Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Log Analysis 5Analyzes system and application logs to detect anomalies and security threats in blue-team operations.
567 -
majiayu000 Bundle Security Audit 11Automated security posture check of the AI Harness system. Checks credentials, tokens, file permissions, git hygiene, heartbeat health, and configuration drift.
567 -
majiayu000 Bundle Security Auditor 4Conducting interactive security audits using the Map & Probe methodology. Use when the user wants to perform a security review of source code, find vulnerabilities, audit a codebase, or analyze code for security issues.
567 -
majiayu000 Bundle Security Review 19Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, Shopify webhooks, or implementing sensitive features in Go. Provides comprehensive security checklist and Go patterns.
567 -
majiayu000 Bundle Security Scan 9Run a comprehensive security scan across all systems
567 -
majiayu000 Bundle Review Test Quality 2Audit AHK test suite for drifted copies, dead tests, and design issues
567 -
majiayu000 Bundle Ruff 4This skill should be used when users need to lint, format, or validate Python code using the Ruff command-line tool. Use this skill for tasks involving Python code quality checks, automatic code formatting, enforcing style rules (PEP 8), identifying bugs and security issues, or modernizing Python code. This skill should be invoked PROACTIVELY whenever Python code is written or modified to ensure code quality.
567 -
majiayu000 Bundle Security Audit 13Security auditing for Rust/WebAssembly applications. Identifies vulnerabilities, reviews unsafe code, validates input handling, and ensures secure defaults. Follows OWASP guidelines and Rust security best practices.
567 -
majiayu000 Bundle Senior Backend 2Comprehensive backend development skill for building scalable backend systems using NodeJS, Express, Go, Python, Postgres, GraphQL, REST APIs. Includes API scaffolding, database optimization, security implementation, and performance tuning. Use when designing APIs, optimizing database queries, implementing business logic, handling authentication/authorization, or reviewing backend code.
567 -
majiayu000 Bundle Fact Check 5Fact-check manuscript claims against cited sources in a per-source Markdown knowledge base. Use to audit claim support, overclaiming, direction, scope, and misattribution after source intake is complete.
567 -
majiayu000 Bundle Journey Mapping 4Build customer journey maps and service blueprints that visualize the end-to-end user experience including touchpoints, emotions, friction, and underlying systems. Use this skill whenever the user wants to map a customer journey, build a service blueprint, identify friction across an experience, align teams on the user experience, or visualize touchpoints and pain points. Triggers on customer journey, journey map, service blueprint, user journey, experience map, touchpoint analysis, friction map, journey audit, end-to-end experience, customer experience map. Also triggers when the team has departmental views of users but no shared map of what the experience actually feels like.
567 -
majiayu000 Bundle Quality Reviewing 2Deep code review with web research to verify against latest ecosystem. Use when user says 'double check against latest', 'verify versions', 'check security', 'review against docs', or needs deep analysis beyond automatic quality hook.
567 -
majiayu000 Bundle Pre Commit 4Configure pre-commit hooks for code quality, linting, formatting, and security checks. Automate code standards with Git hooks. Use for code quality enforcement, automated formatting, or security scanning before commits. Triggers on pre-commit, git hooks, husky, lint-staged.
567 -
majiayu000 Bundle Review Claudemd 2Audit all CLAUDE.md files for dead references, bloat, and inconsistencies
567 -
majiayu000 Bundle Review Code 12Multi-dimensional code review with structured reports. Analyzes correctness, readability, performance, security, testing, and architecture. Triggers on "review code", "code review", "审查代码", "代码审查".
567 -
majiayu000 Bundle Skill Name 8Personal taste skill — 5 evidence-derived anchors ({anchor_names}) for prose, code, design, and decisions. Two modes: audit judges an artifact against the two-sided charter; anchor loads the taste register before producing. Trigger with "{trigger_phrase}", "taste-test", "is this slop?", or "overkill?".
567 -
majiayu000 Bundle Governance 6Use when validating compliance, ownership, risk lifecycle, or framework integrity for regulated industries. Modes: compliance | ownership | risk | integrity.
567 -
majiayu000 Bundle Security Audit 14Java security checklist covering OWASP Top 10, input validation, injection prevention, and secure coding. Works with Spring, Quarkus, Jakarta EE, and plain Java. Use when reviewing code security, before releases, or when user asks about vulnerabilities.
567 -
majiayu000 Bundle Security Guidance 3Security guidance and best practices for code development. Use when writing authentication code, handling sensitive data, validating user input, designing APIs, or reviewing code for security issues.
567 -
majiayu000 Bundle Security 19セキュリティ・脆弱性対策の開発・テストを行う際に使用。OAuth/OIDC攻撃対策、認証識別子切り替え攻撃、Session Fixation、マルチテナント分離、セキュリティテスト実装時に役立つ。
567 -
majiayu000 Bundle Vulnerability Management 4<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Domain Authority Auditor 3This skill should be used when the user asks to "audit domain authority", "domain trust score", "CITE audit", "how authoritative is my site", "domain credibility check", "is my domain trustworthy", or "domain credibility score". Runs a full CITE 40-item domain authority audit, scoring domains across 4 dimensions with weighted scoring by domain type. Produces a detailed report with per-item scores, dimension analysis, veto checks, and a prioritized action plan. For content-level assessment, see content-quality-auditor. For link profile details, see backlink-analyzer.
567 -
majiayu000 Bundle Tech Debt Analyzer 2This skill should be used when analyzing technical debt in a codebase, documenting code quality issues, creating technical debt registers, or assessing code maintainability. Use this for identifying code smells, architectural issues, dependency problems, missing documentation, security vulnerabilities, and creating comprehensive technical debt documentation.
567 -
majiayu000 Bundle Project Wizard 2Interactive setup wizard for creating new projects with proper structure, security configurations, GitHub repository, and Archon project tracking. Guides users through project creation from template with pre-commit hooks, branch protection, and customized documentation. Use when starting a new project, setting up a repository, or initializing a new codebase.
567 -
majiayu000 Bundle Security Audit 15Identify and fix security vulnerabilities in code and infrastructure
567 -
majiayu000 Bundle Pair Programming 6AI-assisted pair programming with multiple modes (driver/navigator/switch), real-time verification, quality monitoring, and comprehensive testing. Supports TDD, debugging, refactoring, and learning sessions. Features automatic role switching, continuous code review, security scanning, and performance optimization with truth-score verification.
567 -
majiayu000 Bundle Threat Hunting 2Proactive threat hunting, IOC extraction, MITRE ATT&CK mapping, behavioral anomaly detection, log analysis correlation
567 -
majiayu000 Bundle Git Workflow 33Implement Git branching strategies, PR workflows, and release management patterns. Configure GitFlow, trunk-based development, or GitHub Flow for team collaboration. Use when establishing version control workflows or improving development team collaboration.
567 -
majiayu000 Bundle Incident Response 12Manage active production incidents through detection, triage, mitigation, communication, and resolution with structured roles and decision-making. Use this skill whenever the user has an active incident, a production issue, a service outage, a security incident, or needs to plan incident response procedures. Triggers on incident response, production incident, outage, service down, site down, P0, P1, severity, downtime, on-call, incident commander, status page, postmortem prep. Also triggers when something is actively broken in production and the user is figuring out what to do.
567 -
majiayu000 Bundle Service Mesh 4Implement Istio and Linkerd service meshes. Configure mTLS, traffic management, and observability. Use when managing microservices communication.
567 -
majiayu000 Bundle Documentation Cascade Audit 2Иерархический каскадный аудит и исправление документации BioETL. Оркестратор декомпозирует кодовую базу на сегменты и запускает параллельные суб-агенты для исчерпывающего документирования, поиска расхождений кода и документации, проверки соответствия, идентификации недокументированных решений и автоматического исправления. Триггеры: - Полный аудит документации проекта - Каскадное документирование после крупного рефакторинга - Подготовка к релизу (documentation freeze) - Обнаружение массового doc drift
567 -
majiayu000 Bundle Ln 650 Persistence Performance Auditor 2Coordinates persistence and performance audit across queries, transactions, runtime, and resource lifecycle. Use when auditing data layer performance.
567 -
majiayu000 Bundle Code Review 82Thorough code review practices and checklists. Covers security review, performance analysis, maintainability assessment, and constructive feedback. Use when reviewing PRs, auditing code quality, or establishing review standards.
567 -
majiayu000 Bundle Code Reviewer 23Review code changes, diffs, or pull requests for bugs, security issues, and best practice violations. Use after code changes or before merging PRs.
567 -
majiayu000 Bundle Makefile Review 2Audit Makefiles for build correctness and recipe duplication.
567 -
majiayu000 Bundle API Authentication 2Apply when implementing API authentication: JWT tokens, session management, API keys, and auth middleware. Follows JWT Best Current Practices (RFC 8725).
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include log-analysis, security-audit, security-auditor. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.