Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
carreiras Bundle Security Marco CivilGuia completo de conformidade com o Marco Civil da Internet (Lei 12.965/2014) e seu Decreto regulamentador (Decreto 8.771/2016) para desenvolvimento de software e operações de TI no Brasil. Use esta skill sempre que o usuário mencionar Marco Civil da Internet, logs de acesso à internet, guarda de registros de conexão, registros de acesso a aplicações, dados de tráfego, retenção de logs, quebra de sigilo de dados, requisição judicial de dados, neutralidade de rede, responsabilidade de provedores por conteúdo de terceiros, remoção de conteúdo, direito ao esquecimento digital, privacidade de comunicações online, segurança de provedores de conexão ou aplicação, ou quando o usuário perguntar "por quanto tempo guardar logs?", "preciso guardar IP dos usuários?", "posso ser responsabilizado por conteúdo de terceiros?", "como responder requisição judicial de dados?", "o que é registro de conexão vs. acesso a aplicações?", ou qualquer questão sobre obrigações legais de provedores de internet ou aplicações no Brasil.
-
dansnow Skill Spectra Audit 2Audit changed code for security sharp edges — dangerous defaults, type confusion, and silent failures
-
minorun365 Skill Kb Demo App Authデモアプリ・Webアプリの Cognito 認証のおすすめ構成。「Googleで続ける」か「メール+パスキー(パスワードも併用可)」の2経路をCDKとフロントでどう組むか、パスキーが動かない設定の罠、Google client secret の置き場、ログイン画面のUX規約、Googleの同意画面に出るアプリ名の扱い。新しくデモアプリを作るとき、既存アプリの認証を作り直すとき、パスキーやGoogleログインが動かないときに読む。
-
mstepan Bundle Java Micronaut DddUse when working on Java Micronaut applications, Micronaut HTTP APIs, jOOQ persistence, Micronaut Validation, Micronaut Security, Micronaut Messaging, DDD module boundaries, Testcontainers integration tests, MapStruct DTO mapping, transaction management, Redis adapters, or Lombok-free backend code.
-
nunchuk-io Skill Nunchuk Coin ControlInspect and manage a wallet's coins (UTXOs) - list and filter coins, lock and unlock them, and organize them with tags and collections including automatic rules (add untagged coins, add by tag, auto-lock). Use when the user wants to label, organize, protect, or audit individual coins, or set up automatic coin classification.
-
olgaiv39 Bundle Implementation IntegrityAudit an implementation for unnecessary artifacts, test manipulation, hardcoded shortcuts, fake success, bypassed product paths, and unsupported completion claims
-
rossoctl Bundle Dep Bump ScannerMonitor open Dependabot PRs across a GitHub org, classify by severity tier, flag SLA breaches, create GitHub issues for stale PRs, close issues for resolved PRs, and write structured JSON reports. Use when you need to audit dependency update health across an organization's repositories.
-
rossoctl Bundle Link Health ScannerScan all repos in a GitHub org for broken links using lychee, diff against previous results, create GitHub issues for new findings, close issues for fixed links, and write structured JSON reports. Use when you need to audit link health across an organization's repositories.
-
sitabanubanu Bundle Knowledge Video DecomposerExtract, normalize, segment, and audit first-hand video, audio, subtitle, transcript, or video URL material before any report is written. Use for source gates, ASR, Chrome/page probes, and video_analysis_pack creation.
-
t4ku Skill Add Github PermalinksAdd GitHub permalinks with fixed SHA/commit references to research documentation containing code snippets. Use when writing technical docs with code examples, creating investigation/research docs that reference source files, user asks to "add permalinks" or "add GitHub links", documenting code research findings with file:line references, or creating audit trails needing permanent code references. Triggers on "add github links", "add permalinks", "link to source", "make code references permanent".
-
igmarin Skill Quality 2Use for a pre-PR quality sweep: conventions, refactor, docs, linters, suite. Trigger words: before PR, quality sweep, production-ready, quality audit.
-
cristhianzl Bundle Developing Features 2Write production code in Langflow with security-first thinking, SOLID design, pragmatic principles, observability, and strict file-structure limits — tuned for Langflow conventions (uv workspaces, SQLModel, lfx vs langflow-base split, pre-commit invoked via uv run). Use when implementing a new feature, designing a service, refactoring backend code, adding an API route, or whenever the task is "build production code" rather than fix a bug or write tests. This is the default for feature and production-code work — use it unless the user explicitly asks for TDD (tests-first / red-green-refactor), which is developing-features-tdd. For new Components specifically, use building-langflow-components. Pairs with ensuring-cross-platform for portability and writing-tests for coverage.
-
fossasia Skill Pr Review 2Use this skill to review pull requests for VoxBento. Covers correctness, security, architecture compliance, and testing.
-
fossasia Skill Production Readiness Review 2Use this skill to evaluate whether VoxBento is ready for production deployment. Combines security, deployment, and operational readiness checks.
-
rohankhullar24-oss Bundle HumanizerRewrite, audit, or draft text so it reads like a human wrote it. Kills em dashes, robotic tone, AI-giveaway words, negative-parallelism reframes, forced analogies, and formulaic structure. Use this skill whenever the user invokes /humanizer or /delete-ai-words, asks to humanize text, "delete the AI words", "de-AI this", "make this sound less like AI", "audit this against the writing rules", "fix the AI writing", removes the "ChatGPT voice", or complains that a draft sounds robotic, stiff, or generated. Also trigger when the user says "audit your text" (target = your own most recent draft), and use it proactively whenever drafting content that will be read as the user's own words: emails, LinkedIn posts, blog articles, essays, bios, cover letters, newsletters, website copy, and social posts. Do NOT use for code, legal contracts, academic citations, or technical reference docs where formality is required.
-
navikt Bundle Security Review 3Assess a design or change for security and privacy risks. Use for sensitive data, identity, authorization, trust boundaries, privileged operations or a requested security review; use `auth-overview` to implement an authentication mechanism and `architecture-review` for broader design trade-offs.
-
navikt Bundle Security Review 4Assess a design or change for security and privacy risks. Use for sensitive data, identity, authorization, trust boundaries, privileged operations or a requested security review; use the full-context identity implementation workflow to implement an authentication mechanism and the full-context architecture assessment workflow for broader design trade-offs.
-
godzhiwzz-create Bundle Academic Manuscript WritingOwn stage-aware academic manuscript work from initial drafting through standardized polishing, pre-submission audit, major or minor revision, reviewer response, final-package handoff, and proof correction. Use for writing, restructuring, polishing, reviewing, revising, responding to reviewers, producing clean and marked-up manuscripts, or preparing manuscript content for submission. Select one manuscript stage first and enforce its mutation, mainline-preservation, prose, figure/table, response, and transition rules. Do not replace literature search, citation verification, statistics, figure rendering, Word/PDF production, research evidence management, or irreversible submission controls.
-
hassancs91 Skill Suggest SfxStep 4 of the AI Video Editor pipeline — the SFX pass. Analyze a video's beats + narration and propose tasteful sound effects synced to them, drawing from (and growing) a shared, reusable SFX library, then render an SFX-mixed audition preview. Use when the user wants to "add SFX / sound effects", "suggest sfx", "score the transitions", "sound-design this beat", generate/source sound effects, build or extend the sfx library/catalog, author or audit a sfx-plan, or mix SFX over a video-N preview in this repo. Covers reading timeline + edited-transcript + brand §10, the library-first flow, generating misses with the ElevenLabs Sound Effects API, the per-video sfx-plan.json, the hard user-audit gate, and mixing with tools/mix_sfx.py (light voice ducking). Not the music bed (that is the final-mix step) and not the visual beats (that is /make-tsx).
-
stackhawk Bundle OptimizeAnalyze a codebase and produce an optimal HawkScan setup — tech flags, scan-policy plugin selection, and stackhawk.yml corrections — then apply it as a non-destructive trial, run ONE trial scan, and promote or discard. Use when the user asks to "optimize my scan", "tune HawkScan", "make my scan faster", "reduce false positives", "pick the right plugins/policy for my app", or invokes /optimize. Also invoked automatically by the hawkscan skill on every fresh stackhawk.yml (Phase 0c) to set up the scan policy + tech flags (Setup mode), and re-runnable anytime via /optimize; the metrics Refine mode is surfaced when a scan is slow. Do NOT use for: a normal security scan or fixing vulnerabilities (use the hawkscan skill); querying existing findings or posture (use the api skill); or editing stackhawk.yml without optimizing/scanning. Requires an onboarded StackHawk app + env and a `hawk` build whose `hawk op` has the `policy` write commands.
-
just1cup Bundle Secure APIEnforce security and performance best practices whenever Claude is writing, reviewing, or designing code that touches APIs — as a client consuming external APIs (REST, WebSocket, GraphQL) or as a server exposing endpoints. Trigger on ANY of the following: - Writing API client code (fetch, reqwest, axios, httpx, or any HTTP lib) - Writing or reviewing API route/handler code - Integrating with external services (VirusTotal, AbuseIPDB, Shodan, Stripe, etc.) - Storing or transmitting API keys, tokens, or secrets - Designing request/response payloads, pagination, or caching strategies - Reviewing code that makes HTTP requests or exposes HTTP endpoints - Phrases: "call the API", "integrate with", "API key", "rate limit", "auth token", "fetch data from", "send request", "endpoint", "REST", "WebSocket", "cache the response", "retry logic", "timeout", "bearer token", "secret", "credentials" Apply to Rust, TypeScript/JavaScript, Python, Go, and shell scripts equally. When in doubt, apply — over-triggering is better tha
-
just1cup Bundle Security Code ReviewUse this skill whenever the user wants to write code, security review, vulnerability analysis, or security audit of any code snippet, file, or codebase. Trigger on: "review my code for security issues", "check for vulnerabilities", "is this code secure?", "security audit", "find bugs/flaws in this code", "OWASP", "pen test this code", "is there an injection here?", "check for XSS/SQLi/SSRF/auth issues", or any request to analyze code with a security lens. Also trigger when the user pastes code and asks "what's wrong with this?" in a security context, or asks Codex to find security bugs before a deployment or code review. Apply even when the user doesn't say "security" explicitly but the context clearly involves hardening, authentication, authorization, input validation, or cryptography. When in doubt, apply this skill.
-
coryparrry Bundle Deep Code ReviewReview a repository snapshot or code change for evidence-backed correctness, security, compatibility, and regression risks. Use for deep, exhaustive, repository-wide, adversarial, or AI-generated code review.
-
coryparrry Bundle Appstore Readiness AuditAudit Apple apps before App Store upload or review. Use when checking a release candidate for build, runtime, privacy, SDK, account, payment, metadata, compliance, or reviewer-access rejection risks. Return read-only, evidence-backed upload and submission verdicts.
-
pedrohcgs Skill Deep Audit 2Deep consistency audit of the entire repository infrastructure. Launches 4 parallel specialist agents to find factual errors, code bugs, count mismatches, and cross-document inconsistencies. Then fixes all issues and loops until clean. Use when: after making broad changes, before releases, or when user says "audit", "find inconsistencies", "check everything".
-
pedrohcgs Skill Visual Audit 2Perform adversarial visual audit of Quarto or Beamer slides checking for overflow, font consistency, box fatigue, and layout issues.
-
pedrohcgs Skill Slide Excellence 2Comprehensive slide excellence review combining visual audit, pedagogical review, and proofreading. Produces three reports and a combined summary.
-
pedrohcgs Skill Audit Reproducibility 2Enforce the replication-protocol.md rule by cross-checking numeric claims in a manuscript against the actual R / Stata / Python outputs. Report PASS/FAIL per claim against tolerance thresholds. Use before submission and before releasing a replication package.
-
jsuvic Skill Loop Security Patch Retest 3Use to run a bounded security-review, patch, and retest loop that stops on green, on no diff, or on a repeated identical finding.
-
steliord Skill Repo MaintainerAudit and repair repository hygiene across artifacts, dependencies, CI, docs, Git state, and code-quality signals. Use for repository maintenance, cleanup, health checks, or pre-release hardening.
-
perry-lynn Bundle Story Originality Audit审查中文小说、网文、改编稿和参考驱动写作的原创性距离,建立参考来源清单,比较文字重合、专有组合、情节节点顺序、人物关系映射、世界规则和标志性表达,区分通用题材惯例、合理借鉴、需改写依赖与高风险近似。用户提到原创性、洗稿风险、撞梗、抄袭自查、同人转原创、参考某书写、改编距离、文本相似或发布前来源审计时使用。
-
sage-bionetworks Bundle Evolve ClaudemdUpdate existing CLAUDE.md files by analyzing code changes, GitHub PRs/issues, Jira/Confluence since last modification, with full accuracy audit.
-
tscarpe Bundle Sdlc SyncSyncs local SDLC artifacts (requirement digest/audit/checklist, test cases) to a team-facing web platform and pulls PM clarification answers back into local markdown files. Bridges the single-developer local workflow with multi-role collaboration: push artifacts for sharing, pull answers to close the clarification loop, publish the clarified standard requirement document, register test cases for team traceability. Use when the user wants to 推送产物到平台 / 同步到平台 / 拉回答复 / 发布标准文档 / 用例上平台 / sdlc-sync. 触发词:同步平台、产物上平台、推送需求、拉回答复、用例登记、sdlc-sync.
-
tscarpe Bundle Sdlc Config Review扫描当前分支相对基线分支(master/main)的 Java 代码 diff,提取发版前需在代码之外人工处理的事项——①配置中心(Apollo/Nacos)Key:@Value 单值、@ConfigurationProperties 前缀、任意注解属性中的 ${...} 占位符;②外部平台注册操作:@XxlJob 任务(新增/改名/孤儿检测)、RocketMQ/Kafka/Rabbit listener 订阅关系;③行为知会项(@Scheduled 集群重复执行等)。产出配置 Key 清单 + 平台操作清单 + 知会项。Use when 用户要梳理上线配置清单、检查新增配置 Key、准备 Apollo/Nacos 发版配置、检查新增定时任务/xxl-job 任务/MQ 订阅,或说 config-sentinel、config review、Apollo/Nacos key audit、release config checklist、xxl-job audit、上线检查。
-
alenpjose Bundle Audit Obs Native PluginAudit native OBS Studio plugins for API contract compatibility, source callback registration, per-instance isolation, C++ lifetime and thread safety, rendering discipline, teardown, CMake configuration, and optional Aitum integration. Use for repository audits, OBS version upgrades, module-load failures, or suspected source/output ownership defects.
-
alenpjose Bundle Release Curious Bipedal OverlayCoordinate audit, runtime, visual, packaging, evidence, GitHub draft-PR, and artifact-delivery gates for the Curious Bipedal native OBS Overlay. Use only for this repository's Windows x64 releases, validation reports, user test checklists, or release-candidate decisions.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-marco-civil, spectra-audit, kb-demo-app-auth. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.