Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tuyv Bundle Bullshit Detector 2Fact-check and hype-audit content. Extracts the discrete claims from a video, article, tweet, or PDF, verifies each against independent sources via web search, and produces a report card with per-claim verdicts and an overall BS score (0-10). Use when the user asks to fact-check, verify, debunk, or evaluate credibility — "is this true/legit/bullshit", "check this video", "how much of this holds up".
-
tuyv Bundle Website Finishing Director 2Run a structured 5-pass finishing audit on any website before launch — scoring visual polish, technical foundation, UX completeness, content quality, and cross-device readiness on 100 points. Use when: **Pre-launch** - Final validation before going live; **Post-redesign** - Verify nothing broke during the overhaul; **Client handoff** - Structured proof that the site is ready; **Quarterly review** - Catch accumulated debt; **Single-pass focus** - Run just Pass 2 after a perf sprint
-
tuyv Bundle Suede Rights Audit 2Suede Labs skill that finds and organizes the rights gaps in a creator project before packaging: ownership, contributors, splits, samples, licenses, provenance, metadata, licensing readiness, and royalty-routing readiness, each marked confirmed or unknown against an evidence trail. Use when a song, release, or creative project needs a rights check before registry, licensing, sync, or payout discussion; when splits, sample clearance, or chain of title are unclear; or when someone asks whether they have the rights to release, license, or get paid for a work. Organizes evidence only: clears no rights, confirms no ownership, moves no money, writes to no registry. NOT FOR: building the transfer package itself (use suede-rights-passport); linting a release folder's files and metadata (use suede-release-linter); a sync one-sheet or pitch (use suede-sync-packaging).
-
tuyv Bundle Ar Social Contributions 2Use this skill whenever asked about Argentine self-employed social contributions (aportes autónomos). Trigger on phrases like "aportes autónomos", "categoría autónomos", "jubilación autónomos", "PAMI autónomos", "cuánto pago de autónomo", "contribuciones SIPA", or any question about Argentine social security obligations for self-employed individuals. Covers Categories I-V, retirement (SIPA), PAMI (INSSJP), and obra social contributions, monthly fixed amounts, VEP payment, and edge cases. ALWAYS read this skill before touching any Argentine social contribution work.
-
tuyv Bundle Bd Financial Statements 2> Use this skill whenever asked about financial statements and accounting reporting in Bangladesh. Trigger on phrases like "Bangladesh financial statements", "do I file accounts as sole proprietor Bangladesh", "RJSC financial statements", "IFRS Bangladesh", "BFRS", "audit requirement Bangladesh". Explains that sole proprietors file accounts with the tax return rather than statutory statements, and what companies must prepare under BFRS/IFRS and file with RJSC. ALWAYS read before any Bangladesh financial-reporting work.
-
tuyv Bundle Bd Social Contributions 2> Use this skill whenever asked about social security, pension, or retirement contributions for workers and the self-employed in Bangladesh. Trigger on phrases like "Bangladesh pension", "Universal Pension Scheme", "Sarbojanin Pension", "Surokkha scheme", "provident fund Bangladesh", "do freelancers pay social security Bangladesh". Covers the voluntary Universal Pension Scheme (incl. the self-employed Surokkha scheme), employee provident fund/gratuity, and the (limited) mandatory position. ALWAYS read before any Bangladesh social-contribution work.
-
tuyv Bundle Suede Release Linter 2Suede Labs skill that lints a local music or media release folder and scores it for release readiness: missing files, weak or malformed metadata, artwork and stem problems, split gaps, rights blockers, and platform-delivery issues, produced by a bundled offline script as a scored markdown and JSON report. Use when a creator has one or more release folders of tracks, artwork, and stems and wants to know what is missing before distributing, delivering, or handing it off; when metadata quality or a delivery rejection is the question; or when a release-readiness score is asked for. Reports what is present, missing, or unknown; never upgrades unknown to confirmed and never means legal clearance. NOT FOR: organizing the evidence behind a rights or split gap the report surfaces (use suede-rights-audit); building the transfer package (use suede-rights-passport); a sync one-sheet (use suede-sync-packaging).
-
tuyv Bundle Quarterly Database Cleanup 2Run a comprehensive quarterly CRM audit covering list health, bounce monitoring, data quality, scoring calibration, engagement metrics, and property cleanup. Produces a health report with quarter-over-quarter trend comparison.
-
tuyv Bundle Subscription Recovery 2Suede-owned recovery discipline for recurring charges billed outside Amazon: App Store, Google Play, PayPal, direct-bill streaming, gyms, news, and SaaS. Use when the user wants to find, audit, cancel, or dispute a subscription they may have forgotten, is being charged for twice, or no longer uses. Every cancellation and dispute requires the user to name the service first. Never enters payment credentials and never promises a refund. Requires Claude in Chrome for browser actions. NOT FOR: Amazon returns, restocking fees, or Amazon-billed Prime Video Channels, Audible, Kindle Unlimited, or Prime (use amazon-returns-recovery); merchant-side dunning and cancel-flow design (use suede-churn-prevention).
-
diegosouzapw Bundle Istio Majiayu000 2Istio Service Mesh
54 -
diegosouzapw Bundle Claude Settings Audit 3Analyze a repository to generate recommended Claude Code settings.json permissions. Use when setting up a new project, auditing existing settings, or determining which read-only bash commands to allow. Detects tech stack, build tools, and monorepo structure.
54 -
diegosouzapw Bundle Code Reviewer Rootcastleco 2> ⚠️ **AUTHORIZED USE ONLY** — This skill is intended for authorized security professionals only. Use only against systems you own or have explicit written permission to test. Unauthorized use may violate applicable laws.
54 -
diegosouzapw Bundle Credential Manager 2MANDATORY security foundation for OpenClaw. Consolidate scattered API keys and credentials into a secure .env file with proper permissions. Includes GPG encryption for high-value secrets, credential rotation tracking, deep scanning, and backup hardening. Use when setting up OpenClaw, migrating credentials, auditing security, or enforcing the .env standard. This is not optional — centralized credential management is a core requirement for secure OpenClaw deployments.
54 -
diegosouzapw Bundle Claude Settings Audit 4Analyze a repository to generate recommended Claude Code settings.json permissions. Use when setting up a new project, auditing existing settings, or determining which read-only bash commands to allow. Detects tech stack, build tools, and monorepo structure.
54 -
diegosouzapw Bundle Flutter Expert Rootcastleco 2> ⚠️ **AUTHORIZED USE ONLY** — This skill is intended for authorized security professionals only. Use only against systems you own or have explicit written permission to test. Unauthorized use may violate applicable laws.
54 -
diegosouzapw Bundle Deployment Engineer Rootcastleco 2> ⚠️ **AUTHORIZED USE ONLY** — This skill is intended for authorized security professionals only. Use only against systems you own or have explicit written permission to test. Unauthorized use may violate applicable laws.
54 -
diegosouzapw Bundle Hlab Auditor 2HLab Auditor Skill
54 -
diegosouzapw Bundle Program Security Basics 2Program Security Basics
54 -
diegosouzapw Bundle Global Security 2Your approach to handling global security. Use this skill when working on files where global security comes into play.
54 -
diegosouzapw Bundle Backend Architect Rootcastleco 2> ⚠️ **AUTHORIZED USE ONLY** — This skill is intended for authorized security professionals only. Use only against systems you own or have explicit written permission to test. Unauthorized use may violate applicable laws.
54 -
diegosouzapw Bundle Mobile Security Coder Avdelag1 2Use this skill when
54 -
diegosouzapw Bundle Minecraft Bukkit Pro Rootcastleco 2> ⚠️ **AUTHORIZED USE ONLY** — This skill is intended for authorized security professionals only. Use only against systems you own or have explicit written permission to test. Unauthorized use may violate applicable laws.
54 -
diegosouzapw Bundle Security Auditor Rootcastleco 2> ⚠️ **AUTHORIZED USE ONLY** — This skill is intended for authorized security professionals only. Use only against systems you own or have explicit written permission to test. Unauthorized use may violate applicable laws.
54 -
diegosouzapw Bundle Security Best Practices 2Perform language and framework specific security best-practice reviews and suggest improvements. Use when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go), and not for general debugging or non-security tasks.
54 -
diegosouzapw Bundle Secure Code Guardian Majiayu000 2Secure Code Guardian
54 -
diegosouzapw Bundle Power Bi Security Rls Best Practices 2Power BI Security and Row-Level Security Best Practices
54 -
tonone-ai Skill Patch Recon 2Audit existing vulnerability management — find SLA gaps, missing tiers, and process failures. Use when asked to "audit our vulnerability management", "find patch SLA gaps", or "are we patching fast enough".
-
tonone-ai Skill Phish Recon 2Audit existing security awareness program — coverage gaps, effectiveness metrics, and culture indicators. Use when asked to "audit our security awareness program", "find training coverage gaps", or "measure our security culture".
-
tonone-ai Skill Phish Train 2Design a security awareness training curriculum — topics, format, and effectiveness measurement. Use when asked to "design security training", "build a security awareness curriculum", or "train our team on security".
-
tonone-ai Skill Proof Audit 2Audit test suite health — find flaky tests, slow tests, coverage gaps, and testing anti-patterns. Use when asked to "audit tests", "fix flaky tests", "why are tests slow", "test health", or "improve test suite".
-
tonone-ai Skill Queue Recon 2Audit existing queue and streaming infrastructure — find missing DLQs, scaling gaps, and reliability issues. Use when asked to "audit our queues", "do we have DLQs", or "find queue reliability gaps".
-
tonone-ai Skill Terms Recon 2Survey existing privacy and legal docs for completeness and GDPR compliance. Use when asked to "audit our privacy docs", "are we GDPR compliant on paper", or "what legal docs are missing".
-
tonone-ai Skill Token Recon 2Audit token usage patterns — avg context size, waste, truncation frequency, budget adherence. Use when asked to "audit our token usage", "how often do we truncate", or "find context waste".
-
tonone-ai Skill Vigil Check 2Verify observability posture — audit monitoring coverage, find blind spots, prioritize gaps. Use when asked "is monitoring sufficient", "observability review", "are we covered", or "pre-launch monitoring check".
-
tonone-ai Skill Draft Review 2Usability review — evaluate an existing flow or UI against usability heuristics, flag friction points, and recommend fixes. Use when asked to "review the UX", "usability audit", "what's wrong with this flow", "UX feedback", "critique this design", or "why are users dropping off here".
-
tonone-ai Skill Proof Design 2Design QA audit — red flags, severity classification, visual quality scorecard. Use when asked to "QA the design", "check visual quality", "design review before launch", "visual bugs", "design audit", or "does this look right".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include bullshit-detector, website-finishing-director, suede-rights-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.