Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
sd0xdev Skill Codex Security 2OWASP Top 10 security review using Codex exec. Supports review loop with context preservation.
-
sd0xdev Bundle Necessity Audit 2Necessity audit for over-designed spec elements. Use when: auditing lifecycle spec (1-requirements / 2-tech-spec / 3-architecture) for YAGNI/KISS violations, challenging necessity of FRs/NFRs/abstractions/configs via Codex adversarial debate. Not for: FP reasoning validity (use /codex-review-spec), completeness check (use /feature-completeness), detail review (use /codex-review-doc), or code-level simplification (use /simplify).
-
sd0xdev Bundle Security Review 2Security review via Codex exec. Use when: OWASP Top 10:2025 audit, dependency vulnerability check, security-sensitive changes. Not for: code review (use codex-code-review), test review (use test-review). Output: security findings + audit report.
-
sd0xdev Bundle Codex Code Review 2Code review using Codex exec. Use when: PR review, code audit, second opinion on changes. Not for: doc review (use doc-review), security audit (use security-review). Output: severity-grouped findings + merge gate.
-
sd0xdev Bundle Dev Security Audit 2Comprehensive developer workstation security audit — scans for exposed credentials, compromised application data, persistence mechanisms, and supply chain attack indicators. Use this skill whenever the user suspects their machine may be compromised, wants to check for exposed secrets, asks about supply chain attacks, or wants a full security audit of their development environment. Also triggers on: 'am I compromised', 'check my security', 'scan for leaked keys', 'credential audit', 'supply chain attack', 'supply chain check', 'check if I was hacked'.
-
bankrbot Bundle Base Node 2Run a production Base node with Reth client — hardware sizing, port configuration, snapshot bootstrapping, security hardening, and sync monitoring.
1.2k -
shengdabai Bundle Afa Dashboard 2DTC 数据仪表盘与体检引擎——全链路数据分析、KPI 追踪、行业基准对标、数据健康度评估、市场趋势监控。Use when user mentions: 数据体检, data audit, KPI, 仪表盘, dashboard, 指标追踪, metrics, 基准线, benchmark, 数据分析, data analysis, 营收报表, revenue report, 渠道数据, 广告数据, ROAS跟踪.
-
shengdabai Bundle Opc Resource Audit 2Inventory all founder resources across 8 categories for a one-person company. Use when Codex needs to systematically confirm what resources the founder has — experience, network, skills, relationships, channels, assets, time/money constraints, hard limits — by first doing a broad scan of each category, then drilling into specifics (distribution, usable portions, how to use, cost of use), and producing a confirmed detailed resource inventory written to `opc-doc/`. Does NOT analyze directions, preferences, suitability, or risk tolerance — those belong to downstream skills.
-
shengdabai Bundle Chezmoi Dotfiles 2Secure dotfiles management with chezmoi. Use when helping users initialize chezmoi repositories, add/manage dotfiles, handle secrets with age encryption, create templates for multi-machine configs, troubleshoot chezmoi issues, or review dotfiles for security. Always checks for security implications before adding files.
-
gktuoktay Bundle Testing JWT Token Security 2JSON Web Token (JWT) uygulamalarını kriptografik zayıflıklar, algoritma karmaşası ve yetkilendirme atlama zafiyetlerine karşı güvenlik testleri sırasında analiz eder.
-
gktuoktay Bundle Testing For Xss Vulnerabilities 2Web uygulamalarında Reflected, Stored ve DOM tabanlı XSS (Cross-Site Scripting) zafiyetlerini test eder. Burp Suite ve tarayıcı araçlarıyla JavaScript payload'ları enjekte ederek filtreleme (sanitization) ve CSP atlatma yöntemlerini uygular.
-
gktuoktay Bundle Testing For Broken Access Control 2Web uygulamaları ve API'leri Kırık Erişim Kontrolü (OWASP A01:2021) açısından test eder. Yetki yükseltme, eksik fonksiyon seviyesi kontrolleri, IDOR ve çoklu kiracı (multi-tenant) veri sızıntılarını tespit etmek için Burp Suite kullanır.
-
gktuoktay Bundle Performing GRAPHQL Security Assessment 2GraphQL API uç noktalarını introspection (içe bakış) sızıntıları, enjeksiyon saldırıları, yetkilendirme hataları ve servis dışı bırakma (DoS) zafiyetleri açısından değerlendirir.
-
gktuoktay Bundle Testing API Security With Owasp Top 10 2REST, GraphQL ve gRPC API uç noktalarını OWASP API Security Top 10 (2023) standartlarına göre sistemli olarak değerlendirir. Burp Suite ve Postman kullanarak otomatik ve manuel testler gerçekleştirir. Yetkili sızma testleri veya API gateway denetimleri öncesinde kullanılır.
-
gktuoktay Bundle Testing For JSON Web Token Vulnerabilities 2JWT uygulamalarında algoritma karmaşası, 'none' algoritması atlatması, kid/jku parametre enjeksiyonu ve zayıf gizli anahtar (secret) zafiyetlerini test eder. jwt_tool ve Burp Suite kullanarak kimlik doğrulama atlatma ve yetki yükseltmeyi hedefler.
-
gktuoktay Bundle Testing API For Mass Assignment Vulnerability 2API'lerde toplu atama (mass assignment) zafiyetlerini test eder. (OWASP API3:2023). Kayıt, profil veya nesne oluşturma uç noktalarında belgelenmemiş alanlar (role, isAdmin vb.) göndererek sunucunun bu verileri kabul edip etmediğini kontrol eder.
-
gktuoktay Bundle Testing API For Broken Object Level Authorization 2REST ve GraphQL API'lerde Kırık Nesne Seviyesi Yetkilendirme (BOLA/IDOR, OWASP API1:2023) zafiyetlerini test eder. Nesne kimliklerini (ID'ler) analiz edip değiştirerek, sunucunun doğru yetkilendirme yapıp yapmadığını kontrol eder. BOLA veya erişim denetimi testlerinde kullanılır.
-
aaronjmars Skill Send Email 2Compose and send a one-off email to a named recipient via Resend - written in the operator's voice, then sent in-run through the shared send caps with an operator audit copy
-
aaronjmars Skill Inbox Triage 2Daily GitHub notification inbox triage - surfaces aging vuln PR replies, security advisories, review requests, and mentions that need action
-
aaronjmars Bundle Vuln Scanner 2Audit trending repos for real security vulnerabilities and disclose responsibly - scan and route findings (PVR / dependency PR), re-submit queued advisories, and send armed email disclosures
-
aaronjmars Skill Investigation Report 2One-shot Base-token investigation - runs any subset of six onchain-security checks (rug-scan, contract-audit, deployer-trace, holder-concentration, honeypot, lp-lock) into one verdict. Keyless core.
-
bankrbot Bundle QA Checklist 2Pre-ship audit checklist for Ethereum dApps. Ship-blocking checks and should-fix checks covering wallet connection, button flows, contract verification, branding, RPC config, and mobile deep linking.
1.2k -
bankrbot Bundle Uniswap Hooks 2Security-first assistance for building Uniswap v4 hooks — threat modeling, permission flags analysis, NoOp attack prevention, delta accounting, and pre-deployment audit checklists.
1.2k -
bankrbot Bundle Smart Contract Audit 2500+ item EVM smart contract audit system across 19 domains. Runs parallel specialist agents, synthesizes findings, and files GitHub issues. Separate from the security skill — this is for auditing contracts you did not write.
1.2k -
bankrbot Bundle Aeon Vuln Scanner 2Audit trending repos for real exploitable vulnerabilities and disclose responsibly — Private Vulnerability Reporting for code flaws and verified secrets, public PRs only for already-disclosed dependency CVEs. Semgrep + TruffleHog + osv-scanner + Slither with reachability triage. Skips targets that have no safe disclosure channel. Triggers: "vuln scan owner/repo", "audit this repo", "responsible-disclosure scan", "check for secret leaks", "scan dependencies for CVEs".
1.2k -
bankrbot Bundle Security 2Solidity vulnerabilities, defensive code patterns, and a pre-deployment audit checklist. Covers reentrancy, oracle manipulation, token decimals, SafeERC20, ERC-4626 inflation, infinite approvals, and MEV.
1.2k -
asymmetric-al Bundle Payload 2Use when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API). Use when debugging validation errors, security issues, relationship queries, transactions, or hook behavior.
-
asymmetric-al Skill Repo Entry 3Audit or update Core's repository instruction system and skill mirrors. Use for AGENTS.md architecture, canonical skill ownership, skills:sync, or skills:verify; do not invoke for ordinary application work.
-
asymmetric-al Bundle NPM Deps Cleanup 2Audit and reduce JavaScript package dependency footprint across npm, pnpm, Yarn, and Bun projects. Use when asked to remove unused dependencies, deduplicate workspace dependency versions, lockfiles or node_modules, analyze direct dependencies' transitive lockfile closure, find low-risk upgrades that reduce dependency trees, inline trivial dependencies, or apply e18e dependency replacement recommendations.
-
asymmetric-al Bundle Payloadcms Payload 2Payload CMS application development (collections, fields, hooks, access control, Local/REST/GraphQL queries, adapters, plugins). Vendored from payloadcms/skills. Use when editing payload.config.ts, Payload collections, admin, or debugging validation, security, relationships, transactions, or hooks in this repo.
-
asymmetric-al Bundle Stripe Best Practices 2Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial accounts, integration surfaces (Checkout, Payment Element), migrating from deprecated Stripe APIs, and security best practices (API key management, restricted keys, webhooks, OAuth). Use when building, modifying, or reviewing any Stripe integration — including accepting payments, building marketplaces, integrating Stripe, processing payments, setting up subscriptions, creating connected accounts, or implementing secure key handling.
-
howard-lynn-ye Bundle Section 1256 And Derivatives Tax 2Futures and broad-based index options are marked to market on the last business day of the year and split 60/40 long/short regardless of holding period, so two options with the same payoff can have different after-tax P&L. TRIGGER - section 1256, 1256 contract, 60/40, sixty forty, mark to market at year end, marked to market December 31, regulated futures contract, nonequity option, broad-based index option, narrow-based security index, SPX vs SPY tax, XSP, VIX options, futures tax treatment, Form 6781, blended rate on futures, "do I owe tax on an open position", net section 1256 loss carryback, qualified board or exchange. Modelling assumptions for backtests, not tax advice. SKIP for stock lots and cost basis (tax-lot-matching-and-cost-basis), for the wash-sale rule that does not reach these contracts (wash-sale-rules), for reporting an after-tax Sharpe (after-tax-backtesting), and for option pricing and lifecycle mechanics (options-backtesting).
-
plurigrid Bundle Norvidize 2Extract and audit claims for norvid tracking system
-
plurigrid Bundle Security Review 2Scan code changes for security vulnerabilities using STRIDE threat modeling, validate findings for exploitability, and output structured results for downstream patch generation. Supports PR review, scheduled scans, and full repository audits.
-
plurigrid Skill Pentest Exploit Validation 2Proof-driven exploitation with 4-level evidence system, bypass exhaustion protocol, mandatory evidence checklists, and strict EXPLOITED/POTENTIAL/FALSE_POSITIVE classification.
-
yeaight7 Skill Bigquery Cost Audit 2Use when reviewing BigQuery spend, query failure patterns, or scan inefficiencies -- identifying which jobs, users, or projects drive cost, or preparing optimization recommendations for a cost review.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include codex-security, necessity-audit, security-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.