Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
diegosouzapw Bundle API Fuzzing Bug BountyThis skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug b...
54 -
diegosouzapw Bundle Backend Dev 2Comprehensive backend development workflow that orchestrates expert analysis, architecture design, implementation, and deployment using the integrated toolset. Handles everything from API design and database architecture to security implementation and DevOps automation.
54 -
diegosouzapw Bundle Payload 3Use when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API). Use when debugging validation errors, security issues, relationship queries, transactions, or hook behavior.
54 -
diegosouzapw Bundle Security Hardening 2Security best practices for web applications. Covers OWASP Top 10, authentication, authorization, input validation, CSP, and secure headers.
54 -
diegosouzapw Bundle Scanning ToolsThis skill should be used when the user asks to "perform vulnerability scanning", "scan networks for open ports", "assess web application security", "scan wireless networks", "detec...
54 -
diegosouzapw Bundle Vitest Testing 2Write and run Vitest unit and integration tests. Use when creating tests, debugging test failures, or checking test coverage.
54 -
diegosouzapw Bundle Code Review 6Professional code review for quality, security, and best practices. Use when reviewing pull requests, code changes, or when asked to review code quality.
54 -
diegosouzapw Bundle Code Reviewer 3综合代码审查 skill,支持 TypeScript、JavaScript、Python、Swift、Kotlin、Go。包括自动代码分析、最佳实践检查、安全扫描和审查清单生成。当审查 Pull Request、提供代码反馈、识别问题或确保代码质量标准时使用此 skill。
54 -
diegosouzapw Bundle Skill Authoring 2Create high-quality skills: scoped, procedural, and durable. Prefer updates over duplicates. Use when working with SKILL.md files, authoring new skills, improving existing skills, or understanding skill structure and best practices.
54 -
diegosouzapw Bundle Testing 5Test-first development process and test quality review. Use when writing new code, reviewing PRs, diagnosing flaky or failing tests, or improving test coverage. Also use when fixing bugs (write failing test first), adding features (test defines 'done'), or when tests pass but code doesn't work. Essential for TDD, test pyramid strategy, mocking decisions, AAA pattern, table-driven tests, and handling flaky tests.
54 -
diegosouzapw Bundle Testing 6Testing patterns and best practices for unit, integration, and E2E testing.
54 -
diegosouzapw Bundle File Path TraversalThis skill should be used when the user asks to "test for directory traversal", "exploit path traversal vulnerabilities", "read arbitrary files through web applications", "find LFI vu...
54 -
diegosouzapw Bundle Compliance Check 2You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards. Perform comprehensive compliance audits and provide implementation guidance for achieving and maintaining compliance.
54 -
diegosouzapw Bundle Security 2Application security best practices including OWASP Top 10, authentication, and data protection.
54 -
diegosouzapw Bundle Testing 7Access testing configuration and delegate to test-rig tool for test generation and execution
54 -
diegosouzapw Bundle Testing Patterns 2Jest testing patterns, factory functions, mocking strategies, and TDD workflow. Use when writing unit tests, creating test factories, or following TDD red-green-refactor cycle.
54 -
diegosouzapw Bundle Axiom IOS TestingUse when writing ANY test, debugging flaky tests, making tests faster, or asking about Swift Testing vs XCTest. Covers unit tests, UI tests, fast tests without simulator, async testing, test architecture.
54 -
diegosouzapw Bundle Security 3Security audits, vulnerability detection, and secure coding. Use for security reviews, auth implementation, or OWASP compliance.
54 -
diegosouzapw Bundle Burp Suite TestingThis skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp ...
Audited 54 -
diegosouzapw Bundle Devs Security CoreComprehensive application security expertise covering authentication, authorization, OWASP Top 10, and security best practices. Use when (1) Implementing authentication (JWT, OAuth2, sessions, OAuth for CLI/TUI/desktop apps), (2) Adding authorization (RBAC, ABAC, RLS with Supabase/PostgreSQL), (3) Security auditing code or infrastructure, (4) Setting up security infrastructure (headers, CORS, CSP, rate limiting), (5) Managing secrets and credentials, (6) Preventing OWASP Top 10 vulnerabilities (injection, XSS, CSRF, etc.), (7) Reviewing code for security issues, (8) Configuring secure web applications in TypeScript, Python, or Rust. Automatically triggered when working with authentication/authorization systems, security reviews, or addressing security vulnerabilities.
54 -
diegosouzapw Bundle Security Hardening 3Comprehensive security implementation covering authentication, authorization, input validation, vulnerability detection, compliance, and security standards (OWASP, ISO 27001, SOC2, CWE). Use when securing applications, APIs, and infrastructure.
54 -
diegosouzapw Bundle Vibe Security 2This skill helps Claude write secure web applications. Use when working on any web application to ensure security best practices are followed.
54 -
diegosouzapw Bundle Vibe Security 3This skill helps Claude write secure web applications. Use when working on any web application to ensure security best practices are followed.
54 -
diegosouzapw Bundle Code Reviewer 6Reviews code changes in pull requests for the Morphir Moonbit monorepo. Checks for code quality, best practices, security issues, and adherence to project conventions. Use when reviewing PRs or code changes before merging.
54 -
diegosouzapw Bundle Security 6Reviews code for security vulnerabilities, identifies security issues, suggests improvements
54 -
diegosouzapw Bundle API Design 17This skill should be used when designing APIs, choosing between REST, GraphQL, or gRPC, implementing API protocols, or ensuring API security. It provides guidance on RESTful APIs, GraphQL, gRPC, HTTP/WebSockets, and API best practices.
54 -
diegosouzapw Bundle Top Web VulnerabilitiesThis skill should be used when the user asks to "identify web application vulnerabilities", "explain common security flaws", "understand vulnerability categories", "learn about inject...
54 -
diegosouzapw Bundle Dev Swarm Tech Specs 2Define technical specifications including tech stack, security, theme standards (from UX mockup), coding standards, and testing standards. Use when user asks to define tech specs, choose tech stack, or start Stage 7 after architecture.
54 -
diegosouzapw Bundle Broken AuthenticationThis skill should be used when the user asks to "test for broken authentication vulnerabilities", "assess session management security", "perform credential stuffing tests", "evaluate ...
54 -
diegosouzapw Bundle Moai Workflow Testing 2AI-powered enterprise web application testing orchestrator with Context7 integration, intelligent test generation, visual regression testing, cross-browser coordination, and automated QA workflows for modern web applications
54 -
diegosouzapw Bundle Security Review 3Use when performing security audits, vulnerability assessments, penetration testing, or when asked to find security issues. Use when encountering code that handles user input, executes commands, reads files, or makes network requests.
54 -
diegosouzapw Bundle Testing Anti Patterns 2Common testing mistakes to avoid for reliable, maintainable tests
54 -
diegosouzapw Bundle Backend Developer 3Specialist for TypeScript backend development including Node.js servers, NestJS applications, APIs, databases (PostgreSQL, MongoDB, Redis), authentication, testing, deployment, server-side code, microservices, database queries, migrations, controllers, services, repositories, and middleware. Use for ANY work involving .ts backend files, server-side architecture, performance optimization, and backend security.
54 -
diegosouzapw Bundle Senior Backend 4Comprehensive backend development skill for building scalable backend systems using Node.js, Express, Go, Python, PostgreSQL, GraphQL, REST APIs. Includes API scaffolding, database optimization, security implementation, and performance tuning. Use when designing APIs, optimizing database queries, implementing business logic, handling authentication/authorization, or reviewing backend code.
54 -
diegosouzapw Bundle Senior Backend 5This skill should be used when the user asks to "design REST APIs", "optimize database queries", "implement authentication", "build microservices", "review backend code", "set up GraphQL", "handle database migrations", or "load test APIs". Use for Node.js/Express/Fastify development, PostgreSQL optimization, API security, and backend architecture patterns.
54 -
diegosouzapw Bundle Security Audit 2Invoke when reviewing security-sensitive code: authentication, authorization, payment processing, data protection, or any code handling sensitive information.
54
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security, api-design, top-web-vulnerabilities. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.