Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Substance ScreeningUse when screening for alcohol or drug use concerns (heavy drinking, cravings, loss of control, withdrawal symptoms, functional impairment), assessing substance use severity, determining level of care, or patient reports substance-related problems. Provides AUDIT-C (alcohol brief) and DAST-10 (drugs comprehensive) assessments.
567 -
majiayu000 Bundle Magi SecurityMagi Security
567 -
majiayu000 Bundle Audit ReproducibilityEnforce the replication-protocol.md rule by cross-checking numeric claims in a manuscript against the actual R / Stata / Python outputs. Report PASS/FAIL per claim against tolerance thresholds. Use before submission and before releasing a replication package.
567 -
majiayu000 Bundle Batch Rewrite PatternCascade the same edit pattern across N files safely. Use when applying the same refactor to multiple files (e.g. swap import paths across 11 scripts, rename a symbol, migrate a call signature). Detects the common-shape-across-files situation and turns an N-file cascade into a planned audit → apply → verify workflow instead of N sequential manual edits.
567 -
majiayu000 Bundle Review Fix Grill LoopGrill the current changes — fan out parallel review subagents over the working-tree + branch-vs-base diff, resolve each confirmed finding with multiple architectural solutions, fix in verified batches with auto-revert, re-review only changed files, and loop until no critical/high/medium finding remains. Use when the user says "grill my changes", "review-fix loop", "review and fix my diff until clean", "keep reviewing and fixing until no issues", or "grill loop". Diff-scoped sibling of audit-project (whole-project) with a resolve stage and a medium severity floor.
567 -
majiayu000 Bundle Review BlockingDiscover functions that block the main thread, then micro-audit each for internal optimization opportunities
567 -
majiayu000 Bundle Audit Agents SkillsComprehensive quality audit for Claude Code agents, skills, and commands with comparative analysis
567 -
majiayu000 Bundle Brutal HonestUse when user wants honest, evidence-backed code review. Every finding requires file:line proof. Covers security, architecture, performance, UI/UX for 33+ tech stacks.
567 -
majiayu000 Bundle Ln 610 Docs AuditorUse when auditing project documentation through the evaluation platform with mandatory research, coordinated audit workers, and structured summaries.
567 -
majiayu000 Bundle Project Maintenanceプロジェクトメンテナンス統合監査。複雑度(Lizard)・セキュリティ(Gitleaks/npm audit)・デッドコード(Knip)の3つの監査を統合実行し、リファクタリング対象を優先順位付けして特定する。リファクタリング計画、コード品質チェック、PR作成前の包括的監査に使用。
567 -
majiayu000 Bundle Arch Lens SecurityCreate Security architecture diagram showing trust boundaries, validation layers, and process isolation. Security lens answering "Where are the trust boundaries?"
567 -
majiayu000 Bundle Bugcrowd ReportingBugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, manual severity override when VRT defaults underrate impact, severity-request paragraph as first body section, OOS-clause rebuttal templates (rate limiting on auth-flow endpoints, debug-info framing, user-enumeration with sensitive PII, theoretical-issue counter), chained-finding cross-reference patterns, target selection for QA-vs-prod programs, researcher-side hygiene (Bugcrowdninja email alias, account state restoration, friendly-tester posture). Use when filing a Bugcrowd submission, when VRT default seems wrong, when triager closes as OOS or downgrades severity, when chaining linked submissions, or when scope distinguishes production from QA. Pairs with report-writing and triage-validation.
567 -
majiayu000 Bundle Capability Distill能力蒸馏工作流——从用户批准的强模型访谈或真实任务轨迹中提取非显然的判断规则,形成可审计的 judgment packet,再交给 skill-audit 和 skill-creator 决定是否落成可加载 skill。当用户说“蒸馏这个模型的判断力”“把这次任务的关键决策固化下来”“模型窗口要关了,保留它在某类场景的判断”时使用。普通流程文档、直接写 SKILL.md、泛化最佳实践或未授权的会话日志扫描不使用本 skill。
567 -
majiayu000 Bundle Convex ClerkClerk authentication integration for Convex. Use when setting up Clerk auth, configuring ConvexProviderWithClerk, implementing Clerk webhooks for user sync, or troubleshooting Clerk-specific auth issues.
567 -
majiayu000 Bundle Cyber Owasp ReviewMap application security findings to OWASP Top 10 categories and generate remediation checklists. Use for normalized AppSec review outputs and category-level prioritization.
567 -
majiayu000 Bundle Datenpanne MeldungBegleitet Verantwortliche und Berater bei der Prüfung der Meldepflicht nach Art. 33 DSGVO (72-Stunden-Frist an Aufsichtsbehörde) und der Benachrichtigungspflicht nach Art. 34 DSGVO (betroffene Personen), einschließlich Dokumentation. Lädt bei Datenpannen, Sicherheitsvorfällen, unberechtigten Zugriffen und Datenverlust.
567 -
majiayu000 Bundle Finding DisciplineUse when about to record, claim, rate the severity of, or report any security finding — before marking anything [CONFIRMED] or writing it into the report
567 -
majiayu000 Bundle Fix Security AuditFix security vulnerabilities from pip-audit, npm audit, Snyk, and other security scanners. Use when security audit checks fail with CVE warnings.
567 -
majiayu000 Bundle Full InvestigationComplete Tier 2 investigation workflow. Orchestrates deep investigation of escalated cases: deep-dive-ioc, correlate-ioc, specialized triage (malware/login), pivot-on-ioc, and generate comprehensive report. Use for escalated cases requiring thorough analysis.
567 -
majiayu000 Bundle Gathering SecurityThe drum sounds. Spider, Raccoon, and Turtle gather for complete security work. Use when implementing auth, auditing security, or hardening code end-to-end.
567 -
majiayu000 Bundle Guard Users ClaudeGuardrail policy for Claude CLI: refuse catastrophic actions, require scoped approvals, and reduce secret leakage.
567 -
majiayu000 Bundle Guard Users GeminiGuardrail policy for Gemini CLI: refuse catastrophic actions, require scoped approvals, and reduce secret leakage.
567 -
majiayu000 Bundle Laravel PermissionSpatie Laravel Permission - roles, permissions, middleware, Blade directives, teams, wildcards, super-admin, API, testing. Use when implementing RBAC, role-based access control, or user authorization.
567 -
majiayu000 Bundle Logging MonitoringUse when designing security logging, monitoring, and incident detection capabilities. Covers SIEM architecture, audit trail requirements, security event correlation, and compliance logging for GDPR, PCI DSS, HIPAA, and SOX. USE FOR: SIEM, security logging, audit trails, security monitoring, incident detection, log aggregation, security event correlation, compliance logging, intrusion detection DO NOT USE FOR: application performance monitoring (use observability skills), general logging frameworks (use logging skills), incident response procedures (use secure-sdlc)
567 -
majiayu000 Bundle Manage CredentialsSet up and manage package and connection credentials securely in Datagrok
567 -
majiayu000 Bundle Orchardcore OpenidSkill for configuring and managing OpenID Connect in Orchard Core. Covers server setup, client application registration, authorization flows, token validation, external authentication providers, JWT bearer authentication for APIs, and recipe-based configuration.
567 -
majiayu000 Bundle Performing Penetration TestingThis skill enables automated penetration testing of web applications. It uses the penetration-tester plugin to identify vulnerabilities, including OWASP Top 10 threats, and suggests exploitation techniques. Use this skill when the user requests a "penetration test", "pentest", "vulnerability assessment", or asks to "exploit" a web application. It provides comprehensive reporting on identified security flaws.
567 -
majiayu000 Bundle Compact Core Privacy DisclosureUse when encountering "potential witness-value disclosure" compiler errors, implementing commit-reveal patterns, working with persistentCommit/transientCommit vs persistentHash/transientHash, or designing privacy-preserving circuits with proper witness protection.
567 -
majiayu000 Bundle Midnight Proofs Proof VerificationUse when verifying ZK proofs server-side, validating proofs before transaction submission, building verification gateways, implementing batch verification, or debugging proof generation issues.
567 -
majiayu000 Bundle Respond RansomwareRespond to a ransomware incident following PICERL methodology. Use when ransomware is detected or suspected. Orchestrates identification, containment, eradication, and recovery phases. Requires CASE_ID and initial indicators.
567 -
majiayu000 Bundle Security ChecklistSecurity best practices, OWASP guidelines, and vulnerability prevention checklist. (project)
567 -
majiayu000 Bundle Security Reportingセキュリティ診断レポートの作成と脆弱性報告の文書化を支援するスキル。 脅威分析、脆弱性評価、リスク採点、レポート生成の一連のプロセスを体系化し、 専門的で実用性の高いセキュリティドキュメントを作成する。 Anchors: • OWASP Top 10 (2021) / 適用: 脆弱性分類・評価基準 / 目的: 業界標準への準拠 • CVSS v3.1 (FIRST) / 適用: リスクスコア計算 / 目的: 定量的脆弱性評価 • Web Application Security (Andrew Hoffman) / 適用: 脅威モデリング / 目的: 体系的分析手法 • CWE Top 25 / 適用: 脆弱性分類 / 目的: 共通語彙での報告 Trigger: Use when creating security audit reports, vulnerability assessments, penetration test documentation, or risk analysis documents. security report, vulnerability report, security audit, penetration test report, risk assessment, 脆弱性レポート, セキュリティ監査
567 -
majiayu000 Bundle Ssl Tls ManagementManage SSL/TLS certificates with Let's Encrypt and internal PKI. Configure secure HTTPS, certificate renewal, and cipher suites. Use when implementing secure communications.
567 -
majiayu000 Bundle Tos Clause ScannerAudit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues. Trigger when a user asks to review, audit, or analyze a ToS, privacy policy, or user agreement, or mentions specific concerns like auto-renewal or data authorization.
567 -
majiayu000 Bundle Vendor Risk ScorerComprehensive supplier risk scoring skill with multi-dimensional risk assessment
567 -
majiayu000 Bundle Vulnerability ScanScan for specific vulnerabilities in dependencies and configurations
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include substance-screening, magi-security, audit-reproducibility. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.