Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
trycompai Skill Audit Hooks 2Audit & fix hooks and API usage patterns — eliminate server actions, raw fetch, and stale patterns
-
trycompai Skill Audit Tests 2Audit & fix unit tests for permission-gated components
-
uzysjung Bundle Audit Harness Fit 2Audits the resident steering layer — CLAUDE.md/AGENTS.md and its `@import` chain, `.claude/rules/`, hooks, permission rules, and the skill descriptors preloaded every session — against the published authoring checklist. INVENTORY measures what loads; EVIDENCE gathers block logs and correction history; VERDICT maps each section to the documented include categories and exclude list, then rules keep / rewrite / relocate / delete; RELOCATE moves procedures to skills, must-hold guarantees to hooks and permission rules, derivable facts back to code; APPLY proposes and waits for approval. Use when the user says any of "하네스 정리", "룰·훅이 밥값을 하는지", "CLAUDE.md 다이어트", "상주 컨텍스트 정리", "룰이 너무 많아", "훅이 실제로 뭘 막고 있는지" — or "harness audit", "trim my CLAUDE.md", "are my rules earning their keep", "prune the steering layer", "why does Claude ignore my rules". Do NOT use it after a specific defect recurred (that is recurrence-prevention), or for drift between the product's docs and its code (that is audit-service-gaps DRIFT).
-
uzysjung Bundle Audit Service Gaps 2Audits the observable gaps between a service as it is today and an explicit target state, then researches how reference services actually solved each high-ranked gap before proposing a fix. DETECT scans through three independent lenses — north-star alignment, correctness (bugs), and user-perspective (UX) — and enumerates concrete, severity-ranked gaps; BENCHMARK verifies how a reference service closes each one and PROPOSES a differentiated close. VERIFY, CHANGE-IMPACT, DRIFT and FULL extend the same loop to post-fix closure, baseline changes, doc-vs-code drift, and the whole-service sweep. Use when the user says any of: "북극성 기준으로 부족한 점", "갭분석", "다른 벤치마크 서비스는 이 부분을 어떻게 해결했는지", "레퍼런스 서비스랑 비교해서 부족한 점 찾아줘" — or the English "gap analysis", "benchmark against reference services", "audit this service". Do NOT use it to *define* product direction (that is north-star), to review ONE standalone artifact's prose (that is multi-persona-review), or to turn an unverified benchmark claim into a fact.
-
uzysjung Bundle Multi Persona Review 2A panel-review skill that critiques ONE artifact (launch post, README, doc, markdown, plan, design) via 3-5 disjoint user-perspective personas running in parallel, then synthesizes deduped, severity-ranked improvement points (P0/P1/P2). Use when the user says "작성글을 사용자 관점의 페르소나를 여러명 만들어서 (손넷 모델정도로) 피드백 받아바", "다면 리뷰 해볼까", "페르소나로 리뷰", "여러 관점으로 피드백", or in English "multi-persona review", "review this from different user perspectives", "get persona feedback on this post/README/doc", "panel review this artifact". Lighter than a full service audit — point it at ONE artifact, not a whole codebase. Do NOT use it for a whole-service or whole-codebase audit, nor for a gap-vs-benchmark loop (both are audit-service-gaps), and do NOT simulate diversity by renaming reviewers that inspect the same evidence.
-
uzysjung Bundle Recurrence Prevention 2When the same defect, mistake, or incident happens AGAIN — a recurrence, not a one-off — verify it against prior evidence (memory, rule case tables, git/CHANGELOG history), classify it as a simple slip vs a complex harness problem, then escalate the countermeasure one level up the ladder: record (1st) → forced rule with a case table (2nd) → structural gate — test, hook, or derive — once prose has failed (3rd+). Complex problems get countermeasure candidates designed by a multi-persona panel instead of a quick patch. Use for "재발했어", "같은 실수 또 했네", "이거 저번에도 그랬잖아", "재발방지 대책 등록해줘", "재발방지 룰 만들어", "this happened again", "same bug as last time", "add a recurrence countermeasure", "postmortem this failure". Do NOT use it for a first-time defect (fix it, record it, stop), do NOT create a standing rule from an unverified first occurrence, and do NOT use it as a general audit of the steering layer at rest.
-
filippolmt Bundle Web Perf 2Audit, diagnose, or optimize website loading and interaction performance, Core Web Vitals, and Lighthouse performance scores.
-
filippolmt Bundle Wordpress Pro 2Develops custom WordPress themes and plugins, creates and registers Gutenberg blocks and block patterns, configures WooCommerce stores, implements WordPress REST API endpoints, applies security hardening (nonces, sanitization, escaping, capability checks), and optimizes performance through caching and query tuning. Use when building WordPress themes, writing plugins, customizing Gutenberg blocks, extending WooCommerce, working with ACF, using the WordPress REST API, applying hooks and filters, or improving WordPress performance and security.
-
idaibin Bundle Dev Java 2Use when Java source or Java-owned Maven/Gradle configuration must be implemented, migrated, or refactored across Spring services, HTTP/security boundaries, explicit code-first or contract-first OpenAPI, persistence, transactions, messaging, scheduling, caches, tests, or configuration; owns source edits and validation, not non-Java JVM work, audit-only, fixed-basis review, or Git delivery.
-
idaibin Bundle Dev Rust 2Use when a Rust source change must be implemented, ported, or refactored across APIs, crates, services, CLIs, async, persistence, unsafe or FFI boundaries, tests, or docs; owns source edits and validation, not audit-only, review-only, or Git-delivery work.
-
idaibin Bundle Audit Java 2Use when a known Java source surface or Java-owned Spring/build configuration needs a scoped, read-only audit of selected architecture, API/security, transaction, persistence, concurrency, integration, performance, or migration risks; not for non-Java JVM semantics, and use repo-review when a Worktree or immutable change basis needs coordination.
-
idaibin Bundle Audit Rust 2Use when a Rust workspace or known Rust surface needs a scoped, read-only audit of selected architecture, ownership, error, concurrency, performance, persistence, or unsafe-boundary risks; use repo-review when a Worktree or immutable change basis needs coordination.
-
idaibin Bundle Repo Review 2Use when Worktree changes or a fixed snapshot/range need coordinated read-only Standards and Spec findings, documentation-authority review, completed provider-evidence integration, or selected-source visual-completion review; use audit-* for bounded domain audits and a host security workflow for security-only review.
-
juanca202 Bundle Arch Audit 2Auditar el cumplimiento de los estándares de arquitectura (docs/standards/) y de las reglas de AGENTS.md contra el estado real del repositorio (Architecture Compliance Checking), citando el ADR de origen de cada estándar, y generar un informe priorizado en docs/audits/arch-audit-YYYY-MM-DD.md. Audita una raíz de arquitectura por corrida (repo principal o submódulo), con sus estándares, fitness functions e informe. Activar siempre que el usuario quiera verificar, auditar o comprobar si el código respeta los estándares, decisiones arquitectónicas o reglas del proyecto, aunque no diga "estándar", "ADR" o "auditoría". Frases: "audita el cumplimiento", "¿el código respeta los estándares/ADR?", "verifica que seguimos las reglas de AGENTS.md", "compliance de arquitectura", "arch-audit", "/arch-audit". Usar también ante sospecha de desvío de lo documentado, para un informe de brechas con acciones.
-
metagalaxy-crystal Skill Dingtalk Channel Connect 2使用可视浏览器自动完成 CoPaw 的钉钉频道接入。适用于用户提到钉钉、DingTalk、开发者后台、Client ID、Client Secret、机器人、Stream 模式、绑定或配置 channel 的场景;支持遇到登录页时暂停,等待用户登录后继续。
-
duyet Skill Security Hardening 2RBAC configuration, row policies, quotas, network security, audit logging, and access control best practices.
-
armelhbobdad Bundle Skf Audit Skill 2Drift detection between skill and current source code. Use when the user requests to "audit a skill" or "audit skill" for drift.
-
velt-js Bundle Velt Proxy Server Best Practices 2Velt proxy server setup and configuration best practices for routing Velt SDK traffic through your own reverse proxy (nginx or Cloudflare Workers). Use when configuring proxyConfig on VeltProvider or initVelt, setting up nginx or Cloudflare Workers as a reverse proxy for Velt CDN/API/database/storage/auth endpoints, whitelisting Content Security Policy (CSP) domains for Velt, enabling Subresource Integrity (SRI), or debugging proxy-related connectivity issues. Triggers on any task involving Velt proxy, reverse proxy, proxyConfig, cdnHost, apiHost, v1DbHost, v2DbHost, storageHost, authHost, forceLongPolling, CSP whitelisting for Velt, nginx or Cloudflare Workers configuration for Velt, or network policy compliance with Velt — even if the user doesn't explicitly say 'proxy'.
-
dills122 Skill Security Specialist 2Auditing for unsafe code and secrets.
-
hive-intel Bundle Hive Security Risk 2Use this skill before the user signs, approves, swaps, connects a wallet to a dApp, or touches an unknown contract, URL, or transaction payload — any "should I sign/approve/ape/connect" moment, even when the user only implies the transaction. Runs token, address, approval, phishing, and simulation risk checks and reports severity, evidence, and remediation instead of guessing. For research-style "is this token worth a look" questions use hive-token-diligence.
-
hive-intel Bundle Hive Token Diligence 2Use this skill whenever the user asks whether a specific token is real, legit, liquid, well-held, enriched, investable, or worth researching — "is this token a scam", "run diligence on 0x…", "who holds this", "does it have real liquidity" — even if they never say "diligence". Investigates metadata, market context, holders, DEX liquidity, enrichment, and risk signals for an exact chain and contract. For pre-transaction risk checks (approvals, signing, swap simulation) use hive-security-risk; for pool-level depth and trade flow use hive-dex-pool-analysis; for Solana mints use hive-solana-analysis.
-
hive-intel Bundle Hive Wallet Investigation 2Use this skill whenever the user wants to look inside a wallet or address — portfolio, holdings, balances, transfers, PnL, NFT exposure, DeFi positions, whale moves, "what does this address hold", "trace this wallet's activity" — even if they just paste an address. Requires wallet address and chain before executing Hive wallet tools. For Solana wallets use hive-solana-analysis; for "is this address malicious" risk checks use hive-security-risk.
-
hybridlabor-api Skill Tdmcp Quality Audit 2Run or maintain the full tdmcp repo quality-audit team: command sweeps, all package/Makefile/CI gates, security review, usability/flow review, refactor/test-gap analysis, coverage hardening, QA, and follow-up fix waves. Use whenever the user asks for a complete audit, improve repo/code quality, test all commands, find security/usability failures, refactor debt, add missing tests, re-run the audit, continue a previous quality wave, or verify the repo is ready.
-
involvex Bundle Firebase Firestore Standard 2Comprehensive guide for Firestore Standard Edition, including provisioning, security rules, and SDK usage. Use this skill when the user needs help setting up Firestore, writing security rules, or using the Firestore SDK in their application.
-
aospbooks Bundle Aosp Security 2AOSP Part IX — Security. Use when reasoning about SELinux on Android, Keystore/Keymint, Trusty TEE, gatekeeper/weaver, Android Verified Boot, dm-verity, hardware-backed attestation, Credential Manager (CredentialManagerService, credential providers, passkeys/FIDO2, password and autofill integration, digital credentials), or DRM (MediaDrm framework, Widevine L1/L2/L3, OEMCrypto, license acquisition, secure decoder/display path), or the LFI in-process sandbox (Lightweight Fault Isolation for untrusted code such as software codecs). Chapters 40–42, 68.
-
koinod Skill Workflow Auditor 2Audit your business workflows and find automation opportunities
-
metagit-ai Skill Metagit Release Audit 2Mandatory before calling work complete when the session changed repo files. Runs format, lint, tests, integration tests, context-aware pip-audit/bandit, and optional gitleaks via task qa:prepush. Use before push, release, or hand-off.
-
mkurman Skill Label Quality Audit 2Audit label quality using confident learning (Northcutt et al.), cross-validation noise detection, and per-class error analysis. Identifies mislabeled examples for review.
-
openshift Skill Test Rule 2Run Automatus tests for a security rule
-
openshift Skill Create Rule 2Create a new security rule with all required components
-
openshift Skill Onboard Control 2Onboard a new security policy as a control file. Parse the document, create control file structure, and map existing rules to requirements.
-
randalschwartz Skill Update Docs Workflow 2Review the current Jaspr docs, audit source code doc comments, edit the source code, and run the generator script to verify docs updates.
-
code-yeongyu Skill Security Research 2Security Research - Team Mode Vulnerability Audit
-
conorbronsdon Skill Avoid AI Writing 2Audit and rewrite content to remove AI writing patterns ("AI-isms"). Use this skill when asked to "remove AI-isms," "clean up AI writing," "edit writing for AI patterns," "audit writing for AI tells," or "make this sound less like AI." Pairs with writing-voice for full voice alignment.
-
equinor Bundle Fusion Package Scribe 2Systematically improves TSDoc and README documentation across packages in a TypeScript monorepo. Discovers public API surfaces, generates or improves TSDoc on all exports, rewrites READMEs to a consistent retrieval-friendly structure, and commits each package independently. USE FOR: monorepo-wide documentation passes, single-package doc improvements, TSDoc generation on public exports, README standardization, review council quality checks. DO NOT USE FOR: runtime code changes, security scanning, API reference site generation, non-TypeScript languages.
-
equinor Bundle Fusion Dependency Review 2Review dependency PRs with structured research, existing-PR-discussion capture, multi-lens analysis (security, code quality, impact), and a repeatable verdict template. USE FOR: dependency update PRs, Renovate/Dependabot PRs, library upgrade reviews, "review this dependency PR", "should we merge this update". DO NOT USE FOR: feature PRs, application code reviews, dependency automation/bot configuration, or unattended merge without confirmation.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include audit-hooks, audit-tests, audit-harness-fit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.