Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aident-ai Bundle Aident Skill 4Use Aident Loadout to connect your AI agents to 1,000+ real-world apps and tools like Gmail, Slack, Linear, Notion, Firecrawl, and Fal, unlock 27,000+ executable actions, and track full audit history so your agents can get real work done reliably.
-
codewithcj Skill New Migration 2Use whenever adding or changing a SparkyFitness database migration, creating a new table, or altering user-visible data access. Walks the mandatory cross-package checklist (RLS policies, schema backup sync, shared Zod schema, docs security tiers, downstream contracts). Triggers on "new table", "migration", "ALTER TABLE", "RLS", "schema change".
-
ivan-sincek Bundle Dread Threat Modeling Framework 2Systematically score and prioritize threats using the risk-centric DREAD threat modeling framework. Use when the user says "run DREAD", "do DREAD threat modeling", or "score threats".
-
ivan-sincek Skill Pasta Threat Modeling Framework 2Systematically identify and classify technical and business risks using the risk-centric PASTA threat modeling framework. Use when the user says "run PASTA", "do PASTA threat modeling", or "identify risks".
-
ivan-sincek Bundle Stride Threat Modeling Framework 2Systematically identify and classify threats using the software-centric STRIDE threat modeling framework. Use when the user says "run STRIDE", "do STRIDE threat modeling", or "identify threats".
-
securityreviewai Skill Pwnisms Threat Modelling 2Lightweight, security-first threat modelling workflow for code and architecture tasks. Use it to walk all 7 PWNISMS categories, identify plausible threats, prioritize top risks, and propose concrete mitigations before and during implementation.
-
paladini Skill Harness Engineering 2Use when the user asks to improve, fix, or build their repository's AI harness — AGENTS.md, rules, skills, commands, hooks, guardrails, CI sensors — or to act on harness-score audit findings and raise their maturity level.
-
mfish-qf Skill Workflow Audit 2---
-
yujunzhou Bundle Tellonce 2Use when handling any user message; records and enforces user preferences with Codex-native audit/wrapper support.
-
yujunzhou Skill Tellonce 3Use when handling any user message; records and enforces user preferences with Codex-native audit/wrapper support.
-
yujunzhou Skill Tellonce 4EVERY-MESSAGE enforcement: scan for preference/pitfall/friction signals, record to memory, log observations. Also handles memory audit/restructure. Use on EVERY user message — even simple ones, even during intensive technical work, even when you think there's nothing to detect. If you're not invoking this, you're skipping compliance.
-
ivan-sincek Bundle Security Requirements Analysis 2Systematically extract and classify security requirements from a specification document. Use when the user says "do a security requirements analysis" or "extract security requirements".
-
longbridge Bundle Navi 2Write, refactor, debug, and review Navi `.nv` indicator, strategy, and library scripts. Use when working with Navi syntax, script declarations (`indicator`, `strategy`, `library`), bar-by-bar series logic, `const`/`input`/`simple`/`series` qualifiers, `var`/`varip`, `na`, history references (`x[1]`), non-repainting behavior, inputs, plots/drawings, `request.security`, collections (`Array`/`Map`/`Matrix`), or standard-library APIs such as `ta`, `math`, `String`, `input`, `strategy`, `Label`, `Line`, `Box`, and `Table`.
-
patriceckhart Skill Secret Review 2Check a change for accidentally exposed credentials and private data.
-
gnomatix Skill Audit Workflow 2Audit a WORKFLOW document — multi-step procedure, runbook, SOP, Kiro spec, Antigravity workflow, plan-mode document. Runs the standard audit checklist plus phase-boundary checks (are checkpoints meaningful, are approval gates correctly placed) plus portability audit (workflows often invoke specific tools). Use when reviewing or revising any document that prescribes a multi-step procedure with phases. SKIP for always-on rules (use audit-rule) or single-pass invocable skills (use audit-skill).
-
simplevaad-debug Bundle Test MasterGenerates test files, creates mocking strategies, analyzes code coverage, designs test architectures, and produces test plans and defect reports across functional, performance, and security testing disciplines. Use when writing unit tests, integration tests, or E2E tests; creating test strategies or automation frameworks; analyzing coverage gaps; performance testing with k6 or Artillery; security testing with OWASP methods; debugging flaky tests; or working on QA, regression, test automation, quality gates, shift-left testing, or test maintenance.
-
agricidaniel Skill Email AuditAudits email domain deliverability setup (SPF, DKIM, DMARC, MX records, blacklists, TLS) and generates health score (0-100) with prioritized fix list. Checks bulk sender compliance against Google/Yahoo/Microsoft 2024-2026 requirements. Provides DNS records to add/update. Use when user asks to audit, check, or analyze email deliverability, domain health, or inbox placement.
-
alimansoor2003 Skill Security Audit 2@'
-
conorbronsdon Skill Ssot Check 2Audit copied facts, missing SSOT pointers, and disconnected setup guides. Use for documentation drift, cross-repo ownership, orphaned handoffs, or an SSOT manifest.
-
edouard-claude Bundle Ironloop 2Verification-first software engineering harness with 5 layers (spec → gen → test → sim → pentest). Use when generating, reviewing, or planning code with AI agents, especially for Rust projects, new feature work, legacy migrations, or any task where code correctness must be guaranteed. Activates on phrases like "build a", "implement", "refactor", "review this code", "migrate from", "add tests for", or when the user describes a coding task with correctness or security requirements.
-
giljr Bundle Bundler Audit 2Guia completo para instalar, configurar e executar o bundler-audit em projetos Ruby/Rails. Use esta skill sempre que o usuário mencionar bundler-audit, auditoria de gems, vulnerabilidades em gems Ruby, CVEs em dependências, atualização segura de gems, ou quiser garantir segurança nas dependências de um projeto Rails. Também acione para análise de resultados do bundler-audit, interpretação de CVEs/GHSA, e estratégias de atualização segura em produção.
-
imbad0202 Bundle Critical Thinking For Humans 2Trains the HUMAN user's critical thinking through four modes: drill (argument-analysis items with a single defensible answer, judge stance), scene (Socratic exploration of synthetic scenes or user-supplied material, no verdicts on interpretations; includes a configure track — design the information request and verification plan for a decision before any analysis), expedition (guided audit of impossible-tier problems from verified packs), and detective (a runtime-generated multi-layer case worked as an escape room, guide-and-judge stance). Use when the user wants to practice critical thinking, analyze arguments, hunt assumptions, examine bias, train reasoning, or decide what information a decision needs first. Triggers: critical thinking practice, train my thinking, drill, scene, byom, configure, information plan, what would I need to know, spot manipulation tactics, scam literacy, 批判思考練習, 話術辨識, detective, 查案, 破案, 偵探.
36.4k -
zerx-lab Skill Workflow PatternsArgument shapes for the 5 built-in workflow patterns — deep-research, adversarial-review, code-review, multi-perspective, codebase-audit — runnable via the `workflow` tool's `name` input, without slash-command syntax. Use for requests like "research X", "fact-check/adversarially review this", "review this diff/PR", "analyze from multiple perspectives", or "audit the codebase for Y". Not for authoring a new workflow script — see workflow-authoring.
-
zyphraxns Bundle Opensource Doc Generator 2根据项目文件自动生成开源平台(如 GitHub)所需的各种说明文档。扫描项目结构、代码和技术栈,智能判断需要创建哪些文档文件(README、LICENSE、CONTRIBUTING、CHANGELOG、CODE_OF_CONDUCT、SECURITY 等 20+ 种),并为每种文件生成符合规范的内容。 当用户提到"开源文档"、"README"、"上传到 GitHub"、"准备开源"、"项目说明文件"、"文档生成"、"开源准备"、"CONTRIBUTING"、"LICENSE 文件"、"CHANGELOG"等意图时,务必使用此 Skill。即使用户只是说"帮我的项目写个说明"或"我想把项目开源",也应触发此 Skill。
-
conorbronsdon Skill Repo Audit 2Audit repository claims and plan an open-source release. Use when asked to audit a repository or prepare an open-source release.
Audited -
ksimback Bundle Tech Debt AuditThorough, user-invoked tech debt and architecture audit of the current codebase. Produces TECH_DEBT_AUDIT.md with file-cited findings, severity, effort estimates, and a required "looks bad but is actually fine" section. Use when the user asks for a debt audit, codebase health check, architecture review, or code quality assessment of an entire repo. Does not auto-invoke.
-
lanlinju Skill Code ReviewPerform thorough code reviews with security, performance, and maintainability analysis. Use when user asks to review code, check for bugs, or audit a codebase.
-
opencmc Bundle Cmc API DexAPI reference for CoinMarketCap DEX endpoints including token lookup, pools, transactions, trending, and security analysis. Use this skill whenever the user mentions DEX API, asks about on-chain token data, wants to look up tokens by contract address, needs security/rug risk checks, or is building DEX integrations. This is the definitive reference for CMC DEX API questions. Trigger: "DEX API", "token by contract address", "CMC security API", "liquidity pool API", "/cmc-api-dex"
-
mikaru0mystic Bundle Analyzing IOS App Security With ObjectionRuntime iOS app security testing with Objection (Frida): inspect keychain and filesystem data, explore app internals at runtime, and validate/bypass client-side protections during authorized mobile assessments.
-
laragentic Bundle Code Review 2Analyze code for security, performance, and best practices
-
louisbrulenaudet Skill Review Checklist 2Enumerated review checklist for this api-template - the diff-level checks that map to .cursor/rules/. Use when reviewing a diff or auditing files for rule conformance; the criteria for the code-reviewer and security-reviewer agents.
-
google Bundle Unsafe Rust 2Author, document, review, audit, or redesign unsafe Rust with proof-grade rigor. Use for unsafe blocks and functions, unsafe traits and impls, raw pointers, FFI, inline assembly, intrinsics, layout or validity reasoning, concurrency and atomics, SIMD and target features, allocators, invariant-bearing fields, safety comments or `# Safety` documentation, soundness reviews, TCB audits, generated unsafe code, changes to safety or behavioral contracts, and proof-oriented redesign of unsafe abstractions.
14.4k -
google Bundle Unsafe Rust 3Author, document, review, audit, or redesign unsafe Rust with proof-grade rigor. Use for unsafe blocks and functions, unsafe traits and impls, raw pointers, FFI, inline assembly, intrinsics, layout or validity reasoning, concurrency and atomics, SIMD and target features, allocators, invariant-bearing fields, safety comments or `# Safety` documentation, soundness reviews, TCB audits, generated unsafe code, changes to safety or behavioral contracts, and proof-oriented redesign of unsafe abstractions.
14.4k -
google Bundle Unsafe Rust 4Author, document, review, audit, or redesign unsafe Rust with proof-grade rigor. Use for unsafe blocks and functions, unsafe traits and impls, raw pointers, FFI, inline assembly, intrinsics, layout or validity reasoning, concurrency and atomics, SIMD and target features, allocators, invariant-bearing fields, safety comments or `# Safety` documentation, soundness reviews, TCB audits, generated unsafe code, changes to safety or behavioral contracts, and proof-oriented redesign of unsafe abstractions.
14.4k -
google Bundle Unsafe Rust 5Author, document, review, or audit unsafe Rust with proof-grade rigor. Use for unsafe blocks and functions, unsafe traits and impls, raw pointers, FFI, inline assembly, intrinsics, layout or validity reasoning, concurrency and atomics, SIMD and target features, allocators, invariant-bearing fields, safety comments or `# Safety` documentation, soundness reviews, TCB audits, generated unsafe code, and changes to safety or behavioral contracts.
14.4k -
google Bundle Unsafe Rust 6Author, document, review, audit, or redesign unsafe Rust with proof-grade rigor. Use for unsafe blocks and functions, unsafe traits and impls, raw pointers, FFI, inline assembly, intrinsics, layout or validity reasoning, concurrency and atomics, SIMD and target features, allocators, invariant-bearing fields, safety comments or `# Safety` documentation, soundness reviews, TCB audits, generated unsafe code, changes to safety or behavioral contracts, and proof-oriented redesign of unsafe abstractions.
14.4k
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include dread-threat-modeling-framework, stride-threat-modeling-framework, cmc-api-dex. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.