Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
nowely Bundle AuditMeasures a document against two rulers: whether fresh readers get the right answer, and whether every claim about behaviour is true of the code. Returns a reader profile, a claim ledger, reader scores and the list of what broke. It never proposes wording; `rewrite` does that.
-
nowely Bundle RewriteWrites the text in rounds: one candidate, then critics with lenses that differ, then edits declared with the check behind each, until the owner reads a round and says whether they would send it as it is. Starts from a skeleton `rethink` agreed, or from the failures an `audit` measured. Proposes; writes into your tree only on your word.
-
gl0di Skill Helper 4Call when the user says: analyze my repo for security issues
-
stackhawk Bundle Stackhawk OptimizeAnalyze a codebase and produce an optimal HawkScan setup — tech flags, scan-policy plugin selection, and stackhawk.yml corrections — then apply it as a non-destructive trial, run ONE trial scan, and promote or discard. Use when the user asks to "optimize my scan", "tune HawkScan", "make my scan faster", "reduce false positives", "pick the right plugins/policy for my app", or invokes /optimize. Also invoked automatically by the hawkscan skill on every fresh stackhawk.yml (Phase 0c) to set up the scan policy + tech flags (Setup mode), and re-runnable anytime via /optimize; the metrics Refine mode is surfaced when a scan is slow. Do NOT use for: a normal security scan or fixing vulnerabilities (use the hawkscan skill); querying existing findings or posture (use the api skill); or editing stackhawk.yml without optimizing/scanning. Requires an onboarded StackHawk app + env and a `hawk` build whose `hawk op` has the `policy` write commands.
-
holmesrm88 Bundle Review PanelOrchestrate a panel of isolated review subagents over a completed story's full diff, then triage their findings into new harness features, tickets, or inline fixes. Runs security, ghost-test, clean-code, and correctness reviewers in parallel with no cross-talk, deduplicates and ranks what they find, and presents one batch for human approval. Use when all features for a story are committed and the work is heading toward a PR — "run the panel", "review the story", "we're ready for PR", "check PROJ-1234 before I push". Do NOT use for reviewing a single file or a work-in-progress diff (use java-code-review directly) or for implementing features (use harness).
-
holmesrm88 Bundle Java Code ReviewReview Java code against a senior-engineer checklist covering correctness, resource handling, concurrency, exception discipline, API design, persistence, and security, and return prioritized findings with file locations and concrete fixes. Use this whenever the user asks for review, critique, feedback, or a second opinion on Java or Kotlin code — a pull request, a diff, a single class, a method, or "does this look right?" — and also proactively before the user submits Java code they have just written or asks whether it is ready to ship. Use it even when the request is casual ("take a look at this", "anything wrong here?"). This is for evaluating specific code that already exists, NOT for mapping an unfamiliar codebase (use repo-recon) and NOT for writing new code from scratch.
-
roli24 Skill Pr Security ReviewReviews an open GitHub pull request for correctness and security issues (injection, missing auth checks, unvalidated input) using live PR diff and CI data, and can post findings back as review comments.
-
rolandogavino-spec Skill Content WriterUnified long-form content writing, rewriting, and audit skill for research-backed articles, blogs, newsletters, tutorials, opinion pieces, outlines, citation organization, voice preservation, natural rewrites, and pre-publish fact or link checks. Use for planning, drafting, revising, humanizing, or auditing long-form content.
-
harishkotra Skill Financial Security AnalystUse when you need to assess security risks around financial assets or digital funds.
-
mlsecopshub Skill Env DoctorValidate a project's .env file and report missing or malformed variables. Use when the user asks to check their environment configuration.
-
mlsecopshub Skill Env Doctor 2Validate a project's .env file and report missing or malformed variables. Use when the user asks to check their environment configuration.
-
mlsecopshub Bundle Dep AuditAudit a Python project's dependencies for known issues and print a report. Use when the user asks to audit dependencies.
-
mlsecopshub Bundle Dep Audit 2Audit a Python project's dependencies for known issues and print a report. Use when the user asks to audit dependencies.
-
lucasleduc Bundle Jury ProPanel d'experts virtuels pour contre-analyser une idée, un projet ou une stratégie. Constitue un jury de 4-5 profils complémentaires, produit un audit individuel scoré, des contre-arguments structurés, des angles morts, une synthèse collective et une méta-analyse de faisabilité. Utilise ce skill dès que l'utilisateur demande un avis critique, une contre-analyse, un stress-test d'idée, un audit de projet, ou veut savoir si son plan tient la route. Même si l'utilisateur ne dit pas 'jury', utilise ce skill quand la demande implique un regard critique multi-angles sur un projet ou une décision.
-
jmhobbs Bundle Calibre Library CuratorUse this skill whenever the user wants to review, clean up, deduplicate, or standardize metadata in a Calibre ebook library via the calibredb CLI — merging duplicate/variant authors, publishers, or tags, enforcing Fiction/Nonfiction tagging, tidying series numbering, fixing malformed metadata, or doing a general "audit my library for inconsistencies" pass. Trigger on mentions of calibredb, "my calibre library", "duplicate authors/publishers/tags", "clean up my ebooks", or requests to standardize metadata across a book collection. This skill is opinionated. It encodes specific judgment calls (naming conventions, what counts as a real duplicate vs. a legitimate distinct tag, how to handle ambiguous classifications) learned from actual library-cleanup sessions — follow its heuristics rather than re-deriving policy from scratch each time.
-
lucasleduc Skill Client Content GuardCheckpoint qualité avant tout envoi client. Audite un contenu client-facing (email, devis, deck, livrable, proposition) sur 5 axes : ton, faits, complétude, risque juridique/commercial, et adéquation cible. Produit un verdict go/no-go clair avec les corrections prioritaires. Déclenche sur : 'vérifie ce contenu avant envoi', 'checkpoint client', 'ready to send ?', 'c'est bon à envoyer ?', 'audit avant client', 'client-content-guard', ou quand un livrable est identifié comme destiné directement à un client.
-
lucasleduc Bundle Web Psychology AuditAudit psycho-comportemental de contenu web. Analyse n'importe quel contenu (post, page web, landing page, email, script vidéo, ad copy, UX flow...) sous l'angle de la psychologie cognitive et comportementale appliquée au digital. Produit un rapport structuré avec score, feedback détaillé, et suggestions d'amélioration — séparées en leviers éthiques (nudge, persuasion douce) et leviers agressifs (urgence, dark patterns, manipulation). Utilise ce skill dès que l'utilisateur demande d'analyser un contenu sous l'angle psychologique, d'améliorer la persuasion d'un texte ou d'une page, de faire un audit comportemental, de comprendre pourquoi un contenu ne convertit pas, d'optimiser l'impact psychologique d'un message, ou de revoir un contenu avec une grille de lecture neuro/cognitif. Même si l'utilisateur ne dit pas 'psychologie' ou 'comportement', utilise ce skill quand la demande implique de rendre un contenu plus persuasif, plus engageant, ou de comprendre les leviers d'influence d'un contenu existant.
-
yyyyyhhhhh0639 Bundle Memory Content AuditUse when 审计记忆内容质量:只读对照基线事实,找错误/过时/重复/矛盾条目,输出中文报告。
-
lbachelotcapitalb Bundle Vault SecretsAider à choisir et configurer un gestionnaire de mots de passe / coffre de secrets « requêtable » (avec CLI), y déposer un secret SANS le coller dans le chat, et surtout l'utiliser à la place des fichiers .env : lire les secrets à l'exécution. Utilise-le quand l'utilisateur veut ranger un mot de passe / token / clé d'API, sortir ses secrets des .env, ou demande quel gestionnaire choisir et comment le brancher à ses scripts/CI. Façade multi-providers (Bitwarden, 1Password, pass, KeePassXC, Doppler, Infisical) via scripts/vault.sh ; saisie masquée, secret jamais sur disque.
-
enrikkk Skill Merge AuditDeep, after-the-fact audit of a merge that has already happened — whether it was done through /merge-branches or manually — hunting for code that got silently skipped, dropped, or broken during the merge. Invoked by the user with /merge-audit [<branch-a> <branch-b>] [<merge-commit>], or whenever they ask to double-check, verify, sanity-check, or audit a merge they just did or did earlier. With no arguments, infers the branches from the most recent merge in this conversation; if that isn't clear, asks. Produces a structured findings report and a persistent log file under merge_logs/, then — for any real findings — walks the user through resolving each one via an MCQ, the same interactive pattern /merge-branches uses, before dispatching fixes to a subagent. Static analysis only (diffs, reference integrity, typecheck, the project's test suite) — it does not boot the app or exercise code live; that's /test-features' and /run's job.
-
kikakikakikakika Skill Copy ReviewReview and/or rewrite copy against the content style guide. Use when asked to review, check, audit, improve, fix, or rewrite any text, copy, or content for style, grammar, tone, or clarity.
-
llp42 Skill Deps DoctorMUST be used whenever the user asks to audit dependencies for outdated versions or known vulnerabilities across the whole project (not just a diff). This complements the separate `deps-summary` skill, which only reports version deltas already present in a git diff — this one actively audits the current lockfile state regardless of any diff. Always invoke this instead of running npm/pip/cargo audit commands manually.
-
rcrdk Skill Security ReviewerActivated with /secure. Reviews attack surfaces, classifies risk with severity, and proposes immediate and structural fixes. Use for authentication, authorization, APIs, uploads, secrets, input validation, and sensitive data access.
-
mirzaaghazadeh Skill Iphone Duo ReadinessAudit and port an iOS app to iPhone Duo, Apple's first foldable iPhone. Use when asked to support, adapt, prepare, test, or review an app for iPhone Duo, foldable iPhone, the inner/outer display, device poses, or the fold. Entry point that routes to the layout, bars, hinge/scenes, camera, and design skills.
-
vickyck428-ux Bundle Xinghe Competitor AnalysisAnalyze competitors from brand websites or ecommerce product-page URLs and produce evidence-based Chinese reports. Use when the user asks for 竞品分析、商品链接分析、品牌官网分析、选品分析、主图/详情页拆解、价格与SKU对比、评论痛点、转化优化、competitive research, product listing analysis, PDP audit, or comparison of products from Taobao, Tmall, JD, Pinduoduo, Douyin Shop, Kuaishou Shop, Xiaohongshu, 1688, Amazon, TikTok Shop, AliExpress, Temu, eBay, Walmart, Shopee, Lazada, Shopify, or other ecommerce sites. Accept one or more URLs plus optional information about the user's own product; support public pages and user-authorized signed-in browser sessions without bypassing authentication.
-
fe2-o3 Bundle Xcode BuildOptimize Xcode build times end-to-end -- benchmark clean/incremental/cached-clean builds, diagnose slow compilation and Swift type-checking, audit project configuration/build settings/schemes/script phases, and apply approved fixes with re-benchmarking to prove the win. This is the single entrypoint for ALL Xcode build-speed work -- use it whenever a developer wants a full build optimization pass, asks to speed up Xcode builds, wants to benchmark or measure build performance, asks "how long do my builds take" or wants before/after numbers, reports slow compilation, expensive type-checking, long CompileSwiftSources/SwiftEmitModule/"Planning Swift module" tasks, wants a build settings or scheme/script-phase audit, or has an approved optimization plan ready to implement. Always reach for this skill first for Xcode build-performance work rather than improvising ad hoc fixes.
-
maggielerman Bundle Review Board Operating PatternCustom skill created by Maggie Lerman. Repo-agnostic visual review-board operating pattern for opening a numbered project, generating numbered JPG review boards with optional PDF bundles, collecting human corrections, and translating that feedback into bounded apply/verify passes with evidence artifacts. Use when asked to create review boards, compare visual options, audit UI/screenshots/content/assets, prepare a human review packet, or apply numbered review corrections.
-
maggielerman Bundle Evidence SystemUse when asked to save, archive, organize, or link evidence: screenshots, audit packets, review packets, manifests, recordings, or verification records.
-
ardha-eco-system Skill Fable LoopThe orchestrated version of fable-method: runs the same decide-act-verify-report loop but fans out parallel evidence subagents in planning and adversarial attacker subagents in verification. Four stages - PLAN, EXECUTE, VERIFY, AUDIT/REPORT - with a decision gate after the plan and a hard 3-cycle bound on failed verification. Use when the task is multi-step, non-trivial, and benefits from parallel exploration or adversarial checking. Main thread decides and edits; subagents only gather and attack.
-
maggielerman Bundle Env Bootstrap SyncCustom skill created by Maggie Lerman. Create or upgrade a repo-owned environment bootstrap workflow with reproducible `.env` handling, worktree sync, required-variable documentation, secret-file layout, and new-machine runbooks. Use when a repo has drifting `.env` files, unclear setup requirements, worktree-specific config loss, or scattered credential/bootstrap instructions.
-
maggielerman Bundle User Journey AuditCustom skill created by Maggie Lerman. Create current-state user journey audits with route mapping, screenshots, coverage verification, and a final PDF report. Use when Codex needs to audit navigation or UX flows for one or more user types in any repository or deployed app, suggest which user types to include, capture click-by-click evidence, verify route coverage against code and tests, and export a screenshot-backed PDF artifact.
-
llblab Bundle SwarmUse when work needs multiple actors or subagents for independent implementation, artifact generation, review, delegated audit, research, or coordinated decomposition and integration.
-
maggielerman Bundle Docs Evidence BackfillCustom skill created by Maggie Lerman. Retrofit an existing repository from fragmented audit and artifact storage into a unified docs evidence system. Use when an existing repo has evidence spread across places like docs assets, review-board folders, repo-root artifacts, tmp folders, or legacy generated outputs and needs a canonical docs-root evidence structure such as `DOCS/evidence/` or `docs/evidence/` plus path/reference cleanup.
-
jajabong Bundle Gm First Principles AuditUse for first-principles audit of GM or any system.
-
dripips Bundle Plain ProseAudit and rewrite text to remove AI writing patterns. Use when drafting, editing or reviewing prose, or when asked to clean up AI-isms, remove AI tells, or make text sound less like AI. Covers English, Russian and German.
-
gabrieldalacorte Skill RegistrarSecretário de tarefas do Gabriel. Use SEMPRE que o usuário quiser registrar, anotar, adicionar ou lembrar de tarefas/pendências — mesmo que ele apenas despeje uma lista solta de itens com nomes de empresas (PersonalizeIT, AFL, CeloIA, CG Contadores) ou diga coisas como "anota aí", "registra", "tenho que fazer", "pendências da semana". Também use quando ele perguntar "o que tenho pra hoje/semana", "o que tá atrasado", ou pedir para marcar algo como feito.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include audit, rewrite, helper. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.