Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
open-mercato Bundle Code Review 2Review code changes for architecture, security, conventions, and quality compliance. Use when reviewing pull requests, code changes, or auditing code quality.
-
uukuguy Skill Security ReviewSecurity-focused code review guidelines
-
cloudflare Skill Workerd API ReviewPerformance optimization, API design & compatibility, security vulnerabilities, and standards spec compliance for workerd code review. Covers tcmalloc-aware perf analysis, compat flags, autogates, web standards adherence, and security patterns. Load this skill when reviewing API changes, performance-sensitive code, security-relevant code, or standards implementations.
2.1k -
pchalasani Bundle Avoid AI WritingAudit and rewrite content to remove AI writing patterns ("AI-isms"). Use this skill when asked to "remove AI-isms," "clean up AI writing," "edit writing for AI patterns," "audit writing for AI tells," or "make this sound less like AI." Supports a detect-only mode, an edit-in-place mode for files, an optional voice profile (casual / professional / technical / warm / blunt), and an iterate-to-convergence pass.
-
getsentry Bundle Fix Security Vulnerability 2Analyze and propose fixes for Dependabot security alerts
845 -
jx1100370217 Bundle Security HardeningOpenClaw Security Hardening Skill
-
zate Skill Setup 2Inspect and optionally install security scanning tools for the security plugin
-
bitwarden Skill Auditing Hackerone VulnsAction tokens (sorted order in output)
-
av Skill Facts Discover 2Scan the codebase and classify every fact by lifecycle stage — tag @draft, @spec, or @implemented based on what the code actually shows. Add missing facts, fix inaccurate ones, remove obsolete ones. Use when asked to discover facts, bootstrap or update a fact sheet, scan the codebase for truths, sync facts to match the code, or audit the fact sheet for accuracy.
-
dzhng Skill Code Review 2Review changed code for naming, stale references, unnecessary complexity, and comment quality. Use after completing implementation work, before committing, or when the user asks to review or audit code.
-
harshsinghmp Bundle Code Review 2A language-agnostic code review method derived from Linus Torvalds' review corpus. Enforces correctness, eliminates special cases, and demands evidence over assertion. Trigger when: (1) reviewing PRs, diffs, patches, or commits; (2) auditing data structures, memory safety, concurrency, or API stability; (3) refactoring edge cases and special cases into clean representations; (4) demanding proof, benchmarks, or reproducer evidence for code changes; (5) user requests a Linus Torvalds style, no-nonsense, or rigorous code review; (6) reviewing diffs that touch tests, specs, or snapshots to confirm the spec stayed authoritative and tests were never weakened to match broken behavior; (7) security review of a diff or module (OWASP-style control pass); (8) receiving or acting on code review feedback; (9) turning review findings into verified fixes.
-
affaan-m Skill Django Verification 5Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.
226k -
ashhas Bundle Dependency UpdaterDiscover, classify, and batch-apply dependency and plugin updates for any project, whatever the stack. Maven, Gradle, npm/Yarn/pnpm, pip/Poetry, Cargo, Go, Flutter/pub, and others. Use when the user says "update dependencies", "check for updates", "bump versions", or "dependency audit".
-
ezra144israel Skill Ship Or FixOracle-frozen Builder and independent-Judge convergence cycle. Load ONLY when the operator explicitly sets Governance Dial G2 for the task, or explicitly names this skill or an active work unit already running it. Never auto-activate on task class, such as security, auth, or payments. If a task seems to warrant G2 and the operator has not said so, ask first. Not for ordinary governed implementation, analysis, review-only, or documentation work.
-
ezra144israel Skill Better CodingEvaluate minimum-sufficient implementation routes and enforce the selected route for a fixed, authorized outcome. Use after outcome, scope, authority, and acceptance evidence are fixed. Do not choose outcomes, set acceptance, adjudicate governance, grade finished work, design tests alone, conduct security audits, or perform unrelated cleanup.
-
jaycheng113 Skill OAUTH PkceImplement the OAuth 2.0 authorization code flow with PKCE for a client that cannot keep a secret.
-
veschin Skill Write A SkillUse when asked to create, improve, or audit an OMP skill — managed/global or local/project. Picks the right install location so a project skill never lands in the global root, and decides the reuse/ mirror for spawn binding.
-
vorlaxen-labs Bundle Bar JSFramework-agnostic TypeScript API response builder (@vorlaxen-labs/bar-js). Standardizes JSON envelopes with semantic presets, request tracing, pagination, cookies, hooks, and security headers. Use when building REST API responses, Express middleware, res.builder patterns, or consistent error/success shapes.
-
wazuh Skill Resolve Cve 2Resolve a dependency CVE in the Wazuh Dashboard notifications plugin — confirm the vulnerable package is actually present and reachable, apply the least-invasive remediation (direct bump, lockfile dedupe, or scoped resolution), verify build/tests/audit, and hand off a prepared PR. Use when the user asks to fix or resolve a CVE / dependency vulnerability, or provides a CVE id or CVE issue URL.
-
yunhe-dev Skill Codexskin Theme SwitcherList, apply, hot-switch, audit, roll back, status-check, and restore installed CodexSkin themes through a loopback-only Codex Chromium endpoint.
-
dsifry Skill Design Review Gate 2Automatic review gate that runs after brainstorming completes - spawns PM, Architect, Designer, Security, and CTO agents in parallel, iterates until all approve
-
hrygo Bundle Hotplex CLI使用 HotPlex CLI 处理 Cron、明确请求的 Slack 操作、普通用户聊天命令指引,以及只读 status、doctor、security、config 诊断。不要用于飞书写操作、发布、服务安装、二进制更新或 Admin 变更。
-
jabrena Bundle 112 Java Maven Plugins 2Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchmarking (JMH) — through a consultative, modular step-by-step approach that only adds what you actually need. Part of the skills-for-java project
-
jabrena Bundle 124 Java Secure Coding 2Use when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing attack surface via least privilege, applying strong cryptographic algorithms, handling exceptions securely without exposing sensitive data, managing secrets at runtime, avoiding unsafe deserialization, and encoding output to prevent XSS. Part of the skills-for-java project
-
awesomemotive Bundle Pushengage DebugUse when invoked by a PushEngage platform spoke (pushengage-ios, etc.) to diagnose a broken integration. Runs a static audit, matches against a version-pinned known-issues table, then falls back to a symptom-driven decision tree. Not invoked directly by customers.
-
bonaniibm Skill Password ResetUse to reset an employee's corporate account password following the IT security SOP. Use when a user reports they are locked out, forgot their password, or needs a password reset. Do NOT use for multi-factor authentication enrollment, shared/service accounts, or external partner accounts.
-
contentstack Skill Code Review 2Use when preparing or reviewing a pull request for kickstart-next-ssr.
-
gaixianggeng Bundle Skill Audit审查已安装或指定的 Codex Skill,识别触发重叠、上下文浪费、过度流程和权限边界问题,并给出有证据的精简建议。用于 Skill 体检或清理评估。
-
hrygo Bundle Hotplex Diagnostics深入诊断 HotPlex Gateway、Worker、Session、日志或反馈链异常。普通 status/doctor/security/config 只读检查属于 hotplex-cli;安装、更新、重启、配置写入和 Admin 变更属于 hotplex-operator。
-
zaxbyhub Skill Tech Debt CI Review 4Deep technical debt and CI stability audit for identifying test theater, missing or mis-scoped tests, actual and potential test failures, flaky-test risk, dependency/toolchain brittleness, and structural debt that prevents PRs from going green safely.
-
ferueda Skill Code Quality Review 2Review recently modified code for clarity, consistency, and maintainability while preserving exact functionality. Audit adherence to project conventions and industry best practices. Trigger when the user wants a code quality review, readability audit, maintainability review, or behavior-preserving refinement suggestions on a diff or implementation.
-
ipea Skill Review R 2Read-only R code review protocol for `.R` scripts. Checks code quality, reproducibility, domain correctness, tidyverse idioms, and professional standards; produces a report without editing. Use when user says "review this R script", "check the R code", "audit the analysis code", "code review on the R", or when an R file is touched as part of a release. NOT for running the code — pair with `/r-package-check` for the CRAN gate.
-
ipea Skill Deep Audit 2Deep consistency audit of the entire repository infrastructure. Launches 4 parallel specialist agents to find factual errors, code bugs, count mismatches, and cross-document inconsistencies. Then fixes all issues and loops until clean. Use when: after making broad changes, before releases, or when user says "audit", "find inconsistencies", "check everything".
-
vxcozy Skill Audit 2Productivity analyst that maps your workflow, scores tasks, and builds a prioritized automation plan. Use when: (1) "audit my workflow", "what should I automate?", "productivity review", (2) Starting a new project and need to identify high-leverage tasks, (3) Feeling overwhelmed and need to prioritize, (4) After /compounder surfaces new friction or patterns. Reads compounder insights when available. Outputs to system/audit-report.md.
-
vxcozy Skill Architect 2Solution architect that creates implementation blueprints before building. Use when: (1) "architect this", "design a solution", "blueprint for", (2) Taking a task from the audit report and need an implementation plan, (3) "how should I build this?", "plan before building", (4) Before any non-trivial implementation. Reads from system/audit-report.md. Outputs to system/blueprints/.
-
vxcozy Skill Compounder 2Weekly review partner that compounds productivity gains over time. Use when: (1) "weekly review", "what did I accomplish this week?", "compound my gains", (2) End of work week to review progress, (3) "what patterns are emerging?", (4) "update the system map", (5) Feeling stuck and need to identify friction. Reads all system/ files to synthesize progress. Outputs to system/compounder/week-{date}.md. Feeds insights back to /audit.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include code-review, security-review, workerd-api-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.