Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
marcelinero Bundle Auditoria Esg Sostenibilidad 2Auditar reportes y desempeño ambiental, social y de gobernanza (ESG), incluyendo aseguramiento de divulgaciones de sostenibilidad bajo ISSB (IFRS S1/S2), GRI, TCFD y SASB, y la efectividad del sistema de gestión de sostenibilidad. Activar siempre que se hable de auditoría ESG, sustainability audit, reporte de sostenibilidad, ISSB, IFRS S1, IFRS S2, GRI, SASB, TCFD, CSRD, ESRS, doble materialidad, alcance 1, alcance 2, alcance 3, GHG Protocol, huella de carbono, net zero, cambio climático, derechos humanos, debida diligencia ESG, taxonomía verde.
-
marcelinero Bundle Auditoria Tecnologia Informacion 2Auditar el gobierno de TI, los controles generales de TI (ITGCs) y los controles automatizados de aplicación, evaluar la gestión de cambios, accesos lógicos, operaciones, continuidad y seguridad tecnológica conforme a COBIT, ITAF, GTAGs e ISO 27001. Activar siempre que se hable de auditoría de TI, IT audit, controles generales de TI, ITGC, COBIT, gobierno de TI, gestión de accesos, gestión de cambios, gestión de operaciones, computación en la nube, SaaS auditoría, BCP, DRP, continuidad de negocio, virtualización, ERP, SAP, Oracle, integraciones, interfaces, batch jobs, base de datos auditoría.
-
mangowhoiscloud Skill Codebase Audit 2Codebase audit + refactoring workflow. Dead code detection, God Object splitting, duplicate function removal, design flaw identification, frontier comparison verification. Triggered by "audit" ("감사"), "dead code" ("데드코드"), "refactor" ("리팩토링"), "god object", "duplication" ("중복"), "design flaw" ("설계 결함") keywords.
-
sodam-ai Skill Persona Lawyer15년+ 전문 변호사 페르소나(#11) 깊은 도메인. 법률·계약·면책·규제·약관·audit·자본시장법·GDPR·개인정보·저작권·라이선스·AML·컴플라이언스 맥락 시 활성.
-
vignesh-nagarajan-vn Bundle Claim TraceCross-check every number in a paper, report, or README against the run artifacts it should have come from, and flag the ones with no source. Use before submitting or publishing anything containing results, after re-running experiments, when a results directory has been regenerated, and when asked to verify or audit reported figures. Runs scripts/trace_claims.py.
-
zakblacki Bundle Botble REST APIBuild, refactor, or review Botble CMS REST APIs for mobile apps or integrations, including BaseApiController responses, JSON resources, Sanctum authentication, optional guest auth, API headers, rate limiting, guest carts, routes/api.php, and API security.
-
tradecatlabs Skill Web3 Poc FoundryComplete Foundry PoC writing guide + all cheatcodes + DeFiHackLabs reproduction patterns. Use this when building a proof of concept exploit, setting up a fork test, using Foundry cheatcodes, or reproducing a known DeFi hack for learning.
-
op0ai Skill Convex Helpers Patterns 3Guide for convex-helpers library patterns including Triggers, Row-Level Security (RLS), Relationship helpers, Custom Functions, Rate Limiting, and Workpool. Use when implementing automatic side effects, access control, relationship traversal, auth wrappers, or concurrency management. Activates for triggers setup, RLS implementation, custom function wrappers, or convex-helpers integration tasks.
-
cogine-ai Bundle Security Best Practices 2Use when the user explicitly requests security best practices guidance, a security review or report, or secure-by-default coding help for Python, JavaScript or TypeScript, or Go code.
-
s-hiraoku Skill Code Review 2Perform structured code reviews focusing on correctness, readability, security, and maintainability. Use this skill when reviewing pull requests, evaluating code changes, or establishing review standards for a team.
-
netalertx Skill Netalertx Skill HygieneRead before writing or editing any SKILL.md, or any research/audit doc in .gemini/internal-docs/research/. Covers the two standing rules for living-reference prose - state current behavior only, and prefer plain, short wording - plus the grep sweep to run before calling a doc clean. PRDs are the deliberate exception (they keep a correction trail).
-
netalertx Skill Database Patterns 2NetAlertX database architecture patterns. Use this when designing features that write to the Devices table, implementing audit/history logging, or choosing between trigger-based vs Python-hook approaches.
-
0x0w1 Bundle Jig Conformance AuditUse to check whether a repository's history actually followed the jig procedure: conventional squash subjects, Release-Grade trailers on unreleased work, version tag format and placement, the main/develop fast-forward invariant, and a committed rubric. Read-only, exits non-zero on violations, and runs in CI.
-
mangowhoiscloud Skill Anti Deception Checklist 2Verification checklist to prevent fake success. Detects test deletion/disabling, coverage regression, lint bypass, secret exposure. Triggered by "deception", "fake" ("가짜"), "fake success", "verification" ("검증"), "checklist" ("체크리스트"), "deletion detection" ("삭제 탐지"), "regression" keywords.
-
compozy Bundle Refactoring Analysis 3Analyzes codebases to identify refactoring opportunities based on Martin Fowler's catalog of code smells and refactoring techniques. Detects duplicated code, high coupling, complex conditionals, primitive obsession, long functions, and other structural issues. Produces a structured refactoring report with prioritized findings saved to docs/_refacs/. Use when auditing code quality, preparing for a refactoring sprint, or reviewing architectural health. Don't use for style/formatting issues, performance optimization, or security audits.
-
arcasilesgroup Skill AI Debug 2Diagnoses broken behavior systematically with a 4-phase root-cause loop: test failures, runtime errors, crashes, regressions. Never patches symptoms. Trigger for 'it is not working', 'something broke', 'this used to work', 'I am getting an error', 'CI is failing', 'why is X happening'. Not for adding tests; use /ai-test instead. Not for security findings; use /ai-security instead.
-
arcasilesgroup Bundle AI Verify 2Verifies claims with evidence, not assumptions: runs deterministic + acceptance specialists post-W3 (`normal` implicit, `--full` explicit), plus a `--release` mode aggregating 8-dimension release readiness (coverage, security, tests, lint, dependencies, types, docs, packaging) into a GO/CONDITIONAL GO/NO-GO verdict. Trigger for 'check my code', 'is this ready to merge', 'run the tests', 'is coverage good enough', 'scan for security issues', 'prove it works', 'pre-release checklist', 'GO/NO-GO'. Not for narrative code review with human judgment; use /ai-review instead.
-
45ck Skill Vocabulary Audit Beads 2Audit UI terminology and create Beads issues from the findings. Converts terminology drift, overloaded terms, and vague labels into trackable Beads tasks with priorities and dependencies.
-
45ck Skill Consistency Audit Beads 2Audit cross-screen consistency and create Beads issues from the findings. Converts consistency breaks and invariant violations into trackable Beads tasks with priorities and dependencies.
-
45ck Skill Failure Path Audit Beads 2Audit failure paths and create Beads issues from the findings. Converts unhandled failure states, missing empty states, and broken recovery paths into trackable Beads tasks with priorities and dependencies.
-
stiron92-byte Bundle Content Repurpose원본 콘텐츠(유튜브 대본, 강의, 회의록, 블로그 글 등)를 여러 플랫폼에 최적화된 콘텐츠로 자동 변환합니다. 콘텐츠 리퍼포징, 감사(audit), 갭 분석을 지원합니다. "블로그 글을 인스타용으로 바꿔줘", "유튜브 대본 SNS로 변환", "콘텐츠 재활용", "콘텐츠 리퍼포징", "하나의 글을 여러 플랫폼에 올리고 싶어", "원소스 멀티유즈", "이 글을 트위터 스레드로", "뉴스레터로 바꿔줘", "숏폼 스크립트로 변환", "이 영상 대본을 블로그로", "콘텐츠 감사", "콘텐츠 갭 분석", "경쟁 채널 비교", "콘텐츠 전략", "repurpose", "content repurpose", "multi-platform content", "SNS 콘텐츠 만들어줘", "플랫폼별 콘텐츠", "콘텐츠 변환", "게시물 변환", "포스팅 변환" 등의 요청에 사용하세요. 콘텐츠를 다른 형태로 바꾸거나, 하나의 소스를 여러 채널에 맞게 재가공하려는 모든 상황에서 이 스킬을 트리거하세요.
-
neversight Bundle Llvm Security 2Apply or develop LLVM sanitizers, compiler hardening, and exploit mitigations. Use when secure compilation is central, not for general vulnerability analysis unrelated to the toolchain.
-
sethdford Skill Aspect Panel 2Run a panel of 5 specialized verifiers (correctness, edge-case, security, regression, style) in parallel against a change, with confidence-weighted voting. Disagreement (40-60% pass share) escalates to lead. Replaces single-critic for high-stakes review. Triggers on /aspect-panel, "panel review", "multi-aspect verify", "review with multiple critics".
-
bradgroux Bundle PersistencePersistence Demo
-
bradgroux Bundle ExfiltrationExfiltration Collector
-
bradgroux Bundle Review ChecklistReview Checklist
-
bradgroux Bundle Remote ScriptRemote Script Demo
-
bradgroux Bundle Document FormatterDocument Formatter
-
bradgroux Bundle Hidden InstructionHidden Instruction Demo
-
bradgroux Bundle Capability MismatchCapability Mismatch Demo
-
bradgroux Bundle Unpinned DependencyUnpinned Dependency Demo
-
autsachi Bundle Scrutinizeตรวจสอบ plan, PR, diff, design document หรือ code change แบบ end-to-end จากมุมมองคนนอก โดยทบทวน intent มองหาวิธีที่เล็กกว่า ไล่ actual code path และยืนยันว่า change ทำตามที่กล่าวอ้างจริง ใช้เมื่อผู้ใช้ขอ review, audit, sanity-check, second opinion, ตรวจแผน หรือตรวจความเสี่ยงก่อน merge โดย default ให้รายงานอย่างเดียวและไม่แก้ไฟล์
-
autsachi Bundle Audit Product ExperienceAudit a product experience before changing UI code. Use for UX reviews, responsive behavior, mobile/tablet/desktop or device-specific experiences, confusing flows, duplicated views or modes, reader/editor layouts, control density, gestures, navigation, and interface simplification. Establish user goals, usage contexts, capability boundaries, and an interaction contract first; require an approved mockup before structural UI changes; implement only when explicitly authorized.
-
bhoon716 Bundle Deep Code ReviewUse when the user wants a pull request, diff, commit, patch, branch, or set of changed files reviewed through independent specialist passes for actionable issues introduced or worsened by the change. Orchestrate mandatory correctness and contract-test reviews, conditionally add security, reliability, architecture, or infrastructure reviews, independently verify candidate findings, remove root-cause duplicates, and synthesize only confirmed issues into an evidence-backed verdict. Do not use for simple code explanations, implementation-only requests, formatting-only cleanup, generic programming advice, or full-codebase audits unrelated to a specific change.
-
carreiras Bundle Security LgpdGuia completo de conformidade com a LGPD (Lei Geral de Proteção de Dados — Lei 13.709/2018) para desenvolvimento de software e operações de TI no Brasil. Use esta skill sempre que o usuário mencionar LGPD, proteção de dados pessoais, dados sensíveis, consentimento, base legal, titular de dados, ANPD, DPO (Encarregado), ROPA (Registro de Atividades de Tratamento), DPIA (Relatório de Impacto), DSR (requisição de titular), incidente de dados, vazamento de dados, anonimização, pseudonimização, retenção de dados, transferência internacional, privacy by design, privacy by default, ou quando o usuário perguntar "isso está em conformidade com a LGPD?", "preciso de consentimento para isso?", "como implementar LGPD no sistema?", "quais dados posso coletar?", "como responder uma solicitação de titular?", ou qualquer variação relacionada à privacidade de dados pessoais de usuários brasileiros ou de sistemas operando no Brasil.
-
carreiras Bundle Security Pci DssGuia completo de conformidade com o PCI-DSS v4.0 (Payment Card Industry Data Security Standard) para desenvolvimento de software e operações que envolvem dados de cartão de pagamento. Use esta skill sempre que o usuário mencionar PCI-DSS, PCI, dados de cartão, número do cartão, PAN (Primary Account Number), CVV, CVC, dados de portador de cartão, CHD (Cardholder Data), SAD (Sensitive Authentication Data), tokenização de cartão, ambiente de dados de cartão (CDE), QSA, SAQ, ROC, escopo PCI, segmentação de rede para PCI, criptografia de dados de cartão, mascaramento de PAN, pagamento online, gateway de pagamento, processadora de pagamento, adquirente, emissor, bandeira (Visa, Mastercard, Amex, Elo), antifraude, 3DS, ou quando perguntar "posso armazenar o CVV?", "como tokenizar cartões?", "qual é o escopo do PCI?", "preciso de certificação PCI?", "como reduzir escopo PCI?", "posso guardar dados de cartão?".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include auditoria-esg-sostenibilidad, auditoria-tecnologia-informacion, codebase-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.