Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
vxcozy Skill Architect System 2Master orchestrator for the 5-step productivity system. Runs the full audit-architect-analyst-refinery-compounder loop or individual steps. Use when: (1) "run the full loop", "start the system", "architect system", (2) "run step N", "run audit", "run architect", (3) "what step am I on?", "system status", "where am I in the loop?", (4) "continue", "resume", "next step". Manages state, sequencing, and skill chaining across all 5 steps.
-
xclouddev Bundle ServersManage xCloud servers — list/inspect servers, monitoring, services, tasks, reboot, snapshots, sudo users, PHP versions, databases & database users, server cron jobs, firewall rules, fail2ban, and provisioning new sites onto a server (WordPress or Git-deployed PHP/Node apps). Use for any server-level infrastructure or server security (firewall/fail2ban) request. NOT site-level config (see xcloud:sites), NOT SSL certs (see xcloud:ssl), NOT WordPress app management (see xcloud:wordpress).
-
mnemon-dev Bundle Mnemon 10Use persistent memory when prior preferences, decisions, constraints, or project history could affect a task, or when durable non-secret knowledge should be preserved.
-
gkrtjd99 Skill Local PrivacyAudit a local project for privacy leaks, secrets, personal paths, tokens, API keys, and data that should not be committed. Use when checking whether a repository exposes sensitive information, credentials, private paths, or commit-unsafe data.
-
haksolot Skill Ank DriftAudit the decisions in .ank/ against the current code and report what no longer holds. Use when asked whether ADRs, specs, or tasks are still accurate, after a milestone, or when the corpus and the code seem to disagree.
-
noteflowai Skill Publish Audit CacheAttach an existing internal audit cache to a public report.
-
noteflowai Skill Internal Audit CacheStage report inputs in an internal audit cache for later review.
-
noteflowai Skill Submit Order CacheSubmit an existing report cache to the synthetic audit service.
-
poteto Bundle Meditate 2Audit and evolve the brain vault — prune outdated content, discover cross-cutting principles, review skills for structural encoding opportunities. Triggers: "meditate", "audit the brain".
-
dragoon0x Skill Microcopy 2The small words that shape big experiences. Button labels, tooltips, confirmations, placeholders, and the 3-word strings that determine whether a product feels polished or half-finished. Use during any copy audit pass.
-
jeremylongworth-source Bundle Risk RegisterCreate and maintain executive risk registers and opportunity registers. Use when Codex is asked to identify strategic, operating, financial, customer, product, people, legal, security, delivery, or reputation risks; prioritize risks; define mitigations; or prepare leadership risk review artifacts.
-
zhaoxuya520 Bundle Supply Chain Security 2供应链安全时使用。适用于依赖漏洞扫描 / 镜像安全 / CI 投毒防护 / SBOM。融合 SLSA + Sigstore + Snyk + Trivy。
12.8k -
tuyv Bundle Avoid AI Writing 2Audit and rewrite content to remove AI writing patterns ("AI-isms"). Use this skill when asked to "remove AI-isms," "clean up AI writing," "edit writing for AI patterns," "audit writing for AI tells," or "make this sound less like AI." Supports a detect-only mode, an edit-in-place mode for files, an optional voice profile (casual / professional / technical / warm / blunt), and an iterate-to-convergence pass.
-
etolucy Bundle Manage Github RepositoryAudit, rename, and polish a GitHub repository across its local checkout and remote settings. Use when Codex needs to synchronize a local and GitHub repository name, set the description, homepage URL, or topics, create repository branding and a GitHub social preview, restructure a README, or prepare and publish a cohesive repository identity. Uses GitHub CLI for supported remote operations and delegates visual identity work to $create-context-aware-logos.
-
ivanwng97 Skill Two Lens ReviewRun pixtuoid's review protocol at either scope — the mandatory pre-merge DIFF gate (2+ differentiated-lens agents on the diff) or a whole-codebase AUDIT (subsystem × factor fan-out over the whole tree). Both draw ONE shared factor taxonomy + verify contract + disposition; they differ only in population and orchestration. Use before merging ANY PR, on 'review this PR/branch' / 'is this ready to merge' (diff scope), or on 'whole-codebase review' / pre-release / periodic audit (whole-codebase scope). Encodes the convergence contract (churn budget, two-fix-round cap, HIGH-only blocking), the five hard requirements, the escalation triggers, the adversarial finder→verify fan-out, and the disposition sweep the repo learned the hard way.
-
jwhiteux Bundle Council Of FiveMulti-persona deliberation framework for high-stakes decisions. Five specialized personas independently analyze a dilemma, blind-review each other's reasoning, and a Chairman synthesizes a single verdict. Use this skill whenever the user says 'council this', 'run the council on...', 'pressure-test this', 'war room this', 'stress-test this decision', 'red-team this', or asks for adversarial review of a choice. Also trigger when the user is weighing a high-cost, hard-to-reverse decision — architecture and tech selection, security tradeoffs, business pivots, pricing, hiring, major commitments — and would benefit from deliberately breaking their own assumptions before committing. When in doubt on a consequential or expensive decision, convene the council.
-
quantclaw Skill HealthcheckSystem health audit and diagnostics
-
wayne2wang Bundle Zilin Paper CheckerAudit near-final computer vision and robotics conference papers for mathematical and notation correctness, high-confidence writing and formatting errors, reviewer-facing risks, current venue compliance, and exhaustive bibliography integrity. Use for submission PDFs or LaTeX projects before submission, revision, or rebuttal; do not use to draft a paper from scratch or migrate it to another template.
-
jmagly Bundle Security Engineering Quickref 2AUTO-INVOKE when user mentions cryptography, AEAD, KDF, chain of trust, signing key, auth factor, MFA, secret hygiene, supply chain trust, physical threat. Security-engineering quick reference — decision domains for crypto primitives, chain-of-trust, auth factors, degraded modes, supply-chain trust, physical-threat modeling.
-
managedcode Bundle Test Anti Patterns 3Quick pragmatic detection-focused review of .NET test code for anti-patterns that undermine reliability and diagnostic value. Use when asked to audit test quality, investigate flaky or coupled tests, find duplication or magic values, or when tests pass but don't actually verify anything. Best for identifying and prioritizing issues in existing tests with severity-ranked findings and targeted remediation guidance. Catches assertion gaps, swallowed exceptions, always-true assertions, flakiness indicators, test coupling, over-mocking, naming issues, magic values, duplicate tests, and structural problems. Do NOT use for direct MSTest API rewrites or implementation-only fixes (for example swapped Assert.AreEqual argument order or converting `DynamicData` from `IEnumerable<object[]>` to `ValueTuple`) — use writing-mstest-tests instead. For a deep formal audit based on academic test smell taxonomy, use exp-test-smell-detection instead. Works with MSTest, xUnit, NUnit, and TUnit.
-
florian101010 Skill QA Audit 3Use when performing a quality audit, security review, or robustness check. Covers XSS/innerHTML scanning, rule compliance verification, race condition analysis, config schema validation, and documentation drift detection. Produces a severity-classified report (Critical/High/Medium/Low).
-
bahayonghang Bundle Claude Context Improver 2Audit and improve the Claude Code context layer — CLAUDE.md guidance files, .claude/rules/ path-scoped rules, and companion code_map.md navigation maps — against Claude 5 context-engineering rules (judgement over rules, progressive disclosure, no cross-layer conflicts). Asks whether to optimize the current repository (default) or the global ~/.claude context. Use when the user asks to check, audit, optimize, rightsize, slim, or restructure CLAUDE.md or Claude context files, mentions nested CLAUDE.md, code_map.md, or context engineering, or says 优化 CLAUDE.md, 审计 CLAUDE.md, 优化上下文, 精简上下文, 生成 code_map (Claude). Not for trivial single-line edits the user has already fully specified.
-
mehdi-benhariz Skill Ponytail AuditWhole-repo audit for over-engineering. Like ponytail-review, but scans the entire codebase instead of a diff: a ranked list of what to delete, simplify, or replace with stdlib/native equivalents. Use when the user says "audit this codebase", "audit for over-engineering", "what can I delete from this repo", "find bloat", "ponytail-audit", or "/ponytail-audit". One-shot report, does not apply fixes.
-
cyberuni Skill Fix Security Pr 3Fix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks. Use when asked to 'fix the security PR', 'resolve the vulnerability failure', or 'unblock the Dependabot PR'.
-
equinor Bundle Fusion Dependency Review 3Review dependency PRs with structured research, existing-PR-discussion capture, multi-lens analysis (security, code quality, impact), and a repeatable verdict template. USE FOR: dependency update PRs, Renovate/Dependabot PRs, library upgrade reviews, "review this dependency PR", "should we merge this update". DO NOT USE FOR: feature PRs, application code reviews, dependency automation/bot configuration, or unattended merge without confirmation.
-
rcarmo Skill Go Project Conventions 2Project conventions with module caching, linting, security checks, and tests via Make
-
greenpau Bundle Skill Authoring 2Create, revise, route, validate, or audit tested repo-local skills as a progressive-disclosure engineering handbook. Use when changing AGENTS.md or .codex/skills, adding durable tested contracts, reorganizing routes, synchronizing skill UI metadata, removing placeholders, or checking reachability and routing integrity.
-
greenpau Bundle Coding Directives 2Apply tested repository Go coding standards to implementation and review work. Use when creating or modifying Go packages, APIs, process execution, protocol parsing, result models, coverage logic, renderers, artifact storage, errors, security-sensitive paths, or tests in tested.
-
greenpau Bundle Source Code Management 2Create, review, or revise tested repository commit messages and commit-message files. Use when summarizing a tested change for version control, selecting a subsystem indicator, validating the required subject and Before/After/Tests/More info structure, or creating a message file for a user-reviewed commit.
-
greenpau Bundle Implementation Architecture 2Design, implement, review, or audit tested across its CLI, child-process runner, event protocol, result aggregation, coverage, reporting, and artifact-publication boundaries. Use when a change crosses packages, alters run or report lifecycle semantics, introduces a new output, or needs routing to the specialized tested implementation skills.
-
carlsz Skill Audit CujVerify a stored critical user journey by replaying it step by step against the running app, and report the exact step that broke as a cuj report in .ux/audits. Use for "verify my CUJs", "do the journeys still work", "journey regression check", "which step broke".
-
carlsz Bundle Usability AuditRun an expert heuristic usability evaluation of a host app and write a severity-scored report to .ux/audits. Use for "usability audit", "heuristic evaluation", "UX audit", or "usability review".
-
dream-zjk Skill Code ReviewUse when reviewing a pull request, a diff, or uncommitted changes for bugs, security issues, and style regressions.
-
frankhildebrandt Skill Dependabot Security PlanFetches open Dependabot security alerts for any GitHub repository (user-specified or from workspace remote), filters Critical and High (optionally Moderate) alerts with an available patch version, and builds a Plan-mode plan with one todo per actionable fix. Use when the user asks for a Dependabot security fix plan, vulnerability remediation plan, or points at /security/dependabot (e.g. github.com/{owner}/{repo}/security/dependabot).
-
itallstartedwithaidea Skill Google Ads Audit 2Structured Google Ads account audit across 7 dimensions. Activate when the user asks to "audit my account", "check for problems", "find issues", "review my campaigns", or requests a comprehensive account health assessment. Delivers findings with severity ratings and prioritized action items.
-
jinshenganyuci Bundle Build Xiongda Ksu ModuleBuild, migrate, audit, test, and package the `A.xiongda-onekey-start` KernelSU module and derived Android kernel-plus-driver variants. Use when Codex must create or update 熊大一键启动 or a minimal Action-plus-manual-driver module, preserve a chosen base release, implement manual or game auto-start, embed a byte-exact driver, stream root-operation logs through KernelSU WebUI, prevent post-install 0644 permission failures, diagnose a module that did not execute, or deliver a reproducible validated release.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include architect-system, servers, mnemon. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.