Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Auditing Wallet SecurityAudit wallet security by analyzing token approvals, permissions, and transaction patterns. Use when checking wallet security, reviewing approvals, or assessing risk exposure. Trigger with phrases like "audit wallet", "check approvals", "security scan", or "revoke tokens".
567 -
majiayu000 Bundle Burpsuite Project ParserSearches and explores Burp Suite project files (.burp) from the command line. Use when searching response headers or bodies with regex patterns, extracting security audit findings, dumping proxy history or site map data, or analyzing HTTP traffic captured in a Burp project.
567 -
majiayu000 Bundle Capacitor Best PracticesBest practices for Capacitor app development including project structure, plugin usage, performance optimization, security, and deployment. Use this skill when reviewing Capacitor code, setting up new projects, or optimizing existing apps.
567 -
majiayu000 Bundle Claude Code Audit PluginAudit a Claude Code plugin against best practices and suggest improvements
567 -
majiayu000 Bundle Databricks Unity CatalogUnity Catalog system tables for lineage, audit logs, billing, compute, jobs, and query history. Use when querying system.access.audit, system.access.table_lineage, system.billing.usage, system.compute.clusters, system.lakeflow.jobs, system.lakeflow.job_run_timeline, or system.query.history.
567 -
majiayu000 Bundle Firestore Security RulesWrite and validate Firestore Security Rules following the project's multi-tenancy Blueprint pattern. Use this skill when implementing collection-level security, Blueprint membership validation, role-based permissions, and data access controls. Ensures rules validate BlueprintMember status, check permissions array, enforce data isolation, and integrate with the three-layer architecture where Security Rules are the first line of defense.
567 -
majiayu000 Bundle Gemini Research SubagentDelegates large-context code analysis to Gemini CLI. Use when analyzing codebases, tracing bugs across files, reviewing architecture, or performing security audits. Gemini reads, Claude implements.
567 -
majiayu000 Bundle Ln 626 Dead Code AuditorDead code & legacy audit worker (L3). Checks unreachable code, unused imports/variables/functions, commented-out code, backward compatibility shims, deprecated patterns. Returns findings.
567 -
majiayu000 Bundle Ln 629 Lifecycle AuditorApplication lifecycle audit worker (L3). Checks bootstrap initialization order, graceful shutdown, resource cleanup, signal handling, liveness/readiness probes. Returns findings with severity, location, effort, recommendations.
567 -
majiayu000 Bundle Ln 773 Cors ConfiguratorConfigures CORS policy for development and production
567 -
majiayu000 Bundle Longbridge Security ListUS overnight-eligible securities directory and HK broker participant directory via Longbridge Securities. `security-list` covers the US overnight-trading catalog only (this is the only category exposed through this endpoint). `participants` is the HK broker_id ↔ name dictionary. For non-US listed-stock lookups, route the user to `longbridge-quote` for individual symbol queries. Triggers: "美股 listed", "美股 overnight", "经纪商 ID", "broker_id", "港股经纪商", "港股經紀商", "經紀商 ID", "list of US stocks", "overnight tradable", "broker directory", "participant lookup".
567 -
majiayu000 Bundle Magento Security AnalystConducts comprehensive Magento 2 security assessments and implements security measures. Use when auditing security, identifying vulnerabilities, implementing security controls, or ensuring compliance. Masters security auditing, vulnerability management, and compliance frameworks.
567 -
majiayu000 Bundle Moai Security ComplianceEnterprise Skill for advanced development
567 -
majiayu000 Bundle Moai Security EncryptionEncryption patterns - AES-GCM, RSA, password hashing, envelope encryption
567 -
majiayu000 Bundle Openclaw Runtime MonitorReal-time security monitoring for OpenClaw including file system access monitoring, credential access detection, anomaly identification, and automated incident response.
567 -
majiayu000 Bundle Openiddict AuthorizationMaster OAuth 2.0 authorization patterns with OpenIddict and ABP Framework including permission-based authorization, role-based access control, custom claims, and multi-tenant security. Use when implementing authentication/authorization for ABP applications.
567 -
majiayu000 Bundle QA API Testing ContractsAPI testing and contract validation across REST (OpenAPI 3.1), GraphQL (SDL), and gRPC (proto). Use when you need schema linting/validation, breaking-change detection (openapi diff, GraphQL schema diff, buf breaking), consumer/provider contract tests (Pact or schema-driven), negative/security testing, and CI quality gates.
567 -
majiayu000 Bundle Safety Pattern DeveloperGuide through TDD process for adding new safety patterns - from threat identification to commit
567 -
majiayu000 Bundle Smart Contract GeneratorGenerates Solidity smart contracts with security best practices (ERC-20, ERC-721, ERC-1155, custom). Use when user asks to "create smart contract", "solidity contract", "erc20 token", "nft contract", or "web3 contract".
567 -
majiayu000 Bundle Software Security AppsecModern application security patterns aligned with OWASP Top 10:2025 (final), OWASP API Security Top 10 (2023), NIST SSDF, zero trust (incl. NSA ZIGs 2026), supply chain security (SBOM), passkeys/WebAuthn, authentication, authorization, input validation, cryptography, plus security ROI, breach cost modeling, and compliance-driven enterprise sales.
567 -
majiayu000 Bundle Spring Boot Security JWTJWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x.
567 -
majiayu000 Bundle Static Security AnalyzerWrapper around Tizen Studio static analyzer. Detects memory leaks, buffer overflows, and coding vulnerabilities in C/C++/JavaScript.
567 -
majiayu000 Bundle Supabase Audit FunctionsDiscover and test Supabase Edge Functions for security vulnerabilities and misconfigurations.
567 -
majiayu000 Bundle System Hardening ToolkitmacOS and Linux security hardening toolkit providing configuration scripts, audit checklists, and remediation procedures for system security.
567 -
majiayu000 Bundle Technical Spec ReviewingReviews technical specifications for completeness, feasibility, and production readiness. Validates architecture, APIs, security, and operational concerns. Use when reviewing tech specs before implementation or architecture review meetings.
567 -
majiayu000 Bundle Triggering AI ReflectionTriggering and managing AI reflection cycles in StickerNest. Use when the user wants to run AI evaluation, trigger reflection, check AI quality, improve AI prompts, analyze AI performance, or audit AI generations. Covers reflection triggers, evaluation analysis, and improvement actions.
567 -
majiayu000 Bundle Unity Catalog GovernanceUnity Catalog governance patterns, permissions models, security best practices, and policy enforcement for enterprise data governance.
567 -
majiayu000 Bundle Using Security ArchitectRoutes to security architecture skills - threat modeling, controls, compliance, authorization
567 -
majiayu000 Bundle Vulnerability ManagementVulnerability assessment, tracking, and remediation management. Process scan results, prioritize findings, and track remediation progress. Use for vulnerability management programs and security assessments.
567 -
majiayu000 Bundle Vulnerability ValidationValidate security findings from commit-security-scan by assessing exploitability, filtering false positives, and generating proof-of-concept exploits. Use after running commit-security-scan to confirm vulnerabilities.
567 -
majiayu000 Bundle UI UX Audit GuidelinesProfessional UI/UX audit methodology and design vocabulary. Use when: conducting UI/UX audits, evaluating visual hierarchy, analyzing responsive design, assessing interaction patterns. Do NOT use for:
567 -
majiayu000 Bundle Agentforge ConvexComprehensive Convex development skill for building production-ready apps. Covers functions (queries, mutations, actions, HTTP endpoints), schemas, real-time subscriptions, cron jobs, migrations, and security. USE THIS SKILL whenever the user is working with Convex — whether they mention Convex directly, reference files in a convex/ directory, ask about reactive databases, real-time subscriptions, Convex functions, Convex schemas, cron jobs in Convex, HTTP actions, webhook handling, data migrations, or security audits for a Convex app. Also trigger for questions about ConvexError, v.* validators, defineSchema, defineTable, useQuery, useMutation, usePaginatedQuery, optimistic updates, or ctx.db / ctx.scheduler / ctx.storage calls.
567 -
majiayu000 Bundle Audit RemediationApply approved remediation actions from audit resolution. Implements config file updates, template syncs, and code fixes using appropriate domain/config agents. Use when audit findings have been approved for remediation and need implementation.
567 -
majiayu000 Bundle Buff CodeThis skill should be used when the user asks to "write code", "implement this", "build a feature", "help me code", "run /buff:code", "audit the code", "explain the code", "add a function", "refactor", or any general coding or implementation request across any language or framework. Project-aware with cross-file context, architecture enforcement, and duplication detection. Auto-activates silently during development to raise code quality; produces visible output only on explicit invocation.
567 -
majiayu000 Bundle Electron PatternsElectron desktop patterns including IPC, security, auto-update, and native integrations.
567 -
majiayu000 Bundle Ck GitGit operations with conventional commits. Use for staging, committing, pushing, PRs, merges. Auto-splits commits by type/scope. Security scans for secrets.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include auditing-wallet-security, burpsuite-project-parser, capacitor-best-practices. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.