Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
pjt222 Skill Investigate Capa Root Cause 7Investigate root causes and manage CAPAs (Corrective and Preventive Actions) for compliance deviations. Covers investigation method selection (5-Why, fishbone, fault tree), structured root cause analysis, corrective vs preventive action design, effectiveness verification, and trend analysis. Use when an audit finding requires a CAPA, when a deviation or incident occurs in a validated system, when a regulatory observation needs a formal response, when a data integrity anomaly requires investigation, or when recurring issues suggest a systemic root cause.
-
thedixitjain Skill Production Audit日本語翻訳:このファイルは production-audit 用の日本語翻訳が必要です
2 -
thedixitjain Skill Pair ProgrammingAI-assisted pair programming with multiple modes (driver$navigator$switch), real-time verification, quality monitoring, and comprehensive testing. Supports TDD, debugging, refactoring, and learning sessions. Features automatic role switching, continuous code review, security scanning, and performance optimization with truth-score verification.
2 -
thedixitjain Bundle Hugging Face JobsRun workloads on Hugging Face Jobs with managed CPUs, GPUs, TPUs, secrets, and Hub persistence.
2 -
thedixitjain Skill Flow Nexus Platform| Comprehensive Flow Nexus platform management - authentication, sandboxes, app deployment, payments, and challenges
2 -
thedixitjain Skill Postgres Patterns 3PostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices.
2 -
thedixitjain Bundle Swiftui Performance AuditAudit and improve SwiftUI runtime performance from code review and architecture. Use for requests to diagnose slow rendering, janky scrolling, high CPU/memory usage, excessive view updates, or layout thrash in SwiftUI apps, and to provide guidance for user-run Instruments profiling when code review alone is insufficient.
2 -
humaisali Bundle AxiomFirst-principles assumption auditor. Classifies each hidden assumption (fact / convention / belief / interest-driven), ranks by fragility × impact, and rebuilds conclusions from verified premises. Bilingual: auto-detects Chinese or English.
-
thedixitjain Skill V3 Security OverhaulComplete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.
2 -
humaisali Skill Design UXUX / usability audit — heuristic evaluation of INTERACTIVE UIs (not just visual polish). Load with design when a UI "feels off", "sucks to use", is hard to learn, needs an instruction wall, or before shipping an interactive tool/editor/app. Scores the RENDERED UI against Nielsen's 10 +...
-
humaisali Skill Find BugsFind bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.
-
humaisali Skill Fix ReviewVerify fix commits address audit findings without new bugs
-
humaisali Skill Cyber AuditRun read-only exposure checks for security advisories and write a structured local audit report.
-
humaisali Skill Network 101Configure and test common network services (HTTP, HTTPS, SNMP, SMB) for penetration testing lab environments. Enable hands-on practice with service enumeration, log analysis, and security testing against properly configured target systems.
-
humaisali Skill Atlas LedgerCompanion to atlas-contract. Auto-invoked by its Final Audit on caught drift; also use after Post Reviews or user requests to record a mistake. Distills drift into WHEN/DON'T/INSTEAD clauses, writes to Atlas.md after confirmation.
-
humaisali Skill Wjttc TesterF1-inspired test EXECUTOR + reporter. Runs a test plan, finds and reproduces bugs, audits suite signal integrity, then files a WJTTC report (Brake/Engine/Aero/Tyre/Pit) with a tier verdict. Use when you need to test code, validate functionality, reproduce a failure, or produce a test...
-
thedixitjain Skill Ship 2Ship phase. Runs isolated integration test in a fresh worktree, creates a PR with full spec + audit report in the body, watches CI, and auto-fixes failures.
2 -
thedixitjain Skill Fix 3Get fix intelligence for a vulnerability and propose concrete remediation for the current repository
2 -
humaisali Bundle Vercel OptimizeAudit deployed Vercel apps for cost and performance issues using metrics, project config, code scans, and version-aware recommendations.
-
humaisali Skill FirebaseFirebase gives you a complete backend in minutes - auth, database, storage, functions, hosting. But the ease of setup hides real complexity. Security rules are your last line of defense, and they're often wrong.
-
humaisali Bundle Wp GuardReview generated or changed WordPress plugins, themes, and blocks for security, internationalization, performance, and API correctness.
-
humaisali Skill Avoid AI WritingAudit and rewrite content to remove 21 categories of AI writing patterns with a 43-entry replacement table
-
humaisali Skill Firmware AnalystExpert firmware analyst specializing in embedded systems, IoT security, and hardware reverse engineering.
-
humaisali Bundle Leiloeiro EditalAnalise e auditoria de editais de leilao judicial e extrajudicial. Riscos ocultos, clausulas perigosas, debitos, ocupante e classificacao da oportunidade.
-
humaisali Skill Security AuditorExpert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.
-
humaisali Skill Variant AnalysisFind similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing systematic code audits after finding an initial issue.
-
humaisali Skill WordpressComplete WordPress development workflow covering theme development, plugin creation, WooCommerce integration, performance optimization, and security hardening. Includes WordPress 7.0 features: Real-Time Collaboration, AI Connectors, Abilities API, DataViews, and PHP-only blocks.
-
humaisali Skill Bugs Are AnnoyingAdversarial code auditor that hunts down bugs, logic errors, and security flaws. Use for deep correctness passes, not style reviews.
-
humaisali Skill GRAPHQL ArchitectMaster modern GraphQL with federation, performance optimization, and enterprise security. Build scalable schemas, implement advanced caching, and design real-time systems.
-
humaisali Skill Pentest ChecklistProvide a comprehensive checklist for planning, executing, and following up on penetration tests. Ensure thorough preparation, proper scoping, and effective remediation of discovered vulnerabilities.
-
humaisali Bundle Solidity SecurityMaster smart contract security best practices, vulnerability prevention, and secure Solidity development patterns.
-
humaisali Skill Vibe Code AuditorAudit rapidly generated or AI-produced code for structural flaws, fragility, and production risks.
-
thedixitjain Bundle Sharp EdgesIdentifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes. Use when reviewing API designs, configuration schemas, cryptographic library ergonomics, or evaluating whether code follows 'secure by default' and 'pit of success' principles. Triggers: footgun, misuse-resistant, secure defaults, API usability, dangerous configuration.
2 -
thedixitjain Bundle Brooks AuditArchitecture audit that maps module dependencies, checks layering integrity, and flags structural decay across a codebase, drawing on twelve classic engineering books. Triggers when: user asks to audit architecture, review folder/module structure, check for circular imports, understand...
2 -
humaisali Skill Sast ConfigurationStatic Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.
-
humaisali Skill Wireshark AnalysisExecute comprehensive network traffic analysis using Wireshark to capture, filter, and examine network packets for security investigations, performance optimization, and troubleshooting.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include investigate-capa-root-cause, production-audit, pair-programming. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.