Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle SagemathRun SageMath computations through the existing Anaconda environment named `sage`. Use when Codex needs Sage for CTF and cryptography work such as asymmetric cryptography, finite fields, elliptic curves, lattices, polynomial algebra, modular arithmetic, discrete logs, small-root attacks, or PRNG cryptanalysis, and when execution should happen from inline code or a `.sage` file instead of plain Python.
567 -
majiayu000 Bundle Zero Day· Hunt novel vulnerabilities: reversing, patch diffing, fuzzing, attack surface, PoCs. Triggers: 'zero-day', '0-day', 'vulnerability research', 'variant analysis', 'fuzz', 'exploit dev', 'CVE'. Not SAST: security-audit.
567 -
majiayu000 Bundle Fix TestsUse when tests are failing, test quality issues were identified, or user wants to fix/improve specific tests. Accepts green-mirage-audit reports, general instructions, or can run tests and fix failures automatically. Lighter-weight than implement-feature, focused on test remediation.
567 -
majiayu000 Bundle Nean KitStartup runbook for NEAN projects. Establishes stack decisions, scaffolds the project, configures GitHub security, and confirms governing constraints.
567 -
majiayu000 Bundle Feed DietAudit your information diet across HN and RSS feeds — beautiful reports with category breakdowns, ASCII charts, and personalized recommendations.
567 -
majiayu000 Bundle GRAPHQL SchemaGraphQL schema validation and optimization with federation support
567 -
majiayu000 Bundle Overleaf SyncTwo-way sync between a local paper directory and an Overleaf project, so ARIS audit/edit workflows stay on the local copy while collaborators edit in the Overleaf web UI. Use when user says "同步 overleaf", "overleaf sync", "推送到 overleaf", "connect overleaf", "Overleaf 桥接", "pull overleaf", "push overleaf", or wants to bridge their ARIS paper directory with an Overleaf project.
567 -
majiayu000 Bundle Vscode DoctorDiagnose slow or freezing VS Code-compatible editors with evidence-first, zero-hardcoded-assumption workflow. Use when the user reports editor lag, typing delay, UI freezes, extension host stalls, file watcher noise, high editor CPU/RSS, or wants a safe editor performance audit.
567 -
majiayu000 Bundle Audit And FixI'll perform a comprehensive security audit and automatically fix vulnerabilities for: $ARGUMENTS
567 -
majiayu000 Bundle Audit ProcessRun a comprehensive multi-stage automation audit with parallel agents
567 -
majiayu000 Bundle Audit SupportSupport SOX 404 compliance with control testing methodology, sample selection, and documentation standards.
567 -
majiayu000 Bundle Auth Securitydescription: Experto en autenticación, autorización y seguridad
567 -
majiayu000 Bundle Check LandingAudit landing page: value prop, CTA, social proof, mobile, load time. Outputs structured findings. Use log-landing-issues to create issues. Invoke for: landing page review, conversion audit, launch readiness.
567 -
majiayu000 Bundle Code CommentsExtract comment locations from code files for analysis. Use when cleaning comments, auditing code documentation, or analyzing comment patterns. Supports Python, JavaScript, TypeScript, Go, Rust, Java, C/C++, Ruby, PHP, Shell scripts. Trigger terms - comments, extract comments, code comments, comment analysis, documentation audit, comment cleanup.
567 -
majiayu000 Bundle Command AuditAudits command files for correctness and best practices. Use when reviewing, improving, or validating commands, checking frontmatter, assessing structure, or learning command quality standards.
567 -
majiayu000 Bundle Context AuditComprehensive quality audit for CLAUDE.md context files. Use when performing thorough quality checks, preparing for releases, ensuring context efficiency, or verifying token optimization.
567 -
majiayu000 Bundle Crack 7z HashThis skill provides guidance for cracking 7z archive password hashes. It should be used when tasks involve extracting hashes from password-protected 7z archives, selecting appropriate cracking tools, and recovering passwords through dictionary or brute-force attacks. Applicable to password recovery, security testing, and CTF challenges involving encrypted 7z files.
567 -
majiayu000 Bundle Docs WorkflowFour slash commands for documentation lifecycle: /docs, /docs-init, /docs-update, /docs-claude. Create, maintain, and audit CLAUDE.md, README.md, and docs/ structure with smart templates. Use when: starting new projects, maintaining documentation, auditing docs for staleness, or ensuring CLAUDE.md matches project state.
567 -
majiayu000 Bundle E2e Test PlanCreate comprehensive E2E test plans with deep application analysis, navigation coverage audit, and browser-testable scenarios
567 -
majiayu000 Bundle Epic SecurityGuide on security practices including CSP, rate limiting, and session security for Epic Stack
567 -
majiayu000 Bundle Fact CheckingUse when reviewing code changes, auditing documentation accuracy, validating technical claims before merge, or user says "verify claims", "factcheck", "audit documentation", "validate comments", "are these claims accurate".
567 -
majiayu000 Bundle Keybind AuditAnalyze keybindings across all dotfiles for conflicts, duplicates, and inconsistencies. Use when modifying keybindings or checking for conflicts.
567 -
majiayu000 Bundle Manage SkillsManage and maintain VRP Toolkit skills through compliance checking, audit tracking, and documentation synchronization. Use when (1) adding or modifying skills, (2) checking skill compliance with project standards, (3) auditing SKILLS.md vs skills directory consistency, (4) recording skill changes to SKILLS_LOG.md, or (5) performing periodic skill health checks. Ensures skills stay independent, under 500 lines, properly structured, and well-documented.
567 -
majiayu000 Bundle Managing TagsManage and consolidate tags. Use when asked to "clean up tags", "consolidate tags", "tag audit", "merge tags", or "rename tag".
567 -
majiayu000 Bundle Mdm CobordismmacOS MDM with auth manifolds as cobordisms for credential derivation
567 -
majiayu000 Bundle Mit LicensingAudit dependency licenses for MIT compatibility. Use when the user wants to check if their project's dependencies are compatible with MIT license, find problematic licenses (GPL, AGPL, etc.), or generate a license audit report. Supports Node.js (npm/pnpm) and Rust (Cargo) projects.
567 -
majiayu000 Bundle Package AuditScan for security vulnerabilities using pnpm audit, Snyk, and automated tools. Use when checking security, before deployments, or resolving CVEs.
567 -
majiayu000 Bundle Perl ValidateThis skill should be used when the user asks to "validate Perl script", "check Perl syntax", "verify Perl code", "/perl-validate", or mentions script validation, compile check, security review, or best practice compliance for Perl code.
567 -
majiayu000 Bundle PHP StandardsPHP coding standards for Oh My Brand! theme. WordPress Coding Standards, strict typing, escaping, sanitization, DocBlocks, and security practices. Use when writing PHP functions, classes, or render templates.
567 -
majiayu000 Bundle Product RoastComprehensive product audit skill combining brutal UX/code roasting with behavioral psychology-informed vision crafting. Use when analyzing apps to find bugs, missed opportunities, and transformative improvements. Generates roast reports, vision documents, prioritized roadmaps, GitHub issues, and implementation specs. Works as a guided workshop with interactive questioning.
567 -
majiayu000 Bundle Python SkillsShared Python best practices for LlamaFarm. Covers patterns, async, typing, testing, error handling, and security.
567 -
majiayu000 Bundle Quality AuditMeta-skill for auditing and validating skill quality. Use when reviewing skills for consistency, completeness, accuracy, and adherence to standards. Provides structured rubrics, scoring frameworks, and actionable recommendations.
567 -
majiayu000 Bundle Report WriterGenerates professional reports from research and data
567 -
majiayu000 Bundle Reverse ProxyManage incoming internet traffic and reverse proxy configuration on the home network gateway. Configure Caddy, OAuth2 authentication, fail2ban security, and traffic routing.
567 -
majiayu000 Bundle Review SonnetFast code/plan review for quality, security, and tests. Use for quick reviews before deeper analysis.
567 -
majiayu000 Bundle Risk AssessorPerform comprehensive risk assessments on OSCAL systems including threat modeling, vulnerability analysis, risk scoring, and POA&M generation. Use this skill to evaluate security posture and prioritize remediation efforts.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include sagemath, zero-day, fix-tests. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.