Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
irahardianto Skill Logging Implementation 2Structured logging implementation patterns: log levels, mandatory context fields (correlationId, userId, duration), security (PII scrubbing), and per-language library choices (Go slog, TypeScript pino, Python structlog). Load when implementing logging in any operation entry point. Prerequisite: logging-and-observability-mandate.md.
-
cosmix Skill Loom Istio 2Service mesh implementation with Istio for microservices traffic management, security, and observability.
-
cosmix Skill Loom Code Review 2Comprehensive code review covering correctness, maintainability, performance, security, and best practices.
-
cosmix Skill Loom Security Scan 2Quick routine security checks for secrets, dependencies, container images, and common vulnerabilities.
-
cosmix Skill Loom Security Audit 2Comprehensive security audits across applications, APIs, infrastructure, and data pipelines.
-
netvar1337 Skill Radio Sdr 2Use for authorized RF/SDR security research including signal identification, replay feasibility study in shielded labs, and wireless protocol analysis outside classic Wi-Fi.
-
netvar1337 Skill Code Audit 2Use for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.
-
netvar1337 Skill Exploit Dev 2Exploit development workflow covering vulnerability research, PoC construction, shellcode writing, ROP chains, heap grooming, and privilege escalation. Invoke with /exploit-dev or when the task involves exploit writing or vulnerability analysis.
-
netvar1337 Skill Thick Client 2Use for authorized security testing of desktop thick clients including local storage, update channels, IPC, traffic, and client-side trust boundaries.
-
netvar1337 Skill Macos Reverse 2Use for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.
-
netvar1337 Skill Email Security 2Use for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research.
-
netvar1337 Skill Mobile Reverse 2Use for authorized Android or iOS application reverse engineering and security testing, including APK or IPA analysis, runtime instrumentation, SSL pinning, and platform protection checks.
-
netvar1337 Skill Ponytail Audit 2> Bundled with Unleash skills pack. Upstream: https://github.com/DietrichGebert/ponytail
-
netvar1337 Skill Database Security 2Use for authorized database security assessment covering PostgreSQL/MySQL/MSSQL/Mongo/Redis exposure, authz, UDF/command paths, and misconfiguration review.
-
netvar1337 Skill Game Hacking Exploits 2Game exploit classes: memory R/W cheats, packets, authority breaks, race bugs, movement exploits, server RPC abuse.
-
quantumquirkxyz Skill Web3 Defi 2Analyse DeFi protocols — AMMs, lending, stablecoins, derivatives — across protocol mechanics, economic security, and composability risks.
-
quantumquirkxyz Skill Web3 Consensus 2Analyse and compare consensus mechanisms — PoW, PoS, BFT, DA — with security properties, finality guarantees, and economic incentive alignment.
-
quantumquirkxyz Skill Web3 Governance 2Design and audit on-chain and off-chain governance — token voting, delegation, quadratic voting, timelock, multisig, and attack vectors.
-
quantumquirkxyz Skill Web3 L2 Scaling 2Analyse Layer-2 scaling solutions — Rollups (optimistic, ZK), validiums, state channels — with security assumptions, data availability, and cost trade-offs.
-
spillwavesolutions Skill Gsd Audit Uat 2Cross-phase audit of all outstanding UAT and verification items
-
spillwavesolutions Skill Gsd Validate Phase 2Retroactively audit and fill Nyquist validation gaps for a completed phase
-
spillwavesolutions Skill Gsd Audit Milestone 2Audit milestone completion against original intent before archiving
-
spillwavesolutions Skill Gsd Plan Milestone Gaps 2Create phases to close all gaps identified by milestone audit
-
ngocsangyem Skill Mk Review Pr 3Reviews a GitHub PR with a shallow correctness/security/breaking/AI-slop checklist and emits a verdict; optionally posts via gh. NOT for own-diff audit (mk:review); NOT for replying (mk:respond-pr).
-
practice019 Bundle Index 6Use when Product Design is explicitly invoked, or when the user's main goal is to explore a design, research UX, audit or critique a flow, faithfully clone a visual source, check a built design, or share a prototype. Do not use Product Design for ordinary implementation unless the user explicitly asks for it.
-
practice019 Bundle Radio Sdr 2Use for authorized RF/SDR security research including signal identification, replay feasibility study in shielded labs, and wireless protocol analysis outside classic Wi-Fi.
-
practice019 Bundle Code Audit 2Use for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.
-
practice019 Bundle Thick Client 2Use for authorized security testing of desktop thick clients including local storage, update channels, IPC, traffic, and client-side trust boundaries.
-
practice019 Bundle Design QA 2Internal prototype QA helper. Use only after a Product Design prototype, URL-to-code build, or image-to-code build has a source visual target and a rendered implementation to compare before handoff. Do not use for broad UX critique, design critique, product audits, or flow reviews; route those user-facing requests to audit.
-
practice019 Bundle Macos Reverse 2Use for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.
-
practice019 Bundle Wifi Wireless 2Use for authorized wireless security assessment including Wi-Fi capture, WPA handshake analysis, rogue AP detection research, and lab-only deauth testing.
-
practice019 Bundle Email Security 2Use for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research.
-
practice019 Bundle Threat Hunting 2Use for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.
-
quantumquirkxyz Skill Math Cryptography 2Analyse cryptographic constructions — symmetric, asymmetric, hashing, MACs, zero-knowledge — with security reductions, hardness assumptions, and attack analysis.
-
quantumquirkxyz Skill Sec Security Audit 2Audit software/security posture — code review, dependency scanning, secret detection, access control, audit logging — with explicit findings and remediation priorities.
-
quantumquirkxyz Skill Sec Threat Modeling 2Design and document threat models for software / systems — assets, threats, vulnerabilities, mitigations — using STRIDE or ATT&CK frameworks.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include logging-implementation, loom-istio, loom-code-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.