Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Sf PermissionsManage and audit Salesforce permissions: Permission Sets, Profiles, Permission Set Groups, object/field-level security (CRUD/FLS), custom permissions, and access troubleshooting. Use when asked about "who has access", permission set creation, FLS auditing, access errors, permission comparison, or muting permission sets. Activate on mentions of "permission set", "profile permissions", "field-level security", "FLS", "CRUD access", "permission set group", "INSUFFICIENT_ACCESS", or "custom permission".
567 -
majiayu000 Bundle Triage MalwareTriage a suspected malicious file hash. Use when investigating malware alerts or suspicious files. Analyzes GTI file report, behavioral indicators, identifies affected hosts, enriches network IOCs, and recommends containment actions.
567 -
majiayu000 Bundle Unsafe CheckerUse when reviewing unsafe code or writing FFI. Keywords: unsafe, raw pointer, FFI, extern, transmute, *mut, *const, union, #[repr(C)], libc, std::ffi, MaybeUninit, NonNull, PhantomData, Send, Sync, SAFETY comment, soundness, undefined behavior, UB, how to call C functions, safe wrapper for unsafe code, when is unsafe necessary, memory layout, bindgen, cbindgen, CString, CStr, invariant, 安全抽象, 裸指针, 外部函数接口, 内存布局, 不安全代码, FFI 绑定, 未定义行为
567 -
majiayu000 Bundle Midnight Core Concepts Zero KnowledgeUse when asking about zero-knowledge proofs, ZK SNARKs, circuit compilation, witness data, prover/verifier roles, constraints, or how Midnight uses ZK for privacy.
567 -
majiayu000 Bundle Claude Md DoctorAudit and improve CLAUDE.md files. Use when rules aren't working, context is bloated, or after learning a lesson that should become a rule.
567 -
majiayu000 Bundle Acp ConformanceValidate an ACP implementation against the protocol specification — schema validation, flow testing, error handling, idempotency, security checks, and production readiness. Use when preparing for launch or certifying compliance.
567 -
majiayu000 Bundle Ucp ConformanceRun and write UCP conformance tests — validate a UCP implementation against the official test suite covering checkout lifecycle, orders, fulfillment, payments, idempotency, webhooks, and security. Use when testing or validating a UCP implementation.
567 -
majiayu000 Bundle Audit WorkflowBi-directional comparison workflow for config auditing. Compares what agents expect (from templates/standards) against what repositories actually have, presenting differences with remediation options. Use when agents need to audit configs, validate standards compliance, or identify mismatches between expected and actual configurations.
567 -
majiayu000 Bundle Benchmark DatasetsStandard datasets and benchmarks for evaluating AI security, robustness, and safety
567 -
majiayu000 Bundle Data Flow AuditDetect split data source anti-patterns and scattered business rule duplication where the same logic is reimplemented across multiple files and languages. Catches semantic duplication that syntactic tools like jscpd miss. Use at phase checkpoints or when investigating data consistency issues.
567 -
majiayu000 Bundle Swiftui API GapGenerate and maintain deterministic SwiftUI-vs-Raven API parity reports and automation. Use when users ask to audit missing SwiftUI components/APIs, refresh coverage reports, reduce report noise, tune matching logic (owner-qualified names, constructors, operators), or update the weekly GitHub Actions PR workflow that publishes Reports/swiftui-api-gap/gap_report.md.
567 -
majiayu000 Bundle Backend API PatternsBackend API implementation patterns for scalability, security, and maintainability. Use when building APIs, services, and backend systems.
567 -
majiayu000 Bundle Broken Link CheckerScans a website to find broken links (404s, 500s). Crawls internal pages, identifies broken outbound links, and reports source pages for easy fixing. Use this when the user asks to "check for broken links", "find 404s", "audit my links", or "is my site healthy".
567 -
majiayu000 Bundle Exploit DevelopmentUse when turning a memory-corruption bug into a working PoC — stack/ROP, glibc heap & FSOP, format strings, browser/JIT type confusion & UAF, Linux/Windows kernel LPE against ASLR/DEP/CFG/CET/V8-Sandbox
567 -
majiayu000 Bundle Osprey AppraisePrecision project estimator that turns security audits and code assessments into professional proposals with scope, timeline, pricing, and deliverables. The Osprey accounts for what others overlook. Use when quoting remediation work, estimating project scope, or producing client-ready proposals.
567 -
majiayu000 Bundle Automating API TestingThis skill automates API endpoint testing, including request generation, validation, and comprehensive test coverage for REST and GraphQL APIs. It is used when the user requests API testing, contract testing, or validation against OpenAPI specifications. The skill analyzes API endpoints and generates test suites covering CRUD operations, authentication flows, and security aspects. It also validates response status codes, headers, and body structure. Use this skill when the user mentions "API testing", "REST API tests", "GraphQL API tests", "contract tests", or "OpenAPI validation".
567 -
majiayu000 Bundle Audit ComprehensiveRun all 7 domain audits in staged waves and aggregate results
567 -
majiayu000 Bundle Audit DocumentationRun a multi-stage parallel documentation audit with 18 specialized agents
567 -
majiayu000 Bundle Clarification PhaseExecutes the /clarify phase using AskUserQuestion tool to resolve ambiguities through structured questions (≤3), prioritization, and answer integration. Use when spec.md contains [NEEDS CLARIFICATION] markers, when requirements need disambiguation, or when running /clarify command to resolve critical scope/security/UX ambiguities before planning. (project)
567 -
majiayu000 Bundle Cqrs Event SourcingCQRS and Event Sourcing patterns for scalable, auditable systems with separated read/write models. Use when building audit-required systems, implementing temporal queries, or designing high-scale applications with complex domain logic.
567 -
majiayu000 Bundle Curriculum ReviewerComprehensively reviews curriculum materials for quality, consistency, and effectiveness. Use when the user asks to review content, check quality, audit materials, or ensure curriculum meets standards. Provides detailed feedback and improvement recommendations.
567 -
majiayu000 Bundle Database VersioningDatabase version control and change management patterns. Use when managing schema history, coordinating database changes across environments, implementing audit trails, or versioning database objects.
567 -
majiayu000 Bundle Dependency AnalysisAnalyze project dependencies for security vulnerabilities, outdated packages, and upgrade paths. Use when auditing dependencies or planning upgrades.
567 -
majiayu000 Bundle Dependency GuardianAutomated dependency management with security scanning, update orchestration, and compatibility validation
567 -
majiayu000 Bundle Developer Detective⚡ PRIMARY TOOL for: 'how does X work', 'find implementation of', 'trace data flow', 'where is X defined', 'audit integrations', 'find all usages'. Uses claudemem v0.3.0 AST with callers/callees analysis. GREP/FIND/GLOB ARE FORBIDDEN.
567 -
majiayu000 Bundle Direction TechniqueDirection Technique pour pilotage stratégique des choix techniques et de l'architecture. Utilise ce skill quand: (1) décisions d'architecture système, (2) choix de stack technique, (3) revue technique stratégique, (4) audit de code ou infrastructure, (5) estimation technique macro, (6) arbitrage dette technique.
567 -
majiayu000 Bundle Documentation AuditUse when documentation drift is detected. Comprehensively audits codebase and creates/updates Swagger, features docs, and general documentation to achieve full sync.
567 -
majiayu000 Bundle Fastapi DevelopmentBuild high-performance FastAPI applications with async routes, validation, dependency injection, security, and automatic API documentation. Use when developing modern Python APIs with async support, automatic OpenAPI documentation, and high performance requirements.
567 -
majiayu000 Bundle Justicehub ReviewerPlatform audit for JusticeHub pages, API routes, Supabase patterns, and Empathy Ledger integration.
567 -
majiayu000 Bundle Ln 630 Test AuditorTest suite audit coordinator (L2). Delegates to 5 workers (Business Logic, E2E, Value, Coverage, Isolation). Aggregates results, creates Linear task in Epic 0.
567 -
majiayu000 Bundle Master Plan AuditorAudit task status across MASTER_PLAN.md and beads. Finds stale tasks, status mismatches, likely-done tasks, and beads sync issues. NEVER auto-marks tasks - only recommends. User confirmation is the only valid evidence of completion.
567 -
majiayu000 Bundle Moai Platform ClerkClerk modern authentication specialist covering WebAuthn, passkeys, passwordless, and beautiful UI components. Use when implementing modern auth with great UX.
567 -
majiayu000 Bundle Moai Security OwaspEnterprise Skill for advanced development
567 -
majiayu000 Bundle Networking ControlsNetwork security and connectivity standards. Use when networking controls guidance is required.
567 -
majiayu000 Bundle Odoo Module CreatorCreates complete Odoo 16.0 modules with proper structure, manifests, models, views, and security. This skill should be used when the user requests creation of a new Odoo module, such as "Create a new module for inventory tracking" or "I need a new POS customization module" or "Generate module structure for vendor management".
567 -
majiayu000 Bundle Opencode Spec CheckThis skill should be used when the user asks to 'check spec alignment', 'verify requirements coverage', 'detect drift', 'spec audit', or automatically at wave gates. Verifies implementation aligns with specification - different from code review which checks quality.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include sf-permissions, triage-malware, unsafe-checker. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.