Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Radflow ComplianceAudit and fix AI-generated or existing code for RadOS design compliance. Use after generating UI code or when reviewing PRs. Catches common mistakes like wrong shadows, hardcoded colors, missing components, and incorrect radius hierarchy.
567 -
majiayu000 Bundle Red Blue ValidatorIterative adversarial stress-testing through Red/Blue team dynamics. Red Team generates substantive, steel-manned attacks against propositions; Blue Team responds with defenses, mitigations, and hardening. Cycles continue until convergence criteria are met, producing a battle-tested proposition. PROACTIVELY activate for: (1) High-stakes decisions requiring stress-testing, (2) Strategy validation before major commitment, (3) Architecture decision hardening, (4) Proposal defense preparation, (5) Security posture review, (6) Investment due diligence with adversarial lens. Triggers: "red team this", "blue team", "stress test", "attack this plan", "find weaknesses", "adversarial review", "devil's advocate", "what could go wrong", "poke holes in this", "challenge this decision", "war game this"
567 -
majiayu000 Bundle Red Team ReportingProfessional security report generation, executive summaries, finding documentation, and remediation tracking
567 -
majiayu000 Bundle Remediation ConfigSecurity fix patterns for configuration and deployment vulnerabilities (path traversal, debug mode, security headers). Provides language-specific secure implementations.
567 -
majiayu000 Bundle Remediation CryptoSecurity fix patterns for cryptographic vulnerabilities (weak algorithms, insecure randomness, TLS issues). Provides language-specific secure implementations.
567 -
majiayu000 Bundle Repository AuditorComprehensive codebase analysis system that evaluates security vulnerabilities, code quality, architecture patterns, and operational readiness across any technology stack.
567 -
majiayu000 Bundle Review And QualityEvaluates code changes and documents against product, architecture, security and coding standards.
567 -
majiayu000 Bundle Row Level SecurityImplement PostgreSQL Row Level Security (RLS) for multi-tenant SaaS applications. Use when building apps where users should only see their own data, or when implementing organization-based data isolation.
567 -
majiayu000 Bundle Security AnticheatImplements security and anti-exploit systems including sanity checks, exploit prevention, secure networking, and data protection. Use when you need to protect a game from exploiters and ensure fair gameplay.
567 -
majiayu000 Bundle Security ArchitectSecurity architecture and threat modeling. OWASP Top 10 analysis, security pattern implementation, vulnerability assessment, and security review for code and infrastructure.
567 -
majiayu000 Bundle Security Protocols🛡️ Comprehensive security management for festivals including crowd control, threat assessment, emergency response, and staff coordination.
567 -
majiayu000 Bundle Security Rbac AuthImplement authentication, authorization, and security controls. Use for JWT handling, API key management, RBAC, OAuth integration, and security policies. Triggers on "authentication", "authorization", "JWT", "API key", "RBAC", "OAuth", "security", "permissions", or when implementing spec/006-security-governance.md.
567 -
majiayu000 Bundle Security StandardsSecurity standards for credential handling and authentication
567 -
majiayu000 Bundle Skill ArchitectureComprehensive guide for creating effective Claude Code skills with security best practices, CLI-specific features, and structural patterns. Use when creating skills, needing security guidance, understanding skill architecture, or learning best practices.
567 -
majiayu000 Bundle Spring Boot VerifyVerify Spring Boot 4.x projects for correct dependencies, configuration, and migration readiness. Use when analyzing pom.xml, build.gradle, application.yml, discussing Spring Boot project setup, dependency versions, configuration validation, version compatibility, migration to Spring Boot 4, deprecated dependencies, or when user mentions "verify project", "check dependencies", "upgrade Spring Boot", "migration readiness", "Jackson 3", "@MockBean deprecated", or "Spring Security 7".
567 -
majiayu000 Bundle Supabase Audit RlsTest Row Level Security (RLS) policies for common bypass vulnerabilities and misconfigurations.
567 -
majiayu000 Bundle Supabase Audit RpcList and test exposed PostgreSQL RPC functions for security issues and potential RLS bypass.
567 -
majiayu000 Bundle Test Quality AuditScan test files for anti-patterns including mesa-optimization, disabled tests, trivial assertions, and error swallowing
567 -
majiayu000 Bundle Testing ValidationComprehensive testing and validation tools for Clerk authentication integrations. Includes E2E auth flow testing, security audits, configuration validation, unit testing patterns for sign-in/sign-up flows. Use when implementing Clerk tests, validating authentication setup, testing auth flows, running security audits, creating E2E tests for Clerk, or when user mentions Clerk testing, auth validation, E2E authentication tests, security audit, or test coverage.
567 -
majiayu000 Bundle Wheels RefactoringRefactor Wheels code for better performance, security, and maintainability. Use when optimizing code, fixing anti-patterns, improving performance, or enhancing security. Provides refactoring patterns and best practices.
567 -
majiayu000 Bundle UX Audit RethinkComprehensive UX audit using IxDF's 7 factors, 5 usability characteristics, and 5 interaction dimensions. Holistic evaluation with redesign proposals based on user-centered design principles.
567 -
majiayu000 Bundle Website UX AuditThis skill should be used when the user asks to "audit this website", "UX review", "analyze user experience", "website modernization report", "evaluate website design", "improve website UX", or provides a URL for comprehensive UX/UI analysis. Produces actionable modernization reports structured for design and implementation handoff.
567 -
majiayu000 Bundle BuildmoduleDesign, build, and validate forge modules. USE WHEN create module, new module, scaffold module, validate module, check module, audit module, module structure, module conventions, module architecture.
567 -
majiayu000 Bundle Get HistoryAccess raw conversation history from Claude Code session storage for audit and analysis
567 -
majiayu000 Bundle Harms CheckUse when building anything USER-FACING (or with persuasion/retention/cancellation/consent/pricing flows, or that touches vulnerable people) to surface design-level harm the security/privacy/compliance gates miss: dark/deceptive patterns and foreseeable misuse. Assumes the product works as designed and asks who it could harm and whether it is Happier-negative. NUDGE, not a block.
567 -
majiayu000 Bundle Rust SafetyRust safety patterns and secure coding. Use when writing code that handles untrusted input, uses unsafe blocks, deals with memory safety, or requires security review.
567 -
majiayu000 Bundle Audit ResolutionUse when presenting audit discrepancies to user for decision (HITL). For each discrepancy show file path, diff (template vs actual), and ask user what to do - [1] apply template, [2] update template (PR), [3] ignore, or [4] custom instruction. Records decisions for remediation phase.
567 -
majiayu000 Bundle Cron Job AuditorAudit cron scripts for reliability and safety.
567 -
majiayu000 Bundle Audit ExtractPhase 1: Extract footnotes from DOCX with formatting annotations
567 -
majiayu000 Bundle Deed Of TrustDrafts combined Deed of Trust and Security Agreement instruments creating real property and UCC Article 9 personal property security interests for commercial financing. Use when drafting trust deeds, security agreements, commercial real estate financing documents, or combined real/personal property security instruments.
567 -
majiayu000 Bundle Improve GuideMain entry point for guide improvement - interactive workflow selection for audit, translation, or both
567 -
majiayu000 Bundle Shipflow HelpCheatsheet for the full task tracking and audit system — skills, modes, prompts, workflows
567 -
majiayu000 Bundle Unity Perf AuditAudit statique de performance pour projets Unity. Triggers: /perf, /perf-audit, 'audit performance', 'optimiser performance', 'anti-pattern performance', 'frame rate', 'profiler', 'budget fps'. Analyse le code C# du projet pour detecter les anti-patterns de performance (CPU, GPU, memoire). Produit un rapport avec severite, localisation fichier:ligne, et correctifs concrets avant/apres.
567 -
majiayu000 Bundle Git PushingStage, commit, and push git changes with conventional commit messages with intelligent security checks. Use when user wants to commit and push changes, mentions pushing to remote, or asks to save and push their work. Also activates when user says "push changes", "commit and push", "push this", "push to github", or similar git workflow requests.
567 -
majiayu000 Bundle Client ReportGenerate client-facing reports. Use when: white-labeled performance report with KPIs, trends, strategic recommendations.
567 -
majiayu000 Bundle Lp WeeklyS10 weekly orchestration wrapper. Coordinates the full weekly decision, audit/CI, measurement compilation, and experiment lane flows into one deterministic sequence. Additive-first; never replaces canonical S10 authorities. No new hard stage blocks in first iteration.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include row-level-security, radflow-compliance, red-blue-validator. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.