Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
blakee-marcus Bundle Discord Bot DevelopmentBuild production-quality Discord bots correctly. Framework-aware (discord.js 14.27, discord.py 2.7) but fundamentals-first: application setup, Gateway intents, interactions/slash commands, permissions, rate limits, OAuth2, security, sharding, testing, and deployment.
-
arin117kaushik Bundle Substack HumanizerUse when a Substack draft, Note, or post reads as AI written, sounds generic, needs a pre-publish review or audit, or the user wants their voice captured from past writing into a voice profile. Not for writing new drafts from scratch (use substack-notes-writer or substack-post-writer).
-
inprealpha Bundle Maintain Verification SkillAudit a project verification skill against current source and observed application behavior.
-
sumanjeet0012 Skill Pylibp2pMaster router and architectural reference for developing, debugging, and maintaining the py-libp2p repository. Guides py-libp2p PR pre-flight validation, newsfragments, Trio structured concurrency auditing, protocol scaffolding, multistream-select, Noise security handshakes, Yamux stream muxing, and interop testing. Use when the user asks for "py-libp2p help", "work on py-libp2p", "prepare py-libp2p PR", "debug py-libp2p", "audit py-libp2p concurrency", or any task inside the py-libp2p codebase.
-
sumanjeet0012 Skill Code Review CritiqueStructured code review for any snippet, file, function, git commit, or git diff. Finds bugs, edge cases, complexity issues, security flaws, resource leaks, and non-idiomatic code, then delivers a prioritized critique with actionable diffs and explanations. Use when the user asks to "review this code", "is this code correct", "critique my solution", "check my diff", "code review", "find bugs in this function", or pastes code asking for feedback.
-
sumanjeet0012 Skill Pylibp2p Concurrency AuditAudit py-libp2p code for Trio structured concurrency bugs, task leaks, cancellation swallow traps, stream lifecycle leaks, short-read truncation bugs, and resource manager (rcmgr) violations. Use when reviewing, debugging, or writing networking, transport, stream muxer (Yamux/Mplex), or protocol handlers in py-libp2p. Triggers on "audit concurrency in py-libp2p", "check task leaks", "Trio cancellation check", "debug stream closing", or "check py-libp2p async code".
-
agentcorp-inc Skill Signals Scout ExperimentsSignals scout for PostHog A/B experiments. Watches running experiments for validity threats (sample ratio mismatch, contamination, exposure stalls, mid-run flag mutations) and lifecycle drift (zombies, decided-but-running), and files each validated validity threat as a report in the inbox.
-
agentcorp-inc Skill Finding Deleted Feature FlagsFind feature flags that were soft-deleted in the active project within a recent time window. Use when the user asks "what flags were deleted in the last N days", "show me recently deleted feature flags", "who deleted flag X", "audit recent flag deletions", or anything similar. Handles the non-obvious gotcha that system.feature_flags exposes the deleted boolean but does not expose a deletion timestamp — the actual deleted-at time lives in the per-flag activity log and must be cross-referenced.
-
agentcorp-inc Skill Diagnosing Endpoint PerformanceDiagnose why a PostHog endpoint is slow or expensive and propose a concrete fix — bump the cache TTL, enable materialisation, restructure variables, or rewrite the query. Use when the user says "this endpoint is slow", "my endpoint times out", "we're hitting the cost cap on this one", or asks "should I materialise this?". Focuses on a single named endpoint, not a project-wide audit.
-
silviobeer Bundle IntakeBootstrap the curated context baseline for a brownfield (or near-greenfield) repo: scan the code and draft ALL curated docs with per-statement provenance markers, interview the developer through every gap/assumption/inconsistency, reconcile via the checkpoint loop, then seal as the initial curation baseline commit. Use when: (1) a repo has code but no curated docs/ baseline (docs/PRODUCT.md missing), (2) an explicit drift audit of the curated docs is requested, (3) a near-greenfield project needs its baseline before the first PROJ. Not for: per-PROJ documentation (use documentation), ongoing doc updates (P7 curation owns those), plan approval (use checkpoint).
-
sodam-ai Skill Persona Lawyer 215년+ 전문 변호사 페르소나(#11) 깊은 도메인. 법률·계약·면책·규제·약관·audit·자본시장법·GDPR·개인정보·저작권·라이선스·AML·컴플라이언스 맥락 시 활성.
-
silviobeer Bundle Intake 2Bootstrap the curated context baseline for a brownfield (or near-greenfield) repo: scan the code and draft ALL curated docs with per-statement provenance markers, interview the developer through every gap/assumption/inconsistency, reconcile via the checkpoint loop, then seal as the initial curation baseline commit. Use when: (1) a repo has code but no curated docs/ baseline (docs/PRODUCT.md missing), (2) an explicit drift audit of the curated docs is requested, (3) a near-greenfield project needs its baseline before the first PROJ. Not for: per-PROJ documentation (use documentation), ongoing doc updates (P7 curation owns those), plan approval (use checkpoint).
-
rospocroccante Bundle Gauntlet LoopUse when the work has to beat an external standard rather than merely satisfy the person asking, and "good enough" is the failure mode. Triggers include a build or redesign or audit where quality matters more than speed, an artifact that will be judged by someone who did not commission it, or the user naming the gauntlet loop directly.
-
dangtran1003 Bundle Signoz MonthlyRun monthly deep audit for BSS portal — full BDR refresh, update Confluence pages, identify new bottlenecks, close/update existing BDRs. Triggered by /signoz-monthly.
-
jakeschincariol Skill Yt AuditAudit a YouTube channel end to end - packaging, consistency, the first fifteen seconds, and what to fix first. Use for "audit my channel", "why isn't my channel growing", "review my videos", or a pasted channel URL.
-
matsubo Bundle Github Actions WorkflowsWrite or edit GitHub Actions workflow files using the action versions that are current right now, looked up from the GitHub API rather than recalled — any version written from memory is stale. Use when creating or changing a file under .github/workflows/, adding a CI, build or release job, porting CI from another provider, or when a run fails because an action version is deprecated or its inputs moved. Covers choosing `uses:` refs, runner labels, and Dependabot upkeep. This skill is not a security reviewer: for script injection, pull_request_target, fork permissions or GITHUB_TOKEN scopes, it does not apply.
-
mohamed-amine-ben-mallessa Bundle Responsive AuditRun a visual responsive and dark-mode audit of a website or local page with iris — captures desktop, iPhone and iPad side by side (light, and dark on request), then reports layout, overflow, overlap and contrast issues with concrete fixes. Use when the user asks to check a page on multiple devices, do a responsive check, a cross-browser-viewport audit, or compare light vs dark rendering.
-
oliverschmidtprietz Bundle Breach SentinelElite incident response and legal compliance guidance for data breaches under GDPR Articles 33 & 34. Use when: (1) User reports a data breach or security incident — including "is this even a personal data breach?" triage, (2) User asks about breach notification obligations or deadlines, (3) User mentions "72 hours", Art. 33, Art. 34, or notification requirements, (4) Discussion involves security incidents affecting personal data, (5) User needs breach risk assessment using ENISA methodology, (6) User mentions "Data Breach" or "Incident" or "Data Leakage" or "Ransomware" or "Exfiltration", (7) User needs to determine Controller vs Processor obligations, (8) Cross-border breach scenarios requiring Lead SA determination, (9) User needs a mitigation playbook or immediate response recommendations, (10) User needs audit-ready breach documentation (.docx) or an EDPB-template-aligned breach notification / evidence file — including follow-up and withdrawal notifications, (11) Breach involves an AI system requiring AI
-
ntphat0322 Bundle Backend MindsetBuild robust backend systems — APIs (REST, GraphQL, gRPC), authentication (OAuth 2.1, JWT), databases, performance optimization, security (OWASP Top 10), scalability patterns (microservices, caching, sharding), and testing. Use when designing APIs, implementing auth, optimizing queries, handling security vulnerabilities, building microservices, or developing production-ready backend systems.
-
erik-corder Bundle VerificationRuns every required deterministic check (lint, type-check, tests, format, secret/dependency scan) against a diff (docs/PROCESS_CONTRACT.md, stage TESTING).
-
ararai1991 Bundle Wp Plugin SkillBuild, review, and ship production-grade WordPress plugins — architecture, hooks, admin pages, settings, custom post types, taxonomies, metadata, users and capabilities, AJAX/REST, HTTP API, cron, shortcodes, blocks, internationalization, privacy, testing, and security hardening. Use when writing any WordPress plugin PHP code, scaffolding a new plugin, adding plugin features, reviewing plugin code for bugs or vulnerabilities, handling $_GET/$_POST, registering AJAX or REST endpoints, running $wpdb queries, or preparing a plugin for the WordPress.org directory.
-
bin-h-17 Skill Dev Security Baseline开发安全基线场景子 skill(MVP 核心)。对本地项目执行密钥/API 泄露扫描(gitleaks)、 SAST(semgrep + bandit)、依赖漏洞与 SBOM(osv-scanner / pip-audit)、License REUSE 合规(reuse), 经 L2 报告合成器产出 P0–P3 统一报告 + 最小改动修复 + 复检命令,并执行发布前 gate。 当用户说"安全审查 dev"、"代码安全扫描"、"密钥扫描"、"依赖漏洞"时启用。
-
bin-h-17 Bundle Security Audit Common本地离线安全审查 Skill 集合 L2 公共层(共享依赖,不直接由用户触发)。承载:编排脚本 (audit_orchestrator / cli_wrappers / report_synthesizer / minimal_fix_engine / ai_copyright_checker / store_compliance / oss_compliance)、报告模板、条款库 references/、 基线 baselines/。被 L0 与各场景子 skill 调用。命令行调用不改上游、本地离线、0 数据出境。
-
bin-h-17 Skill Project Security Audit本地离线「安全审查 Skill 集合」L0 伞形入口。统一触发入口:识别用户场景(开发安全基线 / 开源发布合规 / 应用商店上架 / AI 内容版权),调度对应场景子 skill,并串起 L2 公共层 (编排脚本 / 报告合成 / 最小修复 / 条款库 / 基线)。本地离线、0 数据出境、命令行调用不改上游。 当用户说"安全审查"、"安全审计"、"代码安全"、"开源合规"、"上架体检"、"AI 版权"时启用本 skill。
-
serialexperimentslainnnn Skill Dns StandardsDNS service architecture, zone design and DNS security. Use when editing zone files or named.conf, unbound.conf, knot.conf, kresd config, nsd.conf, pdns.conf, dnsmasq.conf or pihole.toml, designing SOA timers, TTL, delegation and glue, CNAME-at-apex with ALIAS/ANAME, CAA, HTTPS/SVCB, SSHFP, TLSA/DANE, PTR records, DNSSEC signing and KSK/ZSK rollover, NSEC3 parameters, RRL, TSIG-protected AXFR/IXFR, split-horizon views, anycast authoritatives, .internal or home.arpa naming, zone-as-code with dnscontrol or octodns, named-checkzone, kdig, dig +trace, DoT/DoH/DoQ resolver transport, dangling subdomain takeover, DNS tunneling exfiltration or registrar/NS hijack.
-
serialexperimentslainnnn Skill Ctf Lab StandardsUse when building or running an isolated security training lab or playing CTFs — host-only or internal-network VMs with snapshots, Kali, REMnux, FLARE-VM, INetSim, detonating challenge binaries or malware samples in a disposable VM, Hack The Box, TryHackMe, PortSwigger Web Security Academy, pwn.college, OverTheWire, Proving Grounds, CTFtime events, jeopardy vs attack-defense vs king-of-the-hill formats, writeups and platform terms of service, or planning OSCP/CPTS study.
-
serialexperimentslainnnn Skill Xen StandardsThe Xen hypervisor, XCP-ng and the XenServer legacy - dom0/domU, PV/HVM/PVH and when Xen is still the right answer. Use when running xl (xl create, xl list, xl info, xl dmesg, xl sched-credit2, xl vcpu-pin), editing /etc/xen/*.cfg domain config files or xl.conf, sizing dom0_mem, dom0_max_vcpus and dom0 pinning on the Xen command line, choosing between PV, PVH and HVM guests or using pv-shim, running xenstore-ls, xentop, xl debug-keys or the credit2/null schedulers, operating XCP-ng and XenServer hosts with xe CLI, xsconsole, xapi, toolstack, SR and VDI storage repositories (LVM, ext, thin provisioning, XOSTOR/LINSTOR), PIF/VIF/network objects and bonds, pool masters and HA, managing them with Xen Orchestra, XO Lite, XOA or xo-server, migrating from VMware into XCP-ng, tracking Xen Security Advisories (XSA) and the pre-disclosure list, or deciding between Xen and KVM for a new deployment.
-
serialexperimentslainnnn Skill Solidity StandardsSolidity and EVM smart contract engineering standards. Trigger on .sol files, foundry.toml, remappings.txt, hardhat.config.ts, .solhint.json, forge/cast/anvil/foundryup, solc pragma and evm_version, OpenZeppelin Contracts and openzeppelin-upgrades, ERC-20/721/1155/4626/4337, EIP-712 and EIP-7702, UUPS/Transparent/Beacon proxies, reentrancy, oracle and flash-loan issues, invariant and fuzz tests, Slither, Echidna, Medusa, halmos, kontrol, Certora, SMTChecker, gas optimization, or pre-deployment audit and incident-response gates.
-
serialexperimentslainnnn Skill Safety Critical StandardsFunctional safety and certification evidence for software whose failure can injure or kill. Use when working to IEC 61508 (SIL 1-4, systematic capability, route 1S/2S), ISO 26262 (ASIL A-D, HARA with severity/exposure/controllability, ASIL decomposition, freedom from interference, ISO 21448 SOTIF), DO-178C/ED-12C with its supplements DO-330, DO-331, DO-332 and DO-333, DAL/FDAL/IDAL assigned by ARP4754B and ARP4761A, DO-326A/ED-202A and DO-356A airworthiness security, EN 50128 or EN 50716:2023 and EN 50126/EN 50129 railway software, IEC 62304 software safety classes A/B/C with ISO 14971 risk management, ISO/SAE 21434 and UN R155/R156, a hazard log or safety case (GSN), FMEA/FMEDA, fault tree analysis, HAZOP, requirement-to-design-to-code-to-test traceability matrices, structural coverage (statement, decision, MC/DC) and dead or deactivated code, tool qualification (TQL-1..TQL-5, tool criteria 1/2/3, TCL1-3, T1/T2/T3), MISRA C or MISRA C++ or SPARK/Ada subsets, Ferrocene qualified Rust, WCET and stack analysis,
-
serialexperimentslainnnn Skill Session Tooling StandardsUse BEFORE creating or using `.claudetools/`, the project directory where a session leaves its own scripts — gathering commands, index generators, checkers. Carries the gate (every exclusion file must already list it, added before the directory exists), the placement rule (a tool's path mirrors the code scope it covers, so the location is derivable and nobody spends an `ls`), the prohibition on any secret inside, and the rule that it stores tooling and never notes or state. Also use when deciding whether a piece of work should leave something executable behind.
-
serialexperimentslainnnn Skill Ruby StandardsUse when writing, reviewing or upgrading Ruby code and Rails applications - .rb/.rake/.gemspec/.erb files, Gemfile, Gemfile.lock, .ruby-version, Rakefile, config/application.rb, db/migrate, ActiveRecord models, Sidekiq or Solid Queue workers, RSpec spec/ or Minitest test/, .rubocop.yml, standardrb, Brakeman, bundler-audit, RBS sig/ or Sorbet sorbet/rbi, rbenv/mise/asdf Ruby toolchains, bundle exec, gem publishing to RubyGems, or Rails upgrades and YJIT/ZJIT tuning.
-
serialexperimentslainnnn Skill Jvm Spring StandardsJVM engineering standards for Java/Kotlin backends with Spring Boot. Triggers on Java, Kotlin, Spring Boot, Spring Security, Spring Data, JPA/Hibernate, Gradle, Maven, JUnit, Testcontainers, GraalVM, .java/.kt/.kts files, build.gradle.kts, pom.xml, application.yml.
-
serialexperimentslainnnn Skill Operating Systems StandardsOperating-system mechanics as an engineering constraint — what the kernel actually does to your program and which design decisions follow from it. Use when reasoning about CPU scheduling and latency (EEVDF versus the older CFS, sysctl_sched_base_slice, nice and sched_setscheduler, SCHED_FIFO/SCHED_RR/SCHED_DEADLINE via chrt, isolcpus and CPU pinning with taskset, sched_ext BPF schedulers, PREEMPT_RT and preempt=none/voluntary/full, interrupt latency and threaded IRQs, cyclictest), the real cost of a system call and a context switch (vDSO, KPTI and speculative-execution mitigation overhead, syscall batching), virtual memory (page faults, TLB misses, transparent huge pages and MADV_HUGEPAGE versus hugetlbfs, vm.overcommit_memory and Committed_AS, the OOM killer and oom_score_adj, memory.high versus memory.max in cgroup v2, PSI pressure metrics, swappiness and zram/zswap), I/O models (blocking versus O_NONBLOCK, select/poll/epoll, io_uring and its security history, O_DIRECT, readahead, page cache and dirty write
-
serialexperimentslainnnn Skill Physical Security StandardsPhysical security as it applies to IT assets — the controls that matter once someone can touch the hardware. Use when designing or auditing badge and biometric access control with antipassback and escort rules, handling tailgating as the failure that actually happens, managing master keys and key custody, specifying CCTV coverage, retention and its legal basis as personal data, intrusion detection and alarm response, deciding who else can reach your cage or your neighbours' racks in a colocation facility, sanitizing or destroying storage media under NIST SP 800-88 Clear/Purge/Destroy with degaussing, cryptographic erase or shredding, demanding and checking a certificate of destruction with serial numbers, responding to a lost or stolen laptop, phone or backup tape, closing off exposed USB ports, serial consoles, debug headers and live network sockets in meeting rooms and shared areas with 802.1X as a compensating control, governing visitors, cleaners, contractors and maintenance technicians, defending against
-
serialexperimentslainnnn Skill Appsec StandardsApplication security methodology. Use when threat modeling (STRIDE, abuse cases), reviewing code against OWASP Top 10 or ASVS, triaging IDOR/BOLA, SSRF, XSS, SQLi, SSTI, XXE, CSRF, CSP, deserialization or path traversal findings, or selecting SAST/DAST/SCA tools.
-
serialexperimentslainnnn Skill Offensive Security StandardsUse when scoping or running an authorized offensive engagement — Rules of Engagement and scoping documents, penetration test, red team, purple team or adversary emulation with MITRE ATT&CK, Caldera or Atomic Red Team, PTES / OSSTMM / NIST SP 800-115 / OWASP WSTG / MASTG methodology, DORA TLPT and TIBER-EU exercises, PCI DSS 11.4 testing, bug bounty and VDP safe harbor, deconfliction with the SOC, or writing the engagement report, evidence chain, severity rating and retest.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include discord-bot-development, substack-humanizer, maintain-verification-skill. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.