Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
loud-trumpet Skill Blog Review DraftAudit a Loud Trumpet draft before publishing, for overclaiming, style violations, internal contradictions and rigged examples. Use before any post goes live, or when asked to review writing.
-
hacktheseo Bundle AI Citability AuditScores every passage of a page for AI citability (citabilité, GEO, AEO), maps what ChatGPT can quote as is, rewrites the rest. Use for citability audit, audit GEO, être cité par ChatGPT.
-
amit-voais Bundle Fortax AuditAudit fieldwork support for statutory, tax and internal audits - build the working paper file (index, lead schedules, analytical review of the trial balance, ratios, ledger scrutiny area by area, voucher sampling, tick marks, review points), pull Form 3CD and CARO data from the ledgers with source references, test internal financial controls (IFC under s.143(3)(i), or SOX 404 for US-linked groups) with sample sizes, evidence standards and deficiency classification, and draft management letter points. Opinions and sign-off stay with the auditor. Typical asks - "audit file ready karo", "ledger scrutiny karo", "vouching ke liye sample nikalo", "3CD ke clauses bharne hain", "CARO points", "IFC testing", "management letter".
-
vtstech Bundle Codebase AuditAudit, analyze, and produce a condensed intelligence brief for any codebase. Use this skill whenever you need to understand, review, audit, or get oriented on a codebase or project. Triggers on phrases like "audit this repo", "review the codebase", "what does this project do", "get me up to speed", "brief me on", "understand this code", "code review", or when starting work on an unfamiliar codebase. Also triggers when the user asks to clone and review a repo. This skill handles two modes: if a brief.md already exists, load it for instant orientation; if not, perform a full audit and generate both a brief.md (condensed orientation) and an audit.md (detailed findings report). This enables efficient context transfer between sessions and agents without re-reading the entire codebase, while also producing a comprehensive audit artifact with bugs, security findings, and recommendations.
-
aivrar Skill Requesting Code ReviewPre-commit review: security scan, quality gates, auto-fix.
-
amit-voais Bundle Fortax Plan And RunWorking method for CA jobs bigger than a reply - scope a vague ask into a five-line brief the CA confirms, write a plan with blockers first and one action per step, run it step by step ticking the plan and stopping instead of guessing, and run the same return for several clients in parallel with one checklist and one consolidated status table. The last step is always the CA's filing. Typical asks - "Sharma ji ka kaam kar do", "is mahine ke saare GSTR-1 nikalo", "audit file ready karni hai, plan bana lo", "11 clients ka 3B batch", "dekh lo kya karna hai".
-
amit-voais Bundle Fortax India Dpdp ActIndia's Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 for a CA and client — does the Act apply, data fiduciary duties (notice, consent, legitimate uses, security, breach intimation, erasure, processor contracts), data principal rights and grievance, children's data, Significant Data Fiduciary duties, consent managers, transfers abroad, exemptions, the Data Protection Board and the penalty schedule — and a gap assessment with a compliance checklist. Use for "DPDP lagega kya", "privacy policy DPDP ke hisaab se", "data breach hua, Board ko kab batana hai", "consent form banao", "DPDP penalty kitni".
-
efedkaya Bundle Instagram Followback AuditorAudit which Instagram accounts do not follow the user back through the companion browser extension, and help review or cautiously unfollow selected results. Use only when explicitly invoked for the user's own signed-in Instagram account.
-
stijnvanhulle Skill DeslopAudit a diff for over-engineering and AI code/prose tells, then apply only confirmed fixes.
-
stijnvanhulle Bundle ConventionsApply the shared TypeScript, markdown, testing, security, and language rules.
-
agentjido Skill Code ReviewReviews code changes for quality, security, and best practices.
-
catpilotai Bundle Catpilot Safe BuildingPlain-language security guidance for anyone building an app, automation, dashboard, or data tool with an AI assistant, whether or not they can read code. Use whenever the conversation is about building, connecting, deploying, or sharing something that touches company data or company systems. Eight checkpoints: data in prompts, access and identity, hosting, sharing and publishing, keys and credentials, third-party services, untrusted input, and when to ask a human. Advisory guidance the assistant reads; not monitoring, not enforcement, and not a review of the app.
-
kesslernity Bundle Cdo Reviewer 4Reviews a proposal, business case, deck or plan in character as a Chief Data Officer archetype and returns a DRAFT review in the chat with a verdict, findings that cite the exact passage, data and AI governance risks, what would change the verdict and five interrogation questions. Use when the user asks to "run a CDO review", "pressure-test the data governance in this plan", "what would a CDO say about this", "check the metric definitions and data sources" or "prepare this for the data governance board". Do not use for security controls or third-party security risk, use ciso-reviewer instead; for contract, liability or regulatory terms, use general-counsel-reviewer. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Cto Reviewer 4Reviews a proposal, business case, deck or plan in character as a Chief Technology Officer archetype and returns a DRAFT review in the chat with a verdict, findings cited to the exact passage, technology risks (architecture, build versus buy, vendor lock-in, security of design, engineering capacity), what would change the verdict and five interrogation questions. Use when the user asks to "run a CTO review", "pressure-test the technical side of this plan", "what would a CTO ask about this" or "rehearse the technology seat before the review". Do not use for cash, payback or budget questions, use cfo-reviewer instead; for capacity and timeline questions, use coo-reviewer; for security controls, privacy or compliance, use ciso-reviewer. Drafts for human review; never approves, authorises or signs off.
-
catpilotai Skill Secrets ManagementGovern how secrets are stored, scoped, distributed, rotated, and surfaced to running code — never committed `.env` files, never echoed in CI logs, never embedded in URLs or error messages, never shared across environments. Complements `secret-blocking` (which detects hardcoded patterns at write time) by enforcing the lifecycle around already-secured secrets — `.gitignore` hygiene, CI log redaction, vault-backed access, scoped credentials per environment, and a documented response when exposure happens.
-
catpilotai Skill When To Ask A HumanExplicit triggers to stop and ask for a security review, including real customer or employee data, external users, payments, health data, anything that writes to a system of record, and anything the person cannot explain. Give the person a two-sentence summary to send.
-
kesslernity Skill Software Request Review 2Reviews one employee software request (tool, purpose, users, data handled, cost, urgency) against the approved-tools list and the policies the user provides and returns a draft review for the reviewer: match state on the list with the row quoted, approved tools the list itself describes as covering the same need, policy clauses that bear on the request with quoted text, questions for the requester and the reviewer, and one suggested decision with its basis. Never approves, procures, installs or adds a tool to the list. Use when the user asks to "review this software request", "is this tool on the approved list", "check this request against our software policy", "do we already have something approved that does this" or "prepare the decision note for this tool request". Do not use for a full vendor security assessment, use vendor-risk-screening-brief instead; for sorting mixed requests, use request-intake-triage. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Ciso Reviewer 4Reviews a proposal, business case, deck or plan in character as a Chief Information Security Officer archetype and returns a DRAFT review with a verdict, findings cited to specific passages, security and compliance risks and the five interrogation questions a real CISO would ask. Use when the user asks to "run a CISO review", "pressure-test the security of this plan", "what would our CISO say about this" or "check the privacy and third-party risk". Do not use for contract, liability or regulatory-interpretation reviews, use general-counsel-reviewer instead. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Audit Prep Pack 2Prepares a DRAFT internal audit pack from the audit plan: scope as stated, criteria with clauses quoted from the documents provided, document requests per auditee with due dates, open interview questions per process and role, previous findings to follow up and a readiness checklist. Never pre-judges conformity, writes findings or selects the sample; the lead auditor decides. Use when the user asks to "prepare the internal audit", "build the audit pack from this plan", "draft the document requests and interview questions" or "get us ready for the supplier audit". Do not use for evidence requests built from a control list, use control-evidence-request-pack instead; to chase actions from earlier audits, use corrective-action-tracker. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Controls Gap Pack 3Produces a draft controls and gap pack from a requirement, regulation, standard or policy and the organisation's control descriptions: obligations broken out of the source text, the controls that appear to address each, apparent coverage, gaps, questions for control owners and actions to assess. Never concludes compliance or that a control is effective; owners and audit assess. Use when the user asks to "map this regulation to our controls", "run a controls gap analysis", "break this standard into obligations" or "where is our control coverage thin". Do not use for comparing a policy document against a standard, use policy-gap-review instead; to draft evidence requests from the mapped controls, use control-evidence-request-pack. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Policy Gap Review 2Compares one policy against one requirement set (standard, regulation, contract schedule or customer requirement) clause by clause and returns a draft gap review: each requirement element, the policy clause that appears to address it, an apparent match state, and every gap as a question with the clause reference on both sides. Never concludes that the policy complies; the owner decides. Use when the user asks to "gap our policy against the standard", "map this policy to the regulation clause by clause", "check the security policy against the customer's contract schedule", "compare our policy with the new edition" or "where does our policy fall short of the requirements". Do not use for mapping a requirement to the operating controls that implement it, use controls-gap-pack instead; for what a regulatory change means for the organisation, use regulatory-change-impact-note. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle General Counsel Reviewer 4Reviews a proposal, business case, deck, plan or contract summary in character as a General Counsel archetype and returns a DRAFT review in the chat with a verdict, findings that cite the exact passage or clause, legal risks, what would change the verdict and five interrogation questions. Meeting preparation, not legal advice. Use when the user asks to "run a general counsel review", "what would legal say about this", "pressure-test the legal exposure in this deal" or "prepare me for the deal committee". Do not use for price, term, renewal or vendor leverage, use procurement-reviewer instead; for lawful basis and data flows, use cdo-reviewer; for security controls, use ciso-reviewer. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Corrective Action Tracker 2Turns corrective and preventive actions from NCRs, audit reports, action forms, minutes or a tracker into one DRAFT tracker: action as stated, source, owner, due date, evidence expected and status, with flags for overdue, unowned, undated, stale and closed-without-evidence items and one question per flag. Never closes, verifies, reassigns or re-dates an action. Use when the user asks to "build the CAPA tracker", "update the corrective action log from these audit reports", "which actions are overdue or have no owner" or "draft the chase notes for open actions". Do not use for writing up the nonconformity itself, use nonconformance-report-drafter instead. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Export Review Pack 3Reads one export transaction, order or shipment description and returns a DRAFT export review pack: parties to screen with a screening checklist, an item classification worksheet, a red-flag review, licence-determination questions and open items. Use when the user asks to "prepare the export review for this order", "pre-check this shipment for export control", "who do we need to screen on this deal", "build the classification worksheet for this item" or "assemble the trade-compliance file for this technology transfer". Do not use for vendor security or due-diligence screening of a supplier's questionnaire answers; use vendor-risk-screening-brief instead. Never classifies, screens, clears, decides licence need or releases a shipment; trade compliance does. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Skill Claims Evidence Map 2Builds an evidence map for one document, section or contested claim: every factual claim extracted verbatim and numbered, its supporting passage in the supplied sources or UNKNOWN, the strength of that support as evidenced, contradictions between sources, and the specific question or document that would close each gap, returned in the chat as Markdown tables for the author or reviewer. Use when the user asks to "check what this document actually proves", "map the evidence behind these claims", "which of these statements are supported", "build an evidence map", "what would we need to back this up" or "is this claim substantiated". Do not use for requesting evidence of security controls from control owners, use control-evidence-request-pack instead. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Board Paper Skeleton 2Builds a DRAFT board paper skeleton from the sponsor's inputs: purpose, recommendation as the sponsor states it, options including do nothing, risks, financials exactly as provided, authority to decide and the decision sought, with every claim tagged evidenced, asserted or UNKNOWN so the sponsor sees what still needs support. Use when the user asks to "draft a board paper", "structure the committee paper", "prepare the decision paper for the investment committee", "skeleton the board memo" or "what goes in the paper for the audit committee". Do not use for a pre-read or briefing pack with no resolution sought, use executive-briefing-pack instead; to record a decision already taken in a discussion, use decision-memo-builder. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Vendor Risk Screening Brief 2Prepares a DRAFT vendor risk screening brief from the material the user provides on one vendor (questionnaire answers, certificates, assurance reports, policies, contract extracts): per screening topic, what a document evidences with reference, date and scope, what is only asserted, what is missing or contradicted, certificate and report details as stated, and ready-to-send questions for the vendor and the internal owners. No web research, no risk rating, tier, score or recommendation. Use when the user asks to "screen this vendor", "review the vendor's questionnaire answers", "check what the vendor's certificate covers", "what is missing from this due diligence pack" or "draft the follow-up questions for the vendor". Do not use for answering a customer's questionnaire about your own organisation, use vendor-security-questionnaire-prefill instead. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Control Evidence Request Pack 2Turns a control list and an audit scope into draft evidence requests grouped by control owner, each with the control as stated, the audit period, evidence examples (commonly requested) and a proposed due date derived from the fieldwork dates. Never judges whether evidence is sufficient, never selects the sample and never sends a request; the auditor decides. Use when the user asks to "prepare the evidence requests", "draft the PBC list", "build the evidence request pack for the audit" or "what do we need to ask each control owner for". Do not use for document requests and interview questions built from an audit plan, use audit-prep-pack instead; to check claims in a report against sources, use claims-evidence-map. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Bundle Procurement Reviewer 4Reviews a proposal, business case, deck or vendor contract in character as a Head of Procurement archetype and returns a DRAFT review in the chat with a verdict, findings that cite the exact passage or clause, commercial risks, what would change the verdict and five interrogation questions. Use when the user asks to "review this from a procurement angle", "what would procurement say about this proposal", "pressure-test this vendor contract commercially", "find the holes before the sourcing committee" or "check the renewal terms like a Head of Procurement would". Do not use for liability, IP, regulatory or signing-authority questions, use general-counsel-reviewer instead; for whether the spend fits the budget, use cfo-reviewer; for vendor security, use ciso-reviewer. Drafts for human review; never approves, authorises or signs off.
-
kesslernity Skill Rfp Response Drafter 2Drafts answers to the questions in a received RFP, RFQ or tender from the organisation's past responses, answer library, case studies, policies and other documents provided: one row per buyer question with a draft answer marked Reused, Adapted or Missing, its source and date, and a legal or pricing review flag on every answer touching terms, liability, warranties, insurance, data protection or price. Use when the user asks to "draft our RFP response", "answer this tender from our past proposals", "pre-fill the bid questions", "first pass at the RFQ answers" or "reuse our previous bid content". Do not use for writing the buyer's own RFP or requirements, use rfp-requirements-pack instead; for security or due diligence questionnaires use vendor-security-questionnaire-prefill; for scoring received supplier responses use rfp-comparison-pack. Drafts for human review; never approves, authorises or signs off.
-
hi-donwi Bundle Code ReviewReview a diff or PR across correctness, design, tests, security, and clarity, and give actionable, prioritized feedback. Use when asked to review code, before merging a change, or to self-review a diff. Do not use to author large new features from scratch (use the build skills) — this reviews existing changes.
-
hi-donwi Skill Quarkus ServiceBuild or change Quarkus services and endpoints: Maven module structure, resource/service/ repository layering, CDI and scopes, typed configuration, REST clients between services, and lifting demo-grade code to production standard. Use when adding a new endpoint, creating a new Quarkus module, untangling code that mixes layers, moving configuration to @ConfigMapping, or calling another service over REST. Do not use for HTTP contract shape (rest-api-contract), queries and migrations (quarkus-persistence), auth (quarkus-security), tests (quarkus-testing), or large exports (bulk-reporting-export).
-
hi-donwi Skill Dependency AuditAudit, upgrade, or rationalize third-party dependencies for security, licensing, maintenance, bundle/runtime impact, and supply-chain risk. Use when adding dependencies, fixing audit findings, upgrading packages, or reducing dependency surface. Do not use for application logic bugs unrelated to external packages.
-
hi-donwi Skill Quarkus SecurityApply and review backend security in Quarkus: Argon2id, Redis-backed sessions and cookies, closed-by-default RBAC with @RolesAllowed, data-level authorisation pushed into queries, allowlists for dynamic sort and filter, bid-document upload validation, security headers, CORS, and secret handling. Use when touching login or sessions, adding an endpoint that needs a role, accepting user input or files, building dynamic sort/filter, reviewing a PR that touches auth or sensitive data, or handling secrets. Do not use for error response shape (rest-api-contract) or infrastructure/network security (java-delivery).
-
hi-donwi Bundle REST API ContractDesign and review REST contracts: URL shape and HTTP method choice, status codes, uniform pagination and filtering, RFC 9457 problem+json errors with stable ErrorCodes, date/money/ enum formats, OpenAPI annotations and the committed spec, versioning and breaking-change identification. Use when designing a new endpoint, aligning endpoints that have diverged, choosing a status code, shaping an error response, updating the OpenAPI spec, or judging whether a change is breaking. Do not use for internal implementation (quarkus-service), queries (quarkus-persistence), or roles and authorisation (quarkus-security).
-
hi-donwi Bundle Security HardeningFind and fix common security weaknesses (OWASP-style) and manage secrets safely. Use when reviewing code for vulnerabilities, handling auth/input/untrusted data, before shipping anything internet-facing, or when secrets/keys are involved. Do not use for offensive security, exploitation, or attacking systems you don't own.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include blog-review-draft, ai-citability-audit, fortax-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.