Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
genfeedai Bundle Competitor Analyzer 2Audit competitors' content strategy across platforms, formats, topics, engagement patterns, and content gaps. Triggers on competitor content audits, social/content gap analysis, posting analysis, and competitive content reports.
-
hk-hub Skill Writing Guidelines 2Review docs/prose for Writing Guidelines compliance. Use when asked to "review my docs", "check writing style", "audit prose", "review docs voice and tone", or "check this page against the writing handbook".
-
fndlalit Bundle Security Testing 2Test for security vulnerabilities using OWASP principles. Use when conducting security audits, testing auth, or implementing security practices.
-
fndlalit Bundle N8n Security Testing 2Credential exposure detection, OAuth flow validation, API key management testing, and data sanitization verification for n8n workflows. Use when validating n8n workflow security.
-
okhp3 Bundle Audit Integrity 2Shared audit integrity framework for all AppSec agents — enforces output quality, intellectual honesty, and continuous improvement through anti-rationalization guards, self-critique loops, retry protocols, non-negotiable behaviors, self-reflection quality gates (1-10 scoring, ≥8 threshold), and a self-learning system with lesson/memory governance for security analysis agents.
-
okhp3 Bundle Data Breach Blast Radius 2Pre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges sourced verbatim from GDPR Art. 83, CCPA § 1798.155(a), and HIPAA 45 CFR § 160.404. Cost benchmarks from IBM Cost of a Data Breach Report (annually updated). All citations in references/SOURCES.md for verification. Use when asked: "assess breach impact", "what data could be exposed", "calculate blast radius", "data exposure analysis", "how bad would a breach be", "quantify data risk", "sensitive data inventory", "data flow security audit", "pre-breach assessment", "worst-case breach scenario", "breach readiness", "data risk report", "/data-breach-blast-radius". For any stack handling user data, health records, or financial information. Output labels law-sourced figures (exact) vs heuristic estimates (planning only). Does not replace legal counsel.
-
k1lgor Skill Skill Stocktake 2Quality audit and library maintenance for the skill system. Use quarterly or when the skill library feels bloated or stale. Produces a Keep/Improve/Update/Retire/Merge verdict for every skill with self-contained reasons and actionable next steps. Covers inventory listing, quality evaluation against rubric, verdict assignment, and action list generation for non-Keep verdicts.
-
k1lgor Skill Security Reviewer 2Comprehensive security audits and vulnerability checks covering OWASP Top 10 (2025), CWE mappings, threat modeling, supply chain security, and code-level vulnerability detection. Use for security-related tasks: authentication review, input validation, data protection, dependency auditing, and security architecture review. Covers automated secret scanning, dependency auditing, threat modeling with STRIDE, and exploit chain analysis.
-
k1lgor Skill Requesting Code Review 2Structured review flow with pre-review checklists, review templates, and PR size discipline. Use when your code is ready for review and you need to prepare a thorough, reviewable PR. Differentiator: Mandatory self-review checklist completion before requesting, enforced PR size limit (400 lines), and categorized review prompts (logic/architecture/security/performance/testing).
-
oleg-koval Skill Dependabot Triage 3Triage all open Dependabot and Renovate PRs in bulk: classify each by risk tier (patch / minor / major / security), auto-approve and merge safe patch-only bumps, flag breaking major upgrades with a summary of what changed, and post a digest of what was done. Use when dependency PRs are piling up, when the user says "deal with Dependabot", "triage dependency updates", or "merge the safe ones", or at the start of a maintenance window.
-
oleg-koval Skill Skill Budget Audit 3Diagnose and fix Claude Code's skill context budget overflow, identify heavy plugin bundles that exceed the 2% budget, remove domain-specific ones, deactivate rarely-used skill sets, and validate the warning clears. Use when Claude Code shows "Exceeded skills context budget" or skill descriptions are stripped.
-
snowflake-labs Bundle Review Skill Sflabs 2Use when a contributor has built a Cortex Code skill locally and wants a pre-PR readiness check before opening a pull request against Snowflake-Labs/cortex-code-skills. Verdict: promote, adapt, or skip — with concrete fixes. Triggers: "review a skill", "is this skill ready for labs", "check this skill before PR", "audit skill for promotion", "does this skill belong in labs".
-
mulesoft Skill Manage Portal Applications 2Manage the applications that hold API credentials inside an API Experience Hub portal. Use when a portal consumer needs to list their applications, check if a name is available, create a new application, update metadata, rotate the client secret, or delete an application they no longer use.
-
mulesoft Skill Apply Policy To API Instance 2Apply a policy to an existing API Manager instance. Use when the user wants to add a policy, enforce security, configure rate limiting, apply OAuth2, set up IP allowlisting, or protect an API with any policy template from the catalog.
-
backbay-labs Skill Thrunt Audit Evidence 2Cross-phase audit of all outstanding Evidence Review and findings validation items
-
backbay-labs Skill Thrunt Validate Phase 2Retroactively audit and fill Nyquist validation gaps for a completed phase
-
backbay-labs Skill Thrunt Audit Milestone 2Audit milestone completion against original intent before archiving
-
backbay-labs Skill Thrunt Plan Milestone Gaps 2Create phases to close all gaps identified by milestone audit
-
yigitkonur Bundle Audit UX Laws 2Use if building or auditing UI against the 30 Laws of UX (Fitts, Hick, Gestalt, cognitive load).
-
yigitkonur Bundle Audit Completion 2Use if verifying claimed-done work or auditing session/plan/branch completion with evidence.
-
yigitkonur Bundle Audit UI And Save Files 2Use if auditing a running web app UI across pages/viewports, saving per-bug findings to a tree.
-
yigitkonur Bundle Audit UX And Save Files 2Use if auditing a running app's usability via persona journeys, saving per-issue findings to a tree.
-
yigitkonur Bundle Audit Skill By Derailment 2Use if hardening a SKILL.md by running a fresh subagent on a real task and fixing where it snags.
-
udecode Skill Autoclosure 2Autonomously close the current Plate work tree through source sync, proof, review, checks, GitHub delivery, and final audit without expanding product scope.
-
udecode Skill Sync Shadcn 2Autogoal-backed planning, status, review, dashboard, apply, and tracking for upstream shadcn docs syncs into Plate docs. Use when the user asks for `sync-shadcn`, `sync-shadcn status`, `sync-shadcn review`, `sync-shadcn dashboard`, `sync-shadcn apply`, a scoped `sync-shadcn <feature>` lane, to sync shadcn docs, audit newer shadcn docs changes, compare `../shadcn/apps/v4` with `apps/www`, update the shadcn sync baseline, or decide what to adopt, fork, defer, or exclude from upstream shadcn.
-
dtsong Skill Motion Design 2Use when designing the motion language for a feature or system. Covers transition specs, micro-interaction definitions, choreography principles, performance constraints, and reduced-motion alternatives. Do not use for visual design critique (use visual-audit) or design token architecture (use design-system-architecture).
-
dtsong Skill E2e Testing 2Use when designing end-to-end test suites, visual regression testing, or cross-browser test strategies. Covers Playwright/Cypress test architecture, page object patterns, test data management, visual snapshot comparison, cross-browser matrix, and CI integration. Do not use for unit/integration test strategy (use testing-strategy) or code pattern audit (use pattern-analysis).
-
dtsong Skill Caching Strategy 2Use when designing or auditing a caching architecture. Covers multi-layer cache hierarchy, key schema, TTL policies, invalidation flows, and warming strategies. Do not use for runtime performance profiling (use performance-audit) or capacity planning (use load-modeling).
-
dtsong Skill Performance Audit 2Use when profiling application performance or diagnosing slow page loads. Covers full-stack bottleneck identification including Core Web Vitals, bundle analysis, database queries, and network waterfall. Do not use for cache architecture design (use caching-strategy) or capacity planning (use load-modeling).
-
dtsong Skill Microarch Analysis 2Use when analyzing microarchitectural attack surfaces by mapping shared hardware structures, identifying speculative execution vectors, quantifying speculative windows, and proposing countermeasures. Covers cache timing, transient execution, and contention channels. Do not use for RTL-level design review (use rtl-security-review) or physical implementation analysis (use physical-design-security).
-
dtsong Skill Protocol Design 2Use when selecting and designing communication protocol stacks for IoT or embedded systems. Covers physical layer selection, transport and application protocols, security layers, message format design, and error resilience. Do not use for firmware architecture (use embedded-architecture) or fleet-scale operations (use fleet-management).
-
dtsong Skill Rtl Security Review 2Use when reviewing RTL designs for security vulnerabilities including access control gate bypasses, insecure FSM transitions, timing-dependent information leakage, and unintended data paths. Covers Verilog, SystemVerilog, and VHDL modules with security-critical functions. Do not use for physical implementation review (use physical-design-security) or microarchitectural attack analysis (use microarch-analysis).
-
dtsong Skill Platform Audit 2Use when auditing a feature or implementation against platform-specific guidelines such as iOS HIG, Material Design 3, and WCAG. Covers compliance scoring, violation identification, remediation steps, and App Store risk assessment. Do not use for navigation architecture (use navigation-design) or hardware API integration (use device-integration).
-
dtsong Skill Compliance Review 2Use when reviewing proposed features and data flows against GDPR, CCPA, HIPAA, and other privacy regulations. Covers regulatory applicability, PII data flow mapping, consent mechanism assessment, retention policies, and right-to-deletion compliance. Do not use for data sensitivity tiering (use data-classification) or audit logging design (use audit-trail-design).
-
dtsong Skill Audit Trail Design 2Use when designing audit logging systems for accountability and compliance evidence. Covers event catalogs, log schemas, retention policies, immutability requirements, and compliance reporting. Do not use for regulatory gap analysis (use compliance-review) or data sensitivity classification (use data-classification).
-
dtsong Skill Navigation Design 2Use when designing navigation architecture for mobile or cross-platform features including screen hierarchy, deep linking schemes, and state preservation strategies. Covers stack navigation, modal flows, universal links, and process death recovery. Do not use for platform guideline compliance (use platform-audit) or hardware API integration (use device-integration).
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include competitor-analyzer, writing-guidelines, security-testing. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.