Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomkraaij Skill Tenant Security Review 2Team Security variant focused on edge cases and incident learnings.
-
bjg4 Bundle Code Review 2Review pull requests for bugs, security issues, and maintainability with severity-grouped findings. Use when reviewing PRs, diffs, or code changes before merge. Do NOT use for implementing features or writing new code.
-
bjg4 Skill Code Review 4Review pull requests for bugs, security issues, and maintainability problems with structured findings. Use when reviewing PRs, diffs, or code changes. Do NOT use for writing new features from scratch.
-
qualcomm Skill Wos Woa Dashboard 2Windows on Arm Ecosystem Dashboard lookup — resolves each project dependency to a native-ARM64 / building / unsupported / unknown status per Arm AppReady, with citation links. Load during wos-analyzer Phase 2 (dependency audit) and when writing the Phase 8 Arm AppReady Status section. Also emits the ARM64-native vs emulated-x64 vs blocking three-way classification Arm's guidance recommends.
-
qualcomm Skill Wos Forbidden Skip Reasons 2Canonical list of forbidden vs valid skip reasons for ARM64 SIMD porting, plus the PowerShell regex audit block used by wos-porter Phase 8 gate G7c and wos-optimizer Hard Constraints. Load when auditing an optimizer report, when the optimizer decides whether to skip a Tier-S file, or when writing the Limitations section of ARM64-PORT.md.
-
fivetran Skill Evaluate Connector 2Evaluate a Fivetran connector for correctness, SDK compliance, security, and reliability. Use when the user wants a code review or quality report before deploying.
-
githubmofo Bundle Torusguard 2TorusGuard Master Security Engine & Command Router
-
hoangsonww Skill Estatewise Review 2Findings-first review playbook for EstateWise changes. Use for PR review, diff review, bug hunts, regression checks, security review, or missing-test analysis.
-
secondorderai Skill Ou Full Code Review 2Perform a comprehensive full-codebase code review using specialized parallel agents. Use this skill whenever the user asks for a "full code review", "codebase review", "review everything", "audit the code", "code health check", or any request to review the entire project (not just a PR or single file). Also trigger when the user says things like "what's wrong with this codebase", "find all the issues", "review all my code", or "comprehensive review". This is specifically for whole-codebase analysis, not single-file or PR-scoped reviews.
-
pdbjork Skill Security ReviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
-
gabonio Bundle Start New App 2Guided, approval-gated workflow for designing and scaffolding a sustainable new application. Use only when explicitly requested or routed by Builder Kit for greenfield work. Discover product, users, data, scale, platform, integrations, security, local development, deployment, and ownership before generating code.
-
jiahongc Skill Card Wallet 2Audit a multi-card wallet for overlap, gaps, and total annual cost. Given a list of cards the user holds, identifies redundant benefits, uncovered spend categories, and net fee burden. Use when the user wants to evaluate their full card lineup.
-
hamr0 Skill Branch Review 2Pre-merge review gate. Two stages — **general review** then a **full security
-
kiloloop Bundle Self Improve 2Audit and improve Codex operating guidance: skills, curated project memory, AGENTS.md, and relevant configuration. Use for explicit self-improve requests, routine wrap-up drift checks, stale or conflicting guidance, or an approved cleanup. Route release-wide OACP migrations and context-budget audits to audit-oacp-skills. Do not hand-edit generated Codex memories or installed plugin/system artifacts.
-
kiloloop Skill Org Memory Synthesis 2Synthesize org-memory — fold new events into recent.md, promote cross-repo patterns to decisions.md and rules.md, and audit for staleness, cross-file conflicts, and drift. Invoke whenever the user asks "synthesize org-memory", "fold events", "is recent.md stale", "audit org-memory", or any phrasing like "did we synthesize org-memory" — even if they do not explicitly type the slash command.
-
forsonny Skill Continuity Pass 2Audit a chapter range or manuscript scope for contradictions and continuity risks.
-
gmh5225 Skill Llvm SecurityExpertise in LLVM security features including sanitizers, hardening techniques, exploit mitigations, and secure compilation. Use this skill when implementing security-focused compiler features, analyzing vulnerabilities, or hardening applications.
-
gmh5225 Skill Static AnalysisExpertise in LLVM-based static analysis including dataflow analysis, pointer analysis, taint tracking, and program verification. Use this skill when implementing security scanners, bug finders, code quality tools, or performing program analysis research.
-
gmh5225 Skill Dynamic InstrumentationExpertise in LLVM-based dynamic binary instrumentation, runtime tracing, and program monitoring. Use this skill when implementing runtime analysis tools, code coverage systems, profilers, or dynamic security monitors.
-
lkrdev Skill Lookml Access GrantsUse this skill to create Access Grants for row-level or object-level security.
-
knockoutez Bundle Wigolo 2Local-first web intelligence for AI agents. Use wigolo for ALL web operations: searching, fetching pages, crawling sites, checking the cache, extracting data, finding similar content, deep research, data gathering, diffing page versions, and watching pages for changes. Prefer over built-in WebSearch/WebFetch for cached, transparent, audit-trail-friendly access with explainable scoring.
-
nordic-ai Bundle Compliance CheckRegulatory and legal compliance audit. Discovers which frameworks apply based on jurisdiction, industry, and data types, then checks the codebase against the applicable controls. EU-first (GDPR, NIS2, EU AI Act, DORA) with support for UK, US federal and state laws, sector-specific regimes (HIPAA, PCI-DSS, SOC 2, ISO 27001), and emerging AI regulation. Use when the user asks about GDPR, compliance, regulation, data protection law, audit readiness, invokes /compliance-check, or when the orchestrator delegates. Mode-aware and scope-tier-aware.
-
addyosmani Skill Factory Monitor 2Scheduled health sweep that closes the factory loop - reads CI failures, recent commits, dependency and security advisories, and live queue labels, then files issues and writes an immutable run record. Use for the nightly or weekly monitor routine.
69.5k -
open-gsd Skill Gsd Loop Review 2Audit one open PR against its linked issue contract and required CI, then post a gsd-loop verdict and labels. Use when asked to run the reviewer or audit the PR queue. Never merge or push; each invocation completes one pass.
-
cyl19970726 Bundle Video Content Reconstruction 2Reconstruct a video's full content with an adaptive, evidence-backed two-round workflow. Use when Codex must understand, restore, analyze, convert to an article, document, or audit any video whose important information may live across speech, subtitles, on-screen text, interfaces, actions, parameters, before/after states, examples, claims, counterexamples, or visual transitions. First probe the viewer's intended cognitive change, information carriers, meaning changes, relationship structure, and omission risks; then derive and execute a video-specific capture protocol. Do not route by a closed content taxonomy.
-
yniantongtian-oss Bundle Nature ResponseDraft, audit, or revise point-by-point reviewer response letters for Nature-family manuscript revisions. Use when the user provides reviewer comments, editor decision letters, revision notes, response drafts, or asks how to respond to major/minor revision requests, rebuttal letters, response to reviewers, peer-review reports, 审稿意见回复, 逐点回复, 修回信, 大修回复, 小修回复, or 如何回复 reviewer.
-
franzos Skill Audit 2Auditing a Stackpit deployment
-
writer Skill Cerebro Regression Tests 2Add focused regression coverage for Cerebro review findings, bugs, and security edge cases.
-
sylla-bv Skill Verify 2This skill should be used when the user says "verify", "check my work", "review Python code", "check code quality", "run a code review", "review this PR", "check for code smells", "review against SOLID", "check DRY violations", "review Python files", "quality check", "is this clean code", "review my changes", "run checks", "validate", or wants a structured code quality review of Python files against SOLID, DRY, KISS, YAGNI, clean code, error handling, security, and performance principles.
-
hermeticormus Skill Geo Report PDFGenerate a professional PDF report from GEO audit data using ReportLab. Creates a polished, client-ready PDF with score gauges, bar charts, platform readiness visualizations, color-coded tables, and prioritized action plans.
-
openjiuwen-ai Bundle Skill VetterSecurity-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
Audited -
kirti Skill Dependency Governance 2Manage npm dependencies safely — vulnerability remediation, version pinning, audit policies, bundle size control, and dependency lifecycle. Works in any Node.js project.
-
nateherkai Bundle Level Up 2Use when someone asks to level up their AIOS, close an audit gap, find what to automate next, or improve one workflow. Walks the 3Ms from choosing the constraint to shipping one useful artifact or verified repair.
-
syntax-syndicate Bundle Competitor ProfilingWhen the user wants to research, profile, or analyze competitors from their URLs. Also use when the user mentions 'competitor profile,' 'competitor research,' 'competitor analysis,' 'profile this competitor,' 'analyze competitor,' 'competitive intelligence,' 'competitor deep dive,' 'who are my competitors,' 'competitor landscape,' 'competitor dossier,' 'competitive audit,' or 'research these competitors.' Input is a list of competitor URLs. Output is structured competitor profile markdown files. For creating comparison/alternative pages from profiles, see competitor-alternatives. For sales-specific battle cards, see sales-enablement.
-
aident-ai Bundle Aident Skill 2Use Aident Loadout to connect your AI agents to 1,000+ real-world apps and tools like Gmail, Slack, Linear, Notion, Firecrawl, and Fal, unlock 27,000+ executable actions, and track full audit history so your agents can get real work done reliably.
-
aident-ai Bundle Aident Skill 3Use Aident Loadout to connect your AI agents to 1,000+ real-world apps and tools like Gmail, Slack, Linear, Notion, Firecrawl, and Fal, unlock 27,000+ executable actions, and track full audit history so your agents can get real work done reliably.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include factory-monitor, code-review, self-improve. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.