Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
diegosouzapw Bundle Security 7Generate Tekton Task that uses Trivy to scan generated container for vulnerabilities.
54 -
diegosouzapw Bundle Security Review 4Security audit for vulnerabilities, compliance issues, and sensitive data exposure. Use before production deployments or when reviewing security-sensitive code.
54 -
diegosouzapw Bundle Threat Modeling 2Threat modeling methodologies (STRIDE, DREAD), attack trees, threat modeling as code, and integration with SDLC for proactive security design
54 -
diegosouzapw Bundle Code Review 10Reviews code changes for quality, security, and best practices. Auto-invoke when implementation is complete and the workflow reaches the review step (step 9), or when changes are ready for pre-PR review.
54 -
diegosouzapw Bundle Anthropic Doc CoauthoringGuide users through a structured workflow for co-authoring documentation. Use when user wants to write documentation, proposals, technical specs, decision docs, or similar structured content. This workflow helps users efficiently transfer context, refine content through iteration, and verify the doc works for readers. Trigger when user mentions writing docs, creating proposals, drafting specs, or similar documentation tasks.
54 -
diegosouzapw Bundle Code Reviewer 9Review code changes for correctness, security, performance, and maintainability. Use after writing/modifying code or before merging, and produce prioritized findings with concrete fixes.
54 -
diegosouzapw Bundle Security Audit 3Audit codebase for security vulnerabilities, secret leakage, dependency risks, and configuration issues. Use before commits, when adding dependencies, or reviewing PRs. Enforces zero-secrets policy, dependency isolation, and secure build practices.
54 -
diegosouzapw Bundle Security Review 5Comprehensive security analysis and vulnerability assessment. Use this when reviewing code for security issues, analyzing potential vulnerabilities, or conducting security audits.
54 -
diegosouzapw Bundle Security Review 6Scan code for security vulnerabilities (hardcoded secrets, env var exposure, injection, auth issues), generate SECURITY.md guidelines, or verify compliance with existing security rules. Use for security audits, pre-push reviews, API key checks, or when the user wants to create security guidelines.
54 -
diegosouzapw Bundle Security Review 7Scan code changes for security vulnerabilities including OWASP Top 10, hardcoded secrets, injection flaws, and authentication issues. Use after implementation to catch security problems before marking a task complete.
54 -
diegosouzapw Bundle Better Auth Best Practices 2Better Auth framework reference — configuration, security, rate limiting, sessions, plugins, and production hardening. Use when configuring Better Auth, auditing auth security, adding plugins, or troubleshooting Heartwood.
54 -
diegosouzapw Bundle Pci Compliance 2Implement PCI DSS compliance requirements for secure handling of payment card data and payment systems. Use when securing payment processing, achieving PCI compliance, or implementing payment card security measures.
54 -
diegosouzapw Bundle Security Auditor 2Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat modeling, secure authentication (OAuth2/OIDC), OWASP standards, cloud security, and security automation. Handles DevSecOps integration, compliance (GDPR/HIPAA/SOC2), and incident response. Use PROACTIVELY for security audits, DevSecOps, or compliance implementation.
54 -
diegosouzapw Bundle Security Review 8Security vulnerability detection based on OWASP Top 10. Use when reviewing code for security issues.
54 -
diegosouzapw Bundle Security Review 9Perform security-focused code review to identify HIGH-CONFIDENCE vulnerabilities with real exploitation potential. Based on Anthropic's claude-code-security-review. Minimizes false positives with >80% confidence threshold. Use when reviewing PRs for security issues.
54 -
diegosouzapw Bundle Testing Patterns 4Vitest, Playwright, and testing strategies. Use when writing tests, setting up test infrastructure, or debugging test failures.
54 -
diegosouzapw Bundle Doc Coauthoring 2Guia os usuários através de um fluxo de trabalho estruturado para coautoria de documentação. Use quando o usuário quiser escrever documentação, propostas, especificações técnicas, documentos de decisão ou conteúdo estruturado semelhante. Este fluxo de trabalho ajuda os usuários a transferir contexto de forma eficiente, refinar o conteúdo através de iteração e verificar se o documento funciona para os leitores. Acione quando o usuário mencionar escrever documentos, criar propostas, redigir especificações ou tarefas de documentação semelhantes.
54 -
diegosouzapw Bundle Security Auditor 3Expert security auditor specializing in comprehensive security assessments, compliance validation, and risk management. Masters security frameworks, audit methodologies, and compliance standards with focus on identifying vulnerabilities and ensuring regulatory adherence.
54 -
diegosouzapw Bundle Security Audit 4Use when reviewing code for security vulnerabilities and OWASP top 10 issues
54 -
diegosouzapw Bundle Security Engineer 2Application security, vulnerability assessment ve secure coding practices için kullanılır. Authentication, authorization, OWASP Top 10 ve security audit konularında uzman.
54 -
diegosouzapw Bundle Security Review 10Review code for security vulnerabilities. Use when asked to "security review", "audit code", "find vulnerabilities", "check for security issues", "pentest review", or "security audit" a codebase or set of files.
54 -
diegosouzapw Bundle Anti Reversing Techniques 2Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Use when analyzing protected binaries, bypassing anti-debugging for authorized analysis, or understanding software protection mechanisms.
54 -
diegosouzapw Bundle Security Auditor 4Activates when user needs security review, vulnerability scanning, or secure coding guidance. Triggers on "security review", "find vulnerabilities", "is this secure", "check for injection", "security audit", "OWASP", "secure this code", or security-related questions.
54 -
diegosouzapw Bundle GRAPHQL Architect 3Master modern GraphQL with federation, performance optimization, and enterprise security. Build scalable schemas, implement advanced caching, and design real-time systems. Use PROACTIVELY for GraphQL architecture or performance optimization.
54 -
diegosouzapw Bundle Anti Reversing Techniques 3Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Use when analyzing protected binaries, bypassing anti-debugging for authorized analysis, or understanding software protection mechanisms.
54 -
diegosouzapw Bundle Temporal Python TestingTest Temporal workflows with pytest, time-skipping, and mocking strategies. Covers unit testing, integration testing, replay testing, and local development setup. Use when implementing Temporal workflow tests or debugging test failures.
54 -
diegosouzapw Bundle Auth Implementation Patterns 2Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues.
54 -
diegosouzapw Bundle Security Hardening 4Advanced security patterns including zero-trust architecture, secret management, CSP, and compliance frameworks
54 -
diegosouzapw Bundle Better Auth Best Practices 5Better Auth(TypeScript 認証フレームワーク)の統合ガイド。セットアップ、セッション管理、プラグイン、セキュリティ設定に精通。
54 -
diegosouzapw Bundle Auth Implementation Patterns 3Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues.
54 -
johnalbertini14-glitch Bundle Signl4Send and close SIGNL4 alerts using the SIGNL4 inbound webhook (team secret in URL).
1 -
johnalbertini14-glitch Bundle AuthyInject secrets into subprocesses via environment variables. You never see secret values — authy run injects them directly. Use for any command that needs API keys, credentials, or tokens.
1 -
johnalbertini14-glitch Bundle S3Work with S3-compatible object storage with proper security, lifecycle policies, and access patterns.
1 -
johnalbertini14-glitch Bundle PHPWrite solid PHP avoiding type juggling traps, array quirks, and common security pitfalls.
1 -
johnalbertini14-glitch Bundle IronclawSafety for AI agents. Real-time threat classification to detect malicious content before it causes agents harm.
1 -
johnalbertini14-glitch Bundle Chief Information Security OfficerLead security with infrastructure audits, vulnerability triage, compliance tracking, vendor assessment, and incident response.
1
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include auth-implementation-patterns, better-auth-best-practices, auth-implementation-patterns. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.