Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Supabase Audit AuthenticatedCreate a test user (with explicit permission) to audit what authenticated users can access vs anonymous users. Detects IDOR, cross-user access, and privilege escalation.
567 -
majiayu000 Bundle Temporal Workflow GuidelinesComprehensive guide for developing Temporal.io workflows and activities in the A4C-AppSuite. Covers Workflow-First architecture, deterministic workflow design, event-driven activities, saga compensation patterns, CQRS integration, and testing strategies for durable workflow orchestration in healthcare compliance contexts (HIPAA audit trails).
567 -
majiayu000 Bundle Tools Manage Web PermissionsAnalyze and consolidate WebFetch domain permissions across projects with security research and validation
567 -
majiayu000 Bundle Agentuity CLI Auth Ssh AddAdd an SSH public key to your account (reads from file or stdin). Requires authentication. Use for managing authentication credentials
567 -
majiayu000 Bundle Claude Hook AuthoringCreates event hooks for Claude Code automation with proper configuration, matchers, input/output handling, and security best practices. Covers all 9 hook types (PreToolUse, PostToolUse, UserPromptSubmit, Notification, Stop, SubagentStop, PreCompact, SessionStart, SessionEnd). Use when building automation, creating hooks, setting up event handlers, or when users mention hooks, automation, event handlers, or tool interception.
567 -
majiayu000 Bundle Environment Isolation環境分離とアクセス制御スキル。開発・ステージング・本番環境の厳格な分離、 環境間Secret共有の防止、最小権限原則の徹底を提供します。 Anchors: • Building Secure and Reliable Systems / 適用: Defense in Depth原則 / 目的: 多層防御設計 • The Twelve-Factor App / 適用: Config要素とコードの分離 / 目的: 環境変数による設定管理 • Railway Secret Management / 適用: 環境グループによるSecret分離 / 目的: 環境別Secretストア Trigger: Use when designing environment isolation strategy, managing secrets across dev/staging/prod environments, implementing access control policies, preventing cross-environment data contamination, or validating environment separation compliance. environment isolation, secret management, access control, Railway secrets, GitHub secrets, security boundaries
567 -
majiayu000 Bundle Secure Workflow GuideGuide you through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformance/token integration), generates visual security diagrams, helps document security properties for fuzzing/verification, and reviews manual security areas. (project, gitignored)
567 -
majiayu000 Bundle Improve Translate GuidePropagate updated EN guide content to all locales using parallel translation. Requires EN audit to be clean first.
567 -
majiayu000 Bundle Librarian Vault ManagerKnowledge steward for Johnny Decimal/Zettelkasten Obsidian vaults. Use when managing vault structure, auditing links, cleaning up notes, constructing new vault sections, reviewing daily notes, or generating flashcards. Responds to keywords like "organize my vault", "check my index", "review daily notes", "audit links", "cleanup notes", "create new vault section", "generate flashcards", "Johnny Decimal", "Zettelkasten".
567 -
majiayu000 Bundle Living Design DocumentsCreate and maintain structured design documentation that drives development. Use for new projects, design decisions, growing complexity, or when audit is due. Triggers: "design docs", "LDD", "core decisions", "taxonomy", "parked decisions".
567 -
majiayu000 Bundle 810 Regulations Eu Mifid IiUse when reviewing Java enterprise evidence for MiFID II investment services, investment activities, client classification, suitability, appropriateness, order-handling evidence, best-execution evidence, algorithmic-trading governance evidence, market-access governance evidence, transaction evidence, record keeping, monitoring, or compliance-owner handoff. This should trigger for requests such as Review a Java investment-service platform for MiFID II evidence; Assess suitability, appropriateness, order-handling evidence, or best-execution evidence; Document audit, monitoring, or clock-synchronisation gaps for algorithmic-trading governance; Assess investment-service engineering evidence before production release. Part of Plinth Toolkit
567 -
majiayu000 Bundle Kata Plan Milestone GapsCreate phases to close all gaps identified by milestone audit. Triggers include "plan milestone gaps", "plan gaps".
567 -
majiayu000 Bundle Review RRun the R code review protocol on R scripts. Checks code quality, reproducibility, domain correctness, and professional standards. Produces a report without editing files.
567 -
majiayu000 Bundle Spec Driven W3 ComplianceW3 compliance scanning with structural anti-skip enforcement. Detects auto-skill chaining violations (skills/commands that auto-invoke other skills without user approval) using the Execute-Verify-Record pattern at every step. Designed to prevent token optimization bias through lean orchestration and binary CLI gate enforcement. Scans subagent files, skill files, and command files for unauthorized Skill() invocations. Use when auditing W3 compliance, checking for auto-skill chaining violations, or preparing for release validation. Always use this skill when the user runs /audit-w3 or mentions W3 compliance, skill chaining, or auto-invocation scanning.
567 -
majiayu000 Bundle Analyzing Modbus Traffic<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Attack Tree ConstructionBuild comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.
567 -
majiayu000 Bundle Ce Regulatory ComplianceMap calibrated_explanations capabilities to EU AI Act, GDPR, AI Liability Directive, and Product Liability Directive obligations for compliance documentation and presentation materials.
567 -
majiayu000 Bundle Detecting Email Spoofing<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Detecting Mobile Malware<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Iso 27001 Internal AuditRun an ISO 27001 internal audit. Walk through controls by domain, identify gaps, collect evidence, and generate findings with corrective action recommendations. Uses NIST SP 800-53 (public domain) as canonical reference. Use when user says "run internal audit," "ISO 27001 audit," "control assessment," "audit findings," or "ISMS assessment."
567 -
majiayu000 Bundle Prisma RbacAdd, repair, and verify Prisma-backed RBAC (User, Group, Role, Permission) in existing NestJS backends with JWT access tokens, refresh-token session rotation, permission guards, and CRUD/assignment APIs. Use when users ask to implement or fix role-based access control, auth session rotation, permission-protected endpoints, or Prisma auth/authorization wiring.
567 -
majiayu000 Bundle Oc Authentication HelperHelper skill to retrieve OAuth tokens from the correct OpenShift cluster context when multiple clusters are configured
567 -
majiayu000 Bundle Opencrow Network ToolboxUse the Anaconda `ctf` environment and installed network tooling for packet- and protocol-level CTF tasks. Use when Codex needs `scapy`, `tshark`, `tcpdump`, `nmap`, `nc`, or `socat` for packet work, capture analysis, or service triage.
567 -
majiayu000 Bundle Pentest Active DirectoryAssess Active Directory identity attack paths including roasting, relay, and delegation abuse.
567 -
majiayu000 Bundle Pentest Lateral MovementAssess lateral movement and pivot paths across authorized internal trust boundaries.
567 -
majiayu000 Bundle Pentest Web App AttackerAssess web applications against OWASP WSTG and OWASP Top 10 with reproducible evidence capture.
567 -
majiayu000 Bundle Performing Dll Hijacking<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Performing Ssl Tls Audit<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Testing GRAPHQL Security<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Uk Legal Contract ReviewReview contracts against your organisation's negotiation playbook under English law (England & Wales). Flags deviations, classifies severity, generates redline suggestions with UK-specific legal tests and terminology. Use when reviewing vendor contracts, customer agreements, or any commercial agreement requiring clause-by-clause analysis.
567 -
majiayu000 Bundle Uk Legal Risk AssessmentAssess and classify legal risks under English law (England & Wales) using a severity-by-likelihood framework with escalation criteria. References UK regulatory bodies (ICO, FCA, TPR, SFO), legal professional privilege, Companies Act duties, and UK-specific enforcement landscape. Use when evaluating contract risk, deal exposure, regulatory matters, or determining whether a matter needs senior counsel or external solicitor review.
567 -
majiayu000 Bundle Capi Test Naming VerifierThis skill should be used when the user asks to "verify C API test naming", "check test naming convention", "validate test names", "C API test naming compliance", "test naming verification", "ensure test naming consistency", "audit test names", "review test naming", or mentions verifying that C API unit test names follow the standardized naming convention methodNameTestScenario.
567 -
majiayu000 Bundle Conversion Spec GeneratorGenerates detailed actionable conversion specifications from audit results for architectural migration
567 -
majiayu000 Bundle Architecture Paradigm Cqrs EsCQRS and Event Sourcing for auditability, read/write separation, and temporal queries.Triggers: CQRS, event sourcing, audit trail, temporal queriesUse when: read/write scaling differs or audit trail r
567 -
majiayu000 Bundle Auditing Pre Release SecurityAudits security and supply-chain risk between two git refs, 预发布安全审计
567 -
majiayu000 Bundle Cloudflare Security HardeningUse this skill whenever the user wants to harden security for Cloudflare Workers/Pages APIs (e.g. Hono + TypeScript), including WAF-style protections, rate limiting, IP restrictions, secrets handling, and secure headers.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include supabase-audit-authenticated, Temporal Workflow Guidelines, tools-manage-web-permissions. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.