Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
solizardking Skill Pump Fee SystemImplement and audit the Pump.fun fee system, including market-cap fee tiers, creator fee vaults across Pump and PumpAMM, basis-point arithmetic, ceiling division, fee simulation, and dust-safe calculations. Use for protocol fee logic and creator-fee accounting.
0 -
solizardking Skill Cyber AuditRead-only exposure audit of the user's Mac (and ~/Documents/code projects) for a CVE, breach, malicious package, or other security advisory, then write a structured report to ~/Documents/security-audits/. Use when the user shares a breach/CVE/malware/supply-chain advisory and asks if they're affected, says "scan my system for X", "are we affected by Y", "check if I'm vulnerable to Z", or requests any hack/breach/cyber/vulnerability audit on this Mac. Output matches the existing audit format in ~/Documents/security-audits/.
0 -
anantha-236 Skill Springboot SecuritySpring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
1 -
anantha-236 Skill Springboot VerificationVerification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.
1 -
metinduraktr-44 Bundle Security QAGüvenlik QA rubric. Defense-only Security OS skill. Use for ASSESS-ONLY gap/control work.
0 -
metinduraktr-44 Bundle Archive LoopKampanya/LATOS arşiv döngüsü — ARCHIVE manifest + READ→DELTA→DIFF→WRITE→DIGEST; audit zinciri.
0 -
metinduraktr-44 Bundle Iam HardeningIAM least privilege gap. Defense-only Security OS skill. Use for ASSESS-ONLY gap/control work.
0 -
metinduraktr-44 Bundle Crypto AgilityAlgoritma çevikliği, TLS policy. Defense-only Security OS skill. Use for ASSESS-ONLY gap/control work.
0 -
metinduraktr-44 Bundle Secret HygieneSecret tarama, redaksiyon, vault pattern. Defense-only Security OS skill. Use for ASSESS-ONLY gap/control work.
0 -
metinduraktr-44 Bundle Firewall EngineAğ/uygulama engel politikası iskeleti. Defense-only Security OS skill. Use for ASSESS-ONLY gap/control work.
0 -
metinduraktr-44 Bundle Sbom ProvenanceCycloneDX/SPDX/SLSA kanıt yolu. Defense-only Security OS skill. Use for ASSESS-ONLY gap/control work.
0 -
metinduraktr-44 Bundle Threat ModelingSTRIDE/LINDDUN ASSESS threat model. Defense-only. Use for holding automation surfaces.
0 -
metinduraktr-44 Bundle Compliance MapperMap controls to NIST CSF 2.0, 800-53 R5, ISO 27001:2022, CIS v8.1, ASVS 5.0. Defense-only.
0 -
metinduraktr-44 Bundle Incident ResponseIR playbook — contain/eradicate/recover. Defense-only Security OS skill. Use for ASSESS-ONLY gap/control work.
0 -
metinduraktr-44 Bundle Privacy EngineeringPrivacy by design / DPIA iskelet. Defense-only Security OS skill. Use for ASSESS-ONLY gap/control work.
0 -
metinduraktr-44 Bundle Zero Trust ArchitectZTA mimari değerlendirme (800-207). Defense-only Security OS skill. Use for ASSESS-ONLY gap/control work.
0 -
metinduraktr-44 Bundle Detection EngineeringTespit kuralı taslağı (savunma). Defense-only Security OS skill. Use for ASSESS-ONLY gap/control work.
0 -
metinduraktr-44 Bundle Change Protocol EngineDeğişiklik/onay protokolü kontrolleri. Defense-only Security OS skill. Use for ASSESS-ONLY gap/control work.
0 -
metinduraktr-44 Bundle Security Expert EngineGüvenlik uzman persona DIGEST. Defense-only Security OS skill. Use for ASSESS-ONLY gap/control work.
0 -
metinduraktr-44 Skill Security AuditComprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.
0 -
metinduraktr-44 Bundle Vulnerability ManagementVM triage & SLA ASSESS. Defense-only Security OS skill. Use for ASSESS-ONLY gap/control work.
0 -
metinduraktr-44 Skill Otif AnalysisAudit delivery performance from order-level data - compute the OTIF metric ladder (tolerant to strict), find where lateness concentrates, and quantify the gap between the reported KPI and what customers experience. Use when the user mentions OTIF, on-time delivery, delivery performance, late orders, teslimat performansı, zamanında teslimat, or asks why customers complain despite a high on-time score. Differentiator - exposes measurement choices before optimizing operations.
0 -
metinduraktr-44 Bundle Conditional Policy EngineKoşullu erişim/politika kontrolleri. Defense-only Security OS skill. Use for ASSESS-ONLY gap/control work.
0 -
metinduraktr-44 Skill Laravel ExpertSenior Laravel Engineer role for production-grade, maintainable, and idiomatic Laravel solutions. Focuses on clean architecture, security, performance, and modern standards (Laravel 10/11+).
0 -
metinduraktr-44 Skill GRAPHQL ArchitectMaster modern GraphQL with federation, performance optimization, and enterprise security. Build scalable schemas, implement advanced caching, and design real-time systems.
0 -
metinduraktr-44 Skill Saas Multi TenantDesign and implement multi-tenant SaaS architectures with row-level security, tenant-scoped queries, shared-schema isolation, and safe cross-tenant admin patterns in PostgreSQL and TypeScript.
0 -
metinduraktr-44 Skill API Security TestingAPI security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.
0 -
metinduraktr-44 Skill Web Security TestingWeb application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and access control issues.
0 -
metinduraktr-44 Skill Safety Stock ReviewSize or audit safety stock with assumption checks - the z*sigma*sqrt(LT) formula plus an empirical stress test of what it actually delivers (cycle service vs fill rate) per variability class. Use when the user mentions safety stock, emniyet stoku, emniyet stoğu, reorder point, service level, stok seviyesi belirleme. Differentiator - refuses to hand back a number without validating the demand-distribution assumptions behind it.
0 -
mmehdi0606 Skill Audit SkillsExpert security auditor for AI Skills and Bundles. Performs non-intrusive static analysis to identify malicious patterns, data leaks, system stability risks, and obfuscated payloads across Windows, macOS, Linux/Unix, and Mobile (Android/iOS).
2 -
mmehdi0606 Bundle Security ReviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
2 -
mmehdi0606 Skill Postgres PatternsPostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices.
2 -
mmehdi0606 Skill Django VerificationVerification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.
2 -
mmehdi0606 Skill Nodejs Best PracticesNode.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.
2 -
mmehdi0606 Skill Audit Context BuildingEnables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.
2 -
mmehdi0606 Skill Cc Skill Security ReviewThis skill ensures all code follows security best practices and identifies potential vulnerabilities. Use when implementing authentication or authorization, handling user input or file uploads, or creating new API endpoints.
2
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include springboot-verification, cyber-audit, springboot-security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.