Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
yeaight7 Skill Dependency Cleanup 2Use when package manifests carry unused or redundant third-party dependencies that slow builds, widen the security surface, or complicate updates.
-
yeaight7 Skill Secret Leak Preflight 2Use when about to commit, push, or publish -- staged changes touch config or environment files, generated artifacts (relay sessions, logs, build output) are being added, or the session handled credentials even indirectly.
-
compozy Bundle Eng Real Scenario QA 2Dogfoods Compozy through an autonomous startup scenario with live providers, cross-surface observation, and strict evidence audit. Use for release or complex-integration QA. Do not use for smoke, static, mock-only, or unit-test work.
-
compozy Bundle Eng Cleanup Failure Paths 2Partial-failure cleanup audit for Compozy Go functions. Use when a changed function acquires, registers, starts, claims, leases, or opens more than one fallible resource before returning. Do not use for pure transformations, read-only helpers, or test-only code.
-
compozy Bundle Cy Review Round 2Performs a comprehensive code review of a spec implementation and generates a review round directory with issue files compatible with cy-fix-reviews. Use when reviewing implemented spec tasks, creating a manual review round without an external provider, or performing a quality audit of code changes. Do not use for fetching reviews from external providers, fixing existing review issues, executing spec tasks, or editing source code.
-
desesbraker Bundle Solidity Security 2Master smart contract security best practices, vulnerability prevention, and secure Solidity development patterns.
2 -
desesbraker Bundle Wcag Audit Patterns 2Comprehensive guide to auditing web content against WCAG 2.2 guidelines with actionable remediation strategies.
2 -
desesbraker Bundle Anti Reversing Techniques 2AUTHORIZED USE ONLY: This skill contains dual-use security techniques. Before proceeding with any bypass or analysis: > 1.
2 -
desesbraker Bundle Protocol Reverse Engineering 2Comprehensive techniques for capturing, analyzing, and documenting network protocols for security research, interoperability, and debugging.
2 -
projectious-work Skill Code Review 2Structured code review with a checklist covering correctness, clarity, tests, security, performance, and style. Use when reviewing a PR, diff, or set of code changes before merging — including phrases like "review this", "check my changes", or "is this ready to merge".
0 -
projectious-work Skill Dockerfile Review 2Dockerfile best practices — layer optimization, caching, security, image size. Use when writing, reviewing, or optimizing Dockerfiles, investigating bloated images, or fixing cache-busting build orders.
0 -
projectious-work Bundle Secure Coding 2Secure coding practices grounded in the OWASP Top 10. Use when reviewing code for security issues, implementing input validation, hardening web applications, or adding defenses against injection, XSS, or CSRF.
0 -
projectious-work Skill Threat Modeling 2Threat modeling with STRIDE — data flow diagrams, trust boundaries, risk. Use when designing a new system, reviewing architecture for security, conducting a security review, or prioritizing security work by risk.
0 -
projectious-work Skill Dependency Audit 2Audit project dependencies for vulnerabilities and outdated packages. Use when checking the security posture of dependencies, planning updates, or running a pre-release dependency review.
0 -
projectious-work Bundle Binding Management 2Manage Binding entities — scoped, temporal, many-to-many relationships between any two primitives. Use when a relationship between two entities needs scope, time, or its own attributes — e.g. 'Alice is the tech lead for project X from Jan to June' or 'the security gate applies to the release process only on the main branch'.
0 -
projectious-work Skill Secret Management 2Handle secrets safely — env vars, .env files, vaults, rotation. Use when dealing with API keys, passwords, tokens, database credentials, or any other sensitive value the application needs at runtime.
0 -
projectious-work Skill Webhook Integration 2Webhook design and consumption — payload format, HMAC signatures, idempotency, retries, dead-letter queues, security. Use when implementing a webhook consumer, designing an event-notification system, adding signature verification, or debugging duplicate or failed webhook deliveries.
0 -
projectious-work Skill Dependency Management 2Cross-language dependency management — lockfiles, version pinning, automated updates, security, and licenses. Use when setting up or reviewing lockfile strategy, configuring automated dependency updates, auditing dependencies for security or license issues, handling monorepo dependencies, or deciding whether to vendor.
0 -
desesbraker Bundle Security Compliance Compliance Check 2You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards. Perform comprehensive compliance audits and provide implementation guidance for achieving and maintaining compliance.
2 -
desesbraker Bundle Security Scanning Security Dependencies 2You are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilities, assess risks, and provide automated remediation strategies.
2 -
yanacuti1121 Skill Merkle Tree Audit 2Merkle Tree Audit
2 -
desesbraker Skill File Uploads 2Careful about security and performance. Never trusts file extensions. Knows that large uploads need special handling. Prefers presigned URLs over server proxying.
2 -
arjumaan Skill Laravel Expert 2Senior Laravel Engineer role for production-grade, maintainable, and idiomatic Laravel solutions. Focuses on clean architecture, security, performance, and modern standards (Laravel 10/11+).
1 -
arjumaan Skill Laravel Security Audit 2Security auditor for Laravel applications. Analyzes code for vulnerabilities, misconfigurations, and insecure practices using OWASP standards and Laravel security best practices.
1 -
arjumaan Bundle Openclaw Github Repo Commander 27-stage super workflow for GitHub repo audit, cleanup, PR review, and competitor analysis
1 -
yanacuti1121 Skill Dompurify Xss Prevention 2Dompurify Xss Prevention
2 -
manastalukdar Skill Dependency Audit 2Comprehensive dependency security and license audit
-
manastalukdar Skill Security Headers 2Web security headers validation and configuration generation
-
peterbamuhigire Bundle IOS Development 2Use when building or reviewing native iOS applications with Swift, SwiftUI, structured concurrency, security, tests, and performance gates; use focused iOS skills for persistence, release, or monetisation.
-
peterbamuhigire Skill AI Slop Audit 2Use when auditing or scoring an artefact for AI slop after a major iteration or before release. Produces evidence-backed findings, severity, fixes, genericness score, and an A/B/C/F verdict.
-
peterbamuhigire Skill Dpia Generator 2Use when producing or reviewing a Data Protection Impact Assessment (DPIA) for a new feature or for Uganda DPPA-regulated, large-scale, sensitive, monitored, or high-risk personal-data processing.
-
peterbamuhigire Bundle Gis Enterprise Domain 2Use when administering ArcGIS Enterprise or building real-estate-specific GIS features — ArcGIS components, publishing services, security/roles, backup/DR, plus property search, neighbourhood analysis, catchment/isochrones, market heatmaps, and real-estate-SaaS integration.
-
peterbamuhigire Bundle IOS Security And Rbac 2Use when designing or reviewing iOS authentication, Keychain, App Attest, privacy manifests, permissions, RBAC, tenant isolation, or AI security; use ios-development for general implementation.
-
peterbamuhigire Bundle Network Security 2Use when designing, hardening, or auditing network security for self-managed SaaS infrastructure, including firewalls, WAF, VPN, TLS/PKI, IDS/IPS, SSH, segmentation, DDoS, and DNS controls.
-
peterbamuhigire Bundle Skill Engine Audit 2Use when auditing, grading, benchmarking, or conforming an entire skills engine. Measures taxonomy, doctrine, contracts, depth, routing, safety, references, output readiness, and normalisation priorities.
-
peterbamuhigire Bundle Code Safety Scanner 2Use when scanning a codebase before deployment for critical vulnerabilities, server-error risks, unsafe AI-generated code, dependency problems, or payment misconfiguration.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include dependency-cleanup, secret-leak-preflight, eng-real-scenario-qa. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.