Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
patrickserrano Bundle Xcode Disk Cleanup 2Audit and safely clean Xcode-related developer storage on macOS. Use whenever a developer mentions low disk space, Xcode storage, DerivedData, simulator devices or runtimes, stale beta platforms in Xcode Settings, DeviceSupport, archives, dSYMs, CocoaPods caches, simulator dyld caches, project .build folders, downloaded Xcode DMGs/XIPs, duplicate Xcode installers, or old Xcode applications. Also use this skill proactively when you hit low storage during other work, such as a build, download, or install failing with an out-of-disk-space error. Always measure first, report recoverable GiB with evidence, and obtain explicit itemized approval before any mutation.
-
novusedge Bundle Anti Slop 2Audit prose a human reads — comments, docstrings, commit messages, PR bodies, docs, chat replies. STE grammar, no AI buzzwords, no LinkedIn cadence, surgical brevity. Use anti-slop-code for source files.
-
novusedge Bundle Anti Slop Code 2Audit and trim code itself — narrator comments, defensive boilerplate, dead generality, tests that assert mocks, docstrings that restate the signature. Use for source files; use anti-slop for prose.
-
waynesutton Bundle Convex Return Validators 2Guide for when to use and when not to use return validators in Convex functions. Use this skill whenever the user is writing Convex queries, mutations, or actions and needs guidance on return value validation. Also trigger when the user asks about Convex type safety, runtime validation, AI-generated Convex code, Convex AI rules, Convex security best practices, or when they're debugging return type issues in Convex functions. Trigger this skill when users mention "validators", "returns", "return type", or "exact types" in the context of Convex development. Also trigger when writing or reviewing Convex AI rules or prompts that instruct LLMs how to write Convex code.
-
wordpress Skill Self Review 3Review the current branch against this repo's architecture, security, performance, cross-platform and test-coverage rules before opening a PR. Use when the user asks to self-review, review my changes, check my branch before a PR, or says they are about to open a PR.
-
wordpress Skill Self Review 4Review the current branch against this repo's architecture, security, performance, cross-platform and test-coverage rules before opening a PR. Use when the user asks to self-review, review my changes, check my branch before a PR, or says they are about to open a PR.
-
wpacademy Bundle Wp Plugin Dev 2Develop WordPress plugins following official WordPress coding standards, security best practices, and WordPress.org directory guidelines. Use this skill whenever the user wants to create, scaffold, or develop a WordPress plugin — including standard plugins (settings pages, CPTs, shortcodes), WooCommerce extensions, Gutenberg block plugins, or REST API / headless plugins. Also trigger when the user mentions "WordPress plugin", "WP plugin", asks to build a feature as a plugin, wants to add admin pages, register custom post types, create blocks, build WooCommerce add-ons, or extend WordPress in any way via plugin architecture. Even if the user just says "build me a plugin for X", use this skill.
-
holobiomicslab Skill Lipid Type Category Enumeration 2Use when when you have downloaded or cloned a lipidomics library repository (such as LipidMatch) and need to audit the breadth of lipid-type coverage to ensure the library meets minimum requirements for your analysis scope (e.g., ≥60 distinct lipid categories).
-
holobiomicslab Skill Metabolite Generation Logic Mapping 2Use when when you have access to the MAGMa source code and need to understand or audit how in silico metabolite candidates are enumerated from parent structures.
-
pjt222 Skill Awareness 5AI situational awareness — internal threat detection for hallucination risk, scope creep, and context degradation. Maps Cooper color codes to reasoning states and OODA loop to real-time decisions. Use during any task where reasoning quality matters, when operating in unfamiliar territory, after detecting early warning signs such as an uncertain fact or suspicious tool result, or before high-stakes output like irreversible changes or architectural decisions.
-
pjt222 Skill Awareness 6AI situational awareness — internal threat detection for hallucination risk, scope creep, and context degradation. Maps Cooper color codes to reasoning states and OODA loop to real-time decisions. Use during any task where reasoning quality matters, when operating in unfamiliar territory, after detecting early warning signs such as an uncertain fact or suspicious tool result, or before high-stakes output like irreversible changes or architectural decisions.
-
pjt222 Skill Mindfulness 4Cultivate defensive situational awareness, threat assessment, and mental clarity under pressure. Covers the Cooper color code awareness system, body language reading and intent detection, verbal de-escalation, moving mindfulness in public spaces, combat focus and the OODA loop, rapid grounding techniques for acute stress, context-specific integration, and ongoing review and refinement of awareness skills. Use when entering unfamiliar or potentially hostile environments, needing to assess a situation for safety, de-escalating a verbal confrontation, or integrating awareness practice into daily movement.
-
pjt222 Skill Configure Nginx 2Configure Nginx as a web server and reverse proxy. Covers static file serving, reverse proxy to upstream services, SSL/TLS termination with Let's Encrypt, location blocks, load balancing, rate limiting, and security headers. Use when serving static files in production, reverse proxying to backend services (Node.js, Python, R/Shiny), terminating SSL/TLS, load balancing across instances, or adding rate limiting and security headers to harden an endpoint.
-
pjt222 Skill Mindfulness 5Cultivate defensive situational awareness, threat assessment, and mental clarity under pressure. Covers the Cooper color code awareness system, body language reading and intent detection, verbal de-escalation, moving mindfulness in public spaces, combat focus and the OODA loop, rapid grounding techniques for acute stress, context-specific integration, and ongoing review and refinement of awareness skills. Use when entering unfamiliar or potentially hostile environments, needing to assess a situation for safety, de-escalating a verbal confrontation, or integrating awareness practice into daily movement.
-
pjt222 Skill Mindfulness 6Cultivate defensive situational awareness, threat assessment, and mental clarity under pressure. Covers the Cooper color code awareness system, body language reading and intent detection, verbal de-escalation, moving mindfulness in public spaces, combat focus and the OODA loop, rapid grounding techniques for acute stress, context-specific integration, and ongoing review and refinement of awareness skills. Use when entering unfamiliar or potentially hostile environments, needing to assess a situation for safety, de-escalating a verbal confrontation, or integrating awareness practice into daily movement.
-
pjt222 Skill Awareness 2AI situational awareness — internal threat detection for hallucination risk, scope creep, and context degradation. Maps Cooper color codes to reasoning states and OODA loop to real-time decisions. Use during any task where reasoning quality matters, when operating in unfamiliar territory, after detecting early warning signs such as an uncertain fact or suspicious tool result, or before high-stakes output like irreversible changes or architectural decisions.
-
pjt222 Skill Mindfulness 2Cultivate defensive situational awareness, threat assessment, and mental clarity under pressure. Covers the Cooper color code awareness system, body language reading and intent detection, verbal de-escalation, moving mindfulness in public spaces, combat focus and the OODA loop, rapid grounding techniques for acute stress, context-specific integration, and ongoing review and refinement of awareness skills. Use when entering unfamiliar or potentially hostile environments, needing to assess a situation for safety, de-escalating a verbal confrontation, or integrating awareness practice into daily movement.
-
pjt222 Skill Manage Changelog 2Maintain a changelog following Keep a Changelog format. Covers entry categorization (Added, Changed, Deprecated, Removed, Fixed, Security), version section management, and unreleased tracking. Use when starting a new project that needs a changelog, adding entries after completing features or fixes, preparing a release by promoting Unreleased entries to a versioned section, or converting a free-form changelog to Keep a Changelog format.
-
pjt222 Skill Manage Changelog 3Keep a Changelog形式に従ったチェンジログの維持管理。エントリの分類(Added、 Changed、Deprecated、Removed、Fixed、Security)、バージョンセクションの管理、 未リリースの追跡を網羅する。チェンジログが必要な新しいプロジェクトを開始する時、 機能やフィックスの完了後にエントリを追加する時、未リリースエントリをバージョン 付きセクションに昇格させてリリースを準備する時、またはフリーフォームのチェンジ ログをKeep a Changelog形式に変換する時に使用する。
-
pjt222 Skill Defend Colony 4Implement layered collective defense using alarm signaling, role mobilization, and proportional response. Covers threat detection, alert propagation, immune response patterns, escalation tiers, and post-incident recovery for distributed systems and organizations. Use when designing defense-in-depth where no single guardian covers all threats, building incident response that scales with severity, or when current defense is over-reactive to every alert or under-reactive to genuine threats.
-
pjt222 Skill Conduct Gxp Audit 2Realizar una auditoría GxP de sistemas informatizados y procesos. Cubre planificación de la auditoría, reuniones de apertura, recopilación de evidencias, clasificación de hallazgos (crítico/mayor/menor), generación de CAPA, reuniones de cierre, redacción de informes y verificación de seguimiento. Usar para auditorías internas programadas, auditorías de calificación de proveedores, evaluaciones de preparación previa a la inspección, auditorías por causa desencadenadas por desviaciones o preocupaciones de integridad de datos, o revisiones periódicas del estado de cumplimiento de sistemas validados.
-
pjt222 Skill Conduct Gxp Audit 3コンピューター化システムとプロセスのGxP監査を実施します。監査計画、開始ミーティング、 証拠収集、指摘事項の分類(重大/重大/軽微)、CAPA生成、終了ミーティング、報告書作成、 フォローアップ検証を対象とします。定期的な内部監査、サプライヤー適格性評価監査、 査察前の準備評価、逸脱やデータ整合性懸念によって引き起こされた原因別監査、 またはバリデートされたシステムの定期的なコンプライアンス態勢レビューに使用します。
-
pjt222 Skill Defend Colony 5Implement layered collective defense using alarm signaling, role mobilization, and proportional response. Covers threat detection, alert propagation, immune response patterns, escalation tiers, and post-incident recovery for distributed systems and organizations. Use when designing defense-in-depth where no single guardian covers all threats, building incident response that scales with severity, or when current defense is over-reactive to every alert or under-reactive to genuine threats.
-
pjt222 Skill Defend Colony 6Implement layered collective defense using alarm signaling, role mobilization, and proportional response. Covers threat detection, alert propagation, immune response patterns, escalation tiers, and post-incident recovery for distributed systems and organizations. Use when designing defense-in-depth where no single guardian covers all threats, building incident response that scales with severity, or when current defense is over-reactive to every alert or under-reactive to genuine threats.
-
pjt222 Skill Mindfulness 7Cultivate defensive situational awareness, threat assessment, and mental clarity under pressure. Covers the Cooper color code awareness system, body language reading and intent detection, verbal de-escalation, moving mindfulness in public spaces, combat focus and the OODA loop, rapid grounding techniques for acute stress, context-specific integration, and ongoing review and refinement of awareness skills. Use when entering unfamiliar or potentially hostile environments, needing to assess a situation for safety, de-escalating a verbal confrontation, or integrating awareness practice into daily movement.
-
pjt222 Skill Manage Changelog 5Maintain a changelog following Keep a Changelog format. Covers entry categorization (Added, Changed, Deprecated, Removed, Fixed, Security), version section management, and unreleased tracking. Use when starting a new project that needs a changelog, adding entries after completing features or fixes, preparing a release by promoting Unreleased entries to a versioned section, or converting a free-form changelog to Keep a Changelog format.
-
pjt222 Skill Conduct Gxp Audit 4对计算机化系统和流程执行 GxP 审计。涵盖审计计划、首次会议、证据收集、 发现分类(关键/重大/轻微)、CAPA 生成、末次会议、报告编写和后续验证。 适用于定期内部审计、供应商资质审计、监管检查前的就绪评估、由偏差或数据 完整性问题触发的原因审计,或已验证系统的定期合规状态评审。
-
pjt222 Skill Mindfulness 8Cultivate defensive situational awareness, threat assessment, and mental clarity under pressure. Covers the Cooper color code awareness system, body language reading and intent detection, verbal de-escalation, moving mindfulness in public spaces, combat focus and the OODA loop, rapid grounding techniques for acute stress, context-specific integration, and ongoing review and refinement of awareness skills. Use when entering unfamiliar or potentially hostile environments, needing to assess a situation for safety, de-escalating a verbal confrontation, or integrating awareness practice into daily movement.
-
pjt222 Skill Manage Changelog 6Maintain a changelog following Keep a Changelog format. Covers entry categorization (Added, Changed, Deprecated, Removed, Fixed, Security), version section management, and unreleased tracking. Use when starting a new project that needs a changelog, adding entries after completing features or fixes, preparing a release by promoting Unreleased entries to a versioned section, or converting a free-form changelog to Keep a Changelog format.
-
pjt222 Skill Defend Colony 8Implement layered collective defense using alarm signaling, role mobilization, and proportional response. Covers threat detection, alert propagation, immune response patterns, escalation tiers, and post-incident recovery for distributed systems and organizations. Use when designing defense-in-depth where no single guardian covers all threats, building incident response that scales with severity, or when current defense is over-reactive to every alert or under-reactive to genuine threats.
-
pjt222 Skill Review UX UI 10UX/UI review → Nielsen heuristics + WCAG 2.1 + keyboard/screen reader + flow + cognitive load + form. Use → pre-release usability, WCAG audit, flow eval, form review, heuristic eval.
-
pjt222 Skill Security Audit Codebase 2Realizar una auditoría de seguridad del código verificando secretos expuestos, dependencias vulnerables, vulnerabilidades de inyección, configuraciones inseguras y problemas del OWASP Top 10. Utilizar antes de publicar o desplegar un proyecto, para revisiones de seguridad periódicas, después de agregar autenticación o integración con API, antes de hacer público un repositorio privado, o al prepararse para una auditoría de cumplimiento de seguridad.
-
pjt222 Skill Security Audit Codebase 3コードベースのセキュリティ監査を実施し、露出したシークレット、脆弱な依存関係、 インジェクション脆弱性、安全でない設定、OWASP Top 10の問題を検査する。 プロジェクトの公開・デプロイ前、定期的なセキュリティレビュー、認証やAPI 連携の追加後、プライベートリポジトリのオープンソース化前、セキュリティ コンプライアンス監査の準備時に使用する。
-
pjt222 Skill Defend Colony 9Implement layered collective defense using alarm signaling, role mobilization, and proportional response. Covers threat detection, alert propagation, immune response patterns, escalation tiers, and post-incident recovery for distributed systems and organizations. Use when designing defense-in-depth where no single guardian covers all threats, building incident response that scales with severity, or when current defense is over-reactive to every alert or under-reactive to genuine threats.
-
pjt222 Skill Awareness 7AI situational awareness — internal threat detection for hallucination risk, scope creep, and context degradation. Maps Cooper color codes to reasoning states and OODA loop to real-time decisions. Use during any task where reasoning quality matters, when operating in unfamiliar territory, after detecting early warning signs such as an uncertain fact or suspicious tool result, or before high-stakes output like irreversible changes or architectural decisions.
-
pjt222 Skill Awareness 8AI situational awareness — internal threat detection for hallucination risk, scope creep, and context degradation. Maps Cooper color codes to reasoning states and OODA loop to real-time decisions. Use during any task where reasoning quality matters, when operating in unfamiliar territory, after detecting early warning signs such as an uncertain fact or suspicious tool result, or before high-stakes output like irreversible changes or architectural decisions.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include self-review, self-review, wp-plugin-dev. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.