Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Shipflow Market StudyComplete market study for a product/niche — demand analysis, competition audit, keyword volumes, monetization strategy, GO/NO-GO verdict with structured report
567 -
majiayu000 Bundle Checking Hipaa ComplianceCheck HIPAA compliance for healthcare data security requirements. Use when auditing healthcare applications. Trigger with 'check HIPAA compliance', 'validate health data security', or 'audit PHI protection'.
567 -
majiayu000 Bundle Checking Owasp ComplianceCheck compliance with OWASP Top 10 security risks and best practices. Use when performing comprehensive security audits. Trigger with 'check OWASP compliance', 'audit web security', or 'validate OWASP'.
567 -
majiayu000 Bundle Checking Session SecurityAnalyze session management implementations to identify security vulnerabilities in web applications. Use when you need to audit session handling, check for session fixation risks, review session timeout configurations, or validate session ID generation security. Trigger with phrases like "check session security", "audit session management", "review session handling", or "session fixation vulnerability".
567 -
majiayu000 Bundle Comprehensive Test ReviewThis skill should be used when the user asks to "review test coverage", "audit test quality", "check tests for completeness", or mentions reviewing pytest test suites. Performs thorough test review following standard checklist for test isolation, mock usage, naming, and coverage.
567 -
majiayu000 Bundle Context Security ResolverAuthentication, authorization, Clerk integration, RLS policies, and security patterns. Use when working with security-resolver code, files, or integration. Invoke when navigating security-resolver cod
567 -
majiayu000 Bundle Dependency Security CheckYou are an expert in dependency security analysis, vulnerability assessment, and supply chain security. You specialize in identifying security risks in project dependencies, implementing automated sec
567 -
majiayu000 Bundle First Time User DashboardSimulate a first-time CV Dashboard user experience. Tests if documentation enables new users to generate and access the password-protected variant dashboard. Generates UX audit reports.
567 -
majiayu000 Bundle Julien Ref Doc ProductionDocumentation production methodology with DRY principles. Covers 8 document types (GUIDE, INCIDENT, SESSION, AUDIT, RECHERCHE, etc.), naming conventions, and YAML metadata.
567 -
majiayu000 Bundle Klingai Compliance ReviewExecute conduct compliance reviews for Kling AI integrations. Use when preparing for audits, ensuring regulatory compliance, or reviewing security posture. Trigger with phrases like 'klingai compliance', 'kling ai audit prep', 'klingai security review', 'video generation compliance'.
567 -
majiayu000 Bundle Ln 633 Test Value AuditorRisk-Based Value audit worker (L3). Calculates Usefulness Score = Impact (1-5) × Probability (1-5) for each test. Returns KEEP/REVIEW/REMOVE decisions based on thresholds (≥15 KEEP, 10-14 REVIEW, <10 REMOVE).
567 -
majiayu000 Bundle Maven Dependency ResearchResearch Maven dependency updates with breaking changes, release notes, and security information
567 -
majiayu000 Bundle Moai Alfred Code ReviewerEnterprise systematic code review orchestrator with TRUST 5 principles, multi-language support, Context7 integration, AI-powered quality checks, SOLID principle validation, security vulnerability detection, and maintainability analysis across 25+ programming languages; activates for code reviews, quality standard validation, TRUST 5 enforcement, architectural audits, and automated review automation
567 -
majiayu000 Bundle Nist Cybersecurity SkillsComprehensive NIST cybersecurity framework reference covering SP 800-53 Rev 5 (security/privacy controls), SP 800-171 (CUI protection), CSF 2.0 (Cybersecurity Framework), SP 800-53A (assessment procedures), SP 800-37 (RMF), SP 800-207 (Zero Trust), SP 800-30 (risk assessment), SP 800-61 (incident response), SP 800-63 (digital identity), SP 800-161 (supply chain), and FIPS standards. Use when working with NIST controls, compliance, FedRAMP baselines, security assessments, or cybersecurity frameworks.
567 -
majiayu000 Bundle Objection Handling ExpertExpert in analyzing and responding to tenant objections in commercial lease negotiations. Use when tenant objects to rent as above market, requests higher TI allowance, demands more free rent, pushes back on security deposit or personal guarantee, claims market is soft, cites competitive properties, requests shorter term or early termination rights, or challenges any lease provision. Expert in classifying objection types (financial, operational, market-based, risk-based), distinguishing legitimate concerns from negotiating tactics, and crafting evidence-based responses. Key terms include rent objection, TI allowance, free rent, market comparables, competitive pressure, tactical objection, legitimate concern, evidence-based response, value-creating solution
567 -
majiayu000 Bundle Production Code StandardsProduction-ready code standards following CLAUDE Framework with TDD, security, and quality requirements
567 -
majiayu000 Bundle Requirements TraceabilityCreate or audit requirements-to-design-to-code-to-test traceability. Builds a traceability matrix (REQ → design/ADR → implementation files → tests → evidence) and flags gaps (unimplemented requirements, untested changes, undocumented decisions). Use when you need a requirements traceability check for a PR/release, regulated/compliance work, or when requirements are drifting from implementation.
567 -
majiayu000 Bundle Resource Management AuditAudit resource management including IDisposable pattern implementation, proper cleanup of OpenGL resources (buffers, textures, shaders, framebuffers), memory leak detection, resource lifetime management, and GPU resource tracking. Use when investigating memory leaks, GPU resource exhaustion, or implementing new resource types.
567 -
majiayu000 Bundle Reviewing Typescript CodeTypeScript code quality patterns for writing and reviewing code. Covers type safety, clean code, functional patterns, Zod usage, and error handling. Triggers on: add entity, create service, add repository, create comparator, add formatter, deployment stage, GraphQL query, GraphQL mutation, bootstrap method, diff support, command handler, Zod schema, error class, implement feature, add function, refactor code, clean code, functional patterns, map filter reduce, satisfies operator, type guard, code review, PR review, check implementation, audit code, fix types.
567 -
majiayu000 Bundle Security Compliance AuditConduct comprehensive security compliance audits for SOC 2, GDPR, HIPAA, PCI-DSS, and ISO 27001. Use when preparing for certification, annual audits, or compliance validation.
567 -
majiayu000 Bundle Security Testing PatternsSecurity testing patterns including SAST, DAST, penetration testing, and vulnerability assessment techniques. Use when implementing security testing pipelines, conducting security audits, or validating application security controls.
567 -
majiayu000 Bundle Spring Framework PatternsComprehensive Spring Framework and Spring Boot best practices including dependency injection patterns, bean lifecycle and scopes, REST API development, Spring Data JPA, service layer design, Spring Security, testing strategies, caching, AOP, async processing, error handling, and common anti-patterns. Essential reference for code reviews and Spring Boot application development.
567 -
majiayu000 Bundle Supabase Audit Auth UsersTest for user enumeration vulnerabilities through various authentication endpoints.
567 -
majiayu000 Bundle Validate Tenant IsolationVerifies tenant isolation is enforced at all layers (gateway, service, database) following .cursorrules Security Requirements and ModuleImplementationGuide.md Section 11. Checks X-Tenant-ID header validation in routes, verifies tenantId in all database queries, validates tenant enforcement middleware, checks service-to-service tenant propagation, verifies audit logging includes tenantId, and ensures tenantId is in partition key for all Cosmos DB queries. Use when performing security audits, pre-deployment checks, or ensuring multi-tenancy compliance.
567 -
majiayu000 Bundle Webhook Receiver HardenerSecures webhook receivers with signature verification, retry handling, deduplication, idempotency keys, and error responses. Provides verification code, dedupe storage strategy, runbook for incidents. Use when implementing "webhooks", "webhook security", "event receivers", or "third-party integrations".
567 -
majiayu000 Bundle Convex DevelopmentApply Convex database best practices for cost optimization, performance, security, and architecture. Use when: building Convex backends, optimizing queries, handling embeddings/vector search, reviewing Convex code, designing schemas, planning migrations, or discussing Convex architecture. Keywords: Convex, real-time database, queries, mutations, actions, indexes, pagination, vector search, embeddings, schema, migrations, ctx.auth, convex-helpers, bandwidth.
567 -
majiayu000 Bundle Differential AuditCompare two implementations of the same thing — a port (R↔Python↔Stata), a reimplementation, a replication package, a refactor, or a new version against the old — so that agreement means something. Freeze inputs first, inventory every expected output, test the comparator itself, compare every channel (not just the headline number), and give each divergence a stable ID and a smallest witness. Use for cross-language parity, replication, upgrade/regression gates, or whenever "the numbers match" is about to license a claim.
567 -
majiayu000 Bundle Figure Table AuditAudit figures, tables, captions, cross-references, and statistical notes.
567 -
majiayu000 Bundle Naming ObviousnessReviews naming quality and code obviousness. Use when the user asks to check naming, when names feel vague or imprecise, when something is hard to name (a design signal, not a vocabulary problem), or when code behavior isn't obvious on first read. Applies the isolation test, scope-length principle, and consistency audit.
567 -
majiayu000 Bundle Rust Ub Risk AuditUse when auditing Rust UB risks in unsafe, FFI, raw pointers, layout, or concurrency. Triggers:
567 -
majiayu000 Bundle Spring Boot KotlinSpring Boot with Kotlin framework guardrails, patterns, and best practices. Use when working with Spring Boot Kotlin projects, or when the user mentions Spring Boot with Kotlin. Provides coroutine patterns, WebFlux, JPA, security, and idiomatic Kotlin-Spring guidelines.
567 -
majiayu000 Bundle 804 Regulations Eu Nis2Use when reviewing, designing, or modifying Java enterprise systems that may support essential or important entities, critical-sector services, managed service providers, supply-chain dependencies, or cybersecurity incident escalation obligations under NIS2. This should trigger for requests such as Review a Java platform for NIS2 cybersecurity controls; Design operational evidence for critical-sector services; Add incident detection, escalation, continuity, or supply-chain security controls; Assess cybersecurity risk management before production release. Part of cursor-rules-java project
567 -
majiayu000 Bundle Lp Guide ImproveMain entry point for guide improvement - interactive workflow selection for audit, translation, or both
567 -
majiayu000 Bundle Firebase Data ConnectUse when setting up Data Connect, writing GraphQL queries/mutations, configuring generated SDKs, handling offline, or applying security rules.
567 -
majiayu000 Bundle Subscription RecoveryUse when the user wants to find, audit, cancel, or dispute recurring charges billed outside Amazon, including App Store, Google Play, PayPal, direct-bill streaming, gyms, news, and SaaS. Discover charges from evidence the user directly provides or authenticated service pages, report findings first, and require confirmation before cancellation or refund contact. Never enter payment credentials or promise recovery. Requires Claude in Chrome for browser actions. NOT FOR: Amazon returns, restocking fees, or Amazon-billed Prime Video Channels, Audible, Kindle Unlimited, or Prime — use amazon-returns-recovery for those.
567 -
majiayu000 Bundle API Fuzzing For Bug BountyThis skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include nist-cybersecurity-skills, shipflow-market-study, checking-hipaa-compliance. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.