Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Forge SecurityEnforces security guardrails for Claude Code. Blocks access to secrets, credentials, and sensitive files. Requires confirmation for network requests and infrastructure changes. Use when accessing files, making network requests, or running infrastructure commands.
567 -
majiayu000 Bundle Reflex FastapiGuide for building custom FastAPI endpoints within Reflex applications. Use when creating webhooks, external API integrations, JWT authentication, or any endpoint that lives outside the Reflex state/event system. Covers integration pattern, Pydantic V2 schemas, async endpoints, dependency injection, security rules, and endpoint testing with httpx.
567 -
majiayu000 Bundle Sonarqube ScanRun SonarQube/SonarCloud static code analysis to check code quality, detect security vulnerabilities, code smells, and bugs. Use when the user mentions SonarQube, code quality analysis, security scanning, static analysis, or wants to check for vulnerabilities.
567 -
majiayu000 Bundle Audit InvestigationUse when investigating config file discrepancies during audit. Spawns config agents in waves to compare template standards against actual files. READ-ONLY analysis - agents report findings but make no changes.
567 -
majiayu000 Bundle Self Hosted RunnersGitHub Actionsセルフホストランナーの設計、セットアップ、セキュリティ管理を行うスキル。 インストールから運用、トラブルシューティングまでの完全なライフサイクル管理を提供する。 Anchors: • GitHub Actions Documentation / 適用: セルフホストランナー公式仕様 / 目的: 正確なAPI使用と設定 • CIS Benchmark for Linux / 適用: ランナーホストのセキュリティ / 目的: セキュリティ強化 • The Pragmatic Programmer / 適用: 実践的改善 / 目的: 段階的な実装と継続的改善 Trigger: Use when setting up self-hosted runners, configuring runner labels, implementing security measures, troubleshooting runner issues, or optimizing runner performance. self-hosted, runner, GitHub Actions, ephemeral, labels, security, setup, configuration
567 -
majiayu000 Bundle Zero Trust SecurityZero-trust architecture operates on the principle: "Never trust, always verify." Unlike traditional perimeter-based security, zero-trust assumes breach and verifies every request regardless of origin.
567 -
majiayu000 Bundle Wordpress MasterElite WordPress architect specializing in full-stack development, performance optimization, and enterprise solutions. Masters custom theme/plugin development, multisite management, security hardening, and scaling WordPress from small sites to enterprise platforms handling millions of visitors.
567 -
majiayu000 Bundle Document In CaseAdd a comment to a case to document findings, actions, or recommendations. Use to maintain audit trail during investigations. Requires CASE_ID and comment text.
567 -
majiayu000 Bundle Linkedin Post WriterDraft a new LinkedIn post from scratch using one of 16 2026 hook formulas (anaphora, R.I.P., year-pivot, time-anchor, curiosity-gap, contrarian, emotional cold-open, named-gratitude, and more), picked by engagement goal (comments, reposts, likes, saves). Runs the humanizer pass and schedules via Publora on approval. Use when the user asks to write a post, needs a hook, or wants a proven format. Not for reviewing existing drafts (use linkedin-humanizer --mode audit).
567 -
majiayu000 Bundle Suede Release LinterAudit creative release folders before handoff: metadata, file structure, artwork, lyrics, stems, rights blockers, and platform readiness.
567 -
majiayu000 Bundle Test Suite ArchitectThis skill should be used when establishing comprehensive QA testing processes for any software project. Use when creating test strategies, writing test cases following Google Testing Standards, executing test plans, tracking bugs with P0-P4 classification, calculating quality metrics, or generating progress reports. Includes autonomous execution capability via master prompts and complete documentation templates for third-party QA team handoffs. Implements OWASP security testing and achieves 90% coverage targets.
567 -
majiayu000 Bundle Review LatencyAudit the two latency-critical paths for blocking work, redundant computation, and micro-optimization opportunities
567 -
majiayu000 Bundle Review ShadersAudit HLSL pixel shaders for GPU performance — math optimizations, ALU reduction, texture efficiency at 120-240fps
567 -
majiayu000 Bundle Gitlab Code ReviewPerforms comprehensive code reviews of GitLab merge requests, analyzing code quality, security, performance, and best practices. Use when the user says "review" or "code review" or asks to review merge requests or analyze branch changes before merging.
567 -
majiayu000 Bundle Green Mirage AuditUse when reviewing test suites, after test runs pass, or when user asks about test quality
567 -
majiayu000 Bundle Narrow Bare RescueNarrow bare `rescue _ ->` / `rescue e ->` so UndefinedFunctionError, KeyError, and typos propagate instead of being swallowed. Use for auditing rescues, secure-coding review, exception review, refactoring error handling in Elixir.
567 -
majiayu000 Bundle PPTX Slide AuditorAudit a PowerPoint presentation for layout issues, text overflow, visual hierarchy problems, and consistency gaps. Use when asked to review a slide deck, check a presentation before a meeting, audit slides for layout problems, or QA a deck before sharing. Produces a slide-by-slide report with issues ranked by severity and specific fixes. Best used with Claude Opus 4.7 or newer for reliable slide-level vision analysis.
567 -
majiayu000 Bundle Suede Rights AuditFind the rights gaps before packaging: ownership, splits, samples, provenance, metadata, licensing readiness, royalties, and intake blockers.
567 -
majiayu000 Bundle Business LogicHunt business logic flaws — race conditions, workflow state bypass, parameter pollution affecting logic, coupon/discount abuse, refund logic, multi-step process bypass, integer overflow, negative quantities, double-spend. Use when looking for non-CVE bugs that require understanding the app's intended workflow.
567 -
majiayu000 Bundle HTTP SmugglingHunt HTTP Request Smuggling (CL.TE, TE.CL, TE.TE, H2.CL, H2.TE, downgrade smuggling). Use when target is behind a reverse proxy / load balancer / CDN and you want to test for desync attacks that bypass front-end security controls.
567 -
majiayu000 Bundle Abp AuthorizationABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side. Use when working with permissions, authorization, role-based access, or security in ABP projects.
567 -
majiayu000 Bundle Af Audit SecurityAudit security posture and configure vulnerability scanning for projects. Use when running OWASP compliance checks, managing secrets, or adding dependency scanning to CI pipelines.
567 -
majiayu000 Bundle API Auth NextauthAuth.js (NextAuth v5) authentication patterns - configuration, providers, session strategies, middleware, database adapters, role-based access, Edge compatibility
567 -
majiayu000 Bundle API Bypass LayersMulti-layer security architecture for API bypass (superadmin/developer). Covers authentication layers, authorization, team context, RLS policies, and three-layer bypass validation. Use this skill when implementing admin bypass features or validating security architecture.
567 -
majiayu000 Bundle API Rate LimitingImplements API rate limiting using token bucket, sliding window, and Redis-based algorithms to protect against abuse. Use when securing public APIs, implementing tiered access, or preventing denial-of-service attacks.
567 -
majiayu000 Bundle Claude Tob ReviewTrail of Bits security skills analysis for Solidity contracts. Use for deep smart contract security review with invariant suggestions.
567 -
majiayu000 Bundle Convex Auth SetupSet up Convex authentication, user mapping, authorization, and custom function wrappers for data protection.
567 -
majiayu000 Bundle Convex AuthCore authentication patterns for Convex backends. Use when implementing auth checks in functions, storing users in database, creating auth helpers, or debugging auth issues. Works with any auth provider (Clerk, WorkOS, Auth0, etc.).
567 -
majiayu000 Bundle Create Auth SkillA skill to create auth service for new applications.
567 -
majiayu000 Bundle Dataflow AnalysisTrack data flow between function parameters, calls, and arguments using taint analysis. Use when detecting vulnerabilities like command injection, buffer overflows, or tracing user input to dangerous functions.
567 -
majiayu000 Bundle Decision VarianceReconcile the project's architectural artifacts against the scaffold and prior decisions, then present each variance as a SMARTS analysis for the user to decide. Routed to when the user asks to arbitrate, reconcile, or consolidate architectural context, requests a variance report, mentions ADR conflicts, or asks which downstream artifacts the current state supports. Never decides alone — every arbitration is user-attributed and logged.
567 -
majiayu000 Bundle Device Credentialデバイスクレデンシャル(Device Credential)機能の開発・修正を行う際に使用。デバイスシークレット発行、JWT Bearer Grant、CIBAデバイス認証、セキュリティ実装時に役立つ。
567 -
majiayu000 Bundle Df Security AuditScan codebase for security vulnerabilities using parallel auditor agents. Standalone — works without .planning/ state. Covers OWASP Top 10, secrets, dependency risks, auth flaws. Triggers on: "security audit", "scan for vulnerabilities", "check for secrets", "security review", "find security issues"
567 -
majiayu000 Bundle Engagement MemoryUse when recalling prior techniques at recon/weaponize, or recording a confirmed finding at report — cross-engagement pattern memory ranked by impact
567 -
majiayu000 Bundle Firebase SecurityFirebase security rules patterns for Firestore and Storage. Use when writing or reviewing security rules.
567 -
majiayu000 Bundle Full Triage AlertComplete Tier 1 triage workflow. Orchestrates the full alert triage process: check-duplicates, triage-alert, enrich-ioc for each entity, and either close (FP/BTP) or escalate (TP/Suspicious). Use for end-to-end alert processing.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include forge-security, reflex-fastapi, sonarqube-scan. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.