Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Dependency Audit 7Conduct a dependency audit for a project — checking for security vulnerabilities, license compliance issues, outdated packages, and transitive dependency risk. Use when asked to audit dependencies, review package security, check license compliance, assess dependency health, or produce a vulnerability report. Produces a vulnerability findings table, license compliance matrix, update priority matrix, dependency health score, and 30-day remediation plan.
567 -
majiayu000 Bundle Dockerfile Generator 4Generates production-ready multi-stage Dockerfiles and .dockerignore files with BuildKit features, pnpm monorepo support, OCI labels, and security hardening. Use when creating or writing Dockerfiles for Node.js, Python, Go, Java, or Rust. Does not validate (use dockerfile-validator).
567 -
majiayu000 Bundle Memory Forensics 2Analyzes volatile memory dumps to detect malware, rootkits, and security breaches in digital forensics.
567 -
majiayu000 Bundle Copilot Review 4Perform code reviews using GitHub Copilot CLI to identify bugs, security vulnerabilities, performance issues, and code quality problems. Use when the user asks to review code, check for issues, security audit, or before committing. Requires Copilot CLI installed.
567 -
majiayu000 Bundle Review Pr 20Review a PR diff for quality, security, and correctness
567 -
majiayu000 Bundle Cloudflare R2 6Manage Cloudflare R2 buckets, lifecycle, and signed URLs. Use for low-egress object storage and media delivery.
567 -
majiayu000 Bundle Code Reviewer 27Code review specialist for quality, security, and best practices
567 -
majiayu000 Bundle Defense In Depth 5This skill should be used when implementing "multi-layer validation", "comprehensive error handling", "input sanitization", "security testing", "data validation layers", "fault tolerance", or when building robust systems with multiple validation checkpoints.
567 -
majiayu000 Bundle Review Code 15Perform systematic code review following project standards. Use when reviewing pull requests, analyzing code quality, checking for patterns compliance, or auditing code changes. Invoked by: "code review", "review PR", "review changes", "audit code".
567 -
majiayu000 Bundle Audit Logging 4Implement centralized audit logging and SIEM integration. Configure log retention and security monitoring. Use when implementing audit trail requirements.
567 -
majiayu000 Bundle Authentication 3Implement iOS authentication patterns including Sign in with Apple (ASAuthorizationAppleIDProvider, ASAuthorizationController, ASAuthorizationAppleIDCredential), credential state checking, identity token validation, ASWebAuthenticationSession for OAuth and third-party auth flows, ASAuthorizationPasswordProvider for AutoFill credential suggestions, and biometric authentication with LAContext. Use when implementing Sign in with Apple, handling Apple ID credentials, building OAuth login flows, integrating Password AutoFill, checking credential revocation state, or validating identity tokens server-side.
567 -
majiayu000 Bundle Mobile Security 3Guide for mobile game security on Android and iOS platforms. Use this skill when working with Android/iOS reverse engineering, mobile game hacking, APK analysis, root/jailbreak detection bypass, or mobile anti-cheat systems.
567 -
majiayu000 Bundle Workflow Security Audit 2Process for conducting system security reviews and remediating vulnerabilities. Follow the phases sequentially.
567 -
majiayu000 Bundle Skill Creator 98Manage skills through three operations: Create, Update, and Validate.
567 -
majiayu000 Bundle Senior Security 2Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.
567 -
majiayu000 Bundle Code Review 87Perform a maximally picky and professional code review of recent changes. Reviews all code added since the last review, checking for thread safety, async safety, security vulnerabilities, data integrity, test quality, and code smells. Use before committing significant changes.
567 -
majiayu000 Bundle Global Validation 7Data validation strategies for stock_picker_bot using Pydantic models and SQLAlchemy constraints. Covers API input validation, stock data validation, and database integrity.
567 -
majiayu000 Bundle Pci Compliance 2Expert PCI DSS compliance advisor covering PCI DSS v4.0.1 (current) and v4.0. Use this skill whenever a user asks about PCI DSS, payment card security, cardholder data protection, CDE scoping, SAQ types (A, A-EP, B, B-IP, C, C-VT, P2PE, D), ROC, AOC, QSA assessments, ASV scans, merchant levels, service provider levels, network segmentation, penetration testing, tokenisation, encryption of PAN data, or any of the 12 PCI DSS requirements. Also trigger for questions like "are we PCI compliant?", "how do I scope my CDE?", "which SAQ applies to us?", "what changed in PCI DSS v4.0?", "how do I prepare for a QSA audit?", or any request involving payment data security, cardholder data environment, or PCI certification readiness.
567 -
majiayu000 Bundle Security Review 24Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
567 -
majiayu000 Bundle Threat Hunting 3Proactive threat hunting, IOC extraction, MITRE ATT&CK mapping, behavioral anomaly detection, log analysis correlation
567 -
majiayu000 Bundle Analyze Dependencies 2Audit project dependencies for risk when the user asks to check dependencies, audit packages, review dependency health, check for vulnerabilities, or assess supply chain risk
567 -
majiayu000 Bundle Hook Development 2Create, validate, and audit event-driven hooks for intercepting events, enforcing security patterns, and automating interventions. Use when building or reviewing hooks, implementing event handlers, or adding safety guardrails. Includes matcher patterns, action types, timeout configuration, and security enforcement. Not for manual actions, passive knowledge, or non-event-driven automation.
567 -
majiayu000 Bundle Up To Date 2Fetch real, current API docs and verify package versions before installing packages, calling external APIs, using SDKs, or integrating any third-party library. Triggers on npm install, pip install, package.json changes, import statements for external packages, API calls (fetch, axios, SDK methods), "integrate with", "connect to", "use X library", or debugging silent API failures where code returns 200 but produces no effect.
567 -
majiayu000 Bundle Change Management 4Implement change management processes. Configure CAB reviews, change windows, and rollback procedures. Use when managing production changes.
567 -
majiayu000 Bundle Disaster Recovery 3Implement disaster recovery strategies and runbooks. Configure RPO/RTO targets and failover procedures. Use when planning for business continuity.
567 -
majiayu000 Bundle Audit Performance 3Audit performance against Core Web Vitals and performance budgets when the user asks to check performance, audit speed, or analyze web vitals
567 -
majiayu000 Bundle Code Reviewer 29Expert code reviewer who provides constructive, actionable feedback focused on correctness, maintainability, security, and performance — not style preferences.
567 -
majiayu000 Bundle Ln 620 Codebase Auditor 3Coordinates 9 specialized audit workers (security, build, architecture, code quality, dependencies, dead code, observability, concurrency, lifecycle). Researches best practices, delegates parallel audits, aggregates results into docs/project/codebase_audit.md.
567 -
majiayu000 Bundle Authentication 4認証機能(Authentication Policy, MFA)の開発・修正を行う際に使用。認証ポリシー、パスワード、OTP、FIDO2、条件付き認証実装時に役立つ。
567 -
majiayu000 Bundle Gdpr Compliance 3Implement GDPR data protection requirements. Configure consent management, data subject rights, and privacy by design. Use when processing EU personal data.
567 -
majiayu000 Bundle Phx Audit 2Project health audit and health check — architecture, performance, tests, dependencies, code quality. Use when assessing overall project health, before releases, or after refactors.
567 -
majiayu000 Bundle Report Writing 2Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use "could potentially" — prove it or don't report.
567 -
majiayu000 Bundle Security Audit 20Audit code for multi-tenant security vulnerabilities and data isolation issues
567 -
majiayu000 Bundle Threat Modeling 5Conduct threat modeling using STRIDE methodology. Identify threats, assess risks, and design security controls. Use when designing secure systems or assessing application security.
567 -
majiayu000 Bundle Spring Boot Security 3Guide for implementing Spring Security with JWT authentication and role-based access control. Use this when adding security to endpoints or implementing authentication features.
567 -
majiayu000 Bundle Constitution 3Creates, updates, validates, and displays the architectural DNA of a project through two shared documents: docs/specs/architecture.md (technology stack, architectural rules, security constraints, AI guardrails) and docs/specs/ontology.md (domain glossary / Ubiquitous Language). Use BEFORE brainstorm as a project setup step, or at any point in the SDD lifecycle to validate specs/tasks against architecture principles. Triggers on 'create constitution', 'update constitution', 'constitution check', 'validate against constitution', 'project principles', 'architectural guardrails', 'setup project architecture', 'define ontology'.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include dependency-audit, dockerfile-generator, memory-forensics. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.