Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
peterbamuhigire Bundle Skill WritingUse when creating or upgrading reusable skills, specialist-role instructions, or vendor adapters. Covers agent-versus-skill boundaries, model-neutral canonical sources, triggers, capability and output contracts, progressive disclosure, validation, and repository quality gates.
-
peterbamuhigire Skill Dpia GeneratorUse when producing or reviewing a Data Protection Impact Assessment (DPIA) for a new feature or for Uganda DPPA-regulated, large-scale, sensitive, monitored, or high-risk personal-data processing.
-
peterbamuhigire Bundle Gis Enterprise DomainUse when administering ArcGIS Enterprise or building real-estate-specific GIS features — ArcGIS components, publishing services, security/roles, backup/DR, plus property search, neighbourhood analysis, catchment/isochrones, market heatmaps, and real-estate-SaaS integration.
-
oliver-kriska Bundle Phx AuditProject health audit and health check — architecture, performance, tests, dependencies, code quality. Use when assessing overall project health, before releases, or after refactors.
-
oliver-kriska Bundle SecurityEnforce Elixir/Phoenix security — auth, OAuth, sessions, CSRF, XSS; Use when editing auth files, login flows, RBAC…
-
peterbamuhigire Bundle IOS Security And RbacUse when designing or reviewing iOS authentication, Keychain, App Attest, privacy manifests, permissions, RBAC, tenant isolation, or AI security; use ios-development for general implementation.
-
peterbamuhigire Bundle Network SecurityUse when designing, hardening, or auditing network security for self-managed SaaS infrastructure, including firewalls, WAF, VPN, TLS/PKI, IDS/IPS, SSH, segmentation, DDoS, and DNS controls.
-
oliver-kriska Bundle Phx Deps VetRecord vetted Hex versions after security review. Use to approve audited dependencies, not to scan them.
-
oliver-kriska Bundle AuditProject health audit and health check — architecture, performance, tests, dependencies, code quality. Use when assessing overall project health, before releases, or after refactors.
-
oliver-kriska Bundle Phx Deps AuditAudit Hex deps for supply-chain security risk — bidi chars; Use after mix deps.update, when checking if a package…
-
peterbamuhigire Bundle Skill Engine AuditUse when auditing, grading, benchmarking, or conforming an entire skills engine. Measures taxonomy, doctrine, contracts, depth, routing, safety, references, output readiness, and normalisation priorities.
-
peterbamuhigire Skill Skill Safety AuditUse when reviewing new, imported, or changed skills for unsafe tools, installers, credential harvesting, hidden execution, prompt injection, excessive permissions, data exfiltration, or improperly retained third-party source content.
-
peterbamuhigire Bundle Code Safety ScannerUse when scanning a codebase before deployment for critical vulnerabilities, server-error risks, unsafe AI-generated code, dependency problems, or payment misconfiguration.
-
peterbamuhigire Bundle Vibe Security SkillUse when designing or reviewing application, API, or multi-tenant SaaS security. Produces threat models, abuse cases, authorisation matrices, secret plans, and OWASP-aligned evidence.
-
oliver-kriska Bundle ReviewReview code with parallel agents — tests, security, Ecto, LiveView, Oban. Use after implementation to catch bugs and anti-patterns before committing.
-
oliver-kriska Bundle Deps VetRecord a vetted Hex package version in hex_vet.exs after a security review — manages the audit ledger, not the scanner. Use to approve a dep after /phx:deps-audit findings or to initialize hex_vet.exs.
-
oliver-kriska Bundle Narrow Bare RescueNarrow bare rescue in Elixir so real errors like KeyError and typos; Use to audit rescues and refactor error handling.
-
oliver-kriska Bundle Deps AuditAudit Hex deps for supply-chain security risk — bidi chars, compile-time exec, maintainer changes, typosquats, CVEs. Use after mix deps.update, when checking if a package upgrade is safe, or reviewing mix.lock PR diffs.
-
oliver-kriska Skill Assigns AuditInspect LiveView socket assigns for memory bloat — missing temporary_assigns, unused assigns, unbounded lists needing streams, memory estimates. Use when LiveView memory grows or you need to add temporary_assigns.
-
peterbamuhigire Bundle Saas Managed Visual AssetsUse when implementing or reviewing Super Admin or tenant-scoped managed visual assets—background image pools, light/dark logos, or favicons—with secure upload, preview, ordering, activation, replacement, quotas, and audit evidence.
-
goldenzero Bundle Audit Prep AssistantPrepare audit-ready documentation packages for internal audits, external audits, regulatory inspections, and retailer compliance audits in CPG organizations. Use when preparing for an upcoming audit, organizing evidence, conducting pre-audit self-assessments, or building audit response strategies.
-
faberlens Bundle Snyk HardenedComprehensive security analysis and vulnerability assessment — threat modeling, secure code review, and pre-deployment security validation across application and infrastructure layers.
-
peterbamuhigire Bundle Linux Security HardeningUse when hardening or auditing Debian and Ubuntu hosts for identity, sudo, PAM, MFA, permissions, AppArmor, auditd, kernel, patching, integrity, boot, encryption, and CIS controls.
-
peterbamuhigire Bundle Saas Admin Backoffice ToolingUse when designing audited SaaS back-office impersonation, tenant lifecycle, billing overrides, bulk actions, or audit controls.
-
peterbamuhigire Bundle Multi Tenant Saas ArchitectureUse when designing tenant isolation, panel boundaries, zero-trust authorization, audit trails, or tenant permission overrides.
-
peterbamuhigire Bundle Kaizen Improvement SystemUse when auditing or improving this engineering engine or a product it produces. Coordinates evidence-backed baselines, small experiments, standardisation, and re-audits without replacing domain skills.
-
peterbamuhigire Bundle Accounting EngineUse when designing, implementing, or reviewing an embedded accounting engine with append-only ledgers, mapped postings, idempotency, reversals, period locks, audit trails, and integrity tests.
-
faberlens Bundle Postgres Patterns HardenedPostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices.
-
v1truv1us-ai-eng-system Bundle Security And HardeningOWASP Top 10 prevention, auth patterns, secrets management, dependency auditing, boundary validation. Use when handling user input, auth, or external integrations.
-
v1truv1us-ai-eng-system Bundle Thermo Nuclear Performance ReviewRun an extremely strict performance review for runtime efficiency, memory usage, bundle size, database query patterns, and scalability limits. Use for a thermo-nuclear performance review, thermonuclear performance audit, or especially harsh performance review.
-
v1truv1us-ai-eng-system Bundle Thermo Nuclear Architecture ReviewRun an extremely strict architecture and system design review for coupling, boundary violations, dependency direction, layering, and structural decay. Use for a thermo-nuclear architecture review, thermonuclear system design audit, or especially harsh architecture review.
-
faberlens Skill Healthkit Sync HardenediOS HealthKit data sync CLI commands and patterns. Use when working with healthsync CLI, fetching Apple Health data (steps, heart rate, sleep, workouts), pairing iOS devices over local network, or understanding the iOS Health Sync project architecture including mTLS certificate pinning, Keychain storage, and audit logging.
-
grtninja Bundle HealthcheckHost security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).
-
grtninja Bundle Skill AuditorAudit skill candidates and classify each changed skill as unique or upgrade with severity findings. Use when creating/updating skills, preparing admission evidence, or producing audit JSON for skill-game scoring.
-
faberlens Bundle Code Review HardenedAI-powered code analysis via LogicArt — find bugs, security issues, and get logic flow visualizations. Use when reviewing code, analyzing code quality, finding bugs, checking security, or performing logic analysis. Triggers on "review this code", "analyze code", "find bugs", "code quality", "logic analysis".
-
faberlens Bundle Obsidian Organizer HardenedOrganize and standardize Obsidian vaults for reliability and long-term maintainability. Use when designing or cleaning vault folder structure, enforcing file naming conventions, migrating messy vaults, reducing duplicate/ambiguous notes, or creating repeatable audit-and-fix workflows for Obsidian notes.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include review, deps-audit, audit-prep-assistant. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.