Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Shell Review 3Audit shell scripts for correctness, portability, and common pitfalls. Use when reviewing shell scripts, CI scripts, hook scripts, wrapper scripts. Do not use when creating new scripts - use attune:workflow-setup.
567 -
majiayu000 Bundle Evidence Logging 2Use this skill as foundation for all evidence-based review workflows. Use when conducting any review that needs evidence trails, creating audit documentation, ensuring reproducibility of analyses. Do not use when quick informal checks without documentation needs. DO NOT use when: structured output is the focus - use structured-output.
567 -
majiayu000 Bundle Implementing Tasks 0xhoneyjar Loa Beauvoir<input_guardrails>
567 -
majiayu000 Bundle AI GovernanceUse when validating compliance, ownership, risk lifecycle, or framework integrity for regulated industries. Modes: compliance | ownership | risk | integrity.
567 -
majiayu000 Bundle Decision Variance 2Reconcile the project's architectural artifacts against the scaffold and prior decisions, then present each variance as a SMARTS analysis for the user to decide. Routed to when the user asks to arbitrate, reconcile, or consolidate architectural context, requests a variance report, mentions ADR conflicts, or asks which downstream artifacts the current state supports. Never decides alone — every arbitration is user-attributed and logged.
567 -
majiayu000 Bundle Decision Variance 3Reconcile the project's architectural artifacts against the scaffold and prior decisions, then present each variance as a SMARTS analysis for the user to decide. Routed to when the user asks to arbitrate, reconcile, or consolidate architectural context, requests a variance report, mentions ADR conflicts, or asks which downstream artifacts the current state supports. Never decides alone — every arbitration is user-attributed and logged.
567 -
majiayu000 Bundle Implementing Tasks 0xhoneyjar Loa Beauvoir 2<input_guardrails>
567 -
majiayu000 Bundle Multitenant 3This skill provides guidelines and best practices.
567 -
majiayu000 Bundle Multitenant 4This skill provides guidelines and best practices.
567 -
majiayu000 Bundle Recon 2Security reconnaissance. USE WHEN recon, reconnaissance, bug bounty, attack surface. SkillSearch('recon') for docs.
567 -
majiayu000 Bundle Phx Audit 3Project health audit and health check — architecture, performance, tests, dependencies, code quality. Use when assessing overall project health, before releases, or after refactors.
567 -
majiayu000 Bundle Phx Audit 4Project health audit and health check — architecture, performance, tests, dependencies, code quality. Use when assessing overall project health, before releases, or after refactors.
567 -
majiayu000 Bundle Incident Response Vuralserhat86 Antigravity AgenticThis skill empowers Claude to guide you through the security incident response process, ensuring a structured and effective approach to handling security breaches and attacks. It helps you classify in
567 -
majiayu000 Bundle Security FlutterFlutter Security. Use when reviewing security, implementing auth, or hardening code.
567 -
majiayu000 Bundle Test Master 2Use when writing tests, creating test strategies, or building automation frameworks. Invoke for unit tests, integration tests, E2E, coverage analysis, performance testing, security testing.
567 -
majiayu000 Bundle Bmad Wds Workflow ValidateSystematically audit page specifications for completeness, consistency, and quality.
567 -
majiayu000 Bundle Audit Refactoring 2Run a single-session refactoring audit on the codebase
567 -
majiayu000 Bundle Auth Implementation Patterns 2Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues.
567 -
majiayu000 Bundle Architecture Paradigm Cqrs Es 2Apply CQRS and Event Sourcing for read/write separation and audit trails.
567 -
majiayu000 Bundle Ln 512 Tech Debt Cleaner 2Auto-fixes low-risk tech debt (unused imports, dead code, commented-out code) with >=90% confidence. Use when audit findings need safe automated cleanup.
567 -
majiayu000 Bundle Ln 760 Security Setup 2Sets up security scanning for secrets and dependency vulnerabilities. Use when adding security infrastructure to a project.
567 -
majiayu000 Bundle Ln 761 Secret Scanner 2Scans codebase for hardcoded secrets with severity classification and remediation guidance. Use when auditing a project for leaked credentials.
567 -
majiayu000 Bundle Ln 651 Query Efficiency Auditor 2Query efficiency audit worker (L3). Checks redundant entity fetches, N-UPDATE/DELETE loops, unnecessary resolves, over-fetching, missing bulk operations, wrong caching scope. Returns findings with severity, location, effort, recommendations.
567 -
majiayu000 Bundle Ln 643 API Contract Auditor 2API contract audit worker (L3). Checks layer leakage in method signatures, missing DTOs, entity leakage to API, inconsistent error contracts, redundant method overloads. Returns findings with penalty-based scoring + diagnostic sub-scores.
567 -
majiayu000 Bundle Repo Generating Validation Reports 2Guidelines for generating validation/audit reports with UUID chains, progressive writing, and UTC+7 timestamps
567 -
johnalbertini14-glitch Bundle CdnConfigure, optimize, and troubleshoot CDN deployments with caching strategies, security hardening, and multi-provider management.
1 -
johnalbertini14-glitch Bundle IotAssist with IoT device setup, protocols, security hardening, and home automation integration.
1 -
johnalbertini14-glitch Bundle BottubeSecurity and Permissions
1 -
johnalbertini14-glitch Bundle Env DoctorDiagnose .env file issues — missing variables, format errors, security risks, and misconfigurations.
1 -
johnalbertini14-glitch Bundle Lan ScannerDiscover devices and scan ports on your local network using nmap with security-first defaults.
1 -
johnalbertini14-glitch Bundle Secret RotatorAudit and rotate API keys, tokens, and secrets with expiry tracking and safe handling.
1 -
johnalbertini14-glitch Bundle SecurityreviewStandard Operating Procedures: Security Analysis Guidelines
1 -
johnalbertini14-glitch Bundle Seithar Intelseithar-intel — Threat Intelligence & Cognitive Security Feed
1 -
johnalbertini14-glitch Bundle Dependency CheckerScan npm and pip projects for outdated dependencies, security vulnerabilities, and updates.
1 -
johnalbertini14-glitch Bundle Dockerfile OptimizerAnalyze Dockerfiles for size, build speed, and security — generate optimized versions.
1 -
johnalbertini14-glitch Bundle Threat ModelingThreat Modeling Expert
1
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include shell-review, evidence-logging, implementing-tasks-0xhoneyjar-loa-beauvoir. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.