Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
senoritadeveloper01 Skill Spring SecurityUse this skill when implementing or reviewing security in a Spring Boot application. Covers authentication, authorization, input validation, secure configuration, and API security best practices.
-
riskresponse Bundle Soc2 System DescriptionExpert guidance for writing and updating SOC 2 system descriptions with focus on Security (TSC SEC) and Availability (TSC A) trust service criteria. Optimized for experienced compliance teams in SaaS and Healthcare industries. Use when drafting system descriptions, updating existing descriptions for annual audits, or ensuring completeness of SOC 2 documentation.
-
riskresponse Bundle Iso27001 Internal AuditorExpert guidance for conducting ISO 27001:2022 internal audits using Vanta platform. Covers the complete 7-step audit process, evidence analysis, nonconformity identification, and audit reporting for SaaS companies. Use when performing annual ISMS internal audits, reviewing Vanta-exported evidence, or documenting audit findings.
-
berrzebb Skill Consensus Loop GuideGuide for writing evidence packages for the consensus-loop watch file. Use when preparing code review submissions, structuring feedback evidence, or addressing audit rejections.
-
berrzebb Skill Consensus Loop MergeSquash-merge a worktree branch into the target branch with a structured commit message. Use after audit consensus and retrospective completion.
-
berrzebb Bundle Quorum VerifyRun all done-criteria checks (CQ/T/CC/CL/S/I/FV/CV) and produce a pass/fail verification report. Use after implementing code, before submitting evidence to the quorum audit.
-
daianepepes-lab Bundle SecurityAudit and fix security vulnerabilities across web apps, APIs, databases, auth systems, and infrastructure. Use when asked to review security, fix vulnerabilities, implement auth, or harden a system.
-
salihcantekin Bundle Code Security AuditCode Security Audit Copilot Skill
-
salihcantekin Bundle Dependency ScanningDependency Scanning Copilot Skill
-
salihcantekin Bundle Authentication PatternsAuthentication Patterns Copilot Skill
-
alubiama Bundle Skill Quality GateAudit the quality of a local skill after creation or revision. Use when deciding whether a skill is ready to lock, needs light or heavy revision, should be merged, or is not worth further investment. Evaluates triggers, scope, overlap, uncertainty handling, handoff quality, and actionability, then returns concrete upgrade steps or a do-not-invest verdict.
-
alpha-park Skill Genpark Legal Loophole FinderScrapes and parses corporate Terms of Service, Return Policies, and Warranty documents to find and exploit legal loopholes for maximum user payout.
-
leorickcoder Bundle BrandBrand voice, visual identity, messaging, and brand-asset governance. Use when Codex needs to define or audit brand guidelines, extract brand context from a guideline document, validate brand assets, compare palettes, or sync brand rules into design-token artifacts before interface or presentation work.
-
berrzebb Bundle Consensus Loop RetrospectExtract learnings from audit history and conversation, manage memories, clean up stale entries. Use after completing a track, during retrospective (③ memory step), at end of session, or anytime the user wants memory maintenance. Triggers on 'what did we learn', 'memory cleanup', 'review learnings', 'retrospective', 'update memories', '회고', '메모리 정리'.
-
bregman-arie Skill Triage Suspected Secret ExposureContain and respond to a suspected credential/secret exposure without increasing blast radius.
-
xcrrr Skill Security AuditorUse this skill when auditing code for security vulnerabilities, reviewing authentication and authorization logic, or checking OWASP compliance. Trigger phrases: 'audit this for security', 'is this secure', 'check for vulnerabilities', 'OWASP review'. Not for penetration testing tooling or network security configuration.
-
jamestorrevillas Skill Threat ModelingThreat Modeling
-
whyashthakker Bundle Code ReviewPerforms a thorough code review covering complexity, security, and style. Use when the user asks for a review, asks to check this code, or mentions PR review.
-
vincenthsiehisme Bundle Skill ReviewerReview, audit, and improve Claude Code skills based on Anthropic best practices. Use this skill whenever the user wants to evaluate skill quality, get feedback on a SKILL.md file, check if a skill follows best practices, improve an existing skill, or diagnose why a skill isn't triggering or performing well. Trigger on phrases like "review my skill", "is this skill good?", "why isn't my skill working?", "audit this skill", "improve my skill", "check my SKILL.md".
-
yuexueyu Skill Code Audit代码审计技能 - 安全审计、代码质量审查、漏洞挖掘。当你涉及安全检查、漏洞修复、权限/认证逻辑修改、密钥管理、输入验证、OWASP相关问题时必须使用此技能。即使用户只是说"检查下安全"或"加个权限判断",也应触发。
-
yuexueyu Skill Mobile Security移动安全与渗透测试技能 - Android/iOS安全评估、Frida Hook、SSL Pinning绕过、Root/越狱检测绕过、漏洞挖掘、防护对抗、OWASP MASTG。当你涉及移动应用安全测试、Android/iOS渗透、Frida Hook、SSL Pinning、Root检测绕过、漏洞挖掘、红队攻击、防护对抗时必须使用此技能。即使用户只是说"测试这个APP"或"绕过检测",也应触发。
-
johnymontana Skill Neo4j Memory TraceRecord and query reasoning traces — tool calls, decisions, and skill invocations — for full audit trails. Use to capture why you made a decision and what evidence you used.
-
dreydrey9000 Bundle Content Market FitContent Market Fit 2026 — Luis Carrillo's framework for extracting creator/client DNA through a structured interview process. Three corners: YOU (Worldview), AUDIENCE (Bridge), OFFER (Invitation). Use when onboarding a new client, profiling a creator, building a clone, or auditing content strategy. Triggers: "content market fit", "onboard client", "profile this creator", "extract worldview", "audience bridge", "who is their audience", "clone this person", "audit their content", new client intake, creator intelligence extraction.
-
koshkinvv Bundle IOS SecurityiOS security expert skill covering Keychain Services, biometric authentication (Face ID/Touch ID), CryptoKit encryption, Sign in with Apple, OAuth2, certificate pinning, data protection, privacy manifests, and app hardening. Use this skill whenever the user works on iOS security features — storing credentials, encrypting data, authenticating users, handling permissions, or protecting the app. Triggers on: keychain, biometric, face id, touch id, security, encryption, cryptokit, sign in with apple, oauth, token storage, certificate pinning, privacy manifest, ATS, app transport security, jailbreak, secure enclave, data protection, permissions, tracking transparency, password storage, credential management, sensitive data, SecItem, LAContext, authentication flow, or any iOS code that handles secrets, tokens, or user identity.
-
anup4khandelwal Bundle Secrets Detector1. Skill Name
-
anup4khandelwal Bundle API Security Audit1. Skill Name
-
anup4khandelwal Bundle Auth Flow Reviewer1. Skill Name
-
anup4khandelwal Bundle OAUTH Scope Auditor1. Skill Name
-
anup4khandelwal Bundle JWT Policy Validator1. Skill Name
-
anup4khandelwal Bundle Sast Policy Enforcer1. Skill Name
-
alissonlinneker Bundle ShieldOrchestrates security scanning and autonomous penetration testing. Runs Shannon pentester with Semgrep SAST, gitleaks secrets scanning, and dependency audits. Consolidates findings, proposes code fixes with diffs, calculates risk scores, and creates GitHub issues. Invoke with /shield.
-
alissonlinneker Skill Shield 2Orchestrates security scanning and autonomous penetration testing. Runs Shannon pentester with Semgrep SAST, gitleaks secrets scanning, and dependency audits. Consolidates findings, proposes code fixes with diffs, calculates risk scores, and creates GitHub issues. Invoke with /shield:shield (plugin) or /shield (standalone).
-
kyuhyi Skill Webapp Security웹앱 보안 체크리스트 및 구현 가이드. 새 프로젝트 생성 시 자동으로 보안 모범 사례를 적용합니다.
-
joaopaulolndev Skill Code ReviewPerform comprehensive code reviews on PHP/Laravel/Filament projects. Analyze code quality, security, performance, and maintainability.
-
realwigu Bundle ReviewReview Playwright tests for quality. Use when user says "review tests", "check test quality", "audit tests", "improve tests", "test code review", or "playwright best practices check".
-
mrlynn Bundle Mongodb Devrel AdvisorAlways-on conventions advisor for MongoDB DevRel projects providing architecture guidance, branding rules, naming conventions, database patterns, and security best practices
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include spring-security, soc2-system-description, iso27001-internal-auditor. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.