Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle CheatsheetsQuick reference cheatsheets for Kailash SDK patterns, nodes, workflows, and best practices. Use when asking about 'quick tips', 'cheat sheet', 'quick reference', 'common mistakes', 'node selection', 'workflow patterns library', 'cycle patterns', 'production patterns', 'performance optimization', 'monitoring', 'security config', 'multi-tenancy', 'distributed transactions', 'saga pattern', 'custom nodes', 'PythonCode data science', 'ollama integration', 'directoryreader patterns', or 'environment variables'.
567 -
majiayu000 Bundle Cve ResearchResearch CVEs and security advisories for project dependencies. Uses Exa, NVD API, OSV.dev, and GitHub Advisory Database to find known vulnerabilities.
567 -
majiayu000 Bundle Evm AnalysisDeep EVM bytecode analysis and decompilation capabilities for smart contract security, gas optimization, and reverse engineering. Provides tools for analyzing opcodes, storage layouts, proxy patterns, and bytecode verification.
567 -
majiayu000 Bundle OpenzeppelinExpert usage of OpenZeppelin Contracts library for secure smart contract development. Covers access control, token standards, governance, upgrades, and security utilities.
567 -
majiayu000 Bundle Secret SetupFocused micro-skill for secret management setup. Explains options, guides through Bitwarden installation/login/unlock, configures backend. Exits when done.
567 -
majiayu000 Bundle Skill ChainsOrdered sequences of individual audit skills to execute for different audit depth levels ensuring comprehensive, systematic coverage. Use when selecting between quick scan, standard audit, deep audit, or full engagement workflows to match coverage to time and scope constraints.
567 -
majiayu000 Bundle Attack ChainsDetect multi-step exploit sequences where individual steps may appear benign but combine into critical vulnerabilities. Use when analyzing protocols for flash-loan-to-governance chains, oracle manipulation sequences, or cross-contract re-entrancy paths inspired by real-world exploits like Ronin, Wormhole, and Beanstalk.
567 -
majiayu000 Bundle Aztec ScannerUse when the user wants to audit Aztec Network smart contracts written in Noir, scan for privacy-specific vulnerabilities including state leakage, note handling, or nullifier collisions, review private DeFi protocols for information disclosure, or analyze encrypted computation and zero-knowledge proof circuits.
567 -
majiayu000 Bundle Cosmos ScannerUse when the user wants to audit Cosmos SDK modules or CosmWasm smart contracts, scan IBC protocol interactions for relay, channel, or packet vulnerabilities, review Cosmos Go modules for state machine exploits, or analyze cross-chain message handling in the Cosmos ecosystem.
567 -
majiayu000 Bundle Solana ScannerUse when auditing Solana programs for security vulnerabilities, reviewing Anchor or Pinocchio/native Rust smart contracts, checking CPI safety, PDA validation, account ownership, signer verification, or Token-2022 security.
567 -
majiayu000 Bundle Token AnalyzerAnalyze ERC20/ERC721/ERC1155 token implementations for non-standard behavior, fee-on-transfer mechanics, rebasing logic, blacklists, pausability, and integration risks. Use when reviewing protocols that interact with external tokens or implementing token-related features.
567 -
majiayu000 Bundle AuditcodexdirectSend specific files to OpenAI Codex CLI for an independent audit/review
567 -
majiayu000 Bundle Check BlacklistCheck email blacklist status and manage blacklisted emails
567 -
majiayu000 Bundle Cyfrin FindingsQuery the Cyfrin/Solodit findings database (50,530+ findings from 30+ audit firms) for vulnerability research, pattern extraction, and audit enhancement. Use when searching for historical findings by vulnerability type, protocol category, or severity, or when looking for similar bugs found in comparable protocols.
567 -
majiayu000 Bundle Spec ComplianceVerify smart contract implementations comply with EIP/ERC standards and protocol specifications. Use when checking ERC-20, ERC-721, ERC-1155, ERC-4626, or EIP-712 compliance, or when identifying non-standard token behavior that causes integration failures.
567 -
majiayu000 Bundle Perception SystemAI perception skill for sight, hearing, and threat detection systems.
567 -
majiayu000 Bundle Review SimplicityAudit code for over-engineering, premature optimization, and cognitive complexity.
567 -
majiayu000 Bundle Agentshield ScanRun AgentShield security scan on framework configs
567 -
majiayu000 Bundle Solidity ScannerUse when the user wants to audit Solidity smart contracts for security vulnerabilities, scan EVM-compatible contracts for reentrancy, oracle manipulation, access-control, or flash-loan issues, review DeFi protocols on Ethereum, Arbitrum, Optimism, Base, Polygon, or BSC, or generate security audit reports for smart contract deployments.
567 -
majiayu000 Bundle Review Type SafetyAudit TypeScript code for type safety issues—any/unknown abuse, invalid states, missing narrowing.
567 -
majiayu000 Bundle Context DetectionAutomatically identify the type of protocol being audited to load appropriate checklists, templates, and vulnerability patterns without manual configuration. Use when starting any new audit to classify the protocol (DeFi lending, AMM, bridge, governance, etc.) and surface the most relevant checks.
567 -
majiayu000 Bundle Cyber Security Expert网络安全与渗透测试专家,专注于漏洞分析、安全防护及代码审计。
567 -
majiayu000 Bundle Domain MonitoringDomain Monitoring
567 -
majiayu000 Bundle Review TestabilityAudit code for testability design patterns. Identifies business logic entangled with IO and suggests functional core / imperative shell separation.
567 -
majiayu000 Bundle Privacylrs Test RunnerRun PlatformIO tests for PrivacyLRS to validate code changes and security fixes
567 -
majiayu000 Bundle Protocol TemplatesStructured, protocol-type-specific audit templates enumerating the exact checks, invariants, and attack vectors relevant to each protocol category. Use when auditing AMM/DEX, lending, bridge, governance, or vault protocols to load targeted checklists based on context detection results.
567 -
majiayu000 Bundle Security Scan TrivySecurity Scan Trivy
567 -
majiayu000 Bundle Code Review LargeIn-depth code review for large PRs (>500 lines). Full analysis including architecture, performance, security, and maintainability.
567 -
majiayu000 Bundle Code Review MediumStandard code review for medium PRs (100-500 lines). Includes code quality, security basics, and test coverage analysis.
567 -
majiayu000 Bundle Review MaintainabilityAudit code for DRY violations, dead code, complexity, and consistency issues.
567 -
majiayu000 Bundle Auth Intrale PlatformAuth — Auditoría y gestión de permisos de Claude Code
567 -
majiayu000 Bundle Checkpoints Rwb3n Haiosgenerated: 2025-12-05
567 -
majiayu000 Bundle Symfony Security VotersSymfony security voters — role hierarchy, voter pattern, access control, authorization, permissions, IsGranted attribute. Triggers on: security, voter, role, authorization, access control, permission, IsGranted, role hierarchy, RBAC
567 -
majiayu000 Bundle File Integrity MonitoringFile Integrity Monitoring
567 -
majiayu000 Bundle Self Audit Against ProtocolAudit own behavior against protocol specifications.
567 -
majiayu000 Bundle Enforce Security VigilanceEnforce continuous security vigilance and threat monitoring.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include cheatsheets, cve-research, evm-analysis. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.