Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Util Research Library 2Systematic library evaluation with emphasis on readability, actionable insights, and informed decision-making. Use when asked "should we use X", "is there a better library", during security audits, or making migration decisions. Produces concise, scannable reports that drive adoption decisions - not walls of text.
567 -
majiayu000 Bundle Idor Vulnerability Testing 2This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references," or "bypass authorization to access other users' data." It provides comprehensive guidance for detecting, exploiting, and remediating IDOR vulnerabilities in web applications.
567 -
majiayu000 Bundle Onepassword CLI Coder 2This skill guides integrating 1Password CLI (op) for secret management in development workflows. Use when loading secrets for infrastructure, deployments, or local development.
567 -
majiayu000 Bundle Two Factor Auth Issue 2Customer has issues with two-factor authentication, security codes, or device verification.
567 -
majiayu000 Bundle Developer Detective 2⚡ PRIMARY TOOL for: 'how does X work', 'find implementation of', 'trace data flow', 'where is X defined', 'audit integrations', 'find all usages'. Uses claudemem v0.3.0 AST with callers/callees analysis. GREP/FIND/GLOB ARE FORBIDDEN.
567 -
majiayu000 Bundle Qe Security Compliance 2Security auditing, vulnerability scanning, and compliance validation for OWASP, SOC2, GDPR, and other standards.
567 -
majiayu000 Bundle Workflow Postmortem 2Dual-mode workflow issue logger. Use with mode=log to append mistakes during waves. Use with mode=summary at workflow end to review accumulated issues. Use when completing /build, /audit, or /ms workflows.
567 -
majiayu000 Bundle Managing Permissions 2Guide for configuring Claude Code permissions in settings.json with security best practices for allow, ask, and deny rules. Use when: (1) Setting up or modifying permissions in settings.json, (2) Disc
567 -
majiayu000 Bundle Deps Health Inline 2Inline orchestration workflow for dependency audit and updates. Provides step-by-step phases for dependency-auditor detection, priority-based updates with dependency-updater, and verification cycles.
567 -
majiayu000 Bundle Scan Vulnerabilities 2Detect security vulnerabilities in code and dependencies. Use when auditing security.
567 -
majiayu000 Bundle Software Code Review 2Patterns, checklists, and templates for systematic code review with a focus on correctness, security, readability, performance, and maintainability.
567 -
majiayu000 Bundle Traceability Auditor 2Validates complete requirements traceability across EARS requirements → design → tasks → code → tests. Trigger terms: traceability, requirements coverage, coverage matrix, traceability matrix, requirement mapping, test coverage, EARS coverage, requirements tracking, traceability audit, gap detection, orphaned requirements, untested code, coverage validation, traceability analysis. Enforces Constitutional Article V (Traceability Mandate) with comprehensive validation: - Requirement → Design mapping (100% coverage) - Design → Task mapping - Task → Code implementation mapping - Code → Test mapping (100% coverage) - Gap detection (orphaned requirements, untested code) - Coverage percentage reporting - Traceability matrix generation Use when: user needs traceability validation, coverage analysis, gap detection, or requirements tracking across the full development lifecycle.
567 -
majiayu000 Bundle Ln 620 Codebase Auditor 7Coordinates 9 specialized audit workers (security, build, architecture, code quality, dependencies, dead code, observability, concurrency, lifecycle). Researches best practices, delegates parallel audits, aggregates results into single Linear task in Epic 0.
567 -
majiayu000 Bundle Authorization Endpoint 2認可エンドポイント(Authorization Endpoint)機能の開発・修正を行う際に使用。Authorization Request処理、同意フロー、Authorization Code生成実装時に役立つ。
567 -
majiayu000 Bundle Claude Security Review 3Security-focused review for Hyperlane protocol code. Use for Solidity contracts, Rust agents, and infrastructure changes.
567 -
majiayu000 Bundle Workflow Development 2Create, debug, and optimize GitHub Actions workflows with security best practices. USE THIS SKILL when user says "create workflow", "fix workflow", "workflow fails", "add CI", "reusable workflow", or needs help with GitHub Actions.
567 -
majiayu000 Bundle Quality Security Scan 2Scan code for security vulnerabilities and unsafe patterns. Use before committing sensitive code or in security reviews.
567 -
majiayu000 Bundle Batch Rewrite Pattern 2Cascade the same edit pattern across N files safely. Use when applying the same refactor to multiple files (e.g. swap import paths across 11 scripts, rename a symbol, migrate a call signature). Detects the common-shape-across-files situation and turns an N-file cascade into a planned audit → apply → verify workflow instead of N sequential manual edits.
567 -
majiayu000 Bundle Moai System Universal 2The ultimate unified development skill combining 25+ programming languages, 9+ BaaS providers, 6+ development functions, and 15+ security capabilities with AI orchestration, Context7 integration, enterprise compliance, and end-to-end project automation
567 -
majiayu000 Bundle 1password Direnv Secrets 3Secure credential management using 1Password CLI with zero plaintext secrets on disk.
567 -
majiayu000 Bundle Red Team 5Probe docs and skills.
567 -
majiayu000 Bundle Git 20Git operations with conventional commits. Use for staging, committing, pushing, PRs, merges. Auto-splits commits by type/scope. Security scans for secrets.
567 -
majiayu000 Bundle Oss Docs 2Scaffold or audit OSS docs.
567 -
majiayu000 Bundle Network Policies Security 2| ID | sre-network-policies-security |
567 -
majiayu000 Bundle Architecture Paradigm Cqrs Es 3CQRS and Event Sourcing for auditability, read/write separation, and temporal queries. Triggers: CQRS, event sourcing, audit trail, temporal queries Use when: read/write scaling differs or audit trail required DO NOT use when: simple CRUD - use architecture-paradigms first.
567 -
majiayu000 Bundle 701 Technologies Openapi 2Use when you need framework-agnostic OpenAPI 3.x guidance — spec structure, metadata and versioning, paths and operations, reusable schemas, security schemes, examples, documentation quality, contract validation (e.g. Spectral), breaking-change awareness, and handoffs to codegen — without choosing Spring Boot, Quarkus, or Micronaut. This should trigger for requests such as Review an OpenAPI; Improve an OpenAPI; Improve API contract; Improve API schema design. Part of cursor-rules-java project
567 -
majiayu000 Bundle Wheels Controller Generator 2Generate Wheels MVC controllers with CRUD actions, filters, parameter verification, and proper rendering. Use when creating or modifying controllers, adding actions, implementing filters for authentication/authorization, handling form submissions, or rendering views/JSON. Ensures proper Wheels conventions and prevents common controller errors.
567 -
majiayu000 Bundle Skill Auditor 6Audit a SKILL.md (15 checks).
567 -
majiayu000 Bundle Ln 760 Security Setup 3Coordinates security scanning (secrets + deps). Delegates to ln-761/ln-762. Generates SECURITY.md, pre-commit hooks, CI workflow.
567 -
majiayu000 Bundle Redteam 5Adversarial analysis with 32 agents. USE WHEN red team, attack idea, counterarguments, critique, stress test. SkillSearch('redteam') for docs.
567 -
majiayu000 Bundle Dependency Security Scanning 2依存関係の脆弱性スキャン、CVE評価、レポート作成を体系化するスキル。 SCAの運用と修正計画の整理を支援する。 Anchors: • OWASP Dependency-Check / 適用: 依存スキャン / 目的: 検出の標準化 • CVSS v3.1 Specification / 適用: 重大度評価 / 目的: 優先度の整合性 • Web Application Security / 適用: 脅威評価 / 目的: リスク判定の一貫性 Trigger: Use when scanning dependencies for vulnerabilities, evaluating CVE reports, producing audit reports, or planning remediation. dependency scan, CVE, CVSS, SCA, supply chain security, audit report
567 -
majiayu000 Bundle Privacy Check 2Use to assess Privacy by Design compliance and GDPR/data protection alignment for a feature or system.
567 -
majiayu000 Bundle Ck Research 2Research technical solutions, analyze architectures, gather requirements thoroughly. Use for technology evaluation, best practices research, solution design, scalability/security/maintainability analysis.
567 -
majiayu000 Bundle Code Review 96Structured code review guidance focused on correctness, regressions, security, performance, and missing tests.
567 -
majiayu000 Bundle Security Vulnerability Report 2Security researcher reports security vulnerabilities or inquires about bug bounty programs.
567 -
majiayu000 Bundle Unsafe Review 2Comprehensive review of unsafe code — audits safety invariants, demands benchmark+ASM proof of performance benefit, and verifies Miri/Kani/fuzz/property test coverage for every unsafe block
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include util-research-library, idor-vulnerability-testing, onepassword-cli-coder. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.