Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
cyberuni Skill Fix Security Pr 2Use this skill when a PR fails security or vulnerability checks (audit, CVE, Dependabot, Snyk, or advisory blocks).
-
anonaddy Bundle Testing Best Practices 2Laravel test design and review. Use when selecting coverage, naming or structuring tests, choosing assertions or test data, isolating dependencies, testing HTTP or security boundaries, improving suite performance, or reviewing test value. Use framework guidance or search-docs for Pest and PHPUnit syntax.
-
bitfoundation Skill Review 2Reviews code changes against this project's conventions - Bit.BlazorUI usage, theming, enhanced lifecycle methods, WrapHandled, Mapperly, OData, structured logging, nullable awareness, security and concurrency. Reports findings only and never modifies code. Use when the user asks to review changes, review a diff or PR, check code against project conventions, or says "run code review".
-
davila7 Skill Changelog Entry 3Draft the changelog entry for all unreleased commits in Keep a Changelog format. Groups commits into Added, Changed, Fixed, Removed, and Security. Use before releasing a new version or when updating CHANGELOG.md.
-
omas-odoo Bundle Odoo XML Conventions 2Use when writing, reviewing, or migrating any .xml file in an Odoo module — views, actions, menus, security records, data files, QWeb templates. Holds Odoo's naming, formatting, inheritance, and cross-version syntax conventions. Invoke before adding records to views/, security/, data/, or report/ directories.
-
opencoredev Bundle Convex Performance Audit 2Audits Convex performance for reads, subscriptions, write contention, and function limits. Use for slow features, insights findings, OCC conflicts, or read amplification.
-
stacklok Skill Security Vuln Remediation 2Remediate security vulnerabilities found by Grype or pnpm audit. Use when a security scan fails, a CVE needs fixing, or you need to analyze, upgrade, override, or ignore a vulnerable dependency.
-
tjcages Bundle Linear Methodology 2Proven methodology for building and tracking features, projects, and issues in Linear. Use when the user wants to set up Linear tracking, sync or audit a board, run a Linear health check, finish install after skills add, or keep session discipline honest. Routes to linear-setup / linear-sync / linear-monitor / linear-finish-install as needed; linear-discipline is always-on.
-
waynesutton Skill Convex Auth Expert 2Expert Convex Auth setup, production, OAuth, security, and debugging guidance. Use when adding or auditing Convex Auth, configuring GitHub/Google/Apple OAuth, setting auth env vars, protecting Convex functions with getAuthUserId, debugging callback URLs, preparing production auth, rotating keys, or reviewing auth security.
-
meleantonio Skill Formalize Proof 2Formalize a natural-language mathematical proof in Lean 4 (or another kernel) incrementally: small goals first, expand, audit mismatches, refactor. Use after an informal proof of an open problem is drafted and audited, or when the user asks for Lean formalization of a proof artifact.
-
meleantonio Skill Adversarial Proof Audit 2Independently attack a candidate mathematical proof: find gaps, circular lemmas, silent hypothesis changes, insufficient uniformity, and false completions. Use after any draft proof of an open problem, before claiming success, or when the user asks to audit, stress-test, or red-team a proof.
-
mukul975 Skill Exploit DB 2Exploit-DB and searchsploit reference — EDB→Metasploit module mappings, PoC reliability rubric, CVSS tier quick reference, and searchsploit usage patterns
24.6k -
nateherkai Bundle Audit 2Use when someone asks to audit their AIOS, score the Four Cs, find stale paths or unlinked projects, compare AGENTS.md and CLAUDE.md, check Claude/Codex skill compatibility, or assess migration readiness. Automatically saves dated reports and tracks evidence-backed improvements across runs.
-
netalertx Skill Skill Hygiene 2Read before writing or editing any SKILL.md, or any research/audit doc in .gemini/internal-docs/research/. Covers the two standing rules for living-reference prose - state current behavior only, and prefer plain, short wording - plus the grep sweep to run before calling a doc clean. PRDs are the deliberate exception (they keep a correction trail).
-
openai Bundle Verify Fix 2Use only when the user explicitly requests verification that a security fix remediates a reported vulnerability. Do not invoke automatically while implementing fixes, reviewing ordinary code changes, or running tests. Do not use for non-security fixes, candidate finding validation, or full repository scans.
23.3k -
openai Bundle Deep Security Scan 2Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated complete independent Standard scans with the Codex Security deep-scan tool, which aggregates their validated findings and prepares the canonical artifacts; then complete the same scan once. Do not use for PRs, commits, branch diffs, or working-tree diffs.
23.3k -
otrf Bundle Hunt Research System And Tradecraft 2Research system internals and adversary tradecraft to ground a threat hunt in real system behavior and realistic abuse patterns. Use this skill at the start of hunt planning, when you are given a high-level hunt topic but lack a clear understanding of how the system normally operates or how adversaries are known to abuse it. This skill informs early hunt direction by producing candidate abuse patterns, key assumptions, and cited sources, and should be used before defining a concrete hunt hypothesis or selecting data sources.
-
abh80 Bundle Scala Code Optimizer 2Audit a Scala file or codebase for refactoring opportunities — Scala 3 modernization, idiom adoption, anti-pattern removal, performance hygiene, tail-recursion safety, and migration cleanup. Produces educational, documentation-backed findings as suggestions only, never editing the file in place. Use this skill whenever the user asks to refactor Scala code, modernize Scala 2 to Scala 3, find Scala anti-patterns, optimize Scala performance, review Scala idioms, apply opaque types, replace value classes, convert sealed traits to enums, migrate implicits to given/using, audit a `.scala` file, or do anything involving cleaning up or improving Scala code — even if they don't explicitly say "audit" or "refactor". Trigger on phrases like "review my Scala", "modernize this Scala", "make this idiomatic Scala 3", "find issues in this Scala file", "check for Scala anti-patterns", or any pasted Scala code accompanied by a request to improve, clean, optimize, or modernize it.
-
beginnersinai Skill Map 2This skill should be used when the user types '/map', asks to 'run an AI mapping audit', 'scan my workspace for AI gaps', 'find where AI should be in my business', or wants a full workspace AI audit. Runs a comprehensive AI Mapping Audit based on Kim, Kim & Koning (2026) research.
-
beginnersinai Bundle AI Mapping Audit 2Automatically activates when users discuss AI adoption strategy, ask where to use AI in their business, want to find new AI use cases, or mention the 'mapping problem'. Provides the 10-function framework and examples of how other firms have reorganized around AI to help users discover unmapped opportunities.
-
beginnersinai Skill Map Venture 2This skill should be used when the user types '/map-venture', asks to 'audit a single project', 'map AI usage for this venture', or wants a focused AI mapping audit on one specific project or business. Provide the venture name or directory path as context.
-
codealive-ai Bundle Anti Pattern Audit 2Monthly self-deception audit — 25 anti-patterns from CEO Bible Section M
-
coreyhaines31 Skill Owasp Audit 2Audit application source code against the OWASP Top 10 vulnerability categories. Use when the user mentions 'OWASP,' 'security audit,' 'code security review,' 'vulnerability audit,' 'find vulnerabilities,' 'secure code review,' 'security review,' or wants to check their codebase for common security weaknesses.
36.3k -
coreyhaines31 Skill Incident Triage 2Guide rapid triage and initial response to security incidents following NIST SP 800-61 methodology. Use when the user mentions 'incident response,' 'security incident,' 'triage,' 'we've been hacked,' 'breach,' 'compromised,' 'malware detected,' 'suspicious activity,' 'IOC,' 'indicators of compromise,' or needs help handling a security event.
36.3k -
coreyhaines31 Skill Dependency Audit 2Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns. Use when the user mentions 'dependency audit,' 'npm audit,' 'CVE,' 'vulnerable packages,' 'supply chain security,' 'outdated dependencies,' 'known vulnerabilities,' 'security advisory,' 'package security,' 'framework vulnerability,' 'is this package safe,' or needs to check whether their stack has known security issues.
36.3k -
craftos-dev Bundle Semgrep 2Run Semgrep static analysis scan on a codebase using parallel subagents. Supports two scan modes — "run all" (full ruleset coverage) and "important only" (high-confidence security vulnerabilities). Automatically detects and uses Semgrep Pro for cross-file taint analysis when available. Use when asked to scan code for vulnerabilities, run a security audit with Semgrep, find bugs, or perform static analysis. Spawns parallel workers for multi-language codebases.
-
craftos-dev Bundle Differential Review 2Performs security-focused differential review of code changes (PRs, commits, diffs). Adapts analysis depth to codebase size, uses git history for context, calculates blast radius, checks test coverage, and generates comprehensive markdown reports. Automatically detects and prevents security regressions.
-
craftos-dev Bundle Supply Chain Risk Auditor 2Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security engagements.
-
darrenhinde Skill Code Review 2Use when code has been written and needs validation before committing, or when the user asks for a code review or security check.
-
rweisssieker-xp Skill Ceap Quality Governance 2Use for CEAP quality engineering, automated test generation, security checks, compliance validation, policy gates, auditability, and regulated enterprise or MedTech engineering review.
-
rweisssieker-xp Skill Fabric Compliance Officer 2Prepare Microsoft Fabric compliance evidence bundles, audit anomaly reviews, policy exception evaluations, and release risk matrices.
-
ryanduguid Skill Github Repository Audit 2Use when assessing whether a GitHub repository is trustworthy, maintainable, presentable, or ready to feature.
-
skullninja Skill IOS Design 2iOS UX design guidance for building premium SwiftUI interfaces. Triggers on: iOS UI/UX, layout, components, screen design, Liquid Glass, SwiftUI design, app design review, UI audit, view hierarchy, iOS design patterns.
-
stacksjs Skill Stacks Redesign 2Use when auditing and upgrading an existing Stacks UI to premium quality - finding AI-slop and generic patterns in stx templates, then fixing layout, spacing, hierarchy, type, color, states, and copy without breaking functionality or migrating the stack. Composes with stacks-design-taste as the audit-first companion, working in stx + Crosswind + composables.
-
stephschofield Skill Security Analysis 2````skill
-
t0ddharris Skill Skill Audit 2Audit all available Claude skills across user and project scopes — inventory them, map routing and overlap, score each on efficiency, reliability, clarity, maintainability, learning, currency, and safety, then produce a prioritized report and draft patches. Use when the user asks to audit, review, improve, optimize, modernize, clean up, consolidate, benchmark, or evaluate skills; to find outdated, duplicate, or inefficient skills; to identify missing skills; or to check whether skills follow current best practices. Diagnosis only — never edits a skill without explicit approval.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include fix-security-pr, testing-best-practices, review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.