Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ferroxlabs Bundle Legal Cease And Desist 2Draft a cease-and-desist letter for trademark, copyright, IP misuse, defamation, breach of contract or unpaid debt, choosing tone deliberately (professional, firm, litigation-threat) and assembling the evidence section, the specific demand and the response deadline. Use when the user needs a formal written demand that a behaviour stop. Do NOT use for a platform takedown of hosted content (use legal-dmca) or for drafting the agreement being breached (use sentry-contracts-and-terms). Template only — a letter that threatens litigation can create liability of its own, so have an attorney review high-stakes versions before sending.
37 -
fabioc-aloha Skill Test Quality Analysis 2Analyze test code quality to detect coverage-only tests, test smells, and low-value assertions. Use when asked to "analyze test quality", "find coverage-only tests", "audit our tests", "are these tests valuable", "find test smells", or "which tests should we delete". Scores tests 1-5 on real value and produces prioritized improvement reports.
-
fabioc-aloha Skill Markdown Sanitization Chain 2Render user-supplied markdown safely — marked.js → DOMPurify → Mermaid (order matters; skipping the sanitizer is XSS)
-
fabioc-aloha Skill Token Waste Elimination 3Audit and eliminate token waste from cognitive architecture memory files -- instructions, prompts, skills, and agents
-
fabioc-aloha Skill Extension Audit Methodology 2Systematic 5-dimension audit framework for VS Code extensions — debug hygiene, dead code, performance, menu validation, dependency cleanup
-
fabioc-aloha Skill Documentation Quality Assurance 2Systematic documentation audit, drift detection, preflight validation, and multi-pass quality pipelines
-
happy-technologies-llc Skill UI Actions 2Complete guide to UI Action development including form buttons, list buttons, context menu actions, client-side and server-side scripts, conditions, security, and common patterns
-
happy-technologies-llc Skill Code Review 2Review ServiceNow code for security vulnerabilities, performance issues, and platform best practices
-
happy-technologies-llc Skill Issue Summarization 2Summarize GRC issues with context including related risks, controls, compliance gaps, and business impact to generate executive-ready summaries for audit committees
-
happy-technologies-llc Skill Metrics Analysis 2Analyze security operations metrics including MTTD, MTTR, incident volume trends, false positive rates, and analyst workload distribution
-
happy-technologies-llc Skill Acl Management 2Complete access control list management - understanding ACL structure, creating/modifying ACLs, troubleshooting permission issues, and debugging techniques
-
codyswanngt Skill Lisa Attribute Failure 2Event-triggered root-cause attribution for an arbitrary failure: decide, with cited evidence, whether the defect is Lisa's fault or the project's. Accepts a failure event (defect description, implicated files, rule/skill/hook in play) and returns a verdict of lisa | project | ambiguous plus the evidence relied on. Read-only — it never files, writes, or remediates; callers (lisa-doctor findings, the learning judgment gate, rework triage) consume the verdict. Extracted from lisa-doctor's upstream Lisa change-history diagnosis (#1494) so the same attribution procedure can run on ANY failure event, not only doctor config-audit findings.
-
s3yed Skill Code Review 2Guidelines for performing thorough code reviews with security and quality focus
-
s3yed Skill Gws Admin Reports 2Google Workspace Admin SDK: Audit logs and usage reports.
-
happy-technologies-llc Skill Audit Compliance 2Comprehensive audit trail analysis, user activity tracking, compliance reporting, and anomaly detection for ServiceNow environments
-
happy-technologies-llc Skill Incident Response 2Security incident detection, containment, and response procedures for ServiceNow environments
-
happy-technologies-llc Skill Correlation Insights 2Correlate security incidents with related events, vulnerabilities, and threat intelligence to identify attack patterns and common indicators
-
happy-technologies-llc Skill Secops Incident Summarization 2Generate executive and technical summaries for security incidents including threat classification, affected assets, containment status, and recommended actions
-
happy-technologies-llc Skill Post Incident Analysis 2Conduct post-incident review for closed security incidents including timeline reconstruction, detection/response gap analysis, and lessons-learned documentation
-
happy-technologies-llc Skill Government Case Summarization 2Summarize government and public sector cases with regulatory compliance context, service eligibility tracking, inter-agency coordination, and audit trail documentation
-
happy-technologies-llc Skill Security Recommended Actions 2Generate recommended actions for security incidents based on threat type, severity, affected assets, and playbook alignment. Include containment, eradication, and recovery steps
-
comeonoliver Bundle Fastify Best Practices 2Guides development of Fastify Node.js backend servers and REST APIs using TypeScript or JavaScript. Use when building, configuring, or debugging a Fastify application — including defining routes, implementing plugins, setting up JSON Schema validation, handling errors, optimising performance, managing authentication, configuring CORS and security headers, integrating databases, working with WebSockets, and deploying to production. Covers the full Fastify request lifecycle (hooks, serialization, logging with Pino) and TypeScript integration via strip types. Trigger terms: Fastify, Node.js server, REST API, API routes, backend framework, fastify.config, server.ts, app.ts.
61 -
comeonoliver Skill Security Ownership Map 2Security Ownership Map
61 -
comeonoliver Skill Security Best Practices 2Security Best Practices
61 -
comeonoliver Bundle Xss Prevention 2XSS Prevention
61 -
comeonoliver Bundle White Label 2Complete WordPress white-labeling using FREE plugins only - ASE, Branda, White Label CMS, Admin Menu Editor. Covers login page branding, admin cleanup, security hardening, and client handoff preparation.
61 -
comeonoliver Bundle Skill Vetter 2Security-first vetting for OpenClaw skills. Use before installing any skill from ClawHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
61 -
mhassan0000 Skill Quality Nonconformance 2Codified expertise for quality control, non-conformance investigation, root cause analysis, corrective action, and supplier quality management in regulated manufacturing. Informed by quality engineers with 15+ years experience across FDA, IATF 16949, and AS9100 environments. Includes NCR lifecycle management, CAPA systems, SPC interpretation, and audit methodology. Use when investigating non-conformances, performing root cause analysis, managing CAPAs, interpreting SPC data, or handling supplier quality issues.
1 -
mhassan0000 Bundle Compliance Os 2Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across multiple frameworks. Four decisions: (1) Given a company profile, which of the 12 supported frameworks apply (ISO 27001/13485/42001/14971, EU AI Act, MDR 745, GDPR, SOC 2, FDA QSR, NIST CSF 2.0, NIS2, HIPAA)? (2) Across selected frameworks, which controls overlap and how much evidence reuses? (3) For a given framework + scope, what does a realistic mock audit produce — drawing from the 205-scenario library? (4) Across selected frameworks, what's the unified evidence checklist with reuse map? Use when standing up a multi-framework program, planning the annual audit calendar, or preparing for certification stage 1. Does NOT replace per-framework skills (it orchestrates them).
1 -
mhassan0000 Bundle Qms Audit Expert 2ISO 13485 internal audit expertise for medical device QMS. Covers audit planning, execution, nonconformity classification, and CAPA verification. Use when planning internal audits, executing audits, classifying findings, preparing for external audits, or managing an audit program.
1 -
mhassan0000 Skill Pr Review Expert 2Use when the user asks to review pull requests, analyze code changes, check for security issues in PRs, or assess code quality of diffs.
1 -
mhassan0000 Skill Gdpr Audit Prep 2Gdpr Audit Prep
1 -
mhassan0000 Skill Soc2 Audit Prep 2Soc2 Audit Prep
1 -
mhassan0000 Bundle Senior Backend 2Designs and implements backend systems including REST APIs, microservices, database architectures, authentication flows, and security hardening. Use when the user asks to "design REST APIs", "optimize database queries", "implement authentication", "build microservices", "review backend code", "set up GraphQL", "handle database migrations", or "load test APIs". Covers Node.js/Express/Fastify development, PostgreSQL optimization, API security, and backend architecture patterns.
1 -
mhassan0000 Skill Fda Qsr Audit Prep 2Fda Qsr Audit Prep
1 -
mhassan0000 Bundle Knowledge Ops 2Use when a Head of Ops, Knowledge Manager, or TPM-Internal needs to author, validate, or clean up company SOPs and internal runbooks (procurement intake, vendor offboarding, incident-comms cascade, employee onboarding) — including 5W2H completeness checks (Who-What-When-Where-Why-How-HowMuch), cross-link and orphan-page validation across a sprawling Notion/Confluence/Obsidian wiki, KB ingestion + hygiene reporting, and runbook step verification (named owner, expected duration, observable success signal, rollback path, escalation contact). Pairs Ishikawa's 5W2H method, Gawande's *The Checklist Manifesto*, ISO 9001, ITIL v4, and Google SRE Workbook runbook discipline with deterministic stdlib-only Python tools that score completeness, detect anti-patterns, and emit prioritized cleanup lists (e.g., "validate this runbook before it goes into rotation", "audit our Confluence wiki for stale and orphaned SOPs").
1
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include legal-cease-and-desist, test-quality-analysis, markdown-sanitization-chain. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.