Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Rust ReviewerWHEN: Rust project review, ownership/borrowing, error handling, unsafe code, performance WHAT: Ownership patterns + Lifetime analysis + Error handling (Result/Option) + Unsafe audit + Idiomatic Rust WHEN NOT: Rust API → rust-api-reviewer, Go → go-reviewer
567 -
majiayu000 Bundle Secure CodingIncorporating security at every step of software development – writing code that defends against vulnerabilities and protects user data.
567 -
majiayu000 Bundle Security GateClassifies inbound Telegram messages for telclaude as ALLOW/WARN/BLOCK with brief rationale.
567 -
majiayu000 Bundle Security LensApply security awareness during code review and implementation. Catches common vulnerabilities without requiring full security audit.
567 -
majiayu000 Bundle Security ScanProactive security scanning. Triggers when modifying auth, API endpoints, user data, or sensitive operations.
567 -
majiayu000 Bundle Security ViteReview Vite security audit patterns for SPA and dev server security. Use for auditing VITE_* exposure, build-time secrets, and proxy configs. Use proactively when reviewing Vite apps (vite.config.ts present). Examples: - user: "Audit Vite env vars" → check for secrets with VITE_ prefix - user: "Check Vite build config" → verify define block and source maps - user: "Review Vite dev server" → check host binding and proxy security - user: "Scan Vite bundles" → search dist/ for leaked API keys or secrets - user: "Audit Vite SPA auth" → verify server-side auth vs client route guards
567 -
majiayu000 Bundle Senior SecopsComprehensive SecOps skill for application security, vulnerability management, compliance, and secure development practices. Includes security scanning, vulnerability assessment, compliance checking, and security automation. Use when implementing security controls, conducting security audits, responding to vulnerabilities, or ensuring compliance requirements.
567 -
majiayu000 Bundle Sitemap AuditAudit website sitemaps for AEO optimization opportunities. Use when analyzing site structure, checking indexed URLs, planning content migrations, or when user mentions "sitemap", "site structure", "URL audit", "page inventory", or "content migration".
567 -
majiayu000 Bundle Social BridgeAggregate security content from Telegram public channels and X/Twitter accounts, forward to Discord webhooks, and persist to graph-memory. Uses Telethon (MTProto) for Telegram, surf browser automation for X, and Discord webhooks for delivery.
567 -
majiayu000 Bundle Stress TesterComprehensive stress testing skill for FlowState. Runs reliability, backup, container, security, and performance tests. Use before releases, after major refactoring, or when reliability is questioned.
567 -
majiayu000 Bundle Supabase HelpQuick reference for all Supabase security audit skills with usage examples and command overview.
567 -
majiayu000 Bundle Systemd UnitsCreate and harden systemd service unit files following modern best practices. Use when writing new systemd units for web applications, background workers, or daemons, or when hardening existing services with security sandboxing and isolation features. Covers service types, dependencies, restart policies, security options, and filesystem restrictions.
567 -
majiayu000 Bundle Threat HunterActivate when the user needs help conducting proactive threat hunting, investigating suspicious activity, or building hypothesis-driven hunts in LimaCharlie.
567 -
majiayu000 Bundle Usage LoggingConsult this skill when implementing usage logging and audit trails.
567 -
majiayu000 Bundle Zz Code ReconDeep architectural context building for security audits. Use when conducting security reviews, building codebase understanding, mapping trust boundaries, or preparing for vulnerability analysis. Inspired by Trail of Bits methodology.
567 -
majiayu000 Bundle App PlannerGuides you through comprehensive iOS/Swift app planning and analysis. Use for new apps (concept to architecture) or existing apps (audit current state, plan improvements, evaluate tech stack). Covers product planning, technical decisions, UI/UX design, and distribution strategy.
567 -
majiayu000 Bundle Dev RcRelease candidate preparation. Final checks before merge - QA, security, review, changelog. The last gate before shipping.
567 -
majiayu000 Bundle FunurlParse, modify, encode, decode, and deduplicate URLs from the command line. Use when the user needs to extract URL components, manipulate URLs, encode/decode URL strings, or deduplicate URL lists for security testing or web automation.
567 -
majiayu000 Bundle AI Roi AuditAudit whether the organisation's AI spend actually paid — measured against baselines, not vendor math or vibes. Use when a CFO asks what the AI tools returned, when renewing AI contracts, when consolidating overlapping AI subscriptions, or to build the measurement plan before the next spend. Produces an ROI audit with per-tool verdicts (keep/consolidate/cut), the honest-measurement method behind each number, and a baseline plan for whatever can't be scored yet. To forecast ROI before an investment use roi-estimator; this skill measures what already happened.
567 -
majiayu000 Bundle DOCX ToolkitAudit Microsoft Word (.docx) documents for heading hierarchy, comments, tracked changes, broken cross-references, and style consistency. Use when reviewing a contract draft, preparing a document for handoff, or enforcing a style guide.
567 -
majiayu000 Bundle PPTX ToolkitAudit PowerPoint (.pptx) decks for slide count, text density, embedded images and fonts, hidden slides, speaker notes, and animation density. Use when reviewing a board deck, sales deck, or conference talk before sending.
567 -
majiayu000 Bundle Visual AuditAdversarial visual-layout audit of a Quarto `.qmd` or Beamer `.tex` deck. Flags overflow, font inconsistency, box fatigue, spacing, and alignment issues. Use when user says "visual audit", "check the layout", "does this overflow?", "look for visual issues", "audit the slides", or after reworking a deck's appearance. Does NOT check writing or pedagogy — pair with `/proofread` or `/pedagogy-review`.
567 -
majiayu000 Bundle EstimatorConducting project scoping and estimation using logical chunking and metric analysis. Use when the user wants to estimate audit effort, scope a codebase for review, calculate hours for a security engagement, or assess the size of a diff or full repository.
567 -
majiayu000 Bundle AI ReleaseUse when preparing a release: aggregated GO/NO-GO gate checking coverage, security, tests, lint, and dependency vulnerabilities against manifest thresholds.
567 -
majiayu000 Bundle Aif ReviewPerform code review on staged changes or a pull request. Checks for bugs, security issues, performance problems, and best practices. Use when user says "review code", "check my code", "review PR", or "is this code okay".
567 -
majiayu000 Bundle Audit ArchAudit codebase for adherence to architectural standards, practices, and rules. Use when user says "audit arch", "audit architecture", "check architecture", or "architectural review". Spawns parallel subagents to examine multiple architectural aspects and generates a structured report.
567 -
majiayu000 Bundle Audit DocsAudit project documentation for drift against actual code structure
567 -
majiayu000 Bundle Audit FullFull audit — launches all 6 audit skills in parallel, produces unified report
567 -
majiayu000 Bundle Improve PrComprehensive PR analysis with security review, code quality assessment, and automatic improvements. Use when reviewing PRs for security issues, performance optimizations, or best practices violations. Provides multi-dimensional analysis with safe auto-apply options.
567 -
majiayu000 Bundle Kit Verify(ePost) Use when preparing a release, running pre-init checks, auditing kit health, or when asked to "verify", "audit kit", "pre-release check"
567 -
majiayu000 Bundle Self CheckPre-commit self-validation for code quality and security
567 -
majiayu000 Bundle Audit RlsAuditer les policies RLS d'une table ou du projet. TRIGGERS : audit-rls, vérifier RLS, sécurité DB, check policies, audit sécurité
567 -
majiayu000 Bundle Awf SkillUse the AWF (Agentic Workflow Firewall) to run commands with network isolation and domain whitelisting. Provides L7 HTTP/HTTPS egress control for AI agents.
567 -
majiayu000 Bundle Ca ReviewReview a diff with the reviewer fleet, funneled to one triaged verdict. Targets the current working diff, a path, or an inbound GitHub PR.
567 -
majiayu000 Bundle Ca SprintAutonomous sprint — one interactive spec gate, then plan-to-PR execution with every auto-decision SMARTS-scored and logged. Hard gates remain true stops.
567 -
majiayu000 Bundle Dep AuditAudit project dependencies for known vulnerabilities (CVEs). Supports npm, pip, Cargo, and Go. Zero API keys required. Safe-by-default: report-only mode, fix commands require confirmation.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include rust-reviewer, secure-coding, security-gate. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.