Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
weirdgme Bundle Network EngineeringNetwork engineering and architecture covering network design, TCP/IP protocols, routing and switching, load balancing, network security, SDN, service mesh networking, DNS management, VPN, and network troubleshooting. Use when designing networks, implementing network infrastructure, debugging connectivity, or securing network traffic. (project)
-
buldee Skill LegacyLegacy code rescue - audit hotspots, cover with characterization tests, break dependencies, and plan strangler-fig migrations. Use when inheriting, taming, testing, or refactoring an untested/undocumented codebase.
-
nwave-ai Skill Nw Speculative Dispatch 2Speculative parallel implementation methodology — dispatch N candidate implementations, audit all, score, pick best. Auditability mandate: ALL candidates logged (not just winner).
-
ishandutta2007 Bundle Security AuditSkill: Security Audit
-
dhofheinz Bundle Security ScanComprehensive security scanning for secrets, vulnerabilities, and unsafe practices
-
hivellm Skill Security AuditRun a security audit on the project (dependencies, secrets, OWASP)
-
munlucky Skill Kernel Security Review PolicyInternal Kernel policy for security-sensitive verification and independent review.
-
aradotso-security-skills Skill Security Risk Awareness```markdown
-
aradotso-security-skills Skill Bitdefender Security Analysis```markdown
-
aradotso-security-skills Skill Bitdefender Security Awareness```markdown
-
gaia-react Skill Update DepsAutonomous Dependabot, auto-discover outdated packages, audit overrides, apply migrations for major bumps, resolve conflicts, run quality gate. Trigger when the user clicks the statusline `Run /update-deps` indicator or asks "update dependencies", "bump deps", "run dependabot".
-
hughdbrown Skill Hdb Linkedin Profile FixerUse when a user wants to revamp, audit, or rewrite their LinkedIn profile to attract recruiters — runs a sequenced, one-section-at-a-time rewrite anchored to real target job descriptions, never inventing metrics. Triggers on "fix my LinkedIn", "rewrite my profile/headline/About section", "LinkedIn audit", "optimize my profile for recruiters".
-
ligenjian001-ai Bundle API Design AuditAudit API design proposals against user's design preferences. Evaluates 7 checkpoints (raw data preservation, metric justification, core concept, data constraints, minimal state, additive design, market transparency). Trigger: 'audit this API design', '审计API设计', 'review this proposal'.
-
ligenjian001-ai Skill Product Maturity AuditShell-based product maturity checklist for strategy platform SDKs. Runs concrete commands with binary PASS/FAIL outcomes. Designed to avoid the bootstrapping paradox of Python-based checkers.
-
mardab96 Skill Catalog Content Audit EcommerceAudits product content across a whole catalog rather than one page, finding missing attributes, thin descriptions, duplicate copy, weak imagery coverage, and category gaps at scale. Use when the catalog is too large to review page by page, before a feed or marketplace push, or when only the hero products have real content. Above roughly 150 SKUs the counting is done by ../scripts/catalog_scan.py, not by reading the export, because a sampled read is not an audit.
-
orcasecurity Skill Orca Alert TriageAnalyzes Orca Security alerts with timeline visualization, risk assessment, and progressive disclosure. Use when user asks to triage, analyze, explain, summarize, investigate, or check an Orca alert by ID (e.g., "triage orca-3636513", "what is alert orca-3548863", "check orca-3636513").
-
orcasecurity Skill Orca Data ExposureDSPM view — sensitive data at risk across the environment, exposed secrets/PII/credentials, data store security posture, and remediation priorities. Use when user asks about data exposure, sensitive data, or secrets (e.g., "data exposure", "where is our PII", "sensitive data at risk", "exposed secrets", "DSPM view").
-
orcasecurity Bundle Orca Mfa EnforcementFinds users who can sign in without MFA across an account, business unit, or tag, ranks them by identity risk, and drives guided enrollment or gated enforcement. Use for MFA or 2FA gaps, root-account MFA, and MFA coverage evidence for an audit.
-
orcasecurity Skill Orca Morning BriefingDaily security briefing summarizing new critical alerts, attack paths, compliance drift, exposure changes, and aging unactioned alerts from the last 24-72 hours. Use when user asks for a briefing, summary, or overview (e.g., "morning briefing", "what happened", "security summary", "daily report", "what needs attention").
-
renanfranca Bundle Seed4j Worktree FlowManage the local seed4j-cli Git worktree workflow safely. Use when Codex is asked to audit seed4j-cli worktrees, create a feature worktree, clean up a completed worktree, decide which branches are already merged into main, or keep /home/renanfranca/projects/seed4j-cli as the main worktree while feature work happens under /home/renanfranca/projects/seed4j-cli-worktree.
-
renanfranca Bundle Restructure DocumentationAudit and restructure an existing repository documentation system around explicit audiences, user journeys, canonical sources, ordered concepts, and preserved public interfaces. Use for bloated README files, overlapping guides, concepts introduced out of order, duplicated normative facts, broken navigation, or requests to reorganize an existing set of documents. Do not use for isolated corrections, documentation written from scratch, style-only editing, or AGENTS.md changes unless the user explicitly requests a normative restructuring of those operational instructions.
-
greenmamba29 Skill Web Performance Audit| name | description | license | tags |
-
joaquimscosta Bundle Spring Boot VerifyVerify Spring Boot 4.x projects for correct dependencies, configuration, and migration readiness. Use when analyzing pom.xml, build.gradle, application.yml, discussing Spring Boot project setup, dependency versions, configuration validation, version compatibility, migration to Spring Boot 4, deprecated dependencies, or when user mentions "verify project", "check dependencies", "upgrade Spring Boot", "migration readiness", "Jackson 3", "@MockBean deprecated", or "Spring Security 7".
-
joaquimscosta Bundle Spring Boot ScannerSmart code scanner that detects Spring Boot patterns and routes to appropriate skills. Use when editing Java or Kotlin files in Spring Boot projects, working with pom.xml/build.gradle containing spring-boot-starter, or when context suggests Spring Boot development. Detects annotations (@RestController, @Entity, @EnableWebSecurity, @SpringBootTest) to determine relevant skills and provides contextual guidance. Uses progressive automation - auto-invokes for low-risk patterns (web-api, data, DDD), confirms before loading high-risk skills (security, testing, verify).
-
joaquimscosta Bundle Spring Boot TestingSpring Boot 4 testing strategies and patterns. Use when writing unit tests, slice tests (@WebMvcTest, @DataJpaTest), integration tests, Testcontainers with @ServiceConnection, security testing (@WithMockUser, JWT), or Modulith event testing with Scenario API. Covers the critical @MockitoBean migration from @MockBean.
-
joaquimscosta Bundle Spring Boot SecuritySpring Security 7 implementation for Spring Boot 4. Use when configuring authentication, authorization, OAuth2/JWT resource servers, method security, or CORS/CSRF. Covers the mandatory Lambda DSL migration, SecurityFilterChain patterns, @PreAuthorize, and password encoding. For testing secured endpoints, see spring-boot-testing skill.
-
aradotso-security-skills Skill Malware Analysis Security Warning```markdown
-
aradotso-security-skills Skill Security Awareness Malware Detection```markdown
-
aradotso-security-skills Skill Security Warning Malicious Repository```markdown
-
aradotso-security-skills Skill Security Awareness Malware Identification```markdown
-
aradotso-security-skills Skill Security Awareness Avast Malware Detection```markdown
-
aradotso-security-skills Skill Security Awareness Malicious Repository Identification```markdown
-
fndlalit Bundle N8n Security Testing 3Credential exposure detection, OAuth flow validation, API key management testing, and data sanitization verification for n8n workflows. Use when validating n8n workflow security.
-
fndlalit Skill V3 Qe Securityv3-qe-security
-
outlinedriven-odin-claude-plugin Bundle Dx AuditUse when auditing the developer-facing surface of a CLI, SDK, library, or package: API contracts, errors, public types, onboarding, and config.
-
outlinedriven-odin-claude-plugin Bundle Web Design ReviewUse when the user runs /web-design-review with a URL to visually audit and fix a live UI. Not for design direction: use design. Not for variant galleries: use design-variants.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include network-engineering, legacy, nw-speculative-dispatch. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.