Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
newkayak12 Bundle Test MasterUse when someone needs to write, improve, or audit tests — generating unit, integration, E2E, performance, or security tests, analyzing coverage gaps, or producing a test plan or defect report. Triggers on: "테스트 작성", "단위 테스트", "커버리지 분석".
-
newkayak12 Skill Bias AuditorUse when evaluating a person or making a decision with high confidence — audits judgment / attribution / metacognition layers and prescribes per-bias remedies. Triggers on: "편향 점검", "내 판단 비뚤어진 것 같아", "audit my reasoning", "bias check", "확신이 과한 것 같아".
-
kesslernity Bundle Nonconformance Report DrafterDrafts a nonconformance report from inspection notes, test results and the governing specification or procedure: what was observed, where, the evidence with references, the requirement cited quoted verbatim with the departure from it, and containment proposals for the quality lead to decide. Never classifies severity, dispositions the item, names a root cause or closes the report. Use when the user asks to "write up this nonconformance", "draft an NCR from my inspection notes", "formalise this deviation" or "turn this snag into a defect report". Do not use for tracking the actions an NCR raises, use corrective-action-tracker instead. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Vendor Security Questionnaire PrefillPre-fills a customer's or prospect's security or third-party risk questionnaire from the organisation's own answer sources (prior questionnaires, answer library, policies), returning one row per question with a draft answer marked Reused, Adapted, Missing or Routed, its source, date, scope match and owner, plus the Missing list by owner. Never invents an answer, certification or control and never submits. Use when the user asks to "pre-fill this security questionnaire", "take a first pass at the customer's due diligence form", "answer this vendor assessment from our previous responses", "populate the third-party risk questionnaire" or "which questions can we reuse answers for". Do not use for screening a vendor's own answers, use vendor-risk-screening-brief instead; for RFP or tender answers use rfp-response-drafter. Drafts for human review; never approves, authorises or signs off.
-
open-legal-products Bundle Dpa DraftDraft a provider-side Data Processing Agreement from the bundled DOCX template after structured intake covering party roles, processing details, security, subprocessors, incidents, audits, deletion, international transfers, US privacy terms, and risk allocation. Use when a service provider or vendor asks to draft, prepare, create, or customize its DPA or privacy addendum. Do not use to draft customer-side paper, review counterparty paper, or negotiate an existing DPA.
-
open-legal-products Bundle Msa ReviewReviews supplied Master Services Agreements, customer agreements, SaaS-plus-services contracts, and counterparty redlines for commercial, intellectual-property, data, security, professional-services, indemnity, and liability risk. Use when the user asks to review, check, mark up, compare, or negotiate an MSA or customer agreement, including a redline of existing paper. Do not use to draft a new MSA from the bundled template; use an appropriate MSA-drafting workflow for that task.
-
open-legal-products Bundle Design Partner ReviewReview a supplied Design Partner Agreement or early-access co-design agreement for program obligations, feature commitments, fees, conversion, confidentiality, data and security, intellectual property, publicity, warranties, liability, indemnity, and general commercial risk. Use when a user asks to review, negotiate, issue-spot, summarize, or redline design-partner paper. Do not use to draft a new agreement or for a pure trial or pass/fail evaluation with no meaningful co-design obligations.
-
open-legal-products Skill Tender DocumentsDraft an invitation to tender or prepare a tender in a Finnish public procurement under the Public Procurement Act (1397/2016): suitability requirements, award criteria, handling and comparison of tenders, tender compliance, consortia, and trade secret markings.
-
open-legal-products Skill Gdpr Records Of ProcessingBuild and validate the records of processing activities (RoPA) required by GDPR Article 30: the controller register under Article 30(1) and the processor register under Article 30(2), enforcing every mandatory field - purposes, categories of data subjects and data, recipients, third-country transfers and safeguards, erasure time limits, and security measures. Flags activities that trigger a DPIA and tests the narrow Article 30(5) exemption. Use when creating a RoPA from scratch, auditing an existing register for gaps, or preparing accountability evidence for a supervisory authority. Complements the DPA review workflows, which cover the processor contract itself.
-
open-legal-products Skill Financing And Security InterestsDraft and review Finnish financing agreements and security packages: promissory notes and loan agreements with covenants and acceleration clauses, pledges, real-estate mortgages, floating charges, guarantees and third-party pledges, perfection requirements, priority ranking, and clawback risk.
-
newkayak12 Skill Portfolio PatternUse when someone wants to understand the writing patterns in their portfolio — not what it says but how it reads: passive voice ratio, subject audit, number density, and decision visibility. Triggers on: "패턴 분석해줘", "오너십이 잘 드러나나", "피동형 많이 썼나".
-
newkayak12 Bundle Spring Boot EngineerUse when someone needs to build or extend a Java backend using the Spring ecosystem — wiring up a new REST API, configuring security and authentication, connecting to a database via JPA, or setting up reactive endpoints with Spring Boot 3.x.
-
newkayak12 Skill Skill Trigger ValidatorUse when a skill isn't triggering reliably on natural language or Korean input. Triggers on: "스킬이 트리거 안 돼", "skill not firing", "description 개선해줘", "한국어 트리거 추가해줘", "trigger coverage audit", "skill 발동 조건 점검", "description이 너무 keyword만 있어".
-
charlieviettq Skill Doubt Driven Review 2Adversarial fresh-context review for non-trivial decisions before they stand. Use for production-impacting logic, security-sensitive changes, unfamiliar code, or high-blast-radius architecture choices. Triggers: "doubt check", "adversarial review", "challenge this decision", "second look".
-
charlieviettq Skill Secure API Design 2Design and implement secure APIs—authentication patterns, authorization models, input validation, secrets handling, and safe defaults. Use when designing new endpoints, auth flows, or reviewing API contracts. Triggers: "secure API", "auth design", "JWT", "OAuth", "API best practices".
-
charlieviettq Skill API Security Testing 2Security testing checklist for HTTP APIs—authn/z, input validation, rate limits, sensitive data exposure, and common OWASP API issues. Use when reviewing or testing REST/GraphQL endpoints before release. Triggers: "API security", "pen test API", "OWASP API", "auth test", "security test".
-
takusaotome Bundle Audit Doc CheckerReview audit-related documents (control design documents, bottleneck analyses, requirements definitions, etc.) for quality, scoring them 0-100 with a severity-rated findings list. Use when reviewing audit documents, checking control design quality, or verifying cross-document consistency. Supports documents governed by US GAAP, IFRS, or J-GAAP.
-
kesslernity Bundle Cdo Reviewer 3Reviews a proposal, business case, deck or plan in character as a Chief Data Officer archetype and returns a DRAFT review in the chat with a verdict, findings that cite the exact passage, data and AI governance risks, what would change the verdict and five interrogation questions. Use when the user asks to "run a CDO review", "pressure-test the data governance in this plan", "what would a CDO say about this", "check the metric definitions and data sources" or "prepare this for the data governance board". Do not use for security controls or third-party security risk, use ciso-reviewer instead; for contract, liability or regulatory terms, use general-counsel-reviewer. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Cto Reviewer 3Reviews a proposal, business case, deck or plan in character as a Chief Technology Officer archetype and returns a DRAFT review in the chat with a verdict, findings cited to the exact passage, technology risks (architecture, build versus buy, vendor lock-in, security of design, engineering capacity), what would change the verdict and five interrogation questions. Use when the user asks to "run a CTO review", "pressure-test the technical side of this plan", "what would a CTO ask about this" or "rehearse the technology seat before the review". Do not use for cash, payback or budget questions, use cfo-reviewer instead; for capacity and timeline questions, use coo-reviewer; for security controls, privacy or compliance, use ciso-reviewer. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Audit Prep PackPrepares a DRAFT internal audit pack from the audit plan: scope as stated, criteria with clauses quoted from the documents provided, document requests per auditee with due dates, open interview questions per process and role, previous findings to follow up and a readiness checklist. Never pre-judges conformity, writes findings or selects the sample; the lead auditor decides. Use when the user asks to "prepare the internal audit", "build the audit pack from this plan", "draft the document requests and interview questions" or "get us ready for the supplier audit". Do not use for evidence requests built from a control list, use control-evidence-request-pack instead; to chase actions from earlier audits, use corrective-action-tracker. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Rfp Response DrafterDrafts answers to the questions in a received RFP, RFQ or tender from the organisation's past responses, answer library, case studies, policies and other documents provided: one row per buyer question with a draft answer marked Reused, Adapted or Missing, its source and date, and a legal or pricing review flag on every answer touching terms, liability, warranties, insurance, data protection or price. Use when the user asks to "draft our RFP response", "answer this tender from our past proposals", "pre-fill the bid questions", "first pass at the RFQ answers" or "reuse our previous bid content". Do not use for writing the buyer's own RFP or requirements, use rfp-requirements-pack instead; for security or due diligence questionnaires use vendor-security-questionnaire-prefill; for scoring received supplier responses use rfp-comparison-pack. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Ciso Reviewer 3Reviews a proposal, business case, deck or plan in character as a Chief Information Security Officer archetype and returns a DRAFT review with a verdict, findings cited to specific passages, security and compliance risks and the five interrogation questions a real CISO would ask. Use when the user asks to "run a CISO review", "pressure-test the security of this plan", "what would our CISO say about this" or "check the privacy and third-party risk". Do not use for contract, liability or regulatory-interpretation reviews, use general-counsel-reviewer instead. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Board Paper SkeletonBuilds a DRAFT board paper skeleton from the sponsor's inputs: purpose, recommendation as the sponsor states it, options including do nothing, risks, financials exactly as provided, authority to decide and the decision sought, with every claim tagged evidenced, asserted or UNKNOWN so the sponsor sees what still needs support. Use when the user asks to "draft a board paper", "structure the committee paper", "prepare the decision paper for the investment committee", "skeleton the board memo" or "what goes in the paper for the audit committee". Do not use for a pre-read or briefing pack with no resolution sought, use executive-briefing-pack instead; to record a decision already taken in a discussion, use decision-memo-builder. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Policy Gap ReviewCompares one policy against one requirement set (standard, regulation, contract schedule or customer requirement) clause by clause and returns a draft gap review: each requirement element, the policy clause that appears to address it, an apparent match state, and every gap as a question with the clause reference on both sides. Never concludes that the policy complies; the owner decides. Use when the user asks to "gap our policy against the standard", "map this policy to the regulation clause by clause", "check the security policy against the customer's contract schedule", "compare our policy with the new edition" or "where does our policy fall short of the requirements". Do not use for mapping a requirement to the operating controls that implement it, use controls-gap-pack instead; for what a regulatory change means for the organisation, use regulatory-change-impact-note. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Risk Register UpdateReads a risk register together with meeting notes and incident reports and returns a draft update pack: existing risks whose exposure, controls, ownership or status the sources say have changed, new risk candidates, closure candidates, and the one owner decision each item needs. Never assigns or changes a likelihood, impact, score or colour and never edits the register; owners decide. Use when the user asks to "update the risk register from these minutes", "refresh the register with the incidents since the last review", "reconcile the register against the notes" or "what changed on our risks". Do not use for writing up an incident itself, use incident-postmortem-drafter or data-incident-impact-brief instead; to track actions from minutes, use corrective-action-tracker. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Export Review Pack 2Reads one export transaction, order or shipment description and returns a DRAFT export review pack: parties to screen with a screening checklist, an item classification worksheet, a red-flag review, licence-determination questions and open items. Use when the user asks to "prepare the export review for this order", "pre-check this shipment for export control", "who do we need to screen on this deal", "build the classification worksheet for this item" or "assemble the trade-compliance file for this technology transfer". Do not use for vendor security or due-diligence screening of a supplier's questionnaire answers; use vendor-risk-screening-brief instead. Never classifies, screens, clears, decides licence need or releases a shipment; trade compliance does. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Procurement Reviewer 3Reviews a proposal, business case, deck or vendor contract in character as a Head of Procurement archetype and returns a DRAFT review in the chat with a verdict, findings that cite the exact passage or clause, commercial risks, what would change the verdict and five interrogation questions. Use when the user asks to "review this from a procurement angle", "what would procurement say about this proposal", "pressure-test this vendor contract commercially", "find the holes before the sourcing committee" or "check the renewal terms like a Head of Procurement would". Do not use for liability, IP, regulatory or signing-authority questions, use general-counsel-reviewer instead; for whether the spend fits the budget, use cfo-reviewer; for vendor security, use ciso-reviewer. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Software Request ReviewReviews one employee software request (tool, purpose, users, data handled, cost, urgency) against the approved-tools list and the policies the user provides and returns a draft review for the reviewer: match state on the list with the row quoted, approved tools the list itself describes as covering the same need, policy clauses that bear on the request with quoted text, questions for the requester and the reviewer, and one suggested decision with its basis. Never approves, procures, installs or adds a tool to the list. Use when the user asks to "review this software request", "is this tool on the approved list", "check this request against our software policy", "do we already have something approved that does this" or "prepare the decision note for this tool request". Do not use for a full vendor security assessment, use vendor-risk-screening-brief instead; for sorting mixed requests, use request-intake-triage. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Corrective Action TrackerTurns corrective and preventive actions from NCRs, audit reports, action forms, minutes or a tracker into one DRAFT tracker: action as stated, source, owner, due date, evidence expected and status, with flags for overdue, unowned, undated, stale and closed-without-evidence items and one question per flag. Never closes, verifies, reassigns or re-dates an action. Use when the user asks to "build the CAPA tracker", "update the corrective action log from these audit reports", "which actions are overdue or have no owner" or "draft the chase notes for open actions". Do not use for writing up the nonconformity itself, use nonconformance-report-drafter instead. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Data Incident Impact BriefPrepares a DRAFT data incident impact brief from the incident notes and data inventory the user provides: the timeline as stated, systems involved matched to the inventory, data categories held and evidenced as involved, people and record counts potentially affected with the source and method behind every figure, third parties, notification questions for legal and the data protection officer, and every UNKNOWN with the evidence that would settle it. No legal determination: it never states whether the incident is a reportable breach, whether notice is due, to whom or by when. Use when the user asks to "prepare the impact brief for this incident", "what data was involved", "how many people are affected", "map the incident to our data inventory" or "pull together what legal needs on the incident". Do not use for the blameless postmortem or root-cause timeline, use incident-postmortem-drafter instead. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Controls Gap Pack 2Produces a draft controls and gap pack from a requirement, regulation, standard or policy and the organisation's control descriptions: obligations broken out of the source text, the controls that appear to address each, apparent coverage, gaps, questions for control owners and actions to assess. Never concludes compliance or that a control is effective; owners and audit assess. Use when the user asks to "map this regulation to our controls", "run a controls gap analysis", "break this standard into obligations" or "where is our control coverage thin". Do not use for comparing a policy document against a standard, use policy-gap-review instead; to draft evidence requests from the mapped controls, use control-evidence-request-pack. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Vendor Risk Screening BriefPrepares a DRAFT vendor risk screening brief from the material the user provides on one vendor (questionnaire answers, certificates, assurance reports, policies, contract extracts): per screening topic, what a document evidences with reference, date and scope, what is only asserted, what is missing or contradicted, certificate and report details as stated, and ready-to-send questions for the vendor and the internal owners. No web research, no risk rating, tier, score or recommendation. Use when the user asks to "screen this vendor", "review the vendor's questionnaire answers", "check what the vendor's certificate covers", "what is missing from this due diligence pack" or "draft the follow-up questions for the vendor". Do not use for answering a customer's questionnaire about your own organisation, use vendor-security-questionnaire-prefill instead. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle General Counsel Reviewer 3Reviews a proposal, business case, deck, plan or contract summary in character as a General Counsel archetype and returns a DRAFT review in the chat with a verdict, findings that cite the exact passage or clause, legal risks, what would change the verdict and five interrogation questions. Meeting preparation, not legal advice. Use when the user asks to "run a general counsel review", "what would legal say about this", "pressure-test the legal exposure in this deal" or "prepare me for the deal committee". Do not use for price, term, renewal or vendor leverage, use procurement-reviewer instead; for lawful basis and data flows, use cdo-reviewer; for security controls, use ciso-reviewer. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Claims Evidence MapBuilds an evidence map for one document, section or contested claim: every factual claim extracted verbatim and numbered, its supporting passage in the supplied sources or UNKNOWN, the strength of that support as evidenced, contradictions between sources, and the specific question or document that would close each gap, returned in the chat as Markdown tables for the author or reviewer. Use when the user asks to "check what this document actually proves", "map the evidence behind these claims", "which of these statements are supported", "build an evidence map", "what would we need to back this up" or "is this claim substantiated". Do not use for requesting evidence of security controls from control owners, use control-evidence-request-pack instead. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Control Evidence Request PackTurns a control list and an audit scope into draft evidence requests grouped by control owner, each with the control as stated, the audit period, evidence examples (commonly requested) and a proposed due date derived from the fieldwork dates. Never judges whether evidence is sufficient, never selects the sample and never sends a request; the auditor decides. Use when the user asks to "prepare the evidence requests", "draft the PBC list", "build the evidence request pack for the audit" or "what do we need to ask each control owner for". Do not use for document requests and interview questions built from an audit plan, use audit-prep-pack instead; to check claims in a report against sources, use claims-evidence-map. Drafts for human review; never approves, authorises or signs off.
-
takusaotome Bundle Compliance Advisorコンプライアンス・内部統制支援の専門スキル。J-SOX/SOX対応、リスクコントロールマトリクス(RCM)作成、 内部監査計画策定をサポート。内部統制の整備・運用評価から監査対応まで一貫した支援を提供。 日英両言語のテンプレートを提供し、グローバル企業にも対応。COSO内部統制フレームワーク(2013年版)に準拠。 Use when: creating J-SOX/SOX compliance documentation, building risk control matrices, planning internal audits, or assessing internal control effectiveness. Triggers: "J-SOX", "SOX", "内部統制", "コンプライアンス", "RCM", "リスクコントロールマトリクス", "内部監査", "compliance", "internal control", "internal audit", "risk assessment", "COSO"
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include test-master, bias-auditor, nonconformance-report-drafter. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.