Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
mabbit143 Bundle Senior BackendDesigns and implements backend systems including REST APIs, microservices, database architectures, authentication flows, and security hardening. Use when the user asks to "design REST APIs", "optimize database queries", "implement authentication", "build microservices", "review backend code", "set up GraphQL", "handle database migrations", or "load test APIs". Covers Node.js/Express/Fastify development, PostgreSQL optimization, API security, and backend architecture patterns.
-
andreasbloomquist Skill Principal Engineer ReviewUse when the user wants a principal-engineer-level review, a thorough pre-merge review, or an independent multi-lens review of a pull request, branch, or pending changes — trigger phrases include "PE review", "review this like a principal engineer", "review this PR/branch/diff", "check for regressions/security/performance before merging", "is this over-engineered", "second opinion on this code".
-
andrewdryga Skill Security Deps AuditAudit portal/ hex dependencies for supply-chain risk — retired/yanked packages, known advisories, unexpected git/path deps, and vetting a dependency before adding it. Use before adding a dep, before a release, or periodically. emisar is a security product; every new dependency is attack surface.
-
robertoatila Skill PayloadsallthethingsCurated OWASP attack dictionaries and bypass payloads for authorized web security audits.
-
pizza-bot-app Bundle Pizza Bot GuideHelp people understand Pizza Bot, choose useful workflows, configure it, extend it, troubleshoot it, or find the right project documentation. Use when someone asks what Pizza Bot can do, how to use a feature, how its data and security boundaries work, or how to contribute.
-
glitterkill Skill Release NotesGenerate a CHANGELOG.md entry from git history since the last tag, categorized by type (features, fixes, security, breaking changes). Matches the existing CHANGELOG format.
-
robertoatila Skill Security Research AuditAudits software components for CVEs, exposed secrets, insecure configurations, and dependency risks.
-
robertoatila Skill Comprehensive Code ReviewSystematic code review across security, correctness, architecture, maintainability, and test coverage.
-
robertoatila Skill Package Pre Publish AuditAudits packages and tarballs before publishing to npm, PyPI, or Crates.io.
-
robertoatila Skill Tech Debt Audit 2Thorough, file-cited technical debt audit across 9 dimensions using AST-grep (tree-sitter), grep, language-native tooling, and optionally CodeGraph knowledge graph. Produces TECH_DEBT_AUDIT.md with severity, effort estimates, and prioritized fixes. Use when asked for codebase health check, tech debt audit, architecture review, code quality assessment, or cleanup planning. Triggers: 'tech debt', 'technical debt', 'debt audit', 'code health', 'technical debt audit', 'codebase health check', 'find tech debt', 'debt analysis', 'audit code quality'.
-
robertoatila Skill Tech Debt AuditAudits architectural and test debt, generating prioritized remediation scorecards.
-
robertoatila Skill Review WorkPost-implementation review orchestrator. Launches 5 parallel background sub-agents: Oracle (goal/constraint verification), Oracle (code quality), Oracle (security), unspecified-high (hands-on QA execution), unspecified-high (context mining from GitHub/git/Slack/Notion). All must pass for review to pass. MUST USE before a PR handoff or when the user explicitly asks to review completed work. Triggers: 'review work', 'review my work', 'review changes', 'QA my work', 'verify implementation', 'check my work', 'validate changes', 'post-implementation review'.
-
robertoatila Skill Git Unpublished Changes AuditAudits unpublished commits and tags against release registries across monorepos.
-
orderful Bundle Netsuite SetupSet up credentials for an Orderful NetSuite SuiteApp customer. Creates a per-customer `.env` file with NetSuite Token-Based Auth (account ID, consumer key/secret, token ID/secret) and an Orderful API key, then validates both connections work. Use when the user is starting work with a new NetSuite customer, needs to configure access to a customer's NetSuite and Orderful, is onboarding a customer, or says things like "/netsuite-setup", "set up a new customer", "create customer credentials", "onboard <customer>", or "I need access to <customer>'s NetSuite".
-
davidgfolch Skill Gh Actions DebugDebug GitHub Actions / Dependabot run failures with the gh CLI. Use when a workflow run fails, a status check is red, or a Dependabot security/version update errors out.
-
orderful Skill Audit Outbound RulesAudit a customer's per-relationship outbound transformation rules at /v2/rules and flag any whitelist that's narrower than the partner's published spec. Run this BEFORE writing JSONata for a new outbound document type — misconfigured rules silently strip required EDI segments at send time, surfacing as "missing field" validation errors that NS-stored messages and /v3/validate both contradict. Use when the user says "audit the rules", "check outbound rules", "the post-fact validations show missing X but the message has it", "before we write outbound JSONata", or any time you're starting outbound work for a customer / partner / doc type that hasn't been validated end-to-end yet.
-
relaticle Bundle Business ReviewUse when the user asks to business-review their work (local mode default, via 'business-review' or 'review my branch'), a Relaticle pull request ('--pr <N>' or a bare PR number), or a described change (--describe). v3 is a panel-of-QAs engine. It resolves the live environment first (URLs/creds/queue/Redis/Reverb are DISCOVERED from the running app, never assumed), runs a browser-capability preflight, auto-tiers by blast radius, synthesizes journeys from the diff plus Relaticle CRM priors, walks them happy AND sad through the real browser, sweeps the regression ledger, adversarially cold-reproduces every bug, and emits a substance-gated verdict (ai-approved / ai-rejected / ai-needs-human, or blocked on a degraded channel). Browser-truth only: never tinker or hit the DB to fix or fake a result. On request ('fix all issues', --fix) enters fix mode: fix → re-verify each finding against its original repro → re-gate. Publishing to the PR is opt-in and hard-disabled on a degraded run. Does NOT do code/security/scope
-
relaticle Bundle Spatie SecurityApply Spatie's security guidelines when configuring applications, databases, servers, credentials, or signed Git commits, or when reviewing code for security concerns; use for SSL setup, CSRF protection, password hashing, database permissions, and server hardening.
-
blauwtje Skill DeepenUse when the user asks where or how to improve architecture without naming one exact change: tech debt, coupling, shallow modules, refactor candidates across a codebase or subsystem. In a read-only planning mode it owns the turn and writes the plan for its findings. Not for a single named refactor or rename, failing existing behavior, or a security or dependency audit.
-
blauwtje Bundle PlanningUse when a read-only planning mode is active, the user asks for a plan, another session will run the work, or inspection finds two or more edit-order dependencies. Not for same-session work with at most one dependency edge; one-file, typo, rename, or version-bump edits; git-only operations; an unproven failure outside a planning turn; or an architecture audit, which deepen owns.
-
jialuohu Bundle Improve AnimationsUse when a user wants a source-read-only animation audit, prioritized motion-improvement recommendations, or a response-only implementation plan rather than code changes.
-
nik-ti Bundle Analyze ChannelAnalyze any YouTube or Telegram channel — content strategy, cadence, topics, tone, monetization, what performs and why. Use this skill whenever the user pastes a YouTube channel link/@handle or a t.me link and asks to analyze, research, break down, study, reverse-engineer, audit, or "see what they're doing" — and also when they ask softer things like "what kind of content does this channel post?", "how often do they upload?", "what's their strategy?", "what are they promoting?", or "can you look at this channel for me". Applies even when the user doesn't use the word "analyze". For YouTube it can optionally watch videos via the `watch` skill for a deeper read. Do NOT use for analyzing a single video (use `watch` directly).
-
blauwtje Bundle Implementing BatchUse when a decided change builds in this session and inspection shows it modifies more than two source/test/config files, adds a dependency, changes a public signature, crosses a persisted format or security boundary, or reaches an uninspected file; also a whole plan run here. Not for a change reaching at most two files, a version bump, a git-only operation, or an unproven failure.
-
belentani7 Bundle Test MasterGenerates test files, creates mocking strategies, analyzes code coverage, designs test architectures, and produces test plans and defect reports across functional, performance, and security testing disciplines.
-
belentani7 Bundle Anti MalwareDefensive malware detection and analysis skill. Use when user needs to detect, analyze, or defend against malicious software - including static/dynamic analysis, IOC extraction, YARA rule creation, sandbox behavioral analysis, memory forensics, and threat hunting. Trigger on: "detect malware", "analyze suspicious file", "malware analysis", "threat hunting", "IOC extraction", "YARA rules", "sandbox analysis", "memory forensics", "malware defense", "antivirus evasion detection".
-
ai-automation-tools Bundle Recipe ValidatorValidate food recipes for quality and safety. Checks safe cooking temperatures and dangerous ingredients/techniques (food safety), per-serving sodium / saturated fat / added sugar against health standards, ingredient quantities and ratios versus comparable recipes, allergen labeling completeness, and recipe coherence — then reports findings ranked by severity with concrete fixes. Use this whenever the user wants to check, validate, review, audit, quality-check, or "sanity-check" one recipe or a whole folder of recipes, asks whether a recipe is safe, healthy, balanced, or well-made, or mentions reviewing recipe nutrition, salt/fat/sugar content, or food-safety issues — even if they don't use the word "validate." The recipe location is a parameter, so it works on a single file, a folder, or an entire recipe collection in any layout.
-
belentani7 Skill Web PerfAudit, diagnose, or optimize website loading and interaction performance, Core Web Vitals, and Lighthouse performance scores.
-
belentani7 Bundle CloudflareDiscover and choose Cloudflare products for apps, APIs, AI agents, storage, networking, and security. Use for architecture and product selection, including when the user describes a need without naming a Cloudflare product; then find the relevant skill or documentation.
-
belentani7 Skill Windows Fast Safe ConfigConfigure Windows 10/11 for maximum performance and security using only official Microsoft sources, with automatic rollback. Use when hardening Windows, improving boot/UI performance, disabling telemetry or ads, or applying Microsoft security baselines safely.
-
selfishprimate Skill Audit LibrarySweep every mixin and function in Gerillass and report where it misbehaves — silent failures, unhelpful errors, questionable output, and gaps in test coverage. Use when asked to audit or comprehensively test the library, before a release, or after a change that touches many mixins.
-
aitofy-dev Skill Jev GuardUse before running a shell command that might delete data, print a secret, force-push, or do something the user did not ask for. Jev scores the harm. You still decide whether to run it. Runs @aitofy/jev-awesome-skills.
-
uselemma Bundle Lemma Writing GuidelinesReview docs/prose for Writing Guidelines compliance. Use when asked to "review my docs", "check writing style", "audit prose", "review docs voice and tone", or "check this page against the writing handbook".
-
lucasgs520 Bundle Skill AuditScans .claude/skills/ for likely duplicate or overlapping skills (by keyword similarity in their descriptions) and lists installed official/marketplace skills (superpowers, mattpocock-skills, etc.) side by side, so overlap is visible before adding a new skill. Use when the user says "audit skills", "check for duplicate skills", "does a skill for X already exist", or before installing/creating a new skill.
-
julianramirezreyes Skill SecuritySeguridad aplicada: OWASP, autenticación/autorización, secretos, validación, defensa en profundidad.
-
lucasgs520 Bundle N8n Credentials And SecurityUse when handling any auth, API keys, tokens, OAuth, bearer tokens, basic auth, or secret values in n8n workflows. Triggers on "API key", "token", "bearer", "OAuth", "secret", "auth", "credentials", "Authorization header", "x-api-key", or any node configuration that mentions a third-party service.
-
aeneassoft Skill Which Path Is Worth ItWhich path is worth it? Which research or action path should I try next under incomplete information? Use this when choosing between two or more approaches, planning research, deciding where to spend a limited budget, or when the user asks which option to pursue. Given each path's successes, failures, prior, cost per attempt and value on success, computes success probability with bounds, expected value, safe value (lower bound) and optimistic value (upper bound). Returns exactly EXPLOIT, EXPLORE or FOLD per path with a plan; hostnames pull their outcomes from the ledger. Do not use with a single option — then use should-i-stop-and-ask.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include senior-backend, principal-engineer-review, security-deps-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.