writes graded work for you. Check your school's rules on AI use.
In the same field
REST API design
Designs a project's REST API: resources, endpoints (method, path, body, status codes), errors, pagination, authentication and a ready-to-copy OpenAPI 3 excerpt in YAML.
MVP spec sheet
Turns an app idea into a one-page MVP spec (problem, users, user stories, features, data model, screens, stack, acceptance criteria) plus the first five prompts for your AI coding tool.
Project CLAUDE.md
Generates a project's CLAUDE.md and its AGENTS.md variant (the open format read by other AI coding tools): commands, architecture, conventions, rules and no-go zones.