Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Pdpa CompliancePDPA (Personal Data Protection Act) is Thailand's comprehensive data protection law that regulates how organizations collect, use, and store personal data. This skill provides patterns for implementin
567 -
majiayu000 Bundle Privesc WindowsWindows privilege escalation — token abuse, service exploitation, UAC bypass, credential harvesting, AD escalation paths
567 -
majiayu000 Bundle Redteam MindsetRed-team operator discipline — the mindset corrections that separate offensive testing from defensive WAPT. Built from authorized red-team work where conservative defaults caused multiple findings to be missed and one to be incorrectly retracted. Use at the START of any red-team engagement and again whenever feeling stuck or considering "stopping" on a defended target. The single most important skill to load when scope is "external red team" not "bug bounty / WAPT".
567 -
majiayu000 Bundle Resemble DetectDeepfake detection and media safety — detect AI-generated audio, images, video, and text, trace synthesis sources, apply watermarks, verify speaker identity, and analyze media intelligence using Resemble AI
567 -
majiayu000 Bundle Respond MalwareRespond to a malware incident following PICERL methodology. Use when malware is detected on endpoints. Orchestrates triage, containment, eradication, and recovery. Works with triage-malware skill for analysis.
567 -
majiayu000 Bundle Review ContractReview Aztec smart contracts for correctness, security, and best practices. Use proactively after writing or modifying Aztec contracts.
567 -
majiayu000 Bundle Secret RotationValidate secret storage practices and rotation policies. Check for secrets in code, Vault usage, and rotation schedules.
567 -
majiayu000 Bundle Security ReportGenerate a comprehensive security report for stakeholders
567 -
majiayu000 Bundle Server Security服务器安全审计与加固。扫描 SSH、防火墙、端口暴露、文件权限、暴力破解等安全问题,生成报告并提供一键修复。当用户说服务器安全、安全审计、安全检查、安全加固时使用
567 -
majiayu000 Bundle Site To IOS AppTurn a website, PWA, dashboard, or marketplace into an iOS app with App Store strategy, screenshots, metadata, and release gates.
567 -
majiayu000 Bundle Soc2 ComplianceImplement SOC 2 Trust Services Criteria. Configure security, availability, and processing integrity controls. Use when achieving SOC 2 certification.
567 -
majiayu000 Bundle Spring SecuritySecure Spring Boot applications - authentication, authorization, OAuth2, JWT, CORS/CSRF protection
567 -
majiayu000 Bundle X9 Inspect CertYou inspect JWKS files and certificate chains for X9.150 implementations. You wrap the project's opencert.py and validatepair.py utilities and interpret their output.
567 -
majiayu000 Bundle X9 TroubleshootYou diagnose common issues with X9.150 implementations. You check the environment, validate key/cert setup, test server connectivity, and explain error messages.
567 -
majiayu000 Bundle Skill Graph AuditAudit Skill() refs; detect hubs, isolates, and dangling targets. Use when auditing skills.
567 -
majiayu000 Bundle Exp Test TaggingAnalyzes test suites and tags each test with a standardized set of traits (e.g., positive, negative, critical-path, boundary, smoke, regression). Use when the user wants to categorize, audit, or label tests with traits. Do not use for writing new tests, running tests, or migrating test frameworks.
567 -
majiayu000 Bundle Flutter PatternsComprehensive Flutter development patterns covering widgets, testing, performance, security, and animations. Use when you need quick reference for Flutter best practices, common UI patterns, performance optimization techniques, security guidelines, or animation implementations.
567 -
majiayu000 Bundle Supabase TestingTesting patterns for Supabase applications covering auth flow testing, Row Level Security policy testing, realtime subscription testing, and edge function testing
567 -
majiayu000 Bundle Handle ApprovalManage human-in-the-loop approval workflow for sensitive actions like payments, email sending, social media posts, and file operations. Creates structured approval requests, monitors approval status in /Approved and /Rejected folders, executes approved actions safely, and maintains complete audit logs. Use when any action requires approval, user mentions "check approvals", "pending approval", "approve this", "what needs approval", or before executing sensitive operations like payments, emails, or social posts.
567 -
majiayu000 Bundle Conversion AuditAudit pages for conversion optimization opportunities. Analyzes value props, CTAs, social proof, friction points, and mobile conversion to identify drop-off causes.
567 -
majiayu000 Bundle Audit API ConsistencyAudit existing API endpoints for consistency when the user asks to check API quality, review API patterns, audit endpoints, or find API inconsistencies
567 -
majiayu000 Bundle Stripe Best PracticesGuides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial accounts, integration surfaces (Checkout, Payment Element), migrating from deprecated Stripe APIs, and security best practices (API key management, restricted keys, webhooks, OAuth). Use when building, modifying, or reviewing any Stripe integration — including accepting payments, building marketplaces, integrating Stripe, processing payments, setting up subscriptions, creating connected accounts, or implementing secure key handling.
567 -
majiayu000 Bundle Iso 24495 Text AuditAudit user-selected Markdown or text files for deterministic plain-language findings. Use only when the user explicitly invokes this skill.
567 -
majiayu000 Bundle Assumption ValidatorSystematically surface, classify, and stress-test assumptions in decisions, strategies, and plans. Transforms hidden assumptions into visible, testable propositions with load-bearing analysis and counterfactual validation. PROACTIVELY activate for: (1) Pre-commitment decision reviews, (2) Strategy validation before execution, (3) Investment due diligence, (4) Architecture decision records, (5) Product direction pivots, (6) Risk assessments requiring assumption audit. Triggers: "validate assumptions", "test assumptions", "assumption check", "stress test this decision", "what are we assuming", "pre-mortem", "what could go wrong", "challenge this plan", "devil's advocate"
567 -
majiayu000 Bundle Blockchain DeveloperExpert blockchain developer specializing in smart contract development, DApp architecture, and DeFi protocols. Masters Solidity, Web3 integration, and blockchain security with focus on building secure, gas-efficient, and innovative decentralized applications.
567 -
majiayu000 Bundle Bmad Security ReviewHardens designs and implementations with structured security reviews.
567 -
majiayu000 Bundle Change Order ManagerManage construction change orders from request to approval. Track costs, schedule impacts, and maintain audit trail for dispute prevention.
567 -
majiayu000 Bundle Code Search Selector⚡ AUTO-INVOKE when user asks: 'audit', 'investigate', 'how does X work', 'find all', 'where is', 'trace', 'understand', 'map the codebase', 'comprehensive'. MUST run BEFORE Read/Glob when planning to read 3+ files. Prevents tool familiarity bias toward native tools.
567 -
majiayu000 Bundle Scanning For Data Privacy IssuesThis skill enables Claude to automatically scan code and configuration files for potential data privacy vulnerabilities using the data-privacy-scanner plugin. It identifies sensitive data exposure, compliance violations, and other privacy-related risks. Use this skill when the user requests to "scan for data privacy issues", "check privacy compliance", "find PII leaks", "identify GDPR violations", or needs a "privacy audit" of their codebase. The skill is most effective when used on projects involving personal data, financial information, or health records.
567 -
majiayu000 Bundle Designing AssertionsPhylax Credible Layer assertions design. Designs invariants and trigger mapping for phylax/credible layer assertions.
567 -
majiayu000 Bundle Error Handling AuditAudits Go code for error handling best practices - proper wrapping with %w, preserved context, meaningful messages, no error swallowing. Use before committing Go code or during error handling reviews.
567 -
majiayu000 Bundle Event Sourcing CoderRecord domain events and dispatch to inbox handlers for side effects, audit trails, and activity feeds. Use when building activity logs, syncing external services, or decoupling event creation from processing. Triggers on event recording, audit trails, activity feeds, or inbox patterns.
567 -
majiayu000 Bundle Hugo Content CheckerThis skill should be used when checking Hugo content for consistency issues, validating internal references, detecting duplicate content, verifying frontmatter completeness, and ensuring proper naming conventions. Use this skill to audit content quality, fix broken links, and maintain consistency across a Hugo site.
567 -
majiayu000 Bundle Landing Page BuilderGenerate structured landing page copy OR audit existing pages for conversion optimization. Framework-agnostic - adapts approach based on awareness level and offer type.
567 -
majiayu000 Bundle Leverage Point AuditAudit a codebase for the 12 leverage points of agentic coding. Identifies gaps and provides prioritized recommendations. Use when improving agentic coding capability, analyzing why agents fail, or optimizing a codebase for autonomous work.
567 -
majiayu000 Bundle Ln 622 Build AuditorBuild health audit worker (L3). Checks compiler/linter errors, deprecation warnings, type errors, failed tests, build configuration issues. Returns findings with severity (Critical/High/Medium/Low), location, effort, and recommendations.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include Pdpa Compliance, privesc-windows, redteam-mindset. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.