Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
andreaswasita Bundle Security AuditDetects high-confidence security risks in code.
-
phattbeats Bundle Sillytavern LorebookBuild and maintain SillyTavern World Info lorebooks (character cards, event entries, location entries) from a long-form story, interactive-fiction transcript, or roleplay log. Use whenever the user asks to create, update, expand, or catch up a lorebook, world info, character book, or worldbook, or wants continuity tooling for an ongoing AI roleplay story, even without saying "SillyTavern" explicitly. Also trigger when they share a story plus an existing lorebook JSON and want it updated, ask for cards for "all the important characters," or want a keyword/recursion/probability pass on an existing lorebook. Always run the full multi-pass workflow, including the coverage audit and technical pass, even for requests that sound like a quick update, since skipping passes is the main failure mode this skill exists to prevent.
-
arif-2747 Bundle HumanUse this skill to humanize text, defeat AI detectors (GPTZero, Binoculars, Turnitin), strip multi-vendor AI watermarks (Unicode Layer A, sampling Layer B, and C2PA), make prose sound natural, write in the user's voice, or check if a draft reads as AI. Covers general/business prose, narrative work, and file provenance. Triggers on "this sounds like AI," "make this more human," "de-AI this," "beat AI detectors," "rewrite naturally," "write in my style," "remove AI tells," "does this read as AI," "strip AI watermarks," "clean AI metadata," "remove invisible Unicode," /remove-ai-marks, or narrative drafting. Applies 42 patterns (humanizer, stop-slop, no-ai-slop), DIPPER structural paraphrasing (Krishna et al., order/lexical diversity), Unicode hygiene, token entropy dispersion, voice injection, Style Mirroring, Detect mode, Karpathy editorial discipline, and StoryScope 30-feature narrative audit. Preserves full complexity, depth, and length; never simplifies or summarizes.
-
rrijssenbeek Bundle UpworkAudit and rewrite Upwork freelancer profiles using patterns from Top Rated Plus / Expert Vetted top earners. Use when the user wants to improve their Upwork profile, headline, title, bio, overview, specialized profile, project catalog, gig description, skills tags, testimonial, employment history, or job proposal. Triggers on "upwork", "freelancer profile", "improve my headline", "rewrite my bio", "profile overview", "project catalog", "fix my upwork".
-
dyegolara Bundle Nostr Auth 2Authenticate to Nostr sign-in challenges (NIP-07 style) without a wallet or browser extension. Signs kind-22242 AUTH challenge events with a secp256k1 (BIP-340) key derived from a local master secret and optionally submits them to the service callback. Use when a site or API asks for a signed Nostr event to prove key ownership. More methods coming: NIP-98 HTTP Auth, NIP-42 relay AUTH, NIP-05.
-
loulanyue Skill Perl SecurityComprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies.
-
loulanyue Skill Quality NonconformanceCodified expertise for quality control, non-conformance investigation, root cause analysis, corrective action, and supplier quality management in regulated manufacturing. Informed by quality engineers with 15+ years experience across FDA, IATF 16949, and AS9100 environments. Includes NCR lifecycle management, CAPA systems, SPC interpretation, and audit methodology. Use when investigating non-conformances, performing root cause analysis, managing CAPAs, interpreting SPC data, or handling supplier quality issues.
-
loulanyue Skill Laravel SecurityLaravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.
-
loulanyue Skill Perl Security 5Perl Security
-
loulanyue Skill Perl Security 6Comprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies.
-
loulanyue Bundle Security Review 3인증 추가, 사용자 입력 처리, 시크릿 관리, API 엔드포인트 생성, 결제/민감한 기능 구현 시 이 스킬을 사용하세요. 포괄적인 보안 체크리스트와 패턴을 제공합니다.
-
loulanyue Bundle Security ReviewKimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın. Kapsamlı güvenlik kontrol listesi ve kalıplar sağlar.
-
loulanyue Bundle Security Review 4Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
-
loulanyue Skill Perl Security 2Comprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies.
-
loulanyue Skill Perl Security 3Comprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies.
-
loulanyue Skill Perl Security 4Comprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies.
-
loulanyue Bundle Security Review 5Security Review
-
loulanyue Skill Springboot SecuritySpring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
-
loulanyue Skill Laravel Security 4Laravel 安全最佳实践,涵盖认证/授权、验证、CSRF、批量赋值、文件上传、密钥管理、速率限制和安全部署。
-
loulanyue Bundle Security Review 6Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
-
loulanyue Skill Laravel Security 2Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.
-
loulanyue Skill Laravel Security 5Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.
-
loulanyue Skill Postgres Patterns 2PostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices.
-
loulanyue Skill Laravel Security 3Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.
-
loulanyue Skill Springboot Security 2Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
-
loulanyue Skill Django Verification 3Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.
-
loulanyue Skill Springboot Security 3Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
-
loulanyue Skill Postgres Patterns 4PostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices.
-
loulanyue Skill Django VerificationVerification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.
-
loulanyue Skill Postgres Patterns 6PostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices.
-
loulanyue Skill Django Verification 4Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.
-
loulanyue Skill Springboot Security 4Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
-
loulanyue Skill Springboot Security 5Java Spring Boot 服务中认证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全性的 Spring Security 最佳实践。
-
loulanyue Skill Django Verification 6Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.
-
loulanyue Skill Springboot Security 6Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
-
loulanyue Skill Springboot VerificationVerification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-audit, sillytavern-lorebook, human. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.