Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Multi Tenant Safety CheckerEnsures tenant isolation at query and policy level using Row Level Security, automated testing, and security audits. Prevents data leakage between tenants. Use for "multi-tenancy", "tenant isolation", "RLS", or "data security".
567 -
majiayu000 Bundle Political Scientist AnalystAnalyzes events through political science lens using IR theory (Realism, Liberalism, Constructivism), comparative politics, institutional analysis, and power dynamics. Provides insights on governance, security, regime change, international cooperation, and policy outcomes. Use when: Political events, international crises, elections, regime transitions, policy changes, conflicts. Evaluates: Power distributions, institutional effects, actor interests, strategic interactions, norms.
567 -
majiayu000 Bundle Quality Attributes TaxonomyThe "-ilities" framework for non-functional requirements. Use when defining NFRs, evaluating architecture trade-offs, or ensuring quality attributes are addressed in system design. Covers scalability, reliability, availability, performance, security, maintainability, and more.
567 -
majiayu000 Bundle Rust Production ReliabilityProduction reliability patterns including circuit breakers with exponential backoff, graceful shutdown management with signal handling, retry logic with jitter, rate limiting with token bucket, and security best practices. Use when hardening services for production, implementing fault tolerance, adding retry logic, or ensuring graceful degradation.
567 -
majiayu000 Bundle Scanning Container SecurityExecute use when you need to work with security and compliance. This skill provides security scanning and vulnerability detection with comprehensive guidance and automation. Trigger with phrases like "scan for vulnerabilities", "implement security controls", or "audit security".
567 -
majiayu000 Bundle Security Pr Checklist SkillCreates repeatable security review checklist for PRs with required checks, common pitfalls, and automated gating. Use for "security review", "PR checklist", "code review", or "security gates".
567 -
majiayu000 Bundle Skill Reviewer And EnhancerThis skill should be used when reviewing, auditing, or improving existing Claude Code skills to ensure they follow Anthropic best practices, have proper structure, use current domain-specific patterns, and include all necessary resources. It analyzes skill quality, identifies gaps, suggests improvements, and can automatically enhance skills with updated best practices. Trigger terms include review skill, audit skill, improve skill, enhance skill, update skill, check skill quality, skill best practices, fix skill, optimize skill, validate skill structure.
567 -
majiayu000 Bundle Supabase Audit Buckets ListList all storage buckets and their configuration to identify the storage attack surface.
567 -
majiayu000 Bundle Superpower Kryptonite AuditIdentify your core leadership strengths and reframe your perceived weaknesses using story-driven analysis. Use this when you feel stuck in your career, struggle with imposter syndrome, or need to draft a personal "README" to improve team collaboration.
567 -
majiayu000 Bundle Wheels Controller GeneratorGenerate Wheels MVC controllers with CRUD actions, filters, parameter verification, and proper rendering. Use when creating or modifying controllers, adding actions, implementing filters for authentication/authorization, handling form submissions, or rendering views/JSON. Ensures proper Wheels conventions and prevents common controller errors.
567 -
majiayu000 Bundle Vertical Site ConventionsCompose pages and sites that read as their vertical: ecommerce-catalog storefronts that look like storefronts, hospitality-food sites that look like restaurants, b2b-manufacturer sites that look industrial. Use this skill whenever the user wants to build a site that looks like the vertical it serves, fix a build that reads as generic or off-vertical, build to an experience bar produced by competitor-experience-audit, or compose pages with the merchandising, density, and layout conventions a credible site in the category is expected to carry. Triggers on vertical conventions, storefront layout, ecommerce layout, retail conventions, merchandising layout, category page composition, site composition, build to the experience bar, make it look like the vertical, off-vertical, looks generic, build conventions for a vertical, site grammar. Also triggers when a build that is technically clean reads wrong for its category, and the cause is composition, not visual taste.
567 -
majiayu000 Bundle Go Security PatternsThis skill should be used when the user asks about "gosec", "G115", "G404", "integer overflow", "weak random", "crypto/rand", "security lint", "hardcoded credentials", or needs guidance on fixing Go security vulnerabilities. Provides patterns for common security anti-patterns.
567 -
majiayu000 Bundle Software EngineeringEngineering judgment, decision-making principles, and code quality standards. Use when making architectural choices, evaluating trade-offs, determining implementation approaches, assessing code quality, or balancing speed vs thoroughness. Provides foundational senior engineer mindset covering when to proceed vs ask, when to refactor, security awareness, and avoiding over-engineering.
567 -
majiayu000 Bundle Audit Protocol EfficiencyAnalyze session execution patterns for efficiency improvements (execution time, token usage, quality)
567 -
majiayu000 Bundle Documentation StrategyDesign and run a documentation system for a team or product. Use this skill when planning what to document, choosing a documentation tool, organizing existing docs, fixing stale documentation, designing a maintenance cadence, or scoping technical writing work. Triggers on documentation, docs, tech writing, knowledge base, wiki, runbook, README, internal docs, doc audit, doc maintenance, stale docs, where do we document. Also triggers when the team is repeatedly answering the same questions or when onboarding takes too long.
567 -
majiayu000 Bundle Enterprise AI PatternsProduction-grade AI architecture patterns for enterprise - security, governance, scalability, and operational excellence
567 -
majiayu000 Bundle Investigation CreationCreate investigations from security events, detections, or LCQL queries. Performs HOLISTIC investigations - not just process trees, but initial access hunting, org-wide scope assessment, lateral movement detection, and full host context. Builds Investigation Hive records documenting findings with events, detections, entities, and analyst notes. Use for incident investigation, threat hunting, alert triage, or building SOC working reports.
567 -
majiayu000 Bundle Gesellschafts ComplianceGesellschafts-Compliance-Tracker – Initialisierung, Fälligkeitsbericht, Status-Update, Gesundheits-Audit, Export. Pflegt eine compliance-tracker.yaml aus der Gesellschaftstabelle, berechnet Einreichungsfristen nach Rechtsträger und Rechtsordnung und zeigt auf, was in den nächsten 30/60/90 Tagen fällig ist. Trigger: „Gesellschafts-Compliance", „Einreichungsfristen", „Bilanzpublizität", „Transparenzregister", „Jahresabschluss einreichen", „was ist fällig".
567 -
majiayu000 Bundle Regulatory Audit GeneratorBuilds compliance checklists for business scenarios involving GDPR, PIPL, or advertising/data laws. Outputs a structured checklist with check items, legal basis, risk levels, and actionable recommendations. Triggered by requests like "run a compliance check," "GDPR/PIPL compliance," "pre-launch review," "privacy impact assessment (PIA/DPIA)," or asking if a feature is compliant.
567 -
majiayu000 Bundle 15 04 Review To TicketsConvert findings from any review, audit, or analysis into individual tk tickets with proper priority and tagging.
567 -
majiayu000 Bundle Cowork Health CheckAudits your Cowork setup across five categories, scores each one, and gives you a prioritized improvement plan. For reviewing how well you are using Cowork, when optimizing your workspace configuration, or during a quarterly productivity review. Use when the user says "health check", "am I using cowork right", "optimize my setup", "cowork audit", "what am I missing", "is my setup good", or "how do I get more out of cowork".
567 -
majiayu000 Bundle Ln 512 Tech Debt CleanerAuto-fixes low-risk tech debt (unused imports, dead code, commented-out code) with >=90% confidence. Use when audit findings need safe automated cleanup.
567 -
majiayu000 Bundle Review Static LintignoreAudit all lint-ignore suppressions for appropriateness and overuse
567 -
majiayu000 Bundle Risks And ConsiderationsUse when reviewing planning documents for security, performance, and scalability risks.
567 -
majiayu000 Bundle Dotnet Rate LimitingImplements ASP.NET Core rate limiting middleware for API protection. Covers fixed window, sliding window, token bucket, and concurrency limiters with custom policies.
567 -
majiayu000 Bundle Adversarial Code ReviewReview code through hostile perspectives to find bugs, security issues, and unintended consequences the author missed. Use when reviewing PRs, auditing codebases, or before critical deployments.
567 -
majiayu000 Bundle AI Safety And AlignmentImplement safety guardrails, red-teaming, and alignment evaluation for AI systems
567 -
majiayu000 Bundle Amazon Returns RecoveryUse when the user wants to audit Amazon returns or Amazon-billed subscriptions, mentions a restocking fee, short or denied refund, forgotten Prime Video Channel, Audible, Kindle Unlimited, or Prime charge, or asks whether Amazon still owes or bills them. Read order, refund, and subscription evidence first; report findings and require confirmation before chat, cancellation, or dispute. The documented cases recovered $448.31, but never promise recovery. Requires an authenticated Claude in Chrome session. NOT FOR: bank chargebacks, marketplace A-to-z seller claims, price-protection claims, or subscriptions billed outside Amazon — use subscription-recovery for those.
567 -
majiayu000 Bundle Ark Vulnerability FixerCVE research and security patch workflow for Ark. Provides CVE API integration, mitigation strategies, and security-focused PR templates. Works with research, analysis, and setup skills for comprehensive vulnerability fixing.
567 -
majiayu000 Bundle Audit Defense StandardsAudit the codebase against defense standards derived from historical bug patterns. Standards accumulate over time as new patterns are discovered via audit-bugs and design-guards. Use when user says "audit defenses", "audit defense standards", "check defenses", or "defense audit".
567 -
majiayu000 Bundle Authentication PatternsAuthentication patterns for external services: API keys, OAuth, token management, verification. Triggers: authentication, API keys, OAuth, token management, credentials Use when: integrating external services or implementing authentication flows
567 -
majiayu000 Bundle Building C2 With Sliver<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Clawdbot Self Security AuditPerform a comprehensive read-only security audit of Clawdbot's own configuration. This is a knowledge-based skill that teaches Clawdbot to identify hardening opportunities and generate reports. Use when user asks to "run security check", "audit clawdbot", "check security hardening", or "what vulnerabilities do I have". This skill only READS configuration and generates reports—it never modifies settings or executes fixes automatically. Designed to be extensible—new checks can be added by updating this skill's knowledge.
567 -
majiayu000 Bundle Clawsec Clawhub CheckerClawHub reputation checker for ClawSec suite. Enhances guarded skill installer with VirusTotal Code Insight reputation scores and additional safety checks.
567 -
majiayu000 Bundle Cryptographic Practices暗号化・ハッシュ・CSPRNG・鍵管理の実装を安全に進めるためのスキル。 要件整理から設計、実装、監査までの一連フローを提供する。 Anchors: • Applied Cryptography / 適用: アルゴリズム選定と強度判断 / 目的: 標準準拠の基礎固め • Web Application Security / 適用: 脅威モデリング / 目的: 実装リスクの明確化 • NIST SP 800-57 / 適用: 鍵管理 / 目的: ライフサイクル設計 Trigger: Use when implementing cryptographic functions, selecting algorithms, generating secure random values, managing encryption keys, or auditing crypto implementations. cryptographic practices, crypto implementation, key management, csprng, algorithm selection
567 -
majiayu000 Bundle Deploying Osquery Fleet<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include multi-tenant-safety-checker, political-scientist-analyst, quality-attributes-taxonomy. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.