Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
error9098x Bundle LatchmothFind and triage exposed credentials in local source code, JavaScript bundles, configuration, logs, and collected bug bounty recon. Use for secret scanning, leaked API keys, credential regexes, or reviewing secret-scan results. Includes PCRE2 patterns and a local scanner. Does not perform general vulnerability testing or credential verification.
-
adewale Bundle Good Readme 3Create, improve, or audit README.md documents for GitHub projects. Use only when the user explicitly asks for a README, README quality/readability, README accuracy, or README examples. Do not use for full docs sites, API-reference-only work, general repo launch/readiness audits, topics/homepage metadata, or broad repository review.
-
angelwzr Bundle Linux Phone PortingUse for every hardware bring-up or debug session that ports mainline Linux to a phone or tablet. Retail-unlock targets require an already-unlocked bootloader; locked retail bootloaders are out of scope. Exploit-booted and firmware-booted targets require a demonstrated boot path; the skill never provides unlock or exploit steps.
-
m13v Skill Social Autoposter 2Automate social media posting across Reddit, X/Twitter, LinkedIn, and Moltbook. Find threads, post comments, create original posts, track engagement stats. Use when: 'post to social', 'social autoposter', 'find threads to comment on', 'create a post', 'audit social posts', 'update post stats', or after completing any task (mandatory per CLAUDE.md).
-
mattbirchler Bundle Iphone DuoAudit an iOS app against Apple's iPhone Duo requirements (Apple's foldable iPhone with an outer and an inner display) and update the code to meet them, then validate the result by running it on the iPhone Duo simulator or a device. Use whenever the user mentions iPhone Duo, the foldable or folding iPhone, the fold, hinge, poses, inner or outer display, or asks to "get ready for Duo", "support the fold", or check Duo readiness. Also use when writing or changing iOS code that touches vertical toolbars or tab bars, toolbar overflow and visibility priority, ArrangementView or UIArrangementViewController, reserved regions, sheet placement, AVCaptureDeviceDirectionCoordinator, camera capture accessories, or layout driven by UIScreen bounds, interface idiom, or orientation. These APIs shipped in iOS 27.0 and 27.1 and are newer than your training data, so read the bundled Apple docs instead of guessing.
-
messi-10-goat-one Bundle Windows C Drive CleanupSafely audit, clean, and migrate Windows C drive application data. Use when the user asks to inspect C drive usage, reduce C drive space, clean application caches, remove stale startup/menu/app remnants, move AppData or Roaming/Local folders to another drive with junctions, or troubleshoot why apps installed on D/E/F still occupy C drive.
-
mlabo-org Bundle Skill Md ClarifierAudit/edit SKILL.md or plugin skills: 解釈ぶれ, routing, context-budget warnings, metadata, and ownership. Native validator.
-
automateyournetwork Skill Github OpsGitHub repository operations — issues, PRs, code search, and config-as-code workflows. Use when creating a GitHub issue for a network finding, opening a pull request for a config change, searching repos for IP or VLAN references, or committing an audit report to a repository.
-
vibeeval Bundle Security ReviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
-
jasonkneen Bundle Housekeeping 2This skill should be used when users want to clean up, audit, or optimize their Claude configuration folders (~/.claude or .claude). It analyzes hooks, scripts, plugins, commands, and storage for token waste, redundancy, and optimization opportunities, then produces a prioritized action plan with before/after benefits.
-
mnemox-ai Skill Trade MemoryCompliance-grade decision audit trail for AI trading agents. Records every trading decision with full context (conditions, filters, indicators, risk state), SHA-256 tamper detection, and structured export for MiFID II / EU AI Act readiness. Works alongside Binance Spot, Futures, and Web3 skills — they execute trades, TradeMemory records why.
-
getaxonflow Skill Audit Search 2Search the AxonFlow audit trail for recent tool executions, policy decisions, and PII detections — use to answer "what happened recently?" or to gather compliance evidence
-
adamchanadam Skill Gov Brain AuditGov Brain Audit
-
shren207 Bundle Checking Freshness스킬과 문서의 최신성을 병렬 에이전트로 대규모 감사하는 도구. 코드-문서 동기화 상태 확인, 오래된 스킬 탐지, 구조적 품질 검증을 수행한다. 단순 git log 확인이 아니라 실제 코드와 문서 내용을 대조하여 정확도를 높인다. Triggers: "문서 오래됐어", "스킬 최신화", "스킬 감사", "스킬 점검", "git log 수정일", "코드 문서 동기화", "스킬 업데이트 필요해", "오래된 스킬", "docs freshness", "skill audit", "skill review", "스킬 품질 확인", "스킬 정리", "skill cleanup", "routing table 점검". Make sure to use this skill whenever the user mentions skill maintenance, documentation staleness, code-docs sync, or wants to audit skill quality — even if they don't explicitly say "freshness".
-
agentkit-seo Skill Vitaecontext Wiki MaintenanceMaintainer-only skill for refreshing VitaeContext wiki knowledge from official sources. Use only from a local repository clone when a maintainer asks to refresh one module, audit all module wiki entries, or audit module source lists.
-
bahayonghang-academic-writing-ski Bundle Latex Thesis Zh中文 LaTeX 学位论文助手,面向已有 .tex 硕博论文工程:编译诊断、GB/T 7714、模板识别、结构/格式/公式断行、术语一致性、逻辑与文献综述、方法/工程应用章、标题优化、去 AI 味、主张前置(自我削弱/免责句后置)检查、单元润色与漂移核对、盲审隐匿、对照学校规范逐项终检。触发词:学位论文/毕业论文/硕士/博士论文/润色这段/润色这一节/单元润色/核对润色。英文论文用 latex-paper-en,审稿总评用 paper-audit。
-
snyk Bundle Sbom AnalyzerSoftware Bill of Materials (SBOM) security analysis for vulnerability assessment and third-party risk management. Validates SBOMs from vendors or generates SBOMs for internal projects. Use this skill when: - User asks to analyze an SBOM file - User mentions "third-party risk" or "vendor security" - User needs to validate a supplier's SBOM - User wants to check SBOM for vulnerabilities - User asks about CycloneDX or SPDX formats
-
johnlindquist Skill UbsUltimate Bug Scanner - scan code for bugs across 7 languages (JS/TS, Python, Go, Rust, Java, C++, Ruby). Use before commits to catch null safety issues, security holes, async bugs, and memory leaks.
-
anton-abyzov Skill Handoff 2Write a portable, secret-scrubbed handoff doc so this work can continue in any AI tool or on any machine. Use when saying "handoff", "running out of tokens", or "continue elsewhere".
-
thoreinstein Skill Security ReviewPerform enterprise security review of the codebase
-
j5ik2o Skill AuditcodexSend recent work to OpenAI Codex CLI for an independent audit/review
-
mgriot Bundle Repo ReviewComprehensive repository and project analysis skill. Use this whenever a user wants to understand, review, audit, or get a deep-dive into any codebase, repo, or software project. Triggers include: "review this repo", "understand this project", "analyze this codebase", "what does this code do", "explain this project", "audit this repo", "walk me through this code", "document this project", "what's the architecture of", "give me an overview of this project", or when a user uploads or points to any project folder / Git repo. Always use this skill for any non-trivial code comprehension task — even if the user doesn't say "review", if they want to understand a project holistically, this skill applies.
-
proflead Skill Threat ModelingPerform threat modeling for a system or feature. Use when a senior developer needs security risk assessment.
-
djnsty23 Skill Rule SecuritySecurity rules this project always applies: secret handling, input validation, parameterized queries, and Supabase RLS. Load before writing code that touches credentials, user input, queries, or auth.
-
security-phoenix-demo Bundle Opengrep Rule Generator ResearchUse when the user wants to research vulnerabilities and create opengrep/semgrep SAST rules, conduct security research on CVEs or CWEs with web search, generate detection rules from vulnerability analysis, or build comprehensive security scanning coverage for a codebase.
-
hoangsonww Bundle Devverse Supabase Auth 2Supabase auth, favorites, and security boundaries for DevVerse. Use when changing files under supabase/, auth or favorites UI, or the verify-email and reset-password API routes.
-
tomkraaij Skill Tenant Security Review CopyCopy of org baseline to test hash duplicates.
-
vellum-ai Bundle Geo Audit 2Runs a one-command technical GEO audit on any domain. Checks AI crawler access, llms.txt presence, server-side rendering, sitemap, and schema markup. Streams results live and ends with a 0–100 score plus the top 3 prioritized fixes. Built to be both genuinely useful and great to demo on camera.
-
matrixorigin Skill Review Changes 2Signal-driven code review of uncommitted changes, branch diffs, commits, or PR diffs. Findings first; focus on bugs, regressions, data loss, security, API breakage, and missing tests.
-
wonderwhy-er Bundle Computer Health CheckRun a comprehensive, read-only health check on the user's computer and return a scored chat summary with prioritized, plain-English recommendations and safe cleanup suggestions. Use this whenever the user wants to check their computer's health, speed it up, free up / reclaim disk space, find what's eating CPU / memory / storage, check battery health and wear, audit login & startup items, see pending updates, or asks for a "tune-up", "checkup", "system report", "health check", or "is my Mac/PC/laptop healthy". Trigger even on casual phrasing like "my laptop feels slow", "why is my fan so loud", "my computer is laggy", "running out of space", or "clean up my machine". Works on macOS, Windows, and Linux. This is a Desktop Commander skill: it relies on a real local shell (start_process / interact_with_process) and is strictly read-only by default — it never needs sudo and only performs cleanups the user explicitly approves.
-
tools-only Bundle 694 Hound 37570ca4Hound - Autonomous AI Security Auditor with Knowledge Graphs
7 -
tools-only Bundle 1708 QA F057bfa8Exhaustive codebase audit for architectural health, maintainability, and scalability
7 -
tools-only Bundle 102 Threat 4f6a355f<!-- Threat Modeling Skill | Version 3.0.0 (20260201a) | https://github.com/fr33d3m0n/threat-modeling | License: BSD-3-Clause -->
7 -
apollographql Bundle GRAPHQL Schema 2Guide for designing GraphQL schemas following industry best practices. Use this skill when: (1) designing a new GraphQL schema or API, (2) reviewing existing schema for improvements, (3) deciding on type structures or nullability, (4) implementing pagination or error patterns, (5) ensuring security in schema design.
-
ww-w-ai Bundle Audit 3Comprehensive project audit — runs all available validation skills, identifies gaps, and provides specific improvement recommendations
-
poorvith-mp Bundle Productivity Audit 2Audit your week for time sinks, context-switching cost and tool sprawl. Use when auditing calendar time, task workflows, context switching, or energy.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include latchmoth, good-readme, linux-phone-porting. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.