Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
kaiohenricunha Skill Security Review 2Analyze a diff or changed files for common security vulnerabilities (injection, XSS, SSRF, secrets). Defaults to staged changes. Triggers on: "security review", "check for secrets", "vulnerability scan".
-
bh611627 Skill Typescript RefactorRefactor JavaScript to strict TypeScript or audit types - incremental .js to .ts with explicit return types
-
jorgeasaurus Bundle Powershell Code ReviewProduction-readiness code review for PowerShell scripts and modules using Elon Musk's 5-Step Design Process. Use when auditing PowerShell code for Fortune 100 enterprise environments. Ruthlessly eliminates unnecessary code, challenges every abstraction, and produces a structured markdown report covering critical issues, recommended deletions, security risks, and production readiness.
-
devguyrash Bundle PHP DevelopmentUse for substantive PHP source, Composer, or tooling. Covers types, APIs, errors, resources, and security-sensitive behavior; exclude framework-only work.
-
devguyrash Bundle Rust DevelopmentUse for substantive Rust source, Cargo, or tooling. Covers ownership, APIs/errors, workspaces, MSRV, and verification; compose async-rust, unsafe-rust, or rust-panic-audit as needed; exclude workflow-only work.
-
devguyrash Bundle Rust Panic AuditUse when direct-panic auditing is explicit, policy-required, or material at a hostile-input, embedded, FFI, or high-availability boundary. Compose with rust-development; exclude routine review.
-
josstei Skill Security AuditRun a Maestro-style security assessment for authentication, authorization, data exposure, secret handling, and exploitability risks
-
josstei Skill Security Audit 2Run a Maestro-style security assessment for authentication, authorization, data exposure, secret handling, and exploitability risks
-
hezaohezao Skill Requesting Code ReviewPre-commit review: security scan, quality gates, auto-fix.
-
skywatch-bsky Bundle Skywatch Scanning The NetworkProactive network-wide threat scanning over a specified time window. Use when looking for emerging threats, incident upticks, anomalous network traffic, coordination patterns, or detection gaps.
-
skywatch-bsky Skill Scanning The NetworkProactive network-wide threat scanning over a specified time window. Use when looking for emerging threats, incident upticks, anomalous network traffic, coordination patterns, or detection gaps.
-
dtsong Skill Data Classification 2Use when classifying data elements by sensitivity tier and defining per-tier handling requirements. Covers data inventory, sensitivity classification, PII flow mapping, encryption and masking specifications, and cross-boundary transfer documentation. Do not use for regulatory gap analysis (use compliance-review) or audit logging design (use audit-trail-design).
-
farmage Bundle Test Master 2Generates test files, creates mocking strategies, analyzes code coverage, designs test architectures, and produces test plans and defect reports across functional, performance, and security testing disciplines. Use when writing unit tests, integration tests, or E2E tests; creating test strategies or automation frameworks; analyzing coverage gaps; performance testing with k6 or Artillery; security testing with OWASP methods; debugging flaky tests; or working on QA, regression, test automation, quality gates, shift-left testing, or test maintenance.
-
jensen-yao Bundle Improve UIAudit an existing product surface against its own design evidence and write implementation plans. Strictly read-only on product source. Use only when explicitly invoked or selected by ui-skills-root, and never combine it with a modifying skill in the same execution.
-
jensen-yao Skill UI Skills RootUse automatically as the sole routing entry for UI-related work. Before implementation, select the smallest useful UI skill context with the globally installed ui-skills CLI (fall back to npx ui-skills). Prefer one narrow skill, and never combine a read-only audit skill with a modifying skill in the same execution. If the registry reports an ambiguous slug, use its namespaced slug such as emilkowalski/prototype; local-only skills such as app-shell-ui must be handled explicitly.
-
thoughtspot Bundle TS AuditScan a ThoughtSpot environment across five angles — AI Readiness, Data Modeling, Human Readiness, Performance, Security — and generate a prioritised audit report with actionable recommendations linking to existing skills.
-
thoughtspot Bundle TS Dependency ManagerSafely audit, remove, or repoint columns and objects across a ThoughtSpot environment — generates a risk-rated impact report, backs up TML before any change, and supports full rollback.
-
thoughtspot Bundle TS Object Calendar BuilderBuild ThoughtSpot custom calendars that the native API cannot express — week-aligned fiscal years, 4-4-5 / 4-5-4 / 5-4-4 / 13-period patterns with correct 52/53-week tiling, localized or abbreviated labels, calendar-year vs fiscal-year month labelling, and RLS union calendars spanning multiple tenants. Use whenever someone asks for a retail calendar, a 4-4-5 or 4-5-4 calendar, a fiscal calendar starting on a specific weekday ("first Monday of February"), a 13-period calendar, a custom calendar table for Snowflake, or a per-group calendar resolved by row-level security. Also use when an existing calendar's month labels show the wrong year. Not for standard month-offset fiscal calendars, which the ThoughtSpot API already handles natively.
-
dojogenesis Bundle Health Audit 2> **OpenClaw Integration:** This skill is invoked by the Dojo Genesis plugin via `/dojo run health-audit`.
-
dojogenesis Bundle Documentation Audit 2> **OpenClaw Integration:** This skill is invoked by the Dojo Genesis plugin via `/dojo run documentation-audit`.
-
dojogenesis Bundle Skill Audit Upgrade 2> **OpenClaw Integration:** This skill is invoked by the Dojo Genesis plugin via `/dojo run skill-audit-upgrade`.
-
neomjs Bundle Pr ReviewStandardized guidelines and templates for structuring Pull Request reviews so feedback is actionable, encouraging, and extractable by the Native Edge Graph. MANDATORY ROI WARNING: Skipping the review template guarantees CI lint failure. Triggers: Reviewing a PR (yours or peer's) — structured eval metrics, graph ingestion tags, severity ladder, restates §0 merge gate, post-comment A2A commentId hand-off (reviewer→author) per guide §10, Evidence Audit + Source-of-Authority sections (template §) for substrate/runtime-AC PRs and authority-citation review-comments.
-
prayceo Skill Linkedin Profile AnalyzerAnalyze any LinkedIn profile end-to-end — pull the top 50 most-liked posts, download every photo, rewrite each post as a viral original using Gatena Cookbook + Welsh Brain frameworks, and generate an AB-test recommendation memo. Trigger when the user provides a LinkedIn profile URL (linkedin.com/in/...) and asks to analyze it, study it, rank posts, find their best content, get their photos, rewrite their content, learn from their feed, or any variation. Also trigger for "study this LinkedIn profile", "analyze [URL]", "what's working on this profile", "give me the top X posts for [profile]", "rewrite their best posts", "competitor LinkedIn audit", "personal brand teardown", or "build me a LinkedIn engine from this profile".
-
jensen-yao Bundle Improve AnimationsRead-only audit of a codebase's animation and motion, producing prioritized findings and self-contained implementation plans. Run only when explicitly invoked; never combine it with a modifying skill in the same execution.
-
jensen-yao Skill Fixing Motion PerformanceAudit and fix animation performance problems such as layout thrashing, non-composited properties, scroll-linked motion, and costly blur. Use only when explicitly invoked or selected by ui-skills-root for motion-performance work.
-
gktuoktay Skill Pre Flight Security Gate 2Kod yazılmadan önce, Master Orchestrator'un planındaki zararlı istekleri denetleyen kapı.
-
gktuoktay Skill Audit Trail Guardian Gate 2Veritabanı tablolarında denetim izlerini zorunlu kılan kapı.
-
rylaispirit Bundle Creative WritingPlan, draft, revise, and audit creative or long-form writing with a portable core workflow that does not depend on missing legacy templates.
-
rylaispirit Bundle Academic Writing StylePlan, draft, revise, and audit theses, papers, literature reviews, methods, results, and discussions for argument, evidence, structure, citations, and style.
-
cadugevaerd Skill Quality Security GateAudita gates automatizados de qualidade e segurança por risco, sem corrigir o repositório.
-
irahardianto Bundle Guardrails 3Pre-flight checklists before coding, post-implementation self-review after. Catches arch violations, missing observability, security oversights.
-
irahardianto Bundle Code Review 3Structured code review protocol: inspect against full rule set. Use for audit workflows, code reviews, or when user requests review. Produces findings document with severity tags.
-
aethrox Bundle Repo SecureAudit and enable a GitHub repository's own recommended security settings, confirming with the maintainer which ones actually apply before turning anything on. Use when the user wants a repo hardened, asks to enable secret scanning or branch protection, wants a SECURITY.md written, or references GitHub's maintainer security checklist.
-
aethrox Bundle Secure CodingSecure-coding discipline mapped to the OWASP Top 10, checked at the point of writing code, not after. Covers input validation and injection classes, broken access control, secrets handling, dependency/supply-chain risk, and safe error handling/logging. Use when writing code that crosses a trust boundary (handles user input, auth, payments, file paths, external commands, or third-party dependencies), when reviewing a diff for security issues, or when the user asks for a security review, threat check, or "is this safe."
-
aethrox Bundle Diagnosing BugsSystematic debugging discipline based on David Agans' nine rules, understand the system, reproduce reliably, bisect the search space, change one variable at a time, keep an audit trail, and never declare a fix done until it's verified against the original failure. Use when the user reports something broken, throwing, failing, or slow, or says "diagnose" / "debug this".
-
aethrox Bundle Dependency Upgrade ManagementDiscipline for keeping dependencies current and deprecating capabilities safely, an inventory (SBOM) of what's actually shipped, security patches on a fast lane separate from routine/major upgrades, and a stated deprecation window (Sunset/Deprecation headers, N-2 support) before removing anything consumers rely on. Use when upgrading a dependency, triaging a Dependabot/Renovate PR, deciding whether an upgrade is safe to automerge, or planning to deprecate or remove a capability others depend on.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-review, typescript-refactor, powershell-code-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.