Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
brianlovin Skill Chrome Webstore Release BlueprintGuide a user end-to-end through setting up Chrome Web Store API release automation in any repository. Use when asked to walk someone through OAuth/CWS credential setup, refresh token creation, local/CI secret setup, version-based publish automation, and submission status checks.
-
evloghq Bundle Build Audit LogsBuild or review audit trails in TypeScript/JavaScript apps using evlog (pipelines, typed actions, denials, retention, compliance-style reviews). For application code, not for extending the evlog package.
-
llama-farm Skill Commit Push PrCommit changes, push to GitHub, and open a PR. Includes quality checks (security, patterns, simplification). Use --quick to skip checks.
-
tartinerlabs Bundle DepsUse when hardening a dependency supply chain, pinning versions, adding registry/security flags, or setting up Renovate. Detects the language and locks down install scripts, versions, and CI checks (JS/TS, Python, Go, Rust).
-
tartinerlabs Bundle CommitUse when committing changes, staging files, saving work, or making a git commit. Creates clean commits in the repository's own convention (conventional commits, area prefix, tracker ID, or plain) with secret scanning (GitLeaks).
-
tartinerlabs Bundle SecurityUse when auditing security, checking for vulnerabilities, scanning for secrets, or reviewing dependencies. Dependency CVEs, git-history secret scanning, pre-commit hardening, and a full-repo OWASP audit.
-
tartinerlabs Bundle Audit Xcode Security SettingsAudit and enable security-oriented Xcode build settings. Progressively enables compiler warnings, static analyzer checkers, and Enhanced Security features. Use when: user wants to secure their Xcode project, audit security settings, enable hardening, review security posture of build configuration, set up security-focused static analysis, enable static analysis, improve warning coverage, harden diagnostics, or catch more bugs at compile time in C/C++/Objective-C/Swift. SKIP: network security (TLS/ATS), code signing, privacy APIs.
-
greedychipmunk Bundle Supabase DeveloperExpert Supabase development with PostgreSQL, authentication, Row Level Security, Storage, Edge Functions, and Realtime subscriptions
-
alibaba-skill-up Bundle Code StatsAnalyzes code files and reports statistics including line counts, file counts by extension, and total size. Use this skill whenever the user wants to understand the composition of a codebase - asking about "how many lines of code", "what file types exist", "code distribution", or needing a quick audit of project size and structure. Make sure to invoke this skill when users mention analyzing codebases, counting lines, checking file distributions, or auditing code.
-
alibaba-skill-up Bundle Code Review AssistantTriggered when the user submits code or requests a code review. Automatically analyzes code quality, identifies potential bugs, security vulnerabilities, and performance issues, and provides improvement suggestions. Trigger phrases include "take a look at this code", "review this", "is there a problem with this function".
-
tomlord1122 Bundle Code Review MasterCode review expert that first validates whether a PR achieves its stated goal, then checks security, quality, and performance. Use when reviewing PRs, conducting security audits, or assessing code changes.
-
tomlord1122 Bundle Electron ArchitectElectron desktop application architect. Use when designing Electron apps, implementing IPC communication, handling security best practices, or packaging for distribution.
-
zereight Skill Security ScanRapid security scanning workflow for code changes. Activates a focused security sweep. Activate when: security scan, scan for vulnerabilities, check for secrets, security check, run security audit, check deps.
-
zereight Skill Skill StocktakeAudit the skill inventory for quality, coverage, and staleness. Detect overlapping, incomplete, or outdated skills and produce a health report. Activate when: skill audit, stocktake, skill inventory, check skills, which skills exist, audit skills, skill quality, skill coverage.
-
cfircoo Bundle Damage ControlInstall, configure, and manage Claude Code security hooks that block dangerous commands and protect sensitive files. Use when setting up security protection, blocking destructive commands (rm -rf, git reset --hard), protecting sensitive paths (.env, credentials), or managing PreToolUse hooks.
-
zhaono1 Bundle Code ReviewerReviews pull requests and code changes for quality, security, and best practices. Use when user asks for code review, PR review, or mentions reviewing changes.
-
zhaono1 Bundle Security AuditorSecurity vulnerability expert covering OWASP Top 10 and common security issues. Use when conducting security audits or reviewing code for vulnerabilities.
-
levnikolaevich Skill Ln 22 Codebase AuditorAudits cross-cutting code health, security, delivery, and maintainability when no specialist audit is primary. Not for a single delivery review.
-
levnikolaevich Skill Ln 23 Test Suite AuditorAudits existing tests for meaningful coverage, trustworthy oracles, and maintenance value. Not for test implementation or a single delivery review.
-
levnikolaevich Skill Ln 25 Persistence AuditorAudits queries, transactions, data-path costs, and persistence resource lifetimes. Not for general performance tuning.
-
levnikolaevich Skill Ln 24 Architecture AuditorAudits implemented architecture, boundaries, dependencies, and configuration ownership. Not for documenting current state or reviewing plans.
-
levnikolaevich Skill Ln 21 Documentation AuditorAudits documentation and comments for trustworthy claims, coverage, and discoverability. Not for code, test, or architecture audits.
-
levnikolaevich Skill Ln 74 Architecture Decision RecorderRecords one significant architecture decision, alternatives, and consequences. Not for broad system design, audit, or implementation.
-
levnikolaevich Skill Ln 72 Current Architecture DocumenterDocuments implemented architecture from repository evidence for onboarding or migration baselines. Not for target design or audit verdicts.
-
rand Skill Discover SecurityAutomatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management. Activates for application security, OWASP, and security hardening tasks.
-
rand Skill Discover CryptographyAutomatically discover cryptography skills when working with encryption, TLS, certificates, PKI, and security
-
srstomp Bundle Work SessionUse when starting AI development sessions, resuming interrupted work, managing multi-session projects, or orchestrating work with human checkpoint control (supervised, semi-auto, auto, or unattended modes).
-
srstomp Bundle Security AuditUse when reviewing code security, auditing dependencies for CVEs, checking configuration or secret security, assessing authentication and authorization patterns, identifying OWASP vulnerabilities (injection, XSS, CSRF), or addressing security concerns about implementations.
-
incept5 Skill Eve Manifest AuthoringAuthor and maintain Eve manifest files (.eve/manifest.yaml) for services, environments, pipelines, workflows, and secret interpolation. Use when changing deployment shape or runtime configuration in an Eve-compatible repo.
-
xbklairith Skill Review25-point code quality checklist covering structure, errors, security, performance, and testing. Use before commits or when reviewing code.
-
xbklairith Skill Security ReviewOWASP Top 10 vulnerability detection. Use PROACTIVELY for code handling user input, auth, APIs, payments, or sensitive data.
-
agents365-ai-365-skills Skill Obsidian OrganizerFile new notes into the right folder and audit/reorganize folder structure in the user's Obsidian vault, using the `obsidian` CLI and a single source-of-truth map note (`00_Index/Folder_Map.md`) that lives inside the vault. Use this whenever a note needs to be placed, filed, sorted, or moved into the vault; whenever the user asks where a note "belongs" or "should go"; and whenever they want to clean up, reorganize, deduplicate, audit, or restructure vault folders (e.g. orphaned notes, dead-end notes, near-duplicate titles, overlapping folders). Trigger even when the user just says "add this to my vault", "put this somewhere sensible", or "tidy up the cellchat notes" without naming a folder. Requires the Obsidian desktop app to be running.
-
austintgriffith-ethskills Skill AuditDeep EVM smart contract security audit system. Use when asked to audit a contract, find vulnerabilities, review code for security issues, or file security issues on a GitHub repo. Covers 500+ non-obvious checklist items across 19 domains via parallel sub-agents. Different from the security skill (which teaches defensive coding) — this is for systematically auditing contracts you didn't write.
-
lilmgenius Skill PrismSplit one artifact — a claim, plan, or file — across 2 to 5 independent lenses, one per genuinely distinct failure mode (correctness, security, readability, cost, adversarial-user), and return their convergence: where they agree, where they disagree, and the single next question that resolves the disagreement. Use when one reviewer isn't enough because the failure modes are heterogeneous, or a claim looks strong to its author and needs cross-lens pressure before it ships.
-
lilmgenius Skill SsotizeAudit and consolidate a fact that's scattered across places into one canonical source, after approval, and replace the rest with references. Use when asked to find duplication, check consistency, locate the source of truth, deduplicate, consolidate, unify, or establish SSOT across artifacts or platforms. Starts read-only, reports the map and plan, then mutates only after explicit approval.
-
montagao Bundle Dead Code DetectorFind and remove dead code in TypeScript/JavaScript projects. Detects unused exports (functions, types, constants never imported elsewhere), unused npm dependencies (packages in package.json never imported), and unreachable code patterns (code after returns, always-false conditions, stale TODOs). Use when: "find dead code", "check for unused exports", "clean up unused code", "find unused dependencies", "audit codebase for dead code", "what code can I delete", or before major refactors.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include code-review-assistant, obsidian-organizer, chrome-webstore-release-blueprint. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.