Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Shopify Speed OptimizationStore speed audit — lazy loading, image compression, app bloat removal, theme code optimization
567 -
majiayu000 Bundle Conducting Social Engineering<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Grey Haven Security PracticesGrey Haven's security best practices - input validation, output sanitization, multi-tenant RLS, secret management with Doppler, rate limiting, OWASP Top 10 for TanStack/FastAPI stack. Use when implementing security-critical features.
567 -
majiayu000 Bundle Implementing Secret Detection<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Nextauth JS AuthenticationImplement authentication with NextAuth.js v5, Google OAuth, credentials provider, session management, and protected routes. Apply when building auth flows, protecting routes, managing sessions, or implementing RBAC.
567 -
majiayu000 Bundle Pentest Remediation ValidatorRetest remediated findings, detect regressions, and generate remediation status and certification artifacts.
567 -
majiayu000 Bundle Performing Fedramp Assessment<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Rails Authorization CancancanAuthorization and permissions management for Ruby on Rails applications using CanCanCan. Use when: (1) Implementing role-based access control (RBAC), (2) Defining user permissions and abilities, (3) Restricting resource access in controllers, (4) Filtering queries based on user permissions, (5) Hiding/showing UI elements based on authorization, (6) Testing authorization logic, (7) Managing admin vs user vs guest permissions, (8) Implementing attribute-based access control
567 -
majiayu000 Bundle Security Configuration Reviewセキュリティ関連設定のレビュー、構成監査、セキュリティベースライン確認を統一的に実施するスキル。脅威モデリングに基づいた設定評価とベストプラクティスの適用を通じて、アプリケーションのセキュリティ態勢を向上させます。 Anchors: • 『Web Application Security』(Andrew Hoffman) / 適用: セキュリティ設定監査 / 目的: セキュリティ態勢の向上 Trigger: セキュリティ設定レビュー、構成監査、セキュリティベースライン確認時に使用。セキュリティヘッダー設定、CORS設定、認証・認可の監査などの場面で自動選択対象。
567 -
majiayu000 Bundle Testing Payment Flow Security<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Memory Md ManagementProvides comprehensive memory file management capabilities including auditing, quality assessment, and targeted improvements for files such as CLAUDE.md. Use when user asks to check, audit, update, improve, fix, maintain, or validate project memory files. Also triggers for "project memory optimization", "CLAUDE.md quality check", "documentation review", or when a project memory file needs to be created from scratch. This skill scans memory files, evaluates quality against standardized criteria, outputs detailed quality reports with scores and recommendations, then makes targeted updates with user approval.
567 -
majiayu000 Bundle Checking Infrastructure ComplianceExecute use when you need to work with compliance checking. This skill provides compliance monitoring and validation with comprehensive guidance and automation. Trigger with phrases like "check compliance", "validate policies", or "audit compliance".
567 -
majiayu000 Bundle Repo Generating Validation ReportsGuidelines for generating validation/audit reports with UUID chains, progressive writing, and UTC+7 timestamps
567 -
majiayu000 Bundle Github Security Alert FixerSystematically analyzes and fixes GitHub CodeQL security alerts with proper documentation and testing
567 -
majiayu000 Bundle Parse Conversation TimelineTransform raw session logs into structured timeline JSON for protocol audit analysis
567 -
majiayu000 Bundle System Design InterrogationUse when planning system architecture to ensure nothing is missed. Provides structured questions covering scalability, security, data, and operational dimensions before implementation.
567 -
majiayu000 Bundle Github Publish Readiness CheckAudit a local repository before creating a new public GitHub remote
567 -
majiayu000 Bundle 504 Frameworks Micronaut SecurityUse when you need to design, review, or improve security in Micronaut applications — including micronaut-security authentication, @Secured and intercept-url-map rules, JWT/session strategies, SecurityService checks, CORS, CSRF awareness for browser apps, rejection handlers, and sensitive-data-safe logging. This should trigger for requests such as Add Micronaut security support; Review Micronaut security configuration; Improve API authorization in Micronaut; Add JWT security in Micronaut; Harden Micronaut route authorization rules. Part of cursor-rules-java project
567 -
majiayu000 Bundle API Key ManagerAPI key generation, rotation, and management system
567 -
majiayu000 Bundle Auth Keycloak Confidential ClientCreate confidential OAuth2 clients in Keycloak for server-to-service authentication
567 -
majiayu000 Bundle Building Threat Hunting Notebooks<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Bypassing Stack Canary Protection<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Performing Business Logic Testing<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Security HeadersVerify and configure HTTP security headers (CSP, HSTS, CORS, X-Frame-Options, etc). Checks current configuration and generates framework-specific fixes.
567 -
majiayu000 Bundle 808 Regulations Eu Digital Markets ActUse when reviewing, designing, or modifying Java enterprise systems that may support EU Digital Markets Act gatekeeper-platform concerns, core platform services, interoperability, business-user data access, consent-dependent data combination, ranking, self-preferencing, advertising transparency, or anti-circumvention controls. This should trigger for requests such as Review a Java platform for DMA controls; Design interoperability and business-user data access evidence; Add ranking, consent, preference, or anti-circumvention audit controls; Assess gatekeeper-platform engineering evidence before production release. Part of cursor-rules-java project
567 -
majiayu000 Bundle Audit Verify Definition Of DoneVerifies Definition of Done checks and generates a DoD report.
567 -
majiayu000 Bundle Refactoring 10 Security PrivacyUse when checking for data leaks, PII handling, and license risks in Python research code.
567 -
majiayu000 Bundle MagiMAGI System - 三機平行共識決策系統,參考新世紀福音戰士的 MAGI 超級電腦。三機(Claude Opus、Codex-CLI、Gemini)同時平行分析同一任務,各自提出觀點後進行投票共識。支援 brainstorming、架構審查、plan、review、security、test 等任務類型。
567 -
majiayu000 Bundle Dotnet Permission AuthorizationImplements permission-based authorization with custom attributes, policy providers, and authorization handlers. Provides granular access control beyond simple role-based authorization.
567 -
majiayu000 Bundle Analyzing Web Archive Intelligence<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Authentication Authorization ClerkImplement secure authentication and authorization using Clerk. Use this skill when you need to authenticate users, protect routes, check permissions, implement subscription-based access control, or integrate Clerk with your application. Triggers include "authentication", "auth", "authorization", "Clerk", "protect route", "check user", "sign in", "session", "permissions", "subscription access".
567 -
majiayu000 Bundle Building Incident Enrichment Tools<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Developing Windows Kernel Exploits<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Grey Haven Authentication PatternsGrey Haven's authentication patterns using better-auth - magic links, passkeys, OAuth providers, session management with Redis, JWT claims with tenant_id, and Doppler for auth secrets. Use when implementing authentication features.
567 -
majiayu000 Bundle Mtls ConfigurationConfigure mutual TLS (mTLS) for zero-trust service-to-service communication. Use when implementing zero-trust networking, certificate management, or securing internal service communication.
567 -
majiayu000 Bundle Grey Haven Code Quality AnalysisMulti-mode code quality analysis covering security reviews (OWASP Top 10), clarity refactoring (readability rules), and synthesis analysis (cross-file issues). Use when reviewing code for security vulnerabilities, improving code readability, conducting quality audits, pre-deployment checks, or when user mentions 'code quality', 'code review', 'security review', 'refactoring', 'code smell', 'OWASP', 'code clarity', or 'quality audit'.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include api-key-manager, conducting-social-engineering, grey-haven-security-practices. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.