Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
atulpurohit Skill Secrets ManagerProfessional Secrets Manager Expert skill. Implement enterprise-grade web application security controls and encryption standards.
-
atulpurohit Skill Secrets ScannerProfessional Secrets Scanner Expert skill. Implement enterprise-grade web application security controls and encryption standards.
-
atulpurohit Skill Security TesterProfessional Security Tester Expert skill. Implement robust test suites and automated quality checks for modern web/mobile applications.
-
abeck617 Skill Entity People SearchSearch for people/prospects directly from Onfire's LinkedIn people entity (ONFIRE.PEOPLE = entity `contact`) using the `ask_onfire` tool. Use when the user wants to find prospects by job title, company, location, seniority, persona/role, technology footprint, or keywords in their profile — phrases like "find engineers at Northwind", "who are the VPs of Security at banks in the US", "show me people with 'Loglytics' in their job summary", "look up this LinkedIn URL", or any people search that doesn't require Forschung's cross-database scoring.
-
skillmedev Skill Primary Research PlannerDesigns a rigorous primary research protocol for collecting new data - research question, hypotheses, method selection, sampling with a power analysis, instrument design, a named control for every bias threat, and a pre-specified analysis plan. Use when someone asks "design a study to test this", "how many respondents do I need", "should this be a survey or interviews", or must produce defensible first-hand evidence rather than cite existing work. Do NOT use for synthesizing already-published sources - use deep-research or literature-review instead; for writing the discussion guide for a single expert conversation, use expert-interview instead; for detailed survey question wording and scale design, use survey-designer instead.
-
skillmedev Skill UX Writing AuditAudits an existing corpus of product copy - buttons, labels, errors, empty states, toasts, tooltips - against clarity, consistency, voice, and actionability heuristics, and delivers a scored findings table with rewrites plus a reusable glossary. Use when someone asks "audit our product copy", "why does our UI text feel inconsistent", "review these error messages", "is it log in or sign in", or before a redesign or localization push. Do NOT use for writing new error messages from scratch - use error-message-writer instead; for first-run and activation flows, use onboarding-copy.
-
memoash Bundle Safe ReceiptUse for edits in repos where command risk, secret handling, or outbound actions need audit.
-
skillmedev Skill Error Message WriterRewrites error messages to be specific, actionable, and blame-free - what happened, why it helps to know, and what to do next - with tone calibrated to severity and developer-facing detail kept separate from the user-facing text. Use when someone asks "rewrite this error message", "our app just says something went wrong", "make this validation message less hostile", or is auditing error states before launch. Do NOT use for reviewing all in-product copy beyond errors - use ux-writing-audit instead; for the copy users see during first-run setup, use onboarding-copy.
-
daddia Skill Decision LogThis skill should be used when the user asks to "log this decision," "record why we decided X," or needs a decision and its rationale added to a persisted, append-only decision log for later audit or onboarding reference.
-
bestagentkits Bundle Red TeamUse when planning or executing authorized red team engagements, attack path analysis, or offensive security simulations. Covers MITRE ATT&CK kill-chain planning, technique scoring, choke point identification, OPSEC risk assessment, and crown jewel targeting.
-
bestagentkits Bundle Ra Qm SkillsRouter/index for the 15 regulatory & quality-management skills bundled in this plugin (ISO 13485 QMS, EU MDR 2017/745, FDA submissions under QMSR, ISO 14971 risk, CAPA, document control, ISO 27001/ISMS, ISO 42001 AIMS, EU AI Act, GDPR/DSGVO, SOC 2, auditing). Use when a compliance request doesn't obviously match one skill and you need to pick the right one (e.g., 'prepare us for an ISO 13485 audit', 'is my AI system high-risk under the AI Act').
-
bestagentkits Bundle Compliance OsCompliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across multiple frameworks. Four decisions: (1) Given a company profile, which of the 12 supported frameworks apply (ISO 27001/13485/42001/14971, EU AI Act, MDR 745, GDPR, SOC 2, FDA QSR, NIST CSF 2.0, NIS2, HIPAA)? (2) Across selected frameworks, which controls overlap and how much evidence reuses? (3) For a given framework + scope, what does a realistic mock audit produce — drawing from the 205-scenario library? (4) Across selected frameworks, what's the unified evidence checklist with reuse map? Use when standing up a multi-framework program, planning the annual audit calendar, or preparing for certification stage 1. Does NOT replace per-framework skills (it orchestrates them).
-
bestagentkits Bundle Aims AuditAims Audit
-
bestagentkits Bundle Senior BackendDesigns and implements backend systems including REST APIs, microservices, database architectures, authentication flows, and security hardening. Use when the user asks to "design REST APIs", "optimize database queries", "implement authentication", "build microservices", "review backend code", "set up GraphQL", "handle database migrations", or "load test APIs". Covers Node.js/Express/Fastify development, PostgreSQL optimization, API security, and backend architecture patterns.
-
bestagentkits Bundle Atlassian AdminAtlassian Administrator for managing and organizing Atlassian products (Jira, Confluence, Bitbucket, Trello), users, permissions, security, integrations, system configuration, and org-wide governance. Use when asked to add users to Jira, change Confluence permissions, configure access control, update admin settings, manage Atlassian groups, set up SSO, install marketplace apps, review security policies, or handle any org-wide Atlassian administration task.
-
bestagentkits Bundle Gdpr Audit PrepGdpr Audit Prep
-
bestagentkits Bundle ReviewReview Playwright tests for quality. Use when user says "review tests", "check test quality", "audit tests", "improve tests", "test code review", or "playwright best practices check".
-
bestagentkits Bundle Soc2 Audit PrepSoc2 Audit Prep
-
bestagentkits Bundle Soc2 ComplianceUse when the user asks to prepare for SOC 2 audits, map Trust Service Criteria, build control matrices, collect audit evidence, perform gap analysis, or assess SOC 2 Type I vs Type II readiness.
-
bestagentkits Bundle Pr Review ExpertUse when the user asks to review pull requests, analyze code changes, check for security issues in PRs, or assess code quality of diffs.
-
bestagentkits Bundle Qms Audit ExpertISO 13485 internal audit expertise for medical device QMS. Covers audit planning, execution, nonconformity classification, and CAPA verification. Use when planning internal audits, executing audits, classifying findings, preparing for external audits, or managing an audit program.
-
bestagentkits Bundle Threat DetectionUse when hunting for threats in an environment, analyzing IOCs, or detecting behavioral anomalies in telemetry. Covers hypothesis-driven threat hunting, IOC sweep generation, z-score anomaly detection, and MITRE ATT&CK-mapped signal prioritization.
-
bestagentkits Bundle Iso13485 Audit PrepIso13485 Audit Prep
-
bestagentkits Bundle Iso27001 Audit PrepIso27001 Audit Prep
-
bestagentkits Bundle Iso42001 SpecialistISO/IEC 42001:2023 AI Management System (AIMS) specialist for compliance teams running internal audits. Three decisions: (1) Where are the gaps against Clauses 4-10 and what do we close first? (2) What goes in the AI risk register and which Annex A controls treat each risk? (3) What's the 12-month internal audit plan that satisfies Clause 9.2? Use when preparing for certification, scoping internal audit cycles, or onboarding AI systems into an existing ISMS (27001) / QMS (13485) program. NOT an executive AI strategy skill (see chief-ai-officer-advisor). NOT EU AI Act compliance (see compliance-team-eu-ai-act).
-
bestagentkits Bundle Incident ResponseUse when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection. Covers SEV1-SEV4 classification, false positive filtering, incident taxonomy, and NIST SP 800-61 lifecycle.
-
bestagentkits Bundle Isms Audit ExpertInformation Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support. Use when the user mentions ISO 27001, ISMS audit, Annex A controls, Statement of Applicability (SOA), gap analysis, nonconformity management, internal audit, surveillance audit, or security certification preparation. Helps review control implementation evidence, document audit findings, classify nonconformities, generate risk-based audit plans, map controls to Annex A requirements, prepare Stage 1 and Stage 2 audit documentation, and support corrective action workflows.
-
bestagentkits Bundle Security Appsec EngineerUse when Codex should act as the Application Security Engineer specialist from Agency Agents. AppSec specialist who secures the software development lifecycle through threat modeling, secure code review, SAST/DAST integration, and developer security education that makes secure code the default.
-
bestagentkits Bundle Security Compliance AuditorUse when Codex should act as the Compliance Auditor specialist from Agency Agents. Expert technical compliance auditor specializing in SOC 2, ISO 27001, HIPAA, and PCI-DSS audits — from readiness assessment through evidence collection to certification.
-
bestagentkits Bundle Security Incident ResponderUse when Codex should act as the Incident Responder specialist from Agency Agents. Digital forensics and incident response specialist who leads breach investigations, contains active threats, coordinates crisis response, and writes post-mortems that prevent recurrence.
-
bestagentkits Bundle Google Workspace CLIGoogle Workspace administration via the gws CLI (github.com/googleworkspace/cli). Install, authenticate, and automate Gmail, Drive, Sheets, Calendar, Docs, Chat, and Tasks. Run security audits and use local recipe templates and persona bundles. Use for Google Workspace admin, gws CLI setup, Gmail automation, Drive management, or Calendar scheduling.
-
bestagentkits Bundle Security Pen TestingUse when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. Covers static analysis, dependency scanning, secret detection, API security testing, and pen test report generation.
-
bestagentkits Bundle Security Senior SecopsUse when Codex should act as the Senior SecOps Engineer specialist from Agency Agents. Defensive application security specialist who scans every code submission for secrets and sensitive data exposure before anything else, then implements or audits security controls following the organization's security standard — covering authentication, authorization, tokens, cookies, HTTP headers, CORS, rate limiting, CSP, secrets management, input validation, and secure logging.
-
bestagentkits Bundle Engineering Code ReviewerUse when Codex should act as the Code Reviewer specialist from Agency Agents. Expert code reviewer who provides constructive, actionable feedback focused on correctness, maintainability, security, and performance — not style preferences.
-
bestagentkits Bundle Finance Bookkeeper ControllerUse when Codex should act as the Bookkeeper & Controller specialist from Agency Agents. Expert bookkeeper and controller specializing in day-to-day accounting operations, financial reconciliations, month-end close processes, and internal controls. Ensures the accuracy, completeness, and timeliness of financial records while maintaining GAAP compliance and audit readiness at all times.
-
bestagentkits Bundle Social Media ManagerWhen the user wants to develop social media strategy, plan content calendars, manage community engagement, or grow their social presence across platforms. Also use when the user mentions 'social media strategy,' 'social calendar,' 'community management,' 'social media plan,' 'grow followers,' 'engagement rate,' 'social media audit,' or 'which platforms should I use.' For writing individual social posts, see social-content. For analyzing social performance data, see social-media-analyzer.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include secrets-manager, secrets-scanner, security-tester. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.