Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
dmccreary Bundle Diagram Reports Generator 2Generates a status report of all diagrams and MicroSims across an intelligent textbook's chapters, including difficulty, Bloom's level, and UI complexity. Use to audit visualization coverage before a content review.
-
legioncodeinc Bundle Lovable Audit Stinger 2Audit Lovable-built Supabase apps: RLS denials, role-differential reads, function gating, auth posture, bundle-forensics key/endpoint extraction, findings triage, reporting.
-
legioncodeinc Bundle Money Leak Auditor 2Audit SaaS and vendor spend from Littlebird screen capture. Trigger on subscription audit, where is my money going, cancel unused tools, find zombie subscriptions, failed payments, SaaS spend review, cut software costs, what am I paying for. Reconstructs a receipted vendor ledger from captured billing notices, receipts, dashboards and card alerts, proves which paid tools have not been opened in 90 days, traces failed-payment cascades back to one root cause, and produces a cancel, downgrade, consolidate and renegotiate action pack with cancellation emails drafted and held for approval.
-
x-cmd Skill Cve 3Look up CVE records via x cve — cached, zero-API-key, daily xz TSV. Load for cve, vulnerability id, kev, epss, nvd, cvelist, or security advisory.
-
zauberzeug Bundle Audit Deck 4Hunt for one previously-undocumented defect, doc drift, missing test, or inconsistency; file it via Skill(create-card). AUTO-INVOKE on "find me a bug", "audit X", "check for inconsistencies", or /audit-deck. Inconsistencies are the primary lead.
-
zauberzeug Bundle Audit Deck 5Hunt for one previously-undocumented defect, doc drift, missing test, or inconsistency; file it via Skill(create-card). AUTO-INVOKE on "find me a bug", "audit X", "check for inconsistencies", or /audit-deck. Inconsistencies are the primary lead.
-
get-convex Skill Sec Check 4Security review checklist for Convex functions, auth logic, public queries, admin routes, webhooks, uploads, and AI-generated code. Use when reviewing code that touches user data, PII, or access control.
-
get-convex Skill Convex Doctor 2Run convex-doctor static analysis, interpret findings, and fix issues across security, performance, correctness, schema, and architecture categories. Use when running convex-doctor, fixing convex-doctor warnings or errors, improving the convex-doctor score, or when asked about Convex code quality, static analysis, or linting Convex functions.
-
get-convex Bundle Convex Performance Audit 2Audits Convex performance for reads, subscriptions, write contention, and function limits. Use for slow features, insights findings, OCC conflicts, or read amplification.
-
get-convex Bundle Convex Return Validators 2Guide for when to use and when not to use return validators in Convex functions. Use this skill whenever the user is writing Convex queries, mutations, or actions and needs guidance on return value validation. Also trigger when the user asks about Convex type safety, runtime validation, AI-generated Convex code, Convex AI rules, Convex security best practices, or when they're debugging return type issues in Convex functions. Trigger this skill when users mention "validators", "returns", "return type", or "exact types" in the context of Convex development. Also trigger when writing or reviewing Convex AI rules or prompts that instruct LLMs how to write Convex code.
-
involvex Skill Audit 2Deep EVM smart contract security audit system. Use when asked to audit a contract, find vulnerabilities, review code for security issues, or file security issues on a GitHub repo. Covers 500+ non-obvious checklist items across 19 domains via parallel sub-agents. Different from the security skill (which teaches defensive coding) — this is for systematically auditing contracts you didn't write.
-
involvex Bundle Ethskills 4Ethereum development knowledge for AI agents — from idea to deployed dApp. Fetch real-time docs on gas costs, Solidity patterns, Scaffold-ETH 2, Layer 2s, DeFi composability, security, testing, and production deployment. Use when: (1) building any Ethereum or EVM dApp, (2) writing or reviewing Solidity contracts, (3) deploying to mainnet or L2s, (4) the user asks about gas, tokens, wallets, or smart contracts, (5) any web3/blockchain/onchain development task. NOT for: trading, price checking, or portfolio management — use a trading skill for those.
-
kesslernity Bundle Ciso Reviewer 2Reviews a proposal, business case, deck or plan in character as a Chief Information Security Officer archetype, producing a DRAFT review document with a verdict, findings cited to specific passages, security and compliance risks, and the five interrogation questions a real CISO would ask. Use when the user asks for a CISO review, a security or compliance pressure-test of a document, or help preparing for an executive review where security, privacy or third-party risk will be challenged.
-
atilamedeiros Bundle Pci Compliance 2Implement PCI DSS compliance requirements for secure handling of payment card data and payment systems. Use when securing payment processing, achieving PCI compliance, or implementing payment card security measures.
-
atilamedeiros Bundle Code Review Checklist 2Comprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability
-
atilamedeiros Bundle Production Code Audit 2Autonomously deep-scan entire codebase line-by-line, understand architecture and patterns, then systematically transform it to production-grade, corporate-level professional quality with optimizations
-
atilamedeiros Bundle API Security Best Practices 2Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities
-
lev-os Skill Dsr 2Doodlestein Self-Releaser - fallback release infrastructure for when GitHub Actions is throttled. Local builds, cross-platform releases, supply chain security. Use when: GH Actions slow, local release, build hosts, dsr command.
-
lev-os Bundle Osint 2Structured OSINT investigations — people lookup, company intel, investment due diligence, entity/threat intel, domain recon, organization research using public sources with ethical authorization framework. USE WHEN OSINT, due diligence, background check, research person, company intel, investigate, company lookup, domain lookup, entity lookup, organization lookup, threat intel, discover OSINT sources.
-
lev-os Skill Pr Review 2[WHAT] Unified PR review combining code quality, tests, and security [HOW] Routes by PR scope: quick (<200 LOC) -> standard (200-800) -> deep (>800 or security-sensitive) [WHEN] PR reviews, code audits, architecture validation
-
lev-os Skill Geo Report 2Generate a professional, client-facing GEO report combining all audit results into a single deliverable with scores, findings, and prioritized actions
-
lev-os Skill Openclaw Config 2Manage OpenClaw bot configuration - channels, agents, security, and autopilot settings
-
lev-os Skill Geo Platform Optimizer 2Platform-specific AI search optimization — audit and optimize for Google AI Overviews, ChatGPT, Perplexity, Gemini, and Bing Copilot individually
-
lev-os Bundle Security Best Practices 2Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
-
duclm1x1 Skill Hopeids 2hopeIDS Security Skill
-
oleg494 Bundle Fable Method 2A step-by-step problem-solving loop (classify the ask, define done, gather evidence, decide, act surgically, verify by observation, report outcome-first). Use when the user says "/fable-method", "use the fable method", or "approach this like Fable", or proactively when starting any multi-step task that no task-specific skill covers. Subcommands - plan (stop after the plan), audit (grade finished work against the loop), report (rewrite an answer outcome-first).
-
zinohome Bundle Deskclaw Security Vuln Check 2DeskClaw advisory self-checks for litellm via scripts/check_deskclaw_litellm.py (gateway-venv then every distinct python on PATH; reports version and flags 1.82.7/1.82.8) or equivalent shell snippets in SKILL.md. Use when users ask for 安全漏洞检查, litellm checks, or post-upgrade hygiene audit.
-
mikaru0mystic Bundle Analyzing Dns Logs For Exfiltration 2Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection in SIEM platforms. Use when SOC teams need to identify DNS-based threats that bypass traditional network security controls.
-
mikaru0mystic Bundle Analyzing Windows Amcache Artifacts 2Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations. Uses Eric Zimmerman's AmcacheParser and Timeline Explorer for artifact extraction, SHA-1 hash correlation with threat intel, and timeline reconstruction. Activates for requests involving Amcache forensics, program execution evidence, Windows artifact analysis, or application compatibility cache investigation.
-
mikaru0mystic Bundle Reverse Engineering IOS App With Frida 2Reverse engineers iOS applications using Frida dynamic instrumentation to understand internal logic, extract encryption keys, bypass security controls, and discover hidden functionality without source code access. Use when performing authorized iOS penetration testing, analyzing proprietary protocols, understanding obfuscated logic, or extracting runtime secrets from iOS binaries. Activates for requests involving iOS reverse engineering, Frida iOS hooking, Objective-C/Swift method tracing, or iOS binary analysis.
-
oleg494 Bundle Security And Hardening 2Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when personal data or privacy compliance (GDPR, CCPA) is involved.
-
khaledsaeed18 Skill Secret Scan 2Scan code or a diff for hardcoded secrets (API keys, tokens, passwords, private keys, and other exposed credentials) before they get committed or shipped. Use before committing, during review, or when auditing a repository.
-
khaledsaeed18 Skill Owasp Security 2Review code being written or modified against the OWASP Top 10:2025 and ASVS secure-coding requirements, catching vulnerability classes before they ship. Works in any language or stack. Use when writing authentication or authorization logic, handling user input, adding API endpoints, choosing cryptographic operations, processing file uploads, or making any change that touches a trust boundary. Complements secret-scan (which finds credentials) and dependency-audit (which checks packages) with line-level vulnerability review.
-
khaledsaeed18 Skill Dependency Audit 2Audit a project's dependencies for outdated and vulnerable packages and surface breaking-change notes for upgrades. Works with any ecosystem, including npm/pnpm/yarn, pip/Poetry/uv, Cargo, Go modules, Maven/Gradle, Bundler, Composer, and others. Use when checking a project's dependency health, planning upgrades, or responding to a vulnerability report.
-
khaledsaeed18 Skill Adversarial Reviewer 2Review code through three hostile personas - the Saboteur, the New Hire, and the Security Auditor - each required to find at least one issue. Use when a standard review feels too comfortable, when code is going into a critical path, when a previous review missed bugs that later surfaced, or when you want coverage across correctness, clarity, and security in a single pass.
-
augments-labs Bundle Post Mortem 2Use after a production escape, late defect, data loss, outage, security incident, or badly failed work cycle, once the technical cause and containment are known and the open question is why the safeguards missed it or why the impact grew. Fires on how did this reach production, why didn't we catch this, and what do we change so it doesn't happen again, even if nobody says post-mortem. Skip while the technical cause is still unknown, and skip ordinary bugs.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include diagram-reports-generator, lovable-audit-stinger, money-leak-auditor. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.