Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
comeonoliver Bundle Log AnalysisAnalyze application logs to identify errors, performance issues, and security anomalies. Use when debugging issues, monitoring system health, or investigating incidents. Handles various log formats including Apache, Nginx, application logs, and JSON logs.
61 -
comeonoliver Bundle Pair ProgrammingAI-assisted pair programming with multiple modes (driver/navigator/switch), real-time verification, quality monitoring, and comprehensive testing. Supports TDD, debugging, refactoring, and learning sessions. Features automatic role switching, continuous code review, security scanning, and performance optimization with truth-score verification.
61 -
serejaris Bundle Git Repo Audit深度分析 Git 仓库历史,识别高频变更的热点文件、分析代码的实际贡献归属关系、并扫描历史提交中的密钥泄露等安全隐患。当用户提及分析仓库、查看代码归属、寻找热点文件或安全风险扫描,或询问团队协作、代码审查分配、技术债务与安全审计等关键词时触发。
-
serejaris Bundle Tos Risk Checker以消费者视角审计服务条款(服务条款、用户协议、隐私政策),识别霸王条款、隐蔽数据授权、自动续费陷阱、单方面修改权、责任免除滥用等风险,输出包含总体评级、逐项风险分析和消费者行动建议的结构化审计报告。当用户要求审计服务条款、审查用户协议、分析隐私政策,或提及霸王条款、数据授权、自动续费、terms of service audit、ToS review、privacy policy review、用户协议风险分析、条款合规检查、消费者权益审计时触发。
-
serejaris Bundle Software Testing Guide建立全面的软件QA测试流程,包括制定测试策略、按照Google AAA标准编写测试用例、执行测试计划、使用P0-P4分级追踪缺陷、计算质量指标(如通过率与覆盖率)以及生成每日/每周进度报告。提供完整的文档模板,可直接用于外包团队交接,并实施OWASP安全测试,以90%的覆盖率为目标。当用户提到搭建QA流程、编写测试用例、制定测试计划、追踪缺陷(P0-P4)、计算质量指标、生成QA报告、进行安全测试或准备外包交接时触发。
-
allgpt-co Skill Gsd Audit MilestoneAudit milestone progress and status
-
backbay-labs Skill Thrunt Validate PhaseRetroactively audit and fill Nyquist validation gaps for a completed phase
-
backbay-labs Skill Thrunt Audit MilestoneAudit milestone completion against original intent before archiving
-
backbay-labs Skill Thrunt Plan Milestone GapsCreate phases to close all gaps identified by milestone audit
-
javimosch Skill Audit Badge DemoDemo skill showcasing the audit badge workflow; still experimental.
-
javimosch Skill Skill ScannerScan OpenClaw skills for security vulnerabilities before installing them. Use when evaluating a new skill from ClawHub or any third-party source. Detects credential stealers, data exfiltration, malicious URLs, obfuscated code, and supply chain attacks.
-
tryboy869 Bundle Code ReviewApply when reviewing code, giving feedback, or checking a PR. Covers: what to look for, how to give constructive feedback, security checklist, and common code smells. Trigger for: review, PR, pull request, code quality, feedback, refactor.
-
ulpi-io Skill Persona It AdminAdminister IT — monitor security and configure Workspace.
-
idocohen560 Skill HotfixEmergency fix workflow that bypasses normal sprint processes with a full audit trail. Creates hotfix branch, tracks approvals, and ensures the fix is backported correctly.
-
idocohen560 Skill Skill TestValidate skill files for structural compliance and behavioral correctness. Three modes: static (linter), spec (behavioral), audit (coverage report).
-
idocohen560 Skill Content AuditAudit GDD-specified content counts against implemented content. Identifies what's planned vs built.
-
idocohen560 Skill Security AuditAudit the game for security vulnerabilities: save tampering, cheat vectors, network exploits, data exposure, and input validation gaps. Produces a prioritised security report with remediation guidance. Run before any public release or multiplayer launch.
-
backbay-labs Skill Thrunt Audit EvidenceCross-phase audit of all outstanding Evidence Review and findings validation items
-
javimosch Skill Skill Security ScannerSkill Security Scanner
-
aravinds-wick Skill Network 101Configure and test common network services (HTTP, HTTPS, SNMP, SMB) for penetration testing lab environments. Enable hands-on practice with service enumeration, log analysis, and security testing against properly configured target systems.
-
asymmetric-al Skill Supabase Audit Buckets ReadAttempt to list and read files from storage buckets to verify access controls.
-
mikaru0mystic Bundle Analyzing Dns Logs For ExfiltrationAnalyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection in SIEM platforms. Use when SOC teams need to identify DNS-based threats that bypass traditional network security controls.
-
mikaru0mystic Bundle Analyzing Windows Amcache ArtifactsParses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations. Uses Eric Zimmerman's AmcacheParser and Timeline Explorer for artifact extraction, SHA-1 hash correlation with threat intel, and timeline reconstruction. Activates for requests involving Amcache forensics, program execution evidence, Windows artifact analysis, or application compatibility cache investigation.
-
mikaru0mystic Bundle Reverse Engineering IOS App With FridaReverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract encryption keys, bypass security controls, and discover hidden functionality without source code access. Use when performing authorized iOS penetration testing, analyzing proprietary protocols, understanding obfuscated logic, or extracting runtime secrets from iOS binaries. Activates for requests involving iOS reverse engineering, Frida iOS hooking, Objective-C/Swift method tracing, or iOS binary analysis.
-
udecode Skill Sync ShadcnAutogoal-backed planning, status, review, dashboard, apply, and tracking for upstream shadcn docs syncs into Plate docs. Use when the user asks for `sync-shadcn`, `sync-shadcn status`, `sync-shadcn review`, `sync-shadcn dashboard`, `sync-shadcn apply`, a scoped `sync-shadcn <feature>` lane, to sync shadcn docs, audit newer shadcn docs changes, compare `../shadcn/apps/v4` with `apps/www`, update the shadcn sync baseline, or decide what to adopt, fork, defer, or exclude from upstream shadcn.
-
tuoxie2046 Bundle Nature ResponseDraft, audit, or revise point-by-point reviewer response letters for Nature-family manuscript revisions. Use when the user provides reviewer comments, editor decision letters, revision notes, response drafts, or asks how to respond to major/minor revision requests, rebuttal letters, response to reviewers, peer-review reports, 审稿意见回复, 逐点回复, 修回信, 大修回复, 小修回复, or 如何回复 reviewer.
-
haibarakiku Bundle Social Security ExpertSenior social security expert specializing in pension insurance, medical coverage, unemployment benefits, workers' compensation, and maternity leave administration
-
ulpi-io Skill SecurityOWASP security patterns, secrets management, security testing
-
majiayu000 Bundle UfwUncomplicated Firewall management commands.
567 -
majiayu000 Bundle AssignsCompatibility alias for the Elixir/Phoenix plugin's LiveView assigns audit. Invoke explicitly with /lv:assigns.
567 -
majiayu000 Bundle Dpia StatusDPIA Status Skill
567 -
majiayu000 Bundle MultitenantThis skill provides guidelines and best practices.
567 -
majiayu000 Bundle Setup AuthUse when the user asks to "set up authentication", "add login", "add logout", "add sign in", "enable auth", "add role-based access", "add authorization", "protect routes", "configure identity provider", "configure Entra ID", "configure Entra External ID", "configure OpenID Connect", "add OIDC", "set up SAML", "set up WS-Federation", "set up local login", "add username password", "add Facebook login", "add Google sign in", "add Microsoft Account", "set up invitation login", or otherwise wants to set up authentication (login/logout) and role-based authorization for their Power Pages code site using any supported identity provider (Microsoft Entra ID, Entra External ID, OpenID Connect, SAML2, WS-Federation, local authentication, Microsoft Account, Facebook, or Google).
567 -
majiayu000 Bundle PlaybookConvert AEO audit findings into an executable implementation playbook.
567 -
majiayu000 Bundle Legal CatchallLegal: legal counsel, compliance, contracts, paralegal support. Triggers: contract review, legal advice, compliance, GDPR, SOC2, NDA, terms of service, privacy policy, IP, trademark, litigation, regulatory, vendor agreement.
567 -
majiayu000 Bundle Video PolicySecrets 漏れと .env の追跡を防止します。
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include tos-risk-checker, skill-security-scanner, log-analysis. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.