Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
serialexperimentslainnnn Skill Cms Jamstack StandardsUse when deciding where content lives and who edits it - choosing between Markdown/MDX files in the repo, a git-based CMS (Decap admin/config.yml, TinaCMS), self-hosted open-source headless (Strapi, Directus, Payload, Keystone), paid SaaS headless (Contentful, Sanity, Storyblok, Prismic, Hygraph) or a coupled CMS (WordPress wp-config.php and plugins, Drupal), content modeling with content types, fields, references, localization and schema migration, sanity.config.ts or contentful space migration scripts, content collections and frontmatter schemas, draft and preview modes, publish webhooks and on-demand revalidation or cache purge after publish, stale content after a publish, image CDNs and per-transformation billing (Cloudinary credits, Cloudflare Images, imgix), free-plan API-call quotas and what breaks when you exceed them, editor accounts roles and MFA, plugin supply chain, stored XSS from a rich-text editor, exposing the content API, webhook signature verification, or exporting content out of a CMS befor
-
serialexperimentslainnnn Skill File Servers StandardsClassic file-sharing servers — the protocol that exposes a directory tree to other machines, and its blast radius. Use when working with Samba (smb.conf, testparm, smbcontrol, smbstatus, smbd/nmbd/winbindd, net ads join, net usershare, "server min protocol", "server smb encrypt", "vfs objects", vfs_shadow_copy2, vfs_full_audit, vfs_worm, vfs_recycle, vfs_acl_xattr, vfs_fruit, idmap config, wbinfo, pdbedit, "valid users", "force group", "veto files", msdfs root and msdfs proxy), ksmbd (ksmbd.conf, ksmbd.mountd, ksmbd.addshare) and whether an in-kernel SMB server belongs in production, NFS exports (/etc/exports, exports.d, exportfs -ra, /var/lib/nfs/etab, rpc.mountd, rpc.gssd, nfsdcltrack, nfs.conf, fsid=0 and the v4 pseudo-root, no_root_squash, all_squash, anonuid/anongid, subtree_check, sec=sys/krb5/krb5i/krb5p, nfsvers=3 vs 4.1 vs 4.2, nconnect, xprtsec=tls and xprtsec=mtls, tlshd and ktls-utils per RFC 9289), POSIX ACLs versus NT ACLs (getfacl/setfacl, acl_xattr, security.NTACL), project or user quotas on a
-
serialexperimentslainnnn Skill AI Governance StandardsUse when an organization must account for the AI it uses — building an AI system inventory and surfacing shadow AI, classifying systems into the EU AI Act tiers (prohibited practices, high-risk Annex I and Annex III, Article 50 transparency, minimal), deciding whether you are provider or deployer under Article 25 and when fine-tuning or repurposing turns you into a provider, GPAI duties under Articles 53-55 and the Code of Practice, the Regulation (EU) 2026/1744 Digital Omnibus dates, an internal acceptable-use policy and use-case approval process that does not drive staff into shadow AI, the Article 27 fundamental rights impact assessment and how it complements a DPIA, meaningful human oversight versus automation bias, synthetic content marking and disclosure, AI vendor due diligence (training on your data, retention, subprocessors, audit rights, exit), Article 73 serious incident reporting, an ISO/IEC 42001 AI management system with ISO/IEC 42005 and 42006, NIST AI RMF as a governance framework, AESIA and n
-
serialexperimentslainnnn Skill Email Security StandardsEmail as an attack surface and the DNS records that defend it. Use when publishing or auditing SPF (v=spf1, the 10 DNS-lookup limit, +all, chained include, ~all vs -all), DKIM selectors, key length and rotation (selector._domainkey, rsa-sha256, ed25519-sha256), DMARC (_dmarc TXT, p=none/quarantine/reject, sp, np, t, adkim/aspf alignment, rua/ruf, the DMARCbis tree walk and the removal of pct), aggregate and failure report parsing, ARC and mailing-list or forwarding breakage, Authentication-Results headers, MTA-STS (_mta-sts TXT and .well-known/mta-sts.txt), TLS-RPT (_smtp._tls), DANE TLSA for SMTP with DNSSEC, BIMI (default._bimi, VMC/CMC, Mark Verifying Authority), third-party sending providers and the inventory of who sends on your behalf, Gmail/Yahoo/Outlook bulk-sender requirements and one-click unsubscribe (List-Unsubscribe-Post), inbound filtering, attachment and URL isolation, business email compromise and out-of-band payment verification, phishing simulations, or the reported-phish mailbox.
-
serialexperimentslainnnn Skill Grc Compliance StandardsGovernance, risk and compliance standards. Use when working with ISO 27001/27002/27005/27701, NIST CSF 2.0, CIS Controls v8.1, SOC 2, NIS2, DORA, ENS/CCN-STIC, Statement of Applicability, risk registers, control-to-evidence mapping, OSCAL, audit preparation, vendor questionnaires (SIG, CAIQ), or the regulatory notification clock after a breach — who must be told, within how many hours, and what evidence the filing needs.
-
serialexperimentslainnnn Skill Identity Threat Detection StandardsITDR — detecting and responding to attacks against identity itself, which is where the perimeter actually is. Use when investigating or defending against password spraying, adversary-in-the-middle session-cookie theft and token replay that survives MFA, refresh-token and primary-refresh-token abuse, MFA fatigue and push bombing, consent phishing and malicious OAuth application grants, device-code-flow phishing, SIM swapping, forged federation assertions (Golden SAML, stolen token-signing certificate, cross-tenant trust abuse), credentials or certificates silently added to an existing application or service principal, illicit device registration, hybrid identity attack paths through directory synchronization and authentication agents in both directions, deciding which identity telemetry you actually retain and what your licence tier silently drops, writing high-value identity detections and their triage, and identity-specific containment where revoking sessions, refresh tokens and consents matters far more tha
-
akayashuu Bundle Audit FrAudit web France
-
ontology-of-everything Bundle Concept Audit 2Audits concept and application design arguments and optional code conformance only when the user explicitly invokes $concept-audit. Read-only; use for purpose fitness, independence, composition, drift, and product-subset review.
-
ontology-of-everything Bundle Concept Audit CnAudits concept-design-cn arguments and optional code conformance only when the user explicitly invokes $concept-audit-cn. / 仅在用户显式调用 $concept-audit-cn 时审查概念设计及实现符合性。
-
vaibtan Bundle Maintain Verification SkillPeriodic pass that keeps a project's verification skill and feature map honest: parallel source readers per feature, one live session driving every feature, at most one PR of proven corrections. Use for $maintain-verification-skill or "audit the verify skill".
-
tomtommyyuan Bundle Sde ReviewReview a diff or a pull request the way a senior engineer would — verified, severity-rated findings (blocker / should-fix / nit), each anchored to file:line with a concrete fix, across correctness, security, tests, ML and data pitfalls, and the repo's own conventions. Use to self-review the current branch before opening a PR (fixes are applied and committed), or to review someone else's PR by number or URL and post the review on GitHub.
-
ono-sendai-labs Bundle Code Task ReviewReview jj changes produced by `task-to-code`. Supports initial reviews and re-reviews — a re-review is a fresh invocation that reads the prior review from disk and validates that its findings were addressed in the new change. Verifies acceptance-criteria coverage, test integrity (incl. detection of deleted/weakened tests), code style and LSP cleanliness on touched files, and security. Produces a structured YAML report that an orchestrator can use to route remediation back to the implementer.
-
xjli360 Bundle Sealeap Tianlu Amazon Cross Domain Tax Compliance Self AuditAudit a cross-border seller's tax-compliance exposure across platform data-reporting reconciliation, taxpayer classification, cost-voucher completeness, multi-store/entity reporting consistency, and offshore-entity exposure, producing a risk checklist for professional review. Does not calculate tax owed or issue a compliance conclusion. Use for 平台数据报送后自查、多店铺主体一致性排查、成本票缺口整理、境外主体合规暴露评估. Do not use to file taxes directly or to replace a qualified tax advisor's determination.
-
product-llc Skill UX AuditProduce the findings pass of a UX audit — inventory a product's codebase, walk its real flows in a browser, and write an evidence-backed findings list that says what was measured and what was observed. Use when someone asks for a UX audit, a heuristic review, a design-system check, or "what's wrong with this product". It delivers findings, not priorities.
-
faroxdev Skill Vault ReviewAudit the health and consistency of a long-term Markdown Vault. Use to find duplicate, stale, conflicting, misplaced, verbose, orphaned, or poorly linked knowledge before broad maintenance.
-
rmazrim Skill Monorepo Package CleanerAudit a monorepo workspace for dependency cycles, mismatched shared versions, and cross-boundary imports, then emit a prioritized cleanup plan.
-
rmazrim Skill Cors Csp Headers HardenerInspects HTTP response headers on local web servers and injects defensive security headers to prevent clickjacking, cross-site scripting, and unauthorized domain access.
-
professor-gpt Bundle Code ReviewerExpert code reviewer that analyzes your code for bugs, security vulnerabilities, performance bottlenecks, and style issues.
-
rmazrim Skill Middleware Order ValidatorAudit middleware registration order in Express/FastAPI apps against safety rules — auth before authz, rate-limit before routes, error handlers last — and emit fixes.
-
rmazrim Skill Sqli Xss Payload SanitizerIdentifies unescaped user inputs and unparameterized database queries, injecting sanitization middleware and parameterized bindings to neutralize XSS and SQLi.
-
professor-gpt Bundle Security AuditorComprehensive security review specialist covering OWASP Top 10, authentication flaws, injection attacks, secrets exposure, and infrastructure misconfigurations.
-
rmazrim Skill Owasp Sast Security AuditorAudits local web application source code for OWASP Top 10 vulnerabilities, generating security report logs and applying immediate automated code fixes.
-
rmazrim Skill JWT Security Algorithm Cracker TesterEvaluates JSON Web Token handling on local API routes to identify token forgery, algorithm confusion, and weak signature secrets.
-
rmazrim Skill Owasp Vulnerability CheckerAudit API endpoints for common security vulnerabilities (XSS, SQLi, CSRF).
-
rmazrim Skill Security Suite OrchestratorOrchestrates a full 8-stage security audit chain over a local web app: dependency CVE scan, OWASP SAST static audit, SQLi/XSS input sanitization, JWT security cracking, BOLA/IDOR authorization scan, rate-limit brute-force shielding, and CORS/CSP header hardening, then consolidates every per-stage report into one SECURITY_AUDIT_REPORT.md. Supports full_run, include_steps, skip_steps, fail_fast, and report_dir customization so operators can re-run a subset of the chain without touching the others. Aggregates severity counts per category, per-stage pass/fail status, and a top-remediation ranked list from all seven stage artifacts.
-
rmazrim Skill Dependency Cve Audit PatcherAudits third-party open-source packages for known vulnerabilities (CVEs), evaluating breaking change risks and generating automated patch updates.
-
rmazrim Skill Error Code Consistency AuditorAudit every error class, message, and HTTP mapping across the codebase for duplication, contradictory status codes, and undocumented errors.
-
shivani26singh Skill Pw Suite AuditorAudits an existing Playwright suite — JavaScript or TypeScript — against the pack's best practices and produces a prioritized migration plan that names which specialized skill (pw-locator-fixer, pw-page-object-builder, pw-fixture-designer, pw-flaky-debugger, pw-api-tester, pw-network-mocker, pw-visual-regression, pw-ci-configurator, pw-test-health-reporter) to run on which file. Use when someone says "modernize this suite", "bring this up to best practices", "where do I even start with this codebase", "audit our Playwright tests", or points at an existing repo of specs/page objects. Makes no code changes itself — it is a router, not a fixer.
-
rmazrim Skill Playwright E2e Security Flow TesterCrafts automated End-to-End (E2E) browser testing suites validating critical user journeys, edge cases, and client-side security boundary enforcement.
-
jawahars07 Skill Security VetMandatory pre-install security vetting of any third-party skill, plugin, npm or pip package, editor extension, or cloned repo - reconnaissance, static scan, written verdict of SAFE / SAFE WITH CAVEATS / HOLD, explicit user approval, then a defensive install proportionate to the risk. Use BEFORE installing anything you did not write.
-
jawahars07 Skill Github PublishTake a local project public safely - sweep for secrets including the full git history, harden real weaknesses like plaintext credentials, strip copyrighted and bloat files, write a README from verified claims only, and enable repo security features. Use when asked to publish, open-source, or push a project to GitHub.
-
kiterunner1 Bundle Plugin Audit安装第三方 DSH(DeepSeek Harness)插件之前做静态安全审计:扫出动态求值、patch 层 !!js、安装期脚本、开机自启、凭据复制、出网域名、子进程与提示词注入面,给出硬否决项与能力清单。用户要装/试装插件、或问「这个插件安全吗」「它会联网吗」时使用。Audit a third-party DSH plugin before installing it.
-
steffencarlsen Skill Ponytail AuditWhole-repo audit for over-engineering. Like ponytail-review, but scans the entire codebase instead of a diff: a ranked list of what to delete, simplify, or replace with stdlib/native equivalents. Use when the user says "audit this codebase", "audit for over-engineering", "what can I delete from this repo", "find bloat", "ponytail-audit", or "/ponytail-audit". One-shot report, does not apply fixes.
-
steffencarlsen Skill Test Anti PatternsAudits existing .NET test code (MSTest, xUnit, NUnit, TUnit) for anti-patterns and quality issues that undermine reliability and diagnostic value — produces a severity-ranked report (Critical / Warning / Info) with concrete code-level fixes and acknowledgement of what the tests do well. INVOKE THIS SKILL when the user asks to audit, review, rank, or find problems in existing tests — including prompts about: "audit my tests", "audit for .NET test anti-patterns", "test smell audit", "rank by severity", "are these tests good", tests that pass but verify nothing, no/missing assertions, swallowed exceptions, always-true / self-comparing / self-referential / tautological assertions, broad exception types, flakiness (Thread.Sleep, DateTime.Now), ordering dependency, shared static state, reflection coupling, duplicated tests, magic values, coverage touching, coverage inflation. DO NOT USE FOR: writing new tests (use writing-mstest-tests); running tests (use run-tests); framework migration (use migration skills).
-
steffencarlsen Bundle Test Smell DetectionDeep-dive audit using the full testsmells.org 19-smell academic catalog for .NET tests. Every finding maps to a named, citable smell from the research literature (Assertion Roulette, Duplicate Assert, Constructor Initialization, Default Test, Mystery Guest, Eager Test, Sensitive Equality, Conditional Test Logic, Sleepy Test, Magic Number Test, etc.) with research-backed severity and integration-test calibration. Works with MSTest, xUnit, NUnit, TUnit. INVOKE THIS SKILL ONLY when the user explicitly asks for the testsmells.org / 19-smell academic catalog, a research-backed smell taxonomy audit, citable smell names from the literature, or a catalog deep-dive beyond pragmatic anti-patterns. DO NOT USE FOR: any general or pragmatic test audit — "audit my tests", "do a smell audit", "review test quality", severity-ranked anti-pattern reviews — use test-anti-patterns (the umbrella audit skill); writing new tests (use writing-mstest-tests); running tests (use run-tests); framework migration (use migration skills).
-
steffencarlsen Bundle Code ReviewReviews code changes using CodeRabbit AI. Use when user asks for code review, PR feedback, code quality checks, security issues, or requests fix-review cycles.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include cms-jamstack-standards, file-servers-standards, ai-governance-standards. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.