Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
haomingz Skill Worktree Status 2Audit all git worktrees in the current project. Use when the user asks about worktree status, which branches are merged, which have uncommitted changes, or which worktrees can be safely cleaned up.
-
kreek Bundle Security 2Use when auth, secrets, crypto, trust boundaries, dependency risk, or untrusted input are at stake.
-
light0305 Bundle Light Memory Pm 2Light 项目运行时记忆与项目管理常驻技能:把"项目做到哪/定了啥/出到哪版/术语怎么统一/上次断哪" 落到每个项目自己的 .light/ 目录(项目卡 + 决策日志 + 版本史 + 受控术语表 + 跨会话交接卡), 复用 passport.py 引擎管 DAG 台账(不重造)。它是 consistency 事实源的归属方,定义一改即变更广播 回扫所有材料;是总控"会话开头自动汇报上次断哪"的记忆底座。何时用:长期/跨会话项目、需记住背景/进展/ 版本/决策、会话开头续跑或接手、重要进展后立即落账、上下文将尽要交接、改术语/指标/创新点定义后。 触发词:记忆 / 项目管理 / 项目卡 / 决策日志 / 版本史 / 版本记录 / 续跑 / 接手 / 上次断哪 / 下一步 / 交接 / handoff / 启动提示词 / 术语表 / 变更广播 / 归档 / 台账 / .light / passport / 跨会话。 核心纪律:记忆落 .light/ 显式文件(非向量检索);相对日期转绝对;外部可变事实带 [snapshot]; 自洽用 pm.py audit 出 exit code(不口头说"记过了");不可逆决策(归档/教训回写)停下问用户。
-
light0305 Bundle Light Typesetting 2Build and preflight submission-ready LaTeX/PDF artifacts for Light stage 11. Use when receiving a paper-writing manuscript, figure delivery, citation delivery.json/references.bib/citekey-audit.json, or a venue/template profile; when selecting pdfLaTeX/XeLaTeX/LuaLaTeX and BibTeX/Biber; when diagnosing LaTeX errors or unresolved references; when checking page limits, double-blind identity, PDF metadata, template, page box, embedded fonts, TODOs, figures, tables, labels and citations; or when producing a reproducible compile manifest, PDF, compliance report, failure bundle and venue-matching handoff. Distinguishes PASS, manuscript ERROR, toolchain UNAVAILABLE and convergence UNRESOLVED without redoing citation authenticity or figure scientific QA.
-
light0305 Bundle Light Project Structure 2Audit, plan, scaffold, and safely migrate research project structures across greenfield, existing Git/non-Git repositories, and monorepo subroots. Use for project folders, repository cleanup, source inventory, move maps, naming and storage policy, Python/R/mixed/LaTeX profiles, template provenance, conflict review, applied-move evidence, or rollback. Existing projects are read-only until the user authorizes exact action IDs bound to a plan digest. Preserve uncommitted and untracked work, symlinks, submodules, and memory-pm's .light content. This is an off-DAG local tool: do not emit findings or invent a STAGE_GATES/ROUTES connection.
-
ramp-public Bundle Ramp Spend Audit 2Review Ramp spend for possible duplicate software, fragmented vendor payments, unused funds, oversized limits, and recurring-spend controls. Use when a customer asks for a spend audit, savings opportunities, or safer recurring spending. This skill identifies opportunities; it does not cancel subscriptions or change vendor-side payment settings.
-
eryajf Bundle Github Actions Efficiency 2Audit GitHub Actions workflow efficiency and recommend fixes to reduce CI minutes and costs.
0 -
eryajf Bundle Github Codespaces Efficiency 2Audit and improve GitHub Codespaces efficiency. Use this skill when a user wants faster Codespaces startup, lower Codespaces spend, slim devcontainers, right-size machines, tune idle timeout, or scope prebuilds to branches with sustained usage.
0 -
aravinds-wick Skill Network 101 2Configure and test common network services (HTTP, HTTPS, SNMP, SMB) for penetration testing lab environments. Enable hands-on practice with service enumeration, log analysis, and security testing against properly configured target systems.
-
arcadeai Skill Quality Review 4Deep review of any work-product — code, docs, specs, plans, decisions — grounded in current authoritative sources. Use when double-checking against latest docs, verifying versions or claims, checking security, or pressure-testing correctness and elegance before something ships. Complements the automatic quality hook with ecosystem verification. NOT for divergent ideation (brainstorm), weighing still-open options (figure-it-out), your own spec's framing (self-review), or scenario review (review-spec).
-
axross Bundle Zod Schema 2Modelling data with Zod and enforcing validation where untrusted data enters — the schema layer, from one parse at the boundary to the type every caller downstream reads. Triggers on `z.object`, `z.infer`, `safeParse`, `z.codec`, `z.coerce`, `z.brand`, `z.discriminatedUnion`, `.refine`, `.transform`, `zodResolver`, `z.toJSONSchema`, `ZodError`, a schema module, or an unvalidated `fetch` or `JSON.parse` result. For whether an input is untrusted at all, use an application-security capability; for where the parse hook lives, the framework's own. Covers codecs, coercion traps, and what a passing parse still does not make safe.
-
axross Bundle Code Review 2Reviewing a code change — a pull request, a branch or commit-range diff, or a post-implementation self-review of your own work before calling it done. The methodology for judging whether a change already written is safe to merge, and for reporting why. Not for writing the change, only for judging one that already exists. Covers the reviewer-mode reset, diff scoping, a four-tier severity scale with fixed floors, file-line evidence with fix snippets, escalation for high-risk changes, and lenses for correctness, maintainability, security, testing, and performance. Self-contained, so it works installed on its own.
-
axross Bundle Application Security 2Writing or reviewing code that handles untrusted input, secrets, outbound requests, rendered content, or third-party dependencies — the OWASP Top 10:2025 lens in two modes, writing secure-by-default code and judging the risk a change introduces. Triggers on "is this safe", "secure by default", "harden", "security", "secret", "privacy", "PII", "XSS", "injection", "SSRF", "safe fetch", "access control", or a dependency review. Covers secrets and environment variables, input validation, output encoding, SSRF, access control and data exposure, and supply-chain risk.
-
laiye-adp Bundle Agentic Doc Parse And Extract 2Enables AI-powered parsing and key information extraction from high-frequency documents including invoices, orders, receipts, long texts, and common Chinese identity & credential documents. Supports reusable custom templates for non-standard business files. Features batch concurrent processing and human-in-the-loop review with customizable audit rules to automate document workflows for finance, administration, HR data entry and other departments.
-
kbarbel640-del Bundle Crawsecure 2Offline security analysis skill that helps detect unsafe patterns in ClawHub skills before installation.
1 -
doriangallo Bundle Codebase Cleanup Deps Audit 2You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
1 -
doriangallo Bundle Dependency Management Deps Audit 2You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
1 -
bouclem Skill Exp Mock Usage Analysis 2Audits .NET test mock usage by tracing each mock setup through the production code's execution path to find dead, unreachable, redundant, or replaceable mocks. Use when the user asks to audit mock usage, find unused or unnecessary mock setups, check if mocks are needed, reduce mock duplication or over-mocking, simplify test setup, or review whether mock configurations like ILogger/IOptions should use real implementations instead. Supports Moq, NSubstitute, and FakeItEasy.
7 -
bouclem Skill Detect Static Dependencies 2Scan C# source files for hard-to-test static dependencies — DateTime.Now/UtcNow, File.*, Directory.*, Environment.*, HttpClient, Console.*, Process.*, and other untestable statics. Produces a ranked report of static call sites by frequency. USE FOR: find untestable statics, scan for static dependencies, testability audit, identify hard-to-mock code, find DateTime.Now usage, detect static coupling, testability report, static analysis for testability. DO NOT USE FOR: generating wrappers (use generate-testability-wrappers), migrating code (use migrate-static-to-wrapper), general code review, or finding statics that are already behind abstractions.
7 -
majiayu000 Bundle Auth Security 2OAuth 2.1 + JWT authentication security best practices. Use when implementing auth, API authorization, token management. Follows RFC 9700 (2025).
567 -
majiayu000 Bundle Vscode Doctor 2Diagnose slow or freezing VS Code-compatible editors with evidence-first, zero-hardcoded-assumption workflow. Use when the user reports editor lag, typing delay, UI freezes, extension host stalls, file watcher noise, high editor CPU/RSS, uses VS Code/Cursor as a file browser over a large folder, or wants a safe editor performance audit.
567 -
majiayu000 Bundle Server Security 2服务器安全审计与加固。扫描 SSH、防火墙、端口暴露、文件权限、暴力破解等安全问题,生成报告并提供一键修复。当用户说服务器安全、安全审计、安全检查、安全加固时使用
567 -
majiayu000 Bundle App User Story QA 2End-to-end app feature inventory and user-story testing workflow with a canonical tracker. Use when the user asks to audit every feature, derive expected behavior from code, test user journeys, or explicitly fix and retest documented UX or logistical defects.
567 -
majiayu000 Bundle Skill Ecosystem Doctor 2Audit and safely repair cross-runtime Skill governance: canonical-source ownership, divergent or duplicate projections, exposure scopes and budgets, lifecycle drift, quarantine, and retirement. Use when the user explicitly requests cross-runtime or cross-scope Skill governance; ignore project-local Skill inventory, product/runtime loading or enablement checks, usage statistics, and mentions/traces.
567 -
majiayu000 Bundle Structured Logging Lite 2Design, audit, or implement application structured logging architecture from repository evidence. Use when a user asks whether or where to add logs, how to choose or migrate a logger, how to standardize events/fields/levels/redaction, how to add HTTP access or panic logs, or why production logs cannot answer an incident question. Do not use merely to tail platform logs or to design a full metrics, tracing, SLO, and incident-management program.
567 -
vtex Skill Payment Pci Security 2Apply when handling credit card data, implementing secureProxyUrl flows, or working with payment security and proxy code. Covers PCI DSS compliance, Secure Proxy card tokenization, sensitive data handling rules, X-PROVIDER-Forward-To header usage, custom token creation, and the constraint that Secure Proxy applies only to card authorization (not post-auth operations like cancel, capture, or refund). Use for any payment connector that processes credit, debit, or co-branded card payments to prevent data breaches and PCI violations.
-
vtex Skill Masterdata Storage Strategy 2Apply when deciding whether VTEX Master Data is the right storage for a given workload, designing JSON Schemas with v-indexed, v-cache, v-security, and v-triggers, planning entity capacity and lifecycle, or auditing existing Master Data usage. Covers when to use MD versus Catalog, OMS, VBase, or external databases, schema design best practices, indexing strategy, trigger patterns, and operational considerations. Use before creating any new Master Data entity.
-
vtex Skill Vtex Io Security Boundaries 2Apply when reviewing or designing security-sensitive boundaries in VTEX IO apps. Covers public versus private exposure, trust assumptions at route and integration boundaries, sensitive data handling, validating what crosses the app boundary, and avoiding leakage across accounts, workspaces, users, or integrations. Use for route hardening, data exposure review, or evaluating whether a service boundary is too permissive.
-
vtex Skill Architecture Well Architected Commerce 2Apply when scoping, reviewing, or documenting cross-cutting VTEX commerce architecture across storefront, IO, headless, marketplace, payments, or any other VTEX module. Grounds work in the Well-Architected Commerce framework—Technical Foundation (reliability, trust, integrity; security, infrastructure, compliance), Future-proof (innovation, simplicity, efficiency; scalable and adaptable solutions), and Operational Excellence (accuracy, accountability, data-driven improvement; process and customer experience). Routes implementation detail to product tracks (IO caching and paths, Master Data strategy, marketplace integrations). Use for solution design, architecture reviews, and RFP-level technical structure.
-
compozy Skill Writing Agents Md 2Create, audit, shorten, or scope AGENTS.md and CLAUDE.md instructions. Use writing-skills for on-demand skills; excludes human-facing documentation and READMEs.
-
compozy Bundle Refactoring Analysis 2Audit code quality and architectural health or plan refactoring using Fowler code smells and techniques; write prioritized findings to docs/_refacs/. Excludes formatting, performance, and security audits.
-
compozy Bundle Architectural Analysis 2Audit architecture, dead code, duplication, type confusion, and code smells across a codebase. Excludes formatting, performance profiling, security audits, and feature-level reviews.
-
dnyoussef Bundle When Auditing Code Style Use Style Audit 2When Auditing Code Style Use Style Audit
-
dnyoussef Bundle When Validating Code Works Use Functionality Audit 2When Validating Code Works Use Functionality Audit
-
elzawarudo Bundle Krt Docs Chronicler 2Maintain durable project knowledge without creating documentation sprawl. Use when a user asks to update docs after a feature, incident, release, review, or architecture decision; reconcile stale README/runbook/ADR/changelog content; capture lessons learned; write lightweight ADRs; audit documentation drift; or decide where a new piece of project knowledge belongs. Runtime aliases may expose this as krt:docs-chronicler.
-
elzawarudo Bundle Krt Bicentennial Writer 2Writing and editing guidance for natural, specific, contextual prose that avoids generic patterns associated with AI-generated writing. Use when the user asks to draft, rewrite, humanize, naturalize, polish, localize, or audit text so it sounds less formulaic; when working on theses, academic articles, research documents, academic reasoning, critical argument, or AI-assisted authorship; or when they mention "sounds like AI," "AI detector," "humanize text," "natural writing," "human tone," "AI writing tells," "Bicentennial Writer," "suena a IA," "detector de IA," "humanizar texto," "redacción natural," or "tono humano," or want to avoid typical AI-writing patterns in Spanish or English. Runtime aliases may expose this as krt:bicentennial-writer.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include worktree-status, security, light-memory-pm. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.