Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
jtydhr88 Skill Mc AI Tell AuditThe post-generation AI-tell audit (AI 味诊断). Run this on every generated track before accepting it. Covers the fourteen enumerable defaults that generative music models fall into, which of them are machine-measurable and which need ears, why compliance rate and AI-tell count are two separate numbers that must never be merged, the zero-point calibration that sets the pass threshold at 82 rather than 60, the ordered diagnostic path from symptom to owning skill, and the remediation list. Use when a generation comes back and must be accepted or rejected, when a track sounds synthetic but you cannot say why, when deciding whether to accept a take, or when a high compliance rate still produced a bad result. AI 味、诊断、验收、听不出来是 AI、照做率、生成后检查。
-
g-tavares14 Skill Security And HardeningHardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when auditing dependencies for known vulnerabilities, triaging package-manager audit findings, or assessing supply-chain risk in a new package. Use when personal data or privacy compliance (GDPR, CCPA) is involved.
-
understudylabs Skill Audit Verifier ReliabilityUse when deciding whether a verifier reward is trustworthy for optimization.
-
insightfulanalytics Bundle Review ReportActionable feedback on the quality, usage, and effectiveness of Power BI reports. Automatically invoke when the user asks to "review a report", "audit a report", "report usage analysis", "report health check", "find unused reports", "check if a report is being used", "assess report performance", "evaluate report quality".
-
scriptedalchemy Bundle Maintain Verification SkillPeriodic pass that keeps a project's verification skill and feature map honest: parallel source readers per feature, one live session driving every feature, at most one PR of proven corrections. Use for $maintain-verification-skill or "audit the verify skill".
-
insightfulanalytics Bundle Audit Tenant SettingsAutomatically invoke this skill whenever the user asks about Fabric tenant settings or Power BI tenant settings or auditing tenant settings. You can use this skill if the user mentions "Fabric administration".
-
lmaick Skill Supabase Rls GuardEspecialista em segurança, integridade e arquitetura de dados no Supabase e PostgreSQL. Aplica regras estritas de Row Level Security (RLS), isolamento por tenant/user via auth.uid(), transações atômicas com RPCs e prevenção de vazamento de dados.
-
wycats Skill Code ReviewUse when reviewing git diffs, local changes, or pull requests for merge-relevant risks: correctness regressions, security/privacy, data integrity, performance, reliability, tests, UX, maintainability, and deployability. Produce evidence-backed findings, inline comments when available, and a reviewer-facing summary focused on findings, residual risk, questions, and readiness.
-
yogiraja Skill Ponytail AuditWhole-repo audit for over-engineering. Like ponytail-review, but scans the entire codebase instead of a diff: a ranked list of what to delete, simplify, or replace with stdlib/native equivalents. Use when the user says "audit this codebase", "audit for over-engineering", "what can I delete from this repo", "find bloat", "ponytail-audit", or "/ponytail-audit". One-shot report, does not apply fixes.
-
yogiraja Bundle Anthropic Doc ValidatorValidate claims, documentation, code examples, or generated content about Claude Code, the Anthropic API, or Anthropic SDKs against the latest official documentation. Use when the user asks to "validate against docs", "check against anthropic docs", "verify this is current", "is this still accurate", "audit content against documentation", or similar. Also use proactively after generating slides, READMEs, blog posts, training materials, or runbooks that make specific factual claims about Anthropic products, so that those claims do not drift from the source of truth.
-
arozumenko Bundle Risk RegisterUse when recording, accepting, expiring, closing, superseding or ticketing residual security risks in the append-only register, or reading its exposure and approval counts; provides register.mjs.
-
arozumenko Bundle Code Review 2Use when the user asks to 'review this code', 'check my changes', 'review PR', 'audit' — and proactively after a non-trivial change or before opening, approving, or merging a PR, even unprompted. Reviews code for correctness, security, performance, and maintainability.
-
arozumenko Bundle UX AuditUI/UX, forms, and page-type analysis. Checks general UI patterns, form usability, and domain-specific UX for 20+ page types.
-
arozumenko Bundle Privacy AuditPrivacy, cookie consent, and GDPR analysis. Audits cookies, trackers, consent banners, and GDPR compliance from network traffic and the page.
-
arozumenko Bundle Security AuditSecurity and OWASP analysis. Reviews for XSS, CSRF, injection risks, missing security headers, and exposed data.
-
arozumenko Skill Responsive AuditResponsive-layout analysis on a real browser — viewport configuration, touch-target sizing, and mobile-layout issues via a resized Playwright viewport.
-
arozumenko Bundle Performance AuditPerformance, networking, console, and JavaScript analysis. Checks network issues, console errors, and JS problems; approximates load/resource health where full Core Web Vitals aren't available.
-
arozumenko Bundle Code ReviewUse when the user asks to 'review this code', 'check my changes', 'review PR', 'audit' — and proactively after a non-trivial change or before opening, approving, or merging a PR, even unprompted. Reviews code for correctness, security, performance, and maintainability.
-
arozumenko Bundle Secure Code ReviewUse when reviewing code for security defects with citations anyone can re-check, giving a second opinion on one finding, or verifying a fix at a commit; provides cite.mjs and verify.mjs.
-
insideto27 Bundle Amazon Listing Regulatory ReviewReview Amazon listing and related claims for marketplace policy, restricted-product, substantiation, safety, and jurisdiction-specific risk. Use for a new product link, material listing restructuring, an explicit compliance audit, or an existing-listing edit that changes a material claim, fitment, certification, safety statement, or regulated function. Routine limited-field edits to an already selling link receive a focused changed-field check in the listing workflow unless these triggers arise.
-
swyxio Bundle Design Apps With ImagegenDesign, reskin, or improve apps and sites through a user-confirmed image-first product loop. Use when Codex should audit an existing interface, generate four materially different visual and behavioral directions including a wildcard, present numbered visual and product-behavior decisions for user approval, implement the selected direction with code and generated assets where appropriate, candidly compare matched screenshots across mobile, tablet, and desktop, repair visual drift, and integrate the proven result.
-
swyxio Skill WranglerResolve, construct, review, or run an exact Cloudflare Wrangler command or `wrangler.jsonc` change. Use when the user names Wrangler, asks for a Cloudflare CLI operation, or needs environment, binding, authentication, secret, migration, deployment, or resource-management syntax. Do not trigger for general Cloudflare architecture or application code that does not require Wrangler.
-
swyxio Bundle Vercel Production Cost ReviewAudit a defined Vercel production cost question using billing and usage evidence, then recommend or verify bounded remediations. Use only when the user explicitly asks for a Vercel cost review, unexpected bill or usage spike investigation, Fast Data Transfer analysis, or post-remediation savings verification. Do not trigger for ordinary Vercel deployment, generic performance work, routine caching changes, or optimizing one route without a cost question.
-
swyxio Bundle Productionize App With ServicesProductize a working prototype by adding a bounded set of explicitly requested operational or product services. Use only when the user asks for a broad productization pass or names product-service gaps such as permissions, API access, audit history, admin operations, or production operability as the primary task. Do not trigger for ordinary feature work, a single service integration, generic "make this production ready" phrasing without concrete scope, or routine security, observability, testing, and release tasks covered by narrower skills.
-
swyxio Skill CloudflareRoute an ambiguous or cross-product Cloudflare platform request to the appropriate product, documentation, or narrower local skill. Use when the user needs help choosing among Cloudflare compute, storage, AI, networking, security, media, or infrastructure products. Do not trigger when the request already names a specific Cloudflare product or matches a narrower installed skill.
-
swyxio Bundle Diy NetlifyBuild or audit an isolated Netlify/Vercel-style pull-request preview workflow using GitHub Actions and the project's existing hosting provider. Use when eligible PRs need separate live preview environments, stable and immutable URLs, GitHub reporting, affected-target builds, and safe fork handling. Do not use for production-bound staged versions, artifact promotion or reuse, or generalized release-platform design.
-
swyxio Bundle Gsuite SetupConfigure or audit Google Workspace (formerly G Suite) organization settings for open collaboration, user autonomy, external sharing, Groups privacy, Gmail delegation, Calendar, Meet, Chat, Drive, Directory, and profile editing. Use for new Workspace setup, restrictive-default cleanup, onboarding a small collaborative organization, or verifying that the Latent Space openness baseline remains applied.
-
swyxio Bundle Mobile Webapp UXDesign, build, or review responsive mobile web-app UX when a phone experience needs task-first layout, usable touch controls, compact media comparison, mobile navigation, overlays, forms, or responsive validation without degrading the desktop experience. Use for requests to make an existing web app work well on phones, fit a task into one mobile viewport, improve tap targets, adapt comparison/review screens, or audit mobile usability.
-
swyxio Bundle Antislop CodebaseDiagnose or execute an explicit repository-wide maintainability cleanup while preserving behavior. Use only when the user asks to antislop a codebase, clean up an overgrown repository, plan or run a substantial structural migration, or audit maintainability across a repo. Do not trigger for ordinary feature refactors, a single large file, routine type improvements, adding regression tests, or broader production-readiness work.
-
swyxio Bundle Public QA ChatbotBest practices for building an unauthenticated public Q&A chatbot widget. Covers rate limiting, security hardening, cost optimization, semantic caching, observability, UX patterns, chat scroll behavior, and architecture. Tech-agnostic with concrete examples from a production implementation.
-
swyxio Bundle Security HardeningAudit or harden a defined application-security attack surface when the user explicitly requests a security audit, vulnerability investigation, or scoped security-hardening pass. Do not trigger for routine authentication changes, role design, scoped permissions, ordinary authorization bugs, dependency updates, generic production readiness, or feature implementation with incidental security implications.
-
swyxio Bundle Reserved Handle PolicyDesign, implement, audit, or refresh protected username and handle namespaces for public products. Use whenever a product has open signup, mutable handles, profile URLs, impersonation or squatting risk, reserved route names, short usernames, common-word or common-name claims, developer/AI terminology, notable social identities, or administrator-approved handle assignment—even if the user only asks for a username denylist.
-
venilkukadiya52 Skill Post AuditAudit a CareerSignal draft for factual support, current-source quality, privacy, originality, technical defensibility, voice, and format quality. Use on /CSaudit or before an external write action.
-
ivy00johns Bundle Skill Deep ReviewPerform a thorough, single-skill deep dive reviewing structure, description quality, instruction clarity, progressive disclosure, anti-patterns, and frontmatter compliance — then run test prompts via /skill-creator to validate triggering and output quality. Use this skill when deeply reviewing one skill, auditing a specific skill's quality, checking if a skill triggers correctly, doing a "deep dive" on a skill, or when someone says "review this skill", "is this skill good", "check skill quality", or "deep review". Not for broad multi-skill scans — use skill-audit for that.
-
ivy00johns Bundle Skill ReviewReview skills for quality, consistency, triggering accuracy, and adherence to the 5000-word / 500-line body guideline. Two modes: 'all' (bulk ecosystem-wide scan for ownership conflicts, length outliers, weak triggers, dead xrefs) or a single skill name (deep dive on description quality, body structure, anti-pattern naming, cross-references). Outputs a structured markdown report plus JSON sidecar consumable by skill-update. Trigger on "audit skills", "review this skill", "health check skills", "bulk review", "deep review", "what needs fixing".
-
ivy00johns Bundle Skill AuditScan all skills (or a filtered subset) for consistency, quality issues, gaps, and ownership conflicts in bulk. Use this skill when auditing the full skill ecosystem, running a broad quality scan, checking for ownership overlaps across agents, finding inconsistencies between skills, doing a "health check" on all skills, or when someone says "audit skills", "scan all skills", "skill ecosystem health", "bulk review", or "what needs fixing". Not for single-skill deep dives — use skill-deep-review for that.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include mc-ai-tell-audit, security-and-hardening, audit-verifier-reliability. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.