Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
terrylica Skill Notes AuditAnalyze the macOS Notes folder taxonomy and propose a better organization - find empty/near-empty folders, oversized dumping grounds, duplicate-purpose folders, mixed-language naming, and stale content; then present a target hierarchy for operator approval BEFORE any moves. Use when notes feel sporadic/messy, before a big cleanup, or to review organization health periodically. TRIGGERS - audit my notes, notes are a mess, propose notes organization, analyze notes folders, notes cleanup plan.
-
terrylica Bundle Plugin ValidatorValidate plugin structure and silent failures. TRIGGERS - plugin validation, check plugin, hook audit.
-
terrylica Skill Notes ExportExport/back up EVERY macOS Notes note (all accounts, all folders) to local storage as markdown files plus a JSON manifest — the safety net to run BEFORE any reorganization, and the corpus the notes-audit skill analyzes. Read-only against Notes; writes only to ~/.local/share/notes-commander/export/. TRIGGERS - export my notes, back up notes, notes snapshot, dump notes to disk, notes backup before reorganizing.
-
terrylica Skill Notes OrganizeReorganize macOS Notes deliberately - create folders (incl. nested subfolders), move notes between folders, rename folders, and merge/empty a folder into another. Every destructive-ish verb supports --dry-run, and the workflow REQUIRES a notes-export snapshot first. Use when folderizing sporadic notes, splitting an oversized folder, consolidating near-empty folders, or executing a notes-audit proposal. TRIGGERS - organize my notes, move this note, create notes folder, folderize, merge folders, clean up notes folders, rename notes folder.
-
terrylica Skill Notes InventoryList every macOS Notes account, folder (including nested subfolders), and per-folder note count — the sidebar as machine-readable data. Use to see what exists before organizing, to answer "how many notes are in X", or as the first step of an audit/export. Read-only, safe. TRIGGERS - list my notes folders, notes inventory, how many notes, what folders do I have, show my notes structure.
-
terrylica Skill Health CheckDiagnose the po Pushover plugin and check remaining monthly quota. Runs a full self-test (credential resolution via 1Password/Keychain, /users/validate.json, quota, expected custom sounds present, deps bun/uv/chrome, audit log) and reports message quota remaining. Use when the user asks if Pushover is working, why a notification failed, how many messages are left, or wants a health/diagnostic check. TRIGGERS - pushover health, po doctor, pushover not working, pushover quota, messages left, diagnose pushover.
-
terrylica Bundle Rust Dependency AuditAudit Rust dependencies for vulnerabilities, license compliance, supply chain integrity, and freshness using cargo-audit, cargo-deny, cargo-vet,
-
terrylica Bundle Doppler Secret ValidationValidate and test Doppler secrets. TRIGGERS - add to Doppler, store secret, validate token, test credentials.
-
terrylica Bundle Verbatim Audit NotifySend Pushover notifications with UUID-linked verbatim JSONL audit trail. TRIGGERS - pushover notify, send pushover, observability alert, verbatim notification, fleet alert, pushover-lookup, audit log notification, push notification with UUID
-
aladicf Skill Security UXDesign security-conscious interfaces that protect users without frustrating them. Use when the user asks about MFA, password UX, breach notifications, trust indicators, secure forms, account recovery, or making security feel safe rather than scary.
-
lyndonkl Skill Audit DriftChecks every post currently assigned to a substacker section against that section's promise and flags posts that no longer fit. Distinguishes acceptable-stretch (minor) from borderline (surface for review) from genuine-drift (violates promise). Never reassigns automatically — only flags. Use on every Curator run where at least one section already exists. Trigger keywords — drift, drift audit, section fit, promise violation, post in wrong section.
-
lyndonkl Skill Recommend PruneRecommends structural cleanups for the substacker section map — sections to retire, sections to merge, posts to reassign. Applies under-filled, stale, and overlapping heuristics. Writes proposals with reasons-to-reject (steelman counter). Does not execute. Use once per Curator run, after drift audit. Trigger keywords — prune, retire section, merge sections, reassign post, cleanup.
-
lyndonkl Bundle Cognitive DesignGrounds visual design decisions in cognitive psychology principles — perception, attention, memory, Gestalt grouping, and visual encoding hierarchy — explaining WHY certain designs work. Covers interfaces, data visualizations, educational content, and presentations. Invoke when user mentions cognitive load, visual hierarchy, working memory, preattentive processing, Gestalt principles, encoding hierarchy, or cognitive design pyramid. For design evaluation, use `design-evaluation-audit`. For fallacy prevention, use `cognitive-fallacies-guard`. For data storytelling, use `visual-storytelling-design`.
-
lyndonkl Bundle Narrative Arc MappingMaps researched evidence onto Truby's twenty-two structural steps without fabricating the steps the evidence cannot fill. Runs the designing-principle discrimination test, step-fit triage (PRESENT / ABSENT / NOT APPLICABLE), per-slot warrant cards, the empty-slot decision table, the moral-argument spine, and the revelation-intensity audit, then stops at a tagged scene weave. Use when architecting a long-form nonfiction piece from a research corpus, structuring a post-mortem, market history, biography, or science writeup, or when user mentions Truby, 22 steps, designing principle, moral argument, revelation sequence, scene weave, or step-fit triage.
-
lyndonkl Bundle Prose Force And RhythmRuns Jack Hart's Wordcraft line passes in strict order (Structure, Force, Brevity, Clarity, Rhythm, Humanity, Color, Voice, Mechanics) followed by a slop audit, one pass per edit class, with a claim-strength invariant that stops verb strengthening and hedge cutting from silently overclaiming. Enforces upward escalation instead of downward compensation, a protected-hedge list, a clarity split log the rhythm pass may not undo, and rhythm metrics reported as diagnostics rather than optimized. Use when line-editing a draft, tightening flabby prose, fixing weak verbs or monotonous sentence rhythm, de-slopping AI-sounding copy, or when user mentions line edit, force pass, punch it up, tighten this, passive voice, wordy, sentence variety, sounds like AI, burstiness, or Wordcraft.
-
lyndonkl Bundle Design Evaluation AuditSystematically evaluates existing designs against cognitive science principles using repeatable checklists, scoring rubrics, and severity-classified fix recommendations. Use when conducting design reviews or critiques, evaluating designs for cognitive alignment, performing quality assurance before launch, diagnosing usability issues, or choosing between design alternatives with objective criteria.
-
lyndonkl Bundle Narrative Fallacy GuardStops a true set of facts from being assembled into a false story. Runs the retrospective slot audit, the outcome-blind rewrite (flip test, separation test), the inevitability audit with its overshoot check, the survivorship graveyard pass, the counterfactual admissibility gate, and the expensive proportion and omission audits. Every check labels and discloses; none deletes. Use when drafting or reviewing history, post-mortems, biography, market or protocol narratives, research writeups, or any account written after the outcome was known, or when user mentions hindsight bias, narrative fallacy, survivorship bias, inevitability, halo effect, outcome bias, just-so story, teleology, or Whig history.
-
lyndonkl Bundle Scene Construction ScamBuilds scenes that are reported rather than generated, by running a four-slot SCAM qualification gate (Setting, Character, Action, Meaning) with a source required per slot, a scene floor and ceiling, the 1-of-20 telling-detail cut with a provenance veto, the RUE pass, and a scene/summary narrative-distance audit against per-form ratio targets. Every technique has a person variant and a system variant (market, protocol, institution, codebase, supply chain). Use when turning research notes into a scene, opening a section with a moment, deciding whether a passage is a scene or summary, or auditing whether a vivid paragraph is actually sourced, or when user mentions scene, SCAM, show don't tell, telling detail, scene vs summary, summary in costume, establishing shot, make this vivid, or in medias res.
-
lyndonkl Bundle Narrative Opposition WebBuilds a four-corner opposition web for narrative nonfiction and stops the writer from casting whoever lost as the villain. Runs Truby's four-corner worksheet (shared central moral problem, per-corner value clusters, distinct routes of attack, corner-to-corner conflict), the best-possible-opponent audit (same goal, necessity, relentlessness, value conflict, the double, power parity, justification in the opponent's own voice), the Opponent Warrant evidence test that demotes undocumented antagonists to rivals or constraints, and a drive-section collapse check that catches a web that was decorative. Use when planning a piece with competing parties, when an antagonist feels flat or cartoonish, when the protagonist is a system rather than a person, or when user mentions opposition web, four-corner opposition, antagonist, opponent, villain, steelman the other side, character web, who is the bad guy here.
-
lyndonkl Bundle Cognitive Fallacies GuardDetects and prevents visual misleads, cognitive biases, and data integrity violations in visualizations, dashboards, reports, and presentations. Audits charts for honesty, diagnoses misinterpretation causes, and provides specific fixes. Invoke when user mentions chartjunk, misleading chart, truncated axis, data integrity, visual deception, 3D chart problems, cherry-picking data, or needs to audit visualizations for accuracy. For general design evaluation, use `design-evaluation-audit`. For cognitive foundations, use `cognitive-design`.
-
lyndonkl Skill Recurring Charge DetectorIdentifies recurring charges (subscriptions, monthly bills, biweekly paychecks) from a transaction history by clustering same-merchant transactions of similar amount on a regular cadence, requiring at least 3 confirming occurrences before promoting a candidate to active status. Detects new recurring charges, dormant subscriptions (missed expected dates), and amount drift, and computes annualized cost. Use when auditing subscriptions, building a recurring bills calendar, computing cash-flow forecast inputs, or when user mentions subscription audit, recurring detection, dormant subscription, or annualized cost.
-
rysweet Bundle Merge ReadyChecks whether a pull request satisfies the project's merge criteria and records the required evidence in the PR description. Use with `/merge-ready` before review or merge when QA-team scenarios, docs links, quality-audit convergence, CI status, and diff scope must be verified.
-
rysweet Skill Reviewing CodePerforms systematic code review checking for correctness, maintainability, security, and best practices. Activates when user requests review, before creating PRs, or when significant code changes are ready. Ensures quality gates are met before code proceeds to production.
-
thelobbi Skill Deep AnalysisAnalytical thinking patterns for comprehensive evaluation, code audits, security analysis, and performance reviews. Provides structured templates for thorough investigation with extended thinking support.
-
thelobbi Skill AuthenticationAuthentication and authorization including JWT, OAuth2, OIDC, sessions, RBAC, and security analysis. Activate for login, auth flows, security audits, threat modeling, access control, and identity management.
-
thelobbi Skill Blazor Auth SecurityAuthentication and authorization in Blazor with ASP.NET Core Identity, Entra ID, JWT, and policy-based auth
-
thelobbi Skill Linear Webhooks Verify Replay DlqThis skill should be used when registering, verifying, or processing Linear webhooks — HMAC signatures, replay protection, idempotency, dead-letter queues. Activates on "linear webhook", "webhook signature", "Linear-Signature", "webhook secret".
-
thelobbi Skill Harness PlatformThis skill should be used when the user asks to "configure Harness delegates", "set up Harness RBAC", "manage connectors/secrets/templates", "apply OPA policy as code", or "review audit logs" — Harness platform administration and governance.
-
thelobbi Skill Enterprise SecurityEnterprise-grade security patterns for Claude Code — audit logging, compliance frameworks, secrets management, permission hardening, network security, and managed settings enforcement
-
mims-harvard Bundle Devtu Docs QualityTOP PRIORITY skill — find and immediately fix or remove every piece of wrong, outdated, or redundant information in ToolUniverse docs. Wrong code, broken links, incorrect counts, and overlapping instructions must be fixed or removed — never left in place. Runs five phases: (D) static method scan, (C) live code execution, (A) automated validation, (B) ToolUniverse audit, (E) less-is-more simplification. Core philosophy: each concept appears exactly once; remove don't add; no emojis; single setup entry point. Use when reviewing docs, before releases, after API changes, or when asked to audit, fix, or simplify documentation.
-
sundial-org Bundle Abm OutboundMulti-channel ABM automation that turns LinkedIn URLs into coordinated outbound campaigns. Scrapes profiles, enriches with Apollo (email + phone), gets mailing addresses via Skip Trace, then orchestrates email sequences, LinkedIn touches, and handwritten letters via Scribeless. The secret weapon for standing out in crowded inboxes.
-
sundial-org Bundle Moltbot SecuritySecurity hardening guide for Moltbot/Clawdbot. Lock down your gateway, fix file permissions, set up auth, configure firewalls. Based on real vulnerability research.
-
terminalskills Bundle Aircrack NgAudit Wi-Fi networks with the aircrack-ng suite. Use when a user asks to test their own wireless network, capture WPA2 handshakes, crack captured handshakes offline, put an adapter into monitor mode, or perform a wireless pentest under an authorized engagement.
-
terminalskills Bundle John The RipperCrack password hashes offline with John the Ripper. Use when a user asks to identify an unknown hash format, recover a forgotten password from a local database or ZIP file, run a CTF hash challenge, or audit the strength of hashes from a system they own.
-
terminalskills Bundle Project Skill AuditAnalyze a project and recommend highest-value skills to create or update. Use when: auditing project skills, getting skill recommendations, or reviewing existing skill coverage.
-
terminalskills Bundle Swiftui Performance AuditAudit and optimize SwiftUI runtime performance. Use when: diagnosing slow rendering, janky scrolling, excessive view updates, or high CPU/memory usage in SwiftUI apps.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-ux, audit-drift, recommend-prune. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.