Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
majiayu000 Bundle Subagent Driven Development 3The implementation engine. Routed to by /sprint (full plan, autonomous) and by executing-plans (scoped batch, checkpoint-gated). One fresh subagent per task — test-first via tdd — followed by spec-compliance review, quality review, and fresh-run verification. No single context accumulates drift, and nothing is accepted on a subagent's word.
567 -
majiayu000 Bundle Audit Tests 2Test quality audit — event replay, GEDCOM round-trip, domain edge cases, API contracts
567 -
majiayu000 Bundle Test Review 5Audit tests for missing edge cases after writing or reviewing test code. Use PROACTIVELY after implementing features or writing tests. Also available as /test-review.
567 -
majiayu000 Bundle Analyze 4Run code analyzers (unused packages, code quality, security). Use when user wants to analyze the codebase or runs /analyze.
567 -
majiayu000 Bundle Research 19Systematic research before planning - gather documentation, security concerns, tech stack analysis, and community insights. Use when user says "let's research", "research this", "investigate", "look into", or needs to understand a technology or feature before planning.
567 -
majiayu000 Bundle Backend API 8Design and implement RESTful API endpoints with proper HTTP methods, status codes, and consistent naming conventions. Use this skill when creating or modifying API routes, endpoints, or server-side request handlers. When working on files in src/pages/api/, files containing API route definitions, files implementing REST endpoints, files handling HTTP requests and responses, server middleware for API requests, API authentication and authorization logic, and files defining API versioning strategies. When designing URL structures for resources, implementing query parameter handling for filtering/sorting/pagination, setting up rate limiting for API endpoints, or configuring CORS and API security headers.
567 -
majiayu000 Bundle Content Strategist 2Strategic content planning for AEO dominance. Use when planning what content to create, identifying data study opportunities, finding terms to own, discovering zero-volume keywords, or auditing content lifecycle. Triggers on "content strategy", "what content", "content plan", "data study", "keyword research", "terms to own", "content audit".
567 -
majiayu000 Bundle Moai Alfred Code Reviewer 2Systematic code review guidance and automation. Apply TRUST 5 principles, check code quality, validate SOLID principles, identify security issues, and ensure maintainability. Use when conducting code reviews, setting review standards, or implementing review automation.
567 -
majiayu000 Bundle Skill Auditor 3Audit an existing SKILL.md against the unified AgentOps template (15 checks). Triggers: "audit skill", "skill quality review", "is this skill ready".
567 -
majiayu000 Bundle Security Review 6OWASP secure design review for code and architecture. Checks input validation, authentication, authorization, data protection.
567 -
majiayu000 Bundle Corrections Audit 2Use to analyze correction trends, surface recurring patterns, and graduate repeat corrections to guardrails or anti-patterns.
567 -
majiayu000 Bundle Wordpress 2WordPress framework guardrails, patterns, and best practices for AI-assisted development. Use when working with WordPress projects, or when the user mentions WordPress. Provides theme development, plugin architecture, REST API, blocks, and security guidelines.
567 -
majiayu000 Bundle Ln 620 Codebase Auditor 2Use when auditing the codebase through the evaluation platform with mandatory research, coordinated domain audit workers, and structured summaries.
567 -
majiayu000 Bundle Orchestrating Workflows 2Command workflow orchestration patterns for /code, /fix, /audit, and other implementation commands. Use when implementing features with /code, /fix, /audit commands, or when user mentions workflow, ワークフロー, RGRC, quality gates, 品質ゲート, completion criteria.
567 -
majiayu000 Bundle Audit 13Comprehensive codebase audit for release readiness. Parallel exploration of docs, code, config, tests, and specs to identify cruft, then interactive triage with clear action options.
567 -
majiayu000 Bundle Code Review 31Systematic security and quality review of uncommitted changes. Groups findings by severity.
567 -
majiayu000 Bundle Code Review 32Systematic code review covering security, performance, architecture, and style
567 -
majiayu000 Bundle Quality Gate 3Pre-merge quality gate — chains verify, review, and security audit into a pass/fail verdict
567 -
majiayu000 Bundle Better Auth 3Complete Better Auth - 40+ OAuth providers, 20+ plugins, all adapters, all frameworks. Use when implementing authentication, login, OAuth, 2FA, magic links, SSO, Stripe, SCIM, or session management.
567 -
majiayu000 Bundle Cryptography 2<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Fix 8Get fix intelligence for a vulnerability and propose concrete remediation for the current repository
567 -
majiayu000 Bundle Log Analysis 2<!-- Copyright (c) 2026 defconxt. All rights reserved. -->
567 -
majiayu000 Bundle Security 13Use when auditing security, checking for vulnerabilities, scanning for secrets, or reviewing dependencies. OWASP Top 10 audit with GitLeaks and dependency checks.
567 -
majiayu000 Bundle Research 20Research technical solutions, analyze architectures, gather requirements thoroughly. Use for technology evaluation, best practices research, solution design, scalability/security/maintainability analysis.
567 -
majiayu000 Bundle Research 21Technical research methodology with YAGNI/KISS/DRY principles. Phases: scope definition, information gathering, analysis, synthesis, recommendation. Capabilities: technology evaluation, architecture analysis, best practices research, trade-off assessment, solution design. Actions: research, analyze, evaluate, compare, recommend technical solutions. Keywords: research, technology evaluation, best practices, architecture analysis, trade-offs, scalability, security, maintainability, YAGNI, KISS, DRY, technical analysis, solution design, competitive analysis, feasibility study. Use when: researching technologies, evaluating architectures, analyzing best practices, comparing solutions, assessing technical trade-offs, planning scalable/secure systems.
567 -
majiayu000 Bundle Security Incident Response 2Handle vulnerability reports with coordinated disclosure, timely patches, and clear communication.
567 -
majiayu000 Bundle Performance Audit 3Profiling, benchmarking, Web Vitals audit, N+1 detection, and performance optimization
567 -
majiayu000 Bundle Code Reviewer 8Perform structured code reviews for quality and security. Checks OWASP top 10, code quality, and provides actionable feedback. Use when user says 'review code', 'PR review', 'security check', or 'is this safe'.
567 -
majiayu000 Bundle Review Code 5Review code for bugs, security vulnerabilities, API misuse, consistency issues, simplicity problems, or test coverage gaps by running internal reviews and a peer review in parallel and returning combined findings. Single-concern with a type argument, or full review with no argument. Use when the user asks to "review my code", "full code review", "review my changes", "check for bugs", "scan for bugs", "review correctness", "security audit", "find vulnerabilities", "review security", "check API usage", "verify against docs", "check for cross-file duplication", "review consistency", "check for code reuse", "review simplicity", "find untested code", or "review test coverage".
567 -
majiayu000 Bundle Validate Skill 3Validates Claude Code skills against official best practices from Anthropic documentation. Fetches latest documentation dynamically to ensure current standards. Checks frontmatter, structure, line count, descriptions, references, workflows, and provides actionable recommendations. Use when asked to validate skill, check skill quality, review skill, or audit skill compliance.
567 -
majiayu000 Bundle Orthogonal Phone VerificationVerify phone numbers using SMS one-time codes via the Didit API. Use when you need to confirm a user owns a phone number, implement SMS-based 2FA, or validate phone during signup/onboarding flows.
567 -
majiayu000 Bundle Security 14[Code Quality] Perform security review on specified scope
567 -
majiayu000 Bundle Skill Creator 33This skill should be used when the user asks to 'create a skill', 'improve a skill', 'edit a skill', 'add enforcement patterns', 'audit skill enforcement', or needs to substantially create or edit any SKILL.md file.
567 -
majiayu000 Bundle Testing 25Comprehensive test implementation across all domains including unit, integration, e2e, security, infrastructure, data pipelines, and ML models. Covers TDD/BDD workflows, test architecture, flaky test debugging, and coverage analysis.
567 -
georgeqle Skill Reconcile Research 3Cross-document consistency audit across research outputs — find contradictions, stale assumptions, and gaps
1 -
georgeqle Skill Reconcile Research 4Cross-document consistency audit across research outputs — find contradictions, stale assumptions, and gaps
1
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include performance-audit, code-reviewer, security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.