Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
rosscrooke Skill Legal ChecklistBTS-Synthetic legal review checklist for inbound RFPs and contracts. Use whenever reviewing an RFP for contractual risk — covers data residency, liability, IP, audit, termination, and our standard counter-positions. Trigger on any request to legal-review, flag, redline, or assess contractual terms in an RFP or customer document.
-
bob-reis Skill Security CommandsSecurity Commands
-
bob-reis Skill Pentest Web AttacksWeb application penetration testing skills covering SQLi, XSS, LFI, SSRF, XXE, file upload bypass, command injection, and SSTI
-
ivanshamaev Skill Starrocks Admin SecurityStarRocks security and RBAC — CREATE USER/ROLE, GRANT/REVOKE privileges (catalog/database/table/view/MV/function/resource group level), built-in roles (cluster_admin/db_admin/user_admin/public), LDAP/LDAP group auth, row-level security policies, column masking, SSL/TLS, audit log, privilege inheritance, security best practices
-
ivanshamaev Skill Trino Security And GovernanceTrino security hardening and data governance — TLS/HTTPS setup, internal-communication shared secret, authentication (LDAP/OAuth2/JWT), file-based access control (catalog/schema/table/column rules, column masking, row-level filtering, query kill permissions), OPA integration, Ranger for dynamic row-filter and column-mask, catalog isolation by domain, user group mapping, impersonation rules, audit logging via event listener, password file authentication for development
-
ivanshamaev Skill Starrocks Admin Query MonitorStarRocks query monitoring and resource management — slow query log, SHOW PROCESSLIST, information_schema.query_history, resource groups (CREATE RESOURCE GROUP), classifiers, CPU/memory/concurrency limits, query queuing, KILL QUERY, workload isolation, Audit Loader plugin
-
taipt1504 Bundle PentestSpring Boot security scanner — OWASP Top 10, SpEL injection, Actuator exploitation, Jackson deserialization, mass assignment, and Spring Security misconfiguration detection. Includes 6 automated scanning scripts and real CVE patterns. Use when performing security reviews, penetration testing, vulnerability assessments, security audits, or checking for known CVEs in Spring Boot projects. Run /pentest-scan for automated full-project scan.
-
taipt1504 Bundle Summer FileSummer Framework streaming zip exporter (0.3.5+). Use when a service produces a downloadable archive of rows (statements, ledger reports, audit extracts, settlement files). Provides ZipExporter, ExportSpec, ChunkWriter, DatedExportRow, SizeLimitedOutputStream — replaces per-service ZipOutputStream plumbing with one call. Both Iterable and Flux overloads; built-in PipedInputStream "pipe to uploader" form.
-
ivanshamaev Skill Dataops Airflow ObservabilityAirflow observability — StatsD/OpenTelemetry metrics (scheduler_heartbeat/task_duration/pool_open_slots/dag_processing_total_parse_time), Prometheus scraping, Grafana dashboards (DAG success rate/task duration/slot utilization), structured task logging (JSON formatter), OpenTelemetry traces for task spans, DAG SLA miss alerts, anomaly detection on task duration, Airflow audit log, DagBag parse error monitoring, dead letter queue for failed tasks
-
taipt1504 Bundle Grpc PatternsgRPC patterns for Java Spring Boot applications. Covers proto file design, Spring Boot gRPC integration with grpc-spring-boot-starter, server and client implementation, reactive gRPC with reactor-grpc, error handling, interceptors, all streaming patterns, security (TLS/JWT), testing with InProcessServer, and Micrometer monitoring. Use when building gRPC services with Spring Boot 3.x and Java 17+.
-
taipt1504 Bundle Spring SecuritySpring Security patterns — authentication, authorization, JWT, CORS, secrets management, OWASP scanning, security review for MVC and WebFlux applications. Use when configuring SecurityFilterChain or SecurityWebFilterChain, implementing JWT authentication, setting up CORS, applying method-level security, managing secrets, or reviewing OWASP compliance.
-
taipt1504 Bundle Summer SecuritySummer Framework security — APISIX auth integration with X-Userinfo header, multi-realm provider config (0.3.0+), @AuthRoles annotation for role definitions, SecurityWebFilterChain config, ReactiveKeycloakClient for Keycloak resource API, KeycloakRoleSynchronizer, KeycloakException error mapping, JWT blacklist via Redis (0.3.0+), and group-role authorization with layered cache (0.2.4+).
-
taipt1504 Bundle Coding StandardsUnified Java code review + coding standards skill (alias "code-review"). Enforces ALL six rule sets — CORE-*, MVC-*, RX-*, WFL-*, XCT-*, JKS-* — across BUILD (REFACTOR self-check) and REVIEW (Stage 2 findings). Every finding cites [<P0-P4>][<RULE-ID>]. Also encodes Java 17+ patterns (records, sealed, pattern matching), naming, Lombok, immutability, Optional/Stream rules. Use whenever Claude writes new Java code, reviews a diff, refactors, or audits style. MANDATORY TRIGGERS — Java, Spring Boot, Spring MVC, Spring WebFlux, Project Reactor, Jackson, ObjectMapper, @JsonProperty, @JsonCreator, @JsonTypeInfo, @JsonFormat, JSON, BigDecimal, money, @Transactional, R2DBC, JpaRepository, Mono, Flux, WebClient, code review, audit, refactor, REFACTOR step, /dc-review, /build.
-
pangzhenying2025 Skill Automotive SatelliteSkill for implementing vehicle over-the-air (OTA) software update systems using satellite connectivity, covering update distribution architecture, delta compression, multicast delivery, update scheduling, security, and hybrid cellular-satellite delivery strategies for global vehicle fleets. Covers 8 topics across satellite-connectivity domain. Includes 8 skill files covering 3GPP TS 22.101 - eCall over IMS Requirements, 3GPP TS 22.261 - Service Requirements for 5G NTN, 3GPP TS 23.501 - 5G System Architecture (multi-access support), 3GPP TS 23.502 - 5G Procedures for Non-3GPP Access, 3GPP TS 36.440 - eMBMS (evolved Multimedia Broadcast Multicast), 3GPP TS 38.821 - NR NTN (Non-Terrestrial Networks), ADASIS v3 - Advanced Driver Assistance Systems Interface Specification, CEN EN 15722 - eCall Minimum Set of Data (MSD) and more.
-
pangzhenying2025 Skill Automotive Sotif AuditAutomotive Sotif Audit expertise. Covers 1 topics: Sotif Audit.
-
pangzhenying2025 Bundle Automotive RulesCoding standards, safety rules, security rules, and testing standards for automotive development. Covers MISRA C, ISO 26262, ASPICE, and cybersecurity requirements.
-
pangzhenying2025 Skill Automotive Security SystemsExpert skill in alarm focusing on security-systems domain applications. Covers 40 topics across security-systems domain. Includes 40 skill files covering ASPICE Level 3, AUTOSAR 4.4, ISO 21434, ISO 26262.
-
pangzhenying2025 Skill Automotive ZonalAutomotive Zonal expertise. Covers 5 topics: Automotive Ethernet, Network Security Zonal, Service Oriented Communication, Zonal Architecture Design, Zone Controller Development.
-
pangzhenying2025 Bundle Automotive SecurityExpert skill in authentication focusing on security domain applications. Covers 198 topics across security domain. Includes 198 skill files covering ASPICE Level 3, AUTOSAR 4.4, ISO 21434, ISO 26262.
-
anilveersingh1308 Skill Redesign Existing ProjectsONLY USE when the user explicitly types `/redesign-existing-projects` or asks specifically for this skill by name. Do NOT auto-trigger on general 'audit' or 'redesign' phrasing — `impeccable` (with its audit/shape/polish subcommands) is the default for those in this workspace. Kept available for direct invocation only.
-
anilveersingh1308 Bundle Gstack Devex ReviewLive developer experience audit. Uses the browse tool to actually TEST the developer experience: navigates docs, tries the getting started flow, times TTHW, screenshots error messages, evaluates CLI help text. Produces a DX scorecard with evidence. Compares against /plan-devex-review scores if they exist (the boomerang: plan said 3 minutes, reality says 8). Use when asked to "test the DX", "DX audit", "developer experience test", or "try the onboarding". Proactively suggest after shipping a developer-facing feature. (gstack) Voice triggers (speech-to-text aliases): "dx audit", "test the developer experience", "try the onboarding", "developer experience test".
-
anilveersingh1308 Bundle Gstack Design ReviewDesigner's eye QA: finds visual inconsistency, spacing issues, hierarchy problems, AI slop patterns, and slow interactions — then fixes them. Iteratively fixes issues in source code, committing each fix atomically and re-verifying with before/after screenshots. For plan-mode design review (before implementation), use /plan-design-review. Use when asked to "audit the design", "visual QA", "check if it looks good", or "design polish". Proactively suggest when the user mentions visual inconsistencies or wants to polish the look of a live site. (gstack)
-
duaooo Skill Security ReviewRun a comprehensive security review on code
-
duaooo Skill Verification LoopThis skill should be used when the user asks to "verify code", "run verification", "check quality", "validate changes", or before creating a PR. Provides comprehensive verification including build, type check, lint, tests, security scan, and diff review.
-
l3mpire Skill Copywriting RefinerAudits any cold email, LinkedIn message, or outreach sequence against a strict quality checklist and rewrites every failing element. Use when asked "refine this email", "clean up my copy", "check this email", "can you review this sequence", "fix my cold email", or whenever outreach copy is shared and needs to be tightened up. Also use when the user pastes an email and asks if it's good, too long, too formal, or "too salesy". Always produces a pass/fail audit + a corrected version of the copy.
-
idoforgod Skill Vision Foresight Futures Wheel Quality ControlTLDR — Jerome C. Glenn (V3.0 06장 §IV + §III.A + endnote 4) Quality Control sub-skill + 박사님 2026-05-11 강화 명령 3종 강제. **vision-foresight-futures-wheel** 마스터 전용. **11 Audit Gate**: Gate 1-8 Glenn 원전(Wagschal·spaghetti·premature·causation·butterfly·timing·probability·strengths) + ⭐ **Gate 9 Citation Completeness** + ⭐ **Gate 10 Reasoning Chain Validity·SRS** + ⭐ **Gate 11 SCBE Compliance**. 모든 wheel 산출의 *최종 품질 게이트* — 통과 못하면 REVISIONS_REQUIRED 반환. ## Triggers — INTERNAL ONLY. 마스터 Cycle 2·4·6·7·8에서 호출. Cycle 8 단독 발동. 사용자가 'Wagschal Unanimity', 'rule of unanimity', '품질 점검', '검증해줘', 'intellectual spaghetti', 'plausibility 검증', 'correlation vs causation', '함정 체크', 'butterfly effect', '직선적 단정 회피', 'citation 검증', 'SRS 측정', '6차 깊이 확인' 명시 시 마스터가 본 sub-skill 발동. ## Detailed Methodology — Glenn (2009) §IV + §III.A + endnote 4 + 박사님 2026-05-11 두 차례 강화. **11 Audit Gate**: ① **Gate 1 Wagschal Unanimity** — *"requires a restriction on the group to prevent them from arriving at conclusions that are so speculative."* ② **Gate 2 In
-
andrewnggirl Bundle Pr ReviewerUse when the user asks to review, audit, comment on, or 评审 / 审查 a GitHub Pull Request. Generates structured review comments covering team-specific code style, naming, and structural conventions — complements (not replaces) bug-finding tools like Copilot Code Review or CodeQL.
-
andrewnggirl Bundle Stock Trading AnalystUse when the user needs an A-share stock watchlist, short-term theme rotation review, or trading-plan risk audit based on user-provided market data. Produces evidence-based sector analysis, signal confidence, risk warnings, and a non-advisory action checklist for retail investors, research assistants, and trading educators.
-
andrewnggirl Skill Banking Workflow AssistantUse when bank operations, relationship managers, or credit middle-office teams need to pre-check onboarding, credit, KYB, due diligence, or post-loan documents, route exceptions, track SLA risk, and preserve audit-ready compliance reasoning.
-
l3mpire Skill Trigger FinderBuying trigger analysis skill for outbound sales teams. Identifies and interprets trigger events (funding, hiring, tool changes, job changes, LinkedIn activity, M&A, etc.) to help time outreach and sharpen messaging. Works in two modes: (1) Strategic — given an ICP, recommends the best triggers to activate and the right messaging angle for each; (2) Tactical — given a specific company or signal, explains how to exploit it right now. ALWAYS use this skill when the user mentions signals, triggers, buying intent, "right time to reach out", timing outreach, "they just raised", "they just hired", "they changed jobs", job postings, funding rounds, tech stack changes, LinkedIn activity, or any event-based prospecting. Use it even if the user just says "when should I reach out to X".
-
guyue010 Bundle Lark To Codex BridgeBuild, audit, harden, or productize a Lark/Feishu to Codex bridge that receives chat messages through event subscription or long connection, routes them to Codex, OpenAI, or a local CLI, and replies back to Lark. Use when implementing a Zara-style lark-channel-bridge adaptation for Codex, diagnosing duplicate replies/self-triggering/history replay, creating setup/doctor/start commands, designing App ID/Secret storage, or documenting Lark Open Platform bot permissions and event setup.
-
ekajto Skill Security ReviewSenior Security Auditor — Security Review
-
mangiapanejohn-dev Skill HealthcheckHost security hardening and risk-tolerance configuration for Resonix deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, Resonix cron scheduling for periodic checks, or version status checks on a machine running Resonix (laptop, workstation, Pi, VPS).
-
kotrotsos Skill Decision Audit TrailUse this skill after a real organizational decision has been made (vendor selected, architecture chosen, hire approved, strategy committed, project killed) to capture the reasoning while it is still fresh. Triggers on phrases like "audit decision", "document why we decided", "decision memo for [X]", or when the user references a recently made choice. Produces a one-page "Why we decided X" memo for future you, new hires, or board context.
-
goog-cmmartin Skill Secops Threat InvPerforms deep enrichment, UDM searches, and entity analysis in Google SecOps.
-
denniswei9898 Skill Level CheckAudit the current project against the 5 Levels of Claude Code framework and auto-fix any gaps found. Trigger on "check claude levels", "audit project structure", "am I at level 3", "level check", "5 levels check", "檢查 claude 層級", "盤點專案結構", "level 偵測", "我現在在哪個層級", "Claude Code 五個層級"
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include legal-checklist, security-commands, pentest-web-attacks. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.