Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
faberlens Bundle Security Vuln Scanner HardenedScan source code for security vulnerabilities and suggest fixes.
-
darthlinuxer Skill Nodejs Best PracticesNode.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.
-
darthlinuxer Bundle Vulnerability ScannerAdvanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization.
-
peterbamuhigire Bundle Electronic Fiscal TaxingUse when implementing or reviewing electronic fiscal taxation integrations in web, ERP, POS, or mobile-backed systems; covers jurisdiction adapters, tenant-scoped tax identities, API security, queues, offline operation, fiscal evidence, and Uganda EFRIS as the detailed reference.
-
peterbamuhigire Bundle Saas Tenant Data Portability And ErasureUse when designing verified tenant data export, retention, erasure, backup handling, audit evidence, or privacy-law portability workflows.
-
peterbamuhigire Bundle Ecommerce Platform Audit RequirementsUse when scoping or specifying an e-commerce platform, payment, API, security, AI, data protection, integration, and remediation audit for SMEs or cross-border digital trade programmes.
-
peterbamuhigire Bundle Game Security Anti Cheat And AbuseUse when threat-modelling a game client/server, validating actions, protecting game economy and accounts, detecting tampering or cheats, limiting bots and abuse, investigating incidents, or designing proportionate enforcement and appeals.
-
elsolal Skill Security AuditorAudit de sécurité du code. Analyse OWASP Top 10, dépendances vulnérables, secrets exposés, et configurations. Utiliser après l'implémentation ou avant une release.
-
elsolal Skill Supabase SecurityAudit de sécurité complet pour les projets Supabase. Lance un pentest automatisé qui vérifie RLS, buckets, auth, keys exposées, et génère un rapport avec remediation. Utiliser quand l'utilisateur dit "audit supabase", "sécurité supabase", "vérifier mon supabase", ou veut s'assurer que son backend Supabase est sécurisé.
-
elsolal Skill Performance AuditorAudit de performance du code et de l'application. Analyse Lighthouse, bundle size, Core Web Vitals, et optimisations. Utiliser après l'implémentation, avant une release, ou quand l'utilisateur dit "performance", "slow", "optimize", "bundle size".
-
alexei-led Bundle Reviewing CodeUse when reviewing changed code, PRs, diffs, or specific files. Finds evidence-backed defects in security, correctness, tests, reliability, performance, maintainability, and docs. Supports quick, standard, deep, team, and external-review modes. NOT for repo-wide architecture review, general codebase exploration, fixing issues (use fixing-code), improving tests without a code review (use improving-tests), or applying refactors (use refactoring-code).
-
elsolal Skill Thermo Nuclear Code Quality ReviewRuns an unusually strict code-quality and maintainability review. Use when the user asks for a thermo-nuclear or thermonuclear review, a very harsh code-quality audit, a deep maintainability review, or a structural simplification pass before ship. Produces prioritized structural findings and concrete cleaner-design remedies.
-
peterbamuhigire Bundle Bds Intake And Monitoring System SpecUse when specifying application intake, eligibility screening, selection scoring, beneficiary registers, diagnostics tracking, expert deployment, monitoring dashboards, RBAC, audit trails, and donor reporting for BDS programmes.
-
alexei-led Bundle Configuring Git HygieneConfigure safe git workflow hygiene: pre-commit/pre-push hooks, Gitleaks secret scanning, .gitignore rules, local git config, and guardrails. Use when setting up git hooks, gitleaks/git leaks, staged pre-commit checks, pre-push validation, core.hooksPath, .gitignore, or git config best practices. NOT for creating commits (use committing-code), cleaning branches/worktrees (use cleanup-git), or creating worktrees (use using-git-worktrees).
-
megastep Bundle Ads AuditFull multi-platform paid advertising audit with parallel subagent delegation. Analyzes Google Ads, Meta Ads, LinkedIn Ads, TikTok Ads, and Microsoft Ads accounts. Generates health score per platform and aggregate score. Use when user says "audit", "full ad check", "analyze my ads", "account health check", or "PPC audit".
-
megastep Bundle Blog AuditFull-site blog health assessment scanning all blog files for quality scores, orphan pages, topic cannibalization, stale content, and AI citation readiness. Spawns parallel subagents for comprehensive analysis. Produces per-post scores and a prioritized action queue. Use when user says "audit blog", "blog audit", "site audit", "blog health", "audit all posts", "check all blogs".
-
megastep Bundle Ads LandingLanding page quality assessment for paid advertising campaigns. Evaluates message match, page speed, mobile experience, trust signals, form optimization, and conversion rate potential. Use when user says "landing page", "post-click experience", "landing page audit", "conversion rate", or "landing page optimization".
-
kanevry Skill Hook DevelopmentUse when creating, modifying, or debugging Claude Code hooks — PreToolUse, PostToolUse, Stop, SubagentStop, SessionStart, SessionEnd, UserPromptSubmit, PreCompact, Notification. Covers the plugin `hooks/hooks.json` wrapper format vs. the user `settings.json` direct format, matchers, security patterns, `$CLAUDE_PLUGIN_ROOT` portability, lifecycle limitations, and debugging. Trigger on "add a hook", "validate tool use", "block dangerous commands", "enforce completion", "hook-based automation".
-
megastep Bundle Test MasterUse when writing tests, creating test strategies, or building automation frameworks. Invoke for unit tests, integration tests, E2E, coverage analysis, performance testing, security testing.
-
megastep Bundle Ads CreativeCross-platform creative quality audit covering ad copy, video, image, and format diversity across all platforms. Detects creative fatigue, evaluates platform-native compliance, and provides production priorities. Use when user says "creative audit", "ad creative", "creative fatigue", "ad copy", "ad design", or "creative review".
-
infrasity-labs Bundle Llms Txt CheckerAudits any domain's AI-readiness by using curl to directly probe robots.txt, llms.txt, and llms-full.txt, then scores each file against a structured checklist and delivers a formatted report with pass/warn/fail findings and actionable fixes. Use this skill whenever a user provides a domain or URL and wants to know if llms.txt or llms-full.txt is available, discoverable, or properly structured. Trigger on phrases like "check llms.txt for", "does this site have llms.txt", "find llms.txt", "check llms for this url", "audit llms.txt", "is llms-full.txt available", or any time a user shares a domain/docs URL and wants AI-readiness checked. Also trigger when the user wants to verify GEO/AEO readiness of a documentation site.
-
megastep Bundle Code ReviewerUse when reviewing pull requests, conducting code quality audits, or identifying security vulnerabilities. Invoke for PR reviews, code quality checks, refactoring suggestions.
-
infrasity-labs Skill Blog AuditFull-site blog health assessment scanning all blog files for quality scores, orphan pages, topic cannibalization, stale content, and AI citation readiness. Spawns parallel subagents for comprehensive analysis. Produces per-post scores and a prioritized action queue. Use when user says "audit blog", "blog audit", "site audit", "blog health", "audit all posts", "check all blogs".
-
zwright8 Bundle U0471 Education Security Threat ModelerBuild and operate the "Education Security Threat Modeler" capability for Education and Upskilling. Trigger when this exact capability is needed in mission execution.
-
zwright8 Bundle U0606 Security Counterfactual SimulatorBuild and operate the "Security Counterfactual Simulator" capability for Security and Privacy. Trigger when this exact capability is needed in mission execution.
-
zwright8 Bundle U0616 Security Failure Root Cause MinerBuild and operate the "Security Failure Root-Cause Miner" capability for Security and Privacy. Trigger when this exact capability is needed in mission execution.
-
zwright8 Bundle U0625 Security Uncertainty CommunicatorBuild and operate the "Security Uncertainty Communicator" capability for Security and Privacy. Trigger when this exact capability is needed in mission execution.
-
zwright8 Bundle U0871 Community Security Threat ModelerBuild and operate the "Community Security Threat Modeler" capability for Community Engagement and Feedback. Trigger when this exact capability is needed in mission execution.
-
zwright8 Bundle U0991 Evolution Security Threat ModelerBuild and operate the "Evolution Security Threat Modeler" capability for Autonomous Learning and Evolution. Trigger when this exact capability is needed in mission execution.
-
infrasity-labs Skill Blog Locale AuditAudit a directory of multilingual blog content for completeness, consistency, hreflang correctness, meta-tag parity, and freshness. Builds a translation coverage matrix, flags stale translations, validates hreflang and schema, and emits a prioritized report with runnable fix commands. Use when user says "locale audit", "blog locale-audit", "check translations", "multilingual audit", "translation check", "hreflang check", "Uebersetzungen pruefen".
-
zwright8 Bundle Openclaw 0151 Attack Surface ModelingTooling Security Threat Modeler. Use when work requires attack-surface modeling for Tool Reliability and Execution Quality with guardrails, traceable execution, and measurable outcomes.
-
zwright8 Bundle Contested Medevac Airbridge Prioritization CellPrioritize casualty movement under air and fires threat while balancing risk, timing, and treatment urgency. Use when planning, rehearsing, or updating operations that require synchronized actions across multiple components, staff sections, or coalition partners.
-
williamlimasilva Bundle Test Gap AuditRun a read-only audit for missing, weak, stale, or mis-scoped test coverage. If the user does not name a scope, audit the full repository and identify important code paths, routes, features, services, workflows, and contracts that lack proper tests. If the user names a feature, PR, branch, route, workflow, service, bug fix, API, security-sensitive path, or risky code change, focus only on that specific scope. Use when the user asks what tests are missing, whether coverage is enough, what regression tests to add, or how to prove a change is safe. This is not a general bug audit and not a security review; it evaluates whether behavior is covered by tests.
-
williamlimasilva Bundle Docs Sync AuditRun a read-only documentation drift audit for a feature, PR, branch, release, API, configuration change, workflow, CLI, package, or repository area. Use when the user asks whether docs are stale, missing, inconsistent with code, or need updates after code changes. Checks README files, setup guides, API docs, env docs, changelogs, examples, comments, generated docs, and user-facing instructions. This is not a general code review; it compares what the docs claim against what the code does.
-
williamlimasilva Bundle Secret ScanningGuide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation. This skill should be used when users need help enabling secret scanning, setting up push protection, defining custom secret patterns, triaging secret scanning alerts, or resolving blocked pushes.
-
zwright8 Bundle Joint Arctic Overland Convoy Survivability CellOptimize Arctic convoy survivability across mobility, weather, threat, and sustainment constraints. Use when planning cold-region overland movement under denied support conditions.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-vuln-scanner-hardened, nodejs-best-practices, vulnerability-scanner. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.