Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
blurjp Bundle Variant Analysis 2Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing systematic code audits after finding an initial issue.
-
blurjp Bundle Constant Time Analysis 2Detects timing side-channel vulnerabilities in cryptographic code. Use when implementing or reviewing crypto code, encountering division on secrets, secret-dependent branches, or constant-time programming questions in C, C++, Go, Rust, Swift, Java, Kotlin, C#, PHP, JavaScript, TypeScript, Python, or Ruby.
-
fierzone Bundle Laravel Security 2Security standards for hardening Laravel applications.
-
fierzone Bundle Laravel Sessions Middleware 2Expert standards for session drivers, security headers, and middleware logic.
-
sundial-org Bundle Secret Scanner 2Secret Scanner
-
reggiechan74 Skill Audit Trail 2This skill should be used when the user asks to "show audit trail", "why did we make this decision", "what happened after this", "trace this decision", "show decision history", "search audit log", or needs to understand the decision history and rationale behind code changes verified through coherence check.
-
enuno Skill Deep Research 2Research a topic thoroughly in this repo and return a structured summary with file references. Use when you need to understand how something works, find patterns across modules, or audit implementations.
1 -
thebeardedbearsas Skill Security Flutter 3Flutter Security. Use when reviewing security, implementing auth, or hardening code.
-
thebeardedbearsas Skill Security Symfony 2Sécurité & RGPD - Atoll Tourisme. Use when reviewing security, implementing auth, or hardening code.
-
thebeardedbearsas Skill Security Flutter 4Sécurité Flutter. Use when reviewing security, implementing auth, or hardening code.
-
dirien Bundle Security Audit 2Comprehensive security audit covering OWASP Top 10, secrets detection, supply chain security, threat modeling, and language-specific vulnerability patterns. Investigates actual code paths rather than grep-matching keywords. Generates a scored SECURITY_AUDIT.md with prioritized remediation. Use when assessing application security, preparing for a security review, or onboarding to a codebase with security concerns.
-
dirien Bundle Go Nolint Audit 2Audit Go nolint directives for staleness and lazy justifications. Mechanically verifies each suppression with golangci-lint, then runs adversarial Red/Blue/White debates on the top candidates for removal. Use when inheriting a Go codebase, during periodic cleanup, or when nolint count is growing unchecked.
-
dirien Bundle Design Principles 2Audit a codebase against well-known software design principles: SOLID, DRY, YAGNI, KISS, Law of Demeter, Separation of Concerns, Composition over Inheritance, and the code-relevant 12-Factor subset. Scores findings by impact and effort, runs adversarial debate on contested violations, and generates a prioritized DESIGN_AUDIT.md. Use when reviewing code quality beyond what linters catch, assessing design health before a refactor, or onboarding to an unfamiliar codebase. Can be invoked standalone or delegated from tech-debt.
-
jahidulislamseo Skill Semrush Tool 2When the user wants keyword research with search volume, competitive keyword analysis, site audit data, position tracking, or competitor organic analysis. Trigger on "keyword research," "search volume," "keyword difficulty," "what keywords do they rank for," "site audit," "Semrush," or "competitive analysis." Use Semrush for keyword data and competitive intelligence — use Ahrefs for backlink-focused analysis.
-
jahidulislamseo Skill Local Competitor Analysis 2When the user wants to analyze local search competitors, benchmark against map pack rivals, or understand why competitors outrank them. Also use when the user mentions "competitor analysis," "who's outranking me," "competitor GBP," "local competition," or "competitive audit." For geogrid-specific ranking data, see geogrid-analysis. For general map pack strategy, see map-pack-optimization.
-
ligphidonk Bundle Inno Reference Audit 2This skill provides reference guidance for citation verification in academic writing.
-
2233admin Bundle Firmware Pentest 2固件 / IoT 渗透链。从拿到一坨 .bin / .img 开始,闭环走完逆向 → 提取 → 模拟 → 利用。 方法论遵循 OWASP FSTM 九阶段;工具链以 binwalk v3、unblob、EMBA、Firmadyne、AFL++ 为主。 适用场景:路由器/摄像头/智能家居固件审计、固件升级包逆向、IoT CVE 复现、嵌入式 0day 挖掘。 触发关键词:固件、firmware、IoT、binwalk、unblob、UART、JTAG、squashfs、UBI、JFFS2、Firmadyne、QEMU 全系统仿真、EMBA、固件渗透、路由器固件、嵌入式漏洞利用、bootloader、NVRAM、FAT、firmware analysis toolkit。
-
2233admin Bundle Patch Diff Exploit 2N-day 补丁差分到利用。从厂商发布的补丁里反推漏洞点、写 PoC、做成可用的攻击模块。 适用场景:已知 CVE 编号但只有补丁没有 PoC、SRC/红队需要打击未及时更新的资产、N-day 武器化、Patch Tuesday 跟进。 核心方法:拿 before/after 二进制 → 对齐符号 → 二进制 diff → 看新增的安全检查反推 bug class → 写 PoC 触发漏洞。 触发关键词:N-day、Nday、补丁差分、patch diff、patch tuesday、1day、binary diff 漏洞、bindiff 利用、ghidriff、Diaphora、补丁分析、CVE 复现、漏洞还原、补丁反推、N-day 武器化。
-
2233admin Bundle Supply Chain Security 2# Supply Chain Security Testing
-
2233admin Bundle Competition Reverse Pwn 2Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for reverse engineering, malware, DFIR, firmware, pwnable, and native exploit challenges. Use when the user asks to reverse a binary, unpack a sample, inspect a memory dump or PCAP, recover malware behavior, debug a crash, or build or verify an exploit chain under sandbox assumptions. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
-
bradygaster Skill Secret Handling 2Never read .env files or write secrets to .squad/ committed files
-
chuanyue98 Skill Space Xhs Account Audit 2小红书账号整体诊断与竞品对标。对一个或多个小红书账号做量化体检——定位清晰度、内容垂直度、封面统一性、标题钩子率、更新节奏、互动率、爆款率、粉丝转化效率八个维度打分,定位卡点并给出可执行改动。当用户说"账号诊断""帮我看看我的号""我的号没起色/不涨粉/流量下滑""主页体检""账号定位有问题吗""竞品账号分析""对标账号拆解""这个博主为什么能起来""帮我和竞品比一比",或直接贴出小红书主页链接/主页截图要求分析时触发。支持有数据源(GUAIKEI_API_TOKEN / SOCIALDATAX_API_KEY)的量化分析和无数据源的截图定性诊断两条路径。只做分析参谋,不做发布、不刷互动、不批量起号。
-
clawic Skill Code Hygiene Audit 2Audit ClawJS/Clawix code hygiene without editing code, producing categorized findings, baseline status, and validation evidence.
-
clawic Skill Secrets Boundary Review 2Review secret handling, brokered execution, redaction, vault boundaries, host approval, and public hygiene.
-
clawic Skill Constitution Drift Audit 2Audit code, docs, tests, and registries against the Constitution, ADRs, and decision map without making broad repairs. Use when checking whether the repository is drifting away from accepted architecture.
-
jellydn Bundle Security Audit 3Use when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.
-
jellydn Skill Accountable Engineering 2Guides disciplined AI-assisted engineering that avoids cognitive surrender and keeps humans accountable. Use for non-trivial implementation, architecture, security, or operational tasks.
-
managedcode Bundle Codeql 2Use the open-source CodeQL ecosystem for .NET security analysis. Use when a repo needs CodeQL query packs, CLI-based analysis on open source codebases, or GitHub Action setup with explicit licensing caveats. USE FOR: the repo uses or wants CodeQL for .NET security analysis; GitHub code scanning is part of the CI plan. DO NOT USE FOR: teams that need a tool with no private-repo licensing caveat. INVOKES: inspect the repository context, edit targeted files, and run relevant build, test, lint, or validation commands when changes are made.
-
managedcode Bundle Meziantou Analyzer 2Use the open-source free `Meziantou.Analyzer` package for design, usage, security, performance, and style rules in .NET. Use when a repo wants broader analyzer coverage with a single NuGet package. USE FOR: the repo uses or wants Meziantou.Analyzer; the team wants one analyzer pack that covers design, usage, security, performance, and style. DO NOT USE FOR: repos that already enforce an overlapping analyzer baseline and do not want extra diagnostics; formatting-only work. INVOKES: inspect the repository context, edit targeted files, and run relevant build, test, lint, or validation commands when changes are made.
-
managedcode Skill Test Tagging 2Classifies existing tests by standard traits and reports their distribution. MUST USE to tag all tests with category attributes, categorize/tag/label each test, compare happy vs error paths, audit the test mix, describe coverage shape by test type, or tag then verify the project builds. Read bodies when names mislead. Apply canonical attributes; otherwise report only. DO NOT USE for test-quality audits, executed coverage or CRAP, behavioral gaps, writing tests, or migration.
-
managedcode Skill Detect Static Dependencies 2Scan C# source files for hard-to-test static dependencies — DateTime.Now/UtcNow, File.*, Directory.*, Environment.*, HttpClient, Console.*, Process.*, and other untestable statics. Produces a ranked report of static call sites by frequency. USE FOR: find untestable statics, scan for static dependencies, testability audit, identify hard-to-mock code, find DateTime.Now usage, detect static coupling, testability report, static analysis for testability. DO NOT USE FOR: generating wrappers (use generate-testability-wrappers), migrating code (use migrate-static-to-wrapper), general code review, or finding statics that are already behind abstractions.
-
spec-kitty Skill Spec Kitty Program Orchestrate 2Orchestrate a multi-repo, multi-mission Spec Kitty program end-to-end: run specify → plan → tasks → implement → review → merge → mission-review → post-merge fixes across several repositories in a defined dependency order, using background sub-agents for parallel work and a pulse-heartbeat safety net for long uninterrupted runs. Triggers: "ship this program across N repos", "orchestrate a cross-repo release", "run the full mission workflow on repos A/B/C in program order", "drive Decision Moment V1 across all repos", "multi-repo spec-kitty sprint". Does NOT handle: single-mission implement-review loop (use spec-kitty-implement-review), post-merge mission audit (use spec-kitty-mission-review), setup or repair (use spec-kitty-setup-doctor), per-WP review (use spec-kitty-runtime-review).
-
phrazzld Bundle Diagnose 2Investigate, audit, triage, and fix. Systematic debugging, incident lifecycle, domain auditing, and issue logging. Feedback-loop-first protocol: reproduce or replay before root cause, pattern analysis, hypothesis test, and fix. Use for: any bug, test failure, production incident, error spikes, audit, triage, postmortem, "diagnose", "why is this broken", "debug this", "production down", "is production ok", "audit stripe", "log issues". Trigger: /diagnose.
-
phrazzld Bundle Human Writing 2Edit, audit, or rewrite prose so it sounds like a specific human wrote it, not a generic AI draft. Removes AI tells, filler, formulaic structure, fake polish, vague claims, and detector-bait phrasing while preserving truth, voice, and audience fit. Use when: "humanize this", "make this sound less AI", "remove AI slop", "de-slop this", "edit this prose", "make this sound natural", "fix the writing voice", "rewrite this copy". Trigger: /human-writing, /deslop.
-
2233admin Bundle Pwn Chain 2从逆向走到可用利用 (Working Exploit) 的全链路工程化方法。 适用场景:拿到了二进制 + 漏洞点 + 目标环境,需要写出一个能稳定打通的 exploit(不是只能本地复现一下、远程一打就崩的脚本)。 覆盖三大方向:栈溢出 / 堆利用 / 内核 pwn。强调"CTF 本地通 → 真实远程稳定打通"的工程差距:libc 版本错配、堆喷射时序、SMEP/SMAP/KASLR、栈对齐、远程缓冲。 核心工具链:pwntools + GEF/pwndbg + ROPgadget/Ropper + one_gadget + libc-database + qemu-system 内核调试。 触发关键词:pwn、栈溢出、堆溢出、ROP、ret2libc、ret2csu、one_gadget、libc-database、堆利用、tcache、fastbin、unsorted bin、kernel pwn、kROP、SMEP、SMAP、KASLR、modprobe_path、pwntools、GEF、pwndbg。
-
2233admin Bundle API Security 2API 安全测试
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include variant-analysis, constant-time-analysis, Laravel Security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.