Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
c1trusovo831 Bundle Teleop Hil ReviewAudit teleoperation HIL or physical-safety evidence as an identified Herdr Planner or Reviewer; inspection only.
-
c1trusovo831 Bundle Scientific WritingDraft, revise, or audit scientific manuscripts and reports with traceable evidence. Use for manuscript prose, references, declarations, displays, reporting coverage, or submission preparation.
-
librefang Skill Security AuditSecurity audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology
-
mmacy Skill SessionSave, resume, and audit an osrlib-referee game — enumerate saved games, resume one with a recap, save at a pause with an optional human-readable journal, and inspect the engine's roll/command log. Use when the player wants to continue a saved game, save the current one, or see the roll-log / audit trail.
-
prompthon-io Bundle Crm OperationsResolve and safely create/update demo CRM contacts, deals, activity notes and follow-up tasks with revision checks and an atomic audit trail. Use for business-object operations; do not clean spreadsheets, analyze business performance or send customer messages.
-
hideki5123 Bundle Orch QASenior QA/QC engineer that evaluates existing codebases for test quality. Runs existing tests, diagnoses failures, identifies missing test coverage, and writes missing tests. Framework-agnostic — works with any language and test runner. Use when the user asks to run tests, diagnose failures, do test gap analysis, QA, quality assurance, test coverage analysis, find missing tests, test audit, quality check, quality report, fix failing tests, evaluate test quality, or assess test health of a codebase. Trigger phrases include "run tests", "QA", "quality assurance", "test audit", "test coverage", "missing tests", "gap analysis", "quality report", "fix failing tests", "diagnose test failures", "quality check", "evaluate test quality", "test health".
-
denizaslan36 Skill Verification GateAudit whether completed work actually supports its success claims. Use before saying a change is complete, fixed, passing, compliant, or ready when those claims can be checked. Do not use for early exploration, ideation, or requests that only ask for a plan.
-
danmackenz Skill Ghostspend FixWalks the user through remediating findings from a GhostSpend audit one at a time, proposing a concrete fix per finding and executing nothing without showing the exact command and receiving explicit approval. Use after ghostspend-audit has produced findings, or when the user asks to fix, remediate, or clean up issues GhostSpend reported.
-
danmackenz Skill Ghostspend SetupFirst-run configuration for GhostSpend — installs/verifies ccusage, records which AI CLI tools the user actually uses on purpose, and stores project scan directories. Use this before the first ghostspend-audit run, or when the user wants to reconfigure known tools or scan paths.
-
sergekostenchuk Bundle Admin UI OrchestratorUse when a project needs admin/CMS/back-office UI architecture: roles, permissions, content workflows, AI assistant boundaries, audit logs, destructive-action confirmations, and builder handoff. Planning only; do not perform production admin actions or expose secrets.
-
hideki5123 Bundle Dotnet SeniorSenior-level .NET development guidance for architecture, code review, scaffolding, EF Core, ASP.NET Core, Blazor, and MAUI targeting .NET 8 and .NET 10. Provides opinionated best practices, modern C# idioms, security hardening, performance optimization, and testing strategies at a staff/senior engineer level. Trigger patterns (match any variation): .NET / dotnet / dot net / .net / C# / csharp / c sharp / c-sharp / ASP.NET / aspnet / asp.net core / Entity Framework / EF Core / ef core / Blazor / MAUI / maui / NuGet / nuget / Clean Architecture + .NET / CQRS + .NET / DDD + .NET / {review, scaffold, create, design, architect, optimize, migrate} + {C#, .NET, dotnet, csharp} / "dotnet new" / "dotnet build" / "dotnet test" / "dotnet publish" / ".NET best practices" / "C# patterns" / "senior .NET" / ".NET architecture"
-
andreysukhanov Skill Code ReviewReview a diff or code change for bugs, security issues and risky patterns. Use when the user asks to review, audit or check changes - not when they ask for a commit message.
-
sergekostenchuk Bundle Ssl And Security HardenerUse when planning SSL/TLS, HTTPS redirects, HSTS, security headers, CSP, cookie flags, backups, monitoring, and basic launch hardening. Dry-run first; do not mutate production server, DNS, certificates, or secrets without explicit approval.
-
sergekostenchuk Bundle Server SelectorUse when choosing hosting/server architecture for a site or app: static hosting, VPS, PaaS, CDN, region, cost assumptions, scaling, security, and ops tradeoffs. Advisory only; do not provision servers or create paid resources without explicit approval.
-
romannekrasovaillm Bundle Tui Trace AuditРасследовать подозрительные действия TUI-агента по локальным трейс-файлам: отличить цитату и намерение от попытки и эффекта, проверить обход ограничений, инъекции и недостоверные отчёты.
-
aiblueprinthq Bundle AuditAudit current changes, a path, or the full project for quality, security, performance, or test problems and record durable findings. Independent mode prepares or completes a fresh-reviewer checkpoint handoff. Use for /audit, independent review, security review, code quality review, dead code, duplication, or standards drift.
-
laabidi-ahmed-ai Skill Code Review MentorA teaching-focused code reviewer for ML/MLOps code (FastAPI endpoints, training scripts, data pipelines, Dockerfiles, configs). Restates what the code does, reports findings ranked by severity (correctness → security → MLOps best practices → style) each with the reasoning and a fix, and adds an interview angle. ONLY trigger on explicit invocation by name — e.g. "code review mentor: <code>", "use code review mentor", or "/code-review-mentor". Do NOT activate for code pasted in normal conversation unless the user names this skill.
-
shiaoming123 Bundle Readme SkillsCreate, audit, optimize, restructure, translate, or release-sync repository README files by inspecting actual project evidence and automatically matching the repository type, reader journey, maturity, and hosting constraints. Use when a project has no README, has an incomplete or outdated README, needs a professional rewrite, needs a repository-specific structure, or needs README visuals, badges, architecture diagrams, multilingual navigation, or release-aligned documentation. Do not use for personal GitHub profile READMEs or full documentation-site authoring unless explicitly requested.
-
farzammohammadi Bundle System Layer ExtractionDeep architectural investigation that extracts, documents, and maps every system in a codebase. Use this skill whenever the user asks to: extract layers, map systems, analyze architecture, investigate codebase structure, document system boundaries, create a system map, understand how systems relate, audit dependencies, assess isolation, or do any form of comprehensive architectural analysis. Also trigger when the user says things like 'I want to see all the layers', 'map out the systems', 'what are the moving parts', 'how is this structured', or 'give me the full picture of the architecture'. This is NOT for reviewing code quality or individual files — it's for understanding the full system topology.
-
longppai68-ai Bundle Fake Foreign Health Audit鉴别药品/保健品是否为"假洋货"(伪造洋品牌身份)。当用户给出商品链接、包装图片或品牌名,问"是不是假洋货""是不是真进口""XX国品牌是真的吗",或需要核验某"进口"保健品的产地、资质、宣称国本土在售情况时使用。覆盖加拿大 NPN/LNHPD、德国欧盟工商登记与健康宣称合规、美国 FDA/商标、澳洲 TGA、中国蓝帽子与 GACC 备案。
-
openadminos Bundle Entra App CredentialsUse when the user asks about Entra app registrations, service principals, client secrets, certificates, federated identity credentials, GitHub OIDC, secret-to-OIDC migration, bootstrap permissions, or credential rollback.
-
openadminos Bundle Conditional Access ReviewUse when the user asks to review existing Conditional Access, audit CA policies, find report-only policies, find enabled policies that lack MFA enforcement, or verify emergency-account exclusions.
-
modus-znz Skill No Vibe Feel AuditName rookie patterns in code and PRs: file:line + seasoned fix, severity-ranked. Load with no-vibe-feel for any code review.
-
jtaroreh Skill Maintain Verification SkillPeriodic pass that keeps a project's verification skill and feature map honest: parallel source readers per feature, one live session driving every feature, at most one PR of proven corrections. Use for /maintain-verification-skill or "audit the verify skill".
-
farzammohammadi Bundle Review PrFind bugs in branch changes — races, logic errors, security holes, contract mismatches. Use when user wants to review a PR or branch.
-
presidenteog Skill UI UX Pro MaxSenior UX audit across 5 layers — first impression, task flows, visual consistency, trust signals, and business alignment
-
openadminos Bundle Posture ScriptUse when the user wants a complete script to check, audit, report, harden, export, or remediate Microsoft 365, Intune, Entra, or Graph posture offline.
-
presidenteog Skill Influence PsychologyUse when copy or a UX flow isn't converting and needs a persuasion audit — missing social proof, no clear authority signal, no reciprocity or scarcity, or urgency that reads as manufactured rather than genuine.
-
aaryan1524 Bundle Brooks AuditArchitecture audit that maps module dependencies, checks layering integrity, and flags structural decay across a codebase, drawing on twelve classic engineering books. Triggers when: user asks to audit architecture, review folder/module structure, check for circular imports, understand how the codebase is organized, or asks "does this follow clean architecture?" or "why does everything depend on everything?". Also triggers for onboarding requests: "explain this codebase to a new developer" or "give me a codebase tour" (use onboarding mode). Do NOT trigger for: PR-level code review (use brooks-review) or line-level refactoring questions — this skill analyzes structural/module-level concerns, not individual functions.
-
riclyme Bundle Stata Research AssuranceBuild, audit, reproduce, and validate Stata 19 empirical-research pipelines. Use when the user asks to freeze an econometric design, generate modular do-files, inspect Stata code/logs/data, reconcile changing results, check merges, sample attrition, variable timing, fixed effects, clustering, lags, or validate AI/ML-generated covariates and matching labels. Do not use for a one-line Stata syntax question unless the user requests the full assurance workflow.
-
alphasafal Bundle Feature To ProductionGuides a software feature from a clarified requirement through implementation to production readiness: acceptance criteria, repository understanding, smallest-viable design, tests, implementation, verification, review, security/performance checks, documentation, and a deployment/ rollback plan. Use when asked to build/ship a feature end to end, not just write a snippet. Do not use for a one-line fix (use debugging-investigator if it's a bug) or when the requirement itself is still vague (use product-manager first to scope it).
-
alphasafal Bundle Production Code ReviewPerforms structured, senior-level review of a code change (diff or PR) across correctness, security, reliability, error handling, concurrency, performance, data integrity, API contracts, maintainability, observability, tests, and backward compatibility. Ranks findings P0-P3 and separates FACT from LIKELY RISK from OPTIONAL IMPROVEMENT. Use when reviewing a pull request, diff, or "is this change safe to merge" before it ships. Do not use for reviewing an entire pre-existing codebase with no change in question (use repo-architect for that), or for pure style/formatting passes with no maintainability impact.
-
reaperinvest Skill Time AuditAnalyzes time allocation across activities and recommends optimization strategies with categorization, value scoring, and reallocation plans. Use when a freelancer or solopreneur feels busy but unproductive, wants to find where their time goes, needs to free up hours for higher-value work, or suspects they are spending too much time on low-impact tasks.
-
reaperinvest Skill Social Media AuditConducts a structured social media presence audit across platforms with profile optimization checks, content analysis, engagement assessment, and actionable improvement recommendations. Use when a user wants to evaluate their social media performance, needs to identify what's working and what's not, or is preparing a social media strategy refresh.
-
reaperinvest Skill Tool Stack AuditAudits business technology stacks for redundancy, cost optimization, and integration opportunities. Use when reviewing and optimizing your business software spend.
-
reaperinvest Skill Compliance ChecklistCreates industry-specific regulatory compliance checklists with documentation requirements and audit preparation. Use when ensuring your business meets regulatory obligations.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include teleop-hil-review, scientific-writing, security-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.