Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
modiqo Bundle Clarity Promise 2Stage 1 of the stranger test — audit message match and information scent. Does the page confirm, within one glance, the promise that brought the visitor here? Scored 0-10; a mismatch with the primary entry path is a journey gate.
-
modiqo Bundle Clarity Narrative 2Stage 3 of the stranger test — the heart of the audit. Walk the page section by section carrying the question the visitor is holding at that moment; any section that answers no pending question is an exit ramp. Sequential by nature — never run in parallel. Scored 0-10.
-
nibzard Bundle Git Xray 2Run diagnostic git commands to assess a codebase's health before reading any code. Use this skill whenever the user asks you to understand a new codebase, audit a repo, assess technical debt, find risky code, check project health, figure out where to start reading, identify bus factor risks, or explore an unfamiliar repository. Also use it when the user asks 'what's going on in this repo', 'where are the problem areas', 'give me a health check', or 'what should I look at first'. If the user wants to understand a codebase at a strategic level before diving into code, this is the skill to use.
-
fivetran Skill Evaluate Connector 3Evaluate a Fivetran connector for correctness, SDK compliance, security, and reliability. Use when the user wants a code review or quality report before deploying.
-
frenxt Skill E2e Review 2Use when running periodic E2E test reviews, after UI changes, before releases, or when the user wants to audit test coverage and visual correctness. Works with Playwright, Cypress, Jest E2E, or any test framework.
-
hamr0 Skill Security 2Security audit — recurring six, injection, auth, trust boundaries
-
horizonrobotics Skill Code Reviewer 2Reviews code for bugs, logic errors, security vulnerabilities, code quality issues, and adherence to project conventions, using confidence-based filtering to report only high-priority issues that truly matter.
-
dig1t Bundle Luau Best Practices 2Use when writing, reviewing, or refactoring Luau code for Roblox - modules, services, controllers, error handling (pcall), memory leaks and connection cleanup, server-authoritative security, input validation, naming conventions, or project organization. Triggers include "best practices", "clean code", "code review", "refactor", "memory leak", "server authority".
-
aviz85 Skill Reality Check 2Deep code audit that detects misleading patterns — fake tests, mock abuse, shallow health checks, overly optimistic error handling, hidden debt. Produces a structured report with findings AND actionable recommendations. Use when code looks green but smells wrong.
-
yonatangross Bundle Ork Review Pr 2Review a pull request or branch for correctness, regressions, security, operational risk, and missing evidence. Use when a request asks to review a PR, review a diff, find real bugs, assess merge risk, or provide evidence-backed review findings. Do not use for implementation or style-only cleanup.
-
abrignoni Skill Leapp New Artifact 2Write, rework, review or audit a LEAPP artifact module. Use when adding support for an app or data source in iLEAPP, ALEAPP, RLEAPP, VLEAPP or DLEAPP, when asked to "add an artifact" or "parse <app>", when a module needs new output types, media or a conversation view, and equally when fixing, validating or checking the forensic value of a module that already exists, including one already merged.
-
yila-ai Bundle Academic Humanizer 2Use when researchers ask to remove generic, templated, or AI-like patterns from Chinese or English academic prose, make an AI-assisted draft sound more like the author's own scholarly voice, or audit a paper for “AI味”. Preserve every scientific claim, number, equation, citation, limitation, and uncertainty. Not for detector evasion or ordinary translation and grammar-only editing.
-
yila-ai Bundle Science Research Writing 2Use when researchers need to plan, draft, revise, or audit an empirical research paper from their own materials, including Introduction, Methods, Results, Discussion, Conclusion, Abstract, and Title, with evidence-preserving and target-journal-aware guidance.
-
sablier-labs Bundle Audit 2Security audit and code review for Solidity smart contracts. Trigger phrases - audit, check PR, security review, pre-audit preparation, vulnerability check, or when preparing code for external audit.
-
sbroenne Skill Secret Handling 2Never read .env files or write secrets to .squad/ committed files
-
tile-ai Bundle Tilelang Backend 2Integrate or review a TileLang target backend, target-backend variant, or shared execution backend. Covers language dialects, target and BackendContext contributions, PassPipeline, host/device codegen, execution compatibility, native CMake and packaging, tests, and documentation; covers Build/JIT/Runtime implementation only when a genuinely new execution mode is requested. Use when asked to add, port, scaffold, complete, or audit a TileLang backend or execution mode.
-
paiml Skill Dogfood 2Dogfood pmat — rebuild, install, exercise every CLI command against pmat's own repo, check output integrity + self-quality, find next work. Read-only audit; files issues for bugs.
-
zhanghandong Skill Cowork Guide 2CRITICAL: Comprehensive guide for CoWork Skills CLI tool. Triggers on: cowork, Skills.toml, skill management, plugin configuration, cowork init, cowork install, cowork config, cowork generate, cowork audit, cowork verify, cowork test
-
t4sh Bundle Eleventy Nunjucks 2Eleventy v3, Build Awesome v4 prerelease, and Nunjucks operating guide for static-site authoring, templates, build pipelines, migrations, and security review. Use when the user asks to "create an 11ty page", "add a Nunjucks filter", "fix my layout chain", "review my .njk template", "set up Eleventy", "migrate to Build Awesome", or "audit my static site"; when `package.json` includes `@11ty/eleventy` or `@awesome.me/buildawesome`; when paths include `.eleventy.js`, `eleventy.config.js`, `.njk`, `.11tydata.js`, `.data.js`, `.11ty.js`, or `.server.js`; or when debugging data cascades, filters, shortcodes, async Nunjucks, autoescape, or static-site security.
-
teamtinvio Bundle Jaz Jobs 2Use this skill for recurring accounting workflows — month/quarter/year-end close, bank reconciliation, GST/VAT filing, payment runs, credit control, supplier recon, audit prep, fixed asset review, and Singapore Form C-S tax computation. 12 job playbooks that sequence real platform tools into complete business processes. Also use when the user mentions closing the books, period-end, tax filing, or any operational accounting task.
-
wellwelwel Skill Specialize 2Author a new built-in Lagune sub-skill inside the Lagune source, not a scaffolded `.lagune/` target. Use when adding or refining a security knowledge module that ships with Lagune, against the native layout (`spec/skills/*.md` plus the catalog).
-
whenpoem Skill Replay 2Audit a past pruning or approval decision by creating a counterfactual branch from a saved snapshot without mutating the live graph. Use when the user asks what would have happened under another decision, disputes a paused branch, or wants to inspect an earlier checkpoint.
-
whenpoem Bundle Prove Sop 2Build and audit a statistical or mathematical proof from proposition capture through skeleton selection, diagnosis, correction, optional empirical checking, and optional Lean reinsurance. Use when the user asks to prove or rigorously derive a proposition, a graph proposition lacks a verified proof, or a reviewer requires a theorem-side gate.
-
hraness Bundle Plan Kb 2Create or evolve a durable Markdown plan inside a hraness/kb vault. Use when a user asks for an implementation plan, proposal, RFC, migration plan, execution audit, phased checklist, or an update to an existing plan's decisions, progress, review findings, verification evidence, or final result.
-
jornalistainclusivo Skill Nodejs Best Practices 2Node.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.
-
juspay Skill Fact Check 2Audit code for correctness and rigor — logic errors, silent error swallowing, wishful thinking, and unjustified fallbacks. This is not a style review; it's a logic review. Use when you want a focused correctness audit separate from the full code-police pass.
-
leonvanzyl Bundle Security Scanner 2Performs comprehensive OWASP Top 10:2025 security vulnerability analysis on any codebase. Use this skill whenever the user asks to: review code for security, perform a security audit, scan for vulnerabilities, find security issues, improve application security, check for OWASP compliance, do a penetration test review, assess security posture, look for security flaws, scan for security risks, harden an application, or check code for exploits. Also trigger when the user mentions OWASP, CVEs, CWEs, security hardening, vulnerability assessment, or asks for a security report — even if they don't explicitly say "security scan." This skill works on any codebase in any language (JavaScript, TypeScript, Python, Java, Go, Ruby, C#, PHP, etc.).
-
0xranx Skill Systematic Debugging 2Structured methodology for finding root causes before writing fixes
-
4444j99 Bundle QA Audit 2Verify claims in a session/PR/transcript against on-disk reality. Produce a verification report (verified / false-positive / false-negative / partial) with explicit owners. STOP at verification — do not execute remediation without explicit approval.
-
6ixgodd Skill Mine Sync 2Reconcile MINE-owned design with repository reality using code-first synchronization. Use when onboarding an existing repository, after substantial out-of-band changes, when design drift is suspected, before stable release, or when the user requests a repository/design audit. Creates a verified local backup before rewriting design, then updates design to match current code unless the user explicitly protects a decision. Does not modify business code without a separate architecture/plan/execute flow.
-
chase-key Skill Rell Domain 2The RELL compliance audit engine — architecture, philosophy, active modules, and development status.
-
akiselev Skill Rules Review 2Audit the altium-cli codebase (or a specified scope) against project rules from CLAUDE.md. Activate when the user requests a rules review, rules check, compliance audit, or codebase audit. Checks for: fail-fast violations, raw type usage, privacy leaks across crate boundaries, silent error suppression, unconsumed data skipping, missing domain types, and error handling correctness. Can target the full codebase, specific crates, files, or git changes.
-
giskard-ai Skill Fix Cve 2Use when pip-audit (or a CVE/GHSA advisory, Dependabot, or security scan) flags a vulnerable Python dependency in giskard-oss and it needs upgrading to a fixed version in the uv lockfile.
-
surya8991 Skill Codereview 2Blunt, factual code review. No sugar coating. Finds bugs, security issues, performance problems, and architecture flaws. Use when user says /codereview or asks to review code.
-
surya8991 Skill Security Audit 3Security auditing skill for web applications and codebases. Scans for OWASP Top 10, dependency vulnerabilities, secrets exposure, XSS/CSRF/injection flaws, auth weaknesses, and misconfigurations. Use when task involves security scan, vulnerability assessment, pen test review, threat modeling, or hardening a codebase.
-
clay-good Skill Reviewer 2Security and code quality reviewer. Read-only deep review for vulnerabilities and quality issues.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include clarity-promise, clarity-narrative, git-xray. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.