Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
is-bo Skill Forge Integrations 4Audit outbound and inbound integrations for authentication, validation, failure isolation, drift, and replay safety.
-
is-bo Skill Forge Supply Chain 4Inspect dependencies, build integrity, provenance, releases, licenses, actions, and secret exposure across the delivery chain.
-
is-bo Skill Forge Infrastructure 4Audit infrastructure as code, network and identity boundaries, encryption, state, drift, and least privilege.
-
is-bo Skill Forge API 5Audit API contracts, boundary validation, authorization, consistency, pagination, errors, and idempotency.
-
is-bo Skill Forge Docs 5Verify that user, contributor, architecture, operations, security, and release documentation is accurate and executable.
-
is-bo Skill Forge Cache 5First decide whether caching is justified, then audit keys, invalidation, consistency, privacy, and failure behavior.
-
is-bo Skill Forge Offline 5Audit local persistence, queued actions, synchronization, conflicts, revocation, privacy, and recovery under intermittent connectivity.
-
is-bo Skill Forge Discover 5Build an evidence-backed application profile and architecture map before any specialized audit begins.
-
is-bo Skill Forge Payments 5Audit money movement, pricing, entitlements, provider events, reconciliation, idempotency, and sensitive data boundaries.
-
is-bo Skill Forge Security 5Perform a threat-informed audit of trust boundaries, injection, secrets, browser controls, dependencies, and abuse cases.
-
is-bo Skill Forge Reliability 5Audit timeouts, retries, overload, dependencies, degradation, consistency, and operational objectives.
-
is-bo Skill Forge Integrations 5Audit outbound and inbound integrations for authentication, validation, failure isolation, drift, and replay safety.
-
is-bo Skill Forge Supply Chain 5Inspect dependencies, build integrity, provenance, releases, licenses, actions, and secret exposure across the delivery chain.
-
is-bo Skill Forge Infrastructure 5Audit infrastructure as code, network and identity boundaries, encryption, state, drift, and least privilege.
-
golemcloud Skill Golem Add Secret Rust 2Adding secrets to Rust Golem agents. Use when the user needs to store sensitive configuration such as API keys, passwords, or tokens that should not be checked into source control.
-
spike-faye-lei Bundle Antivibe 2Code learning and audit framework. Analyze any codebase — new, legacy, or AI-generated — and produce educational explanations or architectural audits. Use when the user wants to understand WHAT and WHY behind any code, not just accept it.
-
zaxbysauce Bundle Commit Pr 6Apply when committing, pushing, opening or updating a PR, writing a pull request, creating release notes, or closing out remote CI. Enforces the opencode-swarm invariant audit, release-note fragment workflow, full validation suite, issue comment requirement, and post-PR lifecycle rules.
-
zaxbysauce Skill Commit Pr 8Apply when committing, pushing, opening or updating a pull request, or closing out CI. A portable, project-agnostic commit and PR workflow: verify before you push, write conventional commits and a clear PR body, and never commit generated or secret files.
-
zaxbysauce Bundle Research First 3Codex adapter for research-before-planning work. Use when a task depends on current external facts, unfamiliar libraries, APIs, standards, security advisories, release notes, product behavior, or repo behavior that must be verified before planning or implementation.
-
zaxbysauce Skill Tech Debt CI Review 4Deep technical debt and CI stability audit for identifying test theater, missing or mis-scoped tests, actual and potential test failures, flaky-test risk, dependency/toolchain brittleness, and structural debt that prevents PRs from going green safely.
-
golemcloud Skill Golem Add HTTP Auth Moonbit 2Enabling authentication on HTTP endpoints in MoonBit Golem agents. Use when the user asks to add auth, security, or access control to HTTP endpoints.
-
gktuoktay Skill Software Composition And Dependency Auditing 3Proje bağımlılıklarındaki (npm, pip vb.) CVE zafiyetlerinin taranması, supply chain güvenliği ve versiyon güncellemeleri.
-
gktuoktay Skill Master Orchestrator 2Tüm alt orkestratörleri (Code, Design, Security, Test, Git, Docs) ve eleştirel denetim kapılarını tek noktadan yöneten ana sistem mimarı.
-
gktuoktay Skill Security Orchestrator 2Siber güvenlik, sızma testleri, API güvenliği ve kod zafiyet taramalarını yöneten ana orkestratör.
-
gktuoktay Skill Structured Logging Audit Gate 2Sistemde optimum maliyetli yapısal loglama, asenkron exception takibi ve temiz denetim izi (Audit Trail) kurallarını zorunlu tutan kapı.
-
gktuoktay Skill DB Architect Security 3Veritabanı mimarisi, güvenlik standartları, ORM yapılandırmaları ve veritabanı tasarımı için yetenek.
-
gktuoktay Skill Secret Scanning And Management 2Kod tabanında unutulmuş API key, şifre, sertifika gibi hassas verilerin taranması ve .env yönetimi.
-
plurigrid Skill Implementing Privileged Session Monitoring 2Implements privileged session monitoring and recording using Privileged Access Management (PAM) solutions, focusing on CyberArk Privileged Session Manager (PSM) and open-source alternatives. Covers session recording configuration, keystroke logging, real-time monitoring, risk-based session analysis, and compliance audit trail generation. Activates for requests involving privileged session recording, PAM session monitoring, CyberArk PSM configuration, administrator activity monitoring, or compliance session auditing.
-
sd0xdev Skill Dep Audit 2Audit dependency security risks
-
sd0xdev Bundle Doc Review 2Document review via Codex exec. Use when: reviewing .md docs, tech spec audit, document quality check. Not for: code review (use codex-code-review), test review (use test-review). Output: 5-dimension rating table + gate.
-
sd0xdev Bundle Risk Assess 2Uncommitted code risk assessment with breaking change detection, blast radius analysis, and scope metrics. Use when: evaluating PR risk, pre-commit risk check, large refactoring review. Not for: security vulnerabilities (use /codex-security), code correctness (use /codex-review-fast). Output: 3-dimension weighted score + risk level + gate.
-
sd0xdev Bundle Test Health 2Holistic test coverage measurement. Use when: assessing test health, measuring coverage trends, quantitative + qualitative test audit. Not for: running tests (use verify), reviewing test sufficiency only (use codex-test-review), generating tests (use codex-test-gen). Output: multi-dimensional dashboard with coverage metrics + test inventory + trend.
-
sd0xdev Bundle Test Review 2Test coverage review via Codex exec. Use when: reviewing test sufficiency, identifying coverage gaps, test quality audit. Not for: generating tests (use codex-test-gen), code review (use codex-code-review). Output: coverage analysis + gap report.
-
sd0xdev Bundle Seek Verdict 2Independent second-opinion verification for any finding. Use when: Claude or user wants independent Codex verification of a review finding — dismiss (false positive check), confirm (does this issue exist?), or clarify (what's the impact?). Triggers: dismiss verification, seek verdict, verify dismiss, false positive check, second opinion, confirm finding, clarify impact. Not for: general code review (use codex-code-review), architecture debates (use codex-brainstorm). Output: [DISMISS_VERDICT] or [SEEK_VERDICT] audit trail with verdict, confidence, and evidence refs.
-
sd0xdev Bundle Deep Research 2Universal multi-source research orchestration. Use for any research/investigate/analyze request needing synthesis across web, codebase, and community evidence — especially broad, mixed, or ambiguous intent. Triggers on: 'research this', 'deep research', 'investigate', 'analyze from multiple angles', 'comprehensive analysis', 'explore this topic', 'study', 'survey the landscape', 'look into', 'understand deeply', '了解', '調查', '分析', '研究'. When intent is clearly single-dimension (code-only tracing, checklist-style compliance audit, or bounded option-ranking), dispatcher may prefer a narrower skill. Otherwise route here. Supports low/medium/high budget tiers.
-
sd0xdev Bundle Project Audit 2Project health audit with deterministic scoring. Use when: evaluating project quality, onboarding to new codebase, periodic health checks. Not for: runtime performance analysis, security-specific audits (use /codex-security). Output: 5-dimension score + actionable findings.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include forge-integrations, forge-supply-chain, forge-infrastructure. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.