Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
reaperinvest Skill Sales Funnel BuilderMaps complete sales funnels with stages, conversion points, content, and optimization opportunities. Use when you need to design or audit your customer acquisition path.
-
reaperinvest Skill Data Processing AgreementDrafts data processing agreements for GDPR compliance with processing details and security measures. Use when you process personal data on behalf of another business.
-
reaperinvest Skill Process Automation AuditIdentifies automation opportunities in business processes with tool recommendations, ROI estimates, and implementation priority rankings.
-
reaperinvest Skill Intellectual Property AuditAudits IP assets with trademark, copyright, trade secret, and patent inventory and protection recommendations. Use when assessing and organizing your business IP portfolio.
-
talhamah56 Skill Writing GuidelinesReview docs/prose for Writing Guidelines compliance. Use when asked to "review my docs", "check writing style", "audit prose", "review docs voice and tone", or "check this page against the writing handbook".
-
7kim Bundle System Analysis And DesignGenerate a complete, academic-grade System Requirements Specification (SRS) and system-design document from a project idea, AND evaluate an existing codebase against computer science principles using strict evidence-based benchmarking. Use this skill whenever the user asks for an SRS, software requirements document, system design document, UML diagrams, code audit, code benchmark, quality grading, SWOT analysis of a software project, or anything resembling "design this system for me," "write an SRS," "audit this codebase," "benchmark the code," "grade the project," or "run the benchmark." Also triggers on "coding principles," "strict audit," "gaps report," "gaps kanban," "implementation plan," and "SWOT benchmark" in the context of evaluating code quality.
-
maybackcompany Skill Devex ReviewLive developer experience audit. Uses the browse tool to actually TEST the developer experience: navigates docs, tries the getting started flow, times TTHW, screenshots error messages, evaluates CLI help text. Produces a DX scorecard with evidence. Compares against /plan-devex-review scores if they exist (the boomerang: plan said 3 minutes, reality says 8). Use when asked to "test the DX", "DX audit", "developer experience test", or "try the onboarding". Proactively suggest after shipping a developer-facing feature. (gstack) Voice triggers (speech-to-text aliases): "dx audit", "test the developer experience", "try the onboarding", "developer experience test".
-
talhamah56 Skill Citation AuditZero-context verification that every bibliographic entry in the paper is real, correctly attributed, and used in a context the cited paper actually supports — catching hallucinated authors, wrong years, fabricated venues, version mismatches, and wrong-context citations. Use when user says "审查引用", "check citations", "citation audit", "verify references", "引用核对", or before submission to ensure bibliography integrity.
-
talhamah56 Skill Paper Claim AuditZero-context verification that every number, comparison, and scope claim in the paper matches raw result files. Uses a fresh self-review pass — Claude re-reads the paper and raw results with none of its drafting/experiment context — to reduce (not eliminate) confirmation bias. Use when user says "审查论文数据", "check paper claims", "verify numbers", "论文数字核对", or before submission to ensure paper-to-evidence fidelity.
-
maybackcompany Bundle Plan Devex ReviewInteractive developer experience plan review. Explores developer personas, benchmarks against competitors, designs magical moments, and traces friction points before scoring. Three modes: DX EXPANSION (competitive advantage), DX POLISH (bulletproof every touchpoint), DX TRIAGE (critical gaps only). Use when asked to "DX review", "developer experience audit", "devex review", or "API design review". Proactively suggest when the user has a plan for developer-facing products (APIs, CLIs, SDKs, libraries, platforms, docs). (gstack) Voice triggers (speech-to-text aliases): "dx review", "developer experience review", "devex review", "devex audit", "API design review", "onboarding review".
-
roche-k Bundle Va Wordpress MasterUse when you need to architect, optimize, or troubleshoot WordPress implementations ranging from custom theme/plugin development to enterprise-scale multisite platforms. Use this skill for performance optimization, security hardening, headless WordPress APIs, WooCommerce solutions, and scaling WordPress to handle millions of visitors.
-
roche-k Bundle Va AI Writing AuditorUse when you need to audit content for AI writing patterns and rewrite text to remove them.
-
roche-k Bundle Va Dependency ManagerUse when you need to audit dependencies for vulnerabilities, resolve version conflicts, optimize bundle sizes, or implement automated dependency updates.
-
roche-k Bundle Va Incident ResponderUse when an active security breach, service outage, or operational incident requires immediate response, evidence preservation, and coordinated recovery.
-
roche-k Bundle Va Penetration TesterUse when you need to conduct authorized security penetration tests to identify real vulnerabilities through active exploitation and validation. Use penetration-tester for offensive security testing, vulnerability exploitation, and hands-on risk demonstration.
-
roche-k Bundle Va Security AuditorUse when conducting comprehensive security audits, compliance assessments, or risk evaluations across systems, infrastructure, and processes. Invoke when you need systematic vulnerability analysis, compliance gap identification, or evidence-based security findings.
-
hassancs91 Skill Suggest Sfx 2The SFX pass. Analyze a short's beats + narration and propose tasteful sound effects synced to them, drawing from (and growing) a shared, reusable SFX library, then render an SFX-mixed audition preview. Use when the user wants to "add SFX / sound effects", "suggest sfx", "score the transitions", "sound-design this beat", generate/source sound effects, build or extend the sfx library/catalog, author or audit a sfx-plan, or mix SFX over a rendered short in this repo. Covers reading beats + word times + brand §7, the library-first flow, generating misses with the ElevenLabs Sound Effects API, the per-video sfx-plan.json, the hard user-audit gate, and mixing with tools/mix_sfx.py (light voice ducking).
-
kklimuk Skill Security Review 3Review code for security vulnerabilities. Use when the user says 'security review', 'security audit', 'check for vulnerabilities', 'pentest the code', 'OWASP check', or any variation of wanting a security assessment.
-
ctaxnagomi Bundle Security AuditorSecurity auditing and vulnerability assessment.
-
ctaxnagomi Bundle Post Tool Audit Log HookAudit logging for AI tool usage.
-
itsual Skill API SecuritySecure APIs — authentication, authorization, input validation, rate limiting, and inventory of exposed endpoints. Use when designing, reviewing, or testing API-heavy applications and integrations.
-
itsual Skill Financial ControlsDesign and operate financial controls that protect assets, ensure accurate reporting, and reduce fraud and error risk. Use when strengthening internal controls, preparing for audit, or scaling finance operations.
-
just1cup Bundle Secure API 2Enforce security and performance best practices whenever Codex writes, reviews, or designs code that touches APIs as a client consuming external APIs (REST, WebSocket, GraphQL) or as a server exposing endpoints. Trigger on ANY of the following: - Writing API client code (fetch, reqwest, axios, httpx, or any HTTP lib) - Writing or reviewing API route/handler code - Integrating with external services (VirusTotal, AbuseIPDB, Shodan, Stripe, etc.) - Storing or transmitting API keys, tokens, or secrets - Designing request/response payloads, pagination, or caching strategies - Reviewing code that makes HTTP requests or exposes HTTP endpoints - Phrases: "call the API", "integrate with", "API key", "rate limit", "auth token", "fetch data from", "send request", "endpoint", "REST", "WebSocket", "cache the response", "retry logic", "timeout", "bearer token", "secret", "credentials" Apply to Rust, TypeScript/JavaScript, Python, Go, and shell scripts. When in doubt, apply.
-
comsky Bundle Change Reaudit 2Re-audit code changes to identify side effects, regression risks, and unhandled edge cases before merging or deploying. Use after a change is complete and before merging to a shared branch, before deploying a hotfix, after complex multi-module refactoring, or when a previous review may have missed side effects in async, state-mutating, or security-sensitive code paths.
-
diegosouzapw Bundle Pci Compliance 3PCI Compliance workflow skill. Use this skill when the user needs Master PCI DSS (Payment Card Industry Data Security Standard) compliance for secure payment processing and handling of cardholder data and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Security Audit 5Security Auditing Workflow Bundle workflow skill. Use this skill when the user needs Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
shakacode Bundle Docs 2Generate, audit, or update project documentation to a professional open-source standard. Use this skill whenever the user mentions docs, documentation, README, API reference, guides, migration guides, troubleshooting, llms.txt, doc audit, or wants to improve any written developer-facing content in a repository. Also trigger when the user says things like "document this", "write docs for", "update the docs", "our docs need work", or compares documentation quality to other projects. Covers Ruby (YARD), TypeScript (TSDoc/JSDoc), Markdown guides, configuration references, and doc site structure.
-
diegocconsolini Bundle Plugin Security Checker 2Advanced security scanner for Claude Code plugins with 91 specialized pattern agents. Detects vulnerabilities, code obfuscation, and security anti-patterns across plugin manifests, agents, and scripts.
-
atulpurohit Skill Threat ModelerProfessional Threat Modeler Expert skill. Implement enterprise-grade web application security controls and encryption standards.
-
atulpurohit Skill Xss PreventionProfessional XSS Prevention Expert skill. Implement enterprise-grade web application security controls and encryption standards.
-
atulpurohit Skill AI Safety GuardProfessional Ai Safety Guard Expert skill. Implement enterprise-grade web application security controls and encryption standards.
-
atulpurohit Skill Csrf ProtectionProfessional CSRF Protection Expert skill. Implement enterprise-grade web application security controls and encryption standards.
-
diegosouzapw Bundle Security Auditor 5security-auditor workflow skill. Use this skill when the user needs Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle GRAPHQL Architect 4graphql-architect workflow skill. Use this skill when the user needs Master modern GraphQL with federation, performance optimization, and enterprise security. Build scalable schemas, implement advanced caching, and design real-time systems and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
infrasity-labs Skill Llms Txt Checker 2Audits any domain's AI-readiness by using curl to directly probe robots.txt, llms.txt, and llms-full.txt, then scores each file against a structured checklist and delivers a formatted report with pass/warn/fail findings and actionable fixes. Use this skill whenever a user provides a domain or URL and wants to know if llms.txt or llms-full.txt is available, discoverable, or properly structured. Trigger on phrases like "check llms.txt for", "does this site have llms.txt", "find llms.txt", "check llms for this url", "audit llms.txt", "is llms-full.txt available", or any time a user shares a domain/docs URL and wants AI-readiness checked. Also trigger when the user wants to verify GEO/AEO readiness of a documentation site.
-
atulpurohit Skill Mobile SecurityProfessional Mobile Security Expert skill. Implement enterprise-grade web application security controls and encryption standards.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include sales-funnel-builder, data-processing-agreement, process-automation-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.