Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
factory-ai Bundle Vulnerability ValidationValidate security findings from commit-security-scan by assessing exploitability, filtering false positives, and generating proof-of-concept exploits. Use after running commit-security-scan to confirm vulnerabilities.
-
geeksfino Bundle Portfolio Health CheckDiagnose risks and inefficiencies in an existing investment portfolio. Use when the user asks to review, audit, or stress-test their current holdings, evaluate portfolio concentration, check factor exposures, assess correlation risks, identify hidden tilts, or get actionable improvement suggestions for a portfolio they already own.
-
akin-ozer Bundle Promql ValidatorValidate, lint, audit, or fix PromQL queries and alerting rules; detects anti-patterns.
-
akin-ozer Bundle Makefile ValidatorValidate, lint, audit, or check Makefiles and .mk files for errors.
-
akin-ozer Bundle Fluentbit ValidatorValidate, lint, audit, or check Fluent Bit configs (INPUT, FILTER, OUTPUT, tag routing).
-
akin-ozer Bundle Gitlab CI ValidatorValidate, lint, audit, or fix .gitlab-ci.yml pipelines, stages, and jobs.
-
akin-ozer Bundle Dockerfile ValidatorValidate, lint, audit, or scan a Dockerfile for security and best practices.
-
akin-ozer Bundle Terragrunt ValidatorValidate, lint, audit, or check Terragrunt .hcl/terragrunt.hcl files, stacks, modules, compliance.
-
akin-ozer Bundle Bash Script ValidatorValidate, lint, audit, or fix bash/shell/.sh scripts via ShellCheck.
-
akin-ozer Bundle Jenkinsfile ValidatorValidate, lint, audit, or check Jenkinsfiles and shared libraries.
-
akin-ozer Bundle Github Actions ValidatorValidate, lint, audit, fix GitHub Actions workflows (.github/workflows).
-
encoredev Skill Encore SecretManage API keys, credentials, and other secrets in Encore.ts using `secret(...)` from `encore.dev/config`.
-
encoredev Skill Encore Go SecretManage API keys, credentials, and other secrets in Encore Go using a package-level `secrets` struct.
-
playableintelligence Skill Design GameAudit and improve the visual design, polish, and player experience of an existing game. Use when the user says "make my game look better", "improve the design", "add polish", "add juice", "add particles", "fix the UI", or "make it more visually appealing". Do NOT use for gameplay logic changes (use add-feature instead).
-
playableintelligence Skill Review GameReview an existing game codebase for architecture, performance, and best practices. Use when the user says "review my game", "code review", "check my game architecture", "is my game well structured", or "audit my game code". Do NOT use for making changes — this is read-only analysis. Use improve-game to implement fixes.
-
julianobarbosa Skill Power Bi SecurityConfigure row-level security (RLS) roles, object-level security, and perspectives for Power BI semantic models using pbi-cli. Invoke this skill whenever the user mentions "security", "RLS", "row-level security", "access control", "data restrictions", "who can see", "filter by user", "perspectives", "limit visibility", or wants to restrict data access by role.
-
julianobarbosa Skill Knowledge Base Health CheckAudits a local Claude-managed knowledge base in Simon's '/Users/simon/Claude CoWork/Knowledge Base/' system. Surfaces contradictions between articles, broken backlinks, unsourced claims, stale articles, writing-rules violations, and three suggested new articles. Files a full report into the KB's 'Outputs/' folder, appends a one-line CHANGELOG entry, and (in interactive sessions) walks through which findings to action. Use this skill whenever the user says "run a health check", "audit the [name] KB", "audit my knowledge base", "check the wiki", "let's go through the health check report", or "action the latest health check". Also use when the monthly scheduled task 'knowledge-base-monthly-health-check' fires. Use this skill for any audit-style request against a folder under 'Knowledge Base/' even if the user doesn't say the word "health check" - the protocol is the same.
-
cometchat Skill Cometchat ProductionProduction readiness for CometChat — server-side token auth, user management CRUD, environment hardening, and security checklist. Replaces dev-mode authKey with server-side tokens.
-
cometchat Skill Cometchat IOS ProductionProduction-ready CometChat iOS setup — server-side auth tokens, security best practices, and deployment checklist.
-
cometchat Skill Cometchat Android V5 ProductionProduction readiness for CometChat Android — server-side token auth, user management CRUD, ProGuard rules, and security checklist.
-
cometchat Skill Cometchat Android V6 ProductionCometChat Android UIKit v6 production readiness — token auth, ProGuard/R8, security checklist, release configuration
-
cometchat Skill Cometchat Flutter V5 ProductionUse when preparing a CometChat Flutter UIKit v5 app for production. Covers auth tokens, ProGuard, environment config, security hardening.
-
cometchat Skill Cometchat Flutter V6 ProductionProduction readiness for CometChat Flutter UIKit v6 — server-side auth tokens, user management, Android ProGuard/R8, iOS Info.plist, minSdk, release build checklist, environment configuration, and security hardening. Use when preparing a CometChat Flutter app for production deployment.
-
vtex Skill Payment Pci SecurityApply when handling credit card data, implementing secureProxyUrl flows, or working with payment security and proxy code. Covers PCI DSS compliance, Secure Proxy card tokenization, sensitive data handling rules, X-PROVIDER-Forward-To header usage, custom token creation, and the constraint that Secure Proxy applies only to card authorization (not post-auth operations like cancel, capture, or refund). Use for any payment connector that processes credit, debit, or co-branded card payments to prevent data breaches and PCI violations.
-
vtex Skill Masterdata Storage StrategyApply when deciding whether VTEX Master Data is the right storage for a given workload, designing JSON Schemas with v-indexed, v-cache, v-security, and v-triggers, planning entity capacity and lifecycle, or auditing existing Master Data usage. Covers when to use MD versus Catalog, OMS, VBase, or external databases, schema design best practices, indexing strategy, trigger patterns, and operational considerations. Use before creating any new Master Data entity.
-
vtex Skill Vtex Io Security BoundariesApply when reviewing or designing security-sensitive boundaries in VTEX IO apps. Covers public versus private exposure, trust assumptions at route and integration boundaries, sensitive data handling, validating what crosses the app boundary, and avoiding leakage across accounts, workspaces, users, or integrations. Use for route hardening, data exposure review, or evaluating whether a service boundary is too permissive.
-
vtex Skill Architecture Well Architected CommerceApply when scoping, reviewing, or documenting cross-cutting VTEX commerce architecture across storefront, IO, headless, marketplace, payments, or any other VTEX module. Grounds work in the Well-Architected Commerce framework—Technical Foundation (reliability, trust, integrity; security, infrastructure, compliance), Future-proof (innovation, simplicity, efficiency; scalable and adaptable solutions), and Operational Excellence (accuracy, accountability, data-driven improvement; process and customer experience). Routes implementation detail to product tracks (IO caching and paths, Master Data strategy, marketplace integrations). Use for solution design, architecture reviews, and RFP-level technical structure.
-
vivy-yi Skill Account SafetyUse when needing to protect account from hacking, unauthorized access, suspension, or other security threats on Xiaohongshu
-
pedronauck Bundle Electron DevExpert guide for Electron development with Electron Vite and Electron Builder. Use when developing Electron applications, working with main/renderer processes, IPC communication, preload scripts, security configuration, native module handling, or build/distribution setup.
-
pedronauck Skill Writing Agents MdCreate, audit, shorten, or scope AGENTS.md and CLAUDE.md instructions. Use writing-skills for on-demand skills; excludes human-facing documentation and READMEs.
-
pedronauck Bundle Refactoring AnalysisAudit code quality and architectural health or plan refactoring using Fowler code smells and techniques; write prioritized findings to docs/_refacs/. Excludes formatting, performance, and security audits.
-
pedronauck Bundle Architectural AnalysisAudit architecture, dead code, duplication, type confusion, and code smells across a codebase. Excludes formatting, performance profiling, security audits, and feature-level reviews.
-
doccker Bundle Cc Review结构化代码审查工作流,适用于显式 quick/full/security review;不负责普通实现或 bug 修复流程。
-
the-art-of-hacking Bundle CodeguardA CodeGuard security skill that helps AI coding agents write secure code and prevent common vulnerabilities. Use this skill when writing, reviewing, or modifying code to ensure secure-by-default practices are followed.
-
adibirzu Bundle Openclaw Security MonitorProactive security monitoring, threat scanning, and auto-remediation for OpenClaw deployments
-
nextfrontierbuilds-strykr-prism-skill Bundle Strykr PrismStrykr PRISM API for canonical asset resolution, price lookups, token security scanning, and cross-market intelligence. 120+ endpoints covering crypto, stocks, ETFs, forex, commodities, and DeFi.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include openclaw-security-monitor, vulnerability-validation, portfolio-health-check. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.