Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
awjackson2 Skill Phase Audit 2Use to check the integrity of the phase log and the workflow's git state. Trigger when the user asks to "audit the phases", "check the phase log", "is the phase log healthy", "phase doctor", "validate the phases", "any drift?", or before relying on the log for a release or a recap. Reports drift between plans, logs, the index, design docs, and git (missing logs, broken index links, dangling worktrees, stale design-doc sync, numbering gaps), most-severe first, then offers to fix what's safely fixable via a docs-lane PR. Read-only by default.
-
cnwu16 Bundle Vedic Core 2Run the standard full Vedic/Jyotish natal analysis from a verified structured_data.md: P1-P12 planet audit, divisional-chart cross-checks, house diagnostics, ten life areas, report packaging, and Q&A. Use for 'full Vedic chart analysis', 'complete birth chart reading', 'planet or house audit', 'analyze my life from this chart'; Chinese requests such as '完整分析', '星盘审计', '开始分析', and '生成报告'; Japanese requests such as 'ヴェーダ占星術で総合鑑定して', '出生図を詳しく分析して', and '完全分析して'; and follow-ups about an existing report. / 吠陀占星标准核心分析引擎。
-
matrixorigin Skill Unhappy Path Audit 2Reachability-first unhappy-path audit for changed Astra code paths: dead paths, error propagation, state consistency, resource leaks, hung waits, and unbounded accumulation.
-
motormetrics Skill Code Review 2Perform automated code reviews checking for security vulnerabilities, performance issues, and code quality. Use before creating PRs, when reviewing complex changes, checking for security issues, or identifying performance problems.
-
panaversity Bundle Logistics Brief 2Activate for: logistics, carrier, freight, shipping, route, delivery, on-time delivery, OTD carrier, logistics performance, carrier review, freight cost, cost per kg, lane analysis, route optimisation, logistics brief, carrier scorecard, logistics KPI, shipping performance, freight audit, expedited freight, premium freight, mode of transport, logistics network, carbon emissions, Scope 3 logistics. NOT for: supply network facility placement (use network-design), vendor assessment (use vendor-assessment), spend category analysis (use spend-analysis).
-
panaversity Bundle Vendor Assessment 2Classifies, scores, and evaluates vendors. Activate for: vendor assessment, classify vendor, vendor classification, Kraljic matrix, vendor tier, bottleneck vendor, strategic vendor, vendor review, supplier assessment, vendor onboarding, new vendor approval, vendor audit, annual vendor review, vendor scorecard, supplier evaluation, vendor qualification, approve vendor, vendor due diligence, vendor health check, vendor performance review, bottleneck supplier, vendor exit, risk profile of a vendor. USE THIS when the task is to CLASSIFY a vendor into a category (Strategic / Tactical / Commodity / Bottleneck), SCORE them across dimensions, or EVALUATE a vendor for onboarding/approval/exit. NOT for: ongoing risk signal monitoring or risk alerts (use supplier-risk), invoice reconciliation (use invoice-reconciliation), carrier performance review (use logistics-brief), spend category analysis (use spend-analysis).
-
profpowell Skill Security 2Write secure web pages and applications. Use when handling user input, forms, external resources, authentication, or implementing security headers and CSP.
-
shkarupa-alex Bundle Senior Python 2Apply repository-grounded senior engineering judgment to substantial Python work and bounded Python changes with production or cross-boundary risk. Do not use for trivial syntax questions, generic tutoring, or tasks with no Python artifact unless explicitly invoked. Use for writing, review, diagnosis, design, refactoring, or maintenance where correctness, state, effects, concurrency, compatibility, security, reuse, testing, or long-term ownership materially matters.
-
vechain Bundle Smart Contract Development 2Solidity smart contract development on VeChainThor — Hardhat setup, ERC-20/721 patterns, upgradeable contracts, gas optimization, testing with Thor Solo, security auditing, and ABI codegen.
-
muhammedzohaib Skill Auth Review 2Perform a defensive review of authentication and authorization flows in an authorized codebase. Use for login, session, MFA, OAuth, password reset, cookie security, JWT validation, impersonation, privilege checks, and object-level access control.
-
muhammedzohaib Skill Pr Diff Review 2Review an authorized pull request diff for security regressions. Use when changes modify trust boundaries, auth logic, data-access scope, file handling, logging, headers, or secrets.
-
muhammedzohaib Skill Security Audit 2Conduct authorized defensive security audits of codebases and web applications. Use for broad appsec review across OWASP, authz, business logic, SSRF, XSS, CSRF, injection, file upload, secrets, logging, and tenant isolation. Produces structured findings with severity, confidence, evidence, and safe remediation guidance.
-
skillmedev Skill Series A Readiness 2Audits whether a seed-stage company clears the Series A bar - benchmark metrics, narrative, team, and data room - and produces a red/yellow/green readiness scorecard with a 90-day gap-closing plan. Use when a founder asks "am I ready for Series A", "what metrics do I need to raise an A", "what goes in a Series A data room", "should I raise now or wait two quarters", or is deciding when to open an A process. Do NOT use for a general pre-pitch hygiene check at any stage - use fundraise-readiness-audit instead - or for choosing which round to raise at all - use fundraising-stage-selector instead.
-
thecolliery Skill Doc Leak 2Docs-health audience-safety scan — PROSE-level sensitive content in a doc meant to be public: internal URLs/hostnames/paths, personal data (names, emails, phone numbers in examples or logs), unpublished plans or roadmaps, private figures (pricing, customers), anything whose audience boundary the doc crosses. Catches LEAKED docs. Explicitly NOT a secret scanner: token-shaped secrets (API keys, passwords, private keys) are gitleaks' job — this canary hunts the sensitive PROSE that token scanners and gitignore both miss. Triggers on: "/doc-leak", "doc-leak", "is this safe to publish", "leak check", "anything private in this doc". Semantic, conservative by design: EVERY finding is SUSPECTED — public-vs-private is the human's judgment, never the tool's. Config-gated via `docLeak` (`.coalledger.json`, global + project merge; default on; a private-only project turns it off).
-
amkisko Bundle Claims Audit 2Inventory and verify checkable claims, quotations, dates, statistics, research summaries, causal statements, and citations in docs or prose. Use for factual review, source audits, citation checks, or verification when text relies on external events, scholarship, technical behavior, law, policy, or other verifiable assertions.
-
amkisko Bundle Dependency Audit 2Select, alter, and audit third-party dependencies with advisory scans, target-scoped vulnerability assessments, and deep recon/OSINT. Use when adding, replacing, or removing packages; when asked to audit, review, or harden dependency graphs, lockfiles, or manifests; or when ordinary work surfaces suspicious package behavior, an advisory, a scanner match, or a plausible vulnerability or exploitation signal involving a package. Includes freshness lag (libyears or equivalent).
-
potpie-ai Skill Potpie Project Preferences 2Use before writing, modifying, reviewing, refactoring, or testing code so repo/project preferences surface: error handling, file structure, frameworks, logging, dependency choices, testing, security, API style, and naming. Also use after code work when a reusable project preference should be recorded.
-
seanspiesman Bundle Security Patterns 2Security vulnerability detection patterns including OWASP Top 10, language-specific vulnerabilities, and remediation guidance. Load when reviewing code for security issues, conducting audits, or implementing authentication/authorization.
-
bcanfield Bundle Debt Ops Review 2Audit the tech-debt registry, rank survivors by churn × Fowler quadrant, surface a top-N list, then walk paydown on user follow-up. Use when the user asks to review debt, see what to pay down, work through entries, or check the debt registry. Stale entries drop with "drop A,B,C".
-
miroapp Bundle Miro Code Review 2Use when the user wants to create a visual code review on a Miro board from a pull/merge request (GitHub, GitLab, or any forge), local uncommitted changes, or a branch comparison — produces a file-changes table, summary/architecture/security docs, and architecture diagrams, then links them back from the PR/MR.
-
buzzbysolcex Skill Wallet Guard 2Transaction governance layer for crypto wallet operations. 3-state evaluation: BLOCK / WARN / ALLOW with receipt. Schema-frozen with AION (Aldo/CODÉ). Checks token score, deployer identity, liquidity depth, and contract security before any wallet interaction proceeds.
-
agentscope-ai Skill Dingtalk Channel Connect 2使用可视浏览器自动完成 QwenPaw 的钉钉频道接入。适用于用户提到钉钉、DingTalk、开发者后台、Client ID、Client Secret、机器人、Stream 模式、绑定或配置 channel 的场景;支持遇到登录页时暂停,等待用户登录后继续。
-
wtthornton Bundle Security Review 2Run security review workflow. Uses security, data-privacy-compliance; invokes @reviewer *review (security) and @ops *audit-security.
-
sc30gsw Skill Nodejs Best Practices 2Node.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.
-
amkisko Bundle Operational Signal Intake 2Triage live service evidence from alerts, error groups, monitors, traces, profiles, metrics, logs, probes, deployment changes, and user reports. Use to establish observed impact, test reliability and security hypotheses such as resource exhaustion or abuse, correlate the minimum useful evidence, record confidence and gaps, and route confirmed work. Do not use to install telemetry, redesign monitoring, conduct a full engineering or vulnerability audit, or mutate production.
-
antgroup Bundle Secureclaw 2Security hardening toolkit for OpenClaw. Run audits, apply fixes, scan skills, monitor costs and memory integrity.
-
arenukvern Bundle Mixture Of Experts 2Run a Mixture of Experts (MoE) audit on any topic, plan, codebase, evidence archive, or process. Dynamically spawns specialized subagents with different critical lenses to cross-reference findings and detect flaws, overlap, retention issues, or drift. Use when designing architectures, analyzing complex code, verifying multi-step plans, classifying evidence artifacts, or looking for duplicated intent in a repo.
-
commercetools Skill Security Auditor 2Perform comprehensive security audit of a repository with detailed findings and step-by-step PoCs. Use when assessing a repo's security posture or investigating potential vulnerabilities.
-
drn Skill Hera Review 2Default, user-overridable code review methodology — the review CONTRACT (what to analyze, how to tag findings) that a broad finder follows when spawned inside a hera-spawn-review panel, or that runs standalone via /hera-review for a single-pass review outside a panel. Encodes ralph-review's review contract (behavior / delta / plan / regression / security / test-coverage audits, the canonical finding tags) without ralph's loop control, auto-fix execution, or OpenSpec-drift resolution flow — those stay with hera-spawn-review (the panel synthesizer + fix loop) or with the invoking user when this runs standalone. Named in a diligence profile's [panel] as review_skill = "hera-review" (the shipped default); a project overrides it freely with its own review_skill or review_instruction — swapping it never requires touching hera-spawn-review.
-
kynetic-ai Skill Audit 2Comprehensive codebase audit for release readiness. Parallel exploration of docs, code, config, tests, and specs to identify cruft, then interactive triage with clear action options.
-
huydepzai121 Skill Repomix 2Guide for using Repomix - a powerful tool that packs entire repositories into single, AI-friendly files. Use when packaging codebases for AI analysis, generating context for LLMs, creating codebase snapshots, analyzing third-party libraries, or preparing repositories for security audits.
-
shinpr-claude-code-workflows Skill Recipe Review 2Reviews completed implementation for governing-source compliance, scope economy, repository quality, and security, then applies user-approved corrections.
-
talont-org Skill Audit Bugs 2Analyze historical bug patterns by mining Claude Code project logs for /investigate skill invocations since a specified date. Identifies recurring root causes, architectural gaps, and proactive detection strategies. Use when user says "audit bugs", "bug patterns", "analyze investigations", or "bug audit".
-
talont-org Skill Audit Defense Standards 2Audit the codebase against defense standards derived from historical bug patterns. Standards accumulate over time as new patterns are discovered via audit-bugs and design-guards. Use when user says "audit defenses", "audit defense standards", "check defenses", or "defense audit".
-
modiqo Bundle Clarity Trust 2Stage 4 of the stranger test — audit the trust layer. Proof proximity (evidence adjacent to the claim it supports), specificity over adjectives, credibility signals, and risk reversal at the moment of doubt. Scored 0-10.
-
modiqo Bundle Clarity Pricing 2Stage 5 of the stranger test — audit the pricing page against the behavioral-economics literature (anchoring, decoy/compromise effects, loss aversion, mental accounting, pain of paying) and the catalog of SaaS pricing failures. Distinguishes ethical architecture from dark-pattern manipulation. Scored 0-10.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include phase-audit, vedic-core, unhappy-path-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.