Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Skill Auditor 7Audit an existing SKILL.md against the unified AgentOps template (15 checks). Triggers: "audit skill", "skill quality review", "is this skill ready".
567 -
majiayu000 Bundle Ca Pr 2Open a pull request the only sanctioned way — clear every BLOCK-level review finding, then stage the PR. Never a direct write to the default branch.
567 -
majiayu000 Bundle Google Docs Sheets 2Export Google Docs and Google Sheets (spreadsheets) to Markdown files or stdout. Use when asked to fetch, download, or ingest Google Docs/Sheets content for summarization, analysis, or context loading. Tries gcloud ADC first with browser OAuth fallback.
567 -
majiayu000 Bundle Security Compliance Automation 2| ID | sre-security-compliance-automation |
567 -
majiayu000 Bundle Security Scan 12Run a security-oriented review of dependencies, secrets exposure, configuration risk, and code-level security issues for the affected area.
567 -
majiayu000 Bundle Security Suite 2Run composable security analysis.
567 -
majiayu000 Bundle Aif Review 2Perform code review on staged changes or a pull request. Checks for bugs, security issues, performance problems, and best practices. Use when user says "review code", "check my code", "review PR", or "is this code okay".
567 -
majiayu000 Bundle Financial Close 2Month-end and year-end close workflow covering journal entries, reconciliations, close procedures, and audit preparation. Delivers accurate, timely close with full audit trail.
567 -
majiayu000 Bundle Corrections Audit 3Use to analyze correction trends, surface recurring patterns, and graduate repeat corrections to guardrails or anti-patterns.
567 -
majiayu000 Bundle API Review 5Use this skill to review public API changes, design new surfaces, audit consistency, and validate documentation completeness. Run it before any API release to confirm alignment with project guidelines.
567 -
majiayu000 Bundle Ca Preview 2Zero-onboarding, read-only dry-run of the reviewer fleet against the current uncommitted diff. Predicts reviewers, runs the state-free secret scan, writes nothing.
567 -
majiayu000 Bundle Incoherence 4Detect contradictions between documentation and code, ambiguous specs, and policy violations across a codebase. Use when documentation seems stale, specs conflict with implementation, or a pre-release consistency audit is needed. Produces an actionable incoherence report with resolution workflow.
567 -
majiayu000 Bundle Ca Init 2Opt this repo into codeArbiter — scaffold the root-level .codearbiter/ state store.
567 -
majiayu000 Bundle Ca Review 2Review a diff with the reviewer fleet, funneled to one triaged verdict. Targets the current working diff, a path, or an inbound GitHub PR.
567 -
majiayu000 Bundle Ca Sprint 2Autonomous sprint — one interactive spec gate, then plan-to-PR execution with every auto-decision SMARTS-scored and logged. Hard gates remain true stops.
567 -
majiayu000 Bundle Healthcheck 4Host security hardening and risk-tolerance configuration for OpenPaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenPaw cron scheduling for periodic checks, or version status checks on a machine running OpenPaw (laptop, workstation, Pi, VPS).
567 -
majiayu000 Bundle Fixing Tests 3Use when tests themselves are broken, test quality is poor, or user wants to fix/improve tests. Triggers: 'test is broken', 'test is wrong', 'test is flaky', 'make tests pass', 'tests need updating', 'green mirage', 'tests pass but shouldn't', 'audit report findings', 'run and fix tests'. Three modes: fix specific tests, process green-mirage audit findings, and run-then-fix. NOT for: bugs in production code caught by correct tests (use debugging).
567 -
majiayu000 Bundle Ca Override 2Sanctioned, logged bypass of a gate or hard rule — one audit line, then proceed.
567 -
majiayu000 Bundle Ca Tribunal 2Deep, rarely-convened whole-codebase audit — eleven specialist lenses, a resumable on-disk audit log, findings filed as GitHub issues on approval. Expensive; estimates cost and STOPs before running. Never a required gate.
567 -
majiayu000 Bundle 404 Frameworks Quarkus Security 2Use when you need to design, review, or improve security in Quarkus applications — including Quarkus Security with JWT/OIDC, basic auth, @RolesAllowed / @Authenticated / @PermitAll, SecurityIdentity, permission checks, path-based authorization in configuration, exception mapping for auth failures, and sensitive-data-safe logging. This should trigger for requests such as Add Quarkus security support; Review Quarkus security configuration; Improve API authorization in Quarkus; Add JWT/OIDC security in Quarkus; Harden Quarkus authorization rules. Part of cursor-rules-java project
567 -
majiayu000 Bundle Ca Audit 2Assemble the governance record for a range — commits, overrides, ADRs, sprint auto-decisions, open questions, checkpoint findings — into one dated audit packet. Read-only.
567 -
majiayu000 Bundle Git 21Git operations with conventional commits. Use for staging, committing, pushing, PRs, merges. Auto-splits commits by type/scope. Security scans for secrets.
567 -
majiayu000 Bundle Repo Generating Validation Reports 3Guidelines for generating validation/audit reports with UUID chains, progressive writing, and UTC+7 timestamps
567 -
majiayu000 Bundle Context Check 3Optional manual drift audit — report stale provenance-tracked docs (via _provenancelib drift detection across .codearbiter/.provenance/), then per stale doc offer re-scout / re-baseline / defer. Not the daily loop; commit-gate auto-heal owns routine maintenance.
567 -
majiayu000 Bundle Design Guards 2Investigate a bug pattern audit report and design architectural guards (tests, contracts, structural changes) that provide immunity to each identified pattern. Use when user says "design guards", "design defenses", or wants architectural solutions for bug patterns.
567 -
majiayu000 Bundle Fact Checking 3Use when reviewing code changes, auditing documentation accuracy, validating technical claims before merge, or user says "verify claims", "factcheck", "audit documentation", "validate comments", "are these claims accurate".
567 -
majiayu000 Bundle Better Auth 9Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn support, session management, role-based access control (RBAC), rate limiting, and database adapters. Use when adding authentication to applications, implementing OAuth flows, setting up 2FA/MFA, managing user sessions, configuring authorization rules, or building secure authentication systems for web applications.
567 -
majiayu000 Bundle Ca Add Dep 2Vet a new or changed third-party dependency for license, provenance, and supply-chain risk before any install runs.
567 -
majiayu000 Bundle Owasp Top 10 4OWASP Top 10 security vulnerabilities with detection and remediation patterns. Use when conducting security audits, implementing secure coding practices, or reviewing code for common security vulnerabilities.
567 -
majiayu000 Bundle Pci Compliance 3Implement PCI DSS compliance requirements for secure handling of payment card data and payment systems. Use when securing payment processing, achieving PCI compliance, or implementing payment card security measures.
567 -
majiayu000 Bundle Security Audit 24Procedure for analyzing code or dependencies for vulnerabilities
567 -
majiayu000 Bundle Backend Safeguard 2Supabase schema validation, RLS enforcement, and API security best practices.
567 -
majiayu000 Bundle Gemini Peer Review 4[CLAUDE CODE ONLY] Leverage Gemini CLI for AI peer review, second opinions on architecture and design decisions, cross-validation of implementations, security analysis, alternative approaches, and hol
567 -
majiayu000 Bundle Zero Day Rules 2This skill should be used when the user asks about "game rules", "scoring", "phases", "Attack token", "Exploit token", "Ghost token", "tile placement rules", "path matching", "movement rules", "winning conditions", "turn actions", "firewall breach", "path segments", "edge nodes", or discusses Zero-Day Attack game mechanics and design.
567 -
majiayu000 Bundle 504 Frameworks Micronaut Security 2Use when you need to design, review, or improve security in Micronaut applications — including micronaut-security authentication, @Secured and intercept-url-map rules, JWT/session strategies, SecurityService checks, CORS, CSRF awareness for browser apps, rejection handlers, and sensitive-data-safe logging. This should trigger for requests such as Add Micronaut security support; Review Micronaut security configuration; Improve API authorization in Micronaut; Add JWT security in Micronaut; Harden Micronaut route authorization rules. Part of cursor-rules-java project
567 -
majiayu000 Bundle Qc Specialist 2[Project Management] Enforce quality gates, verify compliance with standards, track quality metrics, and generate audit trails. Triggers: quality gate, compliance, audit trail, quality metrics, qc specialist, standards verification.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include skill-auditor, ca-pr, google-docs-sheets. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.