Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
developerscoffee Skill Cwe 434 Unrestricted File UploadUse this skill when you need to remediate CWE-434 (Unrestricted Upload of File with Dangerous Type) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing unrestricted upload of file with dangerous type issues.
-
developerscoffee Skill Cwe 501 Trust Boundary ViolationUse this skill when you need to remediate CWE-501 (Trust Boundary Violation) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing trust boundary violation issues.
-
developerscoffee Skill Cwe 606 Unchecked Loop ConditionUse this skill when you need to remediate CWE-606 (Unchecked Input for Loop Condition) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing unchecked input for loop condition issues.
-
developerscoffee Skill Cwe 693 Missing Security HeadersUse this skill when you need to remediate CWE-693 (Missing Security Headers (Clickjacking)) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing missing security headers (clickjacking) issues.
-
developerscoffee Skill Cwe 732 Improper File PermissionsUse this skill when you need to remediate CWE-732 (Improper File Permissions) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing improper file permissions issues.
-
developerscoffee Skill Cwe 295 Insecure Tls Trust ManagerUse this skill when you need to remediate CWE-295 (Insecure TLS/SSL Configuration) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing insecure tls/ssl configuration issues.
-
developerscoffee Skill Cwe 552 Files Accessible ExternallyUse this skill when you need to remediate CWE-552 (Files Accessible to External Parties) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing files accessible to external parties issues.
-
developerscoffee Skill Cwe 917 Expression Language InjectionUse this skill when you need to remediate CWE-917 (Expression Language Injection) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing expression language injection issues.
-
developerscoffee Skill Cwe 326 Inadequate Encryption StrengthUse this skill when you need to remediate CWE-326 (Inadequate Encryption Strength) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing inadequate encryption strength issues.
-
developerscoffee Skill Cwe 613 Insufficient Session ExpirationUse this skill when you need to remediate CWE-613 (Insufficient Session Expiration) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing insufficient session expiration issues.
-
developerscoffee Skill Cwe 522 Insufficiently Protected CredentialsUse this skill when you need to remediate CWE-522 (Insufficiently Protected Credentials) vulnerabilities in Java code. Triggers on SAST findings, security reviews, or when fixing insufficiently protected credentials issues.
-
alanlee0323 Skill Auditing CodePerforms static analysis, security scanning, and code quality auditing to detect vulnerabilities, secrets, and anti-patterns.
-
alanlee0323 Bundle Researching DeeplySystematic deep-investigation methodology for auditing codebases, evaluating systems, and researching complex questions. Enforces breadth-first mapping, claim-evidence discipline, cross-artifact consistency checks, and negative-space analysis. Use when the user asks for a deep review, audit, investigation, 深度檢視, 盤點, 稽核, or when a conclusion will drive an important decision.
-
tenequm Bundle Standard ReadmeWrites or audits READMEs against the Standard Readme spec. Use whenever the user asks to create, rewrite, improve, audit, or fix a README, or asks about README quality or structure - even if they never mention "standard readme".
-
evolinkai-evolink-skills Bundle Email AssistantAI-powered email writing, review, and compliance checking. Generate templates, optimize subject lines, audit for spam triggers, and check CAN-SPAM/GDPR/CASL compliance. Powered by evolink.ai
-
alanlee0323 Bundle Maintaining Skill LibraryGovernance loop for this skill library. Defines the single-source-of-truth map, the validation workflow, the definition of done for adding or changing skills, the evolution-log convention, and the periodic drift audit. Use when adding, renaming, moving, or retiring a skill, when updating bundles or routing, or when the user asks 維護, 盤點, 一致性檢查, or library health.
-
fabioc-aloha Skill Problem Framing AuditStep-back protocol — restate, generalise, specialise, invert, ask why, pre-mortem, check stakeholders, and audit framings before solving
-
fabioc-aloha Skill Markdown Sanitization ChainRender user-supplied markdown safely — marked.js → DOMPurify → Mermaid (order matters; skipping the sanitizer is XSS)
-
omkar-ukirde Skill WebWeb application security testing skills organized by OWASP Top 10 2021 categories.
-
omkar-ukirde Skill Web3 AuditSmart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for any Solidity/Rust contract audit or when deciding whether a DeFi target is worth hunting.
-
respira-press Bundle Wordpress Site DnaUse when the user says 'analyze my wordpress site', 'what is running on my site', 'site dna', or 'what plugins are on my site'. Detects every page builder, audits active versus dead-weight plugins, maps content structure, finds orphaned shortcodes, and checks performance and security posture.
-
omkar-ukirde Bundle A07 Auth FailuresSkills for exploiting authentication and session management vulnerabilities including JWT, OAuth, and 2FA bypass per OWASP A07:2021.
-
omkar-ukirde Bundle A01 Broken Access ControlSkills for testing broken access control vulnerabilities including IDOR, CSRF, CORS misconfigurations, and open redirects per OWASP A01:2021.
-
omkar-ukirde Bundle A05 Security MisconfigurationSkills for exploiting security misconfigurations including XXE, file upload, subdomain takeover, and cache issues per OWASP A05:2021.
-
respira-press Bundle Technical Debt AuditUse when the user says 'clean up my wordpress', 'what is bloating my wordpress', 'find orphaned shortcodes', or 'scan for unused plugins'. Audits orphaned shortcodes from deleted plugins, unused plugins, database bloat, unused media, and leftover data from inactive builders.
-
respira-press Skill Activity Report ComposerUse when the user asks for a client report, a monthly or activity report, a case study draft, or says 'what did i ship this month'. Turns the site audit log into a written report in one of six framings: agency client report, case study, internal recap, testimonial draft, build-in-public, personal recap.
-
respira-press Bundle Mobile Experience ReportUse when the user says 'my site looks bad on mobile', 'check mobile layout', 'responsive audit', or 'site broken on phones'. Diagnoses breakpoint problems, text sizing, column stacking failures, hidden elements, and navigation menu behavior, device by device.
-
respira-press Bundle Woocommerce Health CheckUse when the user says 'why is my checkout broken', 'audit my woocommerce store', 'cart problems woocommerce', or 'losing sales woocommerce'. Diagnoses checkout and cart failures, AJAX mismatches, caching conflicts, payment gateway setup, and SSL enforcement.
-
respira-press Bundle Wordpress AI Image OptimizerUse when the user says 'optimize my wordpress images with ai', 'compress and optimize all images', 'audit my media library', or 'improve image performance'. Downloads images, compresses, converts to WebP, resizes and renames locally, re-uploads, and updates every content reference.
-
aspiers Skill Code ReviewingReview changed code for correctness, security, maintainability, and verification gaps. Use when code is ready for independent review or before handoff, staging, or merge.
-
eroslifestyle Skill Security ScanRun a security audit on the codebase checking for common vulnerabilities. Use /security-scan for OWASP-style review.
-
lucasilverentand Skill Design ReviewReviews and critiques an existing or proposed system design — flags single points of failure, missing non-functional requirements, scaling bottlenecks, security gaps, operational blind spots, unjustified tech choices, and places where the design will fall over under load or failure. Produces a structured review with severity-tagged findings, not just vibes. Use when the user asks for a second opinion on an architecture, requests a design review, wants feedback on a proposed system, pastes a design doc, or says things like "review this design", "what's wrong with X", "poke holes in this", or "is this a good architecture".
-
dexploarer Bundle Security Header GeneratorGenerates security HTTP headers (CSP, HSTS, CORS, etc.) for web applications to prevent common attacks. Use when user asks to "add security headers", "setup CSP", "configure CORS", "secure headers", or "HSTS setup".
-
lucasilverentand Bundle Tidy Linear ProjectKeeps an existing Linear project tidy after planning and during execution. Use when the user asks to "tidy Linear", "clean up the project", "audit issues", "find duplicates", "check stale blockers", "fix project drift", or run periodic Linear housekeeping on a project, initiative, or milestone set. Use when planning is underway or execution has started and relationships, labels, priorities, documents, and issue states need coherence without changing product scope.
-
lucasilverentand Skill Open Source DocsCreates, audits, and updates public open-source repository documentation, including README files, CONTRIBUTING guides, SECURITY and SUPPORT docs, project badges, quickstarts, usage guidance, community links, and contributor onboarding. Use when maintaining docs for public GitHub projects, libraries, CLIs, apps, or reusable packages, especially when the user says "update this README", "write CONTRIBUTING.md", "make these docs open-source ready", or "improve the public project docs".
-
camoa Skill CheckRun every available check against a Claude Code plugin — the first-party validator, plugin-dev's linters, and three checks nothing else performs. Use when asked to validate, check, audit, or review a plugin, or before publishing one.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include web3-audit, researching-deeply, a07-auth-failures. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.