Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
jinshenganyuci Bundle Kernelsu Module DevelopmentBuild, migrate, audit, package, and troubleshoot complete KernelSU Manager modules. Use when creating a KernelSU module ZIP, module.prop, lifecycle scripts, systemless system overlays, metamodules, WebUI/actions/configuration, native Android payloads, or KernelSU-compatible Zygisk modules; also use for validating module compatibility, installation, update, SELinux, mount, and boot behavior.
-
lennarthennigs Skill Readme 2Audit README.md against the current ESPRotary API and recent CHANGELOG entries, then apply any needed updates
-
lovstudio Bundle Lov Article Creator 2统一创建、改写、品牌化或忠实转载微信公众号文章包:正文写作调用唯一文风与作者性能力,离线完成结构、品牌、封面、4:3 首图、来源与质量验收。Use when asked to write, brand, audit, or faithfully repost a WeChat article package.
-
lovstudio Bundle Lov Quality Gate 2对完整公众号文章包执行结构、事实边界、文风、品牌、双比例图片、散列和可发布状态检查,输出机器可读报告。Use when the user asks to“验收文章包”“audit this WeChat article”或“检查封面和 manifest”。
-
jaypokale Skill Chisle AuditOne-shot efficiency audit of a file, diff, or whole repo across BOTH axes at once: over-engineered code (reinvented stdlib, needless abstractions, speculative config) AND bloated prose (verbose comments, padded docstrings, redundant doc sections). Neither a pure code-minimizer nor a pure prose compressor does both in one pass. That's the point. Ranked report, biggest saving first; changes nothing. Use when the user says "chisle audit", "/chisle-audit", "audit this for bloat", "what can I cut", "review this PR for over-engineering and verbosity".
-
martinplarsen Bundle Architecture AuditRepo Architecture Audit
-
practical-ai-leadership Bundle Company Brain CheckThis skill should be used when the user asks to "check my company brain", "grade my company brain", "run the company brain completeness check", "how complete is our knowledge base", "assess our knowledge base structure", "audit our knowledge repository structure", "set up a company brain", or "recommend a starter structure for our knowledge base". Grades the structural completeness of a company or personal knowledge repository — the place where projects, concepts, and conventions live — across six dimensions plus additional checks (mode 1), or recommends a generalizable starter structure when no structured knowledge base exists yet (mode 2). Runs at a repository or workspace root in Claude Code or Claude Cowork. Not for reviewing source-code quality, not for writing or editing documentation content, and not for auditing a single document's prose.
-
andydixon Skill AitmAnalyse the current repository recursively and create or update an evidence-based AITM.md architecture document for automated threat modelling. Use when asked to document system components, data flows, authentication, access controls, sensitive data, entry points, external integrations, or trust boundaries.
-
andydixon Bundle DebullshitTranslate corporate, confusing, overly formal, vague, jargon-heavy, passive-aggressive, or unnecessarily long emails into clear ADHD-friendly plain English. Use when the user invokes `$debullshit` with pasted email content or asks to simplify, decode, rewrite, summarise, or explain an email while preserving names, dates, figures, links, responsibilities, deadlines, nuance, and security-sensitive warnings.
-
brian861105 Bundle Large Change Test AuditIndependently audit unit-test changes in implementations exceeding the user or repository changed-line threshold, defaulting to 1,000 additions plus deletions. Audit a coherent slice before delivery or merge preparation.
-
ccancellieri Skill Memory Layer AnalysisUse when reviewing auto-memory or project memory files to decide what to keep, archive, or consolidate. Categorization methodology behind master-state-compaction. Apply when the user asks to "audit memory", "find stale memory entries", "what should I archive", or before any large memory rewrite. Forces explicit per-entry classification (ACTIVE / SUPERSEDED / ARCHIVE / CONSOLIDATE) with stated reason rather than vibes-based pruning.
-
novelsavage Bundle UnipaOperate and audit UNIPA/Universal Passport RX university portals through the user's Chrome browser. Use when Codex needs to open UNIPA, reuse a logged-in session, inspect portal structure, scan notices or schedules, find classes, assignments, grades or materials, download files, or help with uploads and submissions. Designed for browser-only Japanese university portals with fragile JSF navigation, repeated labels, modals, multi-frame pages, session expiry, and confirmation-heavy workflows.
-
rodri-oliveira-dev Skill Test Anti Patterns 3Use esta skill para auditar qualidade de testes .NET neste repositorio, encontrando anti-padroes como asserts fracos, ausencia de asserts, flakiness, over-mocking, acoplamento a implementacao, dependencia de ordem, sleeps, dados magicos e cobertura artificial. Nao use para escrever testes novos do zero ou migrar framework.
-
yaacovcorcos Bundle Software Development DocumentationCreate source-backed software documentation for codebases, architecture, setup, testing, debugging, deployment, APIs, security, and operations. Use when documenting, auditing, updating, or organizing engineering docs for a software project or repository.
-
linuxfoundation Skill Copilot Code Reviewer 2Senior code-review method for lfx-v2-member-service pull requests: reviewer scope and knowledge sources, how to place a change in this Salesforce-backed Go service and in the LFX V2 platform around it, and the signal discipline that keeps review quiet unless it has something real. Use when the task is to review a PR on this repo for correctness, design, or security, including on a re-review after a new push. Posts inline severity-tagged comments plus a summary on the PR itself.
-
keep-starknet-strange Bundle Cairo Auditor 2Security audit of Cairo/Starknet code. Trigger on "audit", "check this contract", "review for security". Modes - default (full repo), deep (+ adversarial reasoning), or specific filenames.
-
get-convex Skill Convex Reviewer 2Review Convex code for security, auth, validators, performance, and best practices. TRIGGER when the user asks to review/audit Convex code, or after writing convex/ functions you want checked. Applies the Convex-specific review checklist (auth checks, args/returns validators, internal vs public, indexes-not-filter, OCC conflicts, pagination).
-
bex-co Skill Release 2Bump, validate, publish, and announce a public @bex-co/bex-security release using upstreamVersion-bex.N. Use only when explicitly asked to cut or publish a Bex Security release.
-
jgamaraalv Bundle Owasp Security Review 2Review code and architectures against the OWASP Top 10:2025 — the ten most critical web application security risks. Use when: (1) reviewing code for security vulnerabilities, (2) auditing a feature or codebase against OWASP categories, (3) providing remediation guidance for identified vulnerabilities, (4) writing new code and needing secure coding patterns. Triggers: 'review for security', 'OWASP audit', 'check for vulnerabilities','security checklist', 'is this code secure', 'security review', 'fix vulnerability'.
-
cristoslc Bundle Swain Init 3Project onboarding and session entry point for swain. On first run, performs full onboarding: migrates CLAUDE.md to AGENTS.md, verifies vendored tk, configures pre-commit security hooks, and offers swain governance rules — then writes a .swain/init.json marker. On subsequent runs, detects the marker and runs the per-session fast path (greeting, focus lane, session state). Use as a single entry point — it routes automatically. Triggers also on: 'session', 'session info', 'focus on', 'tab name'.
-
gomigo-labs Skill Scrut Answer QuestionnaireDraft answers to a security or vendor questionnaire from the organization's compliance posture using Scrut's knowledge base, with the sources per answer and an explicit gap flag when Scrut isn't confident. Use when the user pastes or points at a set of security questions (vendor security review, CAIQ, DDQ, RFP security section). Triggers include "answer this questionnaire", "fill this vendor security review", "respond to these security questions", and "draft an answer to this from our compliance posture".
-
ihkreddy Bundle Code Review 2Performs comprehensive code reviews following industry best practices. Use when reviewing pull requests, code changes, or when asked to analyze code quality, security, performance, or maintainability. Checks for common bugs, security vulnerabilities, code smells, and adherence to coding standards.
-
iyoda Bundle Developer ExperienceAudit and improve developer-facing documentation, language tooling, editor support, formatting, linting, test granularity, test doubles, and contributor commands while preserving runtime behavior. Use when a repository needs clearer onboarding, reliable language-server or type-checker feedback, less noisy or faster lint checks, a balanced unit-to-external test strategy, consistent local and CI workflows, or a measured developer-experience cleanup.
-
kklimuk Skill Codebase Review 2Full codebase audit — architecture, structural health, technical debt. Use when the user asks for a 'codebase review', 'architecture review', 'codebase audit', 'full review', 'engineering critique', 'refactoring plan', or 'what would a senior engineer think of this codebase'. Do NOT use for reviewing a PR or branch diff — that's /code-review.
-
kklimuk Skill Security Review 2Review code for security vulnerabilities. Use when the user says 'security review', 'security audit', 'check for vulnerabilities', 'pentest the code', 'OWASP check', or any variation of wanting a security assessment.
-
lovstudio Bundle Lov Bp Polish 3Review and improve an existing BP outline, PPTX, PDF, or rendered slide set across investment logic, evidence, copy, charts, and visual quality. Produces a scored report, page-level revisions, and targeted regeneration instructions while keeping facts separate from assumptions. Trigger on "润色 BP", "审稿商业计划书", "PPT 不专业", "逐页检查", "改图表", "BP review", "polish pitch deck", or "audit investor deck".
-
maccydee Bundle SkepticAdversarial reviewer that challenges whether something should be built at all, before challenging how. Use when asked to be a skeptic, "be skeptical", "pressure-test this", "poke holes in this", "play devil's advocate", or "should we even build this?". Applies a blunt YAGNI / over-engineering / scope critique to any artifact, a plan, a design, requirements, a feature request, or code. Complements correctness and security review, which ask whether something is built right; the skeptic asks whether it should exist.
-
rogerchappel Bundle Skill Drift Audit SkillSkill Drift Audit Skill
-
applicate2628 Bundle Vak Dissertation Review 2VAK dissertation review: audit dissertation and autoreferat.
-
aradotso Skill Awesome Claude Code Subagents 2Collection of 130+ specialized Claude Code subagents for development tasks across languages, frameworks, infrastructure, and security
-
aaronjmars Skill Shiplog 3Recap of everything shipped since the last run - cross-repo PRs, security fixes, star deltas, and X traction, synthesized into a digest article and a ready-to-post shiplog in your voice.
-
serkan-ozal Skill Performance Audit 2Analyze web page performance using Web Vitals and network timing metrics. Use when optimizing load times, checking Core Web Vitals, or investigating slow pages.
-
estoesmoises Bundle Incident To KnowledgeTurn a resolved internal incident into a sourced Stack Internal article or Q&A. Use for outages, degraded service, failed deployments, security events, and operational incidents after the facts are sufficiently verified. Search related incidents first and require approval of the exact article or Q&A before publishing.
-
oimiragieo Bundle Review Pr Diff 2Compresses a git diff before review so noise (lockfile bumps, generated files, whitespace churn) doesn't crowd out the actual logic changes. Use this skill whenever the user asks you to review a pull request, explain a diff, summarize changes, or comment on recent commits. Trigger phrases include "review this PR", "what changed", "explain this diff", "summarize the changes", "look at my diff", "check this branch against main". Uses gotcontext's code-aware compression at fidelity=detailed — detailed because a character dropped in a security fix matters more than a character dropped in prose.
0 -
arcjet Skill Add Request ProtectionDeprecated: use the `arcjet` skill instead. Adds security protection to a server-side route or endpoint — rate limiting, bot detection, email validation, and abuse prevention.
-
shakacode Skill Assess Abtest Quality 2Audit existing .abtest.ts files plus the latest `shaka-perf audit` results for anti-patterns, false-positive PASSes (blank/high-whitespace screenshots), and coverage gaps. Use whenever the user wants to review, audit, improve, or "assess quality" of AB tests — phrasings like "are my visreg tests any good?", "check the ab tests", "why is this test passing?", or "make these tests more reliable".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include kernelsu-module-development, readme, lov-article-creator. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.