Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Electron ScaffoldScaffold a native-looking, effective Electron app with best practices baked in. Creates a production-ready Electron application with security hardening, modern tooling, proper IPC patterns, auto-updates, native UI elements, and optimal build configuration. Use this skill when users want to start a new Electron project or modernize an existing one.
567 -
majiayu000 Bundle Energy ManagementBuild an Energy Management Operating System Pack (energy drivers/drains map, calendar energy audit, zone-of-genius expansion plan, energy-aligned weekly schedule, recovery routines, and 2-week experiments). Use for sustainable leadership performance and burnout prevention. Category: Leadership.
567 -
majiayu000 Bundle Firebase AI LogicGuide for integrating Gemini AI models with Firebase using Firebase AI Logic SDK. This skill should be used when implementing Gemini features (chat, content generation, structured JSON output), configuring security (App Check), or troubleshooting issues (rate limits, schema errors).
567 -
majiayu000 Bundle Firebase DatabaseUse when syncing real-time data, structuring JSON trees, reading/writing, creating listeners, enabling offline persistence, managing presence, sharding, or writing security rules.
567 -
majiayu000 Bundle Form Factor AuditEvaluate which product form factors will create the most leverage: mobile app, Slack app, GitHub app, or browser extension. Use when deciding how an application should surface, notify, or automate work.
567 -
majiayu000 Bundle Hydromet SysadminSystem administrator reviewer representing IT staff at hydromet services in Central Asia, Nepal, Caucasus, and Switzerland. Use when: (1) writing or updating deployment/maintenance documentation, (2) reviewing deployment procedures and scripts, (3) making changes that affect server operations, (4) documenting troubleshooting procedures. This skill provides critical review from a sysadmin perspective - read-only, no edits. Priorities: security, maintainability, clear troubleshooting docs.
567 -
majiayu000 Bundle IOS Feature AuditAudit a specific iOS feature for bugs, dead code, and improvements
567 -
majiayu000 Bundle Isms Audit ExpertSenior ISMS Audit Expert for internal and external information security management system auditing. Provides ISO 27001 audit expertise, security audit program management, security control assessment, and compliance verification. Use for ISMS internal auditing, external audit preparation, security control testing, and ISO 27001 certification support.
567 -
majiayu000 Bundle Managing Env VarsManages environment variables and security. Distinguishes between public and secret keys. Use when setting up project configuration or adding API keys.
567 -
majiayu000 Bundle Marketplace AuditDisplay plugin versions from marketplace.json. Use when user asks to "audit versions", "show plugin versions", "list marketplace versions", or wants to see the current state of plugin versioning.
567 -
majiayu000 Bundle Mtls Service MeshUse when implementing service-to-service security, mTLS, or service mesh patterns. Covers mutual TLS, Istio, Linkerd, certificate management, and service mesh security configurations.
567 -
majiayu000 Bundle NPM Update ReportCheck for outdated npm/pnpm/yarn packages, update them, and generate impact/risk assessment reports with changelog investigation and security audit. Use when asked to "check npm updates", "update dependencies", "review package updates", "update and report", or "check for breaking changes".
567 -
majiayu000 Bundle Reading Op SecretsReads secrets from 1Password using the op CLI. Use when the user needs to retrieve passwords, API keys, credentials, documents, or one-time passwords stored in 1Password. Supports reading items by name or ID, extracting specific fields, listing vault contents, and reading secret references.
567 -
majiayu000 Bundle Openspec To BeadsPROACTIVELY convert approved OpenSpec specs into Beads issues when user applies a change or explicitly approves implementation. Creates trackable work with dependencies, discovers gaps, and maintains audit trail between planning and execution.
567 -
majiayu000 Bundle Openwebf Security Remote ContentReview security risks and mitigations for remote WebF content (untrusted bundles, URL allowlists, HTTPS, trust boundaries, clickjacking). Use when the user mentions untrusted remote bundles, bundle URL validation/allowlists, or remote updates risk.
567 -
majiayu000 Bundle Paw Review ImpactAnalyzes system-wide impact of PR changes including integration effects, breaking changes, performance, and security implications.
567 -
majiayu000 Bundle Performance Audit分析后端性能问题,检测 N+1 查询、无分页查询、全表扫描、AI 服务超时等。使用此 Skill 来评估系统性能瓶颈、检测数据库查询问题、或优化 API 响应时间。
567 -
majiayu000 Bundle Postgres PatternsPostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices.
567 -
majiayu000 Bundle Pytorch To TritonTranslate PyTorch implementations to Triton GPU kernels incrementally. Use when converting PyTorch code to Triton, optimizing GPU kernels, auditing/reviewing existing Triton code, or when user says "triton", "convert to triton", "gpu kernel", "pytorch to triton", "audit triton", or "review kernel".
567 -
majiayu000 Bundle Quality ReviewingDeep code review with web research. USE WHEN user says 'double check against latest', 'verify versions', 'check security'. Complements automatic quality hook with ecosystem verification.
567 -
majiayu000 Bundle Release ChecklistRun a final release checklist before shipping. Verifies no TODOs, no debug code, docs updated, tests passing, dependencies justified, and security reviewed.
567 -
majiayu000 Bundle Sandbox ArchitectAnalyze codebases to generate optimal Claude Code Sandbox configurations. Use this skill when users need to set up sandbox security settings for their projects. This skill should be triggered when users ask about sandbox configuration, security settings, or when setting up Claude Code for a new project. It analyzes the codebase stack (Node.js, Python, Rust, Go, PHP, etc.), detects dependencies, and generates appropriate sandbox and permission settings through an interactive Q&A process.
567 -
majiayu000 Bundle Sec Context DepthComprehensive AI code security review using 27 sec-context anti-patterns. Use for code review when security vulnerabilities are suspected, especially for AI-generated code.
567 -
majiayu000 Bundle Security AnalysisPerform static security review of modified code, identifying vulnerabilities and recommending mitigations
567 -
majiayu000 Bundle Security BaselineSecurity requirements, threats, and controls that apply across this system.
567 -
majiayu000 Bundle Security GuidanceSecurity reminder hook that warns about potential security issues when editing files, including command injection, XSS, and unsafe code patterns
567 -
majiayu000 Bundle Security ReporterUse when generating comprehensive security audit reports, analyzing security scan results, calculating security posture, or creating OWASP Top 10 compliance assessments. Invoked for security reporting, vulnerability aggregation, and remediation planning.
567 -
majiayu000 Bundle Smart Doc ManagerUniversal documentation consolidation skill that verifies system reality before making ANY organizational decisions. Analyzes codebase, detects redundancies, and safely consolidates documentation with preservation of git history and rollback capabilities. Includes specialized MASTER_PLAN.md management with intelligent updates, backup, validation, task creation (/task), and idea/issue processing. Triggers on "master-plan", "plan update", "documentation", "consolidate docs", "audit docs", "add task", "new task", "process ideas", "check inbox".
567 -
majiayu000 Bundle Software SecurityA software security skill that integrates with Project CodeGuard to help AI coding agents write secure code and prevent common vulnerabilities. Use this skill when writing, reviewing, or modifying code to ensure secure-by-default practices are followed.
567 -
majiayu000 Bundle Substitute EraserThis skill should be used when the user asks to "scan for TODOs", "find placeholders", "clean up stubs", "remove temporary code", "audit for incomplete code", or "erase substitutions from codebase". Scans existing files for placeholder tokens and generates remediation plan.
567 -
majiayu000 Bundle Supabase EvidenceInitialize and manage the evidence collection directory for professional security audits with documented proof of findings.
567 -
majiayu000 Bundle Tasks Code ReviewAutonomous subagent variant of code-review. Use when reviewing code changes, pull requests, or performing refactoring analysis with focus on patterns, security, and performance.
567 -
majiayu000 Bundle Tca Removal AuditYou are a migration expert tracking The Composable Architecture removal from Leavn.
567 -
majiayu000 Bundle Test Design AuditELD統合版テスト設計監査スキル。Law/Term駆動でテスト設計の抜け漏れを防止する。 モデル化とEvidence Ladderを組み合わせ、法則の接地を体系的に検証する。 Use when: - テスト設計、テスト計画作成、QA開始前 - ELDのGroundフェーズでのテスト設計 - Law/Termの接地検証 - 「テスト漏れがないか不安」と感じた時
567 -
majiayu000 Bundle Tizen Cve ScannerScans for known Tizen CVEs in app dependencies and kernel. Checks OpenCVE database and Samsung security updates.
567 -
majiayu000 Bundle Type Safety AuditAudits TypeScript code for type safety best practices - no any usage, branded types for IDs, runtime validation, proper type narrowing. Use before committing TypeScript code or during type system reviews.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include electron-scaffold, energy-management, firebase-ai-logic. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.