Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
diaszano Skill Security AuditorUse this skill when conducting comprehensive security audits, compliance assessments, or risk evaluations across systems, infrastructure, and processes. Invoke when you need systematic vulnerability analysis, compliance gap identification, or evidence-based security findings.
-
diaszano Skill Slack ExpertUse this skill when developing Slack applications, implementing Slack API integrations, or reviewing Slack bot code for security and best practices.
-
diaszano Skill AI Writing AuditorUse this skill when you need to audit content for AI writing patterns and rewrite text to remove them.
-
opencue Bundle Openclaw Audit WatchdogAutomated daily security audits for OpenClaw agents with DM delivery and optional email reporting. Runs deep audits, creates or updates a recurring cron job, and sends formatted reports to configured recipients.
-
opencue Skill Source Command Audit GeoAudit cuecards GEO health — verify AI-discoverability files are accurate, citation-ready, and consistent with the source code
-
opencue Bundle Picoclaw Security GuardianPicoclaw security posture skill with advisory awareness, configuration drift detection, and supply-chain verification guidance.
-
opencue Bundle Hermes Attestation GuardianHermes-only runtime security attestation and drift detection skill for operator-managed Hermes infrastructure.
-
eskcti Bundle Backend Controller KtCriar, revisar ou orientar controllers HTTP do backend Spring Boot em Kotlin no padrão DDD/Clean Architecture. Usar quando o pedido envolver arquivos `*Controller.kt`, definição de rotas e verbos HTTP, aplicação de segurança (Spring Security), binding de @RequestBody/@PathVariable/@RequestParam, orquestração de use cases e mapeamento de falhas para ResponseEntity/exceções HTTP.
-
dvcrn Skill ClawauditOfficial repo for clawaudit, coming soon as an automated security checker for repositories.
32 -
dvcrn Bundle Hello ExampleA minimal example skill demonstrating .clawhubignore — the secret.md file should NOT appear in the published version.
32 -
diaszano Skill Architect ReviewerUse this skill when you need to evaluate system design decisions, architectural patterns, and technology choices at the macro level.
-
diaszano Skill Compliance AuditorUse this skill when you need to achieve regulatory compliance, implement compliance controls, or prepare for audits across frameworks like GDPR, HIPAA, PCI DSS, SOC 2, and ISO standards.
-
diaszano Skill Penetration TesterUse this skill when you need to conduct authorized security penetration tests to identify real vulnerabilities through active exploitation and validation. Use penetration-tester for offensive security testing, vulnerability exploitation, and hands-on risk demonstration.
-
diaszano Skill Ad Security ReviewerUse this skill when you need to audit Active Directory security posture, evaluate privilege escalation risks, review identity delegation patterns, or assess authentication protocol hardening.
-
diaszano Skill Gdpr Ccpa ComplianceUse when the user needs to understand GDPR or CCPA compliance, review data practices, or assess privacy requirements. Triggers on: 'GDPR', 'CCPA', 'privacy compliance', 'data privacy', 'right to deletion', 'consent', 'data subject rights', 'California privacy'.
-
diaszano Skill Performance EngineerUse this skill when you need to identify and eliminate performance bottlenecks in applications, databases, or infrastructure systems, and when baseline performance metrics need improvement.
-
diaszano Skill Dependency ManagerUse this skill when you need to audit dependencies for vulnerabilities, resolve version conflicts, optimize bundle sizes, or implement automated dependency updates.
-
diaszano Skill Blockchain DeveloperUse this skill when building smart contracts, DApps, and blockchain protocols that require expertise in Solidity, gas optimization, security auditing, and Web3 integration.
-
diaszano Skill Powershell Security HardeningUse this skill when you need to harden PowerShell automation, secure remoting configuration, enforce least-privilege design, or align scripts with enterprise security baselines and compliance frameworks.
-
roche-k Bundle Va Electron ProUse when building Electron desktop applications that require native OS integration, cross-platform distribution, security hardening, and performance optimization. Use electron-pro for complete desktop app development from architecture to signed, distributable installers.
-
roche-k Bundle Va Slack ExpertUse when developing Slack applications, implementing Slack API integrations, or reviewing Slack bot code for security and best practices.
-
roche-k Bundle Va Code ReviewerUse when you need to conduct comprehensive code reviews focusing on code quality, security vulnerabilities, and best practices.
-
roche-k Bundle Va Ad Security ReviewerUse when you need to audit Active Directory security posture, evaluate privilege escalation risks, review identity delegation patterns, or assess authentication protocol hardening.
-
dvcrn Skill Audit Fixer 2Analyze npm audit output with AI and get actionable fix suggestions. Use when dealing with security vulnerabilities.
32 -
roche-k Bundle Va Powershell Security HardeningUse when you need to harden PowerShell automation, secure remoting configuration, enforce least-privilege design, or align scripts with enterprise security baselines and compliance frameworks.
-
yakeworld Bundle Pima Audit在目标数据集的学术论文中验证一致性:
-
yakeworld Bundle Pidd Leakage Audit1. Never cite CRISP-DM without citing Shearer (2000) or Wirth & Hipp (2000). These are the original
-
yakeworld Bundle Synthos Skill AuditSynthos Skill Audit
-
yakeworld Bundle Reproducibility Audit**边界**:技能功能边界。
-
yakeworld Bundle Paper Experiment Audit**边界**:技能功能边界。
-
yakeworld Bundle Kaggle Leakage Audit1. 不平衡度越高 → 泄漏杀伤越大
-
yakeworld Bundle Knowledge Base Audit**Problem**: `notebooklm list` returns "Not authenticated. Run notebooklm login first." despite havi
-
dvcrn Skill Audit Badge DemoDemo skill showcasing the audit badge workflow; still experimental.
32 -
dvcrn Skill Test Audit BadgeTest skill to demonstrate the audit badge; do not use it for real workflows.
32 -
opencue Bundle HydraUse when the user asks for Hydra, a deep multi-perspective code review, architecture or security tradeoffs, blind spots, or iterative re-review. Avoid for simple fixes and lookups.
-
opencue Skill Vc Predict5 expert personas debate proposed changes before implementation. Catches architectural, security, performance, and UX issues early. Use before major features or risky changes.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-auditor, slack-expert, ai-writing-auditor. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.