Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
peterbamuhigire Bundle Vibe Security Skill 2Use when designing or reviewing application, API, or multi-tenant SaaS security. Produces threat models, abuse cases, authorisation matrices, secret plans, and OWASP-aligned evidence.
-
manastalukdar Skill Owasp Check 2OWASP Top 10 vulnerability scanning and remediation
-
manastalukdar Skill Devex Review 2Audit the developer experience of your project — setup friction, onboarding clarity, local dev loop speed, tooling consistency, and documentation gaps. Produces a DX scorecard and prioritized improvement list. Inspired by gstack's devex-review skill.
-
manastalukdar Skill Legacy Audit 2Map modernization opportunities in a legacy codebase — identify unsupported dependencies, architecture seams, and migration paths using strangler fig, adapter, and parallel-run patterns
-
manastalukdar Skill Security Scan 2Comprehensive security analysis with vulnerability detection and remediation tracking
-
crestapps Bundle Orchardcore Permission Providers 2Skill for implementing Orchard Core permission providers. Covers the PermissionProvider pattern, default stereotypes, OrchardCoreConstants role names, and where to place reusable static permission instances and reusable content-part models. Use this skill when requests mention Orchard Core Permission Providers, Create a Permission Provider, Recommended Project Placement, Static Permission Definitions in a Core Project, PermissionProvider Class, Registering the Provider, or closely related Orchard Core implementation, setup, extension, or troubleshooting work. Strong matches include work with CrestApps.Sports.Teams.Core, OrchardCore.Security.Permissions, CrestApps.Sports.Teams.Core.Permissions, CrestApps.Sports.Teams, OrchardCore.Modules. It also helps with permission provider examples, PermissionProvider Class, Registering the Provider, Content Part Placement Guidance, plus the code patterns, admin flows, recipe steps, and referenced examples captured in this skill.
-
crestapps Bundle Orchardcore Users Admin List Filters 2Skill for adding custom filters to the Orchard Core users admin list (Security → Users). Covers implementing IUsersAdminListFilterProvider to add searchable terms to the users admin search box, wiring named and default terms with OneCondition/ManyCondition against YesSql indexes over User, registering the provider in Startup, and documenting the new filter in the Available Filters dialog with a DisplayDriver<UserIndexOptions> Thumbnail card. Use this skill when requests mention custom users admin list filters, IUsersAdminListFilterProvider, QueryEngineBuilder<User>, WithNamedTerm, the users Filters dropdown or Filter syntax dialog, UserIndexOptions filter cards, UsersAdminFilters Thumbnail views, or closely related Orchard Core users admin list search work. Strong matches include OrchardCore.Users, IUsersAdminListFilterProvider, UserIndexOptions, and UsersAdminFilters-*.Thumbnail.cshtml.
-
peterbamuhigire Bundle Saas Managed Visual Assets 2Use when implementing or reviewing Super Admin or tenant-scoped managed visual assets—background image pools, light/dark logos, or favicons—with secure upload, preview, ordering, activation, replacement, quotas, and audit evidence.
-
peterbamuhigire Bundle Linux Security Hardening 2Use when hardening or auditing Debian and Ubuntu hosts for identity, sudo, PAM, MFA, permissions, AppArmor, auditd, kernel, patching, integrity, boot, encryption, and CIS controls.
-
peterbamuhigire Bundle Saas Admin Backoffice Tooling 2Use when designing audited SaaS back-office impersonation, tenant lifecycle, billing overrides, bulk actions, or audit controls.
-
peterbamuhigire Bundle Multi Tenant Saas Architecture 2Use when designing tenant isolation, panel boundaries, zero-trust authorization, audit trails, or tenant permission overrides.
-
peterbamuhigire Bundle Accounting Engine 2Use when designing, implementing, or reviewing an embedded accounting engine with append-only ledgers, mapped postings, idempotency, reversals, period locks, audit trails, and integrity tests.
-
peterbamuhigire Bundle Electronic Fiscal Taxing 2Use when implementing or reviewing electronic fiscal taxation integrations in web, ERP, POS, or mobile-backed systems; covers jurisdiction adapters, tenant-scoped tax identities, API security, queues, offline operation, fiscal evidence, and Uganda EFRIS as the detailed reference.
-
peterbamuhigire Bundle Saas Tenant Data Portability And Erasure 2Use when designing verified tenant data export, retention, erasure, backup handling, audit evidence, or privacy-law portability workflows.
-
peterbamuhigire Bundle Ecommerce Platform Audit Requirements 2Use when scoping or specifying an e-commerce platform, payment, API, security, AI, data protection, integration, and remediation audit for SMEs or cross-border digital trade programmes.
-
peterbamuhigire Bundle Game Security Anti Cheat And Abuse 2Use when threat-modelling a game client/server, validating actions, protecting game economy and accounts, detecting tampering or cheats, limiting bots and abuse, investigating incidents, or designing proportionate enforcement and appeals.
-
peterbamuhigire Bundle Bds Intake And Monitoring System Spec 2Use when specifying application intake, eligibility screening, selection scoring, beneficiary registers, diagnostics tracking, expert deployment, monitoring dashboards, RBAC, audit trails, and donor reporting for BDS programmes.
-
crestapps Skill Orchardcore Cors 2Skill for administering tenant-specific cross-origin resource sharing in Orchard Core. Covers CorsSettings policies, CorsPolicySetting options, CorsService persistence, CorsOptionsConfiguration, admin configuration, deployment, and secure origin restrictions. Use this skill when requests mention Orchard Core CORS, CorsSettings, cross-origin requests, allowed origins, CORS policies, or closely related Orchard Core implementation, setup, extension, or troubleshooting work. Strong matches include work with OrchardCore.Cors, CorsSettings, CorsPolicySetting, CorsService, CorsOptionsConfiguration, CorsOptions, and ManageCorsSettings. It also helps with feature recipes, policy deployment, security validation, and the code patterns captured in this skill.
-
crestapps Skill Orchardcore Https 2Skill for enforcing HTTPS and HSTS per Orchard Core tenant. Covers HttpsSettings, IHttpsService, HTTPS redirection, permanent redirect status, SSL port selection, HSTS modes, admin settings, and deployment. Use this skill when requests mention Orchard Core HTTPS, HttpsSettings, RequireHttps, HSTS, HTTPS redirection, strict transport security, or closely related Orchard Core implementation, setup, extension, or troubleshooting work. Strong matches include work with OrchardCore.Https, HttpsSettings, IHttpsService, HttpsService, HttpStrictTransportSecurityMode, HttpsSettingsDisplayDriver, HttpsRedirectionOptions, and AddHsts. It also helps with feature recipes, proxy considerations, migrations, and the code patterns captured in this skill.
-
crestapps Bundle Orchardcore Security 2Skill for configuring security and authorization in Orchard Core. Covers permission definitions, authorization services, CORS, security headers, content security policies, and OpenID Connect. Use this skill when requests mention Orchard Core Security, Configure Security and Authorization, Enabling Security Features, Security Headers Configuration, CORS Configuration via Recipe, OpenID Connect Server Setup, or closely related Orchard Core implementation, setup, extension, or troubleshooting work. Strong matches include work with OrchardCore.Security, OrchardCore.Cors, OrchardCore.ReverseProxy, OrchardCore.OpenId, OrchardCore.OpenId.Server, OrchardCore.OpenId.Validation, OrchardCore.Security.Permissions, OrchardCore.ContentManagement, OrchardCore.Contents.Security. It also helps with security examples, CORS Configuration via Recipe, OpenID Connect Server Setup, OpenID Server Settings, plus the code patterns, admin flows, recipe steps, and referenced examples captured in this skill.
-
modu-ai Skill Commerce Automation Audit 2[책임 경계] 셀러 운영 자체 진단 + 자동화 우선순위 점수 산정 + 3 Phase 로드맵 자동 생성 전담. "커머스 업무 자동화" 프레임워크(6대 영역 A-F + 3 자동화 유형 + 4단계 설계 프로세스)를 자연어로 wrapping. 페어 스킬 commerce-integrated-strategy(매출 향상 전략 1장)와 명확히 구분 — 본 스킬은 운영 자동화 진단·로드맵, 페어는 매출 향상 즉시 실행 전술. 다음과 같은 요청 시 반드시 이 스킬을 사용하세요: "자동화 진단해줘", "내 매장 자동화 우선순위", "ROI 자동화 영역 찾아줘", "자동화 로드맵 만들어줘", "Quick Wins Phase 진단", "반복형 판단형 창의형 분류", "RPA 도입 검토", "AI Copilot 적용", "HITL 검수 지점 설계", "조직 규모별 자동화 도구 추천". 6대 영역 (A 상품운영 / B 가격&프로모션 / C 주문&정산 / D 재고&물류 / E 마케팅&고객 / F 데이터&경영) 진단 + 자동화 3분류 + 우선순위 점수 (빈도×시간×오류비용÷복잡도) + 5대 KPI + 3 Phase 로드맵. ai-slop-reviewer 자동 체이닝 (진단 보고서 텍스트 산출물). 슬롭 검수 직후 moai-writer:korean-humanize으로 한국어 AI 티를 제거합니다 (슬롭 검수 다음, 필수). 이커머스 운영 자동화 가능성 자가 진단 + 우선순위·로드맵 생성.
-
modu-ai Bundle Commerce Integrated Strategy 2선행 스킬 산출물(commerce-market-research·commerce-jtbd-persona·commerce-product-naming·cs-channel-message·commerce-detail-page-copy 결과)과 매장 운영 데이터를 종합해 매출 향상 통합 전략 1장 + 실행 우선순위 Top 3을 자동 생성하고, 채널 믹스·가격·프로모션 캘린더·리텐션·KPI까지 단계별(런칭/성장/안정)로 설계합니다. 다음과 같은 요청 시 반드시 이 스킬을 사용하세요: "오늘 배운 것 종합 전략으로 정리해줘", "통합 전략 뽑아줘", "실행 우선순위 정해줘", "매출 올리는 전략 1장", "지금 당장 해야 할 것 Top3", "ROAS 개선 전략", "채널별 매출 비교 분석", "커머스 전략 짜줘", "채널 믹스 추천해줘", "가격 전략 세워줘", "프로모션 캘린더 만들어줘", "리텐션 전략 추천", "이커머스 KPI 대시보드 설계" 매크로 전략 모드(채널 믹스·3단계 가격·시즌 프로모션 캘린더·재구매 자동화·KPI 대시보드 references 제공) + 통합 1장 모드(선행 산출물 종합) 2계층으로 동작하며, 전략 1장 직후 moai-coworker:ai-slop-reviewer를 자동 체이닝합니다. [책임 경계] 본 스킬은 이커머스 셀러 즉시 실행 전술 + 채널 전략. 중장기 사업 전략은 moai-consultant:consult-strategy, 운영 자동화 진단은 moai-seller:commerce-automation-audit 사용.
-
wenjunduan Bundle Security Test 2Use when a business feature needs scoped security verification before delivery. Reads the project's Convention Pack, security checklist, dependency policy, and runtime-env, then performs static checks plus declared dynamic auth, authorization, data-scope, and input-validation cases. It is not an automated penetration test and does not expand scope without approval.
-
wenjunduan Bundle Quantum Codegen 4全栈代码快速生成 (quantum 适配层). 按 mode 生成: 前端页面/组件 (page) · 后端模块脚手架 (module) · 数据库表结构与 DDL (db) · 后端单元测试 (unit) · 安全测试 (security) · 端到端 E2E 测试 (e2e). 当用户说"生成页面/建模块/建表/写单测/安全测试/E2E", 或 biz-delivery-loop 编排到对应 stage 时触发. 系统无关: 只读 Convention Pack + runtime-env, 证据写 PACE runtime-verify.
-
crestapps Skill Orchardcore Audit Trail 2Skill for configuring audit trail in Orchard Core. Covers audit event recording, AuditTrailPart for content tracking, event filtering and sorting, audit settings configuration, custom audit event providers, and audit trail feature setup. Use this skill when requests mention Orchard Core Audit Trail, Configure Audit Trail and Event Tracking, Enabling Audit Trail, Audit Trail Event Categories, Audit Trail Event List Features, Attaching AuditTrailPart via Migration, or closely related Orchard Core implementation, setup, extension, or troubleshooting work. Strong matches include work with OrchardCore.AuditTrail, OrchardCore.ContentManagement.Metadata, OrchardCore.Data.Migration, OrchardCore.AuditTrail.Services, OrchardCore.AuditTrail.Services.Models. It also helps with Audit Trail Event List Features, Attaching AuditTrailPart via Migration, Attaching AuditTrailPart via Recipe, plus the code patterns, admin flows, recipe steps, and referenced examples captured in this skill.
-
crestapps Bundle Orchardcore Users Roles 2Skill for managing users, roles, and permissions in Orchard Core. Covers user registration, role creation, permission definitions, custom user settings, and authentication configuration. Use this skill when requests mention Orchard Core Users & Roles, Manage Users, Roles, and Permissions, Enabling User and Role Features, Defining Custom Permissions, Registering Permission Provider, Checking Permissions in Code, or closely related Orchard Core implementation, setup, extension, or troubleshooting work. Strong matches include work with OrchardCore.Users, OrchardCore.Roles, OrchardCore.Users.Registration, OrchardCore.Users.ResetPassword, OrchardCore.Users.CustomUserSettings, OrchardCore.Security.Permissions, IPermissionProvider, IAuthorizationService. It also helps with users roles examples, Registering Permission Provider, Checking Permissions in Code, Checking Permissions in Liquid, plus the code patterns, admin flows, recipe steps, and referenced examples captured in this skill.
-
crestapps Skill Orchardcore Reverse Proxy 2Skill for configuring reverse proxy support in Orchard Core. Covers forwarded headers middleware (X-Forwarded-For, X-Forwarded-Proto, X-Forwarded-Host), configuration sources (admin UI vs file-based), security considerations for trusted proxies, and multi-tenancy forwarding. Use this skill when requests mention Orchard Core Reverse Proxy, Configure Reverse Proxy Support, Enabling the Reverse Proxy Feature, Configuration Options, Admin UI Configuration (Scenario 1), File-Based Configuration (Scenario 2), or closely related Orchard Core implementation, setup, extension, or troubleshooting work. Strong matches include work with OrchardCore.ReverseProxy, ConfigureReverseProxySettings, OrchardCoreBuilder, CreateBuilder, appsettings.json. It also helps with Admin UI Configuration (Scenario 1), File-Based Configuration (Scenario 2), Partial Override Configuration (Scenario 3), plus the code patterns, admin flows, recipe steps, and referenced examples captured in this skill.
-
wenjunduan Skill Security Review 8安全审查清单 (源自 ECC security-review)
-
codyswanngt Bundle Owasp Zap 2This skill should be used when running or interpreting an OWASP ZAP baseline DAST scan of the Expo web export — after changes to HTTP headers, authentication, or security middleware, before deploying to staging or production, or when triaging ZAP findings from CI or pull request checks. Covers running scripts/zap-baseline.sh locally, risk-level triage, common findings and fixes, and .zap/baseline.conf rule configuration.
-
codyswanngt Bundle Lisa Doctor 2Audit whether the current repository is ready to use Lisa. Runs grouped read-only checks across project detection, Lisa config, runtime distribution surfaces, tracker/source preflight access, automation prerequisites, optional GitHub Project coordination, and optional wiki delegation, then reports PASS/WARN/FAIL/SKIP results plus an overall readiness verdict (`READY`, `READY_WITH_WARNINGS`, or `NOT_READY`).
-
jmagly Skill Schema Review 2Review a schema or data-contract change for authority, correctness, compatibility, fixtures, security, and projection integrity.
-
codyswanngt Bundle Lisa Openclaw Setup 2Set up OpenClaw as the chat-surface runtime for this project's staff roles. Verifies the openclaw CLI, the ~/.openclaw/openclaw.json config, a secret provider, and the required gateway capabilities (sessions_spawn, native-reply session scoping, the NO_REPLY sentinel), then writes a lean `openclaw` section to .lisa.config.json. Prerequisite for lisa-openclaw-connect-staff and lisa-openclaw-connect-repo-topic. Use when a project wants its facilitator/specialist staff reachable from Telegram or Slack.
-
codyswanngt Bundle Lisa Security Review 2Security review methodology. STRIDE threat modeling, OWASP Top 10 vulnerability checks, auth/validation/secrets handling review, and mitigation recommendations.
-
mk-organization-1 Skill Springboot Security 3Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
-
ulpi-io Skill Security 2OWASP security patterns, secrets management, security testing
-
ulpi-io Bundle Test MasterGenerates test files, creates mocking strategies, analyzes code coverage, designs test architectures, and produces test plans and defect reports across functional, performance, and security testing disciplines. Use when writing unit tests, integration tests, or E2E tests; creating test strategies or automation frameworks; analyzing coverage gaps; performance testing with k6 or Artillery; security testing with OWASP methods; debugging flaky tests; or working on QA, regression, test automation, quality gates, shift-left testing, or test maintenance.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include vibe-security-skill, owasp-check, devex-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.