Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
autohandai-community-skills Bundle Analyzing Linux Audit Logs For IntrusionParse and analyze Linux auditd logs to detect intrusion indicators including unauthorized file access, privilege escalation, syscall anomalies, and suspicious process execution using ausearch and Python.
-
autohandai-community-skills Bundle Performing Threat Hunting With Yara RulesUse YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems and memory dumps. Covers rule authoring, yara-python scanning, and integration with threat intel feeds.
-
autohandai-community-skills Bundle Implementing Privileged Session MonitoringMonitor and audit privileged user sessions including SSH, RDP, and database access. Tracks session metadata, records commands, detects anomalous activity, and enforces session policies for PAM compliance.
-
autohandai-community-skills Bundle Implementing Security Information Sharing With Stix2Create, validate, and share STIX 2.1 threat intelligence objects using the stix2 Python library. Covers indicators, malware, campaigns, relationships, bundles, and TAXII 2.1 publishing.
-
tmolavi Bundle Alloydb Postgres Access ManagementUse these skills when you need to manage database users, inspect permissions and roles, and verify global configuration parameters related to security and access control.
-
axidify Skill SecurityDeep security review of code changes or a module. Use when the user asks for security review, threat check, or before auth, payments, or PII. Complements review pass 1. Not a substitute for professional pentest.
-
claude-ai-tools-ventura-county Skill GiantbrainsRouter for the Giant Brains suite: stress-test one doc (a plan, spec, proposal, or migration doc) by running the two or three suite lenses that match the doc's stage, report-only, then synthesizing one combined verdict. Triages in a single message (which doc, what stage), routes by stage — draft: take-a-step-back, iron-triangle, blast-radius; in progress: blast-radius, iron-triangle; complete: decision-record audit, bottom-line — and never edits the doc: writers (record-decision, linear; phase-qa when giant-brains-swe-skills is installed) are offered afterward as explicit opt-ins. Trigger when the user invokes /giantbrains, says "stress test this plan/doc", "pressure-test this", "run the battery", "run all the lenses/brains against this", or asks for a full multi-angle review of a planning doc. Do NOT trigger for a single quick decision (route to the one matching skill), line-by-line code or correctness review (/code-review), or a request to edit, reformat, or rewrite the doc itself.
-
echo-aloha Bundle Pfc5 FishAuthor and audit PFC 5.0 FISH for asphalt cases, including def/end functions, globals and locals, callbacks, numbered histories, object traversal, command blocks, IO, and stop logic.
-
echo-aloha Bundle Pfc Rutting TestDesign, implement, and audit PFC3D 5.0 asphalt wheel-tracking and intersection-rutting simulations using RVE-to-strip-to-full-size scaling, PFC5-compatible vector reaction control, Burger-calibrated contacts, vertical-horizontal coupled loads, rut/shear histories, edition-specific metrics, and explicit surrogate validation.
-
echo-aloha Bundle Pfc Marshall TestAdapt and audit a PFC 5.0 asphalt Marshall stability/flow simulation using the external fistPkg26 dc.fis two-head controller as a starting skeleton; use for curved-head geometry, PFC5 wall/contact kinematics, load-deformation histories, peak stability, edition-specific flow processing, and validation against laboratory data.
-
echo-aloha Bundle Pfc5 Case HandoffAudit, recover, and prepare portable handoffs of existing private PFC2D/PFC3D 5.0 asphalt cases, including integrity manifests, path portability, saved-state claims, cheap restore-first validation, and legacy-state quarantine.
-
echo-aloha Bundle Pfc Fishtank TestsIntegrate an external, licensed Itasca PFC 5.0 fistPkg26 tree as a reproducible material-generation and compression/diametral/tension test baseline; use to validate its PFC5.0 layout, copy a private working case, preserve provenance, and audit ck/ct/dc/tt/ft extension points for asphalt workflows.
-
echo-aloha Bundle Pfc5 Dynamics WaveDesign and audit PFC 5.0 asphalt dynamic loading and stress-wave studies with damping, timestep, rate, dispersion, source direction, boundary reflection, histories, and wheel-load handoff checks.
-
echo-aloha Bundle Pfc5 Standard TestsPlan, audit, and post-process PFC 5.0 asphalt calibration tests, including compression, diametral loading, direct tension, creep-recovery, test geometry, histories, peak metrics, stiffness, and fistPkg handoff.
-
echo-aloha Bundle Pfc5 Servo CalibrationDesign and audit PFC 5.0 wall servo, loading-rate control, equilibrium checks, micro-to-macro calibration, two-target local solves, DOE campaigns, and independent confirmation for asphalt models.
-
kiyoraka Bundle ObservationMUST use when user says 'survey project', 'scan project', 'check health', 'investigate', 'deep dive', 'what's going on in', 'look into', 'refine code', 'clean up code', 'review changes', 'sharpen', 'audit system', 'full audit', 'show me everything', or when the AI needs to assess project health before planning, review code quality after implementation, or investigate a bug. Also triggers on 'how does this project look', 'what's the status', 'review what I changed', 'check for issues'.
-
clarentcinematics Bundle Policy Impact AnalysisAnalyze policy, regulatory, compliance, security, privacy, procurement, or internal guidance changes against business workflows, teams, controls, obligations, risks, and required actions. Use when Codex needs to assess policy impact, map affected stakeholders, identify gaps, or prepare implementation guidance.
-
clarentcinematics Bundle Vendor Security ReviewReview vendor security questionnaires, procurement security notes, SOC2 summaries, DPA excerpts, subprocessor lists, security answer drafts, or risk-review packets for missing coverage, weak evidence, follow-up questions, and human-review risks. Use when Codex needs to prepare a vendor security review without making legal, compliance, or approval decisions.
-
thatmike1 Bundle Cc AuditAudits Claude Code setup and usage patterns, flagging anti-patterns (wrong launch dirs, context bloat, orphaned memories, missing CLAUDE.md) with severity-ranked fixes. Use when user says audit, health check, setup check, cc audit, or wants to improve their Claude Code workflow.
-
yananlong Bundle Research Results AuditorAudit ML/statistics experiment outputs for validity, confounds, statistical support, calibration, and mismatch between measured results and claimed conclusions. Use when asked to interpret results, sanity-check benchmarks, review ablations, assess robustness claims, decide whether an experiment supports a paper claim, or produce a machine-readable result-audit record for downstream paper planning.
-
managedcode Bundle Meziantou Analyzer 3Use the open-source free `Meziantou.Analyzer` package for design, usage, security, performance, and style rules in .NET. Use when a repo wants broader analyzer coverage with a single NuGet package.
-
magnus-gille Bundle Magnus Security ReviewPerform a requested, project-specific security review of a codebase, diff, PR, module, or repository. Use for an explicit security audit; ordinary security-adjacent edits do not activate it.
-
shinpr Bundle Recipe Review 2Reviews completed implementation for governing-source compliance, scope economy, repository quality, and security, and applies user-approved corrections.
-
jamillazarev Skill AuditLoad and follow the **multica-ops** skill (`../mops/SKILL.md`), executing
-
michaellady Skill Audit Buffer QueueUse when user wants a health check on the Buffer queue — bunching, dead channels, theme over-saturation, untagged posts that break closed-loop measurement. Triggers — "audit my buffer queue", "buffer queue health", "is my buffer queue too crowded", "check my queued posts for problems".
-
michaellady Skill Tune Posting ScheduleUse when posting times are bunching, when /audit-buffer-queue surfaces structural bunches that re-appear after rescheduling individual posts, or when /buffer-stats finds a per-hour engagement pattern that disagrees with current Buffer slots. Analyzes each channel's postingSchedule against (a) gap-spacing rules, (b) recent sent-post engagement-by-hour, and (c) audience timezone, then proposes + applies a new schedule via the gstack web-UI driver in _shared/buffer-schedule-edit (Buffer's public API has no schedule mutation). Triggers — "tune my posting schedule", "fix my buffer slots", "analyze posting times", "my queue keeps bunching", "change posting schedule".
-
nhouseholder Skill KgKeep going — audit open work, pick the highest-leverage task, implement it end-to-end, verify, then immediately take the next highest-leverage step. Do not pause for routine confirmation. Do not stop because one commit, push, or PR landed.
-
nhouseholder Skill Keep GoingAlias of /kg — audit open work, pick the highest-leverage task, implement it, verify, and report the next action.
-
roedyrustam Skill Auto Doc Updater 2Automated project documentation tracking. Use whenever the user wants to keep README files, CHANGELOGs, API docs, or architecture docs in sync with code changes. Trigger on phrases like "update the docs", "keep documentation in sync", "generate changelog", "document this change", or after completing a feature/refactor when documentation should reflect the new state. Also trigger when the user asks for a documentation audit of stale or missing docs.
-
roedyrustam Skill Saas Multi Tenant 2Row-Level Security (RLS) and multi-tenant database isolation strategies for SaaS applications. Use whenever the user is designing or implementing multi-tenancy, tenant isolation, RLS policies, or workspace-based access control. Trigger on phrases like "multi-tenant", "RLS", "row-level security", "tenant isolation", "workspace isolation", "organization data", or when the user needs to ensure one tenant cannot access another's data in PostgreSQL or Supabase.
-
roedyrustam Skill Secure Fuzz Testing 2Coverage-guided fuzzing with Atheris, cargo-fuzz, and native Go fuzzing, combined with compilers/sanitizers (ASan, MSan, UBSan) for security validation. Use whenever the user wants to fuzz test code, find memory safety bugs, validate parsers/deserializers against malformed input, or harden security-critical code paths. Trigger on mentions of fuzzing, fuzz testing, AddressSanitizer, libFuzzer, cargo-fuzz, Atheris, go test -fuzz, or security validation of parsing/deserialization logic.
-
roedyrustam Skill App Analyzer Optimizer 2Deeply analyzes application architecture, dependencies, and performance configurations, and executes targeted optimizations aligned with active project skills. Use whenever the user wants a full project health check, dependency audit, performance review, or asks "analyze my codebase" or "optimize my app." Trigger on phrases like "audit my project", "analyze the architecture", "find performance issues", "optimize this app", or "review my dependencies".
-
roedyrustam Skill Firebase Security Expert 2Firebase Security Rules auditing, Service Account protection, and App Check integration. Use whenever the user is working with Firebase security — Firestore rules, Realtime Database rules, Storage rules, App Check, service account key management, or Firebase Auth security. Trigger on mentions of Firebase, Firestore, Firebase Security Rules, App Check, service account JSON, Firebase Admin SDK, or when the user asks to review or write Firebase rules. Also trigger for Firebase project security audits.
-
roedyrustam Skill Supabase Security Expert 2Relational database auditing and Row-Level Security (RLS) best practices for Supabase. Use whenever the user is working with Supabase security, RLS policies, database auditing, PostgREST security, Supabase Auth, service role key protection, or securing Supabase APIs. Trigger on mentions of Supabase, RLS policies, anon key, service_role key, PostgREST, Supabase Auth, or database security audits. Also trigger when the user asks "is my Supabase secure" or wants to review their database policies.
-
wolski Bundle Polymorphism Over DiscriminationFind and fix code that decides what to do by asking what something is. Use this skill whenever reviewing or writing Python that contains an isinstance chain, an `if mode == "x" / elif` chain, `if record.field is None` where the arms do different work, a validator that rejects field combinations ("X is only valid when Y is Z"), a function returning a string that names an operation, or a record carrying a kind flag plus fields belonging to only one kind. Use it when adding an arm to any existing chain of those, when adding an optional field to a type you own, when introducing a `Missing`/`No`-prefixed class, and when naming something Builder, Factory, Strategy, or Visitor. Also use it for any request to review Python design, reduce branching, clean up conditionals, or audit a package for structural problems — even when the user does not say "polymorphism". Python only.
-
octanejs Bundle Update Bindings 3Audit one, several, or all existing Octane bindings; implement selected maintenance findings or remove redundant copied files with evidence matched to source ownership. Use for binding updates, lifecycle fixes, dependency or metadata maintenance, and convenience-import requests.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include tune-posting-schedule, analyzing-linux-audit-logs-for-intrusion, performing-threat-hunting-with-yara-rules. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.