Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
bruk-io Skill Skillsign Parser Attack TaxonomyThis skill provides a taxonomy of input parsing attacks relevant to signing specifications. Use when reviewing YAML parsing security, UTF-8 encoding attacks, path traversal in identifiers, whitespace normalization, size-based DoS, or canonical form manipulation. Covers duplicate keys, anchors/aliases, tag injection, BOM manipulation, null bytes, Unicode homoglyphs, and segment injection. Do NOT use for general web security unrelated to input parsing.
-
bruk-io Skill Skillsign Policy Engine PatternsThis skill provides security patterns for policy engine design in signing specifications. Use when reviewing trust policy format, rule evaluation order (first-match-wins), default action handling, max_age_days semantics, signer vs signer_org matching, require_signer_id_match behavior, CLI flag interactions with offline mode, or unsigned policy file risks. Do NOT use for general authorization policy design unrelated to signing verification.
-
bruk-io Skill Skillsign Spec Quality ChecklistThis skill provides a quality checklist for reviewing signing specification documents. Use when checking cross-reference accuracy, terminology consistency, algorithm consistency between signing and verification, error handling coverage, exit code mappings, format specifications, RFC 2119 compliance, implementability, versioning, or common spec anti-patterns. Do NOT use for general document review unrelated to technical specifications.
-
bruk-io Skill Skillsign Identity Attack PatternsThis skill provides attack patterns for identity spoofing, namespace squatting, and trust boundary violations in signing systems. Use when reviewing signer identity claims, skill_id ownership, SAN manipulation, certificate chain attacks, percent-encoding bypass, case sensitivity mismatches, org membership confusion, or policy evaluation attacks. Do NOT use for general identity/auth patterns unrelated to signing specifications.
-
chenxiaoyi0807 Bundle Spring Boot Domestic Enterprise DevelopmentComprehensive Spring Boot development skill covering auto-configuration, dependency injection, REST APIs, MyBatis-Plus, security, and enterprise Java applications (Domestic Standard)
-
claw-works Bundle Soul MemoryIntelligent memory management system v3.6.1 - reliable pre-response memory injection for OpenClaw with pure JSON CLI output, last-user-message query extraction, typed memory focus grouping, distilled summaries, and audit logging.
-
claw-works Skill Memory AuditComprehensive memory quality review across 6 dimensions: purity, freshness, coverage, clarity, relevance, and structure. Generates prioritized findings with specific memory references and actionable recommendations.
-
claw-works Bundle X OAUTH APIPost to X (Twitter) using the official OAuth 1.0a API. Use when asked to "post to X", "tweet this", "post on Twitter", create threads, delete tweets, or check account info. Free tier compatible. NOT for search, mentions, or media uploads (requires Basic+ tier).
-
claw-works Bundle SkillguardAudit OpenClaw skills for security risks before installation via SkillGuard API.
-
ashref-dev Bundle One Time SecretCreate one-time secret links with https://ots.ashref.tn for plaintext snippets or UTF-8 text files. Use when a user wants to securely share API keys, environment files, tokens, config text, or other sensitive text through a single-use link with optional passphrase protection.
-
wxmb01 Bundle ReviewEnd-to-end project, artifact, and code review for assessing completion, requirements coverage, architecture, implementation quality, testing, risks, documentation, readiness, and improvement opportunities. Use when Codex needs to audit a software or technical project, review a diff or PR, judge whether work is complete or ready, review an architecture or delivery plan, or produce a prioritized remediation plan.
-
leooooooow Bundle Checkout Friction AuditAudit checkout friction points and prioritize fixes that improve completed purchases without increasing risk. Use when the user reports high add-to-cart but low purchase rate, checkout abandonment spikes, or repeated payment/shipping complaints.
-
leooooooow Bundle Creator Performance AuditCreator Performance Audit for creators, ecommerce teams, and operators. Use when you need help with creator performance analysis for commerce teams.
-
leooooooow Bundle Listing Gap AuditAudit listing competitiveness by comparing your PDP/listing against top competitors and surfacing the highest-impact copy/proof gaps. Use when the user asks why conversion is lagging, wants PDP rewrite priorities, or needs a competitor benchmark before launch.
-
niekteg Skill DependabotComprehensive guide for configuring and managing GitHub Dependabot. Use this skill when users ask about creating or optimizing dependabot.yml files, managing Dependabot pull requests, configuring dependency update strategies, setting up grouped updates, monorepo patterns, multi-ecosystem groups, security update configuration, auto-triage rules, or any GitHub Advanced Security (GHAS) supply chain security topic related to Dependabot.
-
usmanskillsmd Skill ClawzembicLighthouse-style efficiency audit for OpenClaw. Scores your instance A+ to F across 6 categories (context injection, cron health, session bloat, config, skills, transcripts). Identifies wasted tokens,
-
usmanskillsmd Skill Threat Modelingthreat-modeling
-
usmanskillsmd Skill Skill 106SKILL
-
usmanskillsmd Skill Raini Skill Auditraini-skill-audit
-
usmanskillsmd Skill Minimal2minimal2
-
usmanskillsmd Skill Minimal3minimal3
-
usmanskillsmd Skill Minimal4minimal4
-
usmanskillsmd Skill API Securityapi-security
-
usmanskillsmd Skill Ethical AI Auditethical ai audit — production AI ethics workflows for machine learning and AI systems.
-
usmanskillsmd Skill Slug Testslug-test
-
usmanskillsmd Skill Afrexai Payroll Auditafrexai-payroll-audit
-
usmanskillsmd Skill Pytest Bddpytest bdd — comprehensive testing patterns and workflows for Python projects.
-
usmanskillsmd Skill Rspec Rubyrspec ruby — comprehensive testing patterns and workflows for Ruby projects.
-
usmanskillsmd Skill Afrexai Tech Debt Auditafrexai-tech-debt-audit
-
usmanskillsmd Skill Memory Guardmemory-guard
-
usmanskillsmd Skill Jmeter Setupjmeter setup — comprehensive testing patterns and workflows for Multi-language projects.
-
usmanskillsmd Skill Nunit Dotnetnunit dotnet — comprehensive testing patterns and workflows for C# projects.
-
usmanskillsmd Skill Pytest Asyncpytest async — comprehensive testing patterns and workflows for Python projects.
-
usmanskillsmd Skill Rust Testingrust testing — comprehensive testing patterns and workflows for Rust projects.
-
usmanskillsmd Skill Sast Semgrepsast semgrep — comprehensive testing patterns and workflows for Multi-language projects.
-
usmanskillsmd Skill Swift Xctestswift xctest — comprehensive testing patterns and workflows for Swift projects.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include skillsign-parser-attack-taxonomy, skillsign-policy-engine-patterns, skillsign-spec-quality-checklist. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.