Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Vulnerability Scanning 2Scan systems and dependencies for CVEs and security vulnerabilities. Use tools like Nessus, OpenVAS, and Qualys to identify and prioritize vulnerabilities. Use when performing security assessments, compliance scanning, or vulnerability management.
567 -
majiayu000 Bundle Ln 610 Docs Auditor 3Coordinates documentation audit across structure, semantic content, fact-checking, and code comments. Use when auditing all project documentation.
567 -
majiayu000 Bundle Code Review Assistant 2Automated code review assistance including best practices evaluation, security vulnerability detection, performance optimization suggestions, code quality assessment, and style guide enforcement. Use when Claude needs to perform code reviews, assess code quality, identify potential issues, or provide improvement recommendations.
567 -
majiayu000 Bundle Ln 610 Docs Auditor 4Coordinates 3 specialized documentation audit workers (structure, semantic, code comments). Detects project type, delegates parallel audits, aggregates results into docs/project/docs_audit.md.
567 -
majiayu000 Bundle Subagent Driven Development 11The implementation engine. Routed to by /sprint (full plan, autonomous) and by executing-plans (scoped batch, checkpoint-gated). One fresh subagent per task — test-first via tdd — followed by spec-compliance review, quality review, and fresh-run verification. No single context accumulates drift, and nothing is accepted on a subagent's word.
567 -
majiayu000 Bundle System Architect 7System architecture skill for designing scalable, maintainable software systems. Covers microservices/monolith decisions, API design, DB selection, caching, security, and scalability planning.
567 -
majiayu000 Bundle Ln 610 Docs Auditor 5Use when auditing project documentation through the evaluation platform with mandatory research, coordinated audit workers, and structured summaries.
567 -
majiayu000 Bundle Ln 620 Codebase Auditor 4Coordinates codebase audit across security, build, code quality, dependencies, and architecture. Use when auditing entire codebase.
567 -
majiayu000 Bundle Ln 620 Codebase Auditor 5Use when auditing the codebase through the evaluation platform with mandatory research, coordinated domain audit workers, and structured summaries.
567 -
majiayu000 Bundle Better Auth Best Practices 3(中文)Skill for integrating Better Auth - the comprehensive TypeScript authentication framework.
567 -
majiayu000 Bundle Auditing Wallet Security 2Execute review crypto wallet security including private key management and transaction signing. Use when auditing wallet security practices. Trigger with phrases like "audit wallet", "check security", or "verify signatures".
567 -
majiayu000 Bundle Code Review Checklist 8Comprehensive code review criteria covering correctness, readability, maintainability, security, performance, and testing. Reference when reviewing code changes or preparing code for review.
567 -
majiayu000 Bundle Ln 611 Docs Structure Auditor 3Documentation structure audit worker (L3). Checks hierarchy & links, SSOT, proactive compression, requirements compliance, actuality (code vs docs), legacy cleanup, stack adaptation. Returns findings with severity, location, and recommendations.
567 -
majiayu000 Bundle Ln 625 Dependencies Auditor 2Dependencies audit worker (L3). Checks outdated packages, unused deps, reinvented wheels, vulnerability scan (CVE/CVSS). Supports mode: full | vulnerabilities_only.
567 -
majiayu000 Bundle Ln 625 Dependencies Auditor 3Checks outdated packages, unused deps, reinvented wheels, CVE/CVSS vulnerability scan. Use when auditing dependencies.
567 -
majiayu000 Bundle Ln 625 Dependencies Auditor 4Checks outdated packages, unused deps, reinvented wheels, CVE/CVSS vulnerability scan. Use when auditing dependencies.
567 -
majiayu000 Bundle Ln 625 Dependencies Auditor 5Checks outdated packages, unused deps, reinvented wheels, CVE/CVSS vulnerability scan. Use when auditing dependencies.
567 -
majiayu000 Bundle Reverse Engineering Firmware Analysis 2Extended firmware analysis for embedded/IoT images with deep extraction, emulation, and vulnerability assessment.
567 -
majiayu000 Bundle Ln 650 Persistence Performance Auditor 3Coordinates 3 specialized audit workers (query efficiency, transaction correctness, runtime performance). Researches DB/ORM/async best practices, delegates parallel audits, aggregates results into docs/project/persistence_audit.md.
567 -
majiayu000 Bundle Ln 620 Codebase Auditor 6Coordinates codebase audit across security, build, code quality, dependencies, and architecture. Use when auditing entire codebase.
567 -
majiayu000 Bundle Ln 650 Persistence Performance Auditor 4Coordinates 3 specialized audit workers (query efficiency, transaction correctness, runtime performance). Researches DB/ORM/async best practices, delegates parallel audits, aggregates results into single Linear task in Epic 0.
567 -
majiayu000 Bundle Ln 650 Persistence Performance Auditor 5Coordinates persistence and performance audit across queries, transactions, runtime, and resource lifecycle. Use when auditing data layer performance.
567 -
majiayu000 Bundle When Configuring Sandbox Security Use Sandbox Configurat 2When Configuring Sandbox Security Use Sandbox Configurator
567 -
majiayu000 Bundle When Setting Network Security Use Network Security Setup 2When Setting Network Security Use Network Security Setup
567 -
majiayu000 Bundle Ln 632 Test E2e Priority Auditor 2E2E Critical Coverage audit worker (L3). Validates E2E coverage for critical paths (Money 20+, Security 20+, Data 15+). Pure risk-based - no pyramid percentages.
567 -
majiayu000 Bundle Ln 635 Test Isolation Auditor 2Test Isolation + Anti-Patterns audit worker (L3). Checks isolation (APIs/DB/FS/Time/Random/Network), determinism (flaky, order-dependent), and 7 anti-patterns.
567 -
majiayu000 Bundle Ln 830 Code Modernization Coordinator 3Modernizes codebase via OSS replacement and bundle optimization. Use when acting on audit findings to reduce custom code.
567 -
joshuashepherd Skill Tenant Check 2Audit components for hardcoded tenant strings, non-semantic colors, or missing feature flags. Use before PR review or to check tenant isolation.
1 -
joshuashepherd Skill Movement Leader Voice 2Author the canonical voice & style guide for a movement leader at `docs/voice/{SLUG}_VOICE.md` — a self-contained, corpus-grounded reference (five weighted voice markers, prose character, signature rhetoric, failure modes, argument patterns, signature phrases, citation habits, audit rubric, and sample passages) describing how this leader sounds, on their own terms, not by comparison to anyone else. Run inside a leader's website repo against `docs/books/`, `docs/movement_leader_research/`, and any other content. Use when standing up or refreshing a leader's voice identity for Writing Studio, AI Lab, agents, and human editors. Distinct from the Movemental company voice ([[movemental-voice]]) and the generic [[voice-designer]]. Reference implementation is the brad-brisco repo.
1 -
joshuashepherd Skill Supabase Security Audit 2Audit Supabase security — RLS policies, exposed secrets, API route auth, storage security, and role grants.
1 -
micsapp Bundle Plugin AuditorAudit automatically audits AI assistant code plugins for security vulnerabilities, best practices, AI assistant.md compliance, and quality standards when user mentions audit plugin, security review, or best practices check. specific to AI assistant-code-plugins repositor... Use when assessing security or running audits. Trigger with phrases like 'security scan', 'audit', or 'vulnerability'.
3 -
micsapp Skill Hipaa Audit HelperHipaa Audit Helper - Auto-activating skill for Security Advanced. Triggers on: hipaa audit helper, hipaa audit helper Part of the Security Advanced skill category.
3 -
micsapp Skill API Key ManagerApi Key Manager - Auto-activating skill for Security Fundamentals. Triggers on: api key manager, api key manager Part of the Security Fundamentals skill category.
3 -
micsapp Skill Iam Policy ReviewerIam Policy Reviewer - Auto-activating skill for Security Advanced. Triggers on: iam policy reviewer, iam policy reviewer Part of the Security Advanced skill category.
3 -
micsapp Skill Siem Rule GeneratorSiem Rule Generator - Auto-activating skill for Security Advanced. Triggers on: siem rule generator, siem rule generator Part of the Security Advanced skill category.
3 -
micsapp Skill Key Rotation ManagerKey Rotation Manager - Auto-activating skill for Security Advanced. Triggers on: key rotation manager, key rotation manager Part of the Security Advanced skill category.
3
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include tenant-check, movement-leader-voice, supabase-security-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.