Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
florianbruniaux-ccboard Bundle CybersecSecurity audit toolkit for the ccboard project (Rust/Leptos/Axum stack). Use when auditing authentication flows, API endpoints, WASM security, or reviewing Rust code for unsafe usage and memory safety issues.
-
saifoelloh Bundle Golang Clean ArchitectureClean Architecture audit for Go services. Use when reviewing layered architecture, dependency rules, or gRPC/usecase/repository patterns. Ensures proper separation of concerns and dependency inversion.
-
foscomputerservices Skill Fosutilities API Catalog UpdateUpdate the FOSUtilities API catalog after API changes. Runs the symbol-graph audit, fixes stale entries, writes curated entries for gaps, maintains the reach-for index, and bumps the plugin version. Use in the FOSUtilities repo when CI's catalog audit warns/fails, after adding or renaming public API, or when a reach-for index line is missing.
-
florianbruniaux-ccboard Skill PerformanceOptimize web performance for faster loading and better user experience. Use when asked to "speed up my site", "optimize performance", "reduce load time", "fix slow loading", "improve page speed", or "performance audit".
-
mondaycom Bundle Data CleanupCheck your CRM board's health and clean up messy data — run a scored health check (missing fields, stalled deals, abandoned columns, automation gaps) as a report, or fix data in bulk (phone formats, missing emails, country codes, unowned deals, stale dates). Use when someone says "clean my CRM", "fix my data", "normalize my phone numbers", "fill in missing owners", "run a board health check", "audit my CRM board", "what's broken in my CRM", "what are the data gaps on my board", "board is messy", or "clean up before my kickoff call".
-
zeyuzhangzyz Skill Oss DocsImprove the repository's open-source documentation and metadata. Use when the user says "improve docs", "make this repo easier to adopt", "fix the README", or wants README polish plus SECURITY.md, CHANGELOG.md, FAQ, architecture notes, and paper-release metadata.
-
zeyuzhangzyz Skill Oss PlanConvert an open-source hardening audit into an executable implementation plan. Use when the user says "turn this audit into a plan", "make a checklist", "write a GitHub issue", or wants a PR-ready checklist with acceptance criteria and commands for a software repo or paper-code release.
-
zeyuzhangzyz Skill Oss AuditAudit an existing repository or paper-code release for open-source hardening gaps across correctness, maintainability, testability, security, performance, observability, and documentation. Use when the user says "audit this repo", "harden this project", "open source readiness", or wants a prioritized file-level report before changing code.
-
poshan0126 Skill Claude MdKeep CLAUDE.md current and lean — capture this session's durable learnings into it (default), or `audit` it for stale commands, drift, and bloat. Enforces the line budget either way.
-
poshan0126 Skill Pr ReviewReview code changes or a pull request. Delegates to specialist agents (code quality, security, performance, silent failures, test quality, docs) in parallel.
-
cyberelf Bundle DeepresearchConduct structured deep research on any topic — security threat analysis, technology trend mapping, ecosystem analysis, market forecasts, or law/policy compliance research. Produces a multi-part report grounded in confirmed sources with no premature design assumptions. Use when asked to "deepresearch", "research deeply", or produce a comprehensive multi-part research report. Auto-detects whether the topic calls for security-focused, tech-trend-focused, or law/policy-focused structure.
-
ddunnock Bundle Skill TesterThis skill should be used whenever the user wants to test a skill's behavior, analyze how it uses the Claude API, inspect inputs/outputs from scripts, or run security and code review audits against skill scripts. Even for casual phrases like "test my skill", "analyze this skill", "audit skill scripts", "review skill for security issues", "what does this skill actually do when it runs", "inspect API calls from skill", "run a skill through its paces", "check my skill for bugs or vulnerabilities". Also trigger when the user shows you a SKILL.md and asks you to evaluate, critique, or stress-test it.
-
chfle Bundle Linux Vuln ScannerUse when user wants to scan a Linux server, container, or web app for vulnerabilities — checking installed packages against CVE databases, scanning open ports and services, auditing SSL/TLS configuration, running web application security scans, or performing an authorized security assessment of their own infrastructure.
-
wondermove-inc Bundle Security보안 검사. OWASP Top 10, 시크릿 탐지, 의존성 취약점을 검사합니다.
-
chfle Bundle Linux Config AuditorUse when user wants to audit, review, analyze, or improve a Linux config file — nginx, Apache, sshd_config, systemd service/timer/socket units, iptables, nftables, firewalld, fail2ban, sudoers, /etc/security/limits.conf, sysctl.conf, or any server config — for security issues, misconfigurations, performance problems, or compliance gaps.
-
chfle Bundle Linux Security HardenerUse when user wants to harden a Linux server, secure a fresh VPS, follow CIS benchmarks, reduce attack surface, lock down SSH, configure a firewall, set up fail2ban, disable unused services, configure auditd, or asks how to make a Linux system more secure.
-
christopheryeo Bundle Daily WorkCross-environment workday lifecycle for Claude and ChatGPT Work with three sub-commands: START (morning enablement — email triage, calendar audit, Drive activity, news snapshot, workspace prep, executive brief; replaces set-up-workday), RECAP (end-of-day cross-reference of Calendar, Gmail, Drive, and all AI workforce Plans task logs into a comprehensive activity report in the work-day folder), and MINUTES (given a meeting title, find it in Calendar, search the work-day Drive folder for minutes, fall back to Gmail for transcript, then return a direct link). Use for "set up my workday", "start my day", "kick off today", "morning brief", "daily recap", "end of day", "wrap up the day", "what did I do today", "what happened today", "find the minutes", "meeting minutes for [title]", "where are the minutes", "get me the notes from [meeting]", "meeting transcript", or any workday activity review.
-
peabody124 Skill Audit RepoAudit the current repository against RAE standards. Use when the user says "audit repo", "check repo standards", "sync with RAE", "check for drift", "compare against template", or when you want to verify a repo follows RAE conventions. Compares pyproject.toml, CLAUDE.md, ruff config, pytest/coverage config, and dev dependencies against the canonical RAE template.
-
mckinsey Skill Ark Vulnerability FixerCVE research and security patch workflow for Ark. Provides CVE API integration, mitigation strategies, and security-focused PR templates. Works with research, analysis, and setup skills for comprehensive vulnerability fixing.
-
porteden Skill Docs LoggerGoogle Docs Log Automation. Use when the user wants to append log lines, audit trail entries, or event records to auto-created daily Google Docs in Drive (PortEden Secure Access).
-
porteden Skill LoggerGoogle Sheets Log Automation. Use when the user wants to append log entries, record audit trails, or automate event logging to a pre-configured Google Sheet (PortEden Secure access).
-
mckinsey Skill Ark Pentest Issue ResolverResolve common penetration testing issues in Ark. Use when fixing security vulnerabilities from pentest reports, security audits, or OWASP Top 10 issues.
-
cellinlab Bundle Celf Style WriterPersonal Chinese writing-style skill for Cell 细胞 style articles, rewrites, style enhancement, and style review. Use when Codex needs to write, rewrite, enhance, or audit Chinese content so it sounds like Cell speaking directly to the reader: friend-to-friend, warm but sharp, concrete, hook-driven, anti-academic, anti-AI-template, and grounded in real experience instead of abstract sermonizing.
-
get-convex Skill Convex ReviewerReview Convex code for security, auth, validators, performance, and best practices. TRIGGER when the user asks to review/audit Convex code, or after writing convex/ functions you want checked. Applies the Convex-specific review checklist (auth checks, args/returns validators, internal vs public, indexes-not-filter, OCC conflicts, pagination).
-
agentfront Bundle Frontmcp ConfigUse when configuring a FrontMCP server through frontmcp.config or the @FrontMcp options. Covers auth modes (public, transparent, local, remote), OAuth plus credential vault and secureStore, CORS, HTTP port / entry-path prefix / unix socket, security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options), rate limiting / throttling / concurrency / timeout / IP filtering (GuardConfig), session storage (Redis, Vercel KV), client transport protocols (SSE, Streamable HTTP, stateless, protocol presets), elicitation, multi-target build config, and skillsConfig (HTTP catalog, caching, audit log, instruction injection). Triggers: configure auth, set up CORS, add rate limiting, throttle requests, manage sessions, choose transport, set HTTP options, configure JWT or OAuth. The skill for server CONFIGURATION.
-
laiye-ai-repos Bundle Agentic Doc Parse And ExtractEnables AI-powered parsing and key information extraction from high-frequency documents including invoices, orders, receipts, long texts, and common Chinese identity & credential documents. Supports reusable custom templates for non-standard business files. Features batch concurrent processing and human-in-the-loop review with customizable audit rules to automate document workflows for finance, administration, HR data entry and other departments.
-
agentfront Bundle Frontmcp ExtensibilityUse when extending FrontMCP beyond the core SDK by integrating external npm packages, libraries, or third-party services into providers and tools. Covers VectoriaDB for in-memory semantic and vector search (ML-based embeddings or TF-IDF keyword engines, with persistence) and the tamper-evident, hash-chained skill audit log (pluggable signer and store, with chain verification). Triggers: add semantic search, vector search, embeddings, similarity search, recommendations, ML features, audit logging, or integrate an external library, database, or API beyond the built-in SDK.
-
clickhouse-clickhouse Skill Close Flaky IssuesAudit open "flaky test" GitHub issues and close those whose tests are no longer failing on master. Cross-references CI history from play.clickhouse.com with git log to attribute fixes.
-
co-labs-co Skill Multipeerconnectivity P2p StreamingPeer-to-peer video streaming using Apple's MultipeerConnectivity framework. Use this skill when building local mesh networking apps, video streaming between devices (baby monitors, security cameras), local multiplayer games without servers, or AirDrop-like file sharing with custom protocols.
-
kimasplund Skill Security AnalysisSecurity assessment using STRIDE threat modeling, OWASP Top 10, and CVSS scoring. Use for security reviews, threat modeling, and secure coding guidance.
-
glincker-claude-code-marketplace Bundle Security ScannerComprehensive security scanner for vulnerabilities, hardcoded secrets, and OWASP Top 10 issues
-
altimateai-altimate-code Skill Pii AuditClassify schema columns for PII (SSN, email, phone, name, address, credit card) and check whether queries expose them. Use for GDPR/CCPA/HIPAA compliance audits.
-
diegocconsolini Bundle Plugin Security CheckerUse this skill to scan a Claude Code plugin (or any npm/PyPI package tree) for security issues before installation. Detects dangerous functions, code obfuscation, hardcoded credentials, schema problems, and known 2024-2026 supply-chain attack IOCs (Shai-Hulud, Nx s1ngularity, chalk/debug clipper, Axios RAT, litellm/.pth), mapped to MITRE ATT&CK/ATLAS, CVE, and OWASP.
-
sherifeldeeb Bundle ResearchGather and synthesize information from web sources, APIs, and databases. Compile research findings into structured reports. Use when researching topics, gathering threat intelligence, or compiling background information.
-
sherifeldeeb Bundle Incident ResponseIncident response documentation, timeline analysis, containment procedures, and IR reporting. Support the full incident lifecycle from detection to lessons learned. Use for security incidents, breach response, and IR planning.
-
luw2007 Bundle Herdr Pi OrchestraOrchestrate recursive pi-worker Orchestra Trees in Herdr using sibling DAGs, SKILL.state context, bounded delegation, fresh audit, CAS promotion, and safe cleanup. Use only for explicit Herdr orchestration or parallel pi work. Requires HERDR_ENV=1.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include frontmcp-config, frontmcp-extensibility, plugin-security-checker. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.