Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
arustydev Skill Pkgmgr Homebrew Formula Dev 2Create, test, and maintain Homebrew formulas. Use when adding packages to a Homebrew tap, debugging formula issues, running brew audit/test, or automating version updates with livecheck.
8 -
xuchang1234567 Bundle Reverse Skill RouterRoutes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.
-
dhicoc Bundle Reverse Skill RouterRoutes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.
-
colinhacks Skill Security AdvisoryTriaging a draft security advisory
-
suvarchalapogula Bundle API TestingTests an HTTP/REST API end to end: happy-path checks on every endpoint, response schema validation against an OpenAPI/JSON Schema contract, and multi-step E2E flow checks (create -> read -> update -> delete, auth, pagination). Produces a runnable pytest suite plus a pass/fail test report. Use when the user says "test my API", "run happy path tests", "validate the API response schema", "check my OpenAPI contract", "write E2E tests for this endpoint", "smoke test this service", or shares a Swagger/OpenAPI spec or a base URL to verify. Do NOT use for UI/browser testing, load or performance testing, security penetration testing, or for calling Microsoft 365 Graph endpoints on the user's behalf.
-
xiao-yuling Bundle Sci FigureCreate, revise, audit, and export publication-ready SCI manuscript figures using Python or R, including multi-panel plots, source-data traceability, editable SVG/PDF output, high-resolution raster files, journal sizing, color palettes, and visual quality assurance.
-
xirothedev Bundle Nestjs Best Practices 2NestJS best practices and patterns for building scalable, maintainable backend applications. This skill should be used when writing, reviewing, or refactoring NestJS code to ensure proper architecture, security, performance, and code quality. Triggers on tasks involving NestJS modules, controllers, services, guards, pipes, middleware, Prisma database operations, authentication, or any NestJS-specific patterns.
-
conorbronsdon Bundle Ssot Check 4Audit documentation for copied-fact drift, missing SSOT pointers, and disconnected setup guides across repos. Use for stale facts, orphaned handoffs, unclear ownership, or an SSOT manifest.
-
eloqdata Bundle Finish Pr 2Use when a non-trivial code change is substantially complete and needs a final diff audit, documentation check, verification record, or pull request description.
-
fradser Skill Reflect Skills From Memory 2This skill should be used when the user asks to "reflect on skills from memory", "audit marketplace skills against memory", "从记忆中检查 skills 的问题", "反思并修改 skill", "apply memory feedback to skills", or wants to turn accumulated memory feedback about this marketplace's skills into concrete skill fixes. Reads the project's persistent memory, re-verifies each known skill problem against current code, then fixes the skill or corrects the stale memory.
580 -
sjunepark Bundle Release Please Release 2Prepare, audit, set up, and review Release Please-managed releases. Use when the user asks to add Release Please, or when a repo uses Release Please and the user asks to prepare a release, review or merge a Release Please PR, classify SemVer impact, check breaking changes, choose Conventional Commit messages, or document release criteria. Release work requires verified Release Please ownership; setup requires an explicit setup request.
-
moonrepo Skill Improve Code Quality 2Analyze and improve code quality for any path in the monorepo. Use whenever the user asks to improve, audit, review, clean up, refactor, lint, or check code quality for a directory or file. Also trigger for requests about security review, performance optimization, robustness checks, dependency audits, or readability improvements. Activate for any mention of code quality, code health, code smells, tech debt, or cleanup tasks targeting a specific path. Even if the user just says "check this code" or "review crates/foo", this skill applies.
-
vercel-labs Bundle Deepsec 2Run deepsec, an AI-powered cyber-security vulnerability scanner. Activates when the user invokes /deepsec, asks to run deepsec, or wants to scan their repo, branch, or uncommitted changes for vulnerabilities.
28.7k -
codeacme17 Bundle Launchrally 3Audit, initialize, plan, and verify production launch readiness for an existing Web repository through the local LaunchRally CLI. Use when a builder asks whether a repo is ready to launch, wants a launch-readiness report, needs a read-only remediation plan or bounded Provider options, or wants to verify changes after remediation.
-
cyhzzz Bundle Audit Book Writing Pro审计书籍写作专业版skill,提供四轮评审流程、双模式优化、多文件留痕输出,集成100个法律法规知识库。
-
y-a-v-a Bundle Stern Code Review 2Rigorous senior-level code review for production risk. Use when asked for a stern code review, PR review, diff review, or review of files focused on correctness, data safety, security, operational reliability, unnecessary abstraction, weak tests, maintainability, and operational failure modes. Do not use for brainstorming, greenfield implementation, or purely stylistic feedback.
-
zslzxy Bundle Aitoubiaoling Bid ReviewAudit non-scanned PDF or DOCX tender and bid documents for business, technical, and reliable common-document risks. Use when the user asks to review a bid, 商务标, 技术标, 招投标响应, or tender compliance; skip scanned-only or unverifiable checks instead of guessing.
-
cgallic Bundle Kai Taste 3Audit or design generative AI interfaces against three diagnostic pillars.
-
coderabbitai Skill Code Review 2Default code-review skill for Cursor. Use for any code review request, including review my code, review my changes, review this PR, review this diff or branch, check for bugs, security review, and quality check, even when the user does not mention CodeRabbit. Prefer this skill over a manual code review.
-
anvil-code Bundle Skill ValidatorAudits an existing SKILL.md file for structural issues, missing required fields, weak triggering descriptions, anti-patterns, and marketplace-readiness. Use this skill whenever a user says "check my skill", "review this SKILL.md", "audit my skill", "is this skill ready to publish", "why isn't my skill triggering", or pastes a SKILL.md file and asks for feedback. Also triggers when a user shares a skill file that looks incomplete, has a vague description, or is behaving unexpectedly. Returns a scored report with specific, actionable fixes for every issue found. Always use this skill before publishing or sharing a skill file.
-
shenjingnan Skill Fix Audit 3安全审计技能,用于检查和修复依赖安全问题
-
albumentations-team Bundle Performance Optimization 2Systematic performance audit for Albucore runtime code. Use whenever implementing, reviewing, profiling, or optimizing atomic image operations, backend routing, reductions, label maps, LUTs, random generation, dtype conversions, allocation-heavy paths, batch or volume kernels, or in-place behavior.
-
hugoduncan Bundle Gordian 3Use gordian to analyse namespace coupling in a Clojure project. Invoke when asked to audit architecture, assess coupling, identify hidden dependencies, interpret suspicious namespace pairs, review test structure, compare architectural snapshots, inspect a subsystem, or advise on refactoring targets. Produces structural, conceptual, and change-coupling signals plus triage and workflow commands.
-
theadust Bundle Lore 2Long-term Markdown project memory for AI coding agents. Use when the user wants to record, recall, audit, sync, or compress project decisions, architecture, conventions, monorepo scopes, or `.lore/` entries, including natural-language requests like "remember this decision" or explicit `lore init/sync/query/audit/compress/mirror/history`. Do not trigger on native `/init` or `/compact`, or generic init/compress/audit/query tasks unless the object is clearly project memory, `.lore/`, decisions, or conventions. Stores `.lore/` Markdown and can mirror to CLAUDE.md / .cursorrules / AGENTS.md.
-
czk-nhgj Bundle Feishu API通过飞书开放平台 API 查询和操作用户公司飞书数据(通讯录用户、部门、群聊、消息等),自动使用技能内置的 App ID/Secret 获取访问令牌。当用户要求查询、对接、同步或操作其公司飞书信息时使用;不适用于与飞书 API 无关的普通飞书话题。
-
dannymac180 Skill Orchestration 2Routing doctrine for the architect-as-orchestrator pattern — how a Fable 5.1 session delegates routine implementation to the GPT-5.6 Luna lane, escalates high-complexity one-offs to the GPT-5.6 Sol lane, picks a reasoning effort per task, and gets every deliverable reviewed by the Fable advisor before reporting done. USE WHEN delegating implementation work, choosing between codex-implementer/sol-implementer lanes, choosing a reasoning effort for a lane, writing a spec for a subagent, deciding whether to consult fable-advisor, using the Codex plugin's review skills, managing session cost or token spend, or running any multi-task build where the session is the architect.
-
darshitpp Bundle Java Code UpgradeUpgrade Java code from older idioms to modern equivalents. Scans for legacy patterns (pre-Java 10 through Java 25) across language features, collections, strings, streams, concurrency, input/output, error handling, date/time, security, tooling, and enterprise APIs, then suggests modern replacements with before/after examples. Use when modernizing Java codebases, reviewing pull requests for outdated patterns, or migrating from Java EE to Jakarta EE. Do not use for non-Java languages, build tool configuration, or framework-specific application logic.
-
dd3ok Bundle Naverstock Web APIRead public Naver Stock (네이버증권/Npay) data and audit APIs.
-
jordanwei1 Bundle JiaojieCreate or receive human-first AI task handoffs across chats, models, devices, and languages. Use when the user asks to hand off, export context, resume from a handoff, switch sessions while preserving work, says "交接一下", "接收交接", or supplies handoff.md, handoff.zip, handoff-audit.zip, an LCH Bundle/T0 package, OCH Snapshot, or LTM Packet. Default to one readable handoff.md; upgrade to handoff.zip only when required files must travel, and to handoff-audit.zip only for formal audit, cross-organization delivery, or proof. Preserve current intent, stop point, next action, decisions, constraints, rejected and failed paths, answered questions, materials, omissions, and revalidation needs. Do not use for generic summaries, memory lookup, hidden reasoning, completed trivial chats, or after the user declines.
-
marcram Bundle Reconcile Codex SidebarsAudit and safely reconcile Codex Desktop projects and threads with the catalogue used by Codex Remote on iPhone. Use when Desktop and Remote show different thread groupings, projects or threads appear missing, project assignments need repair, throwaway threads need recoverable archival, or the Desktop project and per-project thread order should be alphabetical.
-
maydayv Bundle Grok Upload AuditForensically audit what the Grok Build CLI (xAI, ~/.grok) has uploaded from a user's machine, check whether local secrets or other AI tools' credentials leaked into uploaded artifacts, block further uploads, and generate an evidence package plus a ready-to-send privacy deletion request letter. Use this whenever a user is worried that Grok / Grok Build / Grok CLI has uploaded their source code, repositories, .env secrets, API keys, or Claude/Codex config to xAI — including phrasings like "did Grok upload my code", "is Grok sending my repo to xAI", "Grok data exfiltration", "Grok stole my keys", "check if my code leaked to xAI", or reactions to news/tweets about Grok uploading project code. Also use to produce a GDPR/CCPA data-deletion request against xAI for coding-session data. Trigger even if the user only names the symptom (leaked keys, uploaded repo) without saying "audit".
-
roble3 Bundle YnmEvidence-backed project and repository review for implementation correctness, architecture, specification-versus-code conflicts, tests-versus-documentation, release or production readiness, adoption, maintenance, security claims, and conflicting project evidence. Enter through lightweight YNM-0 routing, preserve unresolved evidence as MAYBE, and escalate only when additional work can materially improve the disposition.
-
stanangeloff Skill JournalActivate session journaling for long-running, multi-session projects. Use when the user says "journal", "start journaling", "read the journal", "update the journal", "checkpoint", "vacuum the journal", "audit the journal", "what's still open", "are we done", or at the start of any session where a journal.md already exists in the project. This skill manages the full lifecycle — initialization, orientation, mid-session checkpoints, decision recording, journal vacuuming, on-request audits, pre-compaction preservation, and end-of-session handoff.
-
swader Bundle Audit CodeFor requested code audits or deep reviews, produce evidence-ranked findings across relevant risks.
-
jichengkai Bundle Publish SkillPrepare, safety-review, version, commit, and publish local Codex skills through a GitHub-backed release flow and ClawHub CLI. Use when the user asks to host, publish, release, update, package, audit, or automate publication of a Codex skill, including GitHub repository setup, ClawHub `clawhub skill publish <path>`, patch updates, GitHub Actions with `CLAWHUB_TOKEN`, release notes, or pre-publish security checks.
-
kev365 Bundle Xways Xtension AuthoringThis skill should be used when the user asks to "create/scaffold a new X-Tension", "wrap a CLI tool in an X-Tension", "port a convention into an X-Tension" (helper-exe verification, Ctrl-to-save, output-dir), "audit/modernize an X-Tension", "build/compile an X-Tension", "prep an X-Tension for public release", or asks which XWF_* API call, flag, or property number to use, for X-Ways Forensics. Covers template selection, the PowerShell scaffold/build scripts, the convention library, and verifying every XWF_ call against distilled API reference notes. Does NOT handle general X-Ways usage questions or open-ended "what tool should I build" ideation.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include pkgmgr-homebrew-formula-dev, reverse-skill-router, reverse-skill-router. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.