Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Update Readme 2Autonomously audit the entire repository and update the main README with comprehensive, accurate documentation of the current codebase
567 -
majiayu000 Bundle Auth Bypass 2Hunt authentication and authorization bypasses — forced browsing, path traversal in auth, header injection, JWT downgrade, OAuth state confusion, role manipulation. Use when an endpoint returns 401/403 but appears reachable.
567 -
majiayu000 Bundle Code Reviewing 2高品質なコードレビューを実施するスキル。セキュリティ、パフォーマンス、保守性、 アーキテクチャの観点から包括的にレビューし、Must/Should/Nice to haveで 優先順位付けした建設的なフィードバックを提供します。
567 -
majiayu000 Bundle Codebase Audit 2Domain-parameterized codebase auditing (security, UX, performance, API, copy, CLI). Use when auditing code, assessing quality, finding issues, or pre-launch review.
567 -
majiayu000 Bundle Soc2 Readiness 2Assess SOC 2 Type II readiness. Map Trust Services Criteria to controls, identify gaps, and build a remediation plan. Uses NIST SP 800-53 (public domain) as canonical reference with SOC 2 criterion cross-mapping. Use when user says "SOC 2 readiness," "SOC 2 preparation," "SOC 2 gap analysis," or "prepare for SOC 2 audit."
567 -
majiayu000 Bundle Threat Modeler 2STRIDE threat modeling and privacy impact assessment to generate security/privacy requirements. Use before requirement-architect to shift security left.
567 -
majiayu000 Bundle Gsd Audit Milestone 2Spawn integration checker to validate cross-phase integration and E2E flows
567 -
majiayu000 Bundle Security Baseline 2Security requirements, threats, and controls that apply across this system.
567 -
majiayu000 Bundle Analyze Code 2Intelligence-first code analysis for bugs, architecture, performance, and security. Use proactively when investigating code issues, tracing dependencies, or understanding system behavior. MUST query project-intel.mjs before reading files.
567 -
majiayu000 Bundle Adversarial Review 2Adversarially review something just built — presume it is broken and find where. Use after implementing a feature, finishing a build, or before shipping, or whenever ATLAS or Boss wants a hostile second opinion on a diff, a running app, or a whole codebase. Spawns clean-context reviewers with opposing lenses (correctness, security, empty-world) and reproduces every finding by running the target before believing it. Distinct from /code-review, which statically reads a diff and never runs the app.
567 -
majiayu000 Bundle Writing Guidelines 2This skill should be used when the user asks to "review writing", "check documentation style", "audit interface copy", or "apply writing guidelines".
567 -
majiayu000 Bundle Sonarcloud Tools 2Executes SonarCloud API operations for quality gates, issues, metrics, analysis history, and security hotspots. Use when checking code quality, inspecting bugs/vulnerabilities, retrieving coverage/complexity metrics, or viewing project security status.
567 -
majiayu000 Bundle Review Security 2보안 관점에서 코드를 검토합니다. OWASP Top 10, credential 노출, injection 공격 등을 체크합니다.
567 -
majiayu000 Bundle Security Expert 2OWASPの基本を前提に、デフォルト安全(入力検証/認可/秘密情報/監査ログ/SSR/CSRF等)を落とさずに設計・実装・レビューする。脅威と攻撃面を洗い出し、最小権限と安全な失敗で守るために使う。
567 -
majiayu000 Bundle Security Review 2セキュリティ脆弱性を自動検出する。認証情報のハードコード、コマンドインジェクション、危険なシェル構文などをチェック。
567 -
majiayu000 Bundle Threat Modeling 2Use when implementing auth, file uploads, payments, or external APIs. Applies STRIDE framework systematically. Triggers: "authentication", "file upload", "payment", "multi-tenant", "external API". If
567 -
majiayu000 Bundle Backend Reviewer 3Senior Backend Code Reviewer with 12+ years Java experience. Use when reviewing Java/Spring code, checking code quality and style, identifying code smells and anti-patterns, verifying security practices, ensuring test coverage, or configuring static analysis tools (Checkstyle, SpotBugs, SonarQube).
567 -
majiayu000 Bundle Security Architect 2Comprehensive security architecture combining threat modeling, security-first design, secure coding review, and compliance validation. Consolidated from threat-modeling, security-first-design, secure-coding-review, and compliance-validator.
567 -
majiayu000 Bundle Code Auditing 2Provides code auditing methodology, checklists, and best practices. Use when user asks to "audit code", "find technical debt", "security review", "identify dead code", "analyze code quality", or "check best practices".
567 -
majiayu000 Bundle Skill Factory 3Research-backed skill creation workflow with automated firecrawl research gathering, multi-tier validation, and comprehensive auditing. Use when "create skills with research automation", "build research-backed skills", "validate skills end-to-end", "automate skill research and creation", needs 8-phase workflow from research through final audit, wants firecrawl-powered research combined with validation, or requires quality-assured skill creation following Anthropic specifications for Claude Code.
567 -
majiayu000 Bundle Weaver 2Weaves custom Skills for Claude following official best practices including proper structure, metadata, progressive disclosure, and security guidelines. Use when creating new skills, building custom workflows, or when user mentions skill creation, skill development, custom skill authoring, weaving skills, or crafting skills.
567 -
majiayu000 Bundle Rate Limiting 3Implements ASP.NET Core rate limiting middleware for API protection. Covers fixed window, sliding window, token bucket, and concurrency limiters with custom policies.
567 -
majiayu000 Bundle Dependency Audit 3Audit npm dependencies for security vulnerabilities, outdated packages, and license compliance.
567 -
majiayu000 Bundle Input Validation 2Input-Validation standards for input validation in Security environments.
567 -
majiayu000 Bundle Token Management 2トークン管理(Token Management)機能の開発・修正を行う際に使用。Access Token, Refresh Token, ID Token, Introspection, Revocation実装時に役立つ。
567 -
majiayu000 Bundle Performance Audit 2Run Lighthouse audit and verify Core Web Vitals. Use at project end before release. Triggers on "performance", "Lighthouse", "Core Web Vitals", "speed test", "page speed".
567 -
majiayu000 Bundle Codebase Audit 3Audit and map a codebase to understand structure, dependencies, and risks. Use when the user asks to audit a repo, understand architecture, or assess codebase quality or health.
567 -
majiayu000 Bundle Quality Report 2Génère un rapport complet de qualité du code incluant les vérifications TypeScript, Biome (lint/format), les tests et la couverture de code. Utilise ce skill quand l'utilisateur demande un rapport de qualité, un audit de code, ou veut vérifier l'état général du projet.
567 -
majiayu000 Bundle Security Validation 2Pre-merge security validation detecting secrets, user-specific paths, insecure SSH configurations, and security-weakening flags. Use before committing code/documentation, before creating PRs, or during QA validation. Supports automated scanning with severity-based enforcement (CRITICAL blocks merge, HIGH requires fixes).
567 -
majiayu000 Bundle Code Quality Check 2Apply the code-quality checklist to audit files or directories and produce a Markdown report with findings and suggested fixes. Use when asked to "audit these files", "run a quality check", "code quality review", or "check against the code-quality checklist".
567 -
majiayu000 Bundle Audit Permissions 2This skill should be used when the user asks to "audit claude permissions", "audit permissions", "review local claude settings", "promote permissions to global", "clean up claude settings", "find permission patterns", or wants to identify project-local Claude Code permissions that should be added to global configuration.
567 -
majiayu000 Bundle Codex Code Review 2Perform comprehensive code reviews using OpenAI Codex CLI. This skill should be used when users request code reviews, want to analyze diffs/PRs, need security audits, performance analysis, or want automated code quality feedback. Supports reviewing staged changes, specific files, entire directories, or git diffs.
567 -
majiayu000 Bundle Incident Response 2This skill empowers Claude to guide you through the security incident response process, ensuring a structured and effective approach to handling security breaches and attacks. It helps you classify incidents, develop response strategies, gather crucial evidence, and implement remediation steps to minimize damage and prevent future occurrences.
567 -
majiayu000 Bundle Sec Context Depth 2Comprehensive AI code security review using 27 sec-context anti-patterns. Use for code review when security vulnerabilities are suspected, especially for AI-generated code.
567 -
majiayu000 Bundle Security Auditing 2Audit security with vulnerability scanning, input validation checks, and auth/authz review against OWASP Top 10. Use when implementing authentication, reviewing security-sensitive code, or conducting security audits.
567 -
majiayu000 Bundle Security Guidance 2Comprehensive security best practices, vulnerability scanning, and security guidance for development workflows with automated security checks and compliance monitoring.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include update-readme, auth-bypass, code-reviewing. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.