Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
datasiteai Skill Document Quality CheckDocument Quality Check skill for Datasite deal rooms. Use this skill whenever a deal team wants to audit document quality before going live to buyers. Triggers include: "check document quality", "flag bad documents", "find password protected files", "check for blank documents", "PII check", "redaction review", "find corrupted files", "document audit", "quality check the data room", "are there any blank or broken files", "check for unredacted personal data", or any request to verify that documents in the data room are complete, accessible, and safe to share. Use this skill proactively before a data room goes live. Do not use for renaming files (use smart-file-renaming) or for identifying missing sections (use gap-analysis).
-
datasiteai Skill Launch Readiness OrchestratorLaunch Readiness Orchestrator skill for Datasite deal rooms. Use this skill whenever a deal team wants a single pre-go-live readiness check across their data room — combining gap analysis, document quality audit, and risk review into one consolidated "is the room ready?" view. Triggers include: "are we ready to go live", "launch readiness check", "pre-launch audit", "data room readiness", "can we launch", "is the data room ready", "run a full readiness check", "go-live checklist", "pre-launch checklist", or any request to get a single overall assessment before opening the data room to buyers. Use proactively whenever a deal team is approaching their go-live date and wants a structured sign-off view. Do not use other individual audit skills (gap-analysis, document-quality-check, risk-analysis-audit) when this skill is active — this skill orchestrates all three in one pass.
-
yangyuchen-work Skill Skill Supply Chain AuditSkills 供应链审计
-
yangyuchen-work Skill Production Security Hardening生产级安全加固包
-
yangyuchen-work Skill Security Quickstart Guardrails安全快速启动模板
-
zuoguyoupan2023 Skill Claude Settings AuditAnalyze a repository to generate recommended Claude Code settings.json permissions. Use when setting up a new project, auditing existing settings, or determining which read-only bash commands to allow. Detects tech stack, build tools, and monorepo structure.
-
zuoguyoupan2023 Bundle Rails ConventionsRails 8.x application architecture, implementation, and review guidance for production codebases. Use when building or reviewing Ruby on Rails 8 features across models, controllers, routes, Hotwire, jobs, APIs, performance, security, and testing. Trigger for requests mentioning Rails 8, Active Record, Active Job, GoodJob, Solid Queue, Turbo/Stimulus, REST resources, migrations, code quality, naming, and production readiness.
-
zuoguyoupan2023 Skill Recipe ReviewDesign Doc compliance and security validation with optional auto-fixes
-
zuoguyoupan2023 Skill Close DayEnd-of-day audit ritual — synthesize sessions into daily log, audit patterns against MEMORY.md and existing concepts/rules, propose promotions verbally, write approved patches
-
zuoguyoupan2023 Skill IOS Design ReviewVisual design audit for iOS apps on real hardware. (gstack)
-
zuoguyoupan2023 Skill Quarkus VerificationVerification loop for Quarkus projects: build, static analysis, tests with coverage, security scans, native compilation, and diff review before release or PR.
-
zuoguyoupan2023 Skill Quarkus SecurityQuarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security.
-
surendranb Bundle Funnel Velocity AuditExecute funnel velocity audit to understand unit economics and ROI.
-
bodymobarez Bundle Code Quality MasterMaster hub for Code review, security & quality. Use to review code, audit security/performance, find bugs, and simplify code. Bundles 16 specialized skills (in skills/<name>/GUIDE.md). Use this for any code quality task.
-
hieu-hm Bundle OdooUse when Codex needs to inspect, debug, modify, test, migrate, or review Odoo source code, addons, custom modules, manifests, ORM models, XML views, security rules, controllers, reports, assets, Owl/JavaScript, PostgreSQL data/debugging, upgrade scripts, or Odoo.sh/deployment configuration. Always apply version-aware Odoo workflows before using docs or code patterns.
-
maxmealing Bundle MxkeymacOS dev-secrets workflow via mxkey (a Keychain wrapper). Use whenever the user handles an API key, token, password, or 2FA backup / recovery code — setting up a new API, running a command that needs a key, editing a .env file, spotting a hardcoded secret in code, or storing single-use recovery codes. Secrets never enter chat, shell history, or plaintext files. macOS only.
-
omgutty Skill Soap API TestingSOAP web service testing including WSDL validation, XML schema testing, WS-Security, and SOAP fault handling verification.
-
alexpeclub Bundle QATest features against acceptance criteria, find bugs, and perform security audit. Use after implementation is done.
-
vanyaan77-lgtm Bundle Advertisement BriefTurn advertising briefs, BF documents, product selling points, brand requirements, or client notes into practical Douyin/Xiaohongshu short-video scripts. Use when the user says "advertisement brief", "ab", or asks Codex to write, rewrite, optimize, audit, or format ad scripts from a brief; convert hard selling points into scenes; make a script more Douyin-like, natural, funny, or watchable; add BF coverage labels; or prepare a creator-facing shot table.
-
openmatter-network Bundle AI Audit PlanningUse when scoping or commissioning a psychological audit of an AI/ML personnel assessment — to define which claims the audit will evaluate (validity, utility, lack of bias), establish the auditor's stance and credibility (internal / external / independent), decide formative vs. summative timing and the audience, and settle data/documentation access and disclosure terms. Triggers: "audit an AI hiring tool", "plan an algorithm audit", "bias audit scope", "internal vs external vs independent auditor", "formative vs summative audit", "NYC Local Law 144 bias audit", "what claims should the audit test".
-
openmatter-network Bundle AI Audit ReportingUse when writing up and releasing the results of a psychological audit of an AI/ML personnel assessment — producing a precise, comprehensive technical report for testing professionals AND a layperson-friendly summary for those the predictions affect, establishing the auditor's standards and credibility in the report, and deciding on public release. Triggers: "write the AI audit report", "release the bias audit results", "dual-audience audit report", "should we publish the audit", "auditor credibility statement", "communicate algorithm audit findings".
-
openmatter-network Bundle AI Fairness LensesUse FIRST when evaluating, auditing, or debating whether an AI/ML personnel assessment is "fair" or "unbiased" — to define and defend which meaning of fairness/bias applies before drawing conclusions. Covers the three lenses from Landers & Behrend (2023): individual attitudes (distributive/procedural/ interactional justice), legality-ethicality-morality, and technical domain-embedded meanings (statistics vs. machine learning vs. psychometrics). Triggers: "is this AI hiring tool fair/biased", "what does bias mean here", "algorithmic fairness", "disparate impact vs measurement bias in AI", "bias-variance tradeoff", "define fairness for the audit".
-
openmatter-network Bundle Administration DocumentationUse when preparing the administration documentation / manual for an operational selection procedure — the materials administrators and users need to administer, score, interpret, secure, and communicate the procedure consistently. Covers administrator qualifications, the testing environment, scoring/interpretation, security, candidate communications and feedback, reassessment, nonstandard administrations, data retention, and review/updating. Triggers: "administration manual", "test administration documentation", "test security", "candidate feedback", "retest policy", "reassessment", "data retention for test scores", "proctoring / unproctored internet testing".
-
stevefeldman Skill Security AuditIdentify security vulnerabilities across dependencies, auth, input validation, data protection, secrets, and infrastructure
-
stevefeldman Bundle Core Web VitalsMeasure and assert Core Web Vitals (LCP, INP, CLS) in Playwright scripts. Use when the user wants to capture performance metrics, validate CWV thresholds, audit pages for Google ranking signals, or add CWV measurement to existing Playwright checks. Pairs with the playwright-dev skill.
-
stevefeldman Skill Dependency AuditAudit all project dependencies for security vulnerabilities, outdated packages, license compliance, and health
-
stevefeldman Skill Security HardeningApply security best practices to reduce attack surface — authentication, input validation, headers, encryption, and dependency updates
-
notmatical Skill Move DoctorUse when finishing a Sui Move feature, fixing a bug, before committing Move code, or when the user types /movedoctor, asks to scan, triage, or clean up Move diagnostics. Covers Move Book conventions, Move 2024 idioms, ability mistakes, testing style, and security best practices.
-
stevefeldman Bundle Go HystrixAudit and optimize Hystrix circuit breaker implementations in Go services for scaling, performance, and availability
-
stevefeldman Bundle Go LoggingAudit and improve Go service logging to ensure Splunk logs capture method, request details, TraceID, SpanID, and timing using the go-common logging library
-
stevefeldman Skill Code ReviewWhole-repository code quality review covering architecture, security, performance, and testing
-
stevefeldman Bundle Dependency Security AuditUse when reviewing Dependabot alerts, npm audit findings, govulncheck output, or CVE reports on a JavaScript/Node.js or Go project — especially when triaging multiple alerts across direct and transitive dependencies to assess real-world risk and produce a remediation plan.
-
getgrille Skill Grille AuditUse when verifying tool calls completed, reviewing recent Grille activity, or diagnosing failures. WHEN: 'did that write succeed', 'check audit log', 'what did Claude do', 'recent tool calls', 'grille_audit', 'any errors', 'verify the action'. DO NOT USE WHEN: looking for system events (use grille-eventlog); discovering config (use grille_info).
-
getgrille Skill Grille SystemUse for Grille server health, session diagnostics, and machine state. WHEN: 'start of session', 'is Grille healthy', 'check system state', 'what tools are available', 'OS version', 'disk space', 'RAM usage', 'any errors', 'how many calls this session', 'grille_diagnose', 'grille_health', 'grille_info', 'grille_session_stats', 'secrets doctor', 'check secrets', 'is my AKV reachable', 'secret provider health'. DO NOT USE WHEN: querying the Windows Event Log in depth (use grille-eventlog); reviewing tool call history (use grille-audit).
-
getgrille Skill Grille EventlogUse when querying Windows Event Log for system, application, or security events. WHEN: 'event log', 'eventlog_query', 'windows events', 'check for errors in event log', 'service crash events', 'Grille security events'. DO NOT USE WHEN: reading Grille tool call history (use grille-audit); reading log files on disk (use grille-filesystem).
-
getgrille Skill Grille FirewallUse when reading Windows Firewall rules or the active firewall profile. WHEN: 'why is port X closed', 'what firewall rules exist for port X', 'is there a firewall rule blocking postgres', 'show me inbound block rules', 'what is the active firewall profile', 'what is the default inbound policy', 'firewall_rules', 'firewall_profile', 'is the firewall blocking X'. PAIR WITH grille-networking when net_port_check returns CLOSED and you need to explain why. DO NOT USE WHEN: modifying firewall rules (read-only only); remote machine firewall (local machine only); IPSec / connection security rules (not exposed).
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include document-quality-check, launch-readiness-orchestrator, skill-supply-chain-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.