Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
jefflyt Skill Mandate 2 1 2 Code Static Eval 2Evaluate static code indicators for Mandate 2.1.2 (Secure Credential Management). Use when assessing partial code-evaluable controls and producing a confidence-scored static finding package before requesting runtime/process evidence.
-
jefflyt Skill Mandate 2 1 1 Code Static Eval 2Evaluate static code indicators for Mandate 2.1.1 (Authorization and Access Control). Use when assessing partial code-evaluable controls and producing a confidence-scored static finding package before requesting runtime/process evidence.
-
jefflyt Skill Mandate 2 1 3 Code Static Eval 2Evaluate static code indicators for Mandate 2.1.3 (Segregation from Critical Systems). Use when assessing partial code-evaluable controls and producing a confidence-scored static finding package before requesting runtime/process evidence.
-
jefflyt Skill Mandate 2 3 1 Code Static Eval 2Evaluate static code indicators for Mandate 2.3.1 (Comprehensive Logging and Auditing). Use when assessing partial code-evaluable controls and producing a confidence-scored static finding package before requesting runtime/process evidence.
-
jefflyt Skill Mandate 2 3 2 Runtime Evidence Intake Guide 2Gather natural-language context and generate runtime/process evidence collection guidance for Mandate 2.3.2 (Anomaly Detection), including concrete system command templates and artifact checklists for final compliance evaluation.
-
jefflyt Skill Mandate 2 3 4 Code Static Eval 2Evaluate static code indicators for Mandate 2.3.4 (Mitigation of Misinformation and Hallucination). Use when assessing partial code-evaluable controls and producing a confidence-scored static finding package before requesting runtime/process evidence.
-
jefflyt Skill Mandate 2 4 1 Runtime Evidence Intake Guide 2Gather natural-language context and generate runtime/process evidence collection guidance for Mandate 2.4.1 (Resource Consumption Limits), including concrete system command templates and artifact checklists for final compliance evaluation.
-
jefflyt Skill Mandate 2 1 2 Runtime Evidence Intake Guide 2Gather natural-language context and generate runtime/process evidence collection guidance for Mandate 2.1.2 (Secure Credential Management), including concrete system command templates and artifact checklists for final compliance evaluation.
-
jefflyt Skill Mandate 2 3 7 Code Static Eval 2Evaluate static code indicators for Mandate 2.3.7 (UI/UX Behavioural Safeguards and Trust Calibration). Use when assessing partial code-evaluable controls and producing a confidence-scored static finding package before requesting runtime/process evidence.
-
jefflyt Skill Mandate 2 1 1 Runtime Evidence Intake Guide 2Gather natural-language context and generate runtime/process evidence collection guidance for Mandate 2.1.1 (Authorization and Access Control), including concrete system command templates and artifact checklists for final compliance evaluation.
-
jefflyt Skill Mandate 2 1 3 Runtime Evidence Intake Guide 2Gather natural-language context and generate runtime/process evidence collection guidance for Mandate 2.1.3 (Segregation from Critical Systems), including concrete system command templates and artifact checklists for final compliance evaluation.
-
jefflyt Skill Mandate 2 3 1 Runtime Evidence Intake Guide 2Gather natural-language context and generate runtime/process evidence collection guidance for Mandate 2.3.1 (Comprehensive Logging and Auditing), including concrete system command templates and artifact checklists for final compliance evaluation.
-
jefflyt Skill Mandate 2 1 4 Code Static Eval 2Evaluate static code indicators for Mandate 2.1.4 (Sensitive Data Handling in Training Data and System Prompts). Use when assessing partial code-evaluable controls and producing a confidence-scored static finding package before requesting runtime/process evidence.
-
jefflyt Skill Mandate 2 3 4 Runtime Evidence Intake Guide 2Gather natural-language context and generate runtime/process evidence collection guidance for Mandate 2.3.4 (Mitigation of Misinformation and Hallucination), including concrete system command templates and artifact checklists for final compliance evaluation.
-
jefflyt Skill Mandate 2 3 7 Runtime Evidence Intake Guide 2Gather natural-language context and generate runtime/process evidence collection guidance for Mandate 2.3.7 (UI/UX Behavioural Safeguards and Trust Calibration), including concrete system command templates and artifact checklists for final compliance evaluation.
-
jefflyt Skill Mandate 2 1 4 Runtime Evidence Intake Guide 2Gather natural-language context and generate runtime/process evidence collection guidance for Mandate 2.1.4 (Sensitive Data Handling in Training Data and System Prompts), including concrete system command templates and artifact checklists for final compliance evaluation.
-
huytieu Skill Export Open Issues 2Audit and export open issues from any project tracker with summary analysis and vault archival
-
ils15 Skill Security Audit Pro 2Security audit with SAST, SCA, containers, SBOM, PII detection. Use for comprehensive security reviews.
-
ils15 Skill Code Review Checklist 2Systematic code review with quality gates, security audit, and parallel checks. Use for structured feedback on pull requests.
-
practice019 Bundle Database Security 2Use for authorized database security assessment covering PostgreSQL/MySQL/MSSQL/Mongo/Redis exposure, authz, UDF/command paths, and misconfiguration review.
-
aladicf Skill Security UX 9Design security-conscious interfaces that protect users without frustrating them. Use when the user asks about MFA, password UX, breach notifications, trust indicators, secure forms, account recovery, or making security feel safe rather than scary.
-
aladicf Skill Security UX 10Design security-conscious interfaces that protect users without frustrating them. Use when the user asks about MFA, password UX, breach notifications, trust indicators, secure forms, account recovery, or making security feel safe rather than scary.
-
aladicf Skill Security UX 11Design security-conscious interfaces that protect users without frustrating them. Use when the user asks about MFA, password UX, breach notifications, trust indicators, secure forms, account recovery, or making security feel safe rather than scary.
-
aladicf Skill Security UX 12Design security-conscious interfaces that protect users without frustrating them. Use when the user asks about MFA, password UX, breach notifications, trust indicators, secure forms, account recovery, or making security feel safe rather than scary.
-
aladicf Skill Security UX 13Design security-conscious interfaces that protect users without frustrating them. Use when the user asks about MFA, password UX, breach notifications, trust indicators, secure forms, account recovery, or making security feel safe rather than scary.
-
aladicf Skill Security UX 14Design security-conscious interfaces that protect users without frustrating them. Use when the user asks about MFA, password UX, breach notifications, trust indicators, secure forms, account recovery, or making security feel safe rather than scary.
-
aladicf Skill Security UX 15Design security-conscious interfaces that protect users without frustrating them. Use when the user asks about MFA, password UX, breach notifications, trust indicators, secure forms, account recovery, or making security feel safe rather than scary.
-
bobmatnyc Bundle Security Scanning 2CI security scanning: secrets, deps, SAST, triage, expiring exceptions
71 -
bobmatnyc Bundle Dependency Audit 2Dependency audit and cleanup workflow for maintaining healthy project dependencies. Use for regular maintenance, security updates, and removing unused packages.
71 -
thewatcher01 Bundle Yara Rule Authoring 2Guides authoring of high-quality YARA-X detection rules for malware identification. Use when writing, reviewing, or optimizing YARA rules. Covers naming conventions, string selection, performance optimization, migration from legacy YARA, and false positive reduction. Triggers on: YARA, YARA-X, malware detection, threat hunting, IOC, signature, crx module, dex module.
-
thewatcher01 Bundle Secure Workflow Guide 2Guides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformance/token integration), generates visual security diagrams, helps document security properties for fuzzing/verification, and reviews manual security areas.
-
thewatcher01 Bundle Audit Context Building 2Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.
-
thewatcher01 Bundle Testing Handbook Generator 2Meta-skill that analyzes the Trail of Bits Testing Handbook (appsec.guide) and generates Claude Code skills for security testing tools and techniques. Use when creating new skills based on handbook content.
-
alexei-led Bundle Reviewing Code 2Use when reviewing changed code, PRs, diffs, or specific files. Finds evidence-backed defects in security, correctness, tests, reliability, performance, maintainability, and docs. Supports quick, standard, deep, team, and external-review modes. NOT for repo-wide architecture review, general codebase exploration, fixing issues (use fixing-code), improving tests without a code review (use improving-tests), or applying refactors (use refactoring-code).
-
alexei-led Bundle Configuring Git Hygiene 2Configure safe git workflow hygiene: pre-commit/pre-push hooks, Gitleaks secret scanning, .gitignore rules, local git config, and guardrails. Use when setting up git hooks, gitleaks/git leaks, staged pre-commit checks, pre-push validation, core.hooksPath, .gitignore, or git config best practices. NOT for creating commits (use committing-code), cleaning branches/worktrees (use cleanup-git), or creating worktrees (use using-git-worktrees).
-
blurjp Bundle Fix Review 2Verifies that git commits address security audit findings without introducing bugs. This skill should be used when the user asks to "verify these commits fix the audit findings", "check if TOB-XXX was addressed", "review the fix branch", "validate remediation commits", "did these changes address the security report", "post-audit remediation review", "compare fix commits to audit report", or when reviewing commits against security audit reports.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include mandate-2-1-2-code-static-eval, mandate-2-1-1-code-static-eval, mandate-2-1-3-code-static-eval. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.