Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
a5c-ai Bundle Slither AnalysisExpert integration with Slither static analyzer for smart contract vulnerability detection, code quality analysis, and security reporting. Supports all Slither detectors and custom analysis configurations.
1.7k -
a5c-ai Bundle Crypto PrimitivesImplementation and secure usage of cryptographic primitives including ECDSA, BLS, Schnorr signatures, key derivation, secret sharing, and constant-time operations. Provides guidance for secure cryptographic implementations in blockchain applications.
1.7k -
a5c-ai Bundle Git Forensics ScannerGit diff forensics for surfacing and classifying code changes for trojan detection
1.7k -
a5c-ai Bundle Smart Contract Analysis SkillEthereum and blockchain smart contract security analysis
1.7k -
a5c-ai Skill Five S Auditor5S workplace organization audit skill with scoring, photo documentation, and sustainability tracking
1.7k -
a5c-ai Bundle Owasp Security ScannerAutomated OWASP Top 10 vulnerability detection and assessment. Run OWASP ZAP automated scans, detect injection vulnerabilities, identify broken authentication patterns, check for sensitive data exposure, analyze security misconfigurations, and generate OWASP-compliant reports.
1.7k -
a5c-ai Skill Quality AuditorInternal quality audit skill with planning, execution, findings documentation, and corrective action tracking
1.7k -
a5c-ai Bundle Gdpr Compliance AutomatorGDPR compliance assessment and automation for data mapping, consent management, DSAR handling, and privacy impact assessments
1.7k -
a5c-ai Bundle Soc2 Compliance AutomatorSOC 2 Trust Services Criteria compliance automation for evidence collection, control mapping, and audit preparation
1.7k -
a5c-ai Bundle Hipaa Compliance AutomatorHIPAA security and privacy compliance automation for ePHI protection, safeguards assessment, and audit preparation
1.7k -
a5c-ai Bundle Electron Ipc Security AuditAnalyze Electron IPC implementations for security vulnerabilities including contextIsolation, nodeIntegration, preload scripts, and channel validation
1.7k -
a5c-ai Bundle Key Management OrchestratorCryptographic key lifecycle management orchestration including generation, rotation, and destruction across key management systems
1.7k -
a5c-ai Bundle Sandbox Entitlements AuditorAudit and recommend minimal sandbox entitlements for secure desktop applications
1.7k -
a5c-ai Bundle Pci Dss Compliance AutomatorPCI DSS compliance assessment and reporting for cardholder data protection, SAQ automation, and ASV scan orchestration
1.7k -
a5c-ai Bundle Secure Coding Training SkillDeveloper security training and assessment for secure coding practices and vulnerability prevention
1.7k -
a5c-ai Bundle Compliance ValidatorValidate compliance during migration with rule checking, audit trails, and security control validation
1.7k -
a5c-ai Bundle Vendor Security QuestionnaireAutomated vendor security assessment through questionnaire generation, response parsing, and risk scoring
1.7k -
a5c-ai Bundle Vulnerability ScannerSecurity vulnerability scanning for dependencies and code, with CVE database checking and risk assessment
1.7k -
a5c-ai Skill Freight Audit ValidatorAutomated freight bill validation skill with discrepancy detection and payment processing automation
1.7k -
a5c-ai Bundle Electron Main Preload GeneratorGenerate secure main process and preload script boilerplate with proper context isolation, IPC patterns, and security best practices for Electron applications
1.7k -
a5c-ai Skill Tech Stack ScannerAutomated technical architecture review, security assessment, scalability analysis
1.7k -
a5c-ai Skill Energy AuditorProcess energy audit skill for consumption analysis, benchmarking, and efficiency improvement identification
1.7k -
a5c-ai Skill Adversarial Proof AuditAudit immutable mathematical artifacts through isolated evidence-focused review lenses
1.7k -
a5c-ai Skill Audit Trail VerifierVerifies financial data against source documents, bank statements, contracts
1.7k -
a5c-ai Skill Hipaa Compliance ValidatorHIPAA compliance validation skill for genomic data handling and audit
1.7k -
a5c-ai Skill Audit Sampling CalculatorStatistical and non-statistical audit sampling skill with sample size determination and evaluation
1.7k -
a5c-ai Skill Audit Workpaper GeneratorAutomated audit workpaper preparation skill with PBC list management
1.7k -
a5c-ai Skill Medical Coding AuditReview clinical documentation and assigned codes for accuracy, compliance, and optimization, identifying documentation improvement opportunities and coding errors
1.7k -
a5c-ai Skill Risk Mitigation PlanningDevelop comprehensive risk management plans for collections and cultural venues including disaster preparedness, security protocols, and insurance coordination
1.7k -
a5c-ai Skill Regulatory Compliance AssessmentEvaluate organizational compliance with healthcare regulations including HIPAA, CMS Conditions of Participation, and accreditation standards through gap analysis and audit procedures
1.7k -
curiositech Skill Dag Scope EnforcerRuntime enforcement of file system boundaries and tool access restrictions. Blocks unauthorized operations and logs violations. Activate on 'enforce scope', 'access control', 'boundary enforcement', 'tool restrictions', 'runtime security'. NOT for validation (use dag-permission-validator) or isolation management (use dag-isolation-manager).
10 -
curiositech Skill Code Review ChecklistGenerates comprehensive, context-aware code review checklists tailored to the specific codebase, programming language, and team standards. Analyzes PR diffs and suggests what reviewers should focus on.
10 -
curiositech Bundle Dependency ManagementManaging third-party dependencies — version pinning, security auditing, license compliance, update workflows, lockfile management, supply chain security. Activate on "npm audit", "dependabot", "renovate", "pin versions", "dependency update", "supply chain", "license compliance", "lockfile", "security advisory", "typosquatting", "SBOM". NOT for internal monorepo package management (use monorepo-management) or publishing your own packages to npm/PyPI.
10 -
curiositech Skill Dag Permission ValidatorValidates permission inheritance between parent and child agents. Ensures child permissions are equal to or more restrictive than parent. Activate on 'validate permissions', 'permission check', 'inheritance validation', 'permission matrix', 'security validation'. NOT for runtime enforcement (use dag-scope-enforcer) or isolation management (use dag-isolation-manager).
10 -
curiositech Skill Observability Apm ExpertOpenTelemetry, distributed tracing, Grafana, and Datadog for full-stack observability. Activate on: observability, tracing, OpenTelemetry, Grafana, Datadog, metrics, logging, APM, SLO, alerting. NOT for: application error handling (use relevant language skill), security monitoring (use relevant security skill).
10 -
jeremylongshore Bundle Audit Tests"Diagnostic-only test suite auditor. Classifies repo type, maps against\ \ 7-layer testing taxonomy (git hooks \u2192 static \u2192 unit \u2192 integration\ \ \u2192 system \u2192 E2E \u2192 acceptance), runs deterministic quality gates\ \ (coverage, mutation, CRAP, architecture, escape-scan), builds RTM / personas /\ \ journeys traceability, produces TEST_AUDIT.md, updates tests/TESTING.md, and mandatorily\ \ hands off to implement-tests when gaps are found. Use when auditing test quality,\ \ finding test gaps, or running the full 7-layer sweep. Trigger with \"audit tests\"\ , \"find gaps\", \"test audit\", \"check test quality\", \"full sweep\", \"7-layer\ \ audit\", \"rtm check\"."
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include audit-sampling-calculator, audit-workpaper-generator, code-review-checklist. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.