Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
conorbronsdon Bundle Ssot Check 3Single-source-of-truth drift auditor for documentation-heavy repos. Use when asked to "check for drift," "find copies of this number," "audit the docs for stale facts," or "set up an SSOT manifest." Finds facts hand-copied across files, builds a manifest of canonical locations, and verifies every copy still matches.
-
daydeda Skill Pdpa Export 2Assemble a consolidated export of ALL data ActiveCAMT holds about a single student (PDPA subject-access request), or guide PDPA erasure — admin-only, always audit-logged, with medical detail gated to admin roles and audit_logs never included/erased. Use for a data-subject access or erasure request for one student.
-
daydeda Skill New Admin Route 2Scaffold a new admin API route (src/app/api/admin/**/route.ts) pre-wired with ActiveCAMT's security pattern — server-side auth() role gate, Zod validation, and a db.transaction that writes an AuditService audit log. Use when adding any admin/staff API endpoint, so the role gate and audit log can't be forgotten. For routes that read medical data, audit logging is made mandatory.
-
perhapsspy Bundle Project Context Migration 2Audit scattered repository docs and notes, then move only the right working context into the `project-context` structure.
-
rodri-oliveira-dev Skill Dotnet Security Review 2Use esta skill para revisar código, dependências, configuração e automação de uma biblioteca .NET sob a ótica de segurança. Combine revisão semântica com analyzers e scanners existentes; não trate esta skill como substituta de CodeQL, Dependency Review, NuGet Audit ou outros gates determinísticos.
-
terryso Bundle Bmad Testarch Nfr 2Audit NFR evidence for performance, security, reliability, and scalability. Use when implementation evidence exists and the user says "audit NFR evidence", "audit NFRs", or "evaluate non-functional requirements"
-
using-system Bundle Backend Configuration 2Own the configured observability backend, in two sections invoked by name. Check: display the configured stack and the instance the runs will hit, prove the CLI connected, guide the user when it is not, and hand the preflight over to the mission. Switch: verify the target backend's CLI is installed (offer a guided install when missing), persist the switch via odd_config_set, persist the per-stack stack_config values the missions will need, then run Check for the proof. Stack-agnostic - the stack list and everything about a given stack come from the observability-cli-guides skill. Use before dispatching an observe, verify or bench mission, when the configured stack must be confirmed or the CLI's connection proven, when the user needs guidance to set their CLI up, and when the user asks to change the configured backend or to persist targeting values. Never installs silently, never authenticates on the user's behalf, never stores or echoes a secret.
-
tanstack Bundle Pr Sweep 2Sweep open (or listed) PRs with up to 100 parallel agents: security-scan outside contributors, rebase onto main when behind (push --force-with-lease), approve pending first-time-contributor CI when relevant, optionally rebase in-house PRs, and report who should review. Supports full, changed-only, behind-only, and conflict-only scopes for cheap daily runs. Use when the user runs /pr-sweep (or /pr-inbound-sweep), or asks to "sweep PRs", "sweep inbound PRs", "security-check outside PRs", "rebase outsider PRs", "rebase our PRs", "approve waiting CI on PRs", "daily PR sweep", or "prep external PRs for review".
-
tuoxie2046 Bundle Nature Response 2Draft, audit, or revise point-by-point reviewer response letters for Nature-family manuscript revisions. Use when the user provides reviewer comments, editor decision letters, revision notes, response drafts, or asks how to respond to major/minor revision requests, rebuttal letters, response to reviewers, peer-review reports, 审稿意见回复, 逐点回复, 修回信, 大修回复, 小修回复, or 如何回复 reviewer.
-
waynesutton Skill Convex Doctor 2Static analysis checklist for Convex backends covering 72 rules across security, performance, correctness, schema, architecture, configuration, and client-side patterns. Use when writing, reviewing, or auditing Convex code. Trigger on mentions of "convex-doctor", "health score", "static analysis", "anti-patterns", "audit convex", or before shipping backend changes.
-
angelcampa1 Bundle Scientific Writing 2Draft, revise, and audit scientific manuscripts or reports with explicit evidence provenance, reporting-guideline coverage, authorship accountability, confidentiality controls, and local consistency checks. Use for manuscript sections, references, declarations, tables, figures, or submission preparation when scientific accuracy and traceability matter.
-
derio-net Bundle Fr Progress 2Plan / spec progress reporting, and the repo-state preflight for any repo with docs/superpowers/ or fr config. Use when: "what's in progress", "status board", "audit drift", "spec rollup", "is this plan up to date", "is this repo fr-managed", "legacy v1 plans", "before archiving or moving files under docs/superpowers/".
-
dinaf2026-web Skill Manuscript Profile Setup 2Sets up (or edits) a book project's editorial profile for the Manuscript Editorial Suite. Every other pass auto-detects this profile from the working folder; this skill is what creates it. Use when there is no profile yet, when a pass reports "no profile found", or when the author says "set up my book", "create a profile", "edit my profile", "change my genre/shelf/comps", "onboard this manuscript", or "configure the editorial suite". It writes `<project>/.manuscript/profile.md` and seeds an empty canon ledger. It does not critique, score, or audit — it only configures.
-
dinaf2026-web Bundle Manuscript Fair Play Audit 2Mystery-mechanics auditor for any mystery, crime, or thriller manuscript. Maps the clues, tests whether the solution is fair and re-readable, tracks plant-and- payoff, judges red herrings, and flags any place a coincidence — not deduction — solves the plot. Use when the author says "is the mystery fair", "clue audit", "does the solution hold up", "check the plot logic", "fair-play check", "did I plant the clues", "is the ending earned", "track plant and payoff", or "would a reader feel cheated". It judges mystery construction only — not prose, canon, or marketability. For non-mystery genres, this pass does not apply.
-
dinaf2026-web Bundle Manuscript Continuity Audit 2Continuity and canon-integrity auditor for any novel, series, or manuscript. Cross-checks a chapter, scene, outline, or full draft against the book's own bible (set in the project profile) plus its internal logic, and produces a defect list — every contradiction of established canon, every drifted detail, every broken series rule, every internal inconsistency. Use when the author says "continuity check", "canon audit", "does this break canon", "check this against the bible", "did I get the details right", "find inconsistencies", or "continuity pass". It only diagnoses continuity — it does not rewrite prose or grade craft/marketability (those are the other passes).
-
dinaf2026-web Skill Manuscript Editorial Router 2Routes a broad or ambiguous editorial request to the right pass(es) in the Manuscript Editorial Suite. Use when the ask spans more than one kind of feedback or it's unclear which is wanted — "review my book", "give me editorial feedback", "is this ready", "go over this chapter", "full editorial pass", "what should I check". Picks among manuscript-publisher-critique, manuscript-continuity-audit, manuscript-fair-play-audit, manuscript-cinematic-scene-audit, manuscript-prose- immersion-audit, and manuscript-listing-critique, runs them in the right order for the book's genre, and hands off. Does not itself critique, score, or rewrite — it only dispatches.
-
dinaf2026-web Bundle Manuscript Publisher Critique 2The publisher's read for any manuscript — an acquisitions verdict plus a developmental craft breakdown, delivered as a scored report card graded against the markers of a great book in its genre (set by the project profile). Use for a single craft/acquisitions read of a scene, chapter, outline, full manuscript, or query: "publisher's read", "acquisitions verdict", "critique this", "score this", "grade this", "editor's letter", "would a publisher take this", "what's weak here", "read this like an editor". For a broad "review my book / full editorial pass" that may need several checks, use manuscript-editorial-router. NOT for canon checking (continuity-audit), mystery-fairness logic (fair-play-audit), line-level immersion (prose-immersion-audit), or blurb/listing copy (listing-critique). Diagnoses and scores; does not rewrite prose.
-
dinaf2026-web Skill Manuscript Cinematic Scene Audit 2Cinematic blocking and scene-population auditor for any narrative manuscript. Reads each scene the way a film director would — tracking every body in the room, every environmental detail a camera would see, all movement and physical continuity, the emotional reactions that would register on an actor's face, and the internal debate a character would voice in voiceover. Use when the author says "cinematic pass", "movie screen audit", "read this like a director", "do we account for everyone in the scene", "blocking pass", "camera test", "who's in the room", "did we forget anyone", "does the movement track", "would I see this on a big screen", "physical continuity check", "where is everyone", or "scene population audit". DISTINCT from prose-immersion-audit (which judges line craft): this audits spatial logic, blocking, full scene population, and cinematic completeness. It diagnoses and flags; it does NOT rewrite prose.
-
dinaf2026-web Bundle Manuscript Prose Immersion Audit 2Line-level prose and scene-immersion auditor for any narrative manuscript — the deep craft pass beneath the publisher's read. Diagnoses scenes for the failures that keep prose at draft level: information dialogue, talking-heads, filter words, furniture-inventory description, missing micro-reactions, weak environmental presence, and emotion stated instead of threaded. Use when the author says "line audit", "prose immersion audit", "prose pass", "diagnose this scene", "is this immersive", "does this read like a draft", "craft pass", or "kill the info-dumping". It diagnoses at the line level — it does NOT rewrite prose, grade marketability, check canon, or judge mystery logic. For rewritten prose, route to the author's writing/voice skill.
-
elizaos Bundle Contribute To Eliza 2Review and prove current elizaOS/eliza pull requests on real working systems, finish existing issues through pull requests, restore develop workflow health, then audit mission-critical security, bugs, stale documentation and comments, and missing end-to-end verification, with optional public payout registration. Use for one material outcome on an existing shipped product path, not generic improvements, trivial cleanup, or unit-test production.
-
elizaos Bundle Review Eliza Contributions 2Independently evaluate an elizaOS/eliza implementation, real-system verification, diagnosis, evidence artifact, or substantive review for quality, security, duplication, provenance, and contribution credit. Use in project CI or maintainer review before accepting work or changing a public reward allocation; reject unit-only or mock-only proof.
-
elizaos Bundle Review Delta Star Contributions 2Independently evaluate a SlopDotCash/proximityprize Delta Star implementation, Lean proof, test, refutation, diagnosis, or evidence artifact for correctness, security, duplication, provenance, and contribution credit. Use in project CI or maintainer review before publishing a Proximity Prize contribution share.
-
extrovert-dot-dev Skill Extrovert Writing Rules 2Read Extrovert writing rules before composing and turn reusable human feedback into governed rules. Use for get_rules, category matching, saving or superseding a preference, promotion, retirement, audit, undo, risk-dial inspection, or proposing graduation without confusing one reviewer's edit with a universal rule.
-
fabioc-aloha Bundle Security Review Skill 2Defend before attackers find the gaps - OWASP, STRIDE, and Microsoft SFI
-
jsmastery-pro Bundle Audit 2Run /audit on a greenfield project, an existing codebase with missing docs, or one area (/audit src/auth) to bootstrap the project's AI context — the AGENTS.md files every later skill reads. Writes tool-agnostic AGENTS.md plus thin CLAUDE.md pointers, adding only what is missing; never overwrites curated content.
-
hector-ha Bundle Skill Cleaner 2Codex/OpenClaw skill audit: live budget, usage, duplicates, compact descriptions.
-
ultroncore Skill Swiftui Performance Audit 2Audit and improve SwiftUI runtime performance from code review and architecture. Use for requests to diagnose slow rendering, janky scrolling, high CPU/memory usage, excessive view updates, or layout thrash in SwiftUI apps, and to provide guidance for user-run Instruments profiling when code review alone is insufficient.
-
florian101010 Skill QA Audit 2Use when performing a quality audit, security review, or robustness check of [FILL: main-source-file]. Covers XSS/innerHTML scanning, rule compliance verification, race condition analysis, config schema validation, and documentation drift detection. Produces a severity-classified report (Critical/High/Medium/Low).
-
fossasia Skill Route Analysis 2Use this skill to analyse, audit, or modify HTTP and WebSocket routes in VoxBento. All routes live in `portal/routers/`.
-
grimoire-rs Bundle Hex Architect 2Tiered architecture-decision orchestrator — evaluates trade-offs and produces ADRs or system designs through discover, research, design, and adversarial-review phases. Use for architecture decisions, ADRs, system design, trade-off analysis between approaches, one-way-door decisions, C4-level design, or NFR evaluation (scalability, availability, latency, security, cost, operability). Tier (low|medium|high|xhigh|max, auto by default) scales research-axis count and selection, whether the design is delegated to an architect worker, and review breadth.
-
ils15 Skill Token Audit 2Audit a repository for token waste — find redundant context files, measure baseline, recommend optimizations
-
masumi-network Skill Citadel Data Boundary 2Use when deciding what Citadel data may be quoted, committed, or shared; when onboarding agents to Masumi Citadel; or when the user asks what is public vs private, what goes in git, or whether vault content can be published. Triggers include "public or private", "what can I share", "citadel security boundary", "is the vault public", and /skills/boundary.
-
meleantonio Skill Replication Checker 3Use when asked to verify reproducibility, audit a replication package, check a clean run, validate run instructions, or review before sharing research code.
-
meleantonio Skill Replication Checker 4Use when asked to verify reproducibility, audit a replication package, check a clean run, validate run instructions, or review before sharing research code.
-
asymmetric-al Skill Supabase Audit Buckets Read 2Attempt to list and read files from storage buckets to verify access controls.
-
automattic Skill Wordpress Creator 2Route WordPress build and audit requests to the right implementation path for a Studio-backed site. Use when the user wants WordPress work and it is not yet clear whether the task should be handled as site creation, theme work, a custom block, a plugin, or an audit.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include ssot-check, pdpa-export, new-admin-route. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.