Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Evidence CollectorPlan and manage security evidence collection for compliance audits and assessments. Use this skill to identify required evidence, track collection status, and ensure audit readiness.
567 -
majiayu000 Bundle Evidence StandardsEvidence citation and domain scope standards for Neo4j subagents. Prevents hallucination and ensures audit trail.
567 -
majiayu000 Bundle Financial AnalysisComprehensive financial analysis workflow covering ratio analysis, trend analysis, benchmarking, and variance analysis. Delivers documented, audit-ready insights.
567 -
majiayu000 Bundle Fullstack SecuritySecurity and performance - hardening, optimization, auditing
567 -
majiayu000 Bundle Gemini Peer Review[CLAUDE CODE ONLY] Leverage Gemini CLI for AI peer review, second opinions on architecture and design decisions, cross-validation of implementations, security analysis, alternative approaches, and hol
567 -
majiayu000 Bundle Google Docs SheetsExport Google Docs and Google Sheets (spreadsheets) to Markdown files or stdout. Use when asked to fetch, download, or ingest Google Docs/Sheets content for summarization, analysis, or context loading. Tries gcloud ADC first with browser OAuth fallback.
567 -
majiayu000 Bundle Goth Echo SecurityThis skill should be used when the user asks to "integrate goth with echo", "oauth echo framework", "echo authentication", "goth session management", "oauth security", "secure oauth", "gorilla sessions", or needs help with session storage, security patterns, or Echo framework integration for Goth.
567 -
majiayu000 Bundle Bash Script ValidatorValidates existing .sh/.bash scripts via ShellCheck 0.11.0+ static analysis, syntax/security/portability checks. Use when debugging SC codes, auditing shell scripts, or checking shell best practices.
567 -
majiayu000 Bundle Generate BriefingGenerate the Monday Morning CEO Briefing — a weekly business audit that summarizes revenue, completed tasks, bottlenecks, and proactive suggestions. Reads from Business_Goals.md, vault/Done items, accounting summaries, and social media activity. Use when triggered by the weekly scheduler (Sundays at 8 PM) or when the user requests a business briefing or audit report.
567 -
majiayu000 Bundle Backend Atomic CommitPedantic backend pre-commit + atomic-commit skill for Django/Optimo repos that enforces local repo rules, pre-commit hooks, and security helpers (no AI signatures in commit messages).
567 -
majiayu000 Bundle Code Review StandardsComprehensive code review standards covering security, quality, performance, testing, and documentation. Includes checklists, common issues, and best practices for thorough code reviews.
567 -
majiayu000 Bundle Creating Claude HooksUse when creating or publishing Claude Code hooks - covers executable format, event types, JSON I/O, exit codes, security requirements, and PRPM package structure
567 -
majiayu000 Bundle Cynara Policy CheckerQueries Cynara database and validates runtime privilege policies. Coordinates access control decisions across system services.
567 -
majiayu000 Bundle Dependency ManagementManage project dependencies effectively. Use when adding, updating, or auditing dependencies. Covers version management, security scanning, and lockfiles.
567 -
majiayu000 Bundle Dev Swarm Code ReviewReview and audit code quality, architecture, and implementation. Verify code meets design specs, find bugs, identify improvements, and create change/bug/improve backlogs. Use when reviewing completed code, auditing implementations, or ensuring quality.
567 -
majiayu000 Bundle Discord List ChannelsList all channels in a Discord guild/server via the Discord API. Use this skill when the user wants to see all channels, find specific channels, or audit server structure.
567 -
majiayu000 Bundle Healthcare ComplianceHIPAA compliance, healthcare regulations, privacy and security standards for medical organizations and providers
567 -
majiayu000 Bundle Klingai Audit LoggingImplement comprehensive audit logging for Kling AI operations. Use when tracking API usage, compliance requirements, or security audits. Trigger with phrases like 'klingai audit', 'kling ai logging', 'klingai compliance log', 'video generation audit trail'.
567 -
majiayu000 Bundle Magento Code ReviewerReviews Magento 2 code for quality, security, performance, and compliance with PSR-12 and Magento coding standards. Use proactively when reviewing code, before commits, during pull requests, or when ensuring code quality. Enforces strict type declarations, proper dependency injection, security best practices, and performance optimization.
567 -
majiayu000 Bundle Moai Security SecretsEnterprise Skill for advanced development
567 -
majiayu000 Bundle Moai System UniversalThe ultimate unified development skill combining 25+ programming languages, 9+ BaaS providers, 6+ development functions, and 15+ security capabilities with AI orchestration, Context7 integration, enterprise compliance, and end-to-end project automation
567 -
majiayu000 Bundle Security Headers ConfigurationConfigures HTTP security headers to protect against XSS, clickjacking, and MIME sniffing attacks. Use when hardening web applications, passing security audits, or implementing Content Security Policy.
567 -
majiayu000 Bundle Windsurf Dependency ManagementAnalyze and update dependencies with vulnerability scanning. Activate when users mention "update dependencies", "security audit", "npm audit", "vulnerability scan", or "dependency updates". Handles dependency analysis and updates. Use when working with windsurf dependency management functionality. Trigger with phrases like "windsurf dependency management", "windsurf management", "windsurf".
567 -
majiayu000 Bundle 30 02 Convergence AuditFind semantic duplication — different code doing the same thing written by different sessions. Walks the codebase, adds @purpose markers, builds an intent registry, and flags convergence failures. Uses Delphi for full audits.
567 -
majiayu000 Bundle Authentication SecurityАвтоматизация JWT аутентификации, Telegram OAuth и security middleware
567 -
majiayu000 Bundle Node Package ManagementReference guide for npm, pnpm, yarn, and bun package managers. Covers workspace configuration, security audits, troubleshooting, and migration between package managers. Use for complex monorepo setup, debugging package issues, or deep package manager reference.
567 -
majiayu000 Bundle Audit Protocol ComplianceSystematic audit of session for task protocol compliance violations with documentation fix recommendations
567 -
majiayu000 Bundle Docs Alignment MaintainerCheck and maintain documentation alignment across repositories in a workspace with a two-pass workflow (audit first, then safe targeted fixes), including language-aware checks for Swift, JavaScript/TypeScript, Python, and Rust. Use when running scheduled automation for repo hygiene, when docs may drift from manifests/tooling, or when you need a Markdown + JSON alignment report with optional bounded auto-fixes.
567 -
majiayu000 Bundle Spec Driven DocumentationAutomated documentation generation, auditing, and remediation with structural anti-skip enforcement. Supports 3 workflows: Generation (greenfield/brownfield), Audit (4-dimension DevEx scoring), and Fix (automated/interactive remediation). Uses Execute-Verify-Gate pattern at every step. Designed to prevent token optimization bias through lean orchestration, fresh-context subagent delegation, per-phase reference loading, and binary CLI gate enforcement. Use when generating project documentation, updating docs after story completion, or analyzing documentation coverage.
567 -
majiayu000 Bundle Spec Driven LifecycleCoordinates spec-driven development lifecycle from Epic -> Sprint -> Story -> Architecture -> Development -> QA -> Release with structural anti-skip enforcement. Manages story lifecycle across 11 workflow states, enforces 4 quality gates, and orchestrates skill invocation. Replaces spec-driven-lifecycle as the unified lifecycle coordinator. Use when starting sprints, managing story workflow progression, auditing deferrals, running sprint retrospectives, or coordinating multi-story releases. Always use this skill when /orchestrate, /create-sprint, or /audit-deferrals is invoked.
567 -
majiayu000 Bundle Review Race Conditions OpenOpen Audit for race conditions in timers, hotkeys, callbacks, and shared state
567 -
majiayu000 Bundle Threat Modeling MindmapBuild a mental and visual map of the target application before hunting — entry points, trust boundaries, data flows, and high-value functionality. Use when user has scope parsed and wants to plan WHERE to hunt rather than diving into recon.
567 -
majiayu000 Bundle Betterauth Tanstack ConvexStep-by-step guide for setting up Better Auth authentication with Convex and TanStack Start. This skill should be used when configuring authentication in a Convex + TanStack Start project, troubleshooting auth issues, or implementing sign up/sign in/sign out flows. Covers installation, environment variables, SSR authentication, route handlers, and the expectAuth pattern.
567 -
majiayu000 Bundle Detecting Lateral Movement<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Geldwaesche Kyc OnboardingKYC-Onboarding neuer Kunden mit Identifizierung Risikoklassifizierung und Freigabe nach GwG. Anwendungsfall neue Geschäftsbeziehung soll aufgenommen werden und GwG-Identifizierung muss durchgeführt werden. Normen §§ 10 11 GwG allgemeine Sorgfaltspflichten § 15 GwG verstaerkte Sorgfaltspflicht § 14 GwG vereinfachte Sorgfaltspflicht. Prüfraster Identifizierung Zweck Geschäftsbeziehung Mittelherkunft Eigentumsstruktur Risikoeinstufung Freigabe. Output KYC-Akte mit Identifizierungsprotokoll Risikoeinstufung Freigabevermerk und periodischer Aktualisierungsplan. Abgrenzung zu geldwäsche-pep-hochrisikoland und geldwäsche-ubo-wirtschaftlich-berechtigte.
567 -
majiayu000 Bundle Git Guardrails Claude CodeInstall a Claude-Code PreToolUse hook that blocks destructive git commands (push variants including force-push, hard reset, force clean, branch -D, checkout/restore overwrites) before Bash runs them. Use when the user wants git safety rails, force-push prevention, or repository-wipe protection.
567
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include evidence-collector, evidence-standards, financial-analysis. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.