Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
rpatel05 Skill Audit LexiconReviews Mixpanel Lexicon for data quality issues - missing descriptions, inconsistent naming, hidden events, stale properties, and orphaned tags
-
rpatel05 Skill Update LexiconBulk updates event and property descriptions, tags, and owners in Mixpanel Lexicon. Use after audit-lexicon to fix data governance issues.
-
rpatel05 Skill Replay UX AuditWatches multiple session replays for a specific flow and synthesizes a ranked friction map - common pain points, error patterns, and UX improvements
-
gosulashivakumar Bundle Iso 42001 AimsExpert guidance on ISO/IEC 42001:2023 — the international standard for AI Management Systems (AIMS). Use this skill whenever a user asks about ISO 42001, AI management systems, AIMS audits, AI governance frameworks, AI risk assessments under ISO standards, gap assessments against ISO 42001, clause interpretation, Annex A controls, Annex B implementation guidance, corrective actions, statement of applicability, or responsible AI governance. Also triggers for questions about AI policy requirements, AI system impact assessments, AI risk treatment plans, or certification readiness for ISO 42001. This skill is audit-grade — always cite clause numbers and use precise normative language (shall/should).
-
shyamw-cloud Skill Code ReviewUse to review a pull request or a diff. Produces severity-tagged comments ([blocker], [suggestion], [nit]), one summary verdict, and a security pass. Reads adjacent files to verify claims and never hand-waves "looks good."
-
gouzigouzi Skill Codex Local Token UsageUse when a user wants to audit token usage from local Codex session archives, especially for daily or monthly totals and cached versus uncached token breakdowns.
-
yuvraj3335 Bundle Truto Account Health AuditorAudit integrated account health with Truto CLI, including account metadata, credentials, scopes, environment integration, overrides, capabilities, tools, logs, reauth, refresh, and short-lived token handling. Use for account auth, connection, scope, stale data, or missing tool issues.
-
yuvraj3335 Bundle Truto Integration Config AuditorAudit Truto integration JSON or stored integration configs for syntax, schema validity, provider-doc alignment, auth, pagination, resource methods, docs-table behavior, capabilities, and Truto repo conventions. Use when validating or reviewing an integration config.
-
developersglobal Skill Code ReviewStructured code review focusing on correctness, security, and maintainability. Correctness before style. Every reviewer comment must be actionable.
-
renehdzgtz Bundle Crypto Crisis CommunicationsExpert system for managing communications during crises in Web3 and crypto environments. Use this skill whenever the user needs to respond to a smart contract exploit, security incident, rug pull accusations, FUD campaigns, negative viral content, governance attack, team controversy, or any reputational crisis affecting a crypto project, protocol, or DAO. Also trigger for phrases like "we got hacked", "exploit on our protocol", "FUD spreading", "community is panicking", "negative news", "crisis response", "how do we respond", "our token is crashing", "bad press", "controversy", "our community is angry", "someone is spreading misinformation", "protocol vulnerability disclosed", or any situation requiring urgent or sensitive communication management in a Web3/crypto context.
-
craftsmantuck Bundle R00 Composiohq Awesome Claude Skills Security🔒 Security & Compliance skill suite derived from ComposioHQ/awesome-claude-skills. Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response. Provides 10 specialised commands for security, compliance, gdpr workflows.
-
paintairsever Bundle R00 Getbindu Awesome Claude Code And Skills Security🔒 Security & Compliance skill suite derived from GetBindu/awesome-claude-code-and-skills. Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response. Provides 10 specialised commands for security, compliance, gdpr workflows.
-
cardinalestate Bundle R00 Alirezarezvani Claude Code Skill Factory Security🔒 Security & Compliance skill suite derived from alirezarezvani/claude-code-skill-factory. Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response. Provides 10 specialised commands for security, compliance, gdpr workflows.
-
mergisi Skill Pr First ReviewFirst-pass GitHub PR review: OWASP Top 10, style violations, scope creep, breaking changes. Comments before the maintainer looks.
-
axisfrommall Bundle R00 Alirezarezvani Claude Skills Security🔒 Security & Compliance skill suite derived from alirezarezvani/claude-skills. Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response. Provides 10 specialised commands for security, compliance, gdpr workflows.
-
lavendertalesun Bundle R00 Glebis Claude Skills Security🔒 Security & Compliance skill suite derived from glebis/claude-skills. Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response. Provides 10 specialised commands for security, compliance, gdpr workflows.
-
freewaychameleonnode Bundle R00 Behisecc Awesome Claude Skills Security🔒 Security & Compliance skill suite derived from BehiSecc/awesome-claude-skills. Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response. Provides 10 specialised commands for security, compliance, gdpr workflows.
-
innerprawn98 Bundle R00 Borghei Claude Skills Security🔒 Security & Compliance skill suite derived from borghei/Claude-Skills. Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response. Provides 10 specialised commands for security, compliance, gdpr workflows.
-
regimentpebblehearth Bundle R00 Travisvn Awesome Claude Skills Security🔒 Security & Compliance skill suite derived from travisvn/awesome-claude-skills. Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response. Provides 10 specialised commands for security, compliance, gdpr workflows.
-
shubhashjha Skill Owasp WebBasic skill for OWASP aligned web security review, risk identification, and safer application implementation. Use when Codex needs a basic starting point for this web development area.
-
xiaozhen-y Bundle Skill Sync ManagerManage local Codex or ChatGPT skill folders with Git and GitHub. Use when the user wants to initialize a skills repository, audit which skills are tracked, protect system or sensitive files, pull skill updates on another computer, commit skill changes, push skills to GitHub, package a skill zip, or resolve Git sync conflicts for ~/.codex/skills.
-
darshan-yadav Bundle Architect ReviewerUse when the user wants a reviewer-mindset critique of a design doc, ADR, or technical proposal, focused on NFR rigor, failure modes, security/data boundaries, cost, and reversibility.
-
theaisingularity Skill Code ReviewLocal code review — analyzes a file, function, or git diff for bugs, security issues, edge cases, and style using your project's conventions from memory
-
santosomar Skill Pt ScanningPerforms authorized security scanning using static, dynamic, and vulnerability-focused methods. Use when mapping exposed services, profiling application behavior, and identifying known weaknesses for validation.
-
santosomar Skill Pt Lotl TechniquesDemonstrates Living-off-the-Land (LotL) techniques using native OS tools to simulate realistic threat actor behavior during authorized penetration tests. Use when proving attack feasibility without custom malware, testing detection coverage, and validating what a real adversary could achieve with only built-in system capabilities.
-
jlindstrom21 Bundle Jl Operating CadenceJeremy Haynes' verbatim framework for building a 3-layer operating cadence (daily execution, weekly optimization, monthly strategy) that scales without burnout. Covers duct-tape symptoms diagnosis, current operations audit, daily/weekly/monthly layer design, AI-proposes-humans-dispose integration, 5 operating metrics (task completion rate, decision velocity, capacity utilization, customer friction, revenue per team member), meeting agenda templates, dashboard structure, common mistakes, and implementation sequencing. Trigger when the user says "operating cadence", "scale without burnout", "audit operations", "daily standup", "weekly optimization meeting", "monthly strategy session", "AI integration plan", "friction removal", "fix chaotic operations", or "install operating rhythm". Part of the jl- library (Jeremy Haynes' verbatim skills).
-
santosomar Skill Pt Embedded Device AssessmentPerforms authorized security assessment of embedded and IoT devices across hardware, firmware, interfaces, and update mechanisms. Use when testing device boot flows, debug interfaces, firmware integrity, and local/network attack surfaces.
-
santosomar Skill Pt Web Application AssessmentPerforms authorized web application and API penetration testing with focus on OWASP-style risks and business logic flaws. Use when assessing websites, web APIs, authentication flows, session handling, and input validation.
-
jlindstrom21 Bundle Jl Customer Lifetime ValueJeremy Haynes' verbatim LTV-through-delivery framework for turning post-purchase experience into the highest-leverage driver of Customer Lifetime Value without hiring more staff. Walks through a six-step workflow covering delivery experience audit, automation mapping (order routing, tracking/communication, exception handling), behavioral personalization with zero-party data, omnichannel unification, testing infrastructure across nine delivery variables, and a final LTV improvement plan. Trigger whenever the user says "improve LTV", "customer lifetime value", "post-purchase experience", "reduce churn through delivery", "delivery automation", "repeat purchase rate", "retention through delivery", or asks about upgrading fulfillment, tracking, exception handling, or unifying multi-channel delivery. Part of the jl- library (Jeremy Haynes' verbatim skills).
-
jlindstrom21 Bundle Jl Meta Ad Restrictions PrepJeremy Haynes' verbatim framework for preparing health/wellness and financial services businesses for Meta's new ad restrictions. Covers the 7-step playbook — risk assessment, full vs. partial restriction categories, current infrastructure audit, domain-swap backup infrastructure, backup conversion event conditioning (installed_app, donate, search), appeal strategy, and protection plan delivery. Trigger when the user asks about Meta ad restrictions, pixel restrictions, domain restrictions, health/financial ad compliance, Events Manager restriction banners, backup domains, backup events, pixel conditioning, Meta appeal process, Industry Ad Expert, Hyros/Triple Whale/Northbeam as workarounds, or anything related to "my domain got flagged" / "my pixel went blind" / "Meta restricted my ads." Part of the jl- library (Jeremy Haynes' verbatim skills).
-
heldinhow Skill Code ReviewUse when reviewing code changes, pull requests, or diffs. Provides a structured review framework covering correctness, security, performance, readability, and test coverage.
-
heldinhow Bundle Security AuditPerform security vulnerability scanning and audits to identify and fix security issues.
-
gg-mo Bundle StagecraftUse when the user wants premium, keynote-style UI with refined motion — dark, minimal, cinematic reveals. Trigger words include "premium," "polished," "cinematic," "Apple-like," "keynote," "launch page," "product reveal," and "elevate this screen." Also use when asked to audit or restyle an existing screen to feel more restrained and intentional.
-
selmakcby Skill Code ReviewSenior code review specialist. Use PROACTIVELY after writing or modifying code. Reviews for quality, security, performance, and best practices.
-
selmakcby Skill API DesignBackend API design specialist. Use when building REST/GraphQL APIs, designing endpoints, data models, or backend architecture. Covers RESTful principles, HTTP semantics, error handling, versioning, and OWASP-aligned security.
-
selmakcby Skill Security ReviewAI-powered security vulnerability detection. Use PROACTIVELY after writing code that handles user input, authentication, API endpoints, payments, or sensitive data. Flags OWASP Top 10 issues with diff-aware scanning.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include audit-lexicon, update-lexicon, replay-ux-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.