Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
loulanyue Skill Springboot Verification 3Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.
-
loulanyue Skill Springboot Verification 4Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.
-
loulanyue Skill Springboot Verification 6Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.
-
leynier Bundle Validate Python StackValidate the Python Template repository or a project generated from it. Use before committing, publishing, deploying, or reviewing a stack to check catalog compilation, rendering, dependencies, formatting, tests, security workflows, skills, and representative runtime behavior.
-
barastrong Bundle Grc AnalystUse when working on governance, risk management, compliance, security policies, audits, or regulatory frameworks. Trigger phrases: "GRC", "governance", "risk management", "compliance", "ISO 27001", "SOC 2", "GDPR", "HIPAA", "PCI DSS", "security policy", "risk assessment", "audit", "control framework", "regulatory compliance", "data privacy", "third-party risk", "vendor risk assessment", "policy review", "compliance gap analysis".
-
barastrong Bundle Soc AnalystUse when working in a Security Operations Center — real-time threat monitoring, alert triage, incident detection, or security event investigation. Trigger phrases: "SOC", "security operations", "alert triage", "SIEM alert", "threat detection", "security monitoring", "log analysis", "threat hunting", "IOC investigation", "playbook", "SOAR", "L1/L2/L3 analyst", "security event", "correlation rule", "use case detection".
-
barastrong Bundle Penetration TesterUse when conducting security testing, penetration testing, red teaming, or ethical hacking activities. Trigger phrases: "pentest", "penetration testing", "ethical hacking", "red team", "exploit", "vulnerability exploitation", "web application testing", "OWASP", "Burp Suite", "Metasploit", "privilege escalation", "lateral movement", "social engineering test", "security assessment", "bug bounty", "CTF".
-
barastrong Bundle Cybersecurity AnalystUse when analyzing security threats, reviewing security logs, performing vulnerability assessments, or implementing security controls. Trigger phrases: "cybersecurity", "security analysis", "threat assessment", "vulnerability scan", "security monitoring", "SIEM", "threat intelligence", "security incident", "malware analysis", "CVE", "risk assessment", "security audit", "security posture", "attack surface", "indicators of compromise", "IOC".
-
barastrong Bundle Database AdministratorUse when managing database systems, optimizing queries, designing schemas, handling backups/recovery, replication, or database performance tuning. Trigger phrases: "DBA", "database administration", "query optimization", "slow query", "index optimization", "database backup", "replication", "failover", "PostgreSQL tuning", "MySQL administration", "Oracle DBA", "database migration", "tablespace", "connection pooling", "database security", "EXPLAIN ANALYZE", "vacuum", "RDBMS performance".
-
awesome-ai-garage Skill Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when auditing dependencies for known vulnerabilities, triaging package-manager audit findings, or assessing supply-chain risk in a new package. Use when personal data or privacy compliance (GDPR, CCPA) is involved.
-
barastrong Bundle Network EngineerUse when working on network infrastructure, routing, switching, firewalls, VPNs, DNS, load balancers, or network troubleshooting. Trigger phrases: "network", "routing", "switching", "firewall rule", "VLAN", "VPN", "DNS configuration", "load balancer", "TCP/IP", "subnet", "CIDR", "BGP", "OSPF", "network troubleshooting", "traceroute", "packet capture", "Wireshark", "network design", "SD-WAN", "network security".
-
s0ld13rr Skill Playbook WebappWeb application pentest methodology + ROUTER to the per-vuln-class web skills. Load at the START of systematic web testing to get the phase flow (recon → map → test-by-OWASP-class → prove → report) and pick which web-<class> skill to load for each surface. Use on any web app / HTTP API engagement.
-
s0ld13rr Skill Post Exploit PhasePost-exploitation gotchas — credential dump order, DPAPI trap, host exhaustion checklist. Use when the current phase is POST_EXPLOIT.
-
samin12 Bundle Design ReviewDesigner's eye QA: finds visual inconsistency, spacing issues, hierarchy problems, AI slop patterns, and slow interactions — then fixes them. Iteratively fixes issues in source code, committing each fix atomically and re-verifying with before/after screenshots. For plan-mode design review (before implementation), use /plan-design-review. Use when asked to "audit the design", "visual QA", "check if it looks good", or "design polish". Proactively suggest when the user mentions visual inconsistencies or wants to polish the look of a live site.
-
samin12 Bundle Requesting Code ReviewPre-commit review: security scan, quality gates, auto-fix.
-
redheartsecretman Bundle A Share ResearchResearch A shares and SSE ETFs through an evidence-first deterministic CLI. Use for canonical identity, prices and trends, current intraday snapshots, completed-session intraday replay, ETF or ETF-option quotes, valuation and comparisons, research materials including F10, capital events, market signals, single-security or market-overview plans, and evidence-backed interpretation with explicit dates, provenance, calculation lineage, conflicts, coverage, and limitations.
-
drz-hang Bundle StatmatePlan, audit, run, and explain reproducible statistical analyses for scientific research from a manuscript, study design, and real data or machine-readable results. Use for method selection, research-data QA, biomedical or quantitative models, publication figures/tables, result review, or figure/table reading guidance. Do not use for generic business charts, scientific illustrations, or manuscript writing without a statistical task.
-
emskills-mcp Bundle Scalebar CalibrateCalibrates magnification and pixel size against certified cross-grating standards, producing a drift-corrected calibration record suitable for audit trails.
-
manhvann Skill Ck ResearchResearch technical solutions, analyze architectures, gather requirements thoroughly. Use for technology evaluation, best practices research, solution design, scalability/security/maintainability analysis.
-
noddhogg Bundle Knowledge Gatekeeper个人知识库的治理层 / Governance layer for personal knowledge bases — turn what you saved but never read into something you actually read. 四档质量门禁、成页门禁(防注水)、单一账本增量、断点续跑、防丢闭环、页面结构规范、平台接入清单(集成获取,不做实现)。Triggers — knowledge base governance / quality gate / unread favorites / note triage / padding audit / 知识库治理 / 质量门禁 / 成页门禁 / 注水检测 / 素材定档 / 收藏精炼 / 知识库防丢 / 账本续跑 / 笔记入库审查 / 平台接入
-
daronthedragon Bundle Wallet ForensicsForensic analysis of any Ethereum, Base, Arbitrum, Optimism, Polygon, or Solana wallet address. Reports realized and unrealized PnL, lifetime gas/fee costs, MEV sandwich attacks committed against the wallet, risky token approvals and delegates, and exit liquidity — how much a position would actually sell for versus what a portfolio tracker claims it is worth. Use when the user asks to analyze, audit, review, or investigate a wallet or address; asks what a wallet holds or is worth; asks how much they lost to gas, MEV, sandwiches, or bad trades; asks whether their approvals are safe or whether they should revoke; asks whether a token position can actually be sold or is illiquid; or pastes a raw 0x or base58 address and wants to know about it.
-
manhvann Bundle Ck GitGit operations with conventional commits. Use for staging, committing, pushing, PRs, merges. Auto-splits commits by type/scope. Security scans for secrets.
-
olaservo Skill Secret MenuRecommend an off-menu coffee order based on the user's mood. A deliberately unlisted skill demonstrating that skills absent from skills/list remain retrievable via skills/get and readable by URI.
-
thgmatajs Bundle Reuse Before WriteSearches the current repository for existing callable code and returns a reuse-or-write-new verdict after a fit-first audit. Use when implementing a feature, plan task, or subtask that would add a function, type, class, hook, or module, before writing new production code, when another skill is about to emit implementation, or when looking for an existing helper instead of duplicating logic.
-
qlasse Bundle Audit 152fzАудит сайта, лендинга или веб-сервиса на соответствие 152-ФЗ «О персональных данных» и смежному регулированию (локализация, трансграничная передача, уведомление РКН, cookie, рассылки). Выдаёт отчёт-чеклист со статусами по каждому требованию, ссылками на нормы, оценкой риска по ст. 13.11 КоАП и планом исправлений, который Claude может выполнить сразу. Используй этот скилл всегда, когда речь заходит о проверке сайта на 152-ФЗ, ФЗ-152, персональных данных на сайте, политике конфиденциальности или политике обработки ПДн, согласии на обработку, галочке согласия в форме, cookie-баннере, уведомлении Роскомнадзора, локализации данных в РФ, подготовке к проверке РКН, штрафах за персданные — даже если пользователь не произносит слово «аудит» и просто спрашивает «всё ли у меня по закону с формой заявки» или «нужно ли мне согласие на cookie».
-
aruljothysundaramoorthy Bundle Nestjs Production ReviewerReviews NestJS and Node.js backend services for production readiness. Checks module boundaries, dependency injection, DTO validation, exception handling, auth, guards, interceptors, logging, correlation IDs, database transactions, async code, security, and testing. Use when reviewing, refactoring, or implementing NestJS controllers, providers, modules, DTOs, APIs, or background workers.
-
aruljothysundaramoorthy Bundle Application Security ReviewerReviews application security and explains each finding via its attack path. Checks authentication, authorization, RBAC, object-level auth, JWT, secrets, injection, XSS, CSRF, SSRF, CORS, uploads, encryption, logging of sensitive data, and dependency risk. Use when the user asks for a security review or mentions authentication, authorization, JWT, sensitive data, or security vulnerabilities. Do not use for API retry design or framework architecture reviews.
-
finografic Skill Maintain Verification SkillPeriodic pass that keeps a project's verification skill and feature map honest: parallel source readers per feature, one live session driving every feature, at most one PR of proven corrections. Use for /maintain-verification-skill or "audit the verify skill".
-
paulohfs Skill API SecurityChecklist de segurança de API. Use ao criar, modificar ou revisar endpoints, rotas REST, controllers, middlewares de autenticação ou qualquer código que expõe uma API.
-
paulohfs Skill SecurityRouter para skills de segurança. Use "security" e eu indico qual skill especializada carregar.
-
00200200 Bundle ReproducibilityAudit or repair ML experiment reproducibility and review whether code changes preserve recorded outputs. Use for reproducibility blockers, before-and-after experiment checks, or preparing a reproducible experiment package.
-
mixocreative Bundle Ecommerce CiaUse when auditing a transactional e-commerce codebase — checkout, orders, payments, gateway callbacks, inventory, fulfilment and pickup, refunds, promotions, tax and invoices, digital entitlements, settlement, reconciliation, consumer-law and privacy compliance (GDPR, CCPA, APPI, 個資法, PIPA), legal pages, subscriptions, or setting up a gateway from zero (NewebPay 藍新 / ECPay 綠界 / LINE Pay / PAYUNi / TapPay sandbox, merchant account, 串接, which gateway to use) — or when a commerce project (payment-gateway code, orders/cart schema, checkout routes, or a commerce framework dependency present) hears pre-launch words: run tests, test suite, pre-launch, handoff, green-light, ready for launch, audit, security audit, wiring audit, nothing dies silently, dead control, fail-open, vacuous pass, TOCTOU, four-corner walk, VSM map, admin dashboard. Explicit /ecommerce-cia or $ecommerce-cia always selects this skill. Not for /cia or $cia (the separate Code Integrity Auditor) and not for non-commerce projects.
-
skills-qweer Bundle Codex Storage CleanupAudit and safely reclaim disk space under CodexHome on Windows, including stale tool backups and installers, plugin staging/cache, sandbox logs, SQLite free pages, and completed subagent records. Use when the user asks why CodexHome is large, requests Codex storage cleanup or ended-subagent cleanup, or says “检查占用空间”, “清理 Codex 缓存”, “删除已结束子代理”, or similar. Never automatically delete main or archived conversations or user artifacts.
-
tau625 Bundle Scholar Publication Audit核实某位学者的完整论文清单(用于「帮我找出 XX 老师的全部论文」「这个人发过什么」)。核心是同名作者消歧:OpenAlex / Semantic Scholar 的作者档案普遍存在严重合并污染,必须用「共同作者交集 + 机构核对」双路交叉验证才能得到可信清单。当用户要求检索某学者的论文、确认某篇论文是否属于某人、或整理某人的成果目录时使用。
-
terravic Bundle PDF Extract ConfidenceExtract text from PDF documents (digital vector, scanned, or hybrid) with normalized per-word confidence scores (0.0 to 1.0) and output dual-purpose JSON containing complete document text and word-level audit metadata. Use this skill whenever the user asks to extract text from a PDF, inspect or verify word recognition confidence scores, extract PDFs into JSON, or check for low-confidence or potentially misrecognized words in PDF files.
-
neosiki Bundle Neo Korean Writing한글 글쓰기(윤문)를 위한 구조화된 작성·진단·윤문 스킬이다. 사용자가 "글을 써줘", "윤문해줘", "다듬어줘", "최강 윤문", "번역투 고쳐줘", "진단만 해줘", "내 문체로 고쳐줘"라고 하거나 한국어 기사·칼럼·에세이·리뷰·보도자료·리포트·기술문서·원고를 작성하거나 고칠 때 사용한다. 새 글은 korean-writing 워크플로우로 연결하고, 기존 원고는 사실·인용·숫자·화자를 보존하면서 14개 거시 패턴, 장문 무손실 청킹, 4축 검증 게이트를 적용해 윤문한다. 구조 진단·완독률 개선·칼럼 고도화 요청에서는 Editorial Audit을 분리 실행한다. 단순 맞춤법 교정이나 원문에 없는 내용을 추가하는 작업에는 사용하지 않는다.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include springboot-verification, springboot-verification, springboot-verification. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.