Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
vtex Bundle Architecture Well Architected Commerce 3Apply when scoping, reviewing, or documenting cross-cutting VTEX commerce architecture across storefront, IO, headless, marketplace, payments, or any other VTEX module. Grounds work in the Well-Architected Commerce framework—Technical Foundation (reliability, trust, integrity; security, infrastructure, compliance), Future-proof (innovation, simplicity, efficiency; scalable and adaptable solutions), and Operational Excellence (accuracy, accountability, data-driven improvement; process and customer experience). Routes implementation detail to product tracks (IO caching and paths, Master Data strategy, marketplace integrations). Use for solution design, architecture reviews, and RFP-level technical structure.
-
vivy-yi Skill Account SecurityUse when protecting Xiaohongshu account from unauthorized access, preventing account theft, recovering compromised accounts, or implementing security measures to safeguard account and follower base
-
cinience Skill Aliyun Sas Manage TestMinimal smoke test for Security Center SAS skill. Validate read-only query flow.
-
hnabyz-bot Bundle Moai Platform FirestoreFirebase Firestore specialist covering NoSQL patterns, real-time sync, offline caching, and Security Rules. Use when building mobile-first apps with offline support, implementing real-time listeners, or configuring Firestore security.
-
kubernetes-sigs-kueue Skill Nil SafetyFlag unguarded dereferences of optional pointer fields reachable from a malformed CR, and goroutines without recover (CWE-476).
-
kubernetes-sigs-kueue Skill Path TraversalFlag file paths built from user-supplied names without sanitization, symlink-following in tenant dirs, and unvalidated archive extraction (CWE-22).
-
kubernetes-sigs-kueue Skill Input ValidationFlag missing input validation at trust boundaries — user-settable CR fields, webhook payloads, labels, annotations, or untrusted deserialization (CWE-20, CWE-502).
-
kubernetes-sigs-kueue Skill Supply Chain HygieneFlag supply-chain hygiene gaps — unpinned image refs, TLS bypass, unjustified go.mod replace directives, curl|sh, moving-tag GitHub Actions (CWE-295, CWE-494).
-
kubernetes-sigs-kueue Skill Webhook Safety RegressionsFlag webhook safety regressions — loosened failurePolicy, shortened timeoutSeconds, TLS bypass paths, non-idempotent mutating webhooks.
-
kubernetes-sigs-kueue Skill Feature Gated Insecure PathsFlag feature-gated behavior whose security assumptions do not hold in both gate-on and gate-off states; require a comment near the gate check for new alpha attack surface.
-
aretedriver Bundle HealthProject Health Audit
-
simhacker Bundle Skill SnitchSecurity auditing for MOOLLM skills - static analysis and runtime surveillance
-
ndhananj Skill Postgres Patterns 2PostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices.
-
mmcmedia Bundle Ad AuditAd Audit — Paid Advertising Analysis for OpenClaw
-
sawrus Skill Auth PatternsSkill: Authentication & Authorization Patterns
-
sawrus Skill Crypto StandardsSkill: Cryptography Standards
-
sawrus Skill Dependency AuditSkill: Dependency Audit
-
sawrus Skill Security HeadersSkill: HTTP Security Headers
-
sawrus Skill Sast Dast InterpretationSkill: SAST/DAST Results Interpretation
-
aquariuscook Bundle Security TestingTest for security vulnerabilities using OWASP principles. Use when conducting security audits, testing auth, or implementing security practices.
-
cinience Skill Aliyun Kms Manage TestMinimal smoke test for KMS skill. Validate auth and read-only key listing path.
-
frankxai-agentic-creator-os Bundle Design ReviewDesigner's eye QA: finds visual inconsistency, spacing issues, hierarchy problems, AI slop patterns, and slow interactions — then fixes them. Iteratively fixes issues in source code, committing each fix atomically and re-verifying with before/after screenshots. For plan-mode design review (before implementation), use /plan-design-review. Use when asked to "audit the design", "visual QA", "check if it looks good", or "design polish". Proactively suggest when the user mentions visual inconsistencies or wants to polish the look of a live site.
-
frankxai-agentic-creator-os Skill Design Review 2Designer's eye QA: finds visual inconsistency, spacing issues, hierarchy problems, AI slop patterns, and slow interactions — then fixes them. Iteratively fixes issues in source code, committing each fix atomically and re-verifying with before/after screenshots. For plan-mode design review (before implementation), use /plan-design-review. Use when asked to "audit the design", "visual QA", "check if it looks good", or "design polish". Proactively suggest when the user mentions visual inconsistencies or wants to polish the look of a live site.
-
harshahosur81 Skill Devsecops EngDev Sec Ops Engineer like Guilfoyle
-
kubernetes-sigs-kueue Skill Integration Adapter Trust BoundaryFlag integration adapters reading credential-like fields from third-party CRDs without treating them as untrusted (RayCluster, SparkApplication, JobSet).
-
troykelly-claude-skills Skill Postgres RlsMANDATORY when touching auth tables, tenant isolation, RLS policies, or multi-tenant database code - enforces Row Level Security best practices and catches common bypass vulnerabilities
-
troykelly-claude-skills Skill API DocumentationUse when API code changes (routes, endpoints, schemas). Enforces Swagger/OpenAPI sync. Pauses work if documentation has drifted, triggering documentation-audit skill.
-
troykelly-claude-skills Skill Documentation AuditUse when documentation drift is detected. Comprehensively audits codebase and creates/updates Swagger, features docs, and general documentation to achieve full sync.
-
troykelly-claude-skills Skill Features DocumentationUse when user-facing features change. Ensures features documentation is updated. Pauses work if documentation has drifted, triggering documentation-audit skill.
-
bybren-llc Bundle Safe AI Dlc 2Plan and run programs using the SAFe x AI-DLC fusion. Use when turning an audit, epic, or initiative into Linear structure (initiative, projects, milestones, issues, sub-issues), organizing work as Units of Work and Bolts, wiring a dependency DAG, or running a Bolt swarm with a human-in-the-loop gate.
-
bybren-llc Bundle Rls Patterns 2Row Level Security patterns for database operations. Use when writing Prisma/database code, creating API routes that access data, or implementing webhooks. Enforces withUserContext, withAdminContext, or withSystemContext helpers. NEVER use direct prisma calls.
-
bybren-llc Bundle Security Audit 2RLS validation, security audits, OWASP compliance, and vulnerability scanning. Use when validating RLS policies, auditing API routes, scanning for security issues, or reviewing code for vulnerabilities.
-
hnabyz-bot Bundle Moai Tool Ast GrepAST-based structural code search, security scanning, and refactoring using ast-grep (sg CLI). Supports 40+ languages with pattern matching and code transformation.
-
harshahosur81 Skill Defense In DepthDefense in Depth Skill
-
harshahosur81 Skill Security ArchitectSecurity Architect Skill
-
harshahosur81 Skill Dependency Management Deps AuditYou are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, ou
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include architecture-well-architected-commerce, account-security, aliyun-sas-manage-test. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.