Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
getgrille Skill Grille Windows UpdateUse when checking Windows updates on the local machine. WHEN: 'are there any pending updates', 'check Windows Update', 'is this machine patched', 'any security patches pending', 'is KB<number> installed', 'check patch compliance', 'pending Windows updates', 'wu_status', 'Defender definitions up to date', 'missing patches', 'list installed updates', 'what updates are installed', 'show update history', 'when was KB installed', 'what patches have been applied'. DO NOT USE WHEN: installing or downloading updates (this module is read-only); querying installed software/apps (use grille-wmi with Win32_Product).
-
agencia-conversion Bundle EeatWhen the user wants to audit, strengthen, or prepare evidence for Experience, Expertise, Authoritativeness, and Trust. Also use before registering proof entries in `project/brain/log.md` or referencing them in `project/brain/topic-clusters.md`.
-
miaoge-ge Skill Nodejs Backend ExpertExpert Node.js backends (Express/Fastify/Hono): routing, middleware, validation, auth, async, and production hardening. Trigger keywords: Node.js, Express, Fastify, Hono, REST, middleware, JWT, session, zod, async, streams, unhandled rejection, graceful shutdown, backend, server. Use for building HTTP services, structuring backends, or fixing async/error/security issues.
-
mackewinsson Skill Code ReviewReview code for bugs, security, maintainability, and convention fit. Use when the user asks for a code review, PR review, or feedback on a diff.
-
robisson Skill Design ReviewReview a technical design before specs or implementation. Evaluate problem clarity, requirements, alternatives, trade-offs, architecture, dependency behavior, security, operations, cost, testability, and simplicity.
-
robisson Bundle Operational Readiness ReviewThe ORR process — a self-assessment checklist covering monitoring, alarming, runbooks, on-call, scaling, security, deployment safety, cost, and dependencies. Must pass before launch.
-
yelloooooooow Bundle Simulation Automation SkillAutomate engineering simulation workflows with MATLAB/Simulink, Ansys Fluent/PyFluent, or coupled Simulink-Fluent calibration. Use when users ask to build or audit Simulink simulations, run multiple cases, export Simulink screenshots, automate Fluent CFD geometry/mesh/boundaries/solver/postprocessing, compare Fluent and Simulink results, derive conservative CFD correction factors, run parameter optimization, perform techno-economic analysis, generate publication figures/videos/reports, or perform final project quality review.
-
vzubcu Skill Dotnet 48 Master ArchitectUniversal orchestrator for .NET Framework 4.8/4.8.1. Activates for: WPF, WinForms, ASP.NET MVC 5, WebForms, WCF, EF6, ADO.NET, legacy modernization, security audits, test generation, or architecture questions. Delegates to specialized sub-agents for deep domain work. Covers Desktop, Web, Services, Data, Security, Performance, Testing, and Migration. Updated for 2026.
-
karlmanx33 Bundle Technical Debt Audit RunnerAdvanced operational skill for technical-debt-audit-runner.
-
karlmanx33 Bundle Pre Launch Security ReviewerAdvanced operational skill for pre-launch-security-reviewer.
-
code-yeongyu Skill Review Work 3Post-implementation review orchestrator. Launches 5 parallel background sub-agents: Oracle (goal/constraint verification), Oracle (code quality), Oracle (security), unspecified-high (hands-on QA execution), unspecified-high (context mining from GitHub/git/Slack/Notion). All must pass for review to pass. MUST USE after completing any significant implementation work. Triggers: 'review work', 'review my work', 'review changes', 'QA my work', 'verify implementation', 'check my work', 'validate changes', 'post-implementation review'.
-
leoai-org Skill Cadquery Interference CheckAudit a CadQuery assembly for interferences (unintended overlaps) and unintended gaps at every mating interface. Use when the orchestrator (`cadquery-assembly`) finishes laying out parts, when the user says "check for clashes", "verify there are no interferences", "interference check", or before exporting a final STEP. Walks every part pair, computes pairwise intersections, reports clashes with volume and bounding box, and proposes fixes.
-
coreycore123 Bundle Ad Body Copy AuditEvaluate and improve paid acquisition body copy for lead generation, inquiry, private-message opening, and form submission quality. Use when the user asks to judge, score, compare, rewrite, or create 正文、笔记正文、投放正文、客资正文、咨询正文、进线、开口、留资、私信理由、旅修/疗愈/课程/活动招募文案.
-
coreycore123 Bundle Ad Cover Title AuditEvaluate and improve paid acquisition creative covers and titles for Xiaohongshu/Juguang lead-generation ads, travel retreats, courses, events, and activity recruitment. Use when the user asks to judge, score, rewrite, test, or create 投放素材、客资投放封面、标题、首图、双列流点击率、开口率、获客效率、旅修、疗愈、课程、活动招募素材.
-
coreycore123 Bundle Ad Supporting Images AuditEvaluate non-cover images in paid acquisition notes, Xiaohongshu/Juguang creatives, travel retreats, courses, events, and activity recruitment. Use when the user asks to judge, compare, score, rewrite, plan, or create 非封面图片、组图、详情图、后续图片、行程图、体验图、住宿图、导师图、价格包含图、适合人群图、报名方式图、信任证据链、咨询前决策辅助.
-
liaosw97 Bundle Zero TrustUse when working with zero trust security — mTLS, OPA, identity verification, least privilege
-
liaosw97 Bundle Smart Contract SecurityUse when working with smart contract security — auditing, vulnerability detection, secure coding
-
liaosw97 Bundle Secure MultipartyUse when working with secure multi-party computation — MPC, secret sharing, oblivious transfer
-
liaosw97 Bundle Java Security Standards阿里巴巴Java开发手册安全规约。Use when implementing security features, authentication, authorization, or security best practices in Java applications.
-
liaosw97 Bundle Security Service MeshUse when working with service mesh security — mTLS, SPIFFE, authorization policies
-
liaosw97 Bundle Homomorphic EncryptionUse when working with homomorphic encryption — FHE, BFV, CKKS, privacy-preserving computation
-
manager-rubens Bundle Codex Ops Skill Usage AuditorAudit how a Codex skill was used in a conversation or transcript, mapping invoked skills, shell/tool commands, app/browser/web calls, file edits, procedures performed, repeated steps, friction points, and concrete opportunities to improve the skill workflow. Use when the user asks to audit, review, varrer, analisar, or mapear uso de skill; list commands or procedures used by a skill; reduce repetitive work after a skill run; or turn a conversation into skill improvements.
-
moii-dev Bundle Github Repo PolisherUse this skill whenever preparing a project, repository, homework project, prototype, library, app, bot, website, or codebase for GitHub publication. The skill improves repository structure, README quality, .gitignore, security hygiene, launch instructions, and overall presentation without breaking the project.
-
ila Skill Project ReviewSubsystem-by-subsystem codebase audit. Discovers source directories, reviews each from 5 perspectives, and produces prioritized findings. Use for periodic quality sweeps or before releases.
-
c0urag1 Bundle Break Risk IntelBlack/grey-market intelligence analysis assistant based on JDArmy/BREAK for risk-control, anti-abuse, anti-fraud, trust & safety, and business security teams. Use for 黑灰产情报分析, 风控 case 分析, 反作弊, 反欺诈, 业务安全, 薅羊毛, 刷单, 撞库, 爬虫, 账号风险, 代理IP, 设备风险, 营销风险, 支付金融风险, 商家作弊, 内容刷量, fraud risk, anti-abuse, trust and safety, abuse investigation. Maps cases to BREAK business-risk taxonomy and produces observables, hypotheses, investigation plans, controls, risk matrices, and reports.
-
joaoalvess Bundle Tvos Performance AuditAudit and improve tvOS SwiftUI and playback runtime performance from code review and profiling guidance. Use for requests about sluggish focus movement, janky shelves, dropped frames, image or video cost, playback UI stutter, or excessive view updates on Apple TV.
-
tcvdog Skill Code ReviewerExpert code reviewer who provides constructive, actionable feedback focused on correctness, maintainability, security, and performance — not style preferences.
-
tcvdog Skill Infrastructure MaintainerExpert infrastructure specialist focused on system reliability, performance optimization, and technical operations management. Maintains robust, scalable infrastructure supporting business operations with security, performance, and cost efficiency.
-
tcvdog Skill Bookkeeper ControllerExpert bookkeeper and controller specializing in day-to-day accounting operations, financial reconciliations, month-end close processes, and internal controls. Ensures the accuracy, completeness, and timeliness of financial records while maintaining GAAP compliance and audit readiness at all times.
-
tcvdog Skill Threat Detection EngineerExpert detection engineer specializing in SIEM rule development, MITRE ATT&CK coverage mapping, threat hunting, alert tuning, and detection-as-code pipelines for security operations teams.
-
tcvdog Skill Blockchain Security AuditorExpert smart contract security auditor specializing in vulnerability detection, formal verification, exploit analysis, and comprehensive audit report writing for DeFi protocols and blockchain applications.
-
tcvdog Skill Solidity Smart Contract EngineerExpert Solidity developer specializing in EVM smart contract architecture, gas optimization, upgradeable proxy patterns, DeFi protocol development, and security-first contract design across Ethereum and L2 chains.
-
tcvdog Skill Autonomous Optimization ArchitectIntelligent system governor that continuously shadow-tests APIs for performance while enforcing strict financial and security guardrails against runaway costs.
-
elijj Bundle Code ReviewUse this skill when the user invokes `/code-review`, asks for a code review, wants local uncommitted changes reviewed, provides a GitHub PR number, PR URL, or branch name, asks whether code is safe to merge, or after implementation before commit. It reviews correctness, security, type safety, tests, performance, and maintainability, runs applicable validation, and reports findings by severity before summaries.
-
digitalexplorers Skill API Security ReviewChecks REST and GraphQL APIs for security misconfigurations including authentication flaws, authorization gaps, rate limiting issues, insecure endpoints, and data exposure risks
-
digitalexplorers Skill Dependency Security CheckAnalyzes project dependencies for known vulnerabilities including outdated packages, known CVEs, and unsafe libraries
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include grille-windows-update, eeat, nodejs-backend-expert. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.