Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Ce Serialization AuditAudit save and load behavior for ADR-031 schema contracts, invariants, and round-trip safety.
567 -
majiayu000 Bundle Localsetup Pr ReviewerAutomated GitHub PR code review with diff analysis, lint integration, and structured reports. Use when reviewing pull requests, checking for security issues, error handling gaps, test coverage, or code style problems. Supports Go, Python, and JavaScript/TypeScript. Requires gh CLI authenticated with repo access.
567 -
majiayu000 Bundle Maven Dependency AuditAudit Maven dependencies for outdated versions, security vulnerabilities, and conflicts. Use when user says "check dependencies", "audit dependencies", "outdated deps", or before releases.
567 -
majiayu000 Bundle Quality NonconformanceCodified expertise for quality control, non-conformance investigation, root cause analysis, corrective action, and supplier quality management in regulated manufacturing. Informed by quality engineers with 15+ years experience across FDA, IATF 16949, and AS9100 environments. Includes NCR lifecycle management, CAPA systems, SPC interpretation, and audit methodology. Use when investigating non-conformances, performing root cause analysis, managing CAPAs, interpreting SPC data, or handling supplier quality issues.
567 -
majiayu000 Bundle Review Config RegistryAudit config registry for dead keys, no-op configs, stale descriptions, and organizational opportunities
567 -
majiayu000 Bundle Review Race ConditionsAudit for race conditions in timers, hotkeys, callbacks, and shared state
567 -
majiayu000 Bundle Using Codebase QualityCodebase quality orchestration for maintaining high-quality, secure, well-documented code. Use when completing features, running quality audits, checking security, updating documentation, or before merging PRs. Triggers on quality check, code review, security scan, documentation update, codebase audit, pre-merge check, bd close, feature complete.
567 -
majiayu000 Bundle Af Security ExpertiseUse when configuring security tooling, running security audits, or adding vulnerability scanning to projects. Covers Dependabot, npm audit, GitHub secret scanning, and CI security workflows.
567 -
majiayu000 Bundle Building Attack Trees<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Byte Pattern MatchingSearch for raw byte patterns (hex sequences, opcodes) in binary code. Use when looking for specific instruction sequences, machine code patterns, UEFI SMI handlers, or known vulnerability signatures by their byte representation.
567 -
majiayu000 Bundle Cloudflare Zero TrustProtect internal apps with Cloudflare Access, device posture, and Zero Trust policies.
567 -
majiayu000 Bundle Code Pattern MatchingSearch for code patterns in decompiled output using Weggli semantic matching. Use when finding vulnerable code constructs like unchecked memcpy, buffer operations, or specific function call patterns in pseudocode.
567 -
majiayu000 Bundle Convex Security AuditDeep security review patterns for authorization logic, data access boundaries, action isolation, rate limiting, and protecting sensitive operations
567 -
majiayu000 Bundle Convex Security CheckQuick security audit checklist covering authentication, function exposure, argument validation, row-level access control, and environment variable handling
567 -
majiayu000 Bundle Damage Control ExpertThe Damage Control Expert - Guardian of the Nebuchadnezzar v4.0 system integrity. Monitors PreToolUse hooks, manages blocked operation alerts, and coordinates incident response. This expert protects critical files, prevents destructive commands, and maintains system safety. Use when: (1) Blocked operation detected - HUD shows active damage alerts (2) "damage control" or "security" - review blocked operations history (3) "unblock" or "whitelist" - analyze if operation should be allowed (4) Hook configuration - modify patterns.yaml protections (5) Incident response - coordinate recovery from blocked operations Triggers on: "damage control", "blocked operation", "security alert", "damage detected", "unblock", "whitelist", "hook configuration", "protected path"
567 -
majiayu000 Bundle Detection Engineering<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Employment ComplianceCovers the employment rules that carry real penalties — exempt and non-exempt classification, overtime and hours, employee versus contractor status, work authorization and recordkeeping, accommodation requests, and the notices and retention obligations that go with them. Use this to classify a role, review a contractor arrangement, respond to an accommodation request, work out what records to keep and for how long, or sanity-check a practice you inherited.
567 -
majiayu000 Bundle Enterprise Vpn AttackExternal SSL VPN / remote-access appliance attack matrix — Cisco ASA/AnyConnect, Fortinet FortiGate/FortiOS, Citrix NetScaler/ADC, Palo Alto GlobalProtect, Pulse Secure / Ivanti Connect Secure, SonicWall, F5 Big-IP. Covers version fingerprinting, CVE matrix (2018-2026), AAA backend identification, default credentials, configuration-disclosure paths, pre-auth RCE/SSRF/path-traversal exploits where applicable. Built from authorized-engagement Cisco ASA testing plus 2024-2026 enterprise VPN CVE landscape. Use whenever the target's perimeter exposes any SSL VPN appliance or remote-access gateway — these are the most common initial-access points in 2024-2026 actor TTPs.
567 -
majiayu000 Bundle Extensions ComplianceGuidance for Microsoft.Extensions.Compliance data classification and redaction. USE FOR: classifying sensitive data (PII, EUII, financial), redacting log output, enforcing data handling policies, compliance-aware telemetry, audit-safe logging pipelines. DO NOT USE FOR: encryption at rest (use Data Protection APIs), access control/authorization (use ASP.NET Identity), GDPR consent management, full DLP solutions.
567 -
majiayu000 Bundle Forge Security ReviewPerforms a white-box security review of Atlassian Forge apps using structured, Forge-specific security rules and evidence-driven reporting. Use when the user asks for a Forge security review, security audit, vuln assessment, pentest-style code review, authz review, tenant isolation analysis, web trigger hardening, or static analysis execution for a Forge app.
567 -
majiayu000 Bundle Gke Workload SecurityWorkflows for auditing and hardening the security of GKE workloads.
567 -
majiayu000 Bundle Guard Users OpenhandsGuardrail policy for Openhands CLI: refuse catastrophic actions, require scoped approvals, and reduce secret leakage.
567 -
majiayu000 Bundle Hunt Lateral MovementHunt for lateral movement using PsExec, WMI, or similar techniques. Use when proactively searching for attackers moving through your network using admin tools. Searches for service installations, remote process execution, and suspicious network correlations.
567 -
majiayu000 Bundle Iot Security ReviewerExpert IoT security review covering network security, authentication, encryption, secure boot, and attack surface analysis. Use when reviewing device security, implementing authentication, hardening firmware, conducting security audits, or analyzing embedded systems for vulnerabilities. Particularly valuable for ESP32/RP2350 projects, BLE/WiFi devices, MQTT systems, and mobile IoT applications.
567 -
majiayu000 Bundle Iso27001 Gap AnalyzerAnalyze iso27001 gap analyzer operations. Auto-activating skill for Security Advanced. Triggers on: iso27001 gap analyzer, iso27001 gap analyzer Part of the Security Advanced skill category. Use when analyzing or auditing iso27001 gap analyzer. Trigger with phrases like "iso27001 gap analyzer", "iso27001 analyzer", "analyze iso27001 gap r".
567 -
majiayu000 Bundle Ki FolgenabschaetzungKI-Folgenabschätzung (FRIA nach Art. 27 KI-VO + DSFA nach Art. 35 DSGVO) erstellen – strukturierte Aufnahme, Risikoanalyse, Regulierungsklassifizierung nach KI-VO und DSGVO, Richtlinien-Konsistenzprüfung und Empfehlung mit Bedingungen. Verwendet das Hausformat aus der Seed-Folgenabschätzung in der Praxisprofil-CLAUDE.md. Verwenden, wenn der Nutzer sagt "Folgenabschätzung für", "diesen KI-Anwendungsfall bewerten", "FRIA erstellen", "KI-Folgenabschätzung generieren", "wir müssen dieses KI-System dokumentieren", "KI-Risikoprüfung für X" oder nach einem bedingten Triage-Ergebnis.
567 -
majiayu000 Bundle Ln 760 Security SetupSets up security scanning for secrets and dependency vulnerabilities. Use when adding security infrastructure to a project.
567 -
majiayu000 Bundle Ln 761 Secret ScannerScans codebase for hardcoded secrets with severity classification and remediation guidance. Use when auditing a project for leaked credentials.
567 -
majiayu000 Bundle Nestjs Bcryptjs SetupInstall, repair, and verify bcryptjs hashing in NestJS with ConfigModule-based SALT_ROUNDS validation, a reusable hash/verify EncryptionService, and a global EncryptionModule export. Use when users ask to add or fix password hashing, credential verification, auth secret hashing, login compare flow, or reusable bcrypt utilities.
567 -
majiayu000 Bundle Nw Operational SafetyTool safety protocols, adversarial output validation, error recovery patterns, and I/O contracts for research operations
567 -
majiayu000 Bundle Open Source LicensingUse when selecting, using, or distributing open-source software and understanding license obligations. Covers permissive vs copyleft licenses, license compatibility, compliance obligations, and SCA tools for license auditing. USE FOR: open-source licenses, MIT, Apache, GPL, LGPL, MPL, BSD, copyleft, permissive, license compatibility, OSS compliance, SBOM license auditing, contributor license agreements, dual licensing DO NOT USE FOR: IP ownership questions (use intellectual-property), creating custom licenses (consult legal counsel), software patent analysis (use intellectual-property)
567 -
majiayu000 Bundle Pentest Vuln AnalyzerCorrelate scanner results with CVE and exploit intelligence and prioritize by CVSS and exploitability.
567 -
majiayu000 Bundle Pmtl Verify Auth FlowPMTL_VN auth verification skill. Use when touching register, login, logout, forgot-password, reset-password, profile, session cookies, proxy auth guards, or OAuth callbacks so auth behavior is verified instead of assumed.
567 -
majiayu000 Bundle Privacy Preserving MlUse when implementing differential privacy, PII detection, federated learning, secure aggregation, or ensuring ML systems comply with GDPR/CCPA/HIPAA.
567 -
majiayu000 Bundle QA Scenario AuthoringCreate well-formed quality attribute scenarios with measurable response criteria
567 -
majiayu000 Bundle Secrets Vault ManagerHandle SOPS + Age secrets for ONE_SHOT projects. Manages encrypted secrets, decryption, and secret rotation. Use when user mentions 'secrets', 'API keys', 'environment variables', '.env', or 'SOPS'.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include ce-serialization-audit, localsetup-pr-reviewer, maven-dependency-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.