Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ivy00johns Bundle Dependency Health LoopKeep a project's dependencies healthy on a schedule: audit for known vulnerabilities and over-stale pins, apply ONE safe update (or a vuln fix) per pass, run the full gate to prove the update is non-breaking, and open or update a PR — looping on a sprint cadence with HITL on every major version bump and never auto-merging. Use when you want deps watched while you build, want security advisories acted on a cadence, want lockfiles kept fresh without breaking the build, or want a dependency audit run every 30 minutes during a sprint. Trigger on "audit my dependencies", "keep deps up to date", "dependency health", "check for vulnerable packages", "npm audit on a schedule", "pip-audit loop", "cargo audit loop", "update dependencies safely", "watch for CVEs", "keep the lockfile fresh", "dependabot-style loop", "bump deps and test". Routes major/breaking bumps to a human and never merges. A configuration of loop-controller.
-
optimuslabs-io Bundle Env AuditLists which configuration variables are set (names only).
-
ivy00johns Bundle Skill Improvement PlanConsume review reports from skill-deep-review or skill-audit and produce a prioritized, actionable improvement plan with specific edits per skill. Use this skill when you have review feedback to act on, need to plan skill improvements, want to turn audit results into a fix plan, or when someone says "plan the fixes", "what should we improve", "make a plan from this review", "improvement plan", or "prioritize the changes". Also trigger when a deep-review or audit report exists and the user wants next steps.
-
ivy00johns Skill Plan IntakeTurn any report (repo-deep-dive output, audit, skill-review, QA findings, design audit) into approved entries in a project's living-plan ledger. Use when the user says "intake this report", "add findings to the plan", "turn this audit into work items", "update the ledger from this report", "feed the deep-dive into the plan", or has a finished report and wants it tracked instead of rotting. Format-agnostic: adopts the target project's existing entry format.
-
optimuslabs-io Skill Secure Skills HandbookHandbook of known malicious-skill patterns for reviewer training.
-
optimuslabs-io Skill Policy Compliant HelperProvides utility functions following all security best practices and platform policies.
-
agentik-os Skill Monitor 2Point a monitor at a running rmux session (on this box or on any ssh host) and get an ANSWER instead of a screen. A cheap 60s watcher classifies the session as QUESTION, STALLED, BLOCKED or WORKING and answers each one differently: a question goes to a human because it needs judgement, a stall gets a mechanical nudge, a block is NEVER nudged because that is manufactured thrash, and working stays silent. A deep audit team of parallel read-only sub-agents runs on a slower cadence, with dimensions derived from the WATCHED project's own rules. Use when the user says "/monitor", "/omg-monitor", "monitor this session", "watch this build", "keep an eye on the oracle", "babysit that session", "is it stuck", "did it stall", "why did it stop", "audit that session continuously", or in French "surveille cette session", "surveille ce build", "garde un oeil sur l'oracle", "est-ce qu'il est bloque", "il s'est arrete", "pourquoi il ne bouge plus", "audite la session en continu". NOT for MIRRORING a session so a human can rea
-
agentik-os Skill Ads StrategyFull Ad Strategy Orchestrator (Bucket A — multi-angle fan-out). Launches 5 parallel subagents to build a complete advertising strategy from a single URL — audience personas, creative concepts, funnel architecture, competitive intelligence, and budget allocation. Produces a composite Ad Readiness Score (0-100) with a unified, client-ready strategy report. Use when the user says "/ads strategy <url>", "full ad strategy", "complete advertising plan", "ad audit", "stratégie pub complète", "stratégie publicitaire", "audit publicitaire", "plan média complet", or wants every advertising dimension analyzed in one command.
-
agentik-os Skill Ads Report PDFCompiles already-generated ads outputs (ADS-*.md) into ONE polished, client-ready PDF advertising strategy report (cover gauge, persona cards, funnel diagram, budget charts, 90-day action plan) via ReportLab. Single deliverable, one consistent visual voice. Use when the user says "/ads report-pdf", "PDF report", "client-ready report", "polished ad report", "deliverable for the client", "export the strategy to PDF", or in FR "rapport PDF", "rapport pub PDF", "rapport client", "export PDF de la stratégie", "génère le PDF de la stratégie ads". NOT for running new ads analysis (use /ads strategy first) and NOT a multi-angle audit.
-
jhamidun Bundle Perf AuditLighthouse в headless перед публикацией страницы: LCP, CLS, TBT, размер бандла, конкретные советы. Триггеры: «Core Web Vitals», «оптимизация перформанс».
-
jhamidun Skill Security AuditSecurity-аудит: секреты в коде, pip/npm audit, OWASP Top 10. Триггеры: «аудит безопасности», «проверь на уязвимости».
-
jhamidun Skill Threat HuntingThreat hunting: правила Sigma, detection engineering. Триггеры: «охота на угрозы», «sigma rules». НЕ свой код → security-audit.
-
jhamidun Bundle Health InlineCodebase health инлайн (сам оркестратор): детекция→фикс→верификация. Триггеры: /health-bugs, /health-cleanup, /health-deps, /health-reuse, /health-security.
-
jhamidun Bundle Linkedin Post AuditLinkedIn Post Audit
-
sameque00-source Bundle Software Engineering Universe UltimateAdvanced software-engineering guidance for real-world development across computer science, programming, software design, web and networking, infrastructure, databases and security, and AI engineering. Use this skill for architecture, implementation, debugging, refactoring, code review, testing, security, performance, deployment, reliability, and technical decision-making. Consult the bundled topic references when a task needs deeper, domain-specific guidance.
-
majiayu000 Bundle Core 9Personal AI Infrastructure core. AUTO-LOADS at session start. The authoritative reference for how the PAI system works, how to use it, and all system-level configuration. USE WHEN any session begins, user asks about the system, identity, configuration, workflows, security, or any other question about how the PAI system operates.
567 -
majiayu000 Bundle Openfga 2OpenFGA authorization modeling best practices and guidelines. This skill should be used when authoring, reviewing, or refactoring OpenFGA authorization models. Triggers on tasks involving OpenFGA models, relationship definitions, permission structures, .fga files, .fga.yaml test files, or OpenFGA SDK usage in JavaScript, TypeScript, Go, Python, Java, or .NET.
567 -
majiayu000 Bundle Local 2Audit a skill against Anthropic skill-creator standards
567 -
majiayu000 Bundle Ss Audit 2Audit screens for UX issues using Nielsen's heuristics and modern mobile UX best practices
567 -
majiayu000 Bundle Pr Triage 2PR triage: audit open PRs, deep review selected ones, draft and post review comments. Args: "all" to review all, PR numbers to focus (e.g. "42 57"), "en"/"fr" for language, no arg = audit only in French.
567 -
majiayu000 Bundle Webhooks 3Webhook implementation and consumption patterns. Use when implementing webhook endpoints, sending webhooks, handling retries, or ensuring reliable delivery. Keywords: webhooks, callbacks, HMAC, signat
567 -
majiayu000 Bundle Audit Flow 2Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. Use for security audits, compliance documentation, flow tracing, feature ideation, brainstorming, debugging, architecture reviews, or incident post-mortems. Triggers on audit, trace flow, document flow, security review, debug flow, brainstorm, architecture review, post-mortem, incident review.
567 -
majiayu000 Bundle Hooks Eval 3- Overview
567 -
majiayu000 Bundle Rfc Writer 2Write an engineering RFC (Request for Comments) for a technical decision, architectural change, or significant implementation approach. Use when asked to write an RFC, document a technical proposal, create a design doc, write an architecture decision for review, or produce a technical specification for team feedback. Produces a complete RFC document covering problem statement, motivation, proposed solution, alternatives rejected, implementation plan, migration plan, security and performance implications, observability changes, rollout plan, and open questions.
567 -
majiayu000 Bundle Webhooks 4Webhooks are HTTP callbacks that notify external systems when events occur. They enable real-time communication between services without polling. This skill covers webhook design patterns, security, reliability, and implementation best practices.
567 -
majiayu000 Bundle Test Master 3Use when writing tests, creating test strategies, or building automation frameworks. Invoke for unit tests, integration tests, E2E, coverage analysis, performance testing, security testing. Keywords:
567 -
majiayu000 Bundle Meta Ads Audit 2Meta Ads (Facebook + Instagram) account audit and business context setup. Run this first — it gathers business information, analyzes account health, and saves context that all other Meta ads skills reuse. Trigger on "audit my Meta ads", "audit my Facebook ads", "Meta ads audit", "set up my Meta ads", "onboard Meta", "Meta account overview", "how's my Meta account", "Meta health check", "what should I fix in my Facebook ads", or when the user is new to NotFair Meta and hasn't run an audit before. Also trigger proactively when other Meta ads skills detect that meta business-context.json is missing.
567 -
majiayu000 Bundle Security Skill 2Use when reviewing code for security issues.
567 -
majiayu000 Bundle Test Skill 5answers with the secret
567 -
majiayu000 Bundle Rr Solidity 2Comprehensive Solidity smart contract development skill using Foundry framework. Use for writing, testing, deploying, and auditing Solidity contracts with security-first practices. Also triggers when
567 -
majiayu000 Bundle Resolve Conflict 3Resolve disagreements between security and architecture reviews conservatively.
567 -
majiayu000 Bundle Client Report 3Generate a client-friendly AI visibility report from audit data.
567 -
majiayu000 Bundle Google Ads Audit 4Google Ads account audit and business context setup. Run this first — it gathers business information, analyzes account health, and saves context that all other ads skills reuse. Trigger on "audit my ads", "ads audit", "set up my ads", "onboard", "account overview", "how's my account", "ads health check", "what should I fix in my ads", or when the user is new to NotFair and hasn't run an audit before. Also trigger proactively when other ads skills detect that business-context.json is missing.
567 -
majiayu000 Bundle Raccoon Audit 2Rummage through code with curious precision, inspecting every corner for security risks and cleaning up what doesn't belong. Use when auditing security, finding secrets, removing dead code, or sanitizing before deployment.
567 -
majiayu000 Bundle Hook Audit 2Comprehensive audit of Claude Code hooks for correctness, safety, and performance. Use when reviewing, validating, or debugging hooks, checking JSON stdin handling, verifying exit codes (0=allow, 2=block), analyzing error handling, fixing hook failures, ensuring safe degradation, optimizing performance, or validating settings.json registration. Also triggers when user asks about hook best practices, wants to create a new hook, or needs help with hook configuration.
567 -
majiayu000 Bundle Passwordless 2パスワードレス認証(Passwordless Authentication)機能の開発・修正を行う際に使用。FIDO2/WebAuthn, Passkey, FIDO-UAF実装時に役立つ。
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include dependency-health-loop, env-audit, skill-improvement-plan. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.