Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
l-x-t Bundle Code ReviewCode review changed, staged, last-commit, and merge or PR work against requirements and the repository style guide. Use when reviewing current work, staged changes, the last commit, a branch, a merge, or a pull request. For a whole-codebase style audit use ng-review-style-guide instead.
-
l-x-t Skill Ng SecurityHarden Angular applications against common web vulnerabilities. Use when reviewing or improving app security, preventing XSS, configuring Content Security Policy (CSP) or Trusted Types, working with sanitization / DomSanitizer / bypassSecurityTrust, securing HttpClient (XSRF/CSRF, XSSI), auth and token storage, SSR/SSRF (allowedHosts), or keeping dependencies patched.
-
l-x-t Skill Ng PerformanceOptimize the performance of an Angular (v17+) application – both initial load (bundle size, lazy loading, deferrable views, images, SSR/SSG/hydration) and runtime (change detection, OnPush, zoneless, slow templates, large lists, RxJS). Use when the user wants to make an Angular app load faster, fix slow rendering or janky change detection, reduce bundle size, improve Core Web Vitals / Lighthouse scores, or asks for a performance review/audit. Covers the angular.dev performance best practices.
-
l-x-t Skill Ng Review Style GuideAudit the whole Angular codebase against the project style guide (all of style-guide/, auto-selected by file type) and report severity-ranked conformance findings, then drill in and fix on approval. Use when the user wants a full-codebase style-guide review, a conformance audit, to check the existing code against the style guide, or to find where the codebase drifted from the guide – as opposed to reviewing a diff (use code-review) or only SCSS/styling (use ng-styling).
-
l-x-t Skill Update Skills DirectoryAudit .agents/skills so every skill has valid frontmatter, a lean SKILL.md, flat support folders, and a root 02-SKILLS.md link. Use when the user adds, renames, removes, or restructures a skill, or asks to update the skills index/directory. Do not use it to create per-skill README files.
-
iamneilroberts Skill Gemini ReviewGet a second-opinion review of the current diff (or a chosen focus — architecture, security, docs, design, performance, tests) from the Gemini CLI, then present its findings alongside your own analysis. Single-reviewer counterpart to /codex-review and /review-panel; needs the `gemini` CLI installed. Triggers on `/gemini-review [focus]`, "gemini review this", "get a gemini second opinion on this diff".
-
magnus919 Bundle Legal Strategy 2CLO/General Counsel methodology — regulatory landscape analysis (GDPR, CCPA, AI Act, sector-specific), IP strategy (patent, trademark, trade secret, open source licensing), contract risk assessment (indemnification, liability caps, force majeure), data privacy frameworks (privacy-by-design, DPIAs, data mapping), corporate governance (board responsibilities, fiduciary duties, shareholder rights), employment law (classification, IP assignment, non-competes).
-
magnus919 Bundle Operational Design 2COO methodology for process design, organizational scaling, operational metrics, compliance and audit, vendor management, and team topology. Covers value stream mapping, BPMN, bottleneck analysis, scaling from 10 to 100 to 1000 people, KPI design, balanced scorecard, SOC 2, ISO 27001, GDPR readiness, RFP processes, SLA design, vendor scorecards, team topologies, Conway's Law, and Dunbar's Number.
-
magnus919 Bundle Security Audit Methodology 2Security audit and vulnerability assessment methodology — threat modeling, vulnerability classification, defense-in-depth review, dependency analysis, and security architecture evaluation. Grounded in OWASP, CWE, and STRIDE/LINDDUN frameworks.
-
hack23 Skill Incident Response 3Security incident detection, classification, response procedures, and post-incident review following NIST and ISO 27001
-
hack23 Skill Secure Code Review 3Security code review for HTML/CSS/JavaScript in static websites
-
hack23 Skill Security By Design 3Strategic principles for integrating security from the start, not retrofitting it later
-
hack23 Skill Open Source Governance 3Open source policy, license compliance, contribution guidelines, dependency management, and supply chain security
-
hack23 Skill Secure Development Lifecycle 3Comprehensive SDLC security covering planning, development, testing, deployment, and maintenance with classification-driven controls and AI governance
-
diegosouzapw Bundle Technical ReviewTechnical Review
54 -
diegosouzapw Bundle E2e Testing CosmixE2E Testing
54 -
diegosouzapw Bundle Symfony API Platform SecurityUse when symfony api platform security
54 -
diegosouzapw Bundle Vibe Security SkillThis skill helps Claude write secure web applications. Use when working on any web application to ensure security best practices are followed.
54 -
diegosouzapw Bundle Security Review WcyganSecurity Review
54 -
diegosouzapw Bundle Security Best Practices 3Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
54 -
diegosouzapw Bundle Security Validation ChecklistSecurity Validation Checklist
54 -
diegosouzapw Bundle Pai 2Personal AI Infrastructure (PAI) - PAI System Template. Your name is @assistantName@ and you are @userFullName@'s AI assistant. Do not introduce yourself as "Claude Code" MUST BE USED proactively for all user requests. USE PROACTIVELY to ensure complete context availability. Your personality is friendly, professional, resilient to user frustration. Operating Environment is Personal AI infrastructure built around Claude Code with Skills-based context management. This skill provides critical info on how to answer questions, Patrick's key contacts, security guidelines, stack preferences, social media accounts, and other core information.
54 -
diegosouzapw Bundle JWTJWT y auth. Proyecto usa este skill; contenido canónico en .ai-system.
54 -
construct-ai-primary Skill Security SurveillanceCCTV monitoring, anomaly detection, recording management for the ConstructAI security system
0 -
construct-ai-primary Skill Security Access ControlManagement of access control including badge scanning, authorization checking, entry/exit logging for the ConstructAI security system
0 -
construct-ai-primary Skill Security Domainforge Securitysecurity DomainForge security Skill
0 -
construct-ai-primary Skill Hse Audit ManagementSchedule HSE audits, track audit findings, manage corrective actions, calculate compliance rates, and monitor audit effectiveness with structured audit workflow and corrective action closure verification
0 -
construct-ai-primary Skill Procurement ComplianceValidate procurement activities against regulatory requirements, internal policies, budget constraints, and audit standards with automated compliance checking and reporting
0 -
construct-ai-primary Skill Security Patrol ManagementPlanning, scheduling, GPS tracking, and checkpoint verification for security patrols across the site
0 -
construct-ai-primary Skill Security Visitor ManagementEnd-to-end management of visitor pre-registration, on-site verification, badge printing, and escort tracking
0 -
construct-ai-primary Skill Gps Approval ConfigurationConfigure GPS-based approval routing with location verification, geofencing, biometric authentication, GPS-embedded signatures, and audit trail for procurement approvals
0 -
construct-ai-primary Skill Electrical Loto ComplianceGenerate lockout-tagout procedures for electrical equipment with energy source mapping, isolation point identification, and audit-compliant verification
0 -
construct-ai-primary Skill Pre Award Compliance MonitoringProcurement compliance checking, conflict of interest detection, and audit trail generation
0 -
construct-ai-primary Skill It Security Audit ValidationSkill for RLS policy checking, access control validation, security configuration review, and vulnerability assessment in the ConstructAI platform
0 -
aibot88 Bundle Dep AuditDependency Audit
3 -
aibot88 Bundle Gsd SecureSecurity audit of changes; enforce defense in depth and OWASP best practices
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-domainforge-security, code-review, ng-security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.