Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
monumentalsystems Skill Compliance FrameworksSOC 2 compliance requirements, ISO 27001 standards, PCI DSS requirements, HIPAA security rules, GDPR data protection, NIST Cybersecurity Framework, and industry-specific compliance requirements
-
monumentalsystems Skill Vulnerability ScanningStatic Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), container security scanning, dependency vulnerability management, and common vulnerability tools (Snyk, Trivy, OWASP ZAP, SonarQube)
-
steipete-agent-scripts Bundle Skill CleanerCodex/OpenClaw skill audit: live budget, usage, duplicates, compact descriptions.
-
steipete-agent-scripts Bundle Fleet MaintenanceMac fleet inventory and upkeep with full/worker profiles: collect installed apps and packages, compare desired versus observed state, audit local-account escrow references, update Homebrew/global packages, safely sync repos and Xcode, and report disk, service, backup, update, and security health.
-
steipete-agent-scripts Bundle Swiftui Performance AuditSwiftUI performance: render, scroll, CPU/memory, updates, layout, Instruments.
-
vladm3105 Skill Review TeamRun a multi-persona review team over an SDD artifact - fan the crew out as parallel subagents that deposit findings to a review blackboard, then reduce them into one scored, coverage-aware report. The shared mechanism behind the team mode of doc-*-audit (review), doc-*-fixer (remediate), and doc-*-autopilot (create). Use at quality gates; falls back to single_pass when subagents are unavailable.
-
vladm3105 Skill Doc Adr AuditAudit an ADR - run declarative structural checks plus content review and produce a combined report for doc-adr-fixer. Use for ADR quality gating before SPEC.
-
vladm3105 Skill Doc Adr FixerApply fixes to an ADR from the latest doc-adr-audit report - structure, links, element IDs, content, references, and upstream drift. Use after an audit reports issues.
-
vladm3105 Skill Doc Bdd AuditAudit a BDD suite - run declarative structural checks plus content review and produce a combined report for doc-bdd-fixer. Use for BDD quality gating before ADR.
-
vladm3105 Skill Doc Bdd FixerApply fixes to a BDD suite from the latest doc-bdd-audit report - structure, links, element IDs, YAML scenario content, references, and upstream drift. Use after an audit reports issues.
-
vladm3105 Skill Doc Brd FixerApply fixes to a BRD from the latest doc-brd-audit report - structure, links, element IDs, content, references, and upstream drift. Use after an audit reports issues.
-
vladm3105 Skill Doc Chg AuditAudit a Change Management (CHG) record - run declarative schema, impact/cascade, gate-routing, and change-level checks plus content review, then produce a pass/fail gate-readiness report (no numeric score) for doc-chg-fixer. Use to validate a CHG before requesting gate approval.
-
vladm3105 Skill Doc Chg FixerApply fixes to a Change Management (CHG) record from the latest doc-chg-audit report - schema/required fields, change-level correctness, source-to-gate routing, impact/cascade completeness, conditional blocks, links, registry, and lens-validated content remediations. Use after an audit reports a FAIL.
-
vladm3105 Skill Doc Tdd AuditAudit a TDD - run declarative structural checks plus content review and produce a combined report for doc-tdd-fixer. Use for TDD quality gating before IPLAN.
-
vladm3105 Skill Doc Tdd FixerApply fixes to a TDD from the latest doc-tdd-audit report - structure, links, element IDs, test-case content, references, and upstream SPEC drift. Use after an audit reports issues.
-
vladm3105 Skill Doc Ears AuditAudit an EARS document - run declarative structural checks plus content review and produce a combined report for doc-ears-fixer. Use for EARS quality gating before BDD.
-
vladm3105 Skill Doc Ears FixerApply fixes to an EARS document from the latest doc-ears-audit report - structure, links, element IDs, EARS syntax, references, and upstream drift. Use after an audit reports issues.
-
vladm3105 Skill Doc Spec AuditAudit a SPEC - run declarative structural checks plus content review and produce a combined report for doc-spec-fixer. Use for SPEC quality gating before TDD.
-
vladm3105 Skill Doc Spec FixerApply fixes to a SPEC from the latest doc-spec-audit report - structure, YAML, links, IDs, content, references, and upstream drift. Use after an audit reports issues.
-
vladm3105 Skill Security AuditValidate security requirements and assess vulnerabilities across code, dependencies, infrastructure, and configuration, with OWASP/CWE compliance and STRIDE threat modeling. Use to security-review an SDD project or its implementation.
-
vladm3105 Skill Doc Iplan AuditAudit an IPLAN - run declarative structural checks plus content review and produce a combined report for doc-iplan-fixer. Use for IPLAN quality gating before code implementation.
-
vladm3105 Skill Doc Iplan FixerApply fixes to an IPLAN from the latest doc-iplan-audit report - structure, links, IDs, file manifest, session handoff, implementation contracts, references, and upstream drift. Use after an audit reports issues.
-
cat-xierluo Bundle Verification Gate代码改完后的分层验证执行与证据记录。完成 feature / 重大变更 / 创建 PR / 重构 / 声称「修完」前使用——按项目运行 build、unit、e2e、真机等代表性阶段并记录真实结果(编译过 ≠ 功能可用)。覆盖 Tauri 桌面 / Web / 服务 / Skill 四类分支,可把已执行事实转换为 production-engineering-audit staged receipt;完成等级与发布结论由 production-engineering-audit 裁决。不要用于:业务领域验证、Skill 质量审查(用 skill-lint)、纯文档变更、一次性脚本。
-
duyet Bundle Swiftui Performance AuditAudit SwiftUI runtime performance from code first. Use when diagnosing slow rendering, janky scrolling, expensive updates, or profiling needs.
-
windmill-labs Skill Local ReviewCode review the current PR (or branch diff against main) for bugs, security, and AGENTS.md compliance. MUST use when asked to review code.
-
pixel-process-ug Bundle Security ReviewUse when reviewing code for security vulnerabilities, implementing authentication or authorization, handling user input, managing secrets, or auditing dependencies for known CVEs. Triggers: auth implementation, input handling, secrets management, dependency audit, pre-deployment security check, OWASP compliance review.
-
agiprolabs Bundle Birdeye APISolana token market data via Birdeye — prices, OHLCV, trades, token metadata, security checks, and trader activity
-
boraoztunc Bundle Interface ReviewInterface review of a change rather than a screen: uncommitted work, the current branch, or a pull request. Covers interface quality, not correctness, tests, or security.
-
openclaudia Skill Backlink AuditAudit a domain's backlink profile using the SemRush API. Use when the user says "audit backlinks", "check my backlinks", "backlink analysis", "link profile", "toxic links", "disavow", "link building opportunities", "referring domains", "anchor text", or asks about a site's link authority.
-
openclaudia Skill Google ReviewsFetch Google review ratings and review counts for businesses via DataForSEO API. Use when the user asks to check Google reviews, get review counts, compare business ratings, audit Google Maps presence, or analyze competitor reviews.
-
openclaudia Skill Organize SkillsAudit and reorganize a Claude Code / Codex skill library — enforce a naming convention (prefix each skill by which backend or product it touches), rename skills consistently, fix the symlinks and cross-references a rename breaks, and report broken symlinks and stale name references. Use when the user says "organize my skills", "rename these skills", "clean up the skill library", "enforce a skill naming convention", or "fix broken skill symlinks".
-
openclaudia Bundle Gsc Portfolio AuditAudit EVERY Google Search Console property at once — rank all sites by clicks and impressions with period-over-period deltas, then diff keywords per site to surface what is newly ranking, rising, dropping, lost, or ranking well without earning clicks. Built for agencies and multi-site owners. Use when asked to compare all sites, rank properties by traffic, find new keywords across a portfolio, or spot which site is down. Trigger phrases: "audit GSC", "all my sites", "rank my properties", "portfolio search performance", "which sites are down", "what new keywords are we ranking for", "client site performance", "GSC report across accounts". For ONE site's queries, pages, or index coverage, use the search-console skill instead.
-
openhands Bundle Code ReviewRigorous code review focusing on data structures, simplicity, security, pragmatism, and risk/safety evaluation. Provides brutally honest, actionable feedback on pull requests or merge requests, including a risk assessment for every review. Use when reviewing code changes.
-
s-hiraoku Skill Code ReviewPerform structured code reviews focusing on correctness, readability, security, and maintainability. Use this skill when reviewing pull requests, evaluating code changes, or establishing review standards for a team.
-
s-hiraoku Skill Doc OrganizerAudit, restructure, and consolidate project documentation for clarity and maintainability. Use this skill when docs have grown organically and need reorganization, when duplicate content exists across files, or when documentation structure needs standardization.
-
s-hiraoku Skill Security AuditGeneral-purpose security auditing guide. Covers OWASP Top 10, dependency vulnerabilities, authentication, authorization, input validation, and secret management. Use this when performing a security review or audit.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include birdeye-api, verification-gate, swiftui-performance-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.