Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Security RiskCombine security scanning and threat modeling for changes involving data handling, API interception, sync, storage, authentication, or encryption.
567 -
majiayu000 Bundle Security CatchallSecurity: audits, compliance, penetration testing, secure coding. Triggers: security audit, vulnerability, penetration test, compliance, gdpr, soc2, secure coding, owasp, authentication, authorization, encryption, security policy.
567 -
majiayu000 Bundle Ops Compliance RunbookExecute compliance audit workflows with evidence trails and approvals; use when asked to verify SOC2, HIPAA, or GDPR controls.
567 -
majiayu000 Bundle Lore Link AuditAudit touched files for missing links, missing origin fields, and add Lore Debt entries.
567 -
majiayu000 Bundle Aoa Sanitized Shareaoa-sanitized-share
567 -
majiayu000 Bundle Better Auth Profile 2Add a complete account settings page with profile editing, password changes, email updates, session management, and account deletion.
567 -
majiayu000 Bundle Better Auth EmailsAdd email verification, password reset, and account management emails to Better Auth using Resend.
567 -
majiayu000 Bundle Headless Vault CLISecure credential management with headless vault operations.
567 -
majiayu000 Bundle Review TechnicalParallel multi-skill technical review of plans/specs/approaches for architecture, simplicity, security, and implementation rigor. Use when asked to "review the plan/spec," "technical review," or to sanity-check a proposed approach before implementation.
567 -
majiayu000 Bundle Test Audit SkillTest skill for audit workflow. Use when testing quality gates.
567 -
majiayu000 Bundle Compliance Check SkillCompliance Check Skill
567 -
majiayu000 Bundle Data Sovereignty SkillData Sovereignty Skill
567 -
majiayu000 Bundle Attachment AuditAttachment Audit
567 -
majiayu000 Bundle Antinet Security Scan对进入系统的文件或 URL 执行安全与合规扫描,输出 pass/reject 判定与扫描报告,作为所有文档处理的强制前置关卡。
567 -
majiayu000 Bundle Risk Assessment SkillRisk Assessment Skill
567 -
majiayu000 Bundle Security Review SkillSecurity Review Skill
567 -
majiayu000 Bundle Aoa Approval Gate Checkaoa-approval-gate-check
567 -
majiayu000 Bundle API Credentials HygieneAudit and maintain API credential security and rotation schedules.
567 -
majiayu000 Bundle Better Auth Protected Routes 2Add server-side route protection to enforce authentication on specific pages while keeping others public.
567 -
majiayu000 Bundle Open Source Licensing SkillOpen Source Licensing Skill
567 -
majiayu000 Bundle Aoa Invariant Coverage Auditaoa-invariant-coverage-audit
567 -
majiayu000 Bundle Vulnerability Assessment SkillVulnerability Assessment Skill
567 -
majiayu000 Bundle Security Anton Abyzov SpecweaveSecurity engineer for vulnerability assessment, penetration testing guidance, and secure code review. Use for OWASP Top 10 checks, threat modeling, or security architecture review. Covers authentication flaws, injection vulnerabilities, access control, and compliance requirements.
567 -
majiayu000 Bundle Hope 2Cognitive operating system for structured thinking with confidence tracking. Use when starting complex tasks, making decisions, or needing verification. Triggers on "how confident", "verify this", "alternative approach", "what could go wrong", "think through", confidence questions, or multi-step reasoning tasks.
567 -
majiayu000 Bundle Google Ads Audit 3Google Ads account audit and business context setup. Run this first — it gathers business information, analyzes account health, and saves context that all other ads skills reuse. Trigger on "audit my ads", "ads audit", "set up my ads", "onboard", "account overview", "how's my account", "ads health check", "what should I fix in my ads", or when the user is new to NotFair and hasn't run an audit before. Also trigger proactively when other ads skills detect that business-context.json is missing.
567 -
majiayu000 Bundle Blockchain Anton Abyzov SpecweaveBlockchain and Web3 development with Solidity, Hardhat, Foundry, ethers.js, and smart contract security. Covers Ethereum, Layer 2 solutions, DeFi, NFTs, and decentralized storage. Activates for: blockchain, web3, solidity, smart contract, Ethereum, Hardhat, Foundry, ERC-20, ERC-721, NFT, DeFi, dapp, WalletConnect, IPFS, layer 2, gas optimization, reentrancy, OpenZeppelin.
567 -
majiayu000 Bundle Secrets Davidroliverba ArchitectkbManage secrets via Bitwarden - retrieve credentials, set up environment variables
567 -
majiayu000 Bundle Tasks Code Review 2Use for QUICK PR reviews with structured checklists (architecture, patterns, security, performance). Provides step-by-step review process, git diff commands, and review report templates. Best for pull request reviews and pre-commit checks. NOT for deep refactoring analysis (use code-review instead).
567 -
majiayu000 Bundle Analyze Spec 2Analyze an existing spec for inconsistencies, missing information, ambiguities, and structure issues. Use when user says "analyze spec", "review spec", "spec quality check", "validate requirements", "audit spec", or "check spec quality".
567 -
majiayu000 Bundle Context Check 2Optional manual drift audit — report stale provenance-tracked docs (via _provenancelib drift detection across .codearbiter/.provenance/), then per stale doc offer re-scout / re-baseline / defer. Not the daily loop; commit-gate auto-heal owns routine maintenance.
567 -
majiayu000 Bundle Pci Compliance Anton Abyzov SpecweavePCI DSS compliance expert for secure payment card handling and audit preparation. Use when implementing card tokenization, encrypting payment data, or preparing for PCI compliance audits. Covers SAQ levels, data minimization, access control, and audit logging requirements.
567 -
majiayu000 Bundle Bug Review 2Systematically uncover and fix bugs using language-specific expertise and reproducible evidence. Triggers: bug hunting, defect detection, debugging, fix verification, bug fix, regression check, error investigation, defect documentation Use when: deep bug hunting needed, documenting defects, verifying fixes, systematic debugging required DO NOT use when: test coverage audit - use test-review instead. DO NOT use when: architecture issues - use architecture-review. Use this skill for systematic bug hunting with evidence trails.
567 -
majiayu000 Bundle Java Spring Anton Abyzov SpecweaveJava/Spring Boot backend developer for building enterprise APIs and microservices. Use when building Java backends with Spring Boot 3.x, REST/gRPC APIs, Spring Data JPA, Spring Security 6, reactive WebFlux, or microservice architectures.
567 -
majiayu000 Bundle Issue Triage Florianbruniaux CcboardIssue triage: audit open issues, categorize, detect duplicates, cross-ref PRs, risk assessment, post comments. Args: "all" for deep analysis of all, issue numbers to focus (e.g. "42 57"), "en"/"fr" for language, no arg = audit only in French.
567 -
majiayu000 Bundle Code Review Oprogramadorreal Optimus ClaudeReviews local changes, an open PR/MR, or a branch diff against the project's own coding guidelines through the review lenses — bugs, security, guidelines, architecture, simplification, plus test coverage and API contracts when relevant — inline on a small diff, in parallel agents on a larger one. Excludes style and linter-catchable issues. Read-only: applies fixes or posts PR/MR comments only on explicit approval. For an iterative auto-fix loop, use /optimus:deep review.
567 -
majiayu000 Bundle Security And Vulnerability Management______________________________________________________________________
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-risk, security-catchall, ops-compliance-runbook. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.