Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
viggyv Bundle Security AuditorYou are an expert at identifying security vulnerabilities in code.
-
grp06 Skill Execplan Improve 2Reads an existing ExecPlan, deeply analyzes every referenced file and code path in the codebase, then rewrites the plan with concrete, code-grounded improvements. Use when user asks to improve an execplan, review a plan, make a plan better, audit an execplan, refine a plan, strengthen a plan, or says "improve the plan."
-
lucasvpimentel Skill General Security Awareness---
-
jasonwangyvr Skill Review Pr IssuesReview a GitHub PR's CI status, unresolved review threads, and bugbot issues, then create a fix plan. Use when the user asks to review PR issues, check CI status, check bugbot comments, audit open review feedback, or prepare a PR for merge.
-
ksjpswaroop Skill Unsafe SkillDemo of unsafe patterns for audit testing.
-
subashmurugandev Bundle Security Best PracticesSecurity best practices for OWASP compliance and secure development
-
cduggn Bundle Checking Repo TrustAnalyzes GitHub repositories for trust and quality signals including popularity, activity, security posture (OpenSSF Scorecard), and maturity. Use when evaluating whether to adopt or depend on an open-source repository or skill.
-
nickcuypers Bundle Angular Deps AuditAudit Angular dependency drift, security exposure, and CI impact without mutating files; produce deterministic upgrade planning output.
-
aaroncowley Bundle Claude Security Reviewskill.md — Claude Code (Opus 4.5) Skill: Security Code Reviews
-
ashyrion Bundle Security Compliance GuardSecurity and compliance specialist. Use for secret scanning, public-repo safety checks, and release-time compliance gates.
-
rongyuzzz Bundle Paper Reviewer Strategic Audit以顶会审稿人视角对论文进行严苛评审并给出可执行改稿策略。Use when users ask reviewer-style full-paper critique、reject-oriented audit、投稿前风险排查、or strategic revision advice for conference submission.
-
wrsmith108 Bundle Claude Skill Security AuditorSecurity Auditor Skill
-
toddward Skill Runbook Validator 2Use this skill to validate incident runbooks against team standards. Triggers when asked to review, validate, check, or audit a runbook file. Also triggered automatically by the post-write hook when a runbook file is created or modified.
-
manzarimalik Bundle Software ArchitectureComprehensive guide for production-ready Python backend development and software architecture at scale. Use when designing APIs, building backend services, creating microservices, structuring Python projects, implementing database patterns, writing async code, or any Python backend/server-side development task. Covers Clean Architecture, Domain-Driven Design, Event-Driven Architecture, FastAPI/Django patterns, database design, caching strategies, observability, security, testing strategies, and deployment patterns for high-scale production systems.
-
misfitdev Bundle Frank GrimesA clinical, pessimistic review process for systematically destroying, rebuilding, and hardening ideas or code. Use for code review (especially AI-generated), architecture review, pre-mortems, security reviews, incident response fixes, and any request to “red team”, “critique”, “find problems with”, or “do a pre-mortem on” something.
-
koaedo Skill Security Audit보안 감사 워크플로우. 보안 검토, 취약점 확인, 보안 점검, 코드 보안 감사 요청 시 사용.
-
t3chxn Skill Code Review ChecklistComprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability
-
t3chxn Skill API Security Best PracticesImplement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities
-
kpbray Bundle SecurityImplements Row-Level Security (RLS) and Object-Level Security (OLS) for Power BI models. Use for data access control, dynamic security, and multi-tenant scenarios.
-
keithagroves Bundle Code ReviewPerforms thorough code reviews focusing on correctness, security, performance, and maintainability. Use when reviewing pull requests, examining code changes, or auditing existing code.
-
enbyaugust Bundle Check Your WorkOrchestrates 6 quality agents in parallel (duplicate-detector, jenny, deep-bug-hunter, security, performance, correctness) with severity validation. Use when user says "check your work", "review what we wrote", "quality check", or after writing new features.
-
vadimcomanescu Bundle Security ComplianceSecurity and compliance workflow for designing defense-in-depth controls, performing threat modeling and risk assessments, and mapping mitigations to frameworks (SOC2/ISO27001/GDPR/HIPAA). Use when reviewing security posture, shipping sensitive features, preparing compliance evidence, or running a lightweight secrets scan.
-
vadimcomanescu Bundle Code ReviewerHigh-signal code review workflow for pull requests and patches: correctness, readability, API/UX, performance, security, and maintainability. Use when reviewing diffs/PRs, writing review comments, proposing fixes, or producing a structured review report with actionable follow-ups.
-
vadimcomanescu Bundle Senior SecopsSecurity operations workflow for vulnerability triage, incident response, detection/alerting improvements, and post-incident hardening. Use when responding to security alerts, reviewing logs for suspicious activity, building incident playbooks, or running quick log summaries during triage.
-
mehdiozdemir Skill Code ReviewerComprehensive code review for bugs, security vulnerabilities, performance issues, best practices violations, and code quality problems. Use when reviewing pull requests, analyzing code changes, auditing implementations, or performing quality checks on any codebase.
-
mehdiozdemir Skill Security ScannerAnalyzes code for security vulnerabilities, misconfigurations, and potential attack vectors. Use when auditing codebases for OWASP Top 10 vulnerabilities, reviewing authentication/authorization implementations, checking for secret exposure, validating cryptographic practices, or performing security-focused code reviews.
-
spindizzy5 Skill Senior Python FastapiWrite and review production-grade Python (3.10+) code using senior best practices (typing, testing, architecture, security, performance, maintainability) and implement FastAPI services (routers, dependencies, Pydantic models, auth, background tasks, middleware, exception handling, OpenAPI, async I/O, DB integration); use for new APIs, refactors, bugfixes, and standards enforcement.
-
nand1234 Skill Bdd Test Case ArchitectGenerates BDD-style test scenarios for requirements and distributes them across the testing pyramid (Unit, API, UI/E2E). Includes performance and security checks while ensuring no test redundancy.
-
belokonm Skill Dependency ManagerExpert at package management and supply chain security. Use when managing dependencies, updating packages, resolving version conflicts, ensuring supply chain security, or auditing vulnerabilities in project dependencies.
-
belokonm Bundle Incident ResponderUse when user needs security incident response, operational incident management, evidence collection, forensic analysis, or coordinated response for outages and breaches.
-
belokonm Bundle Ad Security ReviewerUse when user needs Active Directory security analysis, privileged group design review, authentication policy assessment, or delegation and attack surface evaluation across enterprise domains.
-
belokonm Bundle Powershell Security HardeningExpert in Windows security hardening and PowerShell security configuration. Specializes in securing automation, enforcing least privilege, and aligning with enterprise security baselines. Use for securing PowerShell environments and Windows systems. Triggers include "PowerShell security", "constrained language mode", "JEA", "execution policy", "security baseline", "PowerShell logging".
-
smithjoshua Bundle File OrganizerOrganize files using the PARA method (Building a Second Brain). Intelligent categorization into Projects, Areas, Resources, and Archive with inbox workflow. Triggers on "organize my files", "organize my downloads", "second brain", "PARA method", "clean up files", "declutter". Creates numbered PARA folders (0-Inbox, 1-Projects, 2-Areas, 3-Resources, 4-Archive), renames poorly-named files, and maintains complete audit trails.
-
trotsky1997 Bundle Codebase ReadingSystematic methodology for reading and understanding large codebases efficiently. Use when (1) Understanding a new or unfamiliar codebase quickly, (2) Preparing to modify or extend existing code safely, (3) Debugging complex issues requiring deep code understanding, (4) Onboarding new team members to a codebase, (5) Performing code audits or security reviews, (6) Refactoring legacy code with confidence, (7) Creating documentation for existing systems, (8) Tracing execution flows and data transformations
-
snakeo Skill Refactor FlaskRefactor Flask code to improve maintainability, readability, and adherence to best practices. This skill transforms Flask applications using the application factory pattern, Blueprint organization, and service layer separation. It addresses fat route handlers, missing error handling, improper context local usage, and security issues. Apply when you notice global app instances, routes without Blueprints, business logic in handlers, or missing CSRF protection.
-
ikajakam Bundle JshJavaScript security auditor using jsh_helper for reconnaissance
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include Security Auditor, execplan-improve, general-security-awareness. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.