Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Compliance 3Navigate privacy regulations (GDPR, CCPA), review DPAs, and handle data subject requests. Use when reviewing data processing agreements, responding to data subject access or deletion requests, assessing cross-border data transfer requirements, or evaluating privacy compliance.
567 -
majiayu000 Bundle Dependency Audit 4Audit project dependencies for known vulnerabilities using ecosystem-specific tools (npm audit, composer audit, pip-audit, cargo audit, etc).
567 -
majiayu000 Bundle Incident Response 5<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Security Review 11Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
567 -
majiayu000 Bundle Security Reviewer 3Audit memory safety and security in unsafe code blocks, buffer handling, and security-sensitive operations
567 -
majiayu000 Bundle Spider Weave 2Weave authentication webs with patient precision. Spin the threads, connect the strands, secure the knots, and bind the system. Use when integrating auth, setting up OAuth, or securing routes.
567 -
majiayu000 Bundle Claude Skill Builder 3Guides creation and improvement of Claude Code skills using Anthropic's official methodology. Use when user wants to "create a skill", "build a skill", "make a new skill", "write a new skill", "improve an existing skill", "audit my skill", "refine my skill", "test a skill", "package a skill for distribution", or needs guidance on skill structure, progressive disclosure, description quality, testing, or distribution.
567 -
majiayu000 Bundle Skill Factory 4Research-backed skill creation workflow with automated firecrawl research gathering, multi-tier validation, and comprehensive auditing. Use when "create skills with research automation", "build research-backed skills", "validate skills end-to-end", "automate skill research and creation", needs 9-phase workflow from research through final audit, wants firecrawl-powered research combined with validation, or requires quality-assured skill creation following Anthropic specifications for Claude Code.
567 -
majiayu000 Bundle Audit Tests 3Audit the test suite for useless tests, consolidation opportunities, over-mocking, weak assertions, and other test quality issues. Use when user says "audit tests", "audit test suite", "review tests", or "test quality check". Generates an improvement plan in temp/ with explanations for each proposed change.
567 -
majiayu000 Bundle Database Patterns 4SQLite operations using better-sqlite3 with prepared statements. Use when implementing CRUD operations, timestamps, and user-scoped queries with row-level security.
567 -
majiayu000 Bundle Mongodb 3Administer MongoDB databases. Configure replica sets, sharding, and backups. Use when managing MongoDB deployments.
567 -
majiayu000 Bundle Pr Reviewer 3Review pull requests for spec compliance, security, performance, and code quality. Use when analyzing PRs. Not for writing new code or initial development.
567 -
majiayu000 Bundle Security Audit 6Checklist for security-sensitive coding, ensuring MaiHouses guards and policies are respected.
567 -
majiayu000 Bundle Sf Soql 2Build and optimize SOQL queries including relationship queries, aggregate functions, polymorphic TYPEOF, and selective filters. Use when asked to write queries, debug slow queries, optimize existing SOQL, or enforce query security. Activate on mentions of "SOQL", "query", "SELECT", "WHERE", "aggregate", "relationship query", or "query optimization".
567 -
majiayu000 Bundle Electron Pro 2Desktop application specialist building secure cross-platform solutions. Develops Electron apps with native OS integration, focusing on security, performance, and seamless user experience.
567 -
majiayu000 Bundle Redis 7Configure Redis for caching and data storage. Set up clustering, persistence, and Sentinel. Use when implementing Redis caching or queues.
567 -
majiayu000 Bundle Readme Updater 4Audit, create, or rewrite repository README.md files to enterprise-grade quality using a deterministic evidence workflow across purpose, architecture, setup, operations, security, governance, and quality gates. Use when users ask to update/standardize/harden README docs, fix inaccurate onboarding instructions, prepare production-ready repository documentation, or generate executive/ownership-ready README content.
567 -
majiayu000 Bundle Notebooklm 5Query and manage Google NotebookLM notebooks with persistent profile auth, source sync, batch/multi queries, and structured exports. Use when user asks to query NotebookLM, 'ask my notebook', shares NotebookLM notebook URLs, wants to list/create notebooks, manage sources, do bulk folder sync, dedupe, or audit exports.
567 -
majiayu000 Bundle Plan 33Use when a user commits to a direction and asks to plan, brief, research, or operationalize it. Classifies type and tier, researches read-only, and writes to plans/ after acknowledgment. Not for scoring — use planning; not for codebase audit — use plan-review.
567 -
majiayu000 Bundle Code Review 59Systematic code review with security, performance, and architecture analysis. Provides actionable fix suggestions and GitHub PR integration. Use when reviewing PRs, validating code changes, or checking code quality.
567 -
majiayu000 Bundle Code Review 63Use when asked to review a PR, MR, branch, or diff, audit changed files, or check code quality.
567 -
majiayu000 Bundle Code Reviewer 14Comprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go. Includes automated code analysis, best practice checking, security scanning, and review checklist generation. Use when reviewing pull requests, providing code feedback, identifying issues, or ensuring code quality standards.
567 -
majiayu000 Bundle Skill Review 3Audit claude-skills repository documentation with systematic 9-phase review: standards compliance, official docs verification via Context7/WebFetch, code examples accuracy, cross-file consistency, and version drift detection. Auto-fixes unambiguous issues with severity classification. Use when: investigating skill issues, major package updates detected (e.g., v1.x → v2.x), skill not verified >90 days, before marketplace submission, or troubleshooting outdated API patterns, contradictory examples, broken links, version drift.
567 -
majiayu000 Bundle Plan Reviewer 4Senior Architect skill for rigorous implementation plan audit. Enforces the "No Magic" rule and ensures every phase has automated verification and architectural soundness.
567 -
majiayu000 Bundle Dashboard 6View all tracked vulnerabilities and their current status
567 -
majiayu000 Bundle Dependency Auditing 2Use when auditing supply chain security. Covers dependency scanning tools, CVE triage workflows, SBOM generation, license compliance, and Dependabot/Renovate configuration.
567 -
majiayu000 Bundle Security Scan 6Run comprehensive security audits including SAST, dependency scanning, and secret detection
567 -
majiayu000 Bundle Threat Modeling 3Identifies what could go wrong in a system before it is built or changed — the assets worth attacking, the entry points, the trust boundaries, and the controls that actually address the realistic threats. Use this when designing a feature or system, when a change touches authentication, data handling, payments, or external input, before a security review, or when deciding which security work is worth doing at all.
567 -
majiayu000 Bundle Ops Auditor 2Audit infrastructure for cost, security, and compliance - analyze current spending patterns, identify cost optimization opportunities, scan for security vulnerabilities, check compliance with best practices, generate audit reports with prioritized recommendations, track audit history.
567 -
majiayu000 Bundle Workflow Creator 2This skill should be used when the user asks to 'create a workflow', 'design a workflow', 'edit a workflow', 'audit workflow', 'improve workflow', 'break down a task into phases', or needs to substantially create or edit any multi-phase workflow.
567 -
majiayu000 Bundle Research 37Research technical solutions, analyze architectures, gather requirements thoroughly. Use for technology evaluation, best practices research, solution design, scalability/security/maintainability analysis.
567 -
majiayu000 Bundle Postgres Patterns 2PostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices.
567 -
majiayu000 Bundle Code Review 66Perform automated code reviews checking for security vulnerabilities, performance issues, and code quality. Use before creating PRs or when reviewing complex changes.
567 -
majiayu000 Bundle Smart Commit 4Automates intelligent Git commits by analyzing unstaged/staged changes, grouping files by logical development concern, and committing sequentially with descriptive Conventional Commit messages. Includes pre-commit security audit protecting against credential leaks and large binary commits. Use when the user says "commit", "smart commit", "save changes", "push", "git commit", or similar.
567 -
majiayu000 Bundle Review Pr 13Review the current PR's changes for code quality, security, and Rails best practices. Ideal for triggering a thorough review from GitHub Mobile.
567 -
majiayu000 Bundle Review Pr 16Automated diff-scoped PR code review using parallel audit subagents. Posts inline GitHub review comments and submits a summary verdict. Use after a PR is opened to gate CI on review approval.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include compliance, dependency-audit, incident-response. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.