Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
claude-dev-suite Skill Kotlin SecurityKotlin application security for backend and Android: vulnerability review and secure implementation patterns. USE WHEN: securing Kotlin applications (backend/Android), reviewing code for vulnerabilities, or implementing security best practices DO NOT USE FOR: code quality issues (use `kotlin-quality`), general Kotlin patterns, UI/UX concerns
28 -
rafadgarcia Bundle Restful APIUse when creating, reviewing, or refactoring HTTP APIs, REST endpoints, CRUD routes, route handlers, controllers, request/response schemas, API documentation, or backend HTTP interfaces. Guides resource-oriented route design, HTTP method semantics, status codes, validation, errors, pagination, security, tests, and documentation while preserving existing project conventions.
-
rafadgarcia Bundle Audit LoggingReview, design, or implement audit trails for sensitive business operations such as financial changes, permission changes, administrative actions, impersonation, and destructive operations. Use when the user explicitly requests audit logging or when implementing a clearly sensitive state-changing workflow. Do not use for ordinary application logging, observability, debugging, or routine reads.
-
dvy1987 Bundle Technical Debt AuditAudit the project's technical health and identify "high-interest" debt. Load when the user asks to check code quality, find TODOs, assess project health, or prepare for a refactoring sprint. Also triggers on "technical debt audit", "where is the code messy", "assess project health", "find my hacks", or "identify tech debt". Essential for maintaining velocity in growing projects.
3 -
dvy1987 Bundle App Security HardeningHarden an application against common security risks — validate inputs at boundaries, least-privilege access, safe secrets handling, dependency hygiene, and secure defaults. Load when shipping user-facing code, adding auth/session flows, handling untrusted data, exposing APIs, or the user asks for "security hardening", "OWASP hardening", "secure this feature". Not for skill-library security gates (use secure-skill family).
3 -
dvy1987 Bundle Apply Paper To ProjectApply validated research paper insights to the current project codebase — improving architecture, code patterns, testing strategies, documentation, or workflows based on empirical findings. Load when learn-from-paper routes insights to the current project, or when the user asks to apply paper findings to this project, improve this codebase with research, use this paper to improve my project, or apply research to my code. Also triggers on "apply this to my project", "how can this paper help my codebase", "use these findings here", "implement paper recommendations", "use research to improve my code". Always called AFTER learn-from-paper has completed credibility and security checks — never ingests papers directly.
3 -
ysyecust Skill Quarkus SecurityQuarkus Security
-
fatihkan Skill SecurityGuvenlik Becerileri
-
nvidia Skill Nemoclaw Maintainer Find Review PrFind open PRs with the security label and Urgent or High Project Priority. Link each PR to its issue. Identify competing or superseded PRs and report review candidates. Use when looking for the next PR to review. Trigger keywords - find pr, find review, next pr, pr to review, duplicate pr, security pr.
2.2k -
nvidia Bundle Nemoclaw Contributor Implement IssueImplement an accepted NemoClaw GitHub issue in the current checkout. Use when a user asks to pick up an issue for implementation, implement or fix a named issue, or add the issue's tests. Confirm accepted scope, deliver the smallest independently valuable capability slice, and record validation and remaining gates without publishing a PR. Ask which lifecycle stage they want when "work on this issue" could mean planning or implementation. Do not use for issue planning, PR publication, independent security review, or maintainer loops. Trigger keywords - pick up issue for implementation, implement issue, fix issue, code issue, add issue tests.
2.2k -
nvidia Bundle Nemoclaw Contributor Update DependenciesAudit and implement a dependency upgrade as a semantic migration. Use when changing a library, CLI, service, image, runtime, installer artifact, or transitive dependency, including a Hermes release. Trace upstream changes into current NemoClaw consumers, resolve security and lifecycle concerns, and verify the artifacts that NemoClaw uses. Trigger keywords - update dependency, upgrade dependency, bump version, dependency migration, release audit, update Hermes, upgrade Hermes, review Hermes release, publish Hermes base image.
2.2k -
nvidia Skill Nemoclaw Maintainer Security Code ReviewReview a PR, or a PR linked to an issue, for security risks. Check nine categories and report PASS, WARNING, or FAIL. Use when reviewing code for vulnerabilities, secrets, injection, authorization bypasses, or unsafe configuration. Trigger keywords - security review, code review, appsec, vulnerability assessment, security audit, review PR security.
2.2k -
trecek Skill Audit ArchAudit codebase for adherence to architectural standards, practices, and rules. Use when user says "audit arch", "audit architecture", "check architecture", or "architectural review". Spawns parallel subagents to examine multiple architectural aspects and generates a structured report.
-
trecek Skill Audit CohesionAudit codebase for internal cohesion - how well components fit together and maintain consistent patterns. Distinct from audit-arch (which checks rule violations); this checks integration fitness and convergence. Use when user says "audit cohesion", "check cohesion", "cohesion audit", or "alignment check".
-
trecek Skill Audit FrictionScan Claude Code project logs for friction patterns — repeated failures, approach loops, tool errors, misunderstanding cycles, and stuck workflows. Categorizes and counts friction events to surface what causes the most resistance. Use when user says "audit friction", "find friction", "friction audit", or "what keeps going wrong".
-
trecek Skill Arch Lens SecurityCreate Security architecture diagram showing trust boundaries, validation layers, and process isolation. Security lens answering "Where are the trust boundaries?"
-
gaebalai-claude-code-kit-ko Skill Security Quick코드베이스의 기본 보안 점검을 일괄 수행한다. OWASP Top 10 관점에서 점검한다.
-
gaebalai-claude-code-kit-ko Skill Security Secrets코드베이스에서 비밀 정보(API 키·토큰·비밀번호 등) 유출 여부를 탐지한다.
-
omkar-ukirde Bundle MobileMobile application security testing skills for Android and iOS platforms.
-
omkar-ukirde Bundle XssSkills for Cross-Site Scripting (XSS) and client-side injection attacks including clickjacking.
-
omkar-ukirde Bundle IOSSkills for iOS application security testing including IPA analysis, data storage, and runtime manipulation.
-
omkar-ukirde Bundle A10 SsrfSkills for exploiting server-side request forgery and related server-side attacks per OWASP A10:2021.
-
omkar-ukirde Bundle AndroidSkills for Android application security testing including APK analysis, static/dynamic analysis, and exploitation.
-
omkar-ukirde Bundle WirelessSkills for wireless network security testing including WiFi attacks.
-
omkar-ukirde Bundle API SecuritySkills for testing API security including GraphQL and REST API vulnerabilities.
-
omkar-ukirde Bundle A04 Insecure DesignSkills for exploiting insecure design patterns including race conditions and parameter pollution per OWASP A04:2021.
-
omkar-ukirde Bundle Security AnalysisSkills for security analysis including SSL/TLS testing, protocol detection, and evasion techniques.
-
omkar-ukirde Bundle A06 Vulnerable ComponentsSkills for exploiting vulnerable and outdated components including insecure deserialization per OWASP A06:2021.
-
omkar-ukirde Bundle A08 Data Integrity FailuresSkills for exploiting software and data integrity failures including HTTP request smuggling per OWASP A08:2021.
-
proffesor-for-testing Skill Qe N8n Security TestingCredential exposure detection, OAuth flow validation, API key management testing, and data sanitization verification for n8n workflows. Use when validating n8n workflow security.
-
tai-ch0802 Bundle Vulnerability Scanner進階弱點分析原則。OWASP 2025、供應鏈安全、攻擊面映射、風險優先排序。
-
huytieu Skill Export Open Issues 3Audit and export open issues from any project tracker with summary analysis and vault archival
-
javeedishaq Skill Rls SecurityRow-Level Security Patterns
-
rjmurillo Skill Security Content ControlledContent controlled security eval skill
-
x402agent Skill Pump Testing 2Multi-language test infrastructure for the Pump SDK — Rust unit/integration/security/performance tests, TypeScript Jest tests, Python fuzz tests, shell test orchestration, Criterion benchmarks, and CI quality gates.
9 -
x402agent Skill Pump Security 2Defense-in-depth security across Rust, TypeScript, and Bash for the Pump SDK — cryptographic key handling, memory zeroization, secure file I/O, input validation, privilege management, dependency auditing, and a 60+ item security checklist.
9
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include kotlin-security, restful-api, audit-logging. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.