Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
lovstudio Bundle Lov Bp Polish 2Review and improve an existing BP outline, PPTX, PDF, or rendered slide set across investment logic, evidence, copy, charts, and visual quality. Produces a scored report, page-level revisions, and targeted regeneration instructions while keeping facts separate from assumptions. Trigger on "润色 BP", "审稿商业计划书", "PPT 不专业", "逐页检查", "改图表", "BP review", "polish pitch deck", or "audit investor deck".
-
memohai Bundle Skill Creator 2Create or update Memoh workspace skills under /data/skills, including SKILL.md, scripts, references, assets, and validation. Use when the user asks to create, scaffold, revise, audit, or explain a workspace skill.
-
mfish-qf Skill Workflow Audit 3---
-
montgomeryunpopular607 Bundle Readme Polish 2Audit a GitHub README and rewrite it using modern 2025-2026 patterns — centered header, badges, hero image, GitHub alert callouts, emoji-prefixed features, expandable details, Mermaid diagrams, tables over dense prose. Produces a scannable README that works for a 10-second skim and a deep dive.
-
aaronjmars Skill Shiplog 2Recap of everything shipped since the last run - cross-repo PRs, security fixes, star deltas, and X traction, synthesized into a digest article and a ready-to-post shiplog in your voice.
-
arthjean Skill Two Factor Authentication Best Practices 2Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin. Use when users need MFA, multi-factor authentication, authenticator setup, or login security with Better Auth.
-
zhu1090093659 Skill Taste Audit 2品味审查 skill。当用户展示一段代码、一个设计、一个架构方案、一个 API,或者一段文字内容(文档、文案、邮件),并想判断"这东西好不好"、"是不是还能更优雅"、"有没有哪里丑"时,必须使用本 skill。当用户说"你帮我看看这个"、"这样写对吗"、"有没有更好的写法"、"这个设计怎么样"时,也应触发。本 skill 不给评价,不给答案——它只问问题,逼用户自己看出美丑。不要在用户明确要求"直接给建议"或"帮我写"的场景下触发。
-
caarles00 Bundle Security Review 2Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.
-
stunspot Bundle Verification Reviewer 5🔍 Audit release verdicts and test proof.
-
swellshinider Bundle Docs Cleaner 2Audit and improve project documentation and open-source repository readiness: README files, guides, contribution policies, security and conduct files, support guidance, and GitHub issue or pull-request templates. Use when documentation is stale, redundant, incomplete, inconsistent, or needs a conservative open-source standards review. Documentation-only changes.
-
qverisai Bundle Openclaw Secret Scanning Maintainer 2Maintainer-only workflow for handling GitHub Secret Scanning alerts on OpenClaw. Use when Codex needs to triage, redact, clean up, and resolve secret leakage found in issue comments, issue bodies, PR comments, or other GitHub content.
-
rfxlamia Bundle Skillkit 2Toolkit for creating and validating skills and subagents. Use when: creating a new skill (fast or full mode), validating an existing skill, deciding Skills vs Subagents, migrating docs to skills, estimating token cost, or running a security scan. Triggers: "create skill", "build skill", "validate skill", "new subagent", "skills vs subagents", "estimate tokens", "security scan".
-
shenjingnan Skill Fix Audit 2安全审计技能,用于检查和修复依赖安全问题
-
stickerdaniel Skill Email And Password Best Practices 2Configure email verification, implement password reset flows, set password policies, and customise hashing algorithms for Better Auth email/password authentication. Use when users need to set up login, sign-in, sign-up, credential authentication, or password security with Better Auth.
-
vipentti Bundle Planlet Complete 2Validate and safely complete or archive exactly one active repository-local Planlet with a UTC audit record. Use when a user asks to finish the Planlet lifecycle, archive completed work, or explicitly override incomplete tasks with a recorded reason.
-
vltansky Bundle Roast My Agents Md 2Brutally honest AGENTS.md/CLAUDE.md review backed by real A/B test evidence. Not just opinions — actual proof that your rules are dead weight. Roasts instruction files for bloat, slop, and redundancy, then proves it by running evals. Use when user says "roast my agents.md", "roast my CLAUDE.md", "prove my rules are useless", "eval roast", or wants entertaining evidence-based feedback on their AI config files. Also triggers on "audit my instructions" or "are my rules helping".
-
hugorcd Bundle Setup For Oss 2Review and bootstrap open-source repo health (OSS) by auditing or scaffolding README, CONTRIBUTING, CODE_OF_CONDUCT, LICENSE, SECURITY, GitHub templates, CI workflows, Renovate, publishing (pkg-pr-new + npm Trusted Publishing), linting/formatting, Changesets, and automation. Use when asked to review OSS setup, check OSS health, or set up/add OSS files and workflows.
-
jerelvelarde Skill Audit Security 2Perform a security audit when the user asks to check for vulnerabilities, audit security, review OWASP compliance, scan for secrets, or assess application security posture
-
roasbeef Bundle Variant Analysis 2Find similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing systematic code audits after finding an initial issue.
-
sendaifun Bundle Vulnhunter 2Security vulnerability detection and variant analysis skill. Use when hunting for dangerous APIs, footgun patterns, error-prone configurations, and vulnerability variants across codebases. Combines sharp edges detection with variant hunting methodology.
-
btn101 Skill Find Bugs 2Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.
-
btn101 Bundle Gha Security Review 2GitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to "review GitHub Actions", "audit workflows", "check CI security", "GHA security", "workflow security review", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.
-
mahdihedhli Skill Black Omarchy 2Operate a Black omARCHy workstation (Omarchy desktop plus the official BlackArch repository and curated tools). Use when the user mentions Black omARCHy, blackomarchy, BlackArch on Omarchy, installing or removing security profiles, verifying the layer, omarchy update with BlackArch, or asks how this host differs from Kali. Slash: /black-omarchy
-
phenixstar Bundle Skill Vetting 2Vet ClawHub skills for security and utility before installation. Use when considering installing a ClawHub skill, evaluating third-party code, or assessing whether a skill adds value over existing tools.
-
skillmedev Skill Dependency Risk Audit 2Audits third-party dependencies for exploitable CVEs, abandonment, license exposure, and supply-chain hygiene, and delivers a ranked findings report with a remediation order. Use when someone asks "is this package safe to add", "audit our dependencies", "npm audit is screaming, what actually matters", "can we use this GPL library", or is preparing a security review or vendor questionnaire. Do NOT use for triaging vulnerabilities in first-party code or a full CVE queue - use vulnerability-triage instead; for reviewing the code you wrote for security flaws - use secure-code-review instead; for how secrets are stored and rotated - use secrets-hygiene instead; for assembling compliance evidence - use soc2-evidence-helper instead.
-
wso2 Bundle Security Review 2Review code for security vulnerabilities using OWASP guidelines
-
youki0p0 Skill Jen Review 2Jen review mode for acceptance review, UX/product/security/contrarian review, and PR readiness checks.
-
marmelab Skill Ponytail Audit 2Whole-repo audit for over-engineering. Like ponytail-review, but scans the entire codebase instead of a diff: a ranked list of what to delete, simplify, or replace with stdlib/native equivalents. Use when the user says "audit this codebase", "audit for over-engineering", "what can I delete from this repo", "find bloat", "ponytail-audit", or "/ponytail-audit". One-shot report, does not apply fixes.
-
maxritter Skill Upstream Audit 2Audit and update Pilot Shell upstream dependencies in installer/upstreams.yaml. Checks npm, PyPI, brew, and curl-pipe entries for newer stable versions, known security advisories, and sha256 drift. Verifies each update installs successfully before committing. Use when: "check upstreams", "update dependencies", "audit upstreams.yaml", "are our dependencies up to date", "supply chain check".
-
microsoft Skill Asklearn 2Look up Microsoft Purview documentation and guidance from Microsoft Learn. Use this skill ONLY when the user's question does NOT match a diagnostic symptom in dlm-diagnostics. Use dlm-diagnostics first for troubleshooting issues like retention policy errors, archive problems, inactive mailboxes, etc. Use asklearn for general questions like: how do I create a retention policy, how do I set up eDiscovery, how do I enable audit logging, how do I configure communication compliance, how do I set up information barriers, how do I use insider risk management, how do I manage records, or how do I configure adaptive scopes.
2.7k -
microsoft Bundle Dlm Diagnostics 2Diagnose Microsoft Purview Data Lifecycle Management (DLM) issues in Exchange Online. Use this skill when a user reports: retention policy not applying to workloads, retention policy stuck in Error or PendingDeletion, items not moving from primary mailbox to archive, auto-expanding archive not provisioning additional storage, inactive mailbox not created after user deletion, Recoverable Items or SubstrateHolds folder growing uncontrollably, Teams messages not being deleted after retention period expires, MRM and Purview retention conflicting causing unexpected deletion or retention, adaptive scope including wrong members or not populating, or auto-apply retention labels not labeling content or showing Off Error status. Requires Exchange Online and Security & Compliance PowerShell sessions.
2.7k -
nunomaduro Bundle Laravel Best Practices 2Apply this skill whenever writing, reviewing, or refactoring Laravel PHP code. This includes creating or modifying controllers, models, migrations, form requests, policies, jobs, scheduled commands, service classes, and Eloquent queries. Triggers for N+1 and query performance issues, caching strategies, authorization and security patterns, validation, error handling, queue and job configuration, route definitions, and architectural decisions. Also use for Laravel code reviews and refactoring existing Laravel code to follow best practices. Covers any task involving Laravel backend PHP code patterns.
-
nvidia Bundle Nemoclaw Nvteam 2Route product, program, engineering, data and ML, quality, SRE, security, and developer-community work through the eight local role lenses packaged with the developer-community-chief-of-staff recipe in nemoclaw-community. Use for explicit NVTeam or persona activation, cross-functional readiness, developer relations, community enablement, technical-enablement work, or automatic specialist routing within this recipe. Do not use for a standalone question about core NemoClaw product capabilities unless the user explicitly requests NVTeam. This skill is Community-recipe behavior, not a built-in NemoClaw capability.
2.2k -
amazingchow Bundle Sync Self Explanatory Docs 2Synchronize Python architecture documentation with code using a three-level self-explanatory system: repository root docs, package-level `.package.md` files, and module header docstrings. Use when Codex changes Python project structure, adds or removes modules, refactors boundaries, updates entrypoints/domain/usecases/infrastructure responsibilities, or needs to audit and repair drift between the codebase and its architectural documentation.
-
cartridge-gg Bundle Account Abstraction 2Starknet account abstraction correctness and security guidance for validate/execute paths, nonces, signatures, and session policies.
-
dbt-labs Bundle Adapter Skills Annotate References 2Use when annotating fs adapter implementations with upstream dbt-adapters Python reference links. Triggers whenever you need to add or audit GitHub permalink comments in adapter_impl.rs, trace an fs adapter method back to its Python origin in dbt-adapters, or when working on adapter divergence and want to know where a method came from. Also use when asked to "annotate references", "add upstream links", or "link adapter methods".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include lov-bp-polish, skill-creator, workflow-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.