Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
activer007 Bundle Insforge Schema Patterns 2Database schema patterns for InsForge including social graphs, e-commerce, content publishing, and multi-tenancy with RLS policies. Use when designing data models with relationships, foreign keys, or Row Level Security.
-
lza6 Skill Gsd Plan Milestone Gaps 2Create phases to close all gaps identified by milestone audit
-
mn755 Skill Mission Control Review Burst 2Use when Mission Control should recommend a bounded read-only review burst across correctness, security, testing, maintainability, and docs.
-
mn755 Skill Mission Control Tool Registry 2Design or audit tool registries, tool schemas, permissions, and runner capabilities through Mission Control.
-
mn755 Skill Mission Control Subagent Burst 2Recommend or review Mission Control Codex subagent bursts for bounded read-heavy work. Use when the user wants parallel exploration, review, planning, handoff audit, or failure diagnosis without replacing the normal worker system.
-
mn755 Skill Mission Control Handoff Audit Burst 2Use when Mission Control should recommend a read-only handoff audit burst for run instructions, validation evidence, limitations, docs quality, and security caveats.
-
mn755 Skill Mission Control Skill Ecosystem Builder 2Build, audit, or package Mission Control skills and plugin skill bundles. Use when the user wants reusable skills, skill metadata, skill tests, marketplace packaging, or cross-host skill compatibility.
-
delorenj Bundle Project Lifecycle 2Multi-workspace Plane sprint board management with intelligent automation, ticket creation, and BMAD workflow integration. Use this skill when: - Creating tickets, task descriptions, or audit findings - Auditing board organization (ticket clustering, label optimization, status bottlenecks) - Selecting the next optimal ticket to work on - Promoting completed tickets to production and generating changelogs - Working with multiple Plane workspaces - Understanding the canonical Plane CRUD → n8n HMAC → Bloodbank → Candystore event side effect - For higher-level orchestration — "what's next", "clear the board", "orchestrate this ticket" — route to the **`momo`** skill, which surveys the board, triages, decides, and delegates implementation to subagents. Triggers: "create ticket", "board audit", "what should I work on", "next ticket", "promote to production", "changelog", "sprint status", "WIP limit", plane ticket operations
1 -
blockmatic Bundle F Security 2Apply Security First with a security lens who inspects this repo as a data analyst. Use when the user types /f-security or /f security.
-
blockmatic Skill Security Audit 2Audit the change or tree against the repository Security overlay and existing checks. Use when the user types /security-audit.
-
blockmatic Skill Security Review 2Review current code against the repository Security overlay; report evidence and remedies. Use when the user types /security-review.
-
boisenoise Bundle Neurokit2 2Use NeuroKit2 to build or audit reproducible research workflows for physiological time-series preprocessing, event/interval analysis, multimodal alignment, variability, and complexity. Trigger when code imports neurokit2 or needs its current APIs, schemas, and method-aware validation—not for diagnosis or device validation.
-
boisenoise Bundle Scholar Evaluation 2Provide qualitative-first, evidence-traceable developmental review of scholarly works and audit low-stakes research-assessment rubrics with optional local quality controls. Never use for ranking people or consequential decisions.
-
boisenoise Bundle Scientific Writing 2Draft, revise, and audit scientific manuscripts or reports with explicit evidence provenance, reporting-guideline coverage, authorship accountability, confidentiality controls, and local consistency checks. Use for manuscript sections, references, declarations, tables, figures, or submission preparation when scientific accuracy and traceability matter.
-
boisenoise Bundle Scientific Visualization 2Create and audit truthful, accessible, publication-ready scientific figures with Matplotlib, Seaborn, or Plotly. Use for figure design, multi-panel layouts, uncertainty and missing-data displays, color/contrast review, image metadata validation, and journal export planning.
-
iradoweck Skill Top Web Vulnerabilities 2Provide a comprehensive, structured reference for the 100 most critical web application vulnerabilities organized by category. This skill enables systematic vulnerability identification, impact assessment, and remediation guidance across the full spectrum of web security threats.
-
iradoweck Skill Linux Privilege Escalation 2Execute systematic privilege escalation assessments on Linux systems to identify and exploit misconfigurations, vulnerable services, and security weaknesses that allow elevation from low-privilege user access to root-level control.
-
iradoweck Skill Pci Compliance 2Master PCI DSS (Payment Card Industry Data Security Standard) compliance for secure payment processing and handling of cardholder data.
-
rjmurillo Bundle Analyze 2Systematic multi-step codebase analysis producing prioritized findings with file-line evidence. Covers architecture reviews, security assessments, and code quality evaluations through guided exploration, investigation planning, and synthesis. Use when you say "analyze this codebase", "run security assessment", "architecture review of this system", "find code smells", or "review code quality" across multiple files. Do NOT use for single-file maintainability scoring (use code-qualities-assessment) or CWE-78 injection pattern scanning (use security-scan).
-
rjmurillo Skill Dx Review 2Evidence-based developer experience audit. Discovers the target, tests onboarding and setup flows, evaluates API/CLI ergonomics, error messages, documentation, upgrade paths, developer environment, community health, and DX measurement practices. Produces a scorecard where every score cites evidence labeled TESTED, PARTIAL, or INFERRED. Measures Time-to-Hello-World when the target supports it. Compares against a prior dx-review result when one exists (boomerang). Use when asked to "run a DX audit", "test the developer experience", "measure onboarding friction", "DX scorecard", or "evaluate developer ergonomics".
-
rjmurillo Bundle Codeql Scan 2Execute CodeQL security scans with language detection, database caching, and SARIF output. Use when performing static security analysis on Python or GitHub Actions code.
-
rjmurillo Bundle Doc Accuracy 2Multi-phase documentation verification treating code as source of truth. Use when you say "check documentation accuracy", "verify code examples compile", "audit docs vs code", "check doc consistency", or "run doc-accuracy". Use for pre-release doc audits and checking behavioral claims. Do NOT use for broad codebase analysis (use analyze) or fixing markdown fence syntax (use fix-markdown-fences).
-
rjmurillo Bundle Security Scan 2Detect CWE-78 (command injection) regex patterns in Python, PowerShell, Bash, and C# files before PR submission. CWE-22 is delegated to CodeQL; see Scope. Use when you ask "scan for command injection", "CWE-78 check before PR". Do NOT use to decide whether security review is warranted (use security-detection).
-
rjmurillo Bundle Quality Grades 2Grade each product domain and architectural layer with A-F scoring and gap tracking. Produces markdown or JSON reports showing grades, file counts, gaps, and trends. Use when you ask "grade quality", "audit domain quality", "show quality gaps", "domain quality report", or "run quality grades" across a repo. Use for repo-wide A-F domain grading and trend tracking. Do NOT use for single-file maintainability scoring (use code-qualities-assessment) or a pre-merge review (use review).
-
rjmurillo Bundle Threat Modeling 2Structured security analysis using OWASP Four-Question Framework and STRIDE methodology. Generates threat matrices with risk ratings, mitigations, and prioritization. Use for attack surface analysis, security architecture review, or when asking what can go wrong. Do NOT use for per-change diff or snippet risk review; use security-review instead.
-
rjmurillo Bundle Chaos Experiment 2Design and document chaos engineering experiments. Guide steady state baseline, hypothesis formation, failure injection plans, and results analysis. Use when you say "design a chaos experiment", "plan a game day", "failure injection", "test resilience", or "chaos engineering". Do NOT use for security threat analysis (use threat-modeling) or pre-launch project risk identification (use pre-mortem).
-
rjmurillo Bundle AI Agents External Claims 2Verify external, vendor, and third-party claims (numbers, attributions, structure) against authoritative primary sources before they land in a repo artifact or external deliverable. Covers stake-holding sources, round-number tells, citation-chain drift, and the walk-the-gate-or-file-conservative discipline. Use when you say `verify an external claim`, `check a vendor number`, `is this stat real`, `validate a third-party citation`. Do NOT use for running an experiment (use `ai-agents-research-methodology`) or command-injection scanning (use `security-scan`).
-
richfrem Bundle Example Skill 2A minimal well-structured plugin used as a test fixture for self-audit regression testing.
-
tfcbot Skill Audit Claims 2Scan copy for risky claims via Gemini.
-
iradoweck Skill API Security Best Practices 2Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities
-
iradoweck Skill Cc Skill Security Review 2This skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing authentication or authorization, handling user input or file uploads, or creating new API endpoints.
-
lza6 Skill Gsd Code Review 2Review source files changed during a phase for bugs, security issues, and code quality problems
-
lza6 Skill Gsd Secure Phase 2Retroactively verify threat mitigations for a completed phase
-
lza6 Skill Gsd Validate Phase 2Retroactively audit and fill Nyquist validation gaps for a completed phase
-
lza6 Skill Gsd Audit Milestone 2Audit milestone completion against original intent before archiving
-
ai-driven-dev Bundle 04 Audit 2Audit a codebase read-only across seven quality pillars into one ranked report. Use when the user wants to assess, health-check, or audit a codebase or one pillar. Not for fixing findings, reviewing a change, or checking a feature works.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include insforge-schema-patterns, gsd-plan-milestone-gaps, mission-control-review-burst. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.