Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
pluginagentmarketplace Bundle Security PracticesMaster secure development, OWASP top 10, testing, and compliance. Use when building secure systems, conducting security reviews, or implementing best practices.
-
doiiarx Bundle Scientific Color MapsSelect, implement, and audit scientifically accurate, perceptually uniform, and color-vision-accessible color maps for data visualization. Use when creating or reviewing plots, heatmaps, maps, scalar fields, probability bars, progress indicators, scientific figures, dashboards, or visualization code; when choosing a palette or deciding whether hue changes carry real meaning; when replacing rainbow, jet, turbo, arbitrary low-medium-high colors, or red-green scales; or when checking grayscale readability, color blindness, color bars, normalization, and possible visual distortion. Also trigger on British spellings such as colour, colour map, and colour-vision deficiency.
-
ai-evos Bundle Quality NonconformanceCodified expertise for quality control, non-conformance investigation, root cause analysis, corrective action, and supplier quality management in regulated manufacturing. Informed by quality engineers with 15+ years experience across FDA, IATF 16949, and AS9100 environments. Includes NCR lifecycle management, CAPA systems, SPC interpretation, and audit methodology. Use when investigating non-conformances, performing root cause analysis, managing CAPAs, interpreting SPC data, or handling supplier quality issues.
-
elder-plinius Skill Bt6 Pr AuditAudit one pull request in a BT6 research or support repository at an exact head SHA, covering correctness, research integrity, security, tests, contracts, and merge readiness.
-
elder-plinius Skill Bt6 Queue AuditAudit the full pull-request and issue queue of a BT6 research or support repository, classifying readiness, evidence risk, and next action without mutating tracker state.
-
elder-plinius Skill Bt6 Issue StewardTriage and steward issues in BT6 research and support repositories, deciding whether to answer, reproduce, correct evidence, link work, design a feature, route security, implement, or close.
-
veyralabsgroup Bundle Agency AuditAudit any company website and generate a pitch-ready report for agencies. Extracts real problems, competitor comparison, quick wins, and a structured service proposal. No API keys required.
-
pluginagentmarketplace Bundle Security PatternsSecurity architecture, authentication, authorization, and compliance patterns
-
jawwadfirdousi Bundle Read Only Gh Pr ReviewReview backend pull requests for correctness, security, performance, maintainability, and test coverage using GitHub CLI plus local repository inspection. Use when asked to review service-layer/API/database changes, audit backend branch diffs, summarize backend risk, or produce actionable must-fix/should-fix feedback.
-
ling71671 Skill Gstack CsoSecurity audit workflow for OPC code, providers, plugins, Electron surfaces, local HTTP bridges, filesystem access, and command execution.
-
ling71671 Skill Gstack Document ReleaseUpdate or audit OPC documentation after code changes. Use when behavior, setup, CLI flags, desktop workflow, provider support, or plugin surfaces changed.
-
adamchanadam Skill Gov AuditRun post-bootstrap or post-migration governance audit.
-
blazemeter Bundle Blazemeter AdministrationComprehensive guide for BlazeMeter Administration, including workspaces, projects, security, alerts, and team management. Use when working with administration for (1) Managing workspaces and projects, (2) Configuring security settings (SAML SSO, 2FA, API keys), (3) Creating workspace alerts, (4) Managing private locations across workspaces, (5) Creating APM credentials, (6) Managing API Monitoring teams, (7) Configuring AI consent, or any other administration tasks.
-
blazemeter Bundle Blazemeter Network SecurityComprehensive guide for BlazeMeter Network & Security, including allowlisting, DNS configuration, and security best practices. Use when working with network and security for (1) Configuring allowlists for BlazeMeter engines and infrastructure, (2) Disabling DNS caching, (3) Implementing security best practices for API Monitoring, or any other network and security tasks.
-
n43-studio Skill Ralph RunCodex wrapper for the Ralph ralph-run command contract. Use when executing Ralph workflow after audit-project passes.
-
n43-studio Skill Ralph BuildCodex wrapper for the Ralph build command contract. Use when running the single-entry setup flow through audit.
-
n43-studio Skill Ralph Audit ProjectCodex wrapper for the Ralph audit-project command contract. Use when validating project artifacts before ralph-run.
-
adamchanadam Skill Openclaw Workspace Governance InstallerInstall OpenClaw WORKSPACE_GOVERNANCE in minutes. Get guided setup, upgrade checks, migration, and audit for long-running workspaces.
-
getsentry Skill Logging ObservabilityReview code for correct logging and error handling patterns. Use when reviewing code that handles errors, uses logging functions, or captures exceptions. Enforces the error hierarchy where 4xx errors are never logged to Sentry and 5xx errors always are. Trigger phrases include "review logging", "check error handling", "audit observability", or verify correct use of logIssue vs logError.
845 -
phylaxsystems Bundle Optimize Assertion TriggersOptimize Credible Layer/PCL Solidity assertion trigger selection for existing or newly edited assertions. Use when an assertion fires too often, relies on broad onFnCall/registerFnCallTrigger usage, needs lower execution overhead, or needs a trigger review that preserves the same security invariant while preferring narrower triggers such as onTxEnd/registerTxEndTrigger, ERC20-change triggers, storage-change triggers, or cumulative flow triggers where appropriate.
-
google Bundle A2ui AuditMain coordination skill to run the blueprint compliance, documentation synchronization, and test quality audits, posting the combined results as a labeled GitHub issue.
14.4k -
google Bundle A2ui Remediate ProblemRemediates a specific recommendation from an A2UI compliance report issue, or resolves any general GitHub issue, by inspecting context, implementing minimal targeted fixes, verifying tests, creating a branch, and opening a developer-signed Pull Request. Use when asked to fix or remediate an A2UI compliance audit finding, recommendation, or repository issue.
14.4k -
whatifwedigdeeper-agent-skills Bundle JS DepsFix JavaScript package security vulnerabilities or upgrade outdated npm/yarn/pnpm/bun dependencies. Use when the user wants to patch CVEs, resolve npm audit findings, bump package versions, modernize node_modules, or update specific packages across a JS project or monorepo. Handles any project with package.json files. Also triggers for "/js-deps" with or without specific package names or glob patterns. Not for non-JS ecosystems, adding brand-new packages, creating package.json from scratch, switching package managers, or debugging runtime errors.
-
whatifwedigdeeper-agent-skills Bundle Uv DepsMaintain Python packages through security audits or dependency updates using an isolated git worktree and uv. Use for security audits, CVE fixes, vulnerability checks, dependency updates, package upgrades, outdated packages, bump versions, fix Python vulnerabilities, check for Python CVEs, audit Python packages, update pyproject.toml dependencies, modernize Python deps, or when user types /uv-deps with or without specific package names or glob patterns.
-
jasonkuhrt Bundle Flo ReviewUse when asked to review, audit, or QA an epic's implementation. Triggers on "review the issue", "run QA", "audit quality", or /flo:review.
-
cyb3rward0g Bundle Hunt Research System And TradecraftResearch system internals and adversary tradecraft to ground a threat hunt in real system behavior and realistic abuse patterns. Use this skill at the start of hunt planning, when you are given a high-level hunt topic but lack a clear understanding of how the system normally operates or how adversaries are known to abuse it. This skill informs early hunt direction by producing candidate abuse patterns, key assumptions, and cited sources, and should be used before defining a concrete hunt hypothesis or selecting data sources.
-
wirexapp Bundle Wirex Baas AuthWirex BaaS authentication — how to authenticate API requests. Server-to-Server OAuth2 token exchange (POST /api/v1/token), user-scoped token issuance (POST /api/v1/user/authorize), Privy-based authentication. Covers required headers (Authorization, X-Chain-Id, X-User-Address/Email/Id), token caching strategy (48h validity, 5min refresh buffer), and security best practices.
-
abrignoni Skill Leapp New ArtifactWrite, rework, review or audit a LEAPP artifact module. Use when adding support for an app or data source in iLEAPP, ALEAPP, RLEAPP, VLEAPP or DLEAPP, when asked to "add an artifact" or "parse <app>", when a module needs new output types, media or a conversation view, and equally when fixing, validating or checking the forensic value of a module that already exists, including one already merged.
-
mergisi Skill Cost OptimizerTrigger when the user asks to audit Claude Code costs, reduce token spend, says "my Claude bill is too high", "optimize my CLAUDE.md", "why is this project burning tokens", or "/cost-optimizer". Scans a project for the common Claude Code cost leaks and returns a prioritized fix list.
-
johnnyvicious Skill Github ActionsCreate, configure, and optimize GitHub Actions including action types, triggers, runners, security practices, and marketplace integration
-
alirezarezvani Skill Claude Md Drift AuditAudit every CLAUDE.md in this project for drift against the last week of git history. Flags sections that reference deleted files, renamed paths, or removed dependencies. Read-only — returns a punch list, never edits.
20.4k -
berea-ch Skill Manage Openapi OverlaysUse when creating, applying, or validating overlay files including x-speakeasy extensions. Covers overlay syntax, JSONPath targeting, retries, pagination, naming, grouping, open enums, global headers, custom security. Triggers on "create overlay", "apply overlay", "overlay file", "x-speakeasy", "add extension", "configure retries", "add pagination", "overlay for retries".
-
llblab Skill Re ReviewEvidence-grounded review for code, diffs, PRs, documents, plans, specs, and architecture. Use for evidence review, review, code review, quick review, sanity check, quality check, architecture review, production readiness, security review, scaling review, document review, over-engineering review, simplification review, what can be deleted, bloat, evaluate, or check.
-
tile-ai Bundle Tilelang BackendIntegrate or review a TileLang target backend, target-backend variant, or shared execution backend. Covers language dialects, target and BackendContext contributions, PassPipeline, host/device codegen, execution compatibility, native CMake and packaging, tests, and documentation; covers Build/JIT/Runtime implementation only when a genuinely new execution mode is requested. Use when asked to add, port, scaffold, complete, or audit a TileLang backend or execution mode.
-
deevsdeevs Bundle Dev ExpertsApply opinionated developer personas for architecture decisions, production debugging, language-specific code review, comprehensive reviewer passes, and test strategy. Use when you need an architect plan, devops investigation, Rust/Python/C++ review, grumpy reviewer audit, or tester-driven test plan. Triggers: architect, devops, rust-dev, python-dev, cpp-dev, reviewer, tester, pre-merge review, refactor for maintainability.
-
machow Bundle Sop Session AuditUse this skill when writing a session audit file. Triggers: creating audit, writing to .claude/audits/, documenting session work, capturing design decisions, recording feedback from user.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include quality-nonconformance, gov_audit, openclaw-workspace-governance-installer. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.