Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
nudgebee Skill QA Automation Code CheckPre-commit gate for Playwright automation code in app-e2e-tests. Checks the QA's changed spec/locator/helper files against seven mandatory parameters — testid/role-first locators with a safe fallback, single-line comments only, secrets from .env, required tags, structure and reuse (no waitForTimeout, no swallowed assertions, titles that state the journey and the expected result), proven run evidence, and the OSS-push decision — then returns a COMMIT READY or BLOCKED verdict with the exact gaps to close. Also use it on its own to write or audit test titles, or to replace flaky waits.
-
justtyashh Skill Skill AuditCompares compiled Skills against recent BehavioralTraces to detect workflow drift or obsolescence. Use when auditing learned skills, checking if a Soulcatcher skill still matches behavior, or after major project changes.
-
xtieume Bundle GoalrunUse when a user wants work driven to completion or wants to know whether it truly is complete — "build X and don't stop until it's done", "keep going", "don't stop", "is this finished?", "is it done yet?", "audit whether this shipped" — or when you are about to tell the user something is done, finished, or complete.
-
xtieume Bundle Docs ReviewUse when the user asks to review or audit documentation, check whether docs cover a spec, build a requirements traceability matrix, find gaps, stale sections or contradictions between a spec and its documents, investigate a question across a document set, or fix and update documents to match a spec (--fix).
-
xtieume Bundle Playwright NotionUse when downloading or reading Notion pages without an API token — the workspace is company-owned, there is no integration secret, the UI Export button is disabled or missing by permission, and access exists only through a logged-in browser. Also use when a Notion scrape produced wrong markdown (tables repeated, cells duplicated, sidebar text mixed into content) or when a headless browser lands on the Notion login screen.
-
synthesisengineering Bundle Synthesis PreflightPre-merge quality gate framework with six orthogonal dimensions: branch hygiene, clean tree, tests and types, code audit, temporary considerations, and commit history. Produces a mechanical go/no-go verdict. Use when asked to: preflight, pre-merge check, ready to merge, can I ship this, branch ready, quality gate, merge readiness, pre-PR check.
-
synthesisengineering Bundle Synthesis Clean TextEnforce clean-text and no-hidden-marker requirements, audit inspectable characters and provenance, and state the verification boundary for statistical text marks. Use when generating clean text, checking hidden characters, addressing watermark concerns, or selecting a controlled generation path.
-
synthesisengineering Bundle Synthesis Code AuditSystematic 10-dimension quality scan of code diffs, producing scored PASS/WARNING/FAIL verdicts per dimension with a machine-readable overall result. Includes PR review mode for cross-referencing findings against existing reviewer comments. Use when asked to: code audit, audit my changes, quality check, review the diff, check this code, audit my code, scan for issues, code quality scan, diff review.
-
nahid-sparktales Bundle Owasp WebHunt the web failure classes that actually recur — broken access control, injection, XSS by output context, SSRF, unsafe deserialization and mass assignment, session and token handling, secrets leakage, file handling — as patterns to find in this codebase. Use when writing or reviewing request handlers, queries, URL fetches, templates, uploads or auth code, or when asked to check a web app for the common vulnerability classes. Not for design-stage modeling (threat-modeling), not infrastructure or network hardening, and not a list to recite without reading code.
-
brianggggg Skill Expense Policy CheckerChecks expense line items (from a report, invoice, or receipt) against the company spend policy and flags anything over limit, missing a receipt, or in a disallowed category. Use when a user asks to audit, review, or check expenses against policy.
-
bukutsu Skill Audit LoopAutonomous iterative codebase audit and fix loop. Tailors N perspectives, resolves root causes with atomic commits, and loops until all perspectives report clean in one round. Trigger for repo-wide quality sweeps.
-
nahid-sparktales Bundle Threat ModelingWork out what is actually worth defending in this system — the trust boundaries data crosses, the assets behind them, what an attacker can already do, and the small number of threats that justify a control. Use when designing or changing a system's shape, before building auth, payments, uploads, file sharing or multi-tenancy, when adding an integration that crosses a boundary, or when asked whether a design is safe. Not for finding bugs in code that already exists (that is secure-code-review), not a compliance questionnaire, and not incident response.
-
synthesisengineering Bundle Synthesis Codebase ReviewEnterprise-scale codebase audit methodology with tiered review system (Essential through Mission-Critical). Use when asked to: codebase review, code audit, code review, review codebase, architecture review, security audit, full code review, enterprise review, codebase health check.
-
bibinprathap Skill ProvenanceTrace data lineage, source attribution, audit trails, and provenance assertions in VeritasReason graphs.
-
nahid-sparktales Bundle Secrets ManagementKeep credentials out of code, logs, bundles and history — one supply path, scoped per environment, rotatable on demand — and run the rotate-first response when one has already leaked. Use when adding or moving a key, token, connection string or signing secret, when a scanner or reviewer finds one committed, when a credential appears in logs or a client bundle, or when rotation is due. Not for deciding what a credential may access, and not for vulnerability advisories in dependencies.
-
nahid-sparktales Bundle Secure Code ReviewReview a change or a codebase for security defects with a deliberate reading order — where bugs cluster, trace source to sink, confirm reachability, and write a finding someone can actually fix. Use when asked to security-review a pull request, feature or repository, or before shipping anything touching auth, money, tenancy, uploads or secrets. Not a scanner run (its output is leads), not design-stage threat modeling, and not a penetration test — nothing here authorizes touching a running system.
-
nahid-sparktales Bundle Dependency SecurityJudge dependency risk instead of reciting it — resolve the advisory to a real path through the lockfile, decide whether the vulnerable code is reachable in this codebase, and pick upgrade, override, removal or a written acceptance. Use when an audit or advisory alert fires, before adding a new dependency, when a lockfile change needs reviewing, or when someone asks whether a named CVE actually affects this project. Not for finding vulnerabilities in code you wrote, not for secret scanning, and a clean audit output is not a claim that the application is secure.
-
soongwan Bundle Con ArtistAudit whether tests detect broken behavior by tracing assertions and running narrow controlled mutations in an isolated workspace; use for test-quality reviews, not routine test execution.
-
ly87ing Bundle Safe Merge ReviewUse when the user wants to merge a branch, a remote ref, or the corresponding branches across a set of related repos into the current working branch, or wants to review whether "is this branch ready to merge", "this merge is correct", "anything was missed", "the conflict resolution is reliable", or "it is safe to push after the merge". Applies when the user provides a branch name, remote ref, repo path, conflicted files, a merge commit, a merge request link, or a multi-repo set of branches; also when confirming a fix is really present on a parallel release line that commit-id or is-ancestor searches report as missing, and when a merge decision turns on another repo's dependency not yet on the tracked ref. Proves the merge is correct, not merely that git merge ran. Not for branch code-quality review while no merge, audit, or conflict is in play.
-
bacnh85 Skill UX DesignAnti-slop UI/UX design discipline for AI-generated interfaces. Enforces industrial-design principles (Dieter Rams: honest, thorough to the last detail, as little design as possible) so output is a defensible system, not statistical-default slop (purple glow, shadow-as-texture, missing states) — and equally not the correct-but-forgettable default (Inter, blue accent, timid sizes). Covers the Constraint-First method: own the system via a lintable DESIGN.md, write a 5-field brief, DERIVE A DIRECTION from the subject (mood, type voice, color mood, signature element), generate inside constraints, normalise, render-and-inspect with vision, pass a measurable slop-audit gate. Works deterministically with text-only models (DeepSeek-v4, GLM-5.2, Kimi K3); agy/Gemini/Claude is optional polish, never the review gate. Use when designing or building any UI — web, mobile, or desktop. Active via /ux lite|strict|off.
-
pp-jok Bundle Destiny PersonalityUse when a user requests a Bazi and Western astrology personality portrait (legacy, core, core_concise, or core_standard), deterministic birth-chart facts (facts_only), or review of an existing fact packet or execution report (audit).
-
bacnh85 Skill Ponytail AuditWhole-repo audit for over-engineering. Like ponytail-review, but scans the entire codebase instead of a diff: a ranked list of what to delete, simplify, or replace with stdlib/native equivalents. Use when the user says "audit this codebase", "audit for over-engineering", "what can I delete from this repo", "find bloat", "ponytail-audit", or "/skill:ponytail-audit". One-shot report, does not apply fixes.
-
caneff Bundle Crap AuditScore every function's CRAP (Change Risk Anti-Patterns — complexity squared times uncovered fraction cubed, plus complexity) from a fresh test run and rank the real risk hotspots. Slash-only.
-
caneff Bundle Test AuditRuthlessly audit a repo's tests — cut the ones that prove nothing, rewrite the ones checking the wrong thing, keep only what earns its place.
-
caneff Skill Domain DriftAudit whether code names match the project's own domain vocabulary — a generic name standing in for a defined term, two names for one concept, or a term used for the wrong thing.
-
caneff Skill Comment AuditRuthlessly audit a repo's comments — delete every one that doesn't earn its place, keep only what the code cannot say.
-
caneff Bundle Mutation AuditPoint at ONE module to learn which of its tests pass without actually catching a bug — run mutmut, scrape the survivors, emit test-audit findings. Opt-in, never in the default sweep.
-
caneff Bundle Ponytail AuditWhole-repo audit for over-engineering: scans the entire codebase for a ranked list of what to delete, simplify, or replace with stdlib/native equivalents. Use when the user says "audit this codebase", "audit for over-engineering", "what can I delete from this repo", "find bloat", "ponytail-audit", or "/ponytail-audit". One-shot report, does not apply fixes.
-
caneff Skill Type TightnessAudit loose typing the type-checker still accepts — Any where a real type is knowable, ignore-comments with no reason, and fake "boundary" excuses.
-
caneff Bundle Audit InstructionsAudit instruction text against Anthropic's current published guidance and report what to delete.
-
caneff Skill Read The Damn DocsUse when installing or upgrading a version-sensitive package, SDK, or framework; working with auth, billing, migrations, or another security-sensitive flow; or diagnosing an error that suggests API drift (deprecation, missing exports, changed defaults, version mismatch). Web-searches for current official docs and reads them before assuming from memory. For Anthropic/Claude API questions, defer to the claude-api skill instead.
-
undertone0809 Bundle Rudder Workspace Hygiene MaintainerUse to audit or clean Rudder worktrees, generated artifacts, logs, caches, and repo-owned processes without deleting active work, user data, or unrelated machine state. Returns AUDIT, CLEANED, or BLOCKED.
-
caipe-io Skill Review Specific PrPerform a comprehensive code review of a specific GitHub Pull Request. Analyzes code changes, checks for bugs, security issues, test coverage, and coding standards compliance. Use when a user provides a PR URL or asks to review a specific pull request.
-
caipe-io Skill Security Vulnerability ReportScan GitHub repositories for security vulnerabilities including Dependabot alerts, code scanning results, and secret scanning findings. Use when auditing repository security, preparing compliance reports, or triaging vulnerability alerts.
-
caipe-io Bundle Review Specific Pr 2Perform a comprehensive code review of a specific GitHub Pull Request. Analyzes code changes, checks for bugs, security issues, test coverage, and coding standards compliance. Use when a user provides a PR URL or asks to review a specific pull request.
-
caipe-io Bundle Security Vulnerability Report 2Scan GitHub repositories for security vulnerabilities including Dependabot alerts, code scanning results, and secret scanning findings. Use when auditing repository security, preparing compliance reports, or triaging vulnerability alerts.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include qa-automation-code-check, skill-audit, goalrun. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.