Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Validate SecretsValidate SOPS encryption on secret files before committing. Use when staging secrets, committing encrypted files, or checking if secrets are properly encrypted. Prevents committing unencrypted secrets.
567 -
majiayu000 Bundle Webhook SecurityImplement secure webhook handling with signature verification, replay protection, and idempotency. Use when receiving webhooks from third-party services like Stripe, GitHub, Twilio, or building your own webhook system.
567 -
majiayu000 Bundle Wordpress RouterUse at the start of WordPress tasks to classify the repo type (plugin, theme, block theme, WP core, full site) and route to the correct workflow/skill (blocks, theme.json, REST API, WP-CLI, performance, security, testing).
567 -
majiayu000 Bundle Wordpress ThemesWordPress custom theme development specialist focused on clean, maintainable code following VIP standards. Includes modular theme structure, dart-sass via Homebrew, proper script/style enqueueing, template parts organization, text domain management, and comprehensive security practices (escaping, sanitization, file paths).
567 -
majiayu000 Bundle Approval Gates承認ゲートの設計・評価・運用を体系化し、変更管理とリリース判断を安全に進めるスキル。 リスク評価に基づくゲート条件、手動承認と自動検証の分離、監査可能な記録設計を支援します。 Anchors: • The Pragmatic Programmer / 適用: 品質ゲートの段階化 / 目的: 変更の安全性を段階的に高める • リスク評価フレームワーク / 適用: 影響度と発生確率の分類 / 目的: ゲート条件の科学的根拠を整える • ITIL Change Enablement / 適用: 変更承認フロー / 目的: 監査可能な意思決定を実現する Trigger: Use when designing approval gates, change control checkpoints, release readiness criteria, or governance workflows that require risk-based approvals and audit trails.
567 -
majiayu000 Bundle Gold StandardsMandatory best practices and gold standards for Kailash SDK development including absolute imports, parameter passing, error handling, testing policies (NO MOCKING in Tiers 2-3), workflow design, custom node development, security, documentation, and test creation. Use when asking about 'best practices', 'standards', 'gold standards', 'mandatory rules', 'required patterns', 'absolute imports', 'NO MOCKING', 'testing policy', 'error handling standards', 'security best practices', 'documentation standards', or 'workflow design standards'.
567 -
majiayu000 Bundle Bun AuditShared Bun audit/remediation router. Use when auditing a repo for Bun-first correctness, explaining Bun audit findings, listing Bun audit rules, planning safe Bun fixes, applying low-risk remediations, or validating Bun-related changes. This skill delegates to the shared engine in bun-dev/scripts.
567 -
majiayu000 Bundle Mern DepsCheck and update dependencies safely with security audits and test verification.
567 -
majiayu000 Bundle Nean DepsCheck and update dependencies safely with security audits and test verification.
567 -
majiayu000 Bundle AI Code ReviewReview AI-authored code for its characteristic failure modes — plausible-but-wrong logic, hallucinated APIs, over-engineering, dead scaffolding, and silent security shortcuts. Use when reviewing an AI-generated or heavily AI-assisted PR, when AI-written code keeps shipping subtle bugs, or when setting review standards for a team using coding agents. Produces a focused review with AI-specific findings, verification steps per risk class, and a team checklist for AI-authored changes. For general PR review use code-review-checklist — this skill covers what that one assumes a human wouldn't do.
567 -
majiayu000 Bundle Monitor SystemMonitor system health, detect errors, implement recovery procedures, restart failed processes, maintain audit logs. Use for system health checks, error recovery, process monitoring, or when user mentions "system status", "errors", "logs".
567 -
majiayu000 Bundle FactcheckerSystematically verify claims in code comments, documentation, commit messages, and naming conventions. Extracts assertions, validates with evidence (code analysis, web search, documentation, execution), generates report with bibliography. Use when: reviewing code changes, auditing documentation accuracy, validating technical claims before merge, or user says "verify claims", "factcheck", "audit documentation", "validate comments", "are these claims accurate".
567 -
majiayu000 Bundle Feature DocGeneration et maintenance de documentation technique a partir du code, avec modes full, update et audit
567 -
majiayu000 Bundle Rustie DocsDocumentation management skill for audit, creation, and maintenance. Enforces documentation standards, checks for staleness and broken references, auto-fixes issues, and ensures docs are created in correct locations. Use when user says "check docs", "audit docs", "fix docs", "create doc", "archive docs", or when scattered .md files are detected.
567 -
majiayu000 Bundle Sector CreatorCreate Sectors (Digital Web locations) for Mage: The Ascension 20th Anniversary Edition. Designs virtual locations with appropriate class, access levels, security, IC hazards, and Digital Web-specific features. Uses mage-rules-reference for Reality Zone/Practice lookups. Triggers: create a sector, design a digital web location, M20 sector, virtual adept base, digital realm.
567 -
majiayu000 Bundle Enterprise RiskIdentifies, assesses, and tracks organizational risk — building and maintaining a risk register, scoring exposure, assigning owners and treatments, and preparing for audit. Use this to stand up a risk program, assess the risk in a decision or initiative, prepare for a certification or audit, decide whether a risk should be accepted, mitigated, transferred, or avoided, or report risk posture to leadership.
567 -
majiayu000 Bundle Hunt JWT CryptoHunt JWT cryptographic failures — alg:none signature-stripping and RS256→HS256 key-confusion that let an attacker forge a token for any identity (e.g. an admin) without knowing a secret. Use when the app authenticates with a JSON Web Token (an `eyJ...` Bearer token in the Authorization header, a cookie, or a login response). This skill OWNS JWT signature/crypto forgery (alg:none, key confusion, kid/jku header injection); hunt-ato covers JWT as one ATO path, hunt-auth-bypass covers SSO/SAML token trust, hunt-api-misconfig covers non-crypto JWT handling. Critical when a forged token grants access to another user's data or an admin-only endpoint.
567 -
majiayu000 Bundle Phx PermissionsRecommend safe Bash permissions for Elixir mix commands in settings.json. Use when permission prompts slow workflow, "fix permissions", "reduce prompts", "auto-allow mix".
567 -
majiayu000 Bundle Skill LifeguardUse when a skill is brittle, drifting, repeatedly failing, or needs a Reliable Skill Contract. Trigger for phrases like skill lifeguard, reliable skill, self-maintaining skill, negative examples, verification checkpoints, drift signals, replay hooks, or failure log to skill patch. Audits or patches skills so high-value workflows include explicit forbidden behaviors, checkpoints, machine-checkable done conditions, replay or smoke hooks, and drift detection.
567 -
majiayu000 Bundle Theory FidelityAudit whether the theories/methodologies a project claims to implement are faithfully operationalized — or name-dropped, partially built, distorted, or over-claimed. Source-grounds the load-bearing theories; tags the rest provisional. Run periodically alongside /framework-health.
567 -
majiayu000 Bundle Elnora AdminUse this skill when the user asks about "Elnora account", "API keys", "audit log", "feature flags", "health check", "terms of service", "platform status", "feedback", "invitation", or any Elnora platform administration task.
567 -
majiayu000 Bundle Mira Tan PerspectiveThe design-judgment lens of Mira Tan (a FICTIONAL product-design mentor), distilled from an invented corpus into 4 mental models, 5 decision heuristics, and a full expression DNA. Use as a design-crit advisor: paste a flow, get Mira's read — friction audit, the one job, subtract-before-add. Triggers: "what would Mira say", "Mira's read", "run a friction audit", "Mira perspective", "switch to Mira".
567 -
majiayu000 Bundle Audit ContentComprehensive content quality and maintenance assessment. Evaluates documentation quality, relevance, maintenance needs, and provides actionable recommendations.
567 -
majiayu000 Bundle Audit ContextEvaluates ambient context artifacts (CLAUDE.md, memory, local skills, settings hooks) for compatibility with swarm governance. Returns a classified report so users can address interference before launching a team.
567 -
majiayu000 Bundle Audit ProjectAudits the Claude Code configuration of a project against the dotforge template. Generates a report with score and gaps.
567 -
majiayu000 Bundle Design GuardsInvestigate a bug pattern audit report and design architectural guards (tests, contracts, structural changes) that provide immunity to each identified pattern. Use when user says "design guards", "design defenses", or wants architectural solutions for bug patterns.
567 -
majiayu000 Bundle Dk Slop AuditRun a codebase hygiene audit. Scans for misplaced files, dead code, temp files, security issues, structural problems, dependency slop, and git slop. Outputs a prioritized report with P0-P4 findings. Use periodically or before releases. Triggers on: 'audit the codebase', 'find slop', 'hygiene check', 'clean up', or /dk-slop-audit.
567 -
majiayu000 Bundle Doc FreshnessDetect documentation drift, stale references, and cross-document inconsistencies in any project. Scans for code-doc drift (API/function changes not reflected in docs), cross-doc drift (conflicting information across documents), and stale references (broken links, deleted files, outdated versions). Use when checking "doc freshness", "stale docs", "documentation drift", "broken links", "outdated documentation", "doc accuracy", "docs out of date", "doc audit", "doc health", or "verify documentation".
567 -
majiayu000 Bundle Expense AuditAudit spending to find leaks — recurring subscriptions, creep, and cuttable costs — ranked by impact. Use when asked to cut expenses, review subscriptions, find where money is going, or free up cash. Produces a categorized spend breakdown, a ranked list of cuts with dollar amounts, and the annualized savings. Educational, not regulated financial advice.
567 -
majiayu000 Bundle Qc SpecialistAssist QC Specialists with quality gates, compliance verification, audit trail generation, and quality metrics tracking. Use when running quality gates, verifying compliance standards, creating review checklists, or auditing artifacts. Triggers on keywords like "quality gate", "compliance", "audit", "quality metrics", "QC review", "checklist", "standards verification".
567 -
majiayu000 Bundle Reactor AuditUse when proposing or implementing any UI, rendering, shader, UX, motion, or DSP change in TRENCH — forces doctrine audit before code, kills generic output, requires structured review with dominant-read analysis and acceptance test
567 -
majiayu000 Bundle Review MemoryAudit CLAUDE.md and .claude/rules/ for stale references, outdated architecture claims, and rules now redundant with static analysis checks
567 -
majiayu000 Bundle Skill AuditorAudit SKILL.md files against the AgentOps template and readiness checks. Use for quality reviews or template compliance.
567 -
majiayu000 Bundle Audit SourceWhite-box security audit. Blue-teamer evaluates defensive posture, then red-teamers attack informed by defensive gaps. Iterates when exploit chains are discovered. Heavy and thorough by design.
567 -
majiayu000 Bundle Auth BuilderBuild and maintain Stripe → Clerk authentication flows for pricing CTA buttons. Use when implementing new subscription tiers, fixing auto-enrollment issues, or adding payment-to-access flows.
567 -
majiayu000 Bundle Auth Manager网页登录态管理。定期检查各平台 Playwright 登录状态,过期自动告警。支持动态添加/删除平台。
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include webhook-security, wordpress-router, wordpress-themes. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.