Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Security Patterns 2Security patterns for input validation, PII protection, and cryptographic operations
567 -
majiayu000 Bundle Security Reviewer 2Use when reviewing code for security vulnerabilities, conducting threat modeling, ensuring SLSA compliance, or performing security assessments. Invoked for security analysis, vulnerability detection, and compliance verification.
567 -
majiayu000 Bundle Vendor Management 3Implement vendor risk management programs. Assess third-party security and maintain vendor inventory. Use when managing supplier security.
567 -
majiayu000 Bundle Gsd Validate Phase 2Retroactively audit and fill Nyquist validation gaps for a completed phase
567 -
majiayu000 Bundle Security Auditor 2Expert in compliance frameworks (SOC2, ISO 27001), automated auditing, and risk management.
567 -
majiayu000 Bundle Wordpress Master 2Use when user needs WordPress development, theme or plugin creation, site optimization, security hardening, multisite management, or scaling WordPress from small sites to enterprise platforms.
567 -
majiayu000 Bundle Devils Advocate 3Challenge and stress-test ideas through adversarial thinking. Use when user wants to "poke holes", "challenge this", "what could go wrong", "devil's advocate", "stress test", "red team", "pre-mortem", "review this", "validate", "audit", or needs to find weaknesses before they become problems. (project)
567 -
majiayu000 Bundle Precommit Setup 2Configure pre-commit hooks for code formatting, linting, and security checks
567 -
majiayu000 Bundle Pci Dss Compliance 2Implement PCI DSS requirements for payment card data. Configure cardholder data environment and security controls. Use when processing payment cards.
567 -
majiayu000 Bundle Privacy Compliance 3Use this skill when implementing GDPR or CCPA compliance, designing consent management, conducting DPIAs, or managing data processing agreements. Triggers on GDPR, CCPA, data privacy, consent management, DPIA, data subject rights, privacy policy, cookie consent, and any task requiring privacy regulation compliance or data protection design.
567 -
majiayu000 Bundle Architecture Review 4Peer review architecture for quality, risks, and optimization opportunities. Analyzes scalability bottlenecks, security vulnerabilities, performance optimization, technology fit, and provides prioritized recommendations. Use when reviewing proposed architecture documents for quality assurance, risk identification, or architectural decision validation.
567 -
majiayu000 Bundle Seclists Web ShellsWeb shell samples for detection and analysis: PHP, ASP, ASPX, JSP, Python, Perl shells. Use for security research and detection system testing.
567 -
majiayu000 Bundle Supply Chain Security 2Software supply chain security guidance covering SBOM generation, SLSA framework, dependency scanning, SCA tools, and protection against supply chain attacks like dependency confusion and typosquatting.
567 -
majiayu000 Bundle Rollback Changes 2Automatically rollback changes from failed workflow phases using changes log files. Use when workflows fail and need to restore previous state, including file restoration, artifact cleanup, and command reversal. Use for error recovery after failed bug fixes, security patches, or refactoring operations.
567 -
majiayu000 Bundle Dependency Analyzer 2Analyzes project dependencies, detects outdated packages, identifies breaking changes, and suggests safe update strategies. Helps maintain dependency health and security.
567 -
majiayu000 Bundle Moai Platform Clerk 2Clerk modern authentication specialist covering WebAuthn, passkeys, passwordless, and beautiful UI components. Use when implementing modern auth with great UX.
567 -
majiayu000 Bundle Permission Patterns 2Guide for configuring Claude Code permissions effectively. Use when setting up security policies, configuring allow/deny patterns, managing tool permissions, or implementing team security standards. Covers permission modes, sandboxing, and settings.json configuration.
567 -
majiayu000 Bundle Security Specialist 2Implement authentication, authorization, data protection, vulnerability checks, and security best practices. Use when adding authentication, protecting API endpoints, handling user data, or implementing security features.
567 -
majiayu000 Bundle Global Commenting 3Write meaningful code comments that explain WHY rather than WHAT, focusing on business logic, non-obvious solutions, workarounds, and complex algorithms while keeping code self-documenting. Use this skill when adding comments to explain rationale, documenting complex business logic, explaining workarounds or temporary solutions, describing performance optimizations, writing function documentation (JSDoc, docstrings, XML docs), or reviewing code for appropriate commenting. Apply when working on any code file that contains logic requiring explanation, public API functions, complex algorithms, security-critical code, or architectural decisions. This skill ensures comments explain rationale not implementation (WHY not WHAT), self-documenting code through clear naming (refactor unclear code instead of commenting), concise and evergreen comments (no who/when dated comments - Git tracks this), links to external resources for context, proper function documentation format (JSDoc for TS/JS, docstrings for Python, XML d
567 -
majiayu000 Bundle Tauri Development 2Guide for developing Tauri v2 desktop apps on macOS. Covers debugging native apps (Rust panics, Sentry integration, thread-local issues), app signing and updater setup, global shortcuts, Keychain secret storage, and Homebrew distribution. Use when building Tauri apps, debugging Rust backend issues, setting up auto-updates, handling keyboard shortcuts, or distributing macOS apps.
567 -
majiayu000 Bundle Documentation Audit 2Systematic documentation audit that validates every documentation claim against code and identifies undocumented features - executable as a repeatable Claude Code skill (project)
567 -
majiayu000 Bundle Ln 610 Docs Auditor 2Coordinates documentation audit across structure, semantic content, fact-checking, and code comments. Use when auditing all project documentation.
567 -
majiayu000 Bundle Code Review Checklist 2Structured code review criteria for pre-implementation plan review (Critic) and post-implementation security/quality review. Covers security, performance, maintainability, and correctness with severity ratings.
567 -
majiayu000 Bundle Triage Validation 2Validate a bug bounty finding before writing a report — the 7-Question Gate, 4 pre-submission gates, always-rejected list, conditional chain table, CVSS 3.1 quick reference, and severity decision guide. Use BEFORE writing any report to avoid N/A and low quality submissions.
567 -
majiayu000 Bundle Security Review 4Use when reviewing code for security vulnerabilities, implementing authorization, or ensuring data protection.
567 -
majiayu000 Bundle Cloudflare Turnstile 2Status: Production Ready ✅ | Last Verified: 2025-11-26
567 -
majiayu000 Bundle Moai Domain Security 2OWASP Top 10, SAST/DAST, dependency security, and secrets management.
567 -
majiayu000 Bundle Parallel Code Review 2Parallel 3-reviewer code review: Security, Business-Logic, Architecture.
567 -
majiayu000 Bundle Iam 2基于蓝鲸 IAM 的前端鉴权方案,包含 v-authority 指令实现、权限组件封装及无权限交互规范。
567 -
majiayu000 Bundle Phase Workflow RunnerRuns a complete phase workflow: audit existing work, fill gaps, run tests, verify acceptance criteria, and report readiness for next phase. Use when user asks to run or complete a project phase.
567 -
majiayu000 Bundle NPM Publish 4Publish npm packages with 2FA. Use when: publishing scoped packages, setting up npm auth, encountering EOTP errors. CRITICAL: Passkeys/security keys do NOT work for CLI publishing. Use TOTP app or granular access tokens.
567 -
majiayu000 Bundle Repairing Geometry IssuesAutomated geometry repair using RasFixit and quality validation using RasCheck. Handles blocked obstructions, generates before/after visualizations, and creates audit trails. Use when fixing geometry errors, repairing obstructions, validating models, or ensuring FEMA compliance. Triggers: fix, repair, geometry, blocked obstruction, validate, check, RasCheck, RasFixit, FEMA, quality assurance, QA, overlapping, obstruction overlap, elevation envelope, geometry error.
567 -
majiayu000 Bundle Green Mirage Audit 2Use when reviewing test suites, after test runs pass, or when user asks about test quality - performs exhaustive line-by-line audit tracing code paths through entire program, verifying tests actually validate what they claim. Outputs structured report compatible with fix-tests skill.
567 -
majiayu000 Bundle Moai Tool Ast Grep 2AST-based structural code search, security scanning, and refactoring using ast-grep (sg CLI). Supports 40+ languages with pattern matching and code transformation.
567 -
majiayu000 Bundle Audit 4Full codebase audit — dead code, layer violations, concurrency, observability, code quality
567 -
majiayu000 Bundle Review 11Review diffs for risk, find mocks, scan for bugs, and audit codebases.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-patterns, security-reviewer, vendor-management. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.