Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
bg-szy Skill Burpsuite Project ParserSearches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with regex patterns, extracting security audit findings, dumping proxy history or site map data, or analyzing HTTP traffic captured in a Burp project.
-
bg-szy Skill Compliance CheckerAudits a codebase or business process for regulatory compliance across GDPR, HIPAA, SOC2, CCPA, and PCI-DSS. Scans for PII handling, data retention, encryption, access controls, audit logging, consent management, and data transfer issues. Generates a structured compliance report with findings, gap analysis, remediation steps, and evidence requirements.
-
bg-szy Skill Dependency AuditorAudit npm dependencies for security vulnerabilities, outdated packages, and unused dependencies. Use when checking for security issues, updating packages, or cleaning up dependencies.
-
bg-szy Bundle Regulatory DrafterAutomates the drafting of regulatory documents (e.g., FDA CTD sections) with citation management and audit trails.
-
bg-szy Skill Cowork Expense AuditCowork-style sweep of a folder of receipts, statements, and expense exports -- categorizes every transaction, matches receipts to statement lines, flags policy violations and anomalies, and outputs a clean expense report plus a findings memo.
-
bg-szy Skill Power Bi SecurityConfigure row-level security (RLS) roles, object-level security, and perspectives for Power BI semantic models using pbi-cli. Invoke this skill whenever the user mentions "security", "RLS", "row-level security", "access control", "data restrictions", "who can see", "filter by user", "perspectives", "limit visibility", or wants to restrict data access by role.
-
bg-szy Skill Cowork Calendar DefragAudit your calendar with Cowork's calendar tools -- measure meeting load and fragmentation, identify which recurring meetings earn their slot, propose consolidations and focus blocks, and draft the diplomatic messages that reclaim your week.
-
bg-szy Skill Quality NonconformanceCodified expertise for quality control, non-conformance investigation, root cause analysis, corrective action, and supplier quality management in regulated manufacturing. Informed by quality engineers with 15+ years experience across FDA, IATF 16949, and AS9100 environments. Includes NCR lifecycle management, CAPA systems, SPC interpretation, and audit methodology. Use when investigating non-conformances, performing root cause analysis, managing CAPAs, interpreting SPC data, or handling supplier quality issues.
-
dav-niu474 Skill Skill VetterSecurity-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
-
williamcorrea23 Skill Annual Audit Planning年度审计计划制定 — 风险导向审计方法,识别高风险领域, 合理分配审计资源,制定本年度内部审计计划。 适用情形:审计总监/经理在每年 Q4 制定下一年度审计计划时执行, 或年中根据风险变化调整计划时执行。
-
williamcorrea23 Skill Internal Audit Master内部审计管理主流程 — 整合年度审计计划/专项审计/审计发现整改全流程。 适用情形:审计总监/审计经理制定年度审计计划、启动专项审计、 管理审计发现整改时执行,整合 annual-audit-planning、 process-compliance-audit、audit-finding-tracking 和 fraud-investigation, 输出完整的内部审计管理报告。 核心:风险导向 → 发现问题 → 整改跟踪 → 持续改进。
-
williamcorrea23 Skill Audit Adjustment Review审计调整审核 — 核查 [ERP] 审计调整分录,评估调整合理性,处理调整分歧。 适用情形:审计过程中执行,从审计调整台账获取调整数据, 核查调整分录准确性,评估对报表影响,输出调整审核报告。 核心:调整识别 + 影响评估 + 分歧处理 + 最终确认。
-
williamcorrea23 Skill Confirmation Management函证管理 — 协调 [ERP]/[BANK] 银行函证和往来函证,跟踪回函状态,处理异常。 适用情形:审计函证程序时执行,跟踪银行和往来函证发函/回函状态, 核查回函差异,输出函证管理报告。 核心:发函跟踪 + 回函核对 + 差异处理 + 替代程序。
-
williamcorrea23 Skill Audit Finding Tracking审计发现整改跟踪 — 对所有未关闭的审计发现进行跟踪管理, 验证整改效果,对超期未整改项执行升级流程。 适用情形:审计经理/总监每月审查整改状态、 验证已完成整改、或对超期整改执行升级时执行。
-
williamcorrea23 Skill Board Reporting Master董事会汇报主流程 — 整合 Board Deck 编制、审计委员会支持、董事会议程管理与重大事项汇报。 适用情形:年度/季度董事会与审计委员会会议前执行,整合 board-deck-preparation、 audit-committee-support、board-meeting-management 和 board-material-distribution, 输出完整的董事会汇报材料包。 核心:会议准备 → 材料编制 → 委员会协同 → 重大事项汇报。
-
williamcorrea23 Skill Audit Evidence Collection审计资料收集 — 按审计要求收集 [ERP]/[DOC] 资料,完成资料清单编制与核对。 适用情形:审计进场准备时执行,从 [ERP]/[DOC] 获取资料, 按审计资料清单整理,核查完整性,输出资料收集报告。 核心:清单核对 + 缺失识别 + 替代方案 + 按时交付。
-
williamcorrea23 Skill Audit Committee Support审计委员会支持 — 为审计委员会提供专业支持,包括审计计划审阅、 审计发现跟踪、审计报告审阅和委员会议程管理。 适用情形:审计委员会会议前 [X] 天,或用户要求"准备 AC 材料"时执行。 核心:审计发现汇总 + 整改追踪 + 委员会议程设计。
-
williamcorrea23 Skill Process Compliance Audit流程合规性审计 — 对具体业务循环(采购/销售/资金/税务等) 执行穿行测试和控制测试,识别控制缺陷和合规问题。 适用情形:审计人员执行现场审计、编写审计工作底稿时执行。
-
cslawyer1985 Bundle Afrexai Compliance AuditCompliance Audit Generator
-
cslawyer1985 Bundle Afrexai Regulatory ComplianceRegulatory Compliance Audit
-
yorgai Skill Architecture AuditSystematic architecture audit and refactoring methodology for Rust + TypeScript codebases. Use when performing refactoring, cleanup, unification, code review, dead code removal, module reorganization, or tech debt elimination. Ensures no naming confusion, semantic overloading, hidden defaults, duplicate logic, or architectural inconsistencies are missed.
-
compozy Skill Writing Agents MdCreate, audit, shorten, or scope AGENTS.md and CLAUDE.md instructions. Use writing-skills for on-demand skills; excludes human-facing documentation and READMEs.
-
drmoisan Skill Skill Canonical Location Audit 3Audit skills for canonical-location duplication. Use when ensuring a canonical location for a given item is defined in exactly one skill and duplicates are flagged.
-
drmoisan Skill Evidence And Timestamp Conventions 3Evidence storage and timestamp naming conventions for audits and remediation. Use when storing baseline/regression/QA evidence or naming audit artifacts with ISO-8601 timestamps.
-
bg-szy Skill SemgrepRuns a Semgrep security scan over a codebase: detects languages, selects rulesets, presents the plan for explicit approval, then runs every approved ruleset through scripts/run-scans.sh, which batches the semgrep processes and writes scans.json, and merges the output to SARIF. Supports two scan modes, "run all" for full ruleset coverage and "important only" for security findings at medium-to-high confidence and impact. Uses Semgrep Pro for cross-file taint analysis when it is available. Use when asked to scan code for vulnerabilities, run a security audit with Semgrep, find bugs, or perform static analysis. For the same scan without the approval gate, use the /static-analysis:semgrep-scan workflow.
-
bg-szy Skill Fp CheckSystematically verifies suspected security bugs to eliminate false positives, producing a TRUE POSITIVE or FALSE POSITIVE verdict with documented evidence for each. Use when asked whether a specific finding is real, exploitable, or a false positive, or to verify or validate a suspected vulnerability — not for hunting or discovering new bugs.
-
bg-szy Skill AI Readiness AssessmentAssesses how ready a business is for AI adoption across six dimensions. Evaluates data maturity, tech stack, team skills, process documentation, budget, and culture. Generates a comprehensive ai-readiness-report.md with scores, gap analysis, and recommended starting points. Aligned with OneWave AI's audit methodology.
-
bg-szy Skill Security Pentest PlannerPlans security penetration tests for web applications. Analyzes codebase, API routes, auth implementation, and infrastructure config to generate comprehensive pentest plans. For authorized testing only.
-
markus41 Skill Onedrive OrganizerDesign OneDrive for Business folder structure and governance policy specifications to ensure consistent file organization, security, and compliance for financial services firms.
-
markus41 Skill Cc Security ComplianceSecurity & Compliance
-
markus41 Skill Hook Script LibrarySecurity-hardened hook script implementations — ready-to-paste templates for security-guard, auto-format, inject-context, session-init, on-stop, and lessons-learned-capture
-
markus41 Skill Supply Chain SecurityThis skill should be used when triaging dependency advisories, code-scanning alerts, or committed secrets — reachability analysis, revoke-first remediation, provenance, and maintenance risk signals.
-
markus41 Skill Hook Script Library 2Security-hardened hook script implementations — ready-to-paste templates for security-guard, auto-format, inject-context, session-init, on-stop, and lessons-learned-capture
-
mapletechlabs Bundle Maple AuditAudit an already-instrumented project against Maple's OpenTelemetry conventions, report gaps per service, and fix them. Triggers on requests like 'audit my instrumentation', 'check my telemetry', 'review my OTel setup', 'why is my service map missing edges', 'is my Maple instrumentation correct'.
-
mapletechlabs Skill Maple Otel Spec ReviewReview a diff, PR, or specific file in this repo for OpenTelemetry *specification* compliance, grounded in the source-linked spec corpus at docs/otel-spec/ (snapshot v1.58.0). Triggers on requests like 'is this spec compliant', 'review this PR against the OTel spec', 'spec-review this diff', 'check my partial-success handling', 'are these retryable status codes right', 'does apps/ingest honor the OTLP spec', and on reviews of changes touching the OTLP server surface in apps/ingest (partial success, retryable set {429, 502, 503, 504}, protobuf Status bodies, gzip, OTLP/JSON encoding), self-instrumentation (apps/api tracer setup, apps/ingest/src/otel.rs, packages/effect-sdk), or consumers of span status / SeverityNumber / db.query.text (WarehouseQueryService, query-engine). Spec MUSTs and SHOULDs only — for Maple house conventions use maple-telemetry-conventions; for whole-project instrumentation audits use maple-audit; for general diff correctness use /code-review.
-
duyet Skill Security HardeningRBAC configuration, row policies, quotas, network security, audit logging, and access control best practices.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include skill-vetter, writing-agents-md, hook-script-library. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.