Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
immortalqx Bundle Phd Pre Submission ReviewerRuns a pre-submission review of a technical paper across five dimensions: macro logic, writing details, English grammar, LaTeX formatting, and figure quality. Uses a reviewer-style severity taxonomy (CRITICAL / MAJOR / MINOR) and flags banned AI-tone vocabulary and em-dash misuse. Use when the user asks to 'review this paper', 'audit before submission', 'check the draft', 'find issues', 'proofread', or within one week of a submission deadline.
-
speciliam Bundle Notion Application SyncOptionally mirror Liam Van's application tracker data into Notion from the generated visualizer JSON cache. Use only when the user explicitly asks to sync, audit, configure, or schedule Notion matching; normal recruiting skills should not call this by default.
-
wesperez Bundle Sub2api K12 Space Audit按 `credentials.chatgpt_account_id` 只读审计 Sub2API PostgreSQL 中的 K12/OpenAI OAuth Space:统计本地可调度账号、active/deleted、401/402、无错误删除行,并检查指定 Space 或前缀。用户询问本地库 K12 Space 库存、红点/失效原因、某 Space 还剩多少本地可用账号或需要脱敏账号列表时使用。不要用于论坛收集 Space ID、浏览器 exchange 验证、上游额度探测、账号包导入或显示名整理。
-
bernardorubin Bundle Pr ReviewUse when the user wants code reviewed — a GitHub PR, their local/uncommitted changes, or a whole-repo audit. Confidence-scored review with parallel agents, incremental tracking, and GitHub-comment-ready file output (optionally posted to the PR with --comment). Three modes — (1) PR mode reviews a GitHub PR by number or auto-detected from the current branch. (2) Local mode reviews uncommitted changes plus commits ahead of main when no PR exists. (3) Full-repo mode reviews the entire codebase when the user explicitly asks for a full audit ("audit the whole repo", "review the entire codebase", "full repo audit"). Auto-triggers on phrases like "review this PR", "review my changes", "audit my code", "review my uncommitted work", "audit the whole repo".
-
canepro Bundle Loki Label AnalyzerAudit, design, or improve a Grafana Loki label schema: cardinality scoring, static vs dynamic label rules, structured metadata placement, and stream-level query performance diagnosis. Use when Loki queries are slow, stream counts or costs are growing, or the user asks to evaluate or redesign Loki labels. For LogQL syntax and ingestion, use loki.
-
canepro Bundle Prometheus Label StrategyDesign and audit Prometheus label schemas to prevent high cardinality at the source: instrumentation hygiene, target vs application labels, histogram label discipline, info metrics, exemplars. Use when designing or reviewing metric labels. For a live cardinality fire, use prometheus-cardinality-troubleshooter.
-
canepro Bundle Maintain Verification SkillAudit and repair a project-local verification skill and its feature map using source inspection plus one live pass. Use when verification instructions, harness commands, selectors, or documented user features may have drifted.
-
pavel-molyanov Skill Security AuditorAnalyzes changed security boundaries against applicable OWASP risks and project contracts. Use after code-reviewer when authentication, authorization, untrusted input, secrets, sensitive data, database queries, file paths, rendering, or external APIs changed. Use when: "проверь безопасность", "security audit", "найди уязвимости", "check security" Do NOT use for: general code review (use code-reviewer), test quality review (use test-reviewer)
-
pavel-molyanov Bundle Documentation WritingCreates and maintains project documentation in .claude/skills/project-knowledge/: interview, initial Project Knowledge, audit, edit, consistency, and feature finalization. Use when: "заполни документацию проекта", "опиши проект", "создай Project Knowledge", "проведи интервью по проекту", "проверь документацию", "обнови документацию", "аудит документации", "plan a new project", "fill project documentation", "check docs", "audit documentation", "update docs" For reading docs or explaining concepts, read project-knowledge skill directly.
-
pavel-molyanov Skill Security Auditor 2Analyzes changed security boundaries against applicable OWASP risks and project contracts. Use after code-reviewer when authentication, authorization, untrusted input, secrets, sensitive data, database queries, file paths, rendering, or external APIs changed. Use when: "проверь безопасность", "security audit", "найди уязвимости", "check security" Do NOT use for: general code review (use code-reviewer), test quality review (use test-reviewer)
-
pavel-molyanov Bundle Documentation Writing 2Creates and maintains project documentation in .claude/skills/project-knowledge/: interview, initial Project Knowledge, audit, edit, consistency, and feature finalization. Use when: "заполни документацию проекта", "опиши проект", "создай Project Knowledge", "проведи интервью по проекту", "проверь документацию", "обнови документацию", "аудит документации", "plan a new project", "fill project documentation", "check docs", "audit documentation", "update docs" For reading docs or explaining concepts, read project-knowledge skill directly.
-
leadgenjay Bundle CleanupAudit and clean up any project workspace — temp files, security issues, dead code, unused deps, git hygiene, build caches, and code quality. This skill should be used when the user wants to clean up, tidy, audit, or organize the project. Also use when the user mentions 'cleanup,' 'clean up,' 'tidy up,' 'housekeeping,' 'remove temp files,' 'dead code,' 'unused deps,' 'unused dependencies,' 'git hygiene,' 'project audit,' 'repo cleanup,' 'clear cache,' or 'stale branches.'
-
yankieldbc2 Bundle Deep Code ReviewUse this when reviewing code, pull requests, diffs, architecture changes, security risks, regressions, or maintainability problems.
-
yankieldbc2 Bundle Project Recovery AuditUse this when a repository needs a health audit before work starts, especially if the repo may be stale, broken, or hard to resume.
-
yankieldbc2 Bundle Secrets Env ManagementUse this when handling environment variables, API keys, tokens, .env files, secret rotation, or safe credential documentation.
-
akillness Bundle Log Analysis 2Analyze application logs to identify errors, performance issues, and security anomalies. Use when debugging issues, monitoring system health, or investigating incidents. Handles various log formats including Apache, Nginx, application logs, and JSON logs.
42 -
cbusillo Bundle Memory DistillationUse only when the user explicitly asks to audit, clean, prune, archive, reset, or distill Codex or Codex Lab memories into skills, repo docs/issues, or local config. Never use implicitly or for ordinary repo work.
-
halfmoon-mind Bundle Overbroad TriggerImprove quality for any review, audit, documentation, or coding task. Use whenever anything needs checking or improvement.
-
mardab96 Skill Trust Signal AuditTrust Signal Audit
-
mardab96 Skill Landing Page TriageStarts here when a landing page gets traffic and does not convert and nobody knows why. Use when the problem is not yet diagnosed, when you do not know which check to run first, or when someone wants a full page audit and would otherwise get twenty five separate opinions.
-
mardab96 Skill Social Proof Strength AuditChecks whether the proof on the page would convince a sceptic in the reader's own situation, or whether it is decoration. Use when a page has logos and testimonials and still feels unproven, or when proof was inherited from an older version of the business.
-
mardab96 Skill Paid Traffic Message Match AuditCompares what the ad promised with what the page delivers, element by element, and finds the first point where the visitor's expectation breaks. Use when clicks arrive but bounce is high or lead quality is poor, or after ad copy changed and nobody re-read the page.
-
mardab96 Skill Thank You Page Opportunity AuditLooks at the page after conversion, where attention is highest and almost nothing is usually asked. Use when a form or purchase flow has just shipped, or when the thank-you page is still the platform default.
-
dkpapadopoulos Bundle Supply Chain InvestigationUse when investigating a published supply-chain attack on a registry package (npm, Maven, PyPI, Go, Gradle) — advisory-driven org-wide audit. Triggers on attack-language ("compromised", "malicious", "hijacked", "backdoored", "typosquatted"). NOT for routine CVE scanning — that routes to security-scanner.
-
galihadiprayoga Skill Quarkus SecurityQuarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security.
-
galihadiprayoga Skill Quarkus VerificationVerification loop for Quarkus projects: build, static analysis, tests with coverage, security scans, native compilation, and diff review before release or PR.
-
galihadiprayoga Bundle Skill Upgraderaudit, harden, and upgrade existing chatgpt skills into production-ready versions for real business cases. use when asked to improve, upgrade, refactor, validate, package, or make another skill more powerful, especially when input is a skill.zip, a skill folder, pasted skill.md content, draft instructions, or a real-case failure. focuses on edge cases, workflow clarity, trigger descriptions, output consistency, tool and connector rules, validation, and producing a complete upgraded skill.zip.
-
axross Bundle Zod Schema 3A change touching Zod — `z.object`, `z.infer`, `safeParse`, `z.codec`, `z.coerce`, `z.brand`, `z.discriminatedUnion`, `.refine`, `.transform`, `zodResolver`, `z.toJSONSchema`, `ZodError`, a schema module, a validation boundary, or an unvalidated `fetch` or `JSON.parse` result. For which inputs are untrusted at all, use an application-security capability. Modelling a type schema with Zod 4, decoding and encoding across a boundary, and enforcing validation where untrusted data enters. Covers the one-parse boundary, schema-derived types, codecs, coercion traps, error shape, and what a passing parse still does not make safe.
-
axross Bundle Code Review 3Reviewing a code change — a pull request, a branch or commit-range diff, or a post-implementation self-review of your own work before calling it done. Not for writing the change, only for judging one that already exists. Covers the reviewer-mode reset and diff scoping, a four-tier severity scale with fixed floors, evidence-based reporting with file-line citations and fix snippets, escalation for high-risk changes, a posted/CI overlay that collapses to Important/Nit, and lenses for correctness, maintainability, security, testing, and performance. Self-contained, so it works installed on its own.
-
axross Bundle Application Security 3Writing or reviewing code that handles untrusted input, secrets, outbound requests, rendered content, or third-party dependencies — "is this safe", "secure by default", "harden", "security", "secret", "privacy", "PII", "XSS", "injection", "SSRF", "safe fetch", "access control", or a dependency review. The OWASP Top 10:2025 lens in two modes, writing secure-by-default code and judging the risk a change introduces. Covers secrets and environment variables, input validation, output encoding, SSRF, access control and data exposure, and supply-chain risk.
-
bolasblack Bundle Maintain Verification SkillPeriodic pass that keeps a project's verification skill and feature map honest: parallel source readers per feature, one live session driving every feature, at most one PR of proven corrections. Use for /maintain-verification-skill or "audit the verify skill".
-
wonderslife Bundle System Architect 2Acts as a Senior System Architect to design robust, scalable, and maintainable software architectures. Enforces industry standards (PEP 8 for Python, ESLint for JS/TS), modular design, and security best practices. Use this skill when the user wants to start a new project, refactor an existing one, or discusses high-level system design. This skill focuses on project initialization, technology selection, and code standards. 支持中文触发:启动新项目、重构现有项目、系统设计、技术选型、代码标准、项目初始化、架构设计。
-
ysyecust Skill Ecc Tools Cost AuditECC ツール、エージェント、スキル、および実装のコスト監査を実施します。プロンプト入力トークンを分析して、計算効率を定量化します。
-
neronain Skill Security ScanRun full security scans on the codebase using Ruflo security tools
-
dirnbauer Bundle Typo3 Initial Release 3Prepare the first public 1.0.0 release of a TYPO3 14.3+ extension. Use for initial TER upload or Packagist publication readiness, composer.json release metadata, PHP/TYPO3 CI matrix verification, changelog, release notes and tagging an unreleased package. Coordinates the final release review and publication checklist; an ordinary conformance audit or whole-site migration is outside this workflow. Publishing requires explicit authorization.
-
dirnbauer Bundle Security Incident Reporting 3Builds security incident reports, DDoS post-mortems, timelines, IoC sections, CVE correlation, severity scoring, and blameless root cause analysis. Use when the user needs an incident report, post-mortem, forensics summary, security timeline, DDoS analysis, SIR, root cause analysis, or communication for a security event.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include phd-pre-submission-reviewer, notion-application-sync, sub2api-k12-space-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.