Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
plurigrid Skill Pentest Exploit ValidationProof-driven exploitation with 4-level evidence system, bypass exhaustion protocol, mandatory evidence checklists, and strict EXPLOITED/POTENTIAL/FALSE_POSITIVE classification.
-
plurigrid Skill Implementing Privileged Session MonitoringImplements privileged session monitoring and recording using Privileged Access Management (PAM) solutions, focusing on CyberArk Privileged Session Manager (PSM) and open-source alternatives. Covers session recording configuration, keystroke logging, real-time monitoring, risk-based session analysis, and compliance audit trail generation. Activates for requests involving privileged session recording, PAM session monitoring, CyberArk PSM configuration, administrator activity monitoring, or compliance session auditing.
-
lyl1015 Skill Aesthetic Audit商业级视觉资产与网页(详情页/落地页)的审美与UX视觉审查:输出P0/P1/P2问题清单、可落地的样式tokens与改稿建议;可结合截图、URL与源码进行定位与修改。
-
kernel8901 Bundle SecurityreviewStandard Operating Procedures: Security Analysis Guidelines
-
codealive-ai Bundle Installing CLI ToolsInstall, upgrade, configure, and verify developer CLI tools safely. Use when a user asks to install a new CLI, command-line app, SDK tool, package-manager binary, GitHub release binary, language runtime tool, or AI/vendor CLI; configure shell PATH/completions; run first login; set API keys, tokens, or env variables for a CLI; migrate an existing CLI install; or troubleshoot a CLI installation while avoiding secret leakage.
-
codealive-ai Bundle Investigating Repository HistoryInvestigate GitHub repository history before risky code changes using git blame/log, GitHub PRs, review comments, squash/rebase/cherry-pick/rename heuristics, and cited evidence. Use when asking why code exists, whether a change is safe, what PR introduced behavior, or before editing API, compatibility, security, concurrency, persistence, migration, or performance-sensitive code.
-
dirien Bundle Security AuditComprehensive security audit covering OWASP Top 10, secrets detection, supply chain security, threat modeling, and language-specific vulnerability patterns. Investigates actual code paths rather than grep-matching keywords. Generates a scored SECURITY_AUDIT.md with prioritized remediation. Use when assessing application security, preparing for a security review, or onboarding to a codebase with security concerns.
-
dirien Bundle Go Nolint AuditAudit Go nolint directives for staleness and lazy justifications. Mechanically verifies each suppression with golangci-lint, then runs adversarial Red/Blue/White debates on the top candidates for removal. Use when inheriting a Go codebase, during periodic cleanup, or when nolint count is growing unchecked.
-
dirien Bundle Design PrinciplesAudit a codebase against well-known software design principles: SOLID, DRY, YAGNI, KISS, Law of Demeter, Separation of Concerns, Composition over Inheritance, and the code-relevant 12-Factor subset. Scores findings by impact and effort, runs adversarial debate on contested violations, and generates a prioritized DESIGN_AUDIT.md. Use when reviewing code quality beyond what linters catch, assessing design health before a refactor, or onboarding to an unfamiliar codebase. Can be invoked standalone or delegated from tech-debt.
-
dqtx760 Skill PathfinderMap a codebase into feature-grouped flowcharts, identify duplicated concerns across features, and propose a unified architecture. Use when asked to "find the ideal path," unify duplicated systems, or audit architecture before a refactor. Emits a proposed unified flowchart plus per-system /make-plan prompts.
-
duck4nh Skill Quality GatesUnified quality gate skill for pre-delivery checklist, security checks, testing strategy, and handover readiness.
-
theneoai Bundle LocksmithExpert locksmith specializing in residential, commercial, and automotive lock services including emergency lockout response, key cutting, lock installation, master key systems, and security assessments
-
theneoai Bundle Fintech Engineer> **DISCLAIMER:** This skill provides general fintech engineering education and information only. It does NOT constitute professional technology or financial advice. Building financial systems requires proper security audits, regulatory compliance, and professional engineering practices. This skill does not have access to actual financial systems or sensitive data.
-
theneoai Bundle Border InspectorSenior border inspector specializing in immigration control, passport verification, security screening, and traveler risk assessment
-
theneoai Bundle Food Safety ManagerA world-class food safety manager specializing in HACCP, food safety management systems, risk assessment, and regulatory compliance. Use when working on food safety plans, audit preparation, or hazard analysis
-
theneoai Bundle AI Security EngineerAI Security Engineer
-
theneoai Bundle Data Security OfficerData Security Officer
-
theneoai Bundle Robinhood Engineer> **DISCLAIMER:** This skill provides general education about Robinhood's technology and engineering practices. It does NOT constitute professional financial or legal advice. Building trading systems requires proper FINRA/SEC compliance, security audits, and regulatory adherence. Always consult qualified professionals for production implementations.
-
theneoai Bundle Defense ResearcherUse for defense technology research, dual-use assessment, TRL evaluation, and national security R&D. Triggers: "defense research", "dual-use technology", "TRL assessment", "DARPA"
-
theneoai Bundle Information Security AdminInformation Security Admin
-
theneoai Bundle Import Export SpecialistLicensed Customs Broker and International Trade Specialist with 12+ years managing global supply chains, customs clearance, and trade compliance. Expert in HTS classification, Incoterms, FTA utilization, and supply chain security. Licensed by CBP, IIEI certified. Managed $500M+ in annual import/export value. Use when: customs clearance, trade compliance, import/export documentation, HTS
-
theneoai Bundle Threat Intelligence AnalystThreat Intelligence Analyst
-
theneoai Bundle Crowdstrike SecurityExpert skill for crowdstrike-security
-
kbarbel640-del Bundle CrawsecureOffline security analysis skill that helps detect unsafe patterns in ClawHub skills before installation.
1 -
kbarbel640-del Bundle Security Review ConstructionSecurity review checklist for construction software systems. Use when building integrations, APIs, data pipelines, or dashboards for construction projects.
1 -
auto-skiller Bundle Audit Fix<purpose>
1 -
auto-skiller Bundle Audit Uat<purpose>
1 -
auto-skiller Bundle Audit Milestone<purpose>
1 -
heath-gtm Bundle Data Hygiene AuditData-Hygiene Audit
0 -
eryajf Bundle Github Actions EfficiencyAudit GitHub Actions workflow efficiency and recommend fixes to reduce CI minutes and costs.
0 -
eryajf Bundle Github Codespaces EfficiencyAudit and improve GitHub Codespaces efficiency. Use this skill when a user wants faster Codespaces startup, lower Codespaces spend, slim devcontainers, right-size machines, tune idle timeout, or scope prebuilds to branches with sustained usage.
0 -
vstorm-co Skill Code Review 2Systematic code review for bugs, security, style, and performance
-
steipete Bundle Gog Drive AuditRead-only Google Drive sharing and permission audits with gog.
-
darthlinuxer Bundle Webapp TestingWeb application testing principles. E2E, Playwright, deep audit strategies.
-
darthlinuxer Skill Code Review ChecklistCode review guidelines covering code quality, security, and best practices.
-
v1truv1us-ai-eng-system Skill Security And Hardening 2OWASP Top 10 prevention, auth patterns, secrets management, dependency auditing, three-tier boundary system. Use when handling user input, auth, data storage, or external integrations.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include locksmith, crawsecure, pentest-exploit-validation. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.