Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Windows Boundaries- Planning privilege escalation paths through security boundaries
567 -
majiayu000 Bundle Claude Md ManagementProvides comprehensive CLAUDE.md file management capabilities including auditing, quality assessment, and targeted improvements. Use when user asks to check, audit, update, improve, fix, maintain, or validate CLAUDE.md files. Also triggers for "project memory optimization", "CLAUDE.md quality check", "documentation review", or when CLAUDE.md needs to be created from scratch. This skill scans all CLAUDE.md files, evaluates quality against standardized criteria, outputs detailed quality reports with scores and recommendations, then makes targeted updates with user approval.
567 -
majiayu000 Bundle Meta Loop EfficiencyWeekly startup-loop skill efficiency audit. Scans lp-* + startup-loop + draft-outreach skills with deterministic heuristics (wc-l, grep, ls), emits a ranked opportunity artifact, and fires a planning anchor only on new-to-HIGH findings.
567 -
majiayu000 Bundle Linkedin RepurposerRepurpose existing content into a native LinkedIn post. Take a tweet, thread, YouTube video, blog, or newsletter and rebuild it for LinkedIn: re-hook before the fold, expand to the 900 to 1300 char sweet spot, add whitespace and a CTA, move links to the first comment, run the humanizer, publish via Publora on approval. Not for writing from scratch (use linkedin-post-writer), not for auditing a draft (use linkedin-humanizer --mode audit).
567 -
majiayu000 Bundle Lp Onboarding AuditAudit an app's onboarding flow against the "Onboarding Done Right" checklist. Customizes the generic checklist for the app's purpose and audience, then audits actual code using lp-do-fact-find's Outcome A process. Produces an analysis-ready brief.
567 -
majiayu000 Bundle 701 Technologies OpenapiUse when you need framework-agnostic OpenAPI 3.x guidance — spec structure, metadata and versioning, paths and operations, reusable schemas, security schemes, examples, documentation quality, contract validation (e.g. Spectral), breaking-change awareness, and handoffs to codegen — without choosing Spring Boot, Quarkus, or Micronaut. This should trigger for requests such as Review an OpenAPI; Improve an OpenAPI; Improve API contract; Improve API schema design. Part of cursor-rules-java project
567 -
majiayu000 Bundle Installer Quality AuditUse when auditing install, setup, bootstrap, or update scripts for safe, idempotent behavior. Triggers:
567 -
majiayu000 Bundle Antidote Threat HandlerDetect and respond to ideological drift, sycophantic patterns, and alignment threats using the Antidote Protocol.
567 -
majiayu000 Bundle Auditing Access ControlAudit access control implementations for security vulnerabilities and misconfigurations. Use when reviewing authentication and authorization. Trigger with 'audit access control', 'check permissions', or 'validate authorization'.
567 -
majiayu000 Bundle Chrome Extension ExpertBrowser extension expert including Chrome APIs, manifest, and security
567 -
majiayu000 Bundle Code Quality Review AllReview all evaluations in the repository against a single code quality standard. Checks ALL evals against ONE standard for periodic quality reviews. Use when user asks to review/audit/check all evaluations for a specific topic or standard.
567 -
majiayu000 Bundle Cursor Compliance AuditExecute compliance and security auditing for Cursor usage. Triggers on "cursor compliance", "cursor audit", "cursor security review", "cursor soc2", "cursor gdpr". Use when analyzing or auditing cursor compliance audit. Trigger with phrases like "cursor compliance audit", "cursor audit", "cursor".
567 -
majiayu000 Bundle Faion Testing DeveloperTesting: unit, integration, E2E, TDD, mocking, security testing.
567 -
majiayu000 Bundle First Time User Ucv CLISimulate a first-time UCV-CLI user experience. Tests if documentation enables new users to use the interactive variant management dashboard. Generates UX audit reports with friction points.
567 -
majiayu000 Bundle Github AI Features 2025GitHub AI-powered security and automation features for 2025
567 -
majiayu000 Bundle Gsd Plan Milestone GapsParse audit gaps, spawn planner to create gap closure phases
567 -
majiayu000 Bundle Internal Red Team AuditExecute internal red team security audits to identify protocol vulnerabilities and alignment risks.
567 -
majiayu000 Bundle Ln 620 Codebase AuditorCoordinates 9 specialized audit workers (security, build, architecture, code quality, dependencies, dead code, observability, concurrency, lifecycle). Researches best practices, delegates parallel audits, aggregates results into single Linear task in Epic 0.
567 -
majiayu000 Bundle Moai Core Code ReviewerEnterprise systematic code review orchestrator with TRUST 5 principles, multi-language support, Context7 integration, AI-powered quality checks, SOLID principle validation, security vulnerability detection, and maintainability analysis across 25+ programming languages; activates for code reviews, quality standard validation, TRUST 5 enforcement, architectural audits, and automated review automation
567 -
majiayu000 Bundle Moai Framework ElectronElectron 33+ desktop app development specialist covering Main/Renderer process architecture, IPC communication, auto-update, packaging with Electron Forge and electron-builder, and security best practices. Use when building cross-platform desktop applications, implementing native OS integrations, or packaging Electron apps for distribution. [KO: Electron 데스크톱 앱, 크로스플랫폼 개발, IPC 통신] [JA: Electronデスクトップアプリ、クロスプラットフォーム開発] [ZH: Electron桌面应用、跨平台开发]
567 -
majiayu000 Bundle Moai Platform FirestoreFirebase Firestore specialist covering NoSQL patterns, real-time sync, offline caching, and Security Rules. Use when building mobile-first apps with offline support, implementing real-time listeners, or configuring Firestore security.
567 -
majiayu000 Bundle Network Security GroupsConfigure network security groups and firewall rules to control inbound/outbound traffic and implement network segmentation.
567 -
majiayu000 Bundle Pact Testing StrategiesTesting strategies, test pyramid guidance, and quality assurance patterns for PACT Test phase. Use when: designing test suites, implementing unit tests, integration tests, E2E tests, performance testing, security testing, or determining test coverage priorities. Triggers on: test design, unit testing, integration testing, E2E testing, test coverage, test pyramid, mocking, fixtures, performance testing, test phase.
567 -
majiayu000 Bundle Planning Milestone GapsUse this skill when create phases to close all gaps identified by milestone audit. Triggers include "plan milestone gaps", "plan gaps".
567 -
majiayu000 Bundle Program Security BasicsRole framing: You are a Solana security reviewer. Your goal is to catch common vulnerabilities before deployment.
567 -
majiayu000 Bundle Questionably UltrathinkAdvanced reasoning skill integrating Atom of Thoughts (AoT) and Chain of Verification (CoVe) frameworks. Use when facing complex problems requiring rigorous reasoning, systematic decomposition, or factual verification. Activation triggers: - "be thorough", "analyze carefully", "make sure this is right" - Complex multi-part questions - Architecture or security decisions - "verify", "double-check", "are you sure" - High-stakes technical decisions - Debugging complex issues
567 -
majiayu000 Bundle Record Quality BaselineRecord quality metrics baseline before refactoring or major changes, capturing audit scores, test coverage, and complexity for comparison
567 -
majiayu000 Bundle Repo Structure ReviewerAudit a repository's structure and propose a safe, approval-gated reorganization plan. Use when asked to review repo anatomy, propose folder changes, or apply an approved reorg with rollback.
567 -
majiayu000 Bundle Securing AuthenticationAuthentication, authorization, and API security implementation. Use when building user systems, protecting APIs, or implementing access control. Covers OAuth 2.1/OIDC, JWT patterns, sessions, Passkeys/WebAuthn, RBAC/ABAC/ReBAC, policy engines (OPA, Casbin, SpiceDB), managed auth (Clerk, Auth0), self-hosted (Keycloak, Ory), and API security best practices.
567 -
majiayu000 Bundle Security Audit CreationGenerate security audit documentation following the SECURITY-AUDIT template. Use when performing security reviews, checking for vulnerabilities, or when the user asks for a security audit.
567 -
majiayu000 Bundle Security Test GeneratorSecurity Test Generator
567 -
majiayu000 Bundle Security Threat ModelerConducts systematic security analyses using methodologies like STRIDE to identify vulnerabilities in software architectures and propose mitigations.
567 -
majiayu000 Bundle Service Mesh IntegratorConfigure service mesh solutions including Istio, Linkerd, and Consul for traffic management, security, and observability in microservices. Activates for service mesh setup, mTLS, traffic routing, and mesh configuration.
567 -
majiayu000 Bundle Smart Contract SecurityMaster smart contract security with auditing, vulnerability detection, and incident response
567 -
majiayu000 Bundle Spring Boot ApplicationBuild enterprise Spring Boot applications with annotations, dependency injection, data persistence, REST controllers, and security. Use when developing Spring applications, managing beans, implementing services, and configuring Spring Boot projects.
567 -
majiayu000 Bundle Spring Boot DevelopmentComprehensive Spring Boot development skill covering auto-configuration, dependency injection, REST APIs, Spring Data, security, and enterprise Java applications
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include windows-boundaries, claude-md-management, meta-loop-efficiency. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.