Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
google Bundle API Reference AuditAudits whether ADK API reference docs and version-pinned strings are up to date across all language SDKs. Compares in-repo versions against upstream releases and package registries, then reports what needs bumping and which process to follow, and emits an executable plan only when asked. Triggers on "audit API reference", "check API ref docs", "are API docs up to date", "bump API doc versions", "check SDK doc versions".
14.4k -
laravel Bundle Laravel Best PracticesApply this skill whenever writing, reviewing, or refactoring Laravel PHP code. This includes creating or modifying controllers, models, migrations, form requests, policies, jobs, scheduled commands, service classes, and Eloquent queries. Triggers for N+1 and query performance issues, caching strategies, authorization and security patterns, validation, error handling, queue and job configuration, route definitions, and architectural decisions. Also use for Laravel code reviews and refactoring existing Laravel code to follow best practices. Covers any task involving Laravel backend PHP code patterns.
-
lltx Bundle Audit Agents Md审计或精简指定项目、全局的技能与 AGENTS.md,定位触发过宽、流程过重、授权冲突和失效引用。用户要求审计这些指令或按新模型能力调整时使用。
-
pashov Bundle Solidity AuditorSecurity audit of Solidity code while you develop. Trigger on "audit", "check this contract", "review for security". Modes - default (full repo) or a specific filename.
-
photon-hq Bundle Photon CLIUse when working with the Photon CLI — the `photon` binary (alias `pho`). Reach for this skill to set up / bootstrap Photon for a user and run it yourself non-interactively (create a project, capture the id + secret, verify) — when the user says "set this up for me," that is your job to do, not hand back. Also covers running any CLI command, authenticating (device-authorization login / logout / whoami / auth status), managing projects (create, show, list, rename, regenerate the Spectrum API secret, delete, open in the dashboard), managing Spectrum resources (lines, users, platforms, profile, avatar), resolving config and environment (PHOTON_PROJECT_ID, PHOTON_TOKEN, PHOTON_API_HOST, credentials storage, multi-backend), and billing/upgrades (plans, checkout, manage, `projects upgrade`). Answers operational questions like "how many lines do I have?", "what's my project secret?", "how do I make this a business line?", and "how do I point the CLI at a different backend?". This is the entry point; the happy-path s
-
vercel-eve Bundle Technical WritingWrite, edit, review, or audit user-facing documentation for the eve repository. Use for changes under docs/, documentation tied to eve APIs or CLI behavior, docs work based on Slack or support feedback, and requests to make eve docs clearer, more natural, or less AI-patterned while verifying claims against current source, tests, CLI help, public releases, and repository conventions.
-
zjfls Bundle Skill System Analyst系统/代码库架构分析与技术文档编排(mindmap 驱动,分章节 append/render),生成可视化(Mermaid)且注意 XSS 安全的深度报告。
-
better-auth Skill Better Auth Security Best PracticesConfigure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for Better Auth. Use when users need to secure their auth setup, prevent brute force attacks, or harden a Better Auth deployment.
-
better-auth Skill Two Factor Authentication Best PracticesConfigure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin. Use when users need MFA, multi-factor authentication, authenticator setup, or login security with Better Auth.
-
better-auth Skill Email And Password Best PracticesConfigure email verification, implement password reset flows, set password policies, and customise hashing algorithms for Better Auth email/password authentication. Use when users need to set up login, sign-in, sign-up, credential authentication, or password security with Better Auth.
-
howell5 Skill Subtraction Audit代码减法审计与反腐化工程。用于给代码库做减法审计(找死代码/重复实现/死依赖/投机性泛化/死门禁),产出证据驱动的删除候选清单并按风险分级执行;也用于给 AI 重度开发的仓库搭建防膨胀门禁(CI、钩子、死代码基线)。核心信念:代码最终会腐化,人写机器写都一样;防腐化唯一可靠的方式是把约束变成机器门禁、把为什么变成文档、把删除变成一等工作流。方法学源自 DeepSeek Harness(dsh-find-simplifications)。
-
lingui Bundle Find Unwrapped StringsAudit a Lingui project for hardcoded user-facing strings that were never wrapped in macros. Use when asked to find untranslated, unwrapped, or hardcoded strings, to check i18n coverage, to audit what an i18n setup or migration missed, or when text renders in the source language after everything was supposedly translated.
-
specstoryai Bundle Specstory GuardInstall a pre-commit hook that scans .specstory/history for secrets before commits. Run when user says "set up secret scanning", "install specstory guard", "protect my history", or "check for secrets".
-
thananon Skill ScrutinizeOutsider-perspective end-to-end review of a plan, PR, or code change. First questions intent and whether a simpler/more elegant approach would achieve the same goal, then traces the actual code path (not just the diff) to verify the change does what it claims. Output is concise, actionable, and every call carries its rationale. Trigger on /scrutinize and proactively whenever the user asks to review, audit, sanity-check, or get a second opinion on a plan, PR, diff, design doc, or proposed code change.
-
danjdewhurst Skill Revision ContinuityThis skill should be used when the user asks to revise a chapter, edit prose, continuity check, find inconsistencies, audit character state, check timeline consistency, line edit, developmental edit, polish a draft, or prepare existing story material for the next revision pass.
-
frappe Skill Quality Code ReviewReview code for any Frappe application — a checklist distilled from years of engineering practice on correctness, security, performance, concurrency, readability, API design, and testing. Use this when reviewing a diff, a PR, or a piece of code for quality and security, or when you want a reviewer's checklist grounded in hard-won Frappe/ERPNext lessons.
-
frappe Skill Draft Security AdvisoryTurn a vulnerability report into a publication-ready GitHub Security Advisory.
-
juxt Skill WeedWeed the Allium garden. Find where Allium specifications and implementation code have diverged, and help resolve the divergences. Use when the user wants to check spec-code alignment, compare specs against implementation, audit for spec drift or violations, sync specs with code or code with specs, or verify whether the implementation matches what the spec says.
-
okx Bundle Okx Agentic WalletUse this skill whenever the user wants to use OKX Onchain OS / onchainos CLI / agentic wallet for wallet state or on-chain actions. Triggers: onchainos, Onchain OS wallet, agentic wallet; wallet login/status/account/address/balance/holdings/deposit/receive/send/transfer; on-chain swap/DEX trade/buy/sell/convert; bridge; Gas Station; contract calls; transaction history/status; Bitcoin UTXOs, BRC-20, inscriptions; signing; approvals; wallet export/policy; token or DApp security checks; or audit log.
-
sentinelcore Skill Roblox SecurityUse when writing Roblox game scripts that handle player actions, currencies, stats, damage, or any RemoteEvent/RemoteFunction communication. Use when reviewing code for exploitable patterns, implementing anti-cheat logic, validating client requests on the server, or setting up rate limiting.
-
superagents-lab Bundle Audit Xcode Security SettingsAudit and enable security-oriented Xcode build settings. Progressively enables compiler warnings, static analyzer checkers, and Enhanced Security features. Use when: user wants to secure their Xcode project, audit security settings, enable hardening, review security posture of build configuration, set up security-focused static analysis, enable static analysis, improve warning coverage, harden diagnostics, or catch more bugs at compile time in C/C++/Objective-C/Swift. SKIP: network security (TLS/ATS), code signing, privacy APIs.
-
wubing2023 Bundle Paper SpineWrite, rewrite, or build a paper or report (journal, conference, report, review, competition) end to end, then output LaTeX/PDF/Word. The main PaperSpine entry point that orchestrates every step.
-
biw Bundle Setup Cloudflare Pr PreviewsSet up, audit, or repair Cloudflare Workers PR previews with aliased URLs, branch-isolated D1 databases, migrations, binding injection, stable environments, and PR-close cleanup.
-
nhadaututtheky Skill Memory AuditComprehensive memory quality review across 6 dimensions: purity, freshness, coverage, clarity, relevance, and structure. Generates prioritized findings with specific memory references and actionable recommendations.
-
payloadcms Bundle PayloadUse when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API). Use when debugging validation errors, security issues, relationship queries, transactions, or hook behavior.
-
payloadcms Skill Audit DependenciesUse when fixing dependency vulnerabilities, running pnpm audit, or when the audit-dependencies CI check fails
-
webmaxru Bundle Github Agentic WorkflowsAuthors, reviews, installs, and debugs GitHub Agentic Workflows in repositories, including workflow markdown, frontmatter, gh aw compile and run flows, safe outputs, security guardrails, and operational patterns. Use when creating or maintaining GH-AW automation. Don't use for standard deterministic GitHub Actions YAML, generic CI pipelines, or non-GitHub automation systems.
-
ngmeyer Bundle Claude MdAll-in-one skill for CLAUDE.md files. Two modes: `audit` finds drift (claimed facts no longer matching code), leaked secrets, duplicates, instruction-budget bloat, and prescriptive-vs-descriptive imbalance across all CLAUDE.md files in your projects. `improve` measures one CLAUDE.md against Anthropic's official best practices (200-line budget, removability test, emphasis tuning, 3-tier hierarchy) plus community-validated guidance, then proposes concrete rewrite diffs applied only after user approval. Default behavior auto-detects: in a project with a CLAUDE.md → improve mode; otherwise → audit all. Use when: 'audit claude.md', 'check claude md drift', 'lint CLAUDE.md', 'claude md audit', 'refresh instructions', 'improve CLAUDE.md', 'restructure CLAUDE.md', 'tune CLAUDE.md', 'apply CLAUDE.md best practices', 'is my CLAUDE.md good', 'CLAUDE.md is too long', 'rebalance CLAUDE.md', or quarterly as a hygiene check.
-
ngmeyer Bundle SkillforgeForge new Claude Code skills or optimize existing ones to V2. Two modes — `forge` scaffolds a new skill (frontmatter, progressive disclosure, helper scripts, mandatory Gotchas, iterate-then-extract); `optimize` makes an existing skill measurably better at its OUTCOME, not just its packaging (quality audit + domain outcome-research + changelog + V1-vs-V2 verification). Use when the user wants to create, write, build, scaffold, improve, upgrade, or optimize a skill.
-
ngmeyer Bundle Rigorous ReviewAudit a web codebase for security, performance, correctness, and refactoring improvements WITHOUT changing any outward-facing behavior. Fans out parallel read-only reviewers, scores findings on two axes (severity × confidence), suppresses predictable false positives, validates survivors with an INDEPENDENT wave (not self-recheck), classifies safe vs. gated, and writes a report. Applies only behavior-preserving fixes, and only on request. Use when: 'rigorous review', 'hardening audit', 'security and performance audit', 'internal audit', 'harden the codebase', 'audit for security/perf/refactoring', 'tech-debt audit', 'review this codebase without changing behavior'.
-
ngmeyer Bundle Adversarial ReviewSingle-critic adversarial stress test of a known artifact — a PR, draft, spec, plan, code file, or argument. The reviewer actively tries to break it: edge cases, hidden assumptions, failure modes, logical inconsistencies, security gaps, scalability cliffs, surprising user behavior, counter-examples. Distinct from /council-review, which is for OPEN questions and decisions; this skill is for stress-testing a finished thing. Use when: 'adversarial review', 'red team this', 'find what is wrong', 'tell me why this is wrong', 'pre-mortem this', 'attack this', 'stress test', 'devil's advocate', 'try to break this', or before shipping any artifact where a missed edge case is expensive.
-
ngmeyer Bundle Weekly Setup ImprovementsAudit recent work in a folder and produce a forward-looking self-improvement report. Reviews files modified in the past week, git activity, file-type distribution, and recurring task patterns; writes a 5-section weekly-setup-improvements.md with concrete updates for context files, ideas for new skills, workflow gaps to close, files to clean up, and what's working well enough to leave alone. Cross-platform; safe to schedule weekly via /schedule. Use when: 'weekly review', 'weekly self audit', 'improve my setup', 'what should I clean up', 'suggest new skills', 'self improvement loop', 'weekly setup improvements', or before a planning week.
-
ruchernchong Skill SecurityRun security audit with GitLeaks pre-commit hook setup and code analysis
-
codexstar69 Bundle Bug HunterPrecision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects. Uses deterministic risk triage, evidence-bounded retrieval, Hunter/Skeptic/Referee review, optional hybrid verification, and explicit immutable Fixer scope. Scan-only and single-pass by default; complete-coverage loops, edits, autonomous fixes, and commits each require explicit intent. Use for code review, security audits, regression hunting, PR review, and evidence-backed remediation planning in skills-capable coding agents.
-
codexstar69 Skill RefereeFinal arbiter for Bug Hunter. Receives Hunter findings and Skeptic challenges, independently re-reads code, and delivers authoritative verdicts with CVSS scoring and proof-of-concept generation for security findings.
-
codexstar69 Skill Commit Security ScanScan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context. Use whenever the user asks for PR security review, commit-diff scanning, staged-change security checks, branch-comparison security review, or pre-merge security analysis of changed code.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include api-reference-audit, skill-system-analyst, laravel-best-practices. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.