Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
takusaotome Bundle Salesforce CLI ExpertThis skill should be used when generating Salesforce CLI commands for tasks like authenticating to orgs, querying data with SOQL, retrieving metadata (profiles, permission sets, security settings), deploying configuration changes, or automating security audits. Use when the user describes what they want to accomplish with Salesforce and needs the specific CLI command syntax.
-
takusaotome Bundle Audit Control DesignerGenerate audit-ready internal control design documents from As-Is business process inventories. Produces control IDs, assertion mappings, procedures, SoD analysis, KPIs, materiality thresholds, and implementation roadmaps. Use when building internal controls for new audit engagements, SOX/J-SOX compliance, or process improvement initiatives.
-
takusaotome Bundle Internal Audit AssistantInternal audit support skill aligned with IIA (Institute of Internal Auditors) International Standards. Provides risk-based audit planning, audit program development, workpaper documentation, finding development (Condition/Criteria/Cause/Effect), and Corrective Action Request (CAR) tracking. Use when: planning annual/quarterly audits, creating risk assessment matrices, developing audit programs and test procedures, documenting audit workpapers, writing audit findings and reports, tracking corrective actions and follow-ups, preparing for external audits (SOX, ISO). Triggers: "internal audit", "audit plan", "audit program", "audit workpaper", "audit finding", "risk assessment", "CAR tracking", "corrective action", "IIA Standards", "COSO framework", "監査計画", "監査プログラム", "監査調書", "是正措置", "リスク評価".
-
takusaotome Bundle Web Server Security ReviewerWeb サーバ(nginx/apache、Linux 中心)の Phase 1 設定セキュリティレビュー。 target_profile.yaml で対象を確定し、MANIFEST.txt + manifest_attestation.txt で証跡 integrity を検証。 SSH 直接または証跡受領モードで 9 観点 (OS/リソース/ログ/ネットワーク/サービス/認証/監視/バックアップ/証明書) を read-only 走査。6 階層ガード (allowed/conditional/conditional_sensitive/ask-first/exceptional_sensitive_read/forbidden)、 3 軸補助 (Exploitability/Blast Radius/Service Criticality) の重大度判定、 observation_status による未確認の独立管理、evidence_dir/raw_evidence_store 分離、自己レビュー必須。 Windows/IIS は v1 hard fail。 Use when: Web サーバの設定セキュリティレビュー、Phase 1 監査、nginx/apache 構成監査、 EOL ランタイム調査、ログローテーション不備調査、ドキュメントルート漏えい調査。
-
takusaotome Bundle Pci Dss Compliance ConsultantPCI DSS 4.0.1 compliance audit support skill. Provides expert guidance for Cardholder Data Environment (CDE) scoping, gap analysis, audit preparation, SAQ completion support, and remediation planning. Includes SOC 2 mapping for combined audit efficiency. Use when preparing for PCI DSS audits, conducting gap analysis, creating remediation plans, or answering SAQ questionnaires for payment card compliance.
-
takusaotome Bundle Design Implementation ReviewerUse this skill for critical code review that focuses on whether the code actually works correctly and achieves the expected results - not just whether it matches a design document. This skill assumes designs can be wrong, finds bugs the design didn't anticipate, and verifies end-to-end correctness. Triggers include "critical code review", "deep code review", "verify this implementation works", "find bugs in this code", or reviewing implementation against requirements. NOTE - Security review is OUT OF SCOPE; use a dedicated security review skill for that purpose.
-
forexgod21 Bundle Human SignalAudit and rewrite content to remove AI writing patterns and restore authentic human voice. Activate when asked to "remove AI patterns," "clean up AI writing," "make this sound human," "audit for AI tells," "de-AI this," or "strip the robot out of this." Supports a scan-only mode that flags patterns without rewriting. Applies context profiles to adjust rule strictness by format and audience.
-
forexgod21 Bundle De Skilling GuardUse when detecting, preventing, or reversing the erosion of human capability caused by over-reliance on AI. Triggers on "my team is losing skills because of AI", "my team can't function without the AI anymore", "how do I keep humans capable when AI does the work", or any request to audit de-skilling risk and design AI-human workflows that preserve human expertise.
-
forexgod21 Bundle Security Review V2Performs structured security review and red-team style analysis with evidence-first findings, exploit paths, fixes, and verification requirements.
-
forexgod21 Bundle Emergent Value AuditUse this skill whenever the user needs to surface implicit AI preferences and value weightings before deploying an AI system. Triggers when the user asks about hidden AI biases, implicit optimization targets, or says things like "what is my AI actually optimizing for", "are there hidden preferences in my AI system", "audit my AI for implicit values before deployment", "what assumptions are baked into my AI's behavior", or "I want to know what my AI values before I release it." Always activate this skill when the user needs a structured audit of emergent AI values — the implicit preferences, weightings, and objectives that were not explicitly programmed but have emerged through training, design, or deployment patterns.
-
forexgod21 Bundle Value Convergence GuardUse when setting up continuous monitoring that checks an AI system's ongoing outputs against its intended values — a persistent operational guard, not a one-time audit. Triggers on "monitor whether my AI is converging on the right values", "set up ongoing alignment checks", "guard against my AI converging on unintended values", or any request for continuous value-alignment verification.
-
forexgod21 Bundle Utility Control ProtocolUse when redirecting an AI system's active optimization behavior back toward sanctioned targets after divergence, drift, or misaligned exchange rates have been identified. Triggers on "my AI is optimizing for the wrong thing — fix it", "implement a utility correction protocol", "my value audit found misalignment — now what", or any request for a structured intervention to realign AI behavior with authorized values.
-
forexgod21 Bundle Algorithmic Management AuditActivate when evaluating, designing, or repairing any system where software directs, evaluates, or disciplines human work: gig platforms, AI-assisted management tools, productivity monitoring, automated scheduling, algorithmic performance scoring, or agentic systems that assign tasks to people. Audits the system across the six control functions of algorithmic management and scores its human cost against its control benefit.
-
ryankolean Skill Mentor PerelCoaching through Esther Perel's published frameworks. Apply when the user needs advice on relationships, workplace dynamics, desire vs security tensions, or navigating ambiguity in human connection. Trigger with "ask Perel", "what would Perel do", or "Perel mode".
-
tomjiu Skill Offensive MethodologyUse when planning authorized penetration testing or offensive assessment methodology — phases, tool map (download/install/run pointers), engagement hygiene. Distilled from community awesome lists. Does not include exploit payloads, shellcode, or copy-paste attack strings. Prefer for knowing which tools/chains exist.
-
tomjiu Skill Authorized Analysis ScopeUse before reverse engineering, security testing, firmware, mobile instrumentation, or automation against live systems — write explicit authorization and scope; refuse unclear targets.
-
harsh817 Bundle Outcome DefinitionDefine or audit the concrete app outcome before breaking work into features. Use when starting a product, clarifying an existing project, turning a vague idea into a buildable target, or checking whether proposed features serve the real user outcome.
-
harsh817 Bundle Data Migration AuditAudit data and migration readiness before production. Use when checking schema constraints, transactions, migration safety, compatibility, backups, restore tests, data-loss risks, and rollback implications.
-
harsh817 Bundle Security Readiness AuditAudit security readiness before production. Use when reviewing authentication, authorization, input validation, secrets, dependency risks, data exposure, privacy, abuse paths, and unsafe interactions for a release or system.
-
harsh817 Skill Testing RulesDefine or audit required tests, test locations, behavioral seams, fixtures, and verification expectations. Use when adding features, fixing bugs, planning coverage, or preventing tests from coupling to implementation details.
-
ryankolean Skill Automate AuditInterview the user about their daily and weekly routines, then produce a ranked list of automation opportunities with effort-vs-impact scoring. Activates when the user asks "what should I automate?", "audit my workflow", "find my time wasters", or when they describe repetitive frustrations. Serves both technical and non-technical users.
-
yogsoth-ai Skill Benchmark Audit 2Systematic quality assessment using BetterBench 46-criterion framework — 5 benchmarks, 30 papers, 40 web searches
-
yogsoth-ai Bundle Benchmark Synthesis 2Produce final structured audit report
-
yogsoth-ai Bundle Contamination Audit 2Detect train-test data leakage and memorization artifacts
-
yogsoth-ai Bundle Documentation Audit 2Assess documentation completeness against BetterBench/Datasheets standards
-
yogsoth-ai Bundle Reproducibility Checklist Audit 2---
-
jorinyang Bundle Requesting Code ReviewPre-commit review: security scan, quality gates, auto-fix.
-
deankelly751 Skill Review APIEvaluate API design for consistency, correct HTTP semantics, error handling, pagination, versioning, security, and documentation quality. Covers REST and GraphQL.
-
deankelly751 Skill Review SecurityIdentify security vulnerabilities, auth weaknesses, injection risks, secrets exposure, and access control issues. Categorizes findings by OWASP Top 10. Produces a severity-rated security review report.
-
deankelly751 Skill Knowledge Owasp Top 10OWASP Top 10 vulnerability categories with code-level examples and specific mitigations. Use when reviewing code for security issues, designing secure APIs, or advising on common web application vulnerabilities.
-
deankelly751 Skill Knowledge Auth PatternsAuthentication and authorization patterns with trade-offs, implementation guidance, and common mistakes. Covers sessions, JWTs, OAuth/OIDC, API keys, mTLS, RBAC, ABAC, and ReBAC. Use when designing auth systems, reviewing auth implementations, or choosing between auth approaches.
-
deankelly751 Skill Knowledge Secure By DesignSecurity as an architectural property — principles, patterns, and decision frameworks for building systems that are secure by construction rather than by bolt-on controls. Use when designing systems, reviewing architecture, or making security trade-off decisions.
-
deankelly751 Skill Knowledge Privacy By DesignPrivacy as an architectural property — data minimization, purpose limitation, consent management, GDPR/CCPA engineering implications, data classification, retention policies, and right to erasure patterns. Use when designing systems that handle PII, implementing data protection features, or reviewing data flows for privacy compliance.
-
deankelly751 Skill Review Production ReadinessComprehensive assessment of whether a system is ready for production traffic. Covers observability, reliability, security, operations, and scalability. The most thorough reviewer — use before launch or major releases.
-
deankelly751 Skill Execution ContainerizationDockerfile best practices, multi-stage builds, image optimization, and container security. Step-by-step procedure for containerizing services. Use when creating Dockerfiles, optimizing image size, or reviewing container configurations.
-
harsh817 Bundle Reliability Failure AuditAudit reliability and failure readiness before production. Use when testing dependency failures, retries, timeouts, duplicate requests, concurrency, partial failures, idempotency, recovery behavior, and error handling.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include salesforce-cli-expert, audit-control-designer, internal-audit-assistant. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.