Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tools-only Bundle Gemini Peer Review 2Get a second opinion from Gemini on code, architecture, debugging, or security. Uses direct Gemini API calls — no CLI dependencies. Trigger with 'ask gemini', 'gemini review', 'second opinion', 'peer review', or 'consult gemini'.
7 -
tools-only Bundle Active Directory AttacksThis skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodHound enumeration", "Golden Ticket", ...
7 -
tools-only Bundle Context Manager 2Audit and manage the full project context landscape: CLAUDE.md memory hierarchy, project documentation, markdown footprint, and content overlap. Detects project type, scores quality, flags stale docs, and reports total context cost. Trigger with 'audit context', 'audit memory', 'update CLAUDE.md', 'restructure memory', 'session capture', 'check project docs', 'markdown footprint', or 'what docs does this project need'.
7 -
tools-only Bundle Context Manager 3Audit and manage the full project context landscape: CLAUDE.md memory hierarchy, project documentation, markdown footprint, and content overlap. Detects project type, scores quality, flags stale docs, and reports total context cost. Trigger with 'audit context', 'audit memory', 'update CLAUDE.md', 'restructure memory', 'session capture', 'check project docs', 'markdown footprint', or 'what docs does this project need'.
7 -
tools-only Bundle Security Reviewer 3Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles user input, authentication, API endpoints, or sensitive data. Key capabilities: RLS policy validation, multi-tenant isolation checks, secrets detection, OWASP Top 10 scanning, admin client misuse flagging. Trigger phrases: 'review security', 'check for vulnerabilities', 'audit RLS policies', 'is this safe'. Do NOT use for general code quality — use code-quality-reviewer instead. <example> Context: User wrote new API endpoints that handle user input user: "I just added server actions for the billing feature that process credit card metadata. Can you check for security issues?" assistant: "I'll audit the billing server actions for input validation, authentication checks, RLS policy coverage, and sensitive data exposure." <commentary>Triggers because the user wrote code handling sensitive data (billing) and explicitly asks for a security review.</commentary> </example> <example> Context: User asks to audi
7 -
qhjqhj00 Skill Energy Efficiency 2Evaluates the trade-off between energy efficiency and physical-layer security in an IRS-assisted MISO network with cooperative jamming. Probes how varying transmit power constraints and secrecy rate thresholds impact system performance compared to baseline beamforming strategies. Use when the user has predictions and gold and needs to compute Energy Efficiency.
3 -
georgeqle Skill Slim Audit 2Audit codebase for opportunities to reduce lines of code while preserving functionality, performance, and quality
1 -
georgeqle Skill Youtube Audit 2Analyze a YouTube channel with evidence-first metadata, transcripts, performance fields, portfolio shape, and repeated content-quality patterns
1 -
georgeqle Skill Repo Glossary 2Audit and reconcile the shared project glossary — find stale terms, missing definitions, conflicts, and gaps across research docs
1 -
georgeqle Skill Quality Sweep 2Audit and implement behavior-preserving cleanup across types, dead code, dependencies, errors, and comments
1 -
georgeqle Skill Devtool Docs Audit 3Use only for developer-facing products; audit docs for quickstart clarity, examples, API reference, troubleshooting, and migration paths
1 -
georgeqle Skill Devtool Docs Audit 4Use only for developer-facing products; audit docs for quickstart clarity, examples, API reference, troubleshooting, and migration paths
1 -
georgeqle Skill Repo Glossary 3Audit and reconcile the shared project glossary — find stale terms, missing definitions, conflicts, and gaps across research docs
1 -
georgeqle Skill Quality Sweep 3Audit and implement behavior-preserving cleanup across types, dead code, dependencies, errors, and comments
1 -
georgeqle Skill Devtool Docs Audit 6Use only for developer-facing products; audit docs for quickstart clarity, examples, API reference, troubleshooting, and migration paths
1 -
georgeqle Skill Devtool Docs Audit 7Use only for developer-facing products; audit docs for quickstart clarity, examples, API reference, troubleshooting, and migration paths
1 -
georgeqle Skill Reconcile Research 2Cross-document consistency audit across research outputs — find contradictions, stale assumptions, and gaps
1 -
bytesagain Bundle Bytesagain Meme Coin ScannerScan meme coins for scam signals, rug-pull risk, and on-chain audit flags. Use when evaluating tokens, auditing contracts, checking liquidity lock status.
12 -
levalencia Bundle QA ExpertThis skill should be used when establishing comprehensive QA testing processes for any software project. Use when creating test strategies, writing test cases following Google Testing Standards, executing test plans, tracking bugs with P0-P4 classification, calculating quality metrics, or generating progress reports. Includes autonomous execution capability via master prompts and complete documentation templates for third-party QA team handoffs. Implements OWASP security testing and achieves 90% coverage targets.
3 -
levalencia Skill Senior BackendDesigns and implements backend systems including REST APIs, microservices, database architectures, authentication flows, and security hardening. Use when the user asks to "design REST APIs", "optimize database queries", "implement authentication", "build microservices", "review backend code", "set up GraphQL", "handle database migrations", or "load test APIs". Covers Node.js/Express/Fastify development, PostgreSQL optimization, API security, and backend architecture patterns.
3 -
levalencia Skill Qms Audit ExpertISO 13485 internal audit expertise for medical device QMS. Covers audit planning, execution, nonconformity classification, and CAPA verification. Use for internal audit planning, audit execution, finding classification, external audit preparation, or audit program management.
3 -
levalencia Bundle Repomix Safe MixerSafely package codebases with repomix by automatically detecting and removing hardcoded credentials before packing. Use when packaging code for distribution, creating reference packages, or when the user mentions security concerns about sharing code with repomix.
3 -
levalencia Bundle Spring Boot REST API StandardsProvides REST API design standards and best practices for Spring Boot projects. Use when creating or reviewing REST endpoints, DTOs, error handling, pagination, security headers, HATEOAS and architecture patterns.
3 -
levalencia Skill Information Security Manager Iso27001ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use for ISMS design, security risk assessment, control implementation, ISO 27001 certification, security audits, incident response, and compliance verification. Covers ISO 27001, ISO 27002, healthcare security, and medical device cybersecurity.
3 -
sandeeprdy1729 Skill Risk Management 2Comprehensive guide to risk management. Master the concepts, implementation, best practices, and real-world applications of risk management in professional environments.
1 -
sandeeprdy1729 Skill Quantum Cryptography 2Comprehensive guide to quantum cryptography. Master the concepts, implementation, best practices, and real-world applications of quantum cryptography in professional environments.
1 -
jantoniofc Skill Click Path AuditTrace every user-facing button/touchpoint through its full state change sequence to find bugs where functions individually work but cancel each other out, produce wrong final state, or leave the UI in an inconsistent state. Use when: systematic debugging found no bugs but users report broken butt...
6 -
jantoniofc Bundle Backend DevelopmentBuild robust backend systems with modern technologies (Node.js, Python, Go, Rust), frameworks (NestJS, FastAPI, Django), databases (PostgreSQL, MongoDB, Redis), APIs (REST, GraphQL, gRPC), authentication (OAuth 2.1, JWT), testing strategies, security best practices (OWASP Top 10), performance opt...
6 -
jantoniofc Bundle Tech Stack EvaluatorTechnology stack evaluation and comparison with TCO analysis, security assessment, and ecosystem health scoring. Use when comparing frameworks, evaluating technology stacks, calculating total cost of ownership, assessing migration paths, or analyzing ecosystem viability.
6 -
sickn33 Skill Security AuditComprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.
45.1k -
sickn33 Skill Avoid AI WritingAudit and rewrite content to remove 21 categories of AI writing patterns with a 43-entry replacement table
45.1k -
sickn33 Skill Web Security TestingWeb application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and access control issues.
45.1k -
ranbot-ai Skill Threat Modeling ExpertExpert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security requirement extraction. Use for security architecture r...
6 -
sickn33 Skill Wordpress Plugin DevelopmentWordPress plugin development workflow covering plugin architecture, hooks, admin interfaces, REST API, and security best practices.
45.1k -
danstrem2 Bundle Test MasterUse when writing tests, creating test strategies, or building automation frameworks. Invoke for unit tests, integration tests, E2E, coverage analysis, performance testing, security testing.
2 -
danstrem2 Bundle Dont Hack Me別駭我!基本安全檢測 — Security self-check for Clawdbot/Moltbot. Run a quick audit of your clawdbot.json to catch dangerous misconfigurations — exposed gateway, missing auth, open DM policy, weak tokens, loose file permissions. Auto-fix included. Invoke: "run a security check" or "幫我做安全檢查".
2
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include qa-expert, repomix-safe-mixer, energy-efficiency. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.