Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
zwright8 Bundle Coalition Border Refugee Biometric Deconfliction And ScreeniCoordinate coalition border screening for refugee surges while preserving humanitarian law compliance, biometric deconfliction quality, and mission security. Use when commands need options that balance throughput, protection, and legal constraints with protocol-aware outputs.
-
zwright8 Bundle Openclaw 5461 Security Threat ModelingSecurity Threat Modeling for design and user research. Use when work requires security threat modeling for design and user research with guardrails, traceable execution, and measurable outcomes.
-
zwright8 Bundle Openclaw 5466 Security Threat ModelingSecurity Threat Modeling for sales and client success. Use when work requires security threat modeling for sales and client success with guardrails, traceable execution, and measurable outcomes.
-
zwright8 Bundle Autonomous Littoral Port Reopening Under Mining And Drone ThGuide joint maritime teams on rapid port reopening under sea-mine contamination, drone attack pressure, and constrained convoy protection resources.
-
qazbnm456 Skill Awesome Web SecurityLooks up curated web security learning resources (XSS, SQLi, CSRF, SSRF, OAuth/JWT, deserialization, SAML, recon, evasion, defensive tooling, CTF). Filters by topic, difficulty, language, and resource type. Returns top references with archive fallbacks. Defensive and educational use only.
-
ericdumingtong Bundle Code ReviewReview code for bugs, security vulnerabilities, performance issues, and best practices. Use this skill whenever the user asks for a code review, shares code and wants feedback, mentions "review this", "check my code", "what's wrong with this code", pastes a diff or PR, or asks about code quality. Also trigger when users share code snippets and ask general questions that would benefit from a thorough review, even if they don't explicitly say "review".
-
zwright8 Bundle Joint Security Clearance Foreign Contact And Record CorrectiPreserve security-clearance eligibility, foreign-contact reporting, and personnel-security record correction continuity so warfighters are not sidelined by administrative drift or unadjudicated data. Use when clearance friction begins to threaten readiness, assignment, or mobilization timing.
-
abczsl520-codex-review Bundle Codex ReviewThree-tier code quality defense: L1 quick scan, L2 deep audit (via bug-audit), L3 cross-validation with adversarial testing. 三级代码质量防线。
-
bjulius Bundle Skill EvaluatorComprehensive evaluation toolkit for analyzing Claude skills across security, quality, utility, and compliance dimensions. This skill should be used when users need to evaluate a skill before installation, review before publishing, or assess overall quality and safety. Performs 5-layer security analysis, validates structure and documentation, checks compliance with skill-creator guidelines, and generates markdown reports with scoring and recommendations.
-
anecdotes-yair Bundle Trustmyagent🛡️ TrustMyAgent - Security posture monitoring for AI agents. Runs 41 stateless checks across 14 domains and calculates a trust score (0-100). Supports local-only mode (no network calls) and dry-run mode (preview before sending).
-
dominik1001 Skill Review Agents MdReviews an AGENTS.md or CLAUDE.md file against best practices and reports concrete fixes. Use when the user asks to review, audit, lint, or improve an AGENTS.md / CLAUDE.md / context file, or says "review my agents file".
Audited -
c0ffee-milk Bundle Skill Fidelity BenchBenchmark whether a modified or poisoned skill still preserves the clean skill's capabilities, reasoning, boundaries, and distinctiveness. Use this whenever the user wants a clean-vs-poisoned skill benchmark, a capability-fidelity audit, a taskset + rubric workflow, or a reproducible comparison report.
-
zwright8 Bundle Joint Security Clearance Financial Distress Tax Lien And CreProtect security-clearance eligibility when debt, collections, tax liens, identity theft, or pay anomalies begin to threaten adjudication, assignment, or mobilization timing for American warfighters. Use when financial distress is crossing from household strain into personnel-security risk.
-
pleasechooseusername Bundle AegisAutomated Emergency Geopolitical Intelligence System — real-time threat monitoring and safety alerts for civilians in conflict zones. Use when: (1) setting up warzone/crisis safety monitoring for a location, (2) user asks about security situation or threat level, (3) configuring emergency alert delivery, (4) generating security briefings, (5) emergency preparedness planning.
-
deepbitstechnology Skill Binary AnalysisAnalyze binary files (exe, dll, sys, bin, ocx, scr, cpl, drv, elf, so, macho, apk) to assess if they are malicious, perform decompilation, extract strings/imports/exports, detect malware, and provide threat assessment. Use this skill when user asks to analyze, examine, check, or assess any binary file, asks if a file is malicious/suspicious/safe, or provides a file path to a binary. Trigger for phrases like "Is [file] malicious?", "Analyze [file]", "What does [binary] do?", or any request involving binary file analysis.
-
0-vault Bundle Vault0Encrypted secret vault and security layer for OpenClaw agents
-
zeyuzhangzyz Skill Oss SearchSearch GitHub and the web for reference repositories, code patterns, CI examples, and open-source best practices. No API keys required. Use when the user says "find similar repos", "search GitHub", "look up best practices", or when oss-audit / oss-refactor needs external reference material.
-
zeyuzhangzyz Skill Oss HardeningOrchestrate an end-to-end open-source hardening pass for a repository. Use when the user wants to turn a loose codebase or paper-code release into a readable, testable, maintainable open-source project and wants audit, plan, refactor, tests, CI, and docs to run as one continuous workflow unless a blocker appears.
-
ddobrin Skill Plan AuditorExpertise in validating that the codebase matches a specific plan. Use when the user asks to "validate the plan", "check implementation", or "audit the code".
-
giskard-ai Skill Fix CveUse when pip-audit (or a CVE/GHSA advisory, Dependabot, or security scan) flags a vulnerable Python dependency in giskard-oss and it needs upgrading to a fixed version in the uv lockfile.
-
ddobrin Skill Plan ValidatorExpertise in validating that the codebase matches a specific plan. Use when the user asks to "validate the plan", "check implementation", or "audit the code".
-
n24q02m-mnemo-mcp Skill Knowledge AuditReview and clean up stored memories — find duplicates, contradictions, stale entries, and consolidate
-
nasa-pds Skill Sonarcloud Security TriagingAnalyze SonarCloud security issues and suggest triage decisions (SAFE/FIXED/wontfix/falsepositive) with explanations. Use when the user needs help reviewing security issues, making triage decisions, or understanding whether security hotspots/vulnerabilities are true positives.
-
elnora-ai Skill Elnora AdminThis skill should be used when the user asks to "log in", "logout", "check auth", "create API key", "revoke API key", "list API keys", "check health", "submit feedback", "view audit log", "shell completions", "get account", "update account", "account details", "view agreements", "accept terms", "validate token", "elnora setup", "api key policy", "delete account", "list users", "feature flags", "legal documents", "set feature flag", "manage legal docs", "list profiles", "show profiles", "whoami", "run diagnostics", "open platform", or any task involving Elnora Platform authentication, administration, or diagnostics.
-
ricardogomes Bundle Reason About Code SecurityDevelop systematic threat reasoning and adversarial thinking about code security. Use when a learner wants to analyze code for security implications, understand vulnerability patterns, or develop security-minded thinking. This skill teaches systematic threat modeling, assumption surfacing, and defense reasoning—not vulnerability cataloging. Triggers on phrases like "is this secure", "security implications", "could this be exploited", "threat analysis", or when a learner wants to develop security reasoning skills.
-
rayjun Skill Ethereum Security Auditor智能合约安全分析。涵盖已知漏洞扫描、访问控制审查、经济风险评估及中心化分析。适用于代码发布前的审计或链上漏洞复盘。
-
brorlandi Skill Pr ReviewReview a GitHub Pull Request and submit a single review with inline code comments. Identifies bugs, security vulnerabilities, performance issues, logic errors, missing edge cases, and suggests improvements. Use when the user wants to review a PR, do a code review, or add review comments to a pull request.
-
barateza Bundle Best PracticesApply modern web development best practices for security, compatibility, and code quality. Use when asked to "apply best practices", "security audit", "modernize code", "code quality review", or "check for vulnerabilities".
-
apappascs Skill Session Memory AuditHealth-checks Claude Code memories for staleness, broken links, orphaned files, expired dates, missing frontmatter, and duplicates. Offers two-tier fixes: deterministic auto-fixes and AI-assisted corrections. Use when the user asks to clean up memories, check memory health, find stale memories, or audit their stored knowledge. Also triggered by: "memory health", "stale memories", "clean up memories", "memory audit".
-
thedecipherist Skill Security AuditAudit code and dependencies for security vulnerabilities. Use when reviewing PRs, checking dependencies, preparing for deployment, or when user mentions security, vulnerabilities, or audit.
-
antoinebou12 Skill Modern PythonModern Python tooling and best practices using uv, ruff, ty, and pytest. Covers project setup with pyproject.toml (PEP 735), src layout, linting/formatting with ruff, type checking with ty, testing with pytest and coverage, pre-commit with prek, and security (pip-audit, detect-secrets, actionlint). Use when setting up or working on Python projects, replacing pip/virtualenv with uv, replacing flake8/black/mypy with ruff/ty, adding pre-commit or security scanning, or when the user mentions uv, ruff, ty, pytest, or cookiecutter-python patterns.
-
ether-moon Bundle Autofixing And EscalatingClassifies actionable findings from linters, tests, security scans, audits, and PR reviews, automatically applies unambiguous fixes, and pauses only for decisions required by ambiguous findings before applying the complete chosen resolution. Use when processing one or more externally produced findings with the intent to resolve them.
-
uceap Skill Upgrade Drupal ModuleUpgrade Drupal contributed modules. Auto-upgrades minor/patch releases. Prompts for major versions. Handles dependencies, patches, custom code updates, and security advisories.
-
ali5ter Skill Audit StandardsAudits the current project against the development standards defined in ~/.claude/CLAUDE.md. Documents non-compliant findings as GitHub issues and writes a prioritised fix plan to the project CLAUDE.md. Use when the user says audit against settings, audit standards, check standards compliance, or audit this project.
-
mbuyco Skill Code ReviewerReviews code for security vulnerabilities, performance issues, and best practices. Use when reviewing code, performing security audits, checking for code quality, reviewing pull requests.
-
mbuyco Skill Security ReviewProvides structured security analysis and threat modeling for given systems or outputs, integrating common threat categories and secure defaults. Use when evaluating or generating designs/code that require security confidence.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include codex-review, vault0, security-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.