Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
sahit-sai Bundle Geo Audit 2Comprehensive GEO audit diagnosing why AI systems cannot discover, cite, or recommend a website — scores technical, content, schema, and brand dimensions with a prioritized fix plan. Use when the user mentions GEO audit, AI visibility, AI search optimization, AI citability, or provides a URL and asks why AI can't find/cite/recommend their site.
-
sahit-sai Bundle Glic Check 2Systematic quality check for code, skills, configs, and documents. Two modes — GLIC for internal quality (4 dimensions: Grammar / Logic / Integrity / Containment) and UGLIC adding User Experience (5 dimensions: U + G + L + I + C). Each finding cites file:line; severity is tagged as ERR / WARN / INFO with explicit escalation rules (silent-failure = ERR, 3× repeated WARN → ERR, missing public-param doc = ERR). Use when the user says "GLIC check", "UGLIC check", "do a glic", "systematically review this", "audit my skill", "quality check this code", or any phrasing that asks for a multi-dimension review of code / skills / configs / docs.
-
sahit-sai Bundle Geo Monitor 2Re-audit a website and compare scores against a previous GEO audit baseline to track improvement over time. Use when the user asks to re-audit, check progress, track GEO score changes, monitor improvements, or compare before and after optimization.
-
sahit-sai Bundle Review Report 2Actionable feedback on the quality, usage, and effectiveness of Power BI reports. Automatically invoke when the user asks to "review a report", "audit a report", "report usage analysis", "report health check", "find unused reports", "check if a report is being used", "assess report performance", "evaluate report quality".
-
sahit-sai Skill Security Audit 2[中危] 应尽快修复
-
sahit-sai Bundle Audit Tenant Settings 2Automatically invoke this skill whenever the user asks about Fabric tenant settings or Power BI tenant settings or auditing tenant settings. You can use this skill if the user mentions "Fabric administration".
-
junmystery Skill Repo Scan 2Bootstrap pointer that installs the external repo-scan skill from a pinned, reviewable commit. Use when repo-scan must be installed before running its cross-stack source-code asset audit; this ECC pointer does not perform the audit itself.
-
junmystery Skill Perl Security 2Comprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies. Use when reviewing Perl input handling, process execution, DBI queries, or web-facing code.
-
junmystery Bundle Security Review 2Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
-
junmystery Skill Click Path Audit 2Trace every user-facing button/touchpoint through its full state change sequence to find bugs where functions individually work but cancel each other out, produce wrong final state, or leave the UI in an inconsistent state. Use when: systematic debugging found no bugs but users report broken buttons, or after any major refactor touching shared state stores.
-
junmystery Skill Hipaa Compliance 2HIPAA-specific entrypoint for healthcare privacy and security work. Use when a task is explicitly framed around HIPAA, PHI handling, covered entities, BAAs, breach posture, or US healthcare compliance requirements.
-
handsomeboy990 Bundle Security Audit 2Security Audit
-
handsomeboy990 Bundle Security Core 2Security Core
-
handsomeboy990 Bundle Security Testing 2Security Testing
-
handsomeboy990 Bundle Threat Modeling 2Threat Modeling
-
handsomeboy990 Bundle Security Headers 2Security Headers
-
handsomeboy990 Bundle Session Security 2Session Security
-
handsomeboy990 Bundle Dependency Security 2Dependency Security
-
handsomeboy990 Bundle Authorization Design 2Authorization Design
-
handsomeboy990 Bundle Security Architecture 2Security Architecture
-
handsomeboy990 Bundle Authorized Pentesting 2Authorized Pentesting
-
handsomeboy990 Bundle Authentication Security 2Authentication Security
-
handsomeboy990 Bundle Vulnerability Assessment 2Vulnerability Assessment
-
junmystery Skill Laravel Security 2Laravel security best practices — authentication, authorization, Eloquent safety, CSRF, XSS prevention, API security, and secure deployment configurations. Use when reviewing Laravel auth, Eloquent safety, CSRF, XSS, API security, or deployment configuration.
-
junmystery Skill Production Audit 2Local-evidence production readiness audit for shipped apps, pre-launch reviews, post-merge checks, and "what breaks in prod?" questions without sending repo data to an external audit service. Use when auditing production readiness before launch, after a merge, or when asked what breaks in prod.
-
junmystery Skill Quarkus Security 2Quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security. Use when reviewing Quarkus authn/authz, JWT or OIDC, RBAC, validation, or secrets.
-
junmystery Skill Defi Amm Security 2Security checklist for Solidity AMM contracts, liquidity pools, and swap flows. Covers reentrancy, CEI ordering, donation or inflation attacks, oracle manipulation, slippage, admin controls, and integer math. Use when auditing or writing Solidity AMM, liquidity pool, or swap code.
-
junmystery Skill Postgres Patterns 2PostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices. Use when designing PostgreSQL schemas, indexes, or RLS policies, or when a query is too slow.
-
junmystery Skill Django Verification 2Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.
-
junmystery Skill Springboot Security 2Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services. Use when reviewing Spring Security authn/authz, validation, CSRF, secrets, headers, or rate limiting.
-
junmystery Skill Quarkus Verification 2Verification loop for Quarkus projects: build, static analysis, tests with coverage, security scans, native compilation, and diff review before release or PR.
-
vishuwa2004 Skill CLI Command Surface Audit 2Audit a command surface end to end so registration, discoverability, permissions, and execution all line up before shipping.
-
serejaris Bundle Git Repo Audit 2深度分析 Git 仓库历史,识别高频变更的热点文件、分析代码的实际贡献归属关系、并扫描历史提交中的密钥泄露等安全隐患。当用户提及分析仓库、查看代码归属、寻找热点文件或安全风险扫描,或询问团队协作、代码审查分配、技术债务与安全审计等关键词时触发。
-
serejaris Bundle Tos Risk Checker 2以消费者视角审计服务条款(服务条款、用户协议、隐私政策),识别霸王条款、隐蔽数据授权、自动续费陷阱、单方面修改权、责任免除滥用等风险,输出包含总体评级、逐项风险分析和消费者行动建议的结构化审计报告。当用户要求审计服务条款、审查用户协议、分析隐私政策,或提及霸王条款、数据授权、自动续费、terms of service audit、ToS review、privacy policy review、用户协议风险分析、条款合规检查、消费者权益审计时触发。
-
serejaris Bundle Software Testing Guide 2建立全面的软件QA测试流程,包括制定测试策略、按照Google AAA标准编写测试用例、执行测试计划、使用P0-P4分级追踪缺陷、计算质量指标(如通过率与覆盖率)以及生成每日/每周进度报告。提供完整的文档模板,可直接用于外包团队交接,并实施OWASP安全测试,以90%的覆盖率为目标。当用户提到搭建QA流程、编写测试用例、制定测试计划、追踪缺陷(P0-P4)、计算质量指标、生成QA报告、进行安全测试或准备外包交接时触发。
-
yogsoth-ai Skill Assumption Audit 2Surface all assumptions, classify by vulnerability (load-bearing × likely-false), validate causal logic. Focus on dangerous assumptions — high load-bearing + non-explicit.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include geo-audit, glic-check, geo-monitor. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.