Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Top 100 Web Vulnerabilities ReferenceThis skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about injection attacks", "review access control weaknesses", "analyze API security issues", "assess security misconfigurations", "understand client-side vulnerabilities", "examine mobile and IoT security flaws", or "reference the OWASP-aligned vulnerability taxonomy". Use this skill to provide comprehensive vulnerability definitions, root causes, impacts, and mitigation strategies across all major web security categories.
567 -
majiayu000 Bundle Add Admin EndpointsAdd admin API endpoints with proper authorization, audit logging, and rate limiting (project)
567 -
majiayu000 Bundle PlanetscaleOperate MySQL-compatible databases on PlanetScale with branching workflows, safe migrations, and production rollouts.
567 -
majiayu000 Bundle Django DeveloperExpert Django developer mastering Django 4+ with modern Python practices. Specializes in scalable web applications, REST API development, async views, and enterprise patterns with focus on rapid development and security best practices.
567 -
majiayu000 Bundle PocketbaseComprehensive PocketBase development and deployment skill providing setup guides, schema templates, security patterns, API examples, data management scripts, and real-time integration patterns for building backend services with PocketBase.
567 -
majiayu000 Bundle Authentication LogicGuide to using Better Auth for client and server-side authentication.
567 -
majiayu000 Bundle Delon Auth Authentication AuthorizationImplement authentication and authorization using @delon/auth. Use this skill when adding login/logout flows, JWT token management, role-based access control (RBAC), route guards, HTTP interceptors, and session management. Integrates with Firebase Auth and custom permission systems. Ensures secure token storage, automatic token refresh, and consistent authorization checks across components and services.
567 -
majiayu000 Bundle Dependabot SecurityFix Dependabot security vulnerabilities in Java/Gradle projects using severity-based processing, dependency substitution strategies, and dependency graph verification. Use when Dependabot alerts need resolution with proper CI validation.
567 -
majiayu000 Bundle JWT AuthenticationJWT authentication implementation patterns. Use when implementing login, registration, token refresh, password reset, or any authentication/authorization system.
567 -
majiayu000 Bundle Performing Static Analysis Integration<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Security EngineeringApplication security and infrastructure security expert. Use when reviewing code for vulnerabilities, implementing authentication/authorization, securing APIs, hardening infrastructure, threat modeling, implementing encryption, or conducting security audits. Covers OWASP Top 10, secure coding, DevSecOps, and compliance.
567 -
majiayu000 Bundle Variant AnalysisFind similar vulnerabilities across a codebase after discovering one instance. Uses pattern matching, AST search, Semgrep/CodeQL queries, and manual tracing to propagate findings. Adapted from Trail of Bits. Use after finding a bug to check if the same pattern exists elsewhere.
567 -
majiayu000 Bundle When Protecting Physics Ip Use TrackerWhen Protecting Physics Ip Use Tracker
567 -
majiayu000 Bundle Legal Aurigraph Dlt Corp Aurigraph DExpertise Domain: Incident Response, Data Breach Notification, Cybersecurity Compliance, Blockchain Security, Incident Forensics
567 -
majiayu000 Bundle Shodan Reconnaissance And PentestingThis skill should be used when the user asks to "search for exposed devices on the internet," "perform Shodan reconnaissance," "find vulnerable services using Shodan," "scan IP ranges with Shodan," or "discover IoT devices and open ports." It provides comprehensive guidance for using Shodan's search engine, CLI, and API for penetration testing reconnaissance.
567 -
majiayu000 Bundle Typescript Nodenext Apps Maintenancedescription: "Audit and repair TypeScript relative import specifiers for NodeNext/Node16 projects by enforcing runtime-valid emitted extensions (.js, .mjs, .cjs). Use when module or moduleResolution is nodenext|node16, when Node ESM/CJS runs fail with extension-related import errors, or when standardizing import specifiers across src and test files."
567 -
majiayu000 Bundle Wow Assessing Criticality ConfidenceUniversal classification system for checker and fixer agents using orthogonal criticality (CRITICAL/HIGH/MEDIUM/LOW importance) and confidence (HIGH/MEDIUM/FALSE_POSITIVE certainty) dimensions. Covers priority matrix (P0-P4), execution order, dual-label pattern for verification status, standardized report format, and domain-specific examples. Essential for implementing checker/fixer agents and processing audit reports
567 -
majiayu000 Bundle Managing Tickets And Tasks In PlaneMulti-workspace Plane sprint board management with intelligent automation, ticket creation, and BMAD workflow integration. Use this skill when: - Creating tickets from BMAD stories, task descriptions, or audit findings - Auditing board organization (ticket clustering, label optimization, status bottlenecks) - Selecting the next optimal ticket to work on (priority scoring algorithm) - Promoting completed tickets to production and generating changelogs - Managing sprint workflows with status tracking and WIP limits - Working with multiple Plane workspaces (auto-detects from git remote or directory) Triggers: "create ticket", "board audit", "what should I work on", "next ticket", "promote to production", "changelog", "sprint status", "WIP limit", plane ticket operations
567 -
majiayu000 Bundle Codebase Quality Code QualityCode quality analysis including linting, style, type safety, and refactoring suggestions. Use when checking code style, running linters, analyzing complexity, or suggesting refactoring. Invoked by codebase-quality:full-audit after security passes. Triggers on lint, code style, type check, refactor, code quality, complexity.
567 -
majiayu000 Bundle 805 Regulations Eu Cyber Resilience ActUse when reviewing, designing, or modifying Java enterprise products, services, libraries, agents, plugins, connected components, or platform modules that may qualify as products with digital elements and need EU Cyber Resilience Act secure-by-design, vulnerability handling, security update, SBOM, product documentation, or release-readiness controls. Part of cursor-rules-java project
567 -
majiayu000 Bundle Governance ComplianceThe "Bouncer" of Epsilon Prime. Enforces the Constitution (GEMINI.md), manages risk classification, and ensures all high-risk operations (Legal, Credit, Finance) adhere to US-WA jurisdiction.
567 -
majiayu000 Bundle Credit Repair Wa Fcra CroaHigh-risk statutory specialist for US-WA credit repair. Enforces FCRA (Fair Credit Reporting Act) and CROA (Credit Repair Organizations Act) compliance. Operates strictly on Tier 1 legal statutes.
567 -
majiayu000 Bundle Emergency LockdownSystem-wide safety kill-switch. Invoked during critical security breaches, high-risk legal errors, or catastrophic system failures to preserve integrity and data safety.
567 -
majiayu000 Bundle Security Williaby Image Preprocessing DSecurity validation, vulnerability scanning, and compliance checking.
567 -
majiayu000 Bundle Testing Mass Assignment Vulnerabilities<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle API Testing PatternsAPI-specific testing patterns covering functional, security, performance, contract, and integration dimensions. Use when writing API tests, reviewing API test coverage, or assessing API test quality. Do NOT use for API design decisions -- use api-design-patterns instead. Do NOT use for general testing principles -- use testing-principles instead.
567 -
majiayu000 Bundle Ln 72 Current Architecture DocumenterDocuments implemented current-state architecture from repository evidence. Use for onboarding or migration baselines; not for target design, audit verdicts, or code changes.
567 -
majiayu000 Bundle Ln 830 Code Modernization CoordinatorModernizes codebase via OSS replacement and bundle optimization. Use when acting on audit findings to reduce custom code.
567 -
majiayu000 Bundle Sf ApexGenerates and reviews Salesforce Apex code with 2025 best practices and 150-point scoring. Use when writing Apex classes, triggers, test classes, batch jobs, or reviewing existing Apex code for bulkification, security, and SOLID principles.
567 -
majiayu000 Bundle Service Mesh ImplementationImplement service mesh (Istio, Linkerd) for service-to-service communication, traffic management, security, and observability.
567 -
majiayu000 Bundle Audit CodeRun a single-session code review audit on the codebase
567 -
majiayu000 Bundle Claude Skills Nextauth Patterns Skill MdNextAuth.js v5の設定とカスタマイズパターン。 プロバイダー設定、アダプター統合、セッション戦略、 コールバックカスタマイズ、型安全性の確保を提供。 📖 参照書籍: - 『Web Application Security』(Andrew Hoffman): 脅威モデリング 📚 リソース参照: - `resources/Level1_basics.md`: レベル1の基礎ガイド - `resources/Level2_intermediate.md`: レベル2の実務ガイド - `resources/Level3_advanced.md`: レベル3の応用ガイド - `resources/Level4_expert.md`: レベル4の専門ガイド - `resources/legacy-skill.md`: 旧SKILL.mdの全文 - `resources/provider-configurations.md`: NextAuth.js Provider Configurations - `resources/session-callbacks-guide.md`: NextAuth.js Session Callbacks Guide - `scripts/log_usage.mjs`: 使用記録・自動評価スクリプト - `scripts/validate-nextauth-config.mjs`: NextAuth.js設定ファイルの妥当性検証とプロバイダー設定・コールバック実装の検査スクリプト - `scripts/validate-skill.mjs`: スキル構造検証スクリプト - `templates/nextauth-config-template.ts`: Google/GitHub OAuth統合・Drizzleアダプター・JWT/Databaseセッション戦略を含むauth.ts設定テンプレート Use proactively when handling nextauth patterns tasks.
567 -
majiayu000 Bundle Generate JWT Secret EnvGenerate, repair, or verify a cryptographically secure JWT_SECRET in .env for Node.js and NestJS projects when code under src/ references JWT_SECRET and the active .env value is missing, empty, or set to change-me-in-production. Use when fixing JWT auth startup failures, hardening environment configuration, standardizing .env secrets, or repairing placeholder JWT_SECRET values.
567 -
majiayu000 Bundle Zero TrustIdentify and remediate Zero Trust security gaps in Cloudflare deployments. Use this skill when auditing Access policies, checking staging/dev environment protection, detecting unprotected admin routes, or implementing mTLS and service tokens for machine-to-machine auth.
567 -
majiayu000 Bundle Business Logic Flaws AI Generated CodeUnderstand business logic vulnerabilities in AI code including race conditions, integer overflow, and calculation errors that pass functional tests but create security holes. Use this skill when you need to learn about race conditions in AI code, understand integer overflow vulnerabilities, recognize business logic security flaws, or identify calculation errors. Triggers include "race conditions", "business logic vulnerabilities", "integer overflow", "race condition AI", "flash sale security", "concurrent access", "negative totals", "calculation errors".
567 -
majiayu000 Bundle Validate PlanRun Phase 2 validation with Cursor and Gemini in parallel.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include Top 100 Web Vulnerabilities Reference, add-admin-endpoints, django-developer. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.