Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
developerscoffee Skill Cwe 780 Rsa Without OaepUse this skill when you need to remediate CWE-780 (RSA Without OAEP Padding) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing rsa without oaep padding issues.
-
developerscoffee Skill Cwe 191 Integer UnderflowUse this skill when you need to remediate CWE-191 (Integer Underflow) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing integer underflow issues.
-
developerscoffee Skill Cwe 327 Weak CryptographyUse this skill when you need to remediate CWE-327 (Use of a Broken or Risky Cryptographic Algorithm) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing use of a broken or risky cryptographic algorithm issues.
-
developerscoffee Skill Cwe 329 Missing Random IvUse this skill when you need to remediate CWE-329 (Missing Random IV in CBC Mode) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing missing random iv in cbc mode issues.
-
developerscoffee Skill Cwe 359 Privacy ViolationUse this skill when you need to remediate CWE-359 (Privacy Violation) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing privacy violation issues.
-
developerscoffee Skill Cwe 259 Hardcoded PasswordUse this skill when you need to remediate CWE-259 (Hardcoded Password) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing hardcoded password issues.
-
developerscoffee Skill Cwe 328 Weak Hash AlgorithmUse this skill when you need to remediate CWE-328 (Weak Hash Algorithm (MD5/SHA1)) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing weak hash algorithm (md5/sha1) issues.
-
developerscoffee Skill Cwe 400 Resource ExhaustionUse this skill when you need to remediate CWE-400 (Uncontrolled Resource Consumption) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing uncontrolled resource consumption issues.
-
developerscoffee Skill Cwe 78 Os Command InjectionUse this skill when you need to remediate CWE-78 (Improper Neutralization of OS Command) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing improper neutralization of os command issues.
-
developerscoffee Skill Cwe 200 Information ExposureUse this skill when you need to remediate CWE-200 (Information Exposure) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing information exposure issues.
-
developerscoffee Skill Cwe 321 Hardcoded Crypto KeyUse this skill when you need to remediate CWE-321 (Hard-coded Cryptographic Key) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing hard-coded cryptographic key issues.
-
developerscoffee Skill Cwe 347 JWT Signature BypassUse this skill when you need to remediate CWE-347 (JWT Signature Bypass) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing jwt signature bypass issues.
-
developerscoffee Skill Cwe 776 XML Entity ExpansionUse this skill when you need to remediate CWE-776 (XML Entity Expansion (Billion Laughs)) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing xml entity expansion (billion laughs) issues.
-
developerscoffee Skill Cwe 311 Non Encrypted StorageUse this skill when you need to remediate CWE-311 (Missing Encryption of Sensitive Data) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing missing encryption of sensitive data issues.
-
masanao-ohba Skill Evaluation CriteriaInvoke when deliverable-evaluator needs scoring methodology for assessment. Provides evaluation dimensions (completeness, correctness, quality, security, performance), severity classification, pass/fail thresholds, and structured verdict output format.
-
masanao-ohba Skill Completion EvaluatorInvoke when deliverable-evaluator assesses a completed task against its acceptance criteria. Provides dimension-based evaluation (completeness, correctness, quality, security, performance), pass/fail determination with evidence, and rework instructions on FAIL.
-
developerscoffee Skill Cwe 367 Race Condition ToctouUse this skill when you need to remediate CWE-367 (Race Condition (TOCTOU)) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing race condition (toctou) issues.
-
developerscoffee Skill Cwe 798 Hardcoded CredentialsUse this skill when you need to remediate CWE-798 (Hardcoded Credentials) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing hardcoded credentials issues.
-
developerscoffee Skill Cwe 820 Unsynchronized AccessUse this skill when you need to remediate CWE-820 (Missing Synchronization) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing missing synchronization issues.
-
developerscoffee Skill Cwe 209 Error Message ExposureUse this skill when you need to remediate CWE-209 (Information Exposure Through Error Message) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing information exposure through error message issues.
-
developerscoffee Skill Cwe 306 Missing AuthenticationUse this skill when you need to remediate CWE-306 (Missing Authentication for Critical Function) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing missing authentication for critical function issues.
-
developerscoffee Skill Cwe 307 Brute Force ProtectionUse this skill when you need to remediate CWE-307 (Improper Restriction of Excessive Authentication Attempts) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing improper restriction of excessive authentication attempts issues.
-
developerscoffee Skill Cwe 319 Cleartext TransmissionUse this skill when you need to remediate CWE-319 (Cleartext Transmission of Sensitive Information) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing cleartext transmission of sensitive information issues.
-
developerscoffee Skill Cwe 532 Sensitive Info In LogsUse this skill when you need to remediate CWE-532 (Sensitive Information in Logs) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing sensitive information in logs issues.
-
developerscoffee Skill Cwe 113 HTTP Response SplittingUse this skill when you need to remediate CWE-113 (HTTP Response Splitting) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing http response splitting issues.
-
developerscoffee Skill Cwe 284 Improper Access ControlUse this skill when you need to remediate CWE-284 (Improper Access Control) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing improper access control issues.
-
developerscoffee Skill Cwe 287 Improper AuthenticationUse this skill when you need to remediate CWE-287 (Improper Authentication) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing improper authentication issues.
-
developerscoffee Skill Cwe 377 Insecure Temporary FileUse this skill when you need to remediate CWE-377 (Insecure Temporary File) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing insecure temporary file issues.
-
developerscoffee Skill Cwe 434 Unrestricted File UploadUse this skill when you need to remediate CWE-434 (Unrestricted Upload of File with Dangerous Type) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing unrestricted upload of file with dangerous type issues.
-
developerscoffee Skill Cwe 501 Trust Boundary ViolationUse this skill when you need to remediate CWE-501 (Trust Boundary Violation) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing trust boundary violation issues.
-
developerscoffee Skill Cwe 606 Unchecked Loop ConditionUse this skill when you need to remediate CWE-606 (Unchecked Input for Loop Condition) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing unchecked input for loop condition issues.
-
developerscoffee Skill Cwe 693 Missing Security HeadersUse this skill when you need to remediate CWE-693 (Missing Security Headers (Clickjacking)) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing missing security headers (clickjacking) issues.
-
developerscoffee Skill Cwe 732 Improper File PermissionsUse this skill when you need to remediate CWE-732 (Improper File Permissions) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing improper file permissions issues.
-
developerscoffee Skill Cwe 295 Insecure Tls Trust ManagerUse this skill when you need to remediate CWE-295 (Insecure TLS/SSL Configuration) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing insecure tls/ssl configuration issues.
-
developerscoffee Skill Cwe 552 Files Accessible ExternallyUse this skill when you need to remediate CWE-552 (Files Accessible to External Parties) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing files accessible to external parties issues.
-
developerscoffee Skill Cwe 917 Expression Language InjectionUse this skill when you need to remediate CWE-917 (Expression Language Injection) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing expression language injection issues.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include cwe-798-hardcoded-credentials, cwe-780-rsa-without-oaep, cwe-191-integer-underflow. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.