Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
dingxingdi Bundle Security Vulnerability Repair 3Use this skill when the user wants software-fix data focused on identifying, mitigating, or preventing security bugs. Trigger it for requests like 'make security repair tasks', 'generate vulnerability-fixing data', 'ensure the new feature is secure against XSS/injections', or 'create patching tasks for insecure code'. This applies both to patching existing vulnerabilities and securely implementing missing features where the primary challenge is defending against CWEs (like timing side-channels, broken access control, or header injections) during development. Do not use it for ordinary non-security defects.
-
team-telnyx Skill Telnyx Account Go 2Manage account balance, payments, invoices, webhooks, and view audit logs and detail records. This skill provides Go SDK examples.
-
team-telnyx Skill Telnyx Account Curl 2Manage account balance, payments, invoices, webhooks, and view audit logs and detail records. This skill provides REST API (curl) examples.
-
team-telnyx Skill Telnyx Account Java 2Manage account balance, payments, invoices, webhooks, and view audit logs and detail records. This skill provides Java SDK examples.
-
team-telnyx Skill Telnyx Account Ruby 2Manage account balance, payments, invoices, webhooks, and view audit logs and detail records. This skill provides Ruby SDK examples.
-
team-telnyx Skill Telnyx Account Python 2Manage account balance, payments, invoices, webhooks, and view audit logs and detail records. This skill provides Python SDK examples.
-
qte77-claude-code-utils Bundle Securing Mas 2Apply OWASP MAESTRO, MITRE ATLAS, NIST AI RMF, and ISO 42001/23894 security frameworks to MAS designs
-
qte77-claude-code-utils Bundle Reviewing Code 2Provides concise, focused code reviews matching exact task complexity requirements. Use when reviewing code quality, security, or when the user asks for code review.
-
qte77-claude-code-utils Skill Auditing Readme 2Audit README.md files against best practices for repos, accounts, or orgs. Detects missing sections, stale links, inconsistent formatting, and convention violations. Use when reviewing README quality across one or many repos.
-
qte77-claude-code-utils Skill Detecting Secrets 2Detect hardcoded secrets, API keys, tokens, and credentials in code and git history. Use when auditing for leaked secrets or before publishing code.
-
qte77-claude-code-utils Bundle Hardening Codebase 2Audit and tighten codebase quality gates — architecture, lint, types, tests, docs, code review. Use when onboarding a project, before a release, or when validation is too permissive.
-
qte77-claude-code-utils Skill Scanning Dependencies 2Scan project dependencies for vulnerabilities, license issues, and supply chain risks. Use when auditing third-party packages or before releases.
-
team-telnyx Skill Telnyx Account Javascript 2Manage account balance, payments, invoices, webhooks, and view audit logs and detail records. This skill provides JavaScript SDK examples.
-
auto-skiller Bundle Audit Fix 2<purpose>
1 -
auto-skiller Bundle Audit Uat 2<purpose>
1 -
auto-skiller Bundle Audit Milestone 2<purpose>
1 -
qte77-claude-code-utils Skill Auditing Code Security 2Audit code against OWASP Top 10 vulnerabilities with structured findings. Use when reviewing code for security issues or conducting security audits.
-
qte77-claude-code-utils Skill Enforcing Doc Hierarchy 2Audit documentation against its declared hierarchy — broken links, duplicates, misplaced content, stale references, single-source-of-truth enforcement. Use for doc health reviews.
-
qte77-claude-code-utils Bundle Triaging Security Report 2Verify an external or AI-generated security report against the actual codebase before acting on it. Use when handed a scanner PDF, automated teardown, audit report, or bug-bounty submission — classifies every finding CONFIRMED / OVERSTATED / FALSE-POSITIVE / FABRICATED and salvages the real work items.
-
qte77-claude-code-utils Skill Auditing Website Usability 2Audits website usability for UX optimization, covering forms, navigation, validation, and microcopy. Use when reviewing user experience, task completion flows, or interface friction points.
-
alterlab-ieu Skill Alterlab Nmc Digital Ethics 2This skill should be used when the user asks about "digital ethics", "media ethics", "AI ethics", "platform governance", "misinformation", "disinformation analysis", "act as a digital ethics advisor", "digital ethics mode", "algorithmic bias", "data privacy", "content moderation", "ethical framework", "deepfake", "surveillance", "fact-checking tools", "verification workflow", "platform audit", "ethics stress test", "algorithmic accountability", "informed consent", "digital rights", "tech regulation", or needs expertise in analyzing ethical dilemmas in digital media, AI, and platform ecosystems. Part of the AlterLab FC Skills collection (New Media & Communication department).
60 -
gmickel Bundle Flow Next Audit 4Audit `.flow/memory/` entries against the current codebase and decide Keep / Update / Consolidate / Replace / Delete per entry. Triggers on /flow-next:audit, "audit memory", "review memory", "refresh learnings", "sweep stale memory", "consolidate overlapping memory entries". Optional `mode:autofix` token in arguments runs without questions and marks ambiguous as stale. Optional scope hint after the mode token (concept, category, module, or path) narrows what gets audited.
-
gmickel Bundle Flow Next Audit 5Audit `.flow/memory/` entries against the current codebase and decide Keep / Update / Consolidate / Replace / Delete / Harden per entry. Triggers on /flow-next:audit, "audit memory", "review memory", "refresh learnings", "sweep stale memory", "consolidate overlapping memory entries", "graduate a recurring lesson into a gate". Optional `mode:autofix` token in arguments runs without questions and marks ambiguous as stale (Harden is never auto-applied). Optional scope hint after the mode token (concept, category, module, or path) narrows what gets audited.
-
gmickel Bundle Flow Next Audit 6Audit .flow/memory/ entries against current code and keep, update, consolidate, replace, delete, or harden each. Use when asked to audit memory or graduate a recurring lesson into a gate.
-
ftshare-lab Bundle Security Search 2按名称、代码或拼音搜索标的。必填 --query,可选 --limit。接口:GET /api/v1/market/security/search/。
-
concertonotes Skill Audit Search 2Search AxonFlow audit trail for recent tool executions, policy decisions, and compliance evidence
0 -
wahidyankf Bundle Plan Grooming Idea Briefs 2Invocable entry point for the plan-ideas-grooming workflow — sweeps one or more repos' plans/ideas/ folders and converges them into a deduplicated, Eisenhower-quadrant-organized, correctly-resident set of two-pagers. Carries the ten-step procedure, the three residency rules (secrets-bearing, single-repo-only, generalizable), the two classification rubrics (urgency, importance), the fail-safe-toward-duplication relocation sequence, and the six-clause termination audit. Use when a repo's flat idea count exceeds 60, when 90 days have elapsed since the last recorded run, or when a maintainer asks for idea grooming across repos.
-
wahidyankf Bundle Docs Fixing Tutorial Quality 2Domain-specific methodology for docs-tutorial-fixer — re-validating docs-tutorial-checker findings on pedagogical structure, then applying fixes only for objective issues (missing sections, LaTeX delimiters, naming, time estimates, frontmatter) while flagging subjective narrative/style findings for manual review. Use when applying validated fixes from a tutorial audit report.
-
wahidyankf Bundle Pr Review Specialist Protocol 2The shared execution protocol inherited verbatim from the retired pr-review-maker monolith by all nine discipline-scoped pr-review-*-maker specialists (architecture, docs, governance, instruction, integrity, logic, performance, security, types) - context consumption, finding requirements hard rules, scope guard, untrusted-input handling, findings handoff (no direct posting), cross-cycle behaviour, and external fact verification. Use when reviewing a PR as one of the nine discipline specialists.
-
wahidyankf Bundle Repo Generating Validation Reports 2Guidelines for generating validation/audit reports with UUID chains, progressive writing, and UTC+7 timestamps
-
wahidyankf Bundle Repo Assessing Criticality Confidence 2Universal classification system for checker and fixer agents using orthogonal criticality (CRITICAL/HIGH/MEDIUM/LOW importance) and confidence (HIGH/MEDIUM/FALSE_POSITIVE certainty) dimensions. Covers priority matrix (P0-P4), execution order, dual-label pattern for verification status, standardized report format, and domain-specific examples. Essential for implementing checker/fixer agents and processing audit reports
-
elsolal Skill Thermo Nuclear Code Quality Review 2Runs an unusually strict code-quality and maintainability review. Use when the user asks for a thermo-nuclear or thermonuclear review, a very harsh code-quality audit, a deep maintainability review, or a structural simplification pass before ship. Produces prioritized structural findings and concrete cleaner-design remedies.
-
activer007 Bundle Blockchain Developer 2Expert blockchain developer specializing in smart contract development, DApp architecture, and DeFi protocols. Masters Solidity, Web3 integration, and blockchain security with focus on building secure, gas-efficient, and innovative decentralized applications.
-
activer007 Bundle Software Crypto Web3 2Production-grade blockchain and Web3 development with Solidity (Ethereum/EVM), Rust (Solana), CosmWasm (Cosmos), including smart contract architecture, security patterns, gas optimization, testing strategies, DeFi protocols, and deployment workflows.
-
activer007 Bundle Network Security Setup 2Configure Claude Code sandbox network isolation with trusted domains, custom access policies, and environment variables
-
activer007 Bundle API Test Generator 2Генерация полных Python pytest тестов для REST API эндпоинтов с валидацией схемы. Использовать при создании тестов для новых эндпоинтов, добавлении покрытия для CRUD операций или валидации соответствия API с OpenAPI схемами.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-vulnerability-repair, telnyx-account-go, telnyx-account-curl. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.