Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Vulnerable SecretThis skill provides guidance for extracting secrets from vulnerable executables. It should be used when tasks involve binary analysis, reverse engineering executables to find hidden flags/secrets, or exploiting buffer overflows and other vulnerabilities to extract protected data. Applicable to CTF challenges, security research, and authorized penetration testing scenarios.
567 -
majiayu000 Bundle Wheels DeploymentConfigure Wheels applications for production deployment with security hardening, performance optimization, and environment-specific settings. Use when preparing for production, configuring servers, or hardening security.
567 -
majiayu000 Bundle Writing ProposalsUse when creating or pricing energy consulting proposals including ASHRAE Level 1/2/3 audits, benchmarking services, commissioning, compliance pathway consulting, and performance target analysis. Provides pricing models, cost estimation, scope templates, service definitions, labor hour estimates, and proposal generation. Use when the user mentions proposal writing, pricing services, scoping work, energy audit costs, consulting rates, or needs to generate professional proposals for energy projects.
567 -
majiayu000 Bundle Edictum EeImplement features in the Edictum Enterprise layer (ee/). Use when the task touches PII detection backends, enterprise audit sinks, server, auth, sequences, or NL authoring. ee/ imports from core freely.
567 -
majiayu000 Bundle ExhaustiveProve a decision space, state space, requirement set, or behavior surface is fully covered by enumerating every cell and classifying each as covered, gap, or deferred with an executed check. Use when the user says "exhaustive", "prove coverage", "did I miss any case", "enumerate the state space", or when a refactor or feature needs a completeness audit before it is called done.
567 -
majiayu000 Bundle QA AuditorYou are an expert QA auditor specializing in comprehensive Flutter application audits for production readiness, compliance certification, and enterprise deployment. This skill performs deep audits covering architecture, security, compliance, testing, performance, and code quality.
567 -
majiayu000 Bundle Cron AutomationAudit and create cron jobs with reliability and safety.
567 -
majiayu000 Bundle Ase Code AnalyzeAnalyze the source code for problems in either the logic and semantics and its related control flow, performance and efficiency, or security.
567 -
majiayu000 Bundle Ca Context CheckOptional manual drift audit — report stale provenance-tracked docs, then per stale doc offer re-scout, re-baseline, or defer. Not the daily loop; commit-gate auto-heal owns routine maintenance.
567 -
majiayu000 Bundle Decision RecordsCreates, supersedes and validates decision records (ADRs) against the convention a collection already follows, instead of imposing a published one. Use when the user wants to record a decision, write an ADR, supersede an existing decision, audit or lint a decisions folder, check that an ADR index is in sync, or asks "why did we decide X". Deduces the filename scheme, section set and status vocabulary from the records already there; ships a validator with an exit code, so the audit is a check and not an opinion.
567 -
majiayu000 Bundle Firebase StorageUse when setting up Storage, uploading/downloading files, managing metadata, handling errors, or applying security rules.
567 -
majiayu000 Bundle Safety And AuditSets up safe working habits and a change log so you always know what Cowork has done to your files — and can undo anything. Use when setting up file protection guardrails, for establishing safe automation habits, during initial access configuration, when granting file permissions for the first time, or when the user says "is cowork safe", "file safety", "what if it deletes my files", "audit trail", "safety setup", "I'm nervous about file access", "how do I trust cowork with my files", "can cowork mess up my computer", "I heard someone lost files", or "how do I stay in control".
567 -
majiayu000 Bundle Perf CheckUse when the user wants to check performance, find slow code, identify bottlenecks, or audit efficiency.
567 -
majiayu000 Bundle Review D3dAudit the D3D11 interop layer for per-frame waste — buffer allocations, redundant state calls, GPU readback efficiency
567 -
majiayu000 Bundle Scope ProjectAdversarial project planning workflow. Explores the problem space, drafts tickets in batches, then runs sequential adversarial loops — a mandatory UX loop ("should we build this?"), zero or more discretionary specialist loops (security, performance) for projects with architectural implications in those domains, and a mandatory implementer loop ("could we build this?") — to find gaps before implementation. Creates well-specified, batch-tagged tickets upstream only after every applicable loop signs off.
567 -
majiayu000 Bundle Red Team Tools And MethodologyThis skill should be used when the user asks to "follow red team methodology", "perform bug bounty hunting", "automate reconnaissance", "hunt for XSS vulnerabilities", "enumerate subdomains", or needs security researcher techniques and tool configurations from top bug bounty hunters.
567 -
majiayu000 Bundle Audit CohesionAudit codebase for internal cohesion - how well components fit together and maintain consistent patterns. Distinct from audit-arch (which checks rule violations); this checks integration fitness and convergence. Use when user says "audit cohesion", "check cohesion", "cohesion audit", or "alignment check".
567 -
majiayu000 Bundle Audit Fix LoopThis skill should be used when the user asks to 'iteratively improve', 'audit and fix', 'hill-climb quality', 'grade and improve', 'score and fix', 'audit loop', 'quality loop', or needs structured iterative improvement of an artifact using scored independent audits. Also use when the user invokes a ralph loop for quality improvement rather than task completion.
567 -
majiayu000 Bundle Ce Skill AuditAudit the skills catalog for frontmatter quality, trigger precision, structural hygiene, and registry synchronization.
567 -
majiayu000 Bundle Claudemd AuditUse when the user wants to audit CLAUDE.md files for bloat, staleness, misplacement, or information architecture issues. Invoked with /claudemd-audit. Supports --project, --global, --all scopes and --fix for auto-remediation. Use periodically or before shipping to ensure CLAUDE.md stays lean.
567 -
majiayu000 Bundle Code ReviewingPerforms systematic code review with universal best practices and repo-specific standards. Auto-activates after significant code changes. Use when reviewing code, auditing files, checking PRs, examining staged changes, or when asked to "review", "check", "audit", or "examine" code. Enforces design principles (SOLID, DRY, KISS), security (OWASP), performance, concurrency safety, cross-platform compatibility, and codebase patterns.
567 -
majiayu000 Bundle Codebase AuditPerforms comprehensive codebase audit checking architecture, tech debt, security vulnerabilities, test coverage, documentation, dependencies, and maintainability. Use when auditing a project, assessing codebase health, running security scans, checking for vulnerabilities, reviewing code quality, analyzing tech debt, or asked to audit/analyze the entire codebase.
567 -
majiayu000 Bundle Criteria AuditValidate EXECUTION_PLAN.md for verification metadata, manual reasons, and testability. Use when preparing Phase 1 or after editing EXECUTION_PLAN.md.
567 -
majiayu000 Bundle Meta User TestRun a structured, repeatable audit for a live website and produce actionable artifacts.
567 -
majiayu000 Bundle Review ProcessAudit a Zeebe BPMN process and its glue-code (workers, process adapter, tests) for consistency and coverage, producing a structured report written to `.claude/temp/`. Use when the user asks to "review the newsletter process", "audit a BPMN process", "check process consistency", or "use the review-process subagent". Checks task-type coverage, message coverage, ProcessApi consistency, variable coverage, test coverage, and BPMN styleguide compliance.
567 -
majiayu000 Bundle Review ReviewsMeta-audit all review skills for stale references, drifted architecture claims, and cross-skill inconsistencies
567 -
majiayu000 Bundle System CleanerPAL system housekeeping audits. USE WHEN audit system, check references, validate naming, find orphans, health report, system health, clean system. AgentSearch('system-cleaner') for docs.
567 -
majiayu000 Bundle Ato ChainsHunt full Account Takeover (ATO) by chaining lower-severity findings — IDOR-to-email-disclosure, password-reset-token-theft, OAuth-redirect-uri abuse, response-manipulation, cookie scope, CRLF in Set-Cookie, race-condition on signup. Use when the user wants to escalate small findings to ATO or thinks an ATO path exists.
567 -
majiayu000 Bundle OAUTH OidcHunt OAuth 2.0 and OIDC flaws — redirect_uri abuse, state CSRF, PKCE bypass, scope manipulation, implicit-flow token theft, postMessage origin tricks, ID token sub claim swap, JWKS confusion, response_type confusion, and OAuth-CSRF. Use when an app has Google/GitHub/Facebook/Apple/custom OAuth or OpenID Connect.
567 -
majiayu000 Bundle Access ReviewConduct periodic access reviews and certifications. Implement access governance and recertification workflows. Use when managing access compliance.
567 -
majiayu000 Bundle AnnualreportsAnnual security report aggregation and analysis. USE WHEN annual reports, security reports, threat reports, industry reports, update reports, analyze reports, vendor reports, threat landscape.
567 -
majiayu000 Bundle Auth Scaffold> Generate Complete Auth System: Login, register, forgot password, and session management.
567 -
majiayu000 Bundle C2 Frameworks<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Ca CheckpointPeriodic multi-reviewer sweep of the whole codebase — surfaces a triaged checkpoint report.
567 -
majiayu000 Bundle Cmmc AssessorAssess CMMC Level 2/3 compliance by mapping NIST SP 800-171 controls to Embry OS features and detected configurations. Generates gap analysis reports.
567 -
majiayu000 Bundle Command GuardClaude Code runs shell commands, edits files, and manages infrastructure with real consequences. Without guardrails, a misunderstood instruction or a hallucinated flag can delete data, corrupt history, or expose credentials. This skill installs a PreToolUse hook that blocks the most dangerous operations before they run.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include vulnerable-secret, Wheels Deployment, edictum-ee. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.