Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
kensaurus Bundle Audit Backend ArchitectureRead-only audit and decision advisor for backend architecture, topology-gated by stack. Use when "audit backend architecture", "which pattern should I use", "am I over-engineering", "sync vs event-driven". Mechanical boundary rules → enhance-arch-boundaries.
8 -
kensaurus Skill Plan Dependency ProvenanceAudit dependencies for hallucinated or slopsquatted packages, supply-chain risk, and licensing gaps, then a remediation plan. Use when "check my dependencies", "is this package real", "slopsquatting", "SBOM", or "did the AI hallucinate a package".
8 -
kensaurus Bundle Protocol Browser Anti StallBrowser-session guardrail for Playwright CLI: use headed, named, isolated sessions; prevent parallel collisions and recover stalls without scripted shortcuts. Read before browser work or when automation freezes. Product QA behavior remains with the calling test/audit skill.
8 -
nous-hermeshub Skill Network 101Configure and test common network services (HTTP, HTTPS, SNMP, SMB) for penetration testing lab environments. Enable hands-on practice with service enumeration, log analysis, and security testing against properly configured target systems.
1 -
nous-hermeshub Skill Avoid AI WritingAudit and rewrite content to remove 21 categories of AI writing patterns with a 43-entry replacement table
1 -
nous-hermeshub Skill Qms Audit ExpertISO 13485 internal audit expertise for medical device QMS. Covers audit planning, execution, nonconformity classification, and CAPA verification. Use when planning internal audits, executing audits, classifying findings, preparing for external aud...
1 -
nous-hermeshub Skill Tech Stack EvaluatorTechnology stack evaluation and comparison with TCO analysis, security assessment, and ecosystem health scoring. Use when comparing frameworks, evaluating technology stacks, calculating total cost of ownership, assessing migration paths, or analyz...
1 -
nous-hermeshub Skill Skill Security AuditorSkill Security Auditor
1 -
nous-hermeshub Skill Privilege Escalation MethodsProvide comprehensive techniques for escalating privileges from a low-privileged user to root/administrator access on compromised Linux and Windows systems. Essential for penetration testing post-exploitation phase and red team operations.
1 -
terminalskills Bundle HapiYou are an expert in Hapi.js, the configuration-centric enterprise framework for Node.js. You help developers build production APIs with built-in input validation (Joi), authentication strategies, plugin architecture, caching, rate limiting, and comprehensive request lifecycle hooks — designed for teams that need structure, security, and testability without third-party middleware sprawl.
-
bytesagain Bundle Bytesagain Code Reviewer CnReview code files for bugs, security issues, and style problems. Use when auditing Python, JavaScript, Go, or Bash code, checking for injection risks, measuring complexity, or generating review checklists.
12 -
jantoniofc Skill Pr Review ExpertUse when the user asks to review pull requests, analyze code changes, check for security issues in PRs, or assess code quality of diffs.
6 -
jantoniofc Skill Backend Security CoderExpert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.
6 -
jantoniofc Bundle Information Security Manager Iso27001ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use for ISMS design, security risk assessment, control implementation, ISO 27001 certification, security audits, incident response, and compliance verification. Covers ISO 27001, ISO 27002, healthcare...
6 -
a5c-ai Bundle Perception SystemAI perception skill for sight, hearing, and threat detection systems.
1.7k -
michaelschecht Bundle Security Best PracticesPerform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
0 -
curiositech Bundle Security Auditor 2Security vulnerability scanner and OWASP compliance auditor for codebases. Dependency scanning (npm audit, pip-audit), secret detection (high-entropy strings, API keys), SAST for injection/XSS vulnerabilities, and security posture reports. Activate on 'security audit', 'vulnerability scan', 'OWASP', 'secret detection', 'dependency check', 'CVE', 'security review', 'penetration testing prep'. NOT for runtime WAF configuration (use infrastructure tools), network security/firewalls, or compliance certifications like SOC2/HIPAA (legal/organizational).
10 -
terminalskills Bundle KnipFind and remove unused files, dependencies, and exports in JavaScript/TypeScript projects with Knip. Use when someone asks to "find unused code", "clean up dependencies", "remove dead code", "find unused exports", "Knip", "reduce bundle size by removing unused files", or "audit npm dependencies". Covers unused files, dependencies, exports, types, and CI integration.
-
gonzalezpazmonica Bundle Mutation AuditSkill: Mutation Audit
-
gonzalezpazmonica Bundle Performance AuditPerformance Audit Intelligence
-
gonzalezpazmonica Bundle Dynamic Web TesterDynamic Web Security Tester — SE-245
-
gonzalezpazmonica Bundle Git Secret ScannerGit Secret Scanner Skill
-
gonzalezpazmonica Bundle Adversarial SecuritySubagent Scope Guard
-
gonzalezpazmonica Bundle Iac Security ScannerSubagent Scope Guard
-
gonzalezpazmonica Bundle Tls Security CheckerTLS Security Checker
-
gonzalezpazmonica Bundle Mobile Security ScannerMobile Security Scanner
-
pingqlin Skill Dataverse Python Authentication SecurityDataverse SDK for Python — Authentication & Security Patterns
-
curiositech Bundle OAUTH Oidc ImplementerExpert in implementing OAuth 2.0 and OpenID Connect (OIDC) authentication flows. Specializes in secure token handling, social login integration, API authorization, and identity provider configuration. Handles both client-side and server-side flows with security best practices.
10 -
boisenoise Bundle Ln 760 Security SetupSets up security scanning for secrets and dependency vulnerabilities. Use when adding security infrastructure to a project.
-
boisenoise Bundle Ln 761 Secret ScannerScans codebase for hardcoded secrets with severity classification and remediation guidance. Use when auditing a project for leaked credentials.
-
boisenoise Skill Ln 512 Tech Debt CleanerAuto-fixes low-risk tech debt (unused imports, dead code, commented-out code) with >=90% confidence. Use when audit findings need safe automated cleanup.
-
ariffazil Skill Wisdom Reader📜 WISDOM-reader — Witness-First Audit Doctrine
-
ariffazil Bundle Warga ConstitutionalArchived constitutional warga placeholder retained only for audit provenance. Do not use for active work; use the live arifOS governance
-
ariffazil Bundle ArchiveArchived skill artifacts and quarantine records. Retained for audit trace and civilizational memory.
-
sboghossian-mini-claude-for-legal Skill Draft Ip LicensingUse when drafting an intellectual property licensing agreement that grants rights to use a patent, trademark, copyright, trade secret, or software. Covers exclusive, sole, and non-exclusive licenses across any territory and field of use, with full attention to royalty structures, audit rights, improvement ownership, and MENA-specific enforceability traps (commercial agency law, gharar, SAIP registration). Triggers on phrases like "ip license", "licensing agreement", "royalty deal", or "technology transfer".
-
pingqlin Skill Security And OwaspSecure Coding and OWASP Guidelines
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include audit-backend-architecture, plan-dependency-provenance, protocol-browser-anti-stall. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.