Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
nous-hermeshub Skill Information Security Manager Iso27001ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use when designing an ISMS, running security risk assessments, implementing controls, pursuing ISO 27001 certification, preparing security audits, res...
1 -
pjt222 Skill Conduct Gxp Audit 11GxP-Audit von computergestuetzten Systemen und Prozessen durchfuehren. Umfasst Auditplanung, Eroeffnungssitzungen, Beweiserhebung, Befundklassifizierung (kritisch/wesentlich/geringfuegig), CAPA-Erstellung, Abschlusssitzungen, Berichtserstellung und Nachverfolgungsverifizierung. Anzuwenden fuer geplante interne Audits, Lieferantenqualifizierungsaudits, Inspektionsbereitschaftsbewertungen, anlassbezogene Audits aufgrund von Abweichungen oder Datenintegritaetsbedenken oder regelmaessige Konformitaetspruefungen validierter Systeme.
-
pjt222 Skill Review UX UI 11Bewertet User Experience und Interface-Design anhand von Nielsens Heuristiken, WCAG-2.1-Zugaenglichkeitsrichtlinien, Tastatur- und Screenreader-Audit, Nutzerfluss-Analyse, Kognitive-Last-Bewertung und Formular-Usability-Pruefung. Verwenden bei einem Usability-Review vor dem Release, bei der Bewertung der WCAG-2.1-Zugaenglichkeitskonformitaet, bei der Bewertung von Nutzerfluessen auf Effizienz, beim Review von Formulardesign oder bei einer heuristischen Evaluation einer bestehenden Oberflaeche.
-
pjt222 Skill Defend Colony 11Implementieren layered collective defense using alarm signaling, role mobilization, and proportional response. Umfasst threat detection, alert propagation, immune response patterns, escalation tiers, and post-incident recovery for distributed systems and organizations. Verwenden wenn designing defense-in-depth where no single guardian covers all threats, building incident response that scales with severity, or when current defense is over-reactive to every alert or under-reactive to genuine threats.
-
pjt222 Skill Polish Claw Project 11Contribute to OpenClaw ecosystem projects (OpenClaw, NemoClaw, NanoClaw) through a structured 9-step workflow: target verification, codebase exploration, parallel audit, finding cross-reference, and pull request creation. Emphasizes false positive prevention and project convention adherence.
-
pjt222 Skill Audit Dependency Versions 11Audit project Abhaengigkeiten for version staleness, security Schwachstellen, and compatibility issues. Umfasst lock file analysis, upgrade path planning, and brechende Aenderung assessment. Verwenden vor a release to ensure Abhaengigkeiten are current and secure, waehrend periodic maintenance reviews, nach receiving a security advisory, when upgrading to a new language version, vor submitting to CRAN or npm, or when inheriting a project to assess its Abhaengigkeit health.
-
pjt222 Skill Implement Audit Trail 11Auditpfad-Funktionalitaet fuer R-Projekte in regulierten Umgebungen implementieren. Umfasst Protokollierung, Provenienzverfolg, elektronische Signaturen, Datenintegritaetspruefungen und 21-CFR-Part-11-Konformitaet. Anzuwenden wenn eine R-Analyse elektronische Aufzeichnungskonformitaet (21 CFR Part 11) erfordert, wenn nachverfolgt werden soll wer was wann in einer Analyse getan hat, bei der Implementierung von Datenprovenienztracking oder beim Erstellen manipulationssicherer Analyseprotokolle fuer Behoerdeneinreichungen.
-
pjt222 Skill Navigate Dach Bureaucracy 11Step-by-step guidance for DACH-specific governmental procedures including Anmeldung, Finanzamt registration, health insurance enrollment, and social security coordination. Verwenden nach arriving in a DACH country and needing to complete mandatory registrations, vor a specific appointment to understand what to expect, when an initial registration attempt was rejected, when transitioning zwischen DACH countries, or when handling registrations for dependents alongside your own.
-
rudironsoni Skill Dotnet API Security 8Secures ASP.NET Core APIs. Identity, OAuth/OIDC, JWT bearer, passkeys, CORS, rate limiting.
-
pjt222 Skill Assess Github Repo Security 2Read-only audit of a GitHub repository's security posture. Gathers ref protection (rulesets AND classic branch protection), Actions token permissions, code and supply-chain features (Dependabot, secret scanning, push protection, CodeQL), and repo hygiene toggles via `gh api`, then classifies findings against essential / recommended / advanced tiers into a PASS/GAP report. Makes NO changes. Use when reviewing a repo before open-sourcing or a release, auditing a public user-owned repo whose CI auto-commits to the default branch, verifying a hardening change actually took effect, or producing a baseline security posture report for a repository.
-
pjt222 Skill Harden Github Repo Security 2Apply GitHub repository security protections tier by tier — rulesets, read-only Actions token, secret scanning + push protection, Dependabot, and (gated) required status checks / required PR with a GitHub App bypass for a CI auto-commit bot. Mutating and confirmation-gated: always assess first, apply the no-regret baseline, then decide required checks separately. Use when hardening a public user-owned repo after an audit, when a repo has no branch protection, when adding required checks without breaking a bot that pushes to the default branch, or when provisioning a GitHub App bypass actor for trusted automation.
-
pjt222 Skill Security Audit Codebase 11Ein Sicherheitsaudit einer Codebasis durchfuehren und auf offengelegte Geheimnisse, verwundbare Abhaengigkeiten, Injection-Schwachstellen, unsichere Konfigurationen und OWASP-Top-10-Probleme pruefen. Verwenden vor der Veroeffentlichung oder dem Deployment eines Projekts, bei periodischen Sicherheitspruefungen, nach dem Hinzufuegen von Authentifizierung oder API-Integration, vor dem Open-Sourcing eines privaten Repositories oder bei der Vorbereitung auf ein Sicherheits-Compliance-Audit.
-
jeremylongshore Skill Secret Scanner 2Scan secret scanner operations. Auto-activating skill for Security Fundamentals. Triggers on: secret scanner, secret scanner Part of the Security Fundamentals skill category. Use when working with secret scanner functionality. Trigger with phrases like "secret scanner", "secret scanner", "secret".
-
projectious-work Skill Repository Portfolio Review 2Review one or more GitHub repositories for governance, documentation, licensing, privacy, security, and portfolio-boundary hygiene; deduplicate and create repository-local issues for verified remediation work. Use for portfolio reviews, repository standards audits, or baseline governance work.
0 -
cyberstrikeus Skill Cis Tomcat8 V110 10 17Setting Security Lifecycle Listener (Automated)
-
diegosouzapw Bundle Safe Commit 2⚠️ MANDATORY - YOU MUST invoke this skill when committing. Complete commit workflow with all safety checks. Invokes security-scan, quality-check, and run-tests skills. Shows diff, gets user approval, creates commit with conventional format. NO AI attribution. User approval REQUIRED except during PR creation. NEVER commit manually.
54 -
comeonoliver Skill Security Audit 2Security Audit
61 -
diegosouzapw Bundle Codex Code Review 2Perform comprehensive code reviews using OpenAI Codex CLI. This skill should be used when users request code reviews, want to analyze diffs/PRs, need security audits, performance analysis, or want automated code quality feedback. Supports reviewing staged changes, specific files, entire directories, or git diffs.
54 -
diegosouzapw Bundle Software Code Review 2Use when reviewing code, pull requests, or diffs. Provides patterns, checklists, and templates for systematic code review with a focus on correctness, security, readability, performance, and maintainability.
54 -
diegosouzapw Bundle API Fuzzing For Bug Bounty 2This skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques.
54 -
diegosouzapw Bundle Architecture Docs 2Use this skill when creating, updating, or maintaining ARCHITECTURE.md files, when users ask about "my architecture documentation" or "architecture", when generating presentations/slides/PowerPoint from architecture documentation, when generating diagrams from architecture documentation, when validating/checking/auditing architecture (including BIAN alignment, META layers, standards compliance), or when answering questions about documented components, data structures, integrations, security, performance, deployment, technology stack, or architectural decisions
54 -
diegosouzapw Bundle Create Auth Skill 5Build Better Auth integrations for TS/JS apps with secure defaults. Use for implementation or migration work (not just review). Use when the user requests this capability.
54 -
aibot88 Bundle Scanning Database Security 2Process use when you need to work with security and compliance. This skill provides security scanning and vulnerability detection with comprehensive guidance and automation. Trigger with phrases like "scan for vulnerabilities", "implement security controls", or "audit security".
3 -
johnalbertini14-glitch Bundle Install Vt Sentinel 2Install or upgrade VT Sentinel security plugin. Use when the user asks to install, set up, enable, update, or upgrade VT Sentinel, VirusTotal scanning, malware protection, or file security scanning. Handles fresh installs and upgrades from any previous version.
1 -
aibot88 Bundle Encrypting And Decrypting Data 2Validate encryption implementations and cryptographic practices. Use when reviewing data security measures. Trigger with 'check encryption', 'validate crypto', or 'review security keys'.
3 -
aibot88 Bundle Semgrep Code Pattern Scanner 2Runs Semgrep against a codebase using official or custom rule registries and outputs a grouped report of security anti-patterns, deprecated API usage, and policy violations. Supports 30+ languages and produces SARIF output.
3 -
aibot88 Bundle Semgrep Custom Pattern LibraryBuilds custom Semgrep rules using the semgrep YAML rule syntax with metavariable-pattern, pattern-either, and taint-mode analysis. Generates rule packs for OWASP Top 10 detection across Python, JavaScript, and Go codebases.
3 -
aibot88 Bundle Snyk License Compliance CheckerUses the Snyk CLI and REST API to audit open-source dependencies for license compliance across npm, PyPI, Maven, and Go modules. Generates SPDX license reports and flags copyleft violations.
3 -
johnalbertini14-glitch Bundle Auto Reply 2Instagram DM auto-reply system. DM monitoring, reading, replying, security check (injection rejection). Use when checking Instagram DMs, reading unread messages, replying to DMs, setting up DM monitoring cron jobs, or handling DM auto-reply workflows. Triggers on: Instagram DM, DM check, DM reply, DM auto-reply, dm-alert.
1 -
aibot88 Bundle Hashicorp Vault Secret Scanner 2Scans codebases for hardcoded secrets using HashiCorp Vault SDK and truffleHog patterns. Integrates with Vault Transit engine for automatic secret rotation and re-encryption of detected credentials.
3 -
aibot88 Bundle NPM Package Supply Chain AuditorAudits npm dependencies for supply chain risks using npm audit, Socket.dev API, and Snyk vulnerability database. Detects typosquatting, install scripts, and maintainer account takeovers.
3 -
aibot88 Bundle Semgrep Pattern Matching AuditorLeverages the Semgrep OSS engine and semgrep-rules registry to perform deep static analysis across 30+ languages. Combines taint tracking with pattern matching for OWASP Top 10 vulnerability detection.
3 -
aibot88 Bundle Sonarqube Quality Gate ExplainerFetches the latest SonarQube project analysis result, explains why the Quality Gate failed in plain English, and links to specific issues. Covers coverage drops, new bugs, and security hotspots. Supports SonarQube Server and SonarCloud. Diagnostic only.
3 -
johnalbertini14-glitch Bundle Clawback 2Gmail security proxy with policy enforcement, approval workflows, and audit logging. Use when the user wants to read, search, or send Gmail with guardrails — send actions may require human approval before executing.
1 -
aibot88 Bundle Stripe Webhook Signature VerifierVerifies Stripe webhook payload signatures using the Stripe.js SDK and the stripe.webhooks.constructEvent method. Validates the Stripe-Signature header against the raw request body and a configured endpoint secret. Handles tolerance windows for replay attack prevention and logs verification failures to Datadog via the Datadog Logs API.
3 -
aibot88 Bundle Horcrux Shamir Secret File SplitterHorcrux splits files into encrypted fragments using Shamir Secret Sharing, so you can distribute pieces across locations and reconstruct the original with a configurable threshold — no password required.
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include information-security-manager-iso27001, conduct-gxp-audit, review-ux-ui. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.