Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aliyun Bundle Alibabacloud Waf Lua Extension DevUse when creating, editing, or reviewing WAF 3.0 custom Lua extension plugins, plugin parameters, or request validation logic.
-
aliyun Bundle Alibabacloud Security Vuln Coverage Check查询阿里云四款安全产品(云安全中心 / WAF / 云防火墙 / RASP)对指定漏洞的防护覆盖情况,输入 CVE 编号或 AVD 编号即可返回各产品是否已覆盖。当客户或售前 SA 问"我们产品能不能防住 CVE-XXXX?"、"WAF 覆盖这个漏洞了吗?"、"新爆出来的 XX 漏洞有没有覆盖?"、"高危漏洞 YY 我们这边什么情况"时使用本 Skill。基于 avd.aliyun.com 高危漏洞库的离线快照(1697 条记录,覆盖 2002–2026 年),运行时纯本地 grep 查询,不联网、不调用浏览器、不需要任何凭证。也支持批量比对一组 CVE。
-
aliyun Bundle Alibabacloud Web Application Attacks AnalysisAnalyze origin web access logs (Nginx/Apache/IIS) to detect CC attacks, proxy-pool distributed bots, scanning probes, login brute force, abnormal crawlers, QPS/bandwidth/status-code surges, and slow resource consumption, then produce an actionable security report with mitigation advice. Read-only; no credentials required. Triggers: "CC attack", "HTTP flood", "proxy pool bot", "login brute force", "web access log analysis", "access log security analysis", "abnormal crawler", "QPS surge", "bandwidth surge", "4xx/5xx surge", "site being attacked", "scanning probe", "API abuse", "slow request analysis".
-
aliyun Bundle Alibabacloud Openclaw Skill Security ScanScan installed skills for security risks and audit platform configuration. When to use: user requests security scan, security analysis, skill audit, OpenClaw health check, config audit, security baseline check, pre-install, safety check, supply chain security check, or asks "is this skill safe". Trigger phrases: "security scan", "安全扫描", "安全分析", "风险评估", "安全体检", "skill audit", "配置审计", "安全基线", "skill安全扫描", "检查skill风险", "这个skill安全吗", "安装前检查", "能不能装这个skill".
-
duc01226 Bundle Spec[Documentation] Use to author, audit, amend, or test-spec a business Feature Spec. The single spec skill — modes draft|init|update|audit|amend create/maintain the tech-free 8-section Feature Spec; draft authors a provisional spec from an idea/requirement (no code yet, Evidence: TBD); tests generates Section 8 TC-{FEATURE}-{NNN} test specifications; sync reconciles §8 TCs ↔ executing test code. Per-mode procedure lives in references/{author,tests,sync}.md.
-
duc01226 Bundle Tech Spec[Documentation] Use when (re)generating the DERIVED technical spec view over code + tests, or reporting canonical §8 TC/test-code drift. A GENERATOR — it projects code + tests into a regenerable per-component view and NEVER authors business content. Modes generate|audit|sync. Per-mode procedure lives in references/{author,sync}.md.
-
duc01226 Skill Quality Gate Review[Project Management] Use when you need to enforce quality gates, verify compliance with standards, track quality metrics, and generate audit trails.
-
duc01226 Skill Workflow Architecture Audit[Workflow] Use when activating the Architecture Audit workflow to review the whole project's architecture, run an architecture health check, or check production readiness/scalability in one pass — read-only, produces one consolidated Architecture Health Report.
-
duc01226 Bundle Architecture Scalability Review[Architecture] Use when grading project architecture and scalability quality for greenfield init or brownfield audit: build/CI scalability, distributed-monolith risk, module isolation, dependency discipline, loose coupling, horizontal scaling, DRY, abstraction, clean architecture, observability, and delivery.
-
borghei Bundle Pr Review ExpertSystematic PR review with blast-radius analysis, security scanning, and breaking-change and test-coverage deltas. Use when reviewing PRs that touch shared libraries, APIs, database schemas, auth, or security-sensitive code.
-
borghei Bundle Threat DetectionThis skill should be used when the user asks to "analyze logs for threats", "detect suspicious activity", "scan for brute force attempts", "identify injection attacks", or "audit access patterns for anomalies".
-
borghei Bundle Isms Audit ExpertISMS auditing for ISO 27001 compliance, control assessment, and certification support. Use for ISMS audit programs, internal/external ISO 27001 audits, ISO 27002 Annex A control testing, and Stage 1/Stage 2 certification audits.
-
borghei Bundle Pci Dss SpecialistPCI DSS v4.0 payment card data security compliance, assessment, and implementation. Use for PCI DSS scoping, cardholder data environment (CDE) security, SAQ and ROC preparation, QSA engagement, tokenization, and merchant compliance.
-
borghei Bundle Dependency AuditorScan project dependencies for vulnerabilities, license issues, and upgrade opportunities across Python, Node.js, Go, and Rust. Use when auditing dependencies, checking licenses, planning upgrades, or assessing supply chain security.
-
borghei Bundle Doc Drift DetectorDetect documentation drift against code changes, score staleness, validate API docs via AST parsing, and audit link integrity. Use when docs fall out of sync with code, preparing releases, running CI doc gates, or auditing doc accuracy.
-
borghei Bundle Whistleblower ComplianceAudit whistleblower systems and draft compliant reporting policies. Use when assessing or building whistleblower programs.
-
borghei Bundle Data Quality AuditorAudit data quality across pipelines, warehouses, and stores. Use when designing a DQ program, defining DQ dimensions, building rule-based checks, detecting schema drift, monitoring freshness SLAs, or responding to a DQ incident.
-
borghei Bundle Google Workspace CLIThis skill should be used when the user asks to "audit Google Workspace", "check GWS security settings", "set up Google Workspace authentication", "diagnose Workspace issues", or "review Google admin configurations".
-
borghei Bundle Release OrchestratorOrchestrate end-to-end release pipelines. Use when running pre-release validation, generating changelogs, bumping semantic versions, scoring deployment readiness, or gating releases with secret scanning and GO/NO-GO checks.
-
borghei Bundle Tech Stack EvaluatorEvaluate and compare technology stacks with TCO analysis, security assessment, and ecosystem health scoring. Use when comparing frameworks, calculating total cost of ownership, assessing migration paths, or analyzing ecosystem viability.
-
borghei Bundle Aims AuditISO 42001 AI Management System (AIMS) audit-prep playbook. Use when an ISO 42001 certification audit is scheduled (Stage 1 or Stage 2), when a surveillance or internal AIMS audit is due, or when preparing an AI Impact Assessment (AIIA).
-
borghei Bundle Knowledge OpsAudit and repair an internal knowledge base — staleness, ownership gaps, orphans, duplication, and findability. Use when the wiki is untrusted, docs are out of date, nobody owns pages, or search returns the wrong answer.
-
borghei Bundle Secrets Vault ManagerThis skill should be used when the user asks to "generate Vault configurations", "plan secret rotation", "analyze vault audit logs", "manage secrets lifecycle", or "set up HashiCorp Vault".
-
borghei Bundle Soc2 Compliance ExpertSOC 2 Type I and Type II compliance management against the Trust Services Criteria. Use for SOC 2 readiness assessments, TSC gap analysis, audit evidence collection, infrastructure control validation, and CPA firm audit preparation.
-
borghei Bundle Atlassian AdminAdminister the Atlassian suite (Jira/Confluence): user provisioning, groups, SSO/SAML, permissions, security policies, marketplace apps, backups, and org-wide governance. Use for admin config, access management, and system optimization.
-
borghei Bundle Nis2 Directive SpecialistNIS2 Directive (EU 2022/2555) compliance for critical infrastructure entities, covering the 10 minimum security measures. Use for NIS2 compliance assessments, entity scope analysis, supply chain security, and incident reporting readiness.
-
borghei Bundle Gdpr Audit PrepGDPR audit-prep playbook: sprint to prepare for a supervisory authority inquiry, DPA audit, or internal review. Use when an audit is scheduled, when readiness gaps surface, or when ROPA (Records of Processing Activities) needs completion.
-
borghei Bundle Soc2 Audit PrepSOC 2 audit-prep playbook: the 4/8/12-week sprint to audit-ready for a Type I or Type II observation. Use when the audit is scheduled, when readiness assessment surfaced gaps and you need a sprint plan, or when evidence is missing or stale.
-
borghei Bundle AI Act ReadinessEU AI Act readiness assessment and sprint playbook. Use when preparing for the Aug 2026 high-risk AI system deadline, when a notified-body conformity assessment is scheduled, or when GPAI (general-purpose AI) obligations apply.
-
borghei Bundle Fda Qsr Audit PrepFDA Quality System Regulation (21 CFR 820 / QMSR) audit-prep playbook for medical devices. Use when an FDA inspection is announced, when preparing for the new QMSR (2026), or when a 483 / Warning Letter response is needed.
-
borghei Bundle Compliance ReadinessCross-framework compliance readiness orchestrator. Use when preparing for multi-framework certification (SOC 2 + ISO 27001 + NIST CSF), building a shared-evidence strategy, sequencing certifications, or mapping a control across frameworks.
-
borghei Bundle Information Security Manager Iso27001ISO 27001:2022 ISMS implementation and cybersecurity governance for HealthTech and MedTech. Use for ISMS design, risk assessment per Clause 6.1.2, Annex A controls, ISO 27001 certification, security audits, and incident response.
-
shipshitdev Bundle Code ReviewCorrectness, security, and spec-fidelity gate for incoming pull requests. Auto-invoked when reviewing a diff, evaluating a PR, running /code-review at any effort level, or asked "is this safe to merge?" Covers bugs, TypeScript hygiene, security, database safety, test existence, devex regressions, feature-flag leaks, and whether the diff matches the originating issue/spec. Multi-PR report-only review routes through review-dispatch; non-serial queue draining is exposed only through exact /merge force.
-
shipshitdev Bundle Security AuditRun a self-contained security audit workflow for web applications and APIs, covering scoping, reconnaissance, manual testing, API review, hardening, and reporting. Use when auditing a web app or API for security issues, reviewing auth or session handling, checking input validation and injection risk, or hardening before release.
-
shipshitdev Bundle Dependency AuditAudit a project's dependency supply chain — known CVEs in installed packages, secrets about to be committed, and lockfile/provenance integrity — and wire the checks into CI as a merge gate. Use when asked to audit dependencies, check for vulnerable packages, scan for leaked secrets, add a security gate to CI, or harden the supply chain. Complements security-audit (app-level) and git-safety (git history).
-
shipshitdev Bundle Production AuditAudit an application for production readiness using local evidence from code, CI, config, migrations, runtime checks, observability, and deployment paths. Use before launch, after risky merges, or when asked whether an app is ready to ship.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include alibabacloud-waf-lua-extension-dev, alibabacloud-security-vuln-coverage-check, alibabacloud-web-application-attacks-analysis. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.