Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
seaworld008 Bundle Env Secrets ManagerManage environment files, required-variable validation, secret storage, leak detection, and credential rotation across development and production.
65 -
seaworld008 Skill Security Pen TestingPerform authorized security assessments, vulnerability scans, and penetration tests with explicit targets, scope, evidence, and remediation guidance.
65 -
seaworld008 Bundle Security And HardeningHarden authentication, input handling, storage, and integrations when implementing security controls or remediating concrete vulnerabilities.
65 -
seaworld008 Bundle Code Review And QualityReview code changes for correctness, maintainability, security, and validation evidence before integration or when a review is requested.
65 -
seaworld008 Skill Codeql Security Scanner用于通过 CodeQL 执行语义代码扫描、安全查询、自定义规则、SARIF 报告和 GitHub Code Scanning 集成。
65 -
seaworld008 Bundle Security Best PracticesUse when checking language or framework security best practices, producing security review reports, identifying insecure defaults, and recommending secure-by-default improvements.
65 -
seaworld008 Bundle Database Schema DesignerDesign relational database schemas from requirements and generate migrations, TypeScript/Python types, seed data, RLS policies, and indexes. Handles multi-tenancy, soft deletes, audit trails, versioning, and polymorphic associations.
65 -
seaworld008 Skill Information Security Manager Iso27001Design or audit ISO 27001 ISMS controls, security risk treatment, and compliance evidence, including healthcare and medical-device contexts.
65 -
infometa Bundle Outbound EngineDesign, analyze, and optimize cold outbound email campaigns for Instantly. Handles end-to-end ICP definition, expert panel scoring (recursive to 90+), sequence copywriting, infrastructure audit, capacity planning, and implementation docs. Use when asked to build cold outbound sequences, optimize cold email, analyze outbound campaigns, build sales sequences, build Instantly sequences, create cold outbound strategies, or design email campaigns. Supports both "start from scratch" and "optimize existing" modes.
228 -
infometa Bundle Stealth BrowserUltimate stealth browser automation with anti-detection, Cloudflare bypass, CAPTCHA solving, persistent sessions, and silent operation. Use for any web automation requiring bot detection evasion, login persistence, headless browsing, or bypassing security measures. Triggers on "bypass cloudflare", "solve captcha", "stealth browse", "silent automation", "persistent login", "anti-detection", or any task needing undetectable browser automation. When user asks to "login to X website", automatically use headed mode for login, then save session for future headless reuse.
228 -
infometa Skill Skills Security Check腾讯云鼎实验室出品,Skill安全审查工具。对用户指定的skill.md文件及其配套的文档、程序、脚本等进行全面安全审计,确保引用安全
228 -
infometa Bundle Charity Finance AssistantNonprofit finance and receipt management assistant. Use when users need to organize donation receipts, verify financial data, prepare audit materials, handle daily reimbursements, manage donation receipt ledgers, or understand nonprofit financial compliance requirements. Suitable for foundations, social organizations, and social service institutions. Trigger words: receipts, donation receipts, financial organization, reimbursement, ledger, reconciliation, audit preparation, expenditure details, management fees, invoicing, tax deduction, accounting entries, bookkeeping.
228 -
infometa Skill Ip IntakeCollect the concrete facts an IP task depends on before any substantive work — right type (copyright / patent / trademark / trade secret / domain), rights credentials and numbers (patent no., trademark reg./app. no., software-copyright reg. no., work, disputed domain), parties, subject matter, market/geographic scope, timeline, demands and standpoint (rights-holder vs accused party). Use this skill after scenario routing for almost every IP scenario except single-point knowledge Q&A. It carries per-scenario intake checklists; asks what is missing, uses mutually-exclusive assumptions where clarification would stall, and never fabricates rights facts.
228 -
infometa Skill Break TraceRoot-cause a reconciliation break to its source transaction or posting — follow the audit trail from the break row back to the originating entry on each side and state what differs and why. Use after gl-recon has classified a break.
228 -
infometa Skill Crm HygieneCRM cleanup and maintenance: dedupe contacts, update stale records, normalize deal stages, and ensure data quality. Triggers on: clean CRM, CRM cleanup, duplicate contacts, CRM maintenance, CRM audit.
228 -
infometa Bundle Ip Scenario RouterIdentify the user's true intellectual-property intent and route it to the correct scenario (IP-A~IP-F across copyright, patent, trademark, trade secret, domain and综合 needs). Use this skill FIRST for every IP request to determine scenario type, core objective, binding output standard, whether interactive intake is required, which professional IP databases to use, output weight tier, and the next skill in the chain — before any retrieval, analysis or drafting happens.
228 -
infometa Skill Quality Audit方案质量审计工具:魔鬼代言人质询、MECE校验、证据溯源检查、反模式识别(框架沙拉/赢在默认/共识幻觉等)。 触发词:帮我审一下这份方案、这份报告靠谱吗、复核一下这个决策逻辑、这个逻辑站得住吗。
228 -
infometa Skill Entity Evidence Audit审计公开材料中的主体和关键主张,把事实绑定到可回看的来源、日期与原文位置,并记录冲突、不利信息和未知。既可用于企业身份与候选证据,也可用于政策、园区材料、方法论和一般公开事实;没有企业对象时不得虚构实体或候选资产。唯一写来源、主张及证据台账,不决定业务优先级。
228 -
theheavenlyd3mon Bundle GodmodeJailbreak LLMs: Parseltongue, GODMODE, ULTRAPLINIAN.
28 -
theheavenlyd3mon Bundle Legal StrategyCLO/General Counsel methodology — regulatory landscape analysis (GDPR, CCPA, AI Act, sector-specific), IP strategy (patent, trademark, trade secret, open source licensing), contract risk assessment (indemnification, liability caps, force majeure), data privacy frameworks (privacy-by-design, DPIAs, data mapping), corporate governance (board responsibilities, fiduciary duties, shareholder rights), employment law (classification, IP assignment, non-competes).
28 -
theheavenlyd3mon Bundle Hermes Security AuditPerform a comprehensive security audit of a Hermes installation — check secrets, permissions, network exposure, code patterns, dependencies, and infrastructure. Returns prioritized findings with remediation steps.
28 -
theheavenlyd3mon Bundle API Design And EvolutionDesign, document, review, and evolve consumer-facing APIs and event interfaces. Use when choosing REST/HTTP, GraphQL, RPC, events, webhooks, or streaming; writing OpenAPI or AsyncAPI contracts; defining schemas, pagination, mutations, errors, idempotency, or API compatibility; or planning API versioning, deprecation, and migration. Use secure-software-engineering for a full security lifecycle, ADR authoring for durable architecture decisions, and spec-driven-development for a delivery specification and implementation gates.
28 -
theheavenlyd3mon Bundle Hermes Directory CleanupInspect, audit, and safely clean up the ~/.hermes directory to remove orphaned pre-profile data and prune per-profile skill bloat without breaking running agents.
28 -
theheavenlyd3mon Skill Pre Commit Security ChecklistRun before committing code. Catches mistakes Katana can't — secrets in code, missing validation, weak auth, debug leftovers.
28 -
theheavenlyd3mon Bundle Hermes Security HardeningComprehensive security hardening for Hermes installations — fixes permissions, sets up secret scanning, configures macOS Keychain integration, creates security policies, and installs pre-commit hooks.
28 -
theheavenlyd3mon Bundle Security Audit MethodologyPlan authorized security reviews with threat modeling, architecture and dependency audits, and vulnerability classification. Use for scoped defensive security assessment.
28 -
theheavenlyd3mon Bundle Obsidian Vault AuditSystematic audit and cleanup of an Obsidian vault: detect clutter, structural drift, oversized files, dual folders, and icarus accretion, then decompose into kanban tasks.
28 -
theheavenlyd3mon Bundle Privacy EngineeringTranslate privacy principles and legal requirements into data-flow, lifecycle, acceptance, and verification artifacts. Map data classification, purpose, processing, access, retention, deletion, residency, and consent; define verifiable privacy acceptance criteria; and produce data-lifecycle records, retention/deletion verification plans, and privacy change reviews. Use when engineering privacy into a system, feature, or data flow — not for legal advice, jurisdiction-specific regulatory interpretation, or replacing security engineering or incident response.
28 -
theheavenlyd3mon Bundle NPM Supply Chain SweepCheck npm installs after a supply-chain poisoning advisory.
28 -
theheavenlyd3mon Skill Markdown Repo Doc LintAudit and patch a repo's Markdown documentation for tone consistency, section-skeleton drift, dead relative links, and stale boilerplate. Use when asked to review READMEs, guides, profile docs, or any markdown corpus, and return exact diffs or a per-file verdict instead of summary prose.
28 -
theheavenlyd3mon Skill NPM Dependency RemediationRemediate npm vulnerability advisories on a Node project or fork with minimal risk. Clears in-range advisories via non-force `npm audit fix`, isolates force-required bumps (out-of-range) behind a human decision, and verifies the test suite stays green — including the NODE_ENV=production dev-dependency trap that makes `npm test` fail with "vitest: command not found". Trigger when the user says "npm audit shows highs", "remediate vulnerabilities", "update deps on the fork", "fix npm audit", or asks to clear security advisories during a maintenance pass.
28 -
theheavenlyd3mon Bundle Macos Host Security AssessmentAudit a macOS host for malware and vulnerabilities.
28 -
theheavenlyd3mon Bundle Macos Endpoint Security AssessmentScan a Mac for malware, persistence, and overlooked vulns.
28 -
ichichuang Bundle Typescript Import AuditSystematic workflow for auditing TypeScript codebases for import hygiene issues (value vs. type imports, duplicates), missing base class extensions, and incomplete barrel file re-exports, with actionable fix patterns.
0 -
ichichuang Bundle Dir Verify Parallel Shell AuditDiagnose and resolve file access issues by verifying directory structure, reading multiple files in parallel batches, running combined shell property checks (head/wc-l) in the same iteration as directory listing, and validating TypeScript import patterns — all with built-in guidance to minimize total iteration count.
0 -
ichichuang Bundle Verify Directory Structure Parallel AuditDiagnose and resolve file access issues by verifying directory structure, then reading multiple files in parallel batches for efficient auditing, with built-in guidance for validating TypeScript import patterns.
0
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include verify-directory-structure-parallel-audit, security-pen-testing, dir-verify-parallel-shell-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.