Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
the-utopia-studio Skill Porters Five Forces 2Perform Porter's Five Forces analysis — competitive rivalry, supplier power, buyer power, threat of substitutes, and threat of new entrants. Use when analyzing industry dynamics, assessing competitive forces, or evaluating market attractiveness.
-
sairam0424 Skill Web Pentest 3Authorized web application penetration testing — reconnaissance, vulnerability analysis, proof-based exploitation, and professional reporting. Adapts Shannon's "No Exploit, No Report" methodology with hard guardrails for scope, authorization, and aux-client leakage. Active testing against running applications you own or have written authorization to test.
-
sairam0424 Skill Mindforge Audit Uat 2Cross-phase audit of all outstanding UAT and verification items
-
sairam0424 Skill Requesting Code Review 4Pre-commit review: security scan, quality gates, auto-fix.
-
sairam0424 Skill Mindforge Validate Phase 2Retroactively audit and fill Nyquist validation gaps for a completed phase
-
sairam0424 Skill Mindforge Audit Milestone 2Audit milestone completion against original intent before archiving
-
sairam0424 Skill Mindforge Plan Milestone Gaps 2Create phases to close all gaps identified by milestone audit
-
idocohen560 Skill Hotfix 2Emergency fix workflow that bypasses normal sprint processes with a full audit trail. Creates hotfix branch, tracks approvals, and ensures the fix is backported correctly.
-
idocohen560 Skill Skill Test 2Validate skill files for structural compliance and behavioral correctness. Three modes: static (linter), spec (behavioral), audit (coverage report).
-
idocohen560 Skill Content Audit 2Audit GDD-specified content counts against implemented content. Identifies what's planned vs built.
-
idocohen560 Skill Security Audit 2Audit the game for security vulnerabilities: save tampering, cheat vectors, network exploits, data exposure, and input validation gaps. Produces a prioritised security report with remediation guidance. Run before any public release or multiplayer launch.
-
drmoisan Skill Review Epic 2Invoke the epic-review worker to produce epic-audit artifacts for an epic folder.
-
drmoisan Skill Feature Review 2Review a feature branch relative to a base branch and write audit artifacts into the active feature folder. Use when Codex must produce policy, code, and feature audits and trigger remediation planning when needed.
-
drmoisan Skill Review Feature 2Invoke the feature-review worker to produce feature-audit artifacts for an active feature folder.
-
drmoisan Skill Commit Message Conventions 2Generate a single high-signal conventional commit message from staged Git changes or an explicit commit-context artifact. Use when Codex or a subagent must classify dominant change intent, choose a precise commit type and optional scope, and emit an audit-quality message that is immediately usable with `git commit`.
-
drmoisan Skill Policy Audit Template Usage 3Policy audit template usage and output requirements. Use when creating policy-audit.<timestamp>.md artifacts from the repo templates.
-
drmoisan Skill Policy Audit Template Usage 4Policy audit template usage and output requirements. Use when creating policy-audit.<timestamp>.md artifacts from the repo templates.
-
drmoisan Skill Skill Canonical Location Audit 4Audit skills for canonical-location duplication. Use when ensuring a canonical location for a given item is defined in exactly one skill and duplicates are flagged.
-
drmoisan Skill Skill Canonical Location Audit 5Audit skills for canonical-location duplication. Use when ensuring a canonical location for a given item is defined in exactly one skill and duplicates are flagged.
-
drmoisan Skill Skill Canonical Location Audit 6Audit skills for canonical-location duplication. Use when ensuring a canonical location for a given item is defined in exactly one skill and duplicates are flagged.
-
drmoisan Skill Evidence And Timestamp Conventions 4Evidence storage and timestamp naming conventions for audits and remediation. Use when storing baseline/regression/QA evidence or naming audit artifacts with ISO-8601 timestamps.
-
drmoisan Skill Evidence And Timestamp Conventions 5Evidence storage and timestamp naming conventions for audits and remediation. Use when storing baseline/regression/QA evidence or naming audit artifacts with ISO-8601 timestamps.
-
drmoisan Skill Remediation Handoff Atomic Planner 4Remediation handoff chain from orchestrator through atomic-planner, atomic-executor, and feature-review. Use when an audit cycle requires a delegated remediation plan, preflight clearance, task-by-task execution, and reaudit.
-
drmoisan Skill Evidence And Timestamp Conventions 6Evidence storage and timestamp naming conventions for audits and remediation. Use when storing baseline/regression/QA evidence or naming audit artifacts with ISO-8601 timestamps.
-
markus41 Skill M365 Auditor 2Design Microsoft 365 audit log query specifications and compliance reporting for FINRA, state insurance examiner, and internal audit requirements in financial services tenants.
-
dirnbauer Bundle Security Incident Reporting 2Builds security incident reports, DDoS post-mortems, timelines, IoC sections, CVE correlation, severity scoring, and blameless root cause analysis. Use when the user needs an incident report, post-mortem, forensics summary, security timeline, DDoS analysis, SIR, root cause analysis, or communication for a security event.
-
dirnbauer Bundle Architecture Decision Records 2Creates and reviews architecture decision records (ADRs), decision logs, and supersession histories using established conventions and verifiable evidence. Use when users ask to write, reconstruct, audit, standardize, validate, or maintain ADRs, architecture decisions, decision logs, or ADR templates in Markdown or reStructuredText.
-
gabeujin Skill Postgresql Code Review 2PostgreSQL-specific code review assistant focusing on PostgreSQL best practices, anti-patterns, and unique quality standards. Covers JSONB operations, array usage, custom types, schema design, function optimization, and PostgreSQL-exclusive security features like Row Level Security (RLS).
-
the-utopia-studio Bundle Ada 2Run technical due diligence as Ada — The Utopia Studio's DD analyst. Use when the user asks to 'run DD', 'review this startup', 'audit this repo', 'check this portco', mentions a technical due diligence report, asks 'is this technically sound?', or says 'run DD on [company]'. Ada is skeptical, evidence-driven, and never accepts founder claims at face value. She composes repo-scanner, security-auditor, devops-advisor, cost-optimizer, integration-linker, and technical-dd into a structured 5-phase audit and produces a branded TDD .docx report with P0-P3 risk severities. Distinct voice from generic Claude — leads with the verdict, quantifies risk, calls out unknowns explicitly.
-
the-utopia-studio Bundle Hallmark 2Anti-AI-slop design skill for greenfield pages, audits, redesigns, and design extraction from URLs or screenshots. Use when the user asks to build a new app or landing page, wants to redesign something, invokes Hallmark by name, or uses audit/redesign/study.
-
the-utopia-studio Skill Repo Scanner 2Scans a GitHub repository to understand its tech stack, hosting, monitoring, integrations, and current production readiness. Use when the user asks to "audit", "check", or "scan" their repo. Don't use for code review or bug detection.
-
the-utopia-studio Skill Security Auditor 2Audits repository security — hardcoded secrets, dependency vulnerabilities, environment variable management, and authentication patterns. Use when the user asks to "check security", "find secrets", "audit dependencies", or "secure my repo". Don't use for code review, deployment, or monitoring.
-
the-utopia-studio Skill Integration Linker 2Detects and connects development tools — Slack with GitHub, Linear with Git, error tracking with notifications. Provides step-by-step setup procedures for each integration. Use when the user asks to "connect tools", "link Slack", "set up notifications", "integrate Linear", or "connect my tools". Don't use for monitoring setup (use monitoring-setup), deployment (use deployment-engineer), or security (use security-auditor).
-
markus41 Skill Audit Trail 2Design audit log specifications for regulated business processes. Use when a workflow requires a defensible audit trail for FINRA examinations, state insurance audits, SOX controls testing, or internal compliance reviews.
-
markus41 Skill Workflow Audit 2Generate audit trail specifications for regulatory compliance in insurance and financial services. Use when designing audit logging for FINRA, state insurance department, SOX, or internal compliance requirements.
-
markus41 Skill Compliance Check 2Audit a workflow or business process against insurance, mortgage, or financial services regulatory requirements. Use when a client workflow needs regulatory sign-off or when validating that a proposed automation meets compliance requirements before build.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include porters-five-forces, web-pentest, mindforge-audit-uat. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.