Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
saturate Bundle Codebase AuditPerforms comprehensive codebase audit checking architecture, tech debt, security vulnerabilities, test coverage, documentation, dependencies, and maintainability. Use when auditing a project, assessing codebase health, running security scans, checking for vulnerabilities, reviewing code quality, analyzing tech debt, or asked to audit/analyze the entire codebase.
-
hughyau Bundle Criticism Self Criticism批评与自我批评:在工作完成、阶段验收、收到批评或同类错误反复出现时,对成果和过程做诚实、具体、基于事实的审视,输出可执行的改进项,并处理外来批评而不辩解。触发信号包括 review、复盘、审查、"帮我看看有没有问题"、"你确定吗";任务刚开始或只是单步查询时不触发。 English: Criticism and self-criticism. After delivery, at a review checkpoint, on receiving criticism, or when the same mistake recurs, examine the result and the process honestly and concretely, produce actionable fixes, and accept valid criticism without defensiveness. Triggers include review, retrospective, audit, "check this for problems", "are you sure"; skip at the start of a task or for one-step lookups.
-
u1pns Skill Code ReviewerActs as a Senior Security Engineer and Code Auditor. Use this skill when the user asks to review code, audit security, or check for best practices. Triggers: 'review code', 'check for bugs', 'security audit', 'code smells', 'refactor suggestion'.
-
zbruhnke Skill Code ReviewReview code changes for quality, security, and best practices. Use when reviewing staged changes, pull requests, or specific files before merging.
-
epochdevs Skill Audit Exhibit A DefAudit an Exhibit A study definition by comparing it against the original reference image and transcript. Use when the user wants to review, audit, or fix a definition to match the Exhibit A source material. Checks for: visual match, data-driven approach (no hardcoded values), correct data source/range, chart type accuracy, and proper labeling.
-
bmad-code-org Bundle Bmad Testarch NfrAudit NFR evidence for performance, security, reliability, and maintainability. Use when implementation evidence exists and the user says "audit NFR evidence", "audit NFRs", or "evaluate non-functional requirements"
-
photoszzt Skill Tla ReviewThis skill runs a comprehensive review of a TLA+ specification including parsing, symbol extraction, smoke testing, and best practices checklist. It should be used when the user asks to "review my spec", "audit my spec", "is my spec good", "spec quality check", "comprehensive review", "best practices check", "check spec quality", "spec review", "analyze my spec", "what's wrong with my spec", "review my TLA+ spec", "spec health check", "validate my specification", or wants a full quality assessment.
-
pluginagentmarketplace Bundle SecurityJavaScript security best practices and vulnerability prevention.
-
bkircher Skill Snyk CLIScan and triage Snyk security findings in local repositories and container images. Use for Snyk vulnerability reviews, scan summaries, severity filtering, and remediation planning.
-
martin-janci Bundle Code ReviewReview a pull request diff for bugs, security issues, and code quality. Use when reviewing PRs or diffs.
-
rejectall Bundle Privacy Policy Pipl Audit基于《中华人民共和国个人信息保护法》(PIPL)及GB/T 35273-2020对隐私政策/隐私协议进行全面合规审查。当用户需要审查隐私政策合规性、检查隐私协议是否符合个人信息保护法、或对隐私协议进行整改优化时使用此技能。触发词:隐私政策审查、隐私协议合规、个人信息保护法审查、PIPL合规、隐私协议整改。
-
hardw00t Bundle IOS PentestiOS mobile application penetration testing with Frida and Objection on jailbroken or non-jailbroken devices. Use for static + dynamic analysis of IPAs, SSL pinning / jailbreak / biometric bypass, keychain & local-storage extraction, network interception, and OWASP MASTG iOS assessments. Triggers on requests to pentest iOS apps, analyze IPAs, bypass iOS security controls, or produce MASTG-aligned findings.
-
hardw00t Bundle API SecurityRouter skill for API penetration testing across REST, GraphQL, gRPC, and WebSocket. Covers OWASP API Top 10 (2023) including BOLA/BFLA/BOPLA, JWT attack chains, GraphQL introspection abuse, and mass assignment. Invoke when the user asks to pentest an API, analyze OpenAPI/Swagger, test auth/authorization, fuzz endpoints, or find API vulnerabilities.
-
hardw00t Bundle Sca SecuritySoftware Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to suppress unexploitable findings. Use when scanning package dependencies (npm, PyPI, Maven, Cargo, Go, RubyGems, Composer), reviewing PR lockfile diffs, generating SBOMs, auditing licenses, hunting malicious packages, or auditing the software supply chain. Triggers on requests to scan dependencies, check vulnerable packages, generate SBOM, license compliance, typosquat/dependency-confusion review, or reachability-based vuln triage.
-
lukasstrickler Bundle Code ReviewReview code changes using CodeRabbit CLI - supports uncommitted files (task mode) or all PR files vs main branch (pr mode). Catches bugs, security issues, and code quality problems before committing or when reviewing pull requests. Use when: (1) Reviewing uncommitted changes before committing (task mode), (2) Reviewing all changed files in a PR against main branch (pr mode), (3) Working on subtasks and want to check progress, (4) Need feedback on work-in-progress code, (5) Preparing PR for merge, (6) When CodeRabbit review is needed, (7) For bug detection and security scanning, or (8) For automated code quality assessment. Triggers: review code, check code quality, review changes, code review, review PR, check for bugs, security scan, review uncommitted, finalize code, pre-commit review.
-
pymc-labs-causalpy Bundle Review PrReview CausalPy pull requests end-to-end by classifying PR type, checking branch freshness, mergeability, remote CI, correctness, security, tests, docs, and maintainer concerns. Use when asked to review a PR, assess a branch before merge, summarize PR risks, or request changes.
-
pymc-labs-causalpy Bundle Causal DetectiveChallenge causal claims through structured threat assessment, counterfactual reasoning, and CausalPy falsification checks. Use when validating whether a causal effect is real or when the user asks "is this effect real?" or "can I trust this result?"
-
openocta Bundle Djbh AssessmentInvoke for 等保2.0 full-lifecycle assessment on corporate networks on Kali Linux: classification, gap analysis, baseline audit, vuln scanning, penetration testing, and compliance reporting per GB/T 22239-2019.
-
nbbaier Bundle NPM Supply Chain SecurityAudit and harden Node.js projects against npm supply chain attacks — compromised maintainer accounts, malicious package versions, and install-script payloads. Use when reviewing or setting up package.json, lockfiles, .npmrc, Dockerfile, or CI workflows for security; when the user mentions npm security, supply chain attacks, `npm audit`, lockfile policy, install scripts, or min-release-age; also when the user wants to check whether their dependencies are safe, or recover from a suspected compromise.
-
zhanghandong Skill Cowork GuideCRITICAL: Comprehensive guide for CoWork Skills CLI tool. Triggers on: cowork, Skills.toml, skill management, plugin configuration, cowork init, cowork install, cowork config, cowork generate, cowork audit, cowork verify, cowork test
-
michtio Bundle Craft PestTesting Craft CMS 5 plugins and modules with Pest — test isolation, database safety, and the markhuot/craft-pest-core harness. ALWAYS load when writing, running, fixing, or reviewing tests for a Craft plugin or module, and whenever a suite touches a real Craft install. Covers why rollback is opt-in, tests/Pest.php + tests/bootstrap.php wiring, phpunit.xml.dist <env> pins (force DB name + table prefix, default connection coordinates, pin CRAFT_ENVIRONMENT against server-scoped locks), why --configuration= defeats DB isolation, throwing fail-closed DB guards, installing the plugin under test, process-timezone pinning, per-test site fixtures, idempotent Install migrations, stale service caches when components get swapped, muting audit sinks, queue stubs, factories, HTTP/DB assertions, CI test jobs. Triggers on: Pest, pestphp, craft-pest-core, markhuot, RefreshesDatabase, InstallsCraft, tests/Pest.php, phpunit.xml.dist, vendor/bin/pest, composer test, ddev craft pest, db_test, CRAFT_DB_DATABASE, CRAFT_ENVIRONMENT
-
thepm001 Skill Aep Caw Policy EditUse when adding, removing, or updating rules in an existing AepCaw policy, modifying security permissions, HTTP service declarations, Postgres-family database rules, resource limits, or policy YAML files
-
mojoauth Bundle Oidc Hosted Page JavaImplement passwordless authentication in Java Spring Boot applications using MojoAuth OIDC with Spring Security.
-
0xsarwagya Bundle Security ReviewReview authentication, authorization, and security-sensitive flows using Ontoly graph evidence. Use when asked about auth ownership, protected routes, permissions, guards, or security risk.
-
0xsarwagya Bundle Configuration AnalysisAudit configuration and environment variable usage through Ontoly configuration capabilities. Use when asked where env vars, build config, runtime config, or feature flags are read.
-
runtypelabs Bundle Tool Design SecurityDesign tool identity, credential injection, authorization, tenant scope, and audit boundaries.
-
get-maito Skill Local Source AuditUse when the user asks to audit local sources, find missing sources, improve event or story coverage, review a local source list, identify weak coverage areas, or prepare source updates for a local newsletter workspace.
-
thrownlemon Skill Damage ControlSecurity protection system that blocks dangerous commands and protects sensitive files
-
xpozpublic Skill Security OsintMonitor social platforms for security threats, vulnerability discussions, and breach intelligence using Xpoz. Use when asked to "find CVE discussions", "security threat monitoring", "OSINT social media", "vulnerability intelligence", "breach mentions", or "threat intel from Twitter/Reddit".
-
xpozpublic Skill Geo Visibility CheckOne-shot GEO visibility check for a brand using Xpoz. Runs the buyer questions that matter through Claude, ChatGPT, and Gemini, and reports where the brand appears, who wins instead, and which surfaces the answers are assembled from. Use when asked to "check my AI visibility", "does ChatGPT recommend us", "GEO audit", "where do we show up in AI answers", or "who wins our category in AI answers".
-
deveclipsy007 Bundle Auth Rbac HardeningFortalece autenticacao, sessao e autorizacao baseada em papeis no LLMInvoice.
-
duthaho Skill Audit DependenciesUse when investigating dependency bloat, security advisories, supply-chain risk, upgrade planning, or before adding a new third-party package. Activate for keywords like "deps", "dependencies", "package.json", "requirements.txt", "Cargo.toml", "audit", "CVE", "stale package", "do we use", "what depends on", "transitive dep". Produces a written audit with import-graph evidence — never trust scanner output without verifying call sites.
-
0xjitsu Skill Dep AuditAudits project dependencies for known vulnerabilities, outdated packages, and unused modules. Triggered when a user asks to check for vulnerabilities, audit dependencies, or run a security scan on installed packages. Produces a severity-sorted findings table with one-liner fix commands and cross-references Sonatype for recommended versions.
-
0xjitsu Skill Secret ScannerScans the full git history of a repository for leaked secrets, API keys, tokens, and credentials. Triggered when a user asks to audit commits for exposed credentials, run a pre-publish security check, or scan git history for sensitive data. Produces a severity-ranked findings table with remediation commands. Read-only — never modifies git history automatically.
-
0xjitsu Skill Keychain ManagerManages secrets and API keys in the macOS Keychain using the security CLI. Triggered when a user asks to store, retrieve, list, rotate, or delete tokens and credentials. Uses a consistent naming convention with the bbmisa account and uppercase service names. Never exposes secrets in plaintext output or commits them to git.
-
nobrainer-tech Skill Nobrainer ReviewUse when the owner says nb-review, deep-audit, deep-code-review, or deep-autoreview; explicitly requests an evidence-gated CLOSEOUT, adversarial BUG_HUNT or RELEASE_GATE; or needs final findings filtered to verified actionable defects. Use nobrainer-build for ordinary implementation and correction work.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include dep-audit, codebase-audit, npm-supply-chain-security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.