Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ww-w-ai Bundle Code Review 3Automated code review with quality checks, security audit, and best practices. Analyzes code for bugs, performance issues, and convention violations. Triggers: code review, review code, check code, analyze code, PR review, 코드 리뷰, 코드 검사, 코드 분석, コードレビュー, コード分析, 代码审查, 代码分析, revision de codigo, revue de code, Code-Review, revisione Do NOT use for: architecture review (use $phase-8-review), deployment (use $phase-9-deployment).
-
ww-w-ai Bundle Phase 8 Review 3Phase 8: Code Review & Architecture Review. Comprehensive review of code quality, architecture compliance, performance, and security. Triggers: code review, architecture review, review, quality check, 코드 리뷰, 아키텍처, コードレビュー, 代码审查, revisión de código, revue de code, Code-Review, revisione del codice Do NOT use for: initial design (use $phase-3-mockup), deployment (use $phase-9-deployment). Next: $phase-9-deployment
-
bobmatnyc Bundle Security Scanning 3CI security scanning: secrets, deps, SAST, triage, expiring exceptions
71 -
drunkcoding Bundle Academic RebuttalWrite conference paper rebuttals and author responses that effectively counter incorrect or unreasonable reviewer comments. Targets systems venues (OSDI, NSDI, SIGCOMM, MOBICOM, SOSP, ASPLOS, EuroSys, USENIX Security, CCS, PLDI) on HotCRP and ML venues (NeurIPS, ICML, ICLR, AAAI) on OpenReview. Core focus: identify and resolve reviewer false impressions with evidence-backed, firm-but-professional corrections. Covers rebuttal triage, false impression taxonomy (8 types with resolution playbooks), venue-specific constraints, response structure patterns, and ready-to-use phrase templates. Use when asked to write, draft, review, or improve a conference paper rebuttal, author response, or response to reviewer comments.
-
24601 Bundle Design Review 3Designer's eye QA: finds visual inconsistency, spacing issues, hierarchy problems, AI slop patterns, and slow interactions — then fixes them. Iteratively fixes issues in source code, committing each fix atomically and re-verifying with before/after screenshots. For plan-mode design review (before implementation), use /plan-design-review. Use when asked to "audit the design", "visual QA", "check if it looks good", or "design polish". Proactively suggest when the user mentions visual inconsistencies or wants to polish the look of a live site. (gstack)
34 -
paulieb89 Bundle Workflow Auditor 2Analyse a business workflow to find where time is actually lost and recommend specific improvements. Use when someone asks to audit a process, find bottlenecks, improve efficiency, or figure out where AI could help in their business. Based on Theory of Constraints thinking.
-
yigityildiz0 Bundle Brand 2Create, update, apply, and audit brand strategy, voice, messaging, visual identity, asset rules, and governance. Use for brand guidelines, tone of voice.
-
carlkibler Bundle Trust AuditAudit product trust: permissions, privacy, billing, file changes, and silent failures.
-
carlkibler Bundle Empathy AuditReview code through user, machine, developer, and support lenses.
-
carlkibler Bundle Launch SequenceRun first-contact, support-storm, trust-audit, and pre-mortem for a launch verdict.
-
carlkibler Bundle Django Smoke AlarmRun and triage Django/DRF security smoke checks before shipping or after scanner findings.
-
carlkibler Bundle Status Copy Trust AuditAudit CLI and app status wording, repeated-run behavior, and client label alignment.
-
cbusillo Bundle Docs LookupUse when the answer depends on external docs or environment-specific operational context rather than local repo code alone; includes discovering source-of-truth docs and access paths for private operations such as DNS or Cloudflare records, and finding where a credential, API token, or secret is stored, but not performing infrastructure actions or mutations.
-
05-deepak-patidar Skill Saas Multi TenancyTenant isolation and lifecycle for multi-tenant SaaS — data scoping that fails closed, tenant context propagation, noisy neighbors, per-tenant operations. Use when building B2B/B2C SaaS with multiple customers on shared infrastructure, adding tenant-scoped tables or features, debugging cross-tenant data leaks, or when the user says "multi-tenant", "tenant isolation", "SaaS", "workspace", "organization data", or "row-level security".
-
05-deepak-patidar Skill Dependency DisciplineChoosing, pinning, upgrading, and auditing third-party dependencies — and supply-chain safety. Use when adding a library or framework, running npm/pip/cargo installs, responding to a CVE or security advisory, upgrading major versions, or when the user says "which library", "add a package", "dependency", "vulnerability alert", "outdated packages", or "supply chain".
-
05-deepak-patidar Skill Observability ReadinessLogging, metrics, tracing, alerting, and audit trails so production problems are diagnosable from the outside. Use when adding logging, setting up monitoring or alerts, instrumenting a service, preparing for launch, or when the user says "logging", "monitoring", "observability", "alerts", "metrics", "audit trail", or "how do I know if it's working in prod".
-
cor-incorporated Bundle Code ReviewerReview code for quality, security, and best practices across TypeScript, JavaScript, Python, Go, Swift, and Kotlin. Analyzes PRs with automated scripts (pr_analyzer, code_quality_checker, review_report_generator), checks for OWASP vulnerabilities, validates naming/structure/error handling, and generates actionable review reports. Use when: reviewing a pull request, providing code feedback, checking code quality before merge, auditing security of changes. Do NOT use for: writing new code, fixing bugs (use /bugfix), generating tests, or architectural design (use /modern-architecture).
-
xu-xiang Skill Springboot SecuritySpring Boot 服务的 Spring Security 身份验证/授权、验证、CSRF、密钥、响应头、速率限制和依赖项安全最佳实践。
-
first-fluke Bundle Oma Academic Writing 3Academic writing capability for publication-grade English prose. Drafts, revises, and audits essays, reports, analysis sections, executive summaries, conclusions, and literature reviews while enforcing sentence-structure variation, high-frequency academic verbs, calibrated hedging, and anti-AI stylistic compliance. USE for academic writing, essay polish, paragraph rewrite, prose revision against any rubric tier (HD/D/C, A/B/C, top-band/mid-band, etc.), anti-AI audit, reverse outlining, claim-evidence mapping, and rubric enforcement on assignments.
-
galihadiprayoga Skill Laravel SecurityLaravel security best practices — authentication, authorization, Eloquent safety, CSRF, XSS prevention, API security, and secure deployment configurations.
-
natan-mohart Skill Assumption AuditSurfaces every unstated belief a strategy or business case depends on, grades the evidence behind each one, and stress-tests the ones that would break the plan if wrong — using a load-bearing-assumption framework, not a generic risk brainstorm. Use before any strategy, business case, or major decision is finalized or presented, whenever the user asks "what could go wrong," "are we sure about this," or wants a pre-mortem, or when a plan has gone unchallenged for a while.
-
abchoudh-amd Bundle Grill MeCodebase-first interview protocol for planning and design decisions, plus a stress-test front door, answering live in the current turn. Use when the user asks to be grilled about a plan, design, PR, architecture, audit, or decision proposal, or when a calling skill's own contract routes its questions here.
-
onfire-ai Skill Hiring SignalsFind open job postings at target companies using the `ask_onfire` tool against the `job_post` entity. Use when the user wants to know what roles a company is actively hiring for, where they're hiring, what seniority they're posting, which companies are hiring for a technology or skill, what open positions signal budget or expansion - phrases like "what is Northwind hiring for?", "find VP-level roles at my target accounts", "which accounts are expanding their security team?", "find buyers at companies hiring AI engineers", "show open data engineer roles in EMEA", or any job posting / hiring signal lookup.
-
onfire-ai Skill Entity People SearchSearch for people/prospects directly from Onfire's LinkedIn people entity (ONFIRE.PEOPLE = entity `contact`) using the `ask_onfire` tool. Use when the user wants to find prospects by job title, company, location, seniority, persona/role, technology footprint, or keywords in their profile — phrases like "find engineers at Northwind", "who are the VPs of Security at banks in the US", "show me people with 'Loglytics' in their job summary", "look up this LinkedIn URL", or any people search that doesn't require Forschung's cross-database scoring.
-
elinking-111 Bundle AdsMulti-platform paid advertising audit, optimization, and agency operations skill. Analyzes Google, Meta, YouTube, LinkedIn, TikTok, Microsoft, and Apple Ads, plus reporting, tracking, API connectors, policy compliance, shopping feeds, client onboarding, mobile UA, and local services. 250+ checks with scoring, parallel agents, industry templates, and creative generation.
-
elinking-111 Skill Ads AuditFull multi-platform paid advertising audit with parallel subagent delegation. Analyzes Google Ads, Meta Ads, LinkedIn Ads, TikTok Ads, and Microsoft Ads accounts. Generates health score per platform and aggregate score. Use when user says audit, full ad check, analyze my ads, account health check, or PPC audit.
-
elinking-111 Skill Ads LandingLanding page quality assessment for paid advertising campaigns. Evaluates message match, page speed, mobile experience, trust signals, form optimization, and conversion rate potential. Use when user says landing page, post-click experience, landing page audit, conversion rate, or landing page optimization.
-
elinking-111 Skill Ads CreativeCross-platform creative quality audit covering ad copy, video, image, and format diversity across all platforms. Detects creative fatigue, evaluates platform-native compliance, and provides production priorities. Use when user says creative audit, ad creative, creative fatigue, ad copy, ad design, or creative review.
-
elinking-111 Bundle Ads Mobile UaMobile app user acquisition strategy and audit across Google App Campaigns, Meta app campaigns, TikTok app campaigns, Apple Ads, SKAN/AdAttributionKit, MMPs, creative testing, app events, and store conversion. Use when the user mentions mobile UA, app installs, iOS/Android campaigns, UAC, app events, SKAN, AdAttributionKit, AppsFlyer, Adjust, Branch, Singular, CPI, CPP, trial, subscription, ROAS, retention, or app store conversion.
-
elinking-111 Bundle Ads Local ServicesLocal services paid ads strategy and audit for Google Search, Google Local Services Ads, Maps, call ads, Meta local lead ads, Microsoft Ads, service-area businesses, franchises, clinics, home services, legal, real estate, appointments, and call/lead quality tracking. Use when the user mentions local ads, service area, calls, bookings, appointments, Google LSA, local PPC, lead quality, locations, Maps, store visits, call tracking, or geo budget allocation.
-
shawnxxxqazwsx Bundle Goal GuardApply evidence and progress guards to an active Codex Goal without replacing its lifecycle. Use when the user explicitly asks to guard a goal, prevent false-green checks or empty goal turns, audit completion evidence, coordinate parallel goal work, or diagnose repeated goal turns and blockers.
-
shawnxxxqazwsx Bundle Pigora Eq AuditAudit deployed Pigora EQ plug-ins with a detailed, reproducible control and response matrix. Use for post-deployment verification, comprehensive module audits, or targeted rechecks of user-reported curve defects. Covers Bell, shelves, HPF/LPF, native modes, interpolation, automation and installed audio. Do not use for routine fitting, automatic full audits after every build, or GUI-only review.
-
wuyue12-tech Bundle HallmarkAnti-AI-slop design skill for greenfield pages, audits, redesigns, and design extraction from URLs or screenshots. Use when the user asks to build a new app or landing page, wants to redesign something, invokes Hallmark by name, or uses audit/redesign/study.
-
sepivip Bundle NetwatchNetwork monitoring and security audit. Use when: user asks to scan network, check open ports, network audit, who's on wifi, check connection, port scan, firewall check, network status, or network security. Don't use when: user asks about crypto transactions (use solana tools) or web search (use research skill).
-
cwijayasundara Skill Clarify 2Bounded clarification gate for resolving product, domain, API, security, or architecture uncertainty without exhausting the user.
-
tmforum-oda Skill Audit Implementation Against UsecaseGiven a TMFSxxx use-case id and an existing implementation (codebase, API contract, or integration config), checks whether the implementation actually follows the use case's described flow and calls the right real APIs, flagging drift from spec. Use this to audit an existing system against ODA, not to design a new one.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include code-review, phase-8-review, security-scanning. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.