Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
florinsenoner Skill Convex Audit 2Audit Convex bandwidth and function call consumption, identify optimizations, and plan fixes
-
amekala Bundle Adspirer Docs 2Answer questions about Adspirer itself — pricing, plans, quota and tool-call limits, what Adspirer can do, connecting an ad account, supported platforms and AI clients, security, and troubleshooting. Uses the official documentation at adspirer.com/docs rather than guessing.
-
frumu-ai Skill Web Starter Audit 2---
-
frumu-ai Skill Security Playbook Builder 2---
-
avav25 Bundle Code Review 2Structured code review with security, performance, and architecture checklists. Use when reviewing pull requests, code changes, or conducting architecture reviews. Provides actionable checklists for consistent review quality.
-
nwave-ai Skill Nw Security By Design 2Security design principles, STRIDE threat modeling, OWASP Top 10 architectural mitigations, and secure patterns. Load when designing systems or reviewing architecture for security.
-
0x0w1 Bundle Conformance Audit 2Use to check whether a repository's history actually followed the jig procedure: conventional squash subjects, Release-Grade trailers on unreleased work, version tag format and placement, the main/develop fast-forward invariant, and a committed rubric. Read-only, exits non-zero on violations, and runs in CI.
-
aws-samples Skill Generate V3 2Generate all security control artifacts and compliant IaC templates from mapping-results.json and validated.json. Split into 3 focused sub-skills for better accuracy; this skill orchestrates them.
-
aws-samples Skill Generate Detective 2Generate detective and responsive security control artifacts — Config rules with Lambda handlers, EventBridge rules, CloudWatch alarms, SSM runbooks, Step Functions workflows, CloudTrail configuration. Reads from mapping-results.json and validated.json.
-
aws-samples Skill Generate Preventive 2Generate preventive and proactive security control artifacts — SCPs, resource policies, KMS key policies, permission boundaries, tag policies, OPA policies, and CloudFormation Guard rules. Reads from mapping-results.json and validated.json.
-
aws-samples Skill Map Generate Controls 2Generate security controls from mitigations x capabilities, organized by Category x Scope matrix. Produces map-controls-generated.json with rich metadata for downstream framework mapping. Consumes validated.json.
-
aws Bundle Bedrock Adoption Readiness 2Amazon Bedrock production readiness assessment covering IAM governance, data retention (ZDR), quota and capacity headroom, and operational observability across Standard Bedrock and Mantle surfaces. Use this skill when a user asks to review Bedrock readiness, assess Bedrock security posture, evaluate quota headroom, check ZDR configuration, validate Bedrock operational setup, or prepare for Bedrock production deployment. Triggers on "Bedrock readiness review", "am I ready for Bedrock production", "Bedrock security assessment", "check my Bedrock quotas", "Bedrock adoption audit", "Bedrock operational review", or "assess my Bedrock environment".
-
az9713 Skill Test All 2Run the complete UI testing suite — all 15 test skills across functional testing and UX design quality. Use when user wants a comprehensive site audit, full test suite, or complete quality assessment.
-
az9713 Skill Test Links 2Test link integrity, navigation, and semantics. Use when user wants to check for broken links, test navigation, verify external links, or audit link behavior.
-
az9713 Skill Test Conversion 2Analyze conversion optimization, cognitive load, and trust signals. Use when user wants to audit conversion funnels, reduce friction, analyze cognitive load, check trust signals, or optimize CTAs.
-
az9713 Skill Test UX Writing 2Analyze micro-copy, CTA text, error messages, and content quality. Use when user wants to audit UX writing, button labels, error messages, form labels, or content clarity.
-
codealive-ai Bundle Skills Management 2Search, find, discover, install, remove, update, review, deduplicate, list, move, optimise, and iterate on skills for AI coding agents. Use when user asks "find a skill for X", "install skill", "remove skill", "update skills", "list skills", "deduplicate skills", "why are two skills shown", "choose the canonical skill", "check for skill conflicts", "review skill quality", "move skill", "check for updates", "optimise skill", "audit skill edits", "trigger test skill", or "transfer skill across agents". Includes duplicate-free installation preflight and SkillOpt-style training loops. Do not use for creating skills from scratch (use /skill-creator instead).
-
codealive-ai Bundle Installing CLI Tools 2Install, upgrade, configure, and verify developer CLI tools safely. Use when a user asks to install a new CLI, command-line app, SDK tool, package-manager binary, GitHub release binary, language runtime tool, or AI/vendor CLI; configure shell PATH/completions; run first login; set API keys, tokens, or env variables for a CLI; migrate an existing CLI install; or troubleshoot a CLI installation while avoiding secret leakage.
-
codealive-ai Bundle Investigating Repository History 2Investigate GitHub repository history before risky code changes using git blame/log, GitHub PRs, review comments, squash/rebase/cherry-pick/rename heuristics, and cited evidence. Use when asking why code exists, whether a change is safe, what PR introduced behavior, or before editing API, compatibility, security, concurrency, persistence, migration, or performance-sensitive code.
-
florinsenoner Skill Convex Security Audit 2Deep security review patterns for authorization logic, data access boundaries, action isolation, rate limiting, and protecting sensitive operations
-
florinsenoner Skill Security Best Practices 2Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
-
kesslerio Bundle Skill Creator 2Create, edit, improve, tidy, review, audit, or restructure AgentSkills and SKILL.md files.
-
kesslerio Bundle Openclaw Secret Scanning Maintainer 2Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.
-
taewook486 Skill Audit 2Run dependency security audit using pip-audit. Use when checking for known vulnerabilities in project dependencies.
-
taewook486 Skill Check 2Check code quality without making changes — lint, format, type, and security checks. Use when you want to inspect issues before fixing them.
-
taewook486 Skill Auto Fix 2Auto-fix lint and formatting issues in Python code using ruff. Use when you want to apply automatic code fixes. Does not fix type errors or security issues.
-
matiascomercio Skill Configure Audit 2configure-audit
-
matiascomercio Skill Harden Supply Chain Sec 2Harden software supply chain security by configuring minimum release age across package managers. Auto-detects active managers or accepts explicit argument.
-
c0x12c Bundle Security Checklist 2Security best practices for Micronaut/Kotlin backend including authentication, authorization, input validation, and OWASP prevention. Use when implementing auth, validating inputs, or reviewing security.
-
kennyolofsson23-netizen Skill Geo Schema 2Schema.org structured data audit and generation optimized for AI discoverability — detect, validate, and generate JSON-LD markup
-
kennyolofsson23-netizen Skill Geo Report PDF 2Generate a professional PDF report from GEO audit data using ReportLab. Creates a polished, client-ready PDF with score gauges, bar charts, platform readiness visualizations, color-coded tables, and prioritized action plans.
-
kennyolofsson23-netizen Skill Ads Audit 2Full multi-platform paid advertising audit with parallel subagent delegation. Analyzes Google Ads, Meta Ads, LinkedIn Ads, TikTok Ads, and Microsoft Ads accounts. Generates health score per platform and aggregate score. Use when user says "audit", "full ad check", "analyze my ads", "account health check", or "PPC audit".
-
kennyolofsson23-netizen Skill Ads Landing 2Landing page quality assessment for paid advertising campaigns. Evaluates message match, page speed, mobile experience, trust signals, form optimization, and conversion rate potential. Use when user says "landing page", "post-click experience", "landing page audit", "conversion rate", or "landing page optimization".
-
kennyolofsson23-netizen Skill Ads Creative 2Cross-platform creative quality audit covering ad copy, video, image, and format diversity across all platforms. Detects creative fatigue, evaluates platform-native compliance, and provides production priorities. Use when user says "creative audit", "ad creative", "creative fatigue", "ad copy", "ad design", or "creative review".
-
kw12121212 Bundle Spec Driven Review 2Review the code quality of a spec-driven change. Checks readability, security, performance, and best practices before archiving.
-
spec-kitty Bundle Spec Kitty Mission Review 2Review a fully merged Spec Kitty mission post-merge (all WPs done/approved) to verify spec→code fidelity, FR coverage, drift, risks, and security. Triggers: "review the merged mission", "post-merge mission review", "verify the completed mission", "audit the mission implementation", "mission-level acceptance review", "is this mission releasable", "final review before tagging", "cross-WP coverage audit". Does NOT handle: per-WP review during implementation (use spec-kitty-runtime-review), implement-review loop orchestration (use spec-kitty-implement-review), setup or repair (use spec-kitty-setup-doctor), or glossary maintenance (use spec-kitty-glossary-context).
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include convex-audit, adspirer-docs, web-starter-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.