Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
cwijayasundara Skill Review 2Run evaluator and security reviewer concurrently for comprehensive quality gate.
-
dav-niu474 Skill Skill Vetter 2Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
-
dzhng Skill Review 2Closeout pass on a finished substantive change — sequence refactor-clean (shape), code-review (diff), and write-docs (docs) so all three run, in the order where each feeds the next. Use after implementing a slice or feature and before calling it done or committing; when the user asks for a final review, a cleanup-and-document pass, or to "review everything." For a diff-only audit, reach code-review directly.
-
equinor Skill Paperlab Book Release Orchestration 2Define the PaperLab whole-book release workflow: audit order, blocker rules, render commands, artifact freshness checks, and release gate reporting.
-
equinor Skill Paperlab Scientific Traceability Audit 2Audit PaperLab books for claim, figure, equation, notebook, citation, and unit traceability. Use when a book must become scientifically defensible and reproducible, especially for NeqSim-backed quantitative chapters.
-
ferroxlabs Skill Ijfw Memory Audit 2Audit and clean project memory files. Trigger: 'memory audit', 'clean memory', 'memory health', /memory-audit
37 -
ferroxlabs Skill Ijfw Plan Check 3Donahoe Loop audit gate before execution. Trigger: 'audit plan', 'check plan', 'review plan', 'plan audit', 'plan check', 'before we build', 'before execution', 'validate the plan', 'is this plan solid', 'plan review'. Owns pre-execution audit intent -- fires before any foreign plan-checker.
37 -
fabioc-aloha Skill Security And Hardening 2Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. OWASP-aware, language-agnostic principles with TypeScript examples — applies to any feature that accepts untrusted data, manages user sessions, or interacts with third-party services.
-
florianbruniaux Skill Performance 2Optimize web performance for faster loading and better user experience. Use when asked to "speed up my site", "optimize performance", "reduce load time", "fix slow loading", "improve page speed", or "performance audit".
-
florianbruniaux Skill Best Practices 2Apply modern web development best practices for security, compatibility, and code quality. Use when asked to "apply best practices", "security audit", "modernize code", "code quality review", or "check for vulnerabilities".
-
florianbruniaux Skill Security Guardian 2Expert en sécurité applicative pour détecter les vulnérabilités, auditer le code, et guider les bonnes pratiques de sécurité. OWASP Top 10, authentification, autorisation, cryptographie, gestion de secrets. Utiliser pour audits sécurité, reviews de code sensible, conception de features sécurisées, ou résolution de failles.
-
githubmofo Bundle Torusguard 3TorusGuard Master Security Engine & Command Router
-
githubmofo Skill Torusguard Verify 2Verify finding evidence sufficiency, audit live code line matches, and calibrate 0–100 confidence scores.
-
githubmofo Skill Torusguard Web Validate 2Execute authorized HTTP probing against local/staging web applications — session capture, transparent audit headers, and secret redaction.
-
githubmofo Skill Torusguard Exploit Check 2Safe, non-destructive confirmation of exploitability using inert canary tokens and sentinels.
-
howells Skill Audit 2Comprehensive codebase audit with verification and specialized reviewers. Generates actionable reports. Use when asked to "audit the codebase", "review code quality", "check for issues", "security review", or "performance audit". By default, run the complete audit: mechanical checks first, then specialist reviewers, then a scored report.
-
nutstore Bundle Cw Code Review Expert 2Conduct a rigorous, evidence-based code review for a change set, pull request, diff, or selected files. Use when users ask to review code, assess a PR, find bugs/security/performance risks, validate a refactor, or request a second engineering opinion. Inspect scope before details, load targeted checklists progressively, prioritize only actionable findings as P0-P3, and report before making any code changes.
-
op0ai Skill Convex Helpers Patterns 2Guide for convex-helpers library patterns including Triggers, Row-Level Security (RLS), Relationship helpers, Custom Functions, Rate Limiting, and Workpool. Use when implementing automatic side effects, access control, relationship traversal, auth wrappers, or concurrency management. Activates for triggers setup, RLS implementation, custom function wrappers, or convex-helpers integration tasks.
-
profsynapse Bundle Pact Testing Strategies 2Testing strategies, test pyramid guidance, and quality assurance patterns for PACT Test phase. Use when: designing test suites, implementing unit tests, integration tests, E2E tests, performance testing, security testing, or determining test coverage priorities. Triggers on: test design, unit testing, integration testing, E2E testing, test coverage, test pyramid, mocking, fixtures, performance testing, test phase.
-
timdevai Bundle Dependency Auditor 2Audit and manage dependencies across multi-language projects. Identifies vulnerabilities, license conflicts, transitive dependency risks, and safe-upgrade paths. Use when auditing third-party packages before release, investigating a CVE, planning a major version bump, or running a license-compliance review.
-
wenyuchiou Bundle Paper Memory Builder 2Convert a paper draft + figures + Zotero metadata into reusable .paper/claims.yml and .paper/figures.yml files so the academic-writing-skills skill can do writing, revision, and audit passes without re-reading the manuscript every time. Use when the user asks to "build paper memory", "extract claims from this manuscript", "extract claims, supporting evidence, and figure key numbers", or "prepare this paper for AI-assisted writing". NOT for summarizing cited papers in a literature cluster — that's `paper-summarize`. This skill is for the user's own manuscript draft only.
-
wenyuchiou Bundle Zotero Library Curator 2Audit and curate a Zotero library — find duplicate DOIs, orphan items missing required tags, propose collection rebinds, identify bloated or under-used collections, generate tag hygiene reports, emit preview-only cleanup plans. Use when the user asks to "audit Zotero", "find duplicates", "tag hygiene report", "which collections are bloated or under-used", or "propose a Zotero cleanup plan". Defers all CRUD operations to the standalone `zotero-skills` skill or `research-hub zotero` CLI. Includes a backup-first reminder before any apply/CRUD handoff suggestion.
-
yorgai Skill Architecture Audit 2Systematic architecture audit and refactoring methodology for Rust + TypeScript codebases. Use when performing refactoring, cleanup, unification, code review, dead code removal, module reorganization, or tech debt elimination. Ensures no naming confusion, semantic overloading, hidden defaults, duplicate logic, or architectural inconsistencies are missed.
-
tankimgwan Bundle Linmas Incident Triage Lead 2Incident triage skill for security-event classification, containment planning, evidence preservation, and response coordination.
-
tankimgwan Bundle Linmas Secure Code Reviewer 2Secure code review skill for application risk analysis, threat modeling, scanner tuning, and developer-focused remediation guidance.
-
tankimgwan Bundle Linmas Security Operations Lead 2Security operations skill for monitoring, escalation readiness, operational hardening, and day-to-day defensive workflows.
-
tankimgwan Bundle Linmas Controls Compliance Reviewer 2Controls and compliance review skill for evidence review, control mapping, audit preparation, and framework gap analysis.
-
tankimgwan Bundle Linmas Exploit Validation Specialist 2Exploit validation skill for authorized environments, attack-surface review, and bounded proof-of-impact workflows.
-
tenwalk Bundle Ieee Experiments 2Design and audit IEEE communications simulation and numerical-results sections for JSAC, TWC, TCOM, WCL, and CL. Covers benchmark schemes, Monte-Carlo protocol, BER/SER/outage/rate/EE metrics, SNR/antenna/user sweeps, analysis-vs-simulation validation, convergence and complexity, learning-based evaluation, ISAC rate-CRB/detection tradeoffs, robustness, and empirical/ray-tracing/testbed evidence. Use for planning or checking results: benchmark selection, simulation setup, Monte-Carlo validation, neural-network evaluation, CRB/ISAC tradeoffs, fairness boundaries, or reviewer-risk audits.
-
awarexone Skill Web3 Start Here 2Master index for the web3 smart contract security knowledge base. Use this to navigate the skill chain. Read files in order — each ends with NEXT.
-
awarexone Skill Web3 Poc Foundry 2Complete Foundry PoC writing guide + all cheatcodes + DeFiHackLabs reproduction patterns. Use this when building a proof of concept exploit, setting up a fork test, using Foundry cheatcodes, or reproducing a known DeFi hack for learning.
-
awarexone Skill Web3 Hunt Zksync Era 2ZKsync Era (Immunefi) completed hunt — 0 findings after exhaustive 5-session audit. Use as a DEFENSE STUDY — learn what makes a protocol unhuntable, which patterns block all 10 bug classes, and when to abandon a target. Contains architecture breakdown, 25 tested attack vectors, and pre-dive scoring refinements for large L1 bridge protocols.
-
canonical Bundle Documentation Review 2Performs comprehensive documentation review including build validation, Diataxis analysis, structure audit, accuracy verification, and style compliance. Use when reviewing documentation changes or auditing documentation quality.
-
pachca Skill Pachca Security 2Pachca — журнал безопасности: отслеживание входов, действий пользователей, изменений сообщений и нарушений DLP. Требуется тариф «Корпорация». Используй этот скилл, когда пользователь хочет посмотреть события безопасности, журнал аудита, историю входов, подозрительную активность, узнать кто что делал, экспортировать логи безопасности или отслеживать нарушения DLP. НЕ для отправки сообщений или управления сотрудниками. Use when: журнал безопасности, аудит, события безопасности, кто заходил, история входов, подозрительная активность, DLP, экспорт логов, токены API. NOT for: отправить сообщение, управление сотрудниками.
-
speakeasy-api Bundle Manage Openapi Overlays 2Use when creating, applying, or validating overlay files including x-speakeasy extensions. Covers overlay syntax, JSONPath targeting, retries, pagination, naming, grouping, open enums, global headers, custom security. Triggers on "create overlay", "apply overlay", "overlay file", "x-speakeasy", "add extension", "configure retries", "add pagination", "overlay for retries".
-
starforall Bundle Workflow Audit 2Use when auditing whether the repo-local workflow rooted at `docs/workflows/新项目开发工作流/` has same-version maintenance issues in workflow assets, install/embed flows, CLI-native adaptation, or post-install verification boundaries, including a user-approved patch-only stable version mismatch in the current run; do not use for ordinary business code, application features, or generic implementation review, and use `workflow-capability-audit` instead for broader Trellis version-drift or upgrade-compatibility audits.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include review, skill-vetter, review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.