Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aojdevstudio Skill Deep Dive 2USE WHEN: deep dive into X, break this down for me, audit my approach, give me a thorough breakdown, how should I manage X, create a policy for X, expert rundown on X. Delivers structured opinionated analysis with one clear path forward.
-
0xranx Skill Security Review 2Security Review Process
-
samhvw8 Skill Mise Expert 2Mise development environment manager (asdf + direnv + make replacement). Capabilities: tool version management (node, python, go, ruby, rust), environment variables, task runners, project-local configs, backend selection (aqua, github, core, cargo, npm, pipx), security verification (cosign, SLSA, GitHub attestations, minisign). Actions: install, manage, configure, run tools/tasks with mise, troubleshoot attestation failures, migrate backends. Keywords: mise, mise.toml, tool version, runtime version, node, python, go, ruby, rust, asdf, direnv, task runner, environment variables, version manager, .tool-versions, mise install, mise use, mise run, mise tasks, project config, global config, aqua backend, github backend, ubi deprecated, MISE_AQUA_COSIGN, MISE_AQUA_GITHUB_ATTESTATIONS, attestation verification failed, cosign, SLSA, uv astral-sh. Use when: installing runtime versions, managing tool versions, setting up dev environments, creating task runners, replacing asdf/direnv/make, configuring project-local tool
-
akillness Bundle Ralphmode 2Configure Claude Code, Codex CLI, and Gemini CLI for Ralph-style automation with fewer approval prompts while keeping project boundaries, secret denylists, and sandbox-first safety rules intact. Use when the user needs trusted-folder setup, approval-policy tuning, sandbox-first YOLO boundaries, or checkpoint rules for long-running `ralph` or `omg` loops. Triggers on: ralphmode, trusted folder, bypass approvals safely, Codex sandbox mode, approval policy, checkpoint needed, repo-scoped automation.
42 -
whyashthakker Skill Caveman 2Terse "caveman" replies: strip filler, articles, hedging; fragments and short synonyms OK; technical terms and code blocks unchanged. Levels: lite (tight sentences), full (classic caveman), ultra (max abbreviation), plus wenyan-lite, wenyan-full, wenyan-ultra for classical Chinese compression. Switch with /caveman lite|full|ultra (or wenyan-*). Pauses caveman for security warnings, irreversible actions, risky multi-step order, or when user is confused; code, commits, and PRs stay normal prose unless user asks otherwise.
-
gsmlg-dev Skill Cmd Check Phoenix Duskmoon DesignRead `phoenix-duskmoon-design` skill first to understand all design rules, then audit this project for compliance. Report every violation with file path, line number, the offending code, and the correct fix.
-
the-vibe-company Bundle Companion 2Use when managing local SKILL.md packages with Companion: validate, publish, update, resolve dependencies, declare secrets, environment variables, or hosted SQLite state tables, query skill state, install updates, audit skills, check workspace versions, or self-update this Companion skill through the Companion workspace API.
-
tools-only Bundle 011 Main 92fce8efSecurity & Input Validation Skill
7 -
tools-only Bundle 1295 Xss 4735df1eCross-Site Scripting (XSS) Prevention Reference
7 -
tools-only Bundle 2032 Ard D42be74eARD: Wallet Security Auditor
7 -
tools-only Bundle 097 Index 7dc7f681论文审查 (paper-audit)
7 -
tools-only Bundle 097 Index 9a8b6735Paper Audit (paper-audit)
7 -
tools-only Bundle 168 Threat 879e69e1<!-- Threat Modeling Skill | Version 3.0.0 (20260201a) | https://github.com/fr33d3m0n/threat-modeling | License: BSD-3-Clause -->
7 -
tools-only Bundle 169 Threat E82c8d25<!-- Threat Modeling Skill | Version 3.0.0 (20260201a) | https://github.com/fr33d3m0n/threat-modeling | License: BSD-3-Clause -->
7 -
tools-only Bundle 097 Index 3f9d5a0f<meta http-equiv="Content-Security-Policy"
7 -
tools-only Bundle 047 Threat E2ab4fb7<!-- Threat Modeling Skill | Version 3.0.0 (20260201a) | https://github.com/fr33d3m0n/threat-modeling | License: BSD-3-Clause -->
7 -
tools-only Bundle 106 Clause Ecdb052bISO 13485 Audit Guide
7 -
tools-only Bundle 109 Threat 1e93fae4<!-- Threat Modeling Skill | Version 3.0.0 (20260201a) | https://github.com/fr33d3m0n/threat-modeling | License: BSD-3-Clause -->
7 -
tools-only Bundle 109 Threat 25a70d17<!-- Threat Modeling Skill | Version 3.0.0 (20260201a) | https://github.com/fr33d3m0n/threat-modeling | License: BSD-3-Clause -->
7 -
tools-only Bundle 046 Threat Acd9e1df<!-- Threat Modeling Skill | Version 3.0.0 (20260201a) | https://github.com/fr33d3m0n/threat-modeling | License: BSD-3-Clause -->
7 -
tools-only Bundle 047 Threat 700e4ff2<!-- Threat Modeling Skill | Version 3.0.0 (20260201a) | https://github.com/fr33d3m0n/threat-modeling | License: BSD-3-Clause -->
7 -
tools-only Bundle 048 Threat 28bf8573<!-- Threat Modeling Skill | Version 3.0.0 (20260201a) | https://github.com/fr33d3m0n/threat-modeling | License: BSD-3-Clause -->
7 -
tools-only Bundle 2461 Audit 256f139fAudit Namshub installation — show hooks, skills, permissions, data storage, and security posture
7 -
tools-only Bundle 2477 Audit E82b525bSecurity Audit Guide
7 -
tools-only Bundle 2490 Audit 59c5e3e0Security Audit Guide
7 -
tools-only Bundle 2512 Audit Feffe771Audit Workflow
7 -
tools-only Bundle 2609 Audit 3d83e084Security Audit Guide
7 -
tools-only Bundle 2504 Design 52059e14Technical Design: Security Hardening
7 -
tools-only Bundle 2504 Design Ba178a27Technical Design: security-hardening-addendum
7 -
tools-only Bundle 715 Logging Acca4eeeSecurity Logging Reference
7 -
tools-only Bundle 870 Exploit 7ba88d2e870 Exploit 7ba88d2e
7 -
tools-only Bundle 037 Threat 24fba8e0<!-- Threat Modeling Skill | Version 3.0.0 (20260201a) | https://github.com/fr33d3m0n/threat-modeling | License: BSD-3-Clause -->
7 -
tools-only Bundle 096 Threat 8d00c0dc<!-- Threat Modeling Skill | Version 3.0.0 (20260201a) | https://github.com/fr33d3m0n/threat-modeling | License: BSD-3-Clause -->
7 -
tools-only Bundle 102 Strong 3be0bd62Security Checklists
7 -
tools-only Bundle 194 System 4e70fd23zeroize-audit (Claude Skill)
7 -
tools-only Bundle 024 Security F3c95135Backend Security Practices
7
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include deep-dive, security-review, mise-expert. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.