Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
getstoreconnect Bundle Storeconnect Debug Performance 2Instrument and speed up StoreConnect Liquid — the web Console, the debug and timer tags, drop and record introspection, cache key design and invalidation, collection and pagination cost, per-item hot paths, asset weight, and client-side batching. Use when you need to instrument a template that renders blank or wrong, cache a fragment, or cut queries on a slow page, when cached output is stale or reaches the wrong visitor, and before adding any debug, timer, or cache tag. For an audit that changes nothing use storeconnect-theme-review.
-
addxai Skill PrometheusQuery Prometheus monitoring metrics and alert rules. Use when the user needs to check CPU/memory/disk utilization, service health, audit alert rules, analyze capacity trends, or mentions Prometheus, PromQL, metrics monitoring, or targets.
-
counterpointconsulting Skill Security And Hardening 2Apply baseline API security checks for input handling, auth, data access, and error boundaries.
-
surya8991 Skill Security Audit 2Security auditing skill for web applications and codebases. Scans for OWASP Top 10, dependency vulnerabilities, secrets exposure, XSS/CSRF/injection flaws, auth weaknesses, and misconfigurations. Use when task involves security scan, vulnerability assessment, pen test review, threat modeling, or hardening a codebase.
-
databrickslabs Bundle Databricks Unity CatalogUnity Catalog system tables and volumes. Use when querying system tables (audit, lineage, billing) or working with volume file operations (upload, download, list files in /Volumes/).
-
chenwei791129 Skill Spectra Audit 2Audit changed code for security sharp edges — dangerous defaults, type confusion, and silent failures
-
theonize Skill Critic 2Audit the reasoning of a compiled exegetical analysis — cross-section coherence, evidentiary proportion, exegetical fallacies, unstated counter-readings, and application groundedness. Use when a draft study needs its arguments tested before publication, or when checking whether conclusions are proportional to the evidence offered.
-
felinics Bundle Skill CreatorCreate new skills, modify and improve existing skills, and measure skill performance. Use when users want to create a skill from scratch, edit, or optimize an existing skill, run evals to test a skill, benchmark skill performance with variance analysis, or optimize a skill's description for better triggering accuracy.
-
gnekt Skill Defrag 2Weekly vault defragmentation. Runs a 5-phase structural audit: inbox hygiene, area completeness, project archival, MOC refresh, tag consistency, structure evolution, and generates a report. Triggers: EN: "defragment the vault", "reorganize the vault", "structural maintenance", "vault defrag", "weekly defrag". IT: "deframmenta il vault", "riorganizza il vault", "manutenzione strutturale", "defrag settimanale". FR: "defragmenter le vault", "reorganiser le vault". ES: "desfragmentar el vault", "reorganizar el vault". DE: "Vault defragmentieren", "Vault reorganisieren". PT: "desfragmentar o vault", "reorganizar o vault".
-
gnekt Skill Deep Clean 2Extended vault cleanup: full audit PLUS stale content scan, outdated references, content quality review, redundant tags, broken external links, and template compliance. Triggers: EN: "deep clean", "deep cleanup", "thorough cleanup", "the vault is a mess". IT: "pulizia profonda", "pulizia completa", "il vault è un disastro". FR: "nettoyage en profondeur", "le vault est un désordre". ES: "limpieza profunda", "el vault es un desastre". DE: "Tiefenreinigung", "das Vault ist ein Chaos". PT: "limpeza profunda", "o vault está uma bagunça".
-
gnekt Skill Tag Garden 2Analyze all vault tags: find unused, orphan, near-duplicate, over-used, and under-used tags. Suggest merges and cleanup actions. Triggers: EN: "tag garden", "clean up tags", "tag cleanup", "tag audit". IT: "tag garden", "pulizia tag", "revisione tag". FR: "jardinage des tags", "nettoyer les tags". ES: "jardín de tags", "limpiar tags". DE: "Tag-Garten", "Tags aufräumen". PT: "jardim de tags", "limpar tags".
-
cmdecker95 Skill ReviewReview code changes with the Bugbot or Security Review subagent.
Audited -
masriyan Bundle Reconnaissance Osint AutomationPassive and active reconnaissance, subdomain enumeration, DNS analysis, technology fingerprinting, and OSINT data correlation for authorized security assessments
-
masriyan Bundle Web Application Security TestingOWASP Top 10 testing, injection vulnerability detection, API security assessment, authentication testing, and web vulnerability reporting for authorized assessments
-
masriyan Bundle Log Analysis Siem IntegrationSecurity log parsing, anomaly detection, SIEM query building, Sigma rule creation, and correlation rule development across Splunk, Elastic, QRadar, and Microsoft Sentinel
-
masriyan Bundle Threat Hunting Ioc AnalysisIOC extraction, threat intelligence correlation, MITRE ATT&CK mapping, hunt hypothesis generation, and detection rule creation
-
masriyan Bundle Grc ComplianceGovernance, risk, and compliance — risk assessment and scoring, control mapping across NIST CSF 2.0 / ISO 27001:2022 / SOC 2 / CIS Controls v8, gap analysis, audit evidence preparation, and security policy generation
-
masriyan Bundle Mobile Application SecurityAndroid and iOS application security testing — static and dynamic analysis, APK/IPA inspection, OWASP MASVS/MASTG verification, secure-storage and transport review, and mobile malware triage for authorized assessments
-
masriyan Bundle Network Security Traffic AnalysisNetwork traffic analysis, PCAP parsing, IDS/IPS rule creation, firewall configuration auditing, and network anomaly detection
-
masriyan Bundle Blue Team Defense HardeningSystem hardening, detection engineering, security baseline monitoring, patch management, defense-in-depth architecture, and security posture improvement
-
masriyan Bundle Exploit Development Payload EngineeringProof-of-concept development, payload crafting, shellcode analysis, and exploitation technique research for authorized security testing
-
masriyan Bundle Vulnerability Scanning AssessmentDependency auditing, CVE detection, configuration security review, CVSS scoring, and prioritized vulnerability reporting
-
ailearneryang Skill Skill 10security-reviewer 的默认 skill。USE FOR: 权限与注入风险审计、敏感信息检查、生产风险识别。
-
joemccann Skill Testing Weekend 2Weekend testing loop - daily delta-audit of test-suite health for everything merged since the last audited SHA (new findings appended to TEST_AUDIT.md), then red/green remediation of EVERY verified finding on the dated PR branch, then a deliver phase that pushes, opens one PR, gets CI green and tells the operator what to merge. Runs unattended on the always-on runner via scripts/testing_weekend.sh, one daily cycle at 00:10 local that runs audit, remediate, then deliver; invoke as /testing-weekend audit, /testing-weekend remediate or /testing-weekend deliver.
-
joemccann Skill Reliability Weekend 2Weekend reliability loop - daily delta-audit of everything merged since the last audited SHA (new findings appended to RELIABILITY_AUDIT.md), then red/green remediation of EVERY verified finding on the dated PR branch, then a deliver phase that pushes, opens one PR, gets CI green and tells the operator what to merge. Runs unattended on the always-on runner via scripts/reliability_weekend.sh, one daily cycle at 00:00 local that runs audit, remediate, then deliver; invoke as /reliability-weekend audit, /reliability-weekend remediate or /reliability-weekend deliver.
-
joemccann Skill Documentation Nightly 2Nightly documentation maintainer - daily audit that classifies the documentation impact of everything merged since the last audited SHA (rolling issue labeled documentation-nightly), then smallest source-backed remediation of EVERY verified P0/P1/P2 finding on the dated PR branch documentation/<date> without inventing prose, duplicating machine truth, or touching live systems, then a deliver phase that pushes, opens one PR, gets CI green and tells the operator what to merge. Runs unattended on the always-on runner via scripts/documentation_nightly.sh, one daily cycle at 00:30 local that runs audit, remediate, then deliver; invoke as /documentation-nightly audit, /documentation-nightly remediate or /documentation-nightly deliver.
-
fastrepl Skill Product Update Newsletter 2Draft, update, or audit a crisp, changelog-grounded Anarlog product-update newsletter in Loops for a desktop release.
-
mekras Bundle Policy Export 2Создаёт машинное состояние политики проекта.
-
olshansk Skill Cmd Rfc ReviewReview RFCs for problem clarity, compliance, security, and performance using SCQA framework
-
oppo-mente-lab Bundle Skill CreatorCreate, edit, improve, or audit AgentSkills. Use when creating a new skill from scratch or when asked to improve, review, audit, tidy up, or clean up an existing skill or SKILL.md file. Also use when editing or restructuring a skill directory (moving files to references/ or scripts/, removing stale content, validating against the AgentSkills spec). Triggers on phrases like "create a skill", "author a skill", "tidy up a skill", "improve this skill", "review the skill", "clean up the skill", "audit the skill".
-
nwiizo Skill Check Production Ready 2Production readiness audit - checks unwrap elimination, error handling, clippy, docs, channel usage, and test count.
-
hetcreep Bundle Scale Canary 2Performance complexity and resource allocation canary — checks for O(N^2) loops, database N+1 query patterns, memory leaks (unbounded collections), and blocking calls in main event loop. Triggers on keywords: "/scale-canary", "scale-canary", "performance audit", "scale audit". Use when writing loops over growing data, DB queries, caches, or async/event-loop code.
-
hetcreep Bundle Gold Standard 2World-class completeness audit — score a project's rules/standards/features against best-in-class exemplars, name the gaps, fill missing rules, adopt as binding, then offer to conform existing code. Triggers on keywords: "/gold-standard", "gold-standard", "audit rules", "are we world-class", "fill gaps", "complete our rules", "conform old code".
-
hetcreep Bundle Resilience Audit 2Failure-mode audit (FMEA for software) — for each way the system can fail (network, storage, partial completion, crash, concurrency, bad input), check whether code DETECTS, HANDLES, RECOVERS, and COMMUNICATES it. Triggers on: "/resilience-audit", "resilience-audit", "FMEA audit". Use when touching network, storage, async, retry, or rollback paths. Flags data loss, silent-success-on-failure, missing rollback/retry/idempotency. Reports; does not fix unless asked.
-
hetcreep Bundle Telemetry Canary 2Observability and structured logging canary — checks for structured logs (JSON), OpenTelemetry metrics/traces, proper error stack traces, and flags empty catches or silent log swallowing. Triggers on keywords: "/telemetry-canary", "telemetry-canary", "observability audit", "structured logging". Use when adding or changing logging, metrics, tracing, or error-handling code.
-
hetcreep Bundle Supply Chain Audit 2Software supply chain audit — dependencies (CVEs, maintenance, licenses, transitive risk), build/CI integrity (SHA-pinned actions, lockfile, CI-only release), artifact integrity (checksums, signing, SBOM). Triggers on: "/supply-chain-audit", "supply-chain-audit", "dependency audit". Run before adding a dep, before a release, or for periodic review. Reports; does not change deps unless asked.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include critic, review, policy-export. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.