Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
agentik-os Skill Design Debt Audit 2Identify, categorize, and prioritize accumulated design inconsistencies and structural problems across a product.
-
agentik-os Skill Design Token Audit 2Audit design token usage across a product for consistency and coverage.
-
griddynamics Bundle Security Flow 3Workflow for authorized, evidence-preserving security review and remediation-task preparation.
-
griddynamics Bundle Security Flow 4Workflow for authorized, evidence-preserving security review and remediation-task preparation.
-
gaelic-ghost Bundle Mailkit Workflow 2Design macOS MailKit extensions for content blocking, message actions, compose sessions, and message security with explicit privacy, capability, target, and validation boundaries. Use when a macOS app needs to extend Apple Mail.
-
gaelic-ghost Bundle Harden Macos 2Review and improve macOS defensive posture. Use for updates, XProtect and Gatekeeper, FileVault, firewall, remote access, accounts, background items, privacy, backups, credentials, and monitoring after a security assessment or incident.
-
gaelic-ghost Skill Build Falco Web App 2Build or modify a Falco web application in idiomatic F#, using functional routing, request and response helpers, explicit ASP.NET Core integration, security boundaries, and focused tests.
-
gaelic-ghost Bundle Assess Macos Threat 2Assess a suspected macOS threat using exact host and artifact evidence. Use for suspicious apps, processes, downloads, profiles, extensions, alerts, persistence, privacy, or network activity while keeping protections distinct.
-
gaelic-ghost Bundle Route Security Work 2Route an ambiguous cybersecurity request before tools run. Use for suspicious files, links, messages, host behavior, malware, vulnerability reports, authorized pentests, incidents, threat hunting, detection work, or security advice.
-
gaelic-ghost Bundle Use Objective See Tools 2Use installed Objective-See macOS security tools as evidence adapters. Use for KnockKnock, BlockBlock, LuLu, ProcessMonitor, FileMonitor, WhatsYourSign, TaskExplorer, or related tools with explicit permissions, limits, and ownership.
-
gaelic-ghost Bundle Maintain Github Repository 2Audit or align a GitHub repository's server-side settings, rulesets, security automation, Dependabot, and sign-off policy. Use for server-side GitHub policy work, not ordinary local Git commits, PR collaboration, or releases.
-
gaelic-ghost Bundle Assess And Explain Threat 2Assess whether suspicious evidence indicates a real threat and explain it plainly. Use for confidence, protective actions, uncertainty, impact, and advice after artifact, endpoint, identity, or incident evidence.
-
gaelic-ghost Bundle Check Artifact Reputation 2Check reputation for a suspicious artifact, signer, hash, URL, domain, certificate, package, or vendor. Use when threat intelligence informs triage while privacy, stale data, false positives, and behavior limits stay explicit.
-
gaelic-ghost Bundle Contain And Recover Macos 2Contain a macOS threat and verify recovery. Use for isolation, process or service containment, credential response, persistence removal, quarantine, restore, erase/reinstall, monitoring, and return-to-service decisions.
-
gaelic-ghost Bundle Test Web And API Security 2Test an authorized web application or API using OWASP guidance. Use for authentication, authorization, sessions, input, schemas, business logic, file handling, server-side requests, configuration, transport, errors, and data exposure.
-
gaelic-ghost Bundle Assess Exposure And Impact 2Prioritize a vulnerability using actual asset exposure and impact. Use when versions, reachability, prerequisites, privileges, data, exploit maturity, mitigations, detection, business criticality, and urgency matter beyond CVSS.
-
gaelic-ghost Bundle Preserve Security Evidence 2Preserve security evidence before analysis, containment, or remediation changes it. Use for artifacts, volatile host state, vulnerability validation, records, logs, screenshots, commands, hashes, timelines, and reproducible handoffs.
-
gaelic-ghost Bundle Report Security Assessment 2Write a security assessment or penetration-test report from evidence. Use when findings, scope, methodology, limitations, impact, remediation, retest criteria, and an executive explanation need calibrated reporting.
-
legioncodeinc Bundle Runbook Writing Stinger 2Operational runbook authorship specialist covering canonical templates (break-fix, scheduled operation, diagnostic), the no-implied-context audit protocol, exact-command discipline, escalation path architecture, rollback procedure standards, runbook-as-test (game day) methodology, and postmortem-to-runbook linkage. Activate when the user says \\\"write a runbook\\\", \\\"audit this runbook\\\", \\\"our runbooks are out of date\\\", \\\"we need a runbook for this alert\\\", \\\"turn this postmortem into a runbook\\\", \\\"schedule a game day\\\", \\\"our on-call docs are weak\\\", or when `runbook-writing-worker-bee` is invoked. Do NOT activate for incident management tooling setup (PagerDuty/OpsGenie, route to ci-release-worker-bee), infrastructure provisioning decisions (route to ci-release-worker-bee), or documentation culture/process design beyond the runbook format (route to library-worker-bee).
-
legioncodeinc Bundle Dependency Audit Stinger 2npm supply-chain hygiene specialist: dependency updates, lockfile discipline, audit triage, SBOM, and provenance. Use when auditing dependencies, fixing lockfile noise, or checking publish safety.
-
legioncodeinc Bundle Live Chat Support Stinger 2Customer support surface specialist — Intercom, Crisp, Plain, Pylon, Help Scout — widget integration, HMAC/JWT identity verification, conversation routing, AI deflection (Fin 2.0, Ari, Crisp Bot), and the data-export discipline. Use when the user says "integrate live chat", "set up Intercom", "add a support widget", "wire HMAC identity verification", "configure AI deflection", "design conversation routing", or "set up customer support for our SaaS". DO NOT use for managing deployments (devops-worker-bee), application authentication (auth-worker-bee), or security audits of the resulting integration (security-worker-bee).
-
legioncodeinc Bundle Technical Writing Craft Stinger 2Writing docs well -- the Diataxis framework (tutorial / how-to / reference / explanation), inverted-pyramid prose structure, scannable headings, code-example discipline, the \\\"what does the reader already know?\\\" reader-lens, ghostwriting vs voice consistency, and the docs-as-code review workflow. Distinct from library-worker-bee (which owns docs-site architecture and where a doc lives); this stinger owns the craft of writing. Use when the user says \\\"review this document\\\", \\\"is this doc well-written\\\", \\\"audit this page\\\", \\\"write a tutorial for X\\\", \\\"apply Diataxis\\\", \\\"ghostwrite this guide\\\", \\\"my docs PR needs a writing review\\\", or any request about documentation quality rather than documentation tooling.
-
legioncodeinc Bundle Customer Support Tooling Stinger 2Support stack specialist for SaaS products — selects the right tool from Plain, Pylon, Front, Help Scout, and Intercom; configures shared inboxes; designs AI-deflection flows (Fin 2.0, Ari, Crisp Bot); sets SLA tiers; wires integrations to Slack, Linear, and Notion; and provides a founder-as-support playbook for teams of 1-3. Invoke when choosing a support tool, auditing an existing stack, configuring AI deflection, designing SLA policy, or setting up escalation to Linear. Do NOT invoke for chat widget installation code (live-chat-support-worker-bee), auth SSO (auth-worker-bee), or GDPR/retention audits (security-worker-bee).
-
legioncodeinc Bundle Affiliate Referral Program Stinger 2Affiliate and referral program specialist for SaaS products -- platform selection (Rewardful, FirstPromoter, Tolt, PartnerStack, Impact, Refersion), the affiliate-vs-referral distinction, cookie-based and server-side attribution (post-ITP, post-3PC era), payout automation, fraud detection (self-referral, cookie stuffing, velocity fraud), and EPC/LTV program economics. Invoke when the user says "set up an affiliate program", "which affiliate platform should I use", "Rewardful vs FirstPromoter", "my attribution is broken in Safari", "referral program fraud", "EPC or LTV for our program", "20% recurring commission", "postback tracking setup", or "PartnerStack vs FirstPromoter". Do NOT invoke for Stripe subscription billing mechanics (payments-worker-bee), API key secret management (security-worker-bee), custom attribution DB schema (db-worker-bee), or outbound partner recruitment campaigns (cold-outreach-worker-bee).
-
legioncodeinc Bundle Electron Dissection Stinger 2Dissect and reverse engineer Electron desktop apps: locate resources/app.asar, read archive metadata, unpack with @electron/asar, decode bundled/minified JavaScript with webcrack, and attach live inspectors over the Chrome DevTools Protocol. Use when asked to unpack app.asar, reverse engineer / dissect / audit an Electron app, find what code a desktop app runs, recover app logic from a bundle, attach devtools via remote debugging, or harden your own Electron app against exactly this.
-
naveedharri Skill Ads Creative 2Cross-platform creative quality audit covering ad copy, video, image, and format diversity across all platforms. Detects creative fatigue, evaluates platform-native compliance, and provides production priorities. Collects brand context and creates branding.md if missing. Uses infographic-v2 for generating ad creatives. Use when user says "creative audit", "ad creative", "creative fatigue", "ad copy", "ad design", or "creative review".
-
naveedharri Bundle Benai Skill Creator Skill 2Turn a task you just finished into a small, reliable, single-purpose skill by reverse-engineering the process from the conversation you already had. Also improves or audits an existing skill. Use this AFTER you have done a piece of knowledge work in a chat (research, a draft, an analysis, a prep doc) and want to lock the process in as a skill. Triggers include "build a skill from this", "turn this into a skill", "make a skill out of what we just did", "skill-ify this", "build a skill", "improve this skill", "audit my skill", "why does my skill suck", "make my skill smaller", or when the user finishes a repeatable task and wants to reuse it. Built for knowledge workers, not just engineers. For skills you have NOT done yet (only an idea), hand off to process-interviewer instead.
-
spike-faye-lei Skill Overleaf Sync 2Two-way sync between a local paper directory and an Overleaf project, so ARIS audit/edit workflows stay on the local copy while collaborators edit in the Overleaf web UI. Use when user says "同步 overleaf", "overleaf sync", "推送到 overleaf", "connect overleaf", "Overleaf 桥接", "pull overleaf", "push overleaf", or wants to bridge their ARIS paper directory with an Overleaf project.
-
is-bo Skill Forge API 4Audit API contracts, boundary validation, authorization, consistency, pagination, errors, and idempotency.
-
is-bo Skill Forge Docs 4Verify that user, contributor, architecture, operations, security, and release documentation is accurate and executable.
-
is-bo Skill Forge Cache 4First decide whether caching is justified, then audit keys, invalidation, consistency, privacy, and failure behavior.
-
is-bo Skill Forge Offline 4Audit local persistence, queued actions, synchronization, conflicts, revocation, privacy, and recovery under intermittent connectivity.
-
is-bo Skill Forge Discover 4Build an evidence-backed application profile and architecture map before any specialized audit begins.
-
is-bo Skill Forge Payments 4Audit money movement, pricing, entitlements, provider events, reconciliation, idempotency, and sensitive data boundaries.
-
is-bo Skill Forge Security 4Perform a threat-informed audit of trust boundaries, injection, secrets, browser controls, dependencies, and abuse cases.
-
is-bo Skill Forge Reliability 4Audit timeouts, retries, overload, dependencies, degradation, consistency, and operational objectives.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include design-debt-audit, design-token-audit, security-flow. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.