Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
26zl Bundle Implementing Github Advanced Security For Code ScanningConfigure GitHub Advanced Security with CodeQL to perform automated static analysis and vulnerability detection across repositories at enterprise scale.
-
26zl Bundle Implementing Epss Score For Vulnerability PrioritizationIntegrate FIRST's Exploit Prediction Scoring System (EPSS) API to prioritize vulnerability remediation based on real-world exploitation probability within 30 days.
-
zaxbysauce Bundle Commit Pr 2Apply when committing, pushing, opening or updating a PR, writing a pull request, creating release notes, or closing out remote CI. Enforces the opencode-swarm invariant audit, release-note fragment workflow, full validation suite, issue comment requirement, and post-PR lifecycle rules.
-
zaxbysauce Skill Commit Pr 4Apply when committing, pushing, opening or updating a pull request, or closing out CI. A portable, project-agnostic commit and PR workflow: verify before you push, write conventional commits and a clear PR body, and never commit generated or secret files.
-
zaxbysauce Skill Tech Debt CI Review 2Deep technical debt and CI stability audit for identifying test theater, missing or mis-scoped tests, actual and potential test failures, flaky-test risk, dependency/toolchain brittleness, and structural debt that prevents PRs from going green safely.
-
francostino Bundle LoreMarkdown project memory for AI agents. Use for decisions, architecture, conventions, monorepo scopes, `.lore/`, or `lore` commands; not native `/init`/`/compact` or generic init/compress/audit/query.
63 -
francostino Skill Cyber AuditRun read-only exposure checks for security advisories and write a structured local audit report.
63 -
francostino Skill Constant Time AnalysisAnalyze cryptographic code to detect operations that leak secret data through execution timing variations.
63 -
intense-visions Bundle Owasp CryptographyCryptography Best Practices
18 -
intense-visions Bundle Design Design AuditDesign Audit
18 -
intense-visions Bundle Owasp Auth PatternsOWASP Auth Patterns
18 -
intense-visions Bundle Owasp Rate LimitingRate Limiting and Throttling
18 -
intense-visions Bundle Security Mfa DesignMulti-Factor Authentication Design
18 -
intense-visions Bundle API Webhook SecurityAPI Webhook Security
18 -
intense-visions Bundle Owasp Xss PreventionOWASP XSS Prevention
18 -
intense-visions Bundle Security Abac DesignAttribute-Based Access Control
18 -
intense-visions Bundle Security Mtls DesignMutual TLS Design
18 -
intense-visions Bundle Security Rbac DesignRBAC Design
18 -
jeremylongshore Bundle Nixtla Universal ValidatorValidate Nixtla skills and plugins with deterministic evidence bundles and strict schema gates. Use when auditing changes or enforcing compliance. Trigger with 'run validation' or 'audit validators'.
-
jeremylongshore Bundle Nixtla Usage OptimizerAudits Nixtla library usage and recommends cost-effective routing strategies. Scans TimeGPT, StatsForecast, and MLForecast patterns, identifies cost optimization opportunities, generates comprehensive usage reports, and suggests smart routing between models. Activates when user needs cost optimization, API usage audit, routing strategy design, or Nixtla cost reduction.
-
jeremylongshore Bundle Org Universal ValidatorValidate skills and plugins with deterministic evidence bundles and strict schema gates. Use when auditing changes or enforcing compliance. Trigger with 'run validation' or 'audit validators'.
-
qverisai Bundle Openclaw Secret Scanning MaintainerMaintainer-only workflow for handling GitHub Secret Scanning alerts on OpenClaw. Use when Codex needs to triage, redact, clean up, and resolve secret leakage found in issue comments, issue bodies, PR comments, or other GitHub content.
-
openshift Skill Test RuleRun Automatus tests for a security rule
-
openshift Skill Create RuleCreate a new security rule with all required components
-
openshift Skill Onboard ControlOnboard a new security policy as a control file. Parse the document, create control file structure, and map existing rules to requirements.
-
kunanonj Bundle CodeqlScans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis. Triggers on "run codeql", "codeql scan", "codeql analysis", "build codeql database", or "find vulnerabilities with codeql". Supports "run all" (security-and-quality + security-experimental suites) and "important only" (high-precision security findings) scan modes. Also handles creating data extension models and processing CodeQL SARIF output.
-
kunanonj Bundle Security ReviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
-
intense-visions Bundle Owasp Logging MonitoringSecurity Logging and Monitoring
18 -
intense-visions Bundle Owasp Secrets ManagementOWASP Secrets Management
18 -
intense-visions Bundle Security Hmac SignaturesHMAC and Digital Signatures
18 -
intense-visions Bundle Security Hsts PreloadingHSTS and Preloading
18 -
intense-visions Bundle Security Log CorrelationLog Correlation and SIEM
18 -
intense-visions Bundle Security Race ConditionsRace Conditions
18 -
intense-visions Bundle Security Sbom ProvenanceSBOM and Build Provenance
18 -
intense-visions Bundle Owasp Dependency SecurityDependency Security
18 -
intense-visions Bundle Security Audit Log DesignAudit Log Design
18
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-log-correlation, api-webhook-security, nixtla-universal-validator. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.