Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aihip Bundle Apk AnalyzerAnalyze Android APK files: extract metadata, parse AndroidManifest.xml, audit permissions, verify signatures/certificates, inspect DEX files, detect native libraries and third-party SDKs, and perform security auditing. Use when asked to analyze APK, inspect permissions, check APK signature, review manifest, audit Android app security, or perform APK 解析/安全审计.
-
aihip Bundle Android Project AnalyzerAnalyze an Android project codebase to produce a comprehensive report covering: project structure and modules, feature inventory, architecture pattern (MVVM/MVI/MVP/Clean Architecture), dependency list with versions, build configuration, code quality indicators, and potential issues. Use when asked to analyze an Android project, understand its architecture, audit dependencies, review project health, assess code quality, or produce a technical overview. Trigger phrases: analyze android project, project architecture review, dependency audit, 分析安卓项目, 项目架构分析, 依赖审计, 代码质量分析.
-
233i Skill Security And Hardening加固代码以防止漏洞。适用于处理用户输入、认证、数据存储或外部集成时,也适用于构建任何接收不可信数据、管理用户会话,或与第三方服务交互的功能。
-
jonatangs777 Bundle Security Threat Modeling FoundationsBuilds threat models with attacker capability analysis and control-mapping logic.
-
madeinlowcode Bundle Software EngineerUltra Senior Software Engineer (15+ years experience) with absolute mastery across 8 levels - from CS fundamentals and algorithms through clean code, design patterns, system design, DevOps, security, AI-assisted development, and technical leadership. Use this skill for any software development task including implementing features, writing production-grade code, debugging, testing, code reviews, refactoring, performance optimization, and strategic technical decisions. Designed for building MVPs, Micro-SaaS and SaaS with engineering excellence from day one.
-
jonatangs777 Bundle Chatbot Chatbot Security Hardening Skill 2026Construye chatbots de alto rendimiento para chatbot security hardening con dialogo robusto, guardrails claros y monitoreo continuo de calidad.
-
augustscl Skill Skill VetterSecurity-first skill vetting for AI agents. Use before installing any skill from ClawHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
-
whchoi98 Skill Code ReviewUse when reviewing code changes for bugs, security issues, and quality. Confidence-based scoring filters false positives.
-
mahabdalla Skill Pr ReviewReview PyTorch pull requests for code quality, test coverage, security, and backward compatibility. Use when reviewing PRs, when asked to review code changes, or when the user mentions "review PR", "code review", or "check this PR".
-
mahabdalla Skill CamsnapCapture frames or clips from RTSP/ONVIF cameras. Grabs snapshots, video clips, and motion events from IP cameras, security cameras, and video streams. Use when the user wants to take a snapshot from a camera, record a clip from an RTSP stream, monitor motion on a security camera, discover ONVIF devices on the network, or configure camera access for automated surveillance capture.
-
mahabdalla Skill Skill Creator 3Create, edit, improve, or audit AgentSkills. Use when creating a new skill from scratch or when asked to improve, review, audit, tidy up, or clean up an existing skill or SKILL.md file. Also use when editing or restructuring a skill directory (moving files to references/ or scripts/, removing stale content, validating against the AgentSkills spec). Triggers on phrases like "create a skill", "author a skill", "tidy up a skill", "improve this skill", "review the skill", "clean up the skill", "audit the skill".
-
mahabdalla Skill PayloadUse when working with Payload CMS projects (payload.config.ts, collections, fields, hooks, access control, Payload API). Use when debugging validation errors, security issues, relationship queries, transactions, or hook behavior.
-
mahabdalla Skill Security AuditSecurity scanning and vulnerability detection. Use when: authentication, authorization, payment processing, user data. Skip when: read-only operations, internal tooling.
-
mahabdalla Skill Solidity SecurityMaster smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.
-
mahabdalla Skill HealthcheckHost security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).
-
mahabdalla Skill Openwork DebugDebug OpenWork sidecars, config, and audit trail
-
mahabdalla Skill Anti Reversing TechniquesUnderstand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Use this skill when analyzing malware evasion techniques, when implementing anti-debugging protections for CTF challenges, when reverse engineering packed binaries, or when building security research tools that need to detect virtualized environments.
-
mahabdalla Skill Author ContributionsIdentify all files a specific author contributed to on a branch vs its upstream, tracing code through renames. Use when asked who edited what, what code an author contributed, or to audit authorship before a merge. This skill should be run as a subagent — it performs many git operations and returns a concise table.
-
mahabdalla Skill Django VerificationVerification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.
-
mahabdalla Skill Springboot SecuritySpring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
-
mahabdalla Skill Best PracticesApply modern web development best practices for security, compatibility, and code quality. Use when asked to "apply best practices", "security audit", "modernize code", "code quality review", or "check for vulnerabilities".
-
mahabdalla Skill Find BugsFind bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.
-
mahabdalla Skill Find Bugs 2Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.
-
mahabdalla Skill Solidity Security 2Master smart contract security best practices, vulnerability prevention, and secure Solidity development patterns.
-
mahabdalla Skill Springboot VerificationVerification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.
-
mahabdalla Skill Stride Analysis PatternsApply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.
-
mahabdalla Skill Anti Reversing Techniques 2AUTHORIZED USE ONLY: This skill contains dual-use security techniques. Before proceeding with any bypass or analysis: > 1.
-
mahabdalla Skill Threat Mitigation MappingMap identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control effectiveness.
-
nocode-tegethoff Skill Security AuditSecurity Audit
-
mahabdalla Skill Codebase Cleanup Deps AuditYou are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.
-
mahabdalla Skill Protocol Reverse EngineeringComprehensive techniques for capturing, analyzing, and documenting network protocols for security research, interoperability, and debugging.
-
mahabdalla Skill Security Requirement ExtractionDerive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases.
-
withcrux Bundle Analyzing JWT Token SecurityAnalyze JSON Web Tokens (JWTs) for common security vulnerabilities including algorithm confusion attacks (RS256 to HS256), none algorithm bypass, weak secret brute-forcing, and claim manipulation. Practice in isolated lab environments to understand authentication bypass and privilege escalation via token forgery.
-
withcrux Bundle Performing Password Spray In LabExecute controlled password spray attacks against simulated authentication services in isolated lab environments to understand how attackers test large numbers of accounts with a small set of common passwords. Covers SSH, web login, and API endpoint spraying with rate-limit awareness and detection evasion understanding for defensive security purposes.
-
paulofelipem Bundle Laravel Best PracticesLaravel best practices and architecture patterns for building production-ready applications. Use when writing, reviewing, or refactoring Laravel code to ensure proper patterns for service providers, dependency injection, security, Eloquent, and performance.
-
withcrux Bundle Analyzing Network Packet CapturesAnalyze PCAP files and live network captures using Wireshark and tshark to extract credentials, reconstruct HTTP sessions, identify malicious traffic patterns, and detect protocol anomalies in isolated lab environments. Core network forensics and traffic analysis skill for security professionals.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include apk-analyzer, android-project-analyzer, security-and-hardening. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.