Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
inspirai-store Skill Scan全量扫描已安装的 skills/commands,分析功能重叠并生成报告
-
inspirai-store Skill Resolve交互式处理功能重叠 - 根据扫描报告逐组确认保留或禁用
-
jdutton Bundle Release AnnounceAnnounce a tagged release to the team channel. Use when a release tag is pushed and a summary of the changelog highlights needs to be posted to chat.
-
jdutton Bundle Categorizing ExpensesCategorize expense-report line items into GL accounts. Use when a user has an expense export and needs each line mapped to a general-ledger code, with low-confidence matches flagged for review.
-
ndhananj Bundle Security Review 3Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
-
ndhananj Bundle Security Review 4Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
-
fdu-ins Skill Usap CisoCISO and executive security advisor (cs-ciso-advisor). Use for board reports, executive risk briefings, regulatory gap assessments, cyber insurance inputs, or when the user says "board report", "CISO brief", "executive summary", "risk posture for leadership", or "regulatory update".
-
techwavedev Skill Codebase Audit Pre PushDeep audit before GitHub push: removes junk files, dead code, security holes, and optimization issues. Checks every file line-by-line for production readiness.
-
techwavedev Skill Production Code AuditAutonomously deep-scan entire codebase line-by-line, understand architecture and patterns, then systematically transform it to production-grade, corporate-level professional quality with optimizations
-
s3yed Bundle Productized Service Business 2Validate, launch, and deliver productized service businesses, service-first SaaS wedges, managed marketplaces, and audit/retainer offers. Use when the user asks which business idea is worth doing, wants competitor or Dutch/NL market validation, wants a monetization ladder, wants to validate a service before building software, or wants delivery SOPs/templates for a first paid client offer such as Review-to-Revenue / Customer Voice Conversion Audits.
-
fabioc-aloha Skill Markdown Sanitization Chain 3Markdown sanitization order matters — marked.js then DOMPurify then Mermaid to prevent XSS
-
aiescu Bundle Security And HardeningHardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when auditing dependencies for known vulnerabilities, triaging package-manager audit findings, or assessing supply-chain risk in a new package. Use when personal data or privacy compliance (GDPR, CCPA) is involved.
-
ngxtm-devkit Bundle Senior SecopsComprehensive SecOps skill for application security, vulnerability management, compliance, and secure development practices. Includes security scanning, vulnerability assessment, compliance checking, and security automation. Use when implementing security controls, conducting security audits, responding to vulnerabilities, or ensuring compliance requirements.
-
duclm1x1 Skill BottubeSecurity and Permissions
-
duclm1x1 Skill Data Lineage TrackerTrack data origin, transformations, and flow through construction systems. Essential for audit trails, compliance, and debugging data issues.
-
duclm1x1 Skill Virustotal Security ScannerScan files and URLs using VirusTotal API via curl or Python utilities. Check hashes, upload files, and manage comments.
-
ncoevoet Skill LeakyCalls the billing API for invoice data. Use when the user asks about invoices, billing, or payment records.
-
ncoevoet Bundle Scanner DocDocuments which session files the scanners read. Use when the user asks how the audit gathers telemetry from `session.jsonl` or which paths it scans on disk.
-
rysweet Bundle Merge Ready 2Checks whether a PR/pull request satisfies the project's merge criteria and records the required evidence in the PR/pull request description. Use with `/merge-ready` before review or merge when QA-team scenarios, docs links, quality-audit convergence, checks/build validation status, and diff scope must be verified.
-
rysweet Skill Reviewing Code 2Performs systematic code review checking for correctness, maintainability, security, and best practices. Activates when user requests review, before creating PRs, or when significant code changes are ready. Ensures quality gates are met before code proceeds to production.
-
maslennikov-anton Bundle Doubt Driven DevelopmentПроверять high-risk решения свежим скептическим pass: claims, assumptions, irreversible changes, security, unfamiliar code и дорогие ошибки.
-
maslennikov-anton Bundle Source Driven DevelopmentUse when a decision depends on exact current version, official docs, deprecations, external API behavior, security defaults, or citations; skip local-only code.
-
drmoisan Skill Policy Audit Template Usage 5Converted skill
-
drmoisan Skill Skill Canonical Location Audit 7Converted skill
-
drmoisan Skill Evidence And Timestamp Conventions 7Converted skill
-
drmoisan Skill Remediation Handoff Atomic Planner 7Converted skill
-
kaiohenricunha Bundle Terragrunt Specialist 2Deep-dive Terragrunt hierarchy review, DRY pattern audits, and run-all orchestration analysis. Use for structured investigations of multi-environment Terragrunt layouts, dependency graphs, remote state config, and hook correctness. Triggers on: "Terragrunt audit", "run-all review", "dependency block", "DRY pattern review", "env hierarchy audit", "mock_outputs", "terragrunt hooks".
-
hironow Bundle Security Best PracticesPerform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
-
1t1scool Skill Aif ReviewPerform code review on staged changes or a pull request. Checks for bugs, security issues, performance problems, and best practices. Use when user says "review code", "check my code", "review PR", or "is this code okay".
-
dubsopenhub Bundle Codeql Mastery🛡️ CodeQL Mastery — SOSS Fund expert on GitHub CodeQL and code scanning. Ask any question about CodeQL, code scanning, QL queries, vulnerability detection, community packs, or database internals. Validates security features via GitHub API and tracks call-to-action completion for dashboard reporting. Say "codeql" to start.
-
dubsopenhub Bundle Soss Module Id🛡️ SOSS Fund Training — MODULE_TITLE. Interactive trainer with CTA tracking, security validation, and dashboard-ready data export. Say "MODULE_TRIGGER" to start.
-
x-cmd Skill Cve 4通过 x cve 查询 CVE 记录 —— 缓存、零 API key、按日 xz TSV。 加载条件:cve、vulnerability id、kev、epss、nvd、cvelist 或 security advisory。
-
first-fluke Bundle Oma Scm 3SCM (software configuration management) and Git: branching, merges, conflicts, worktrees, baselines, audit readiness, plus Conventional Commits and safe staging.
-
mturac Skill Ecc Tools Cost Audit 3ecc ツール、エージェント、スキル、および実装のコスト監査を実施します。プロンプト入力トークンを分析して、計算効率を定量化します。
-
kaiohenricunha Skill Create Audit 2Create an evidence-based audit document and save it to docs/audits/. Triggers on: "audit", "review", "assessment".
-
kaiohenricunha Bundle Validate Spec 2Audit an already-implemented spec against the codebase. Walks each constraint (ARCH-N, PERF-N, KD-N, etc.) and acceptance criterion, grounds findings in file:line evidence, runs the spec.json acceptance_commands, and writes a single audit doc to docs/audits/. Use whenever the user asks to "validate a spec", "audit a spec", "check if spec is implemented", "verify the spec is done", "is this spec really done", or otherwise wants closure on spec-driven work. Read-only against the spec — produces an audit, never modifies the spec itself.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include scan, resolve, release-announce. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.