Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
jacob-balslev Bundle Comprehension Present Missing UnderstandingNegative fixture for the gate-conformance suite: the audit-state sidecar declares `comprehension_state: present` but the SKILL.md omits the five flat Understanding fields. Activate only inside test-gate-conformance.js to prove the cross-file lint gate (comprehension_state -> Understanding fields) FAILS. Do NOT use as a production skill.
-
frankxai-agentic-creator-os Skill Visual Intelligence System VisAgentic visual asset management — scan, audit, and manage images across your site with AI-powered quality enforcement
-
cgallic Bundle Kai TasteAudit or design generative AI interfaces against three diagnostic pillars (deterministic-stochastic balance, interaction density, visual cohesion). Treats taste as a measurable control system, not subjective preference. Use when: 'taste audit', 'score this UI', 'design quality', 'interaction density', 'visual cohesion', 'refiner layer', 'correction cost', 'why does this feel off', 'polish this', 'design review', or building any user-facing AI product.
-
coderabbitai Skill Code ReviewReviews code changes using CodeRabbit AI. Use when user asks for code review, PR feedback, code quality checks, security issues, or requests fix-review cycles.
-
cgallic Skill Kai Funnel AuditTwo-layer funnel audit on collected data only — stress-test the awareness layer (hooks, messaging, proof placement, attention leaks on live pages and ads) and the lead-capture layer (opt-ins and lead magnets scored on the four Value Equation variables, friction findings, weakest-magnet rewrite), plus a phone-path check under the KaiCalls Fit Rule. Use when "funnel audit", "audit my funnel", "why is my funnel leaking", "top of funnel isn't converting", "audit our lead magnets", "opt-in audit", "awareness to lead audit", "where are we losing people", "lead capture audit", or any request to diagnose the full awareness-to-lead flow rather than one page.
-
coderabbitai Bundle Swiftui Performance AuditAudit and improve SwiftUI runtime performance from code review and architecture. Use for requests to diagnose slow rendering, janky scrolling, high CPU/memory usage, excessive view updates, or layout thrash in SwiftUI apps, and to provide guidance for user-run Instruments profiling when code review alone is insufficient.
-
jamie-bitflight Skill AuditUse when the primary outcome is comparing documentation claims with implementation evidence, synchronizing docs from verified changes, or freshness review, including drift, missing coverage, stale claims, and post-change updates.
-
jamie-bitflight Skill ReviewReviews Python code across type safety, error handling, security, performance, modern patterns, design clarity, typed-boundary compliance, test quality, and documentation. Use when performing code review, PR review, pre-merge quality checks, or assessing Python for security vulnerabilities, bare except clauses, Any usage outside boundaries, or missing input validation at system boundaries.
-
human-avatar Skill S4h Resource Waste AuditFinds where resources are being lost, duplicated, or underused — the seven wastes applied to knowledge work. Triggers: 'waste audit', 'where are we wasting resources', 'inefficiency audit', 'find the waste', 'what's being duplicated', 'resource leakage'.
-
human-avatar Skill S4h Emotional Trust AuditMaps what is building and eroding trust in a relationship or situation — trust degrades silently until it fails loudly. TRIGGERS: 'trust audit', 'why don't they trust us', 'relationship health check', 'what's eroding trust', 'build trust with'.
-
human-avatar Skill S4h Strategy IntelligenceAudits what you actually know vs. what you're assuming about yourself and your opponent before acting. Triggers: 'what do I actually know', 'intelligence audit', 'know your enemy', 'what am I assuming vs knowing', 'prep for negotiation', 'what information do I have', 'what don't I know about them', 'am I missing something important'.
-
human-avatar Skill S4h Writing WorldbuildingAudits a fictional world for internal consistency, texture, economy, and constraint-story alignment. Use when a world feels thin, generic, like a backdrop rather than a place people actually inhabit. Triggers: 'the world feels thin', 'worldbuilding', 'my world doesn't feel real', 'the setting is generic', 'world audit', 'the world feels like a backdrop'.
-
human-avatar Skill S4h Linguistics PragmaticsAnalyzes what is implied rather than said — the gap between literal content and communicative meaning. Use when you say 'what does this really mean', 'what is this message actually doing', 'is this a threat', 'what is being implied here', 'what does this leave unsaid', 'why does this feel off even though it seems polite', or when a communication seems fine on the surface but something is wrong underneath.
-
jamie-bitflight Bundle Perl ValidateThis skill should be used when the user asks to "validate Perl script", "check Perl syntax", "verify Perl code", "/perl-validate", or mentions script validation, compile check, security review, or best practice compliance for Perl code.
-
human-avatar Skill S4h Writing Voice ConsistencyExtracts a voice fingerprint from strong existing passages and uses it to audit and repair voice departures. Use when multiple contributors have created a fractured document, when brand voice has drifted, or when the writing doesn't sound like one person. Triggers: 'the voice isn't consistent', 'voice consistency', 'this doesn't sound like us', 'multi-author document', 'maintain voice', 'brand voice', 'the writing sounds like different people'.
-
harshahosur81 Skill Deps AuditYou are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, ou
-
harshahosur81 Skill Security SastStatic Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks
-
harshahosur81 Skill Linkerd PatternsImplement Linkerd service mesh patterns for lightweight, security-focused service mesh deployments. Use when setting up Linkerd, configuring traffic policies, or implementing zero-trust networking with minimal overhead.
-
harshahosur81 Skill Code ReviewerElite code review expert specializing in modern AI-powered code analysis, security vulnerabilities, performance optimization, and production reliability. Masters static analysis tools, security scanning, and configuration review with 2024/2025 best practices. Use PROACTIVELY for code quality assurance.
-
harshahosur81 Skill Pci ComplianceImplement PCI DSS compliance requirements for secure handling of payment card data and payment systems. Use when securing payment processing, achieving PCI compliance, or implementing payment card security measures.
-
human-avatar Skill S4h Communication Clarity AuditAudits a communication for places where the message will be lost, misread, or misunderstood — before it's sent. Triggers: 'clarity audit', 'will this be understood', 'check my message', 'edit for clarity', 'where will this be misread'.
-
harshahosur81 Skill GRAPHQL ArchitectMaster modern GraphQL with federation, performance optimization, and enterprise security. Build scalable schemas, implement advanced caching, and design real-time systems. Use PROACTIVELY for GraphQL architecture or performance optimization.
-
human-avatar Skill S4h Writing Inconsistency AuditRuns four systematic passes to identify timeline errors, character logic violations, world-rule breaks, and physical continuity errors. Use when a manuscript has contradictions, continuity problems, or logic violations. Triggers: 'there are contradictions', 'continuity errors', 'inconsistency check', 'the character shouldn't know that', 'timeline doesn't add up', 'continuity audit', 'inconsistencies in the manuscript'.
-
human-avatar Skill S4h Investigation Evidence AuditEvaluates the quality, strength, and completeness of evidence for a claim. Covers evidence type hierarchy, sample quality, methodological soundness, conflicts of interest, and what's notably absent. Use when you want to know how good the evidence is — 'is this evidence strong', 'evaluate the research', 'how solid is this', 'is this just one study', 'what kind of evidence supports this', 'what's missing from the evidence'.
-
human-avatar Skill S4h Epistemology Epistemic StatusProduces an honest, rigorous calibration of what you know vs. believe vs. assume vs. hope across a domain. Assigns explicit epistemic statuses to claims and flags when high-confidence claims rest on lower-confidence foundations. Draws from the rationalist tradition of explicit epistemic labeling. Use when you say 'how certain should I be', 'what do we actually know here', 'I want an honest read of our assumptions', 'separate what we know from what we're guessing', 'give me an epistemic audit', 'I want to stop conflating confident with correct', or when producing analysis where the confidence level matters as much as the content.
-
jamie-bitflight Bundle The Rewrite RoomUse when the user explicitly asks Rewrite Room to route documentation work, or when audit/sync/freshness, user-facing authoring, citation-driven writing, docs-to-skill conversion, and AI-instruction optimization overlap and exactly one workflow must be chosen.
-
jamie-bitflight Skill Python3 ReviewComprehensive Python code review checking patterns, types, security, and performance. Use when reviewing Python code for quality issues, when auditing code before merge, or when assessing technical debt in a Python codebase.
-
harshahosur81 Skill Compliance CheckYou are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards. Perform comprehensive compliance audits and
-
jamie-bitflight Skill Hooks Core ReferenceHook system fundamentals — all events, configuration structure, matchers per event type, environment variables, execution behavior, security, and debugging. Use when creating hooks, understanding hook events, matchers, configuration locations, environment variables, or troubleshooting hook issues.
-
jamie-bitflight Bundle Audit Skill LifecycleAudit skill lifecycle by tracing call chains, detecting circular dependencies, finding instruction contradictions, identifying duplicated datasets, analyzing bidirectional coherence, discovering scriptable sequences, and learning patterns. Use when checking skill coherence, validating skill workflow, finding semantic gaps in plugin structure, or auditing plugin before marketplace submission. Generates audit reports to .plugin-creator/audits/ with findings by dimension.
-
jamie-bitflight Skill Code Review NodejsApplies Node.js-specific code review patterns for async I/O, streams, security, process management, and dependency hygiene. Use when reviewing Node.js server code, route handlers, middleware, or any JavaScript file alongside package.json without TypeScript. Triggers on sync I/O in request paths, missing stream backpressure, process.exit misuse, eval/exec injection risks, wildcard version ranges, missing lockfiles, EventEmitter cleanup gaps, and unvalidated environment variables at startup.
-
harshahosur81 Skill Malware AnalystExpert malware analyst specializing in defensive malware research, threat intelligence, and incident response. Masters sandbox analysis, behavioral analysis, and malware family identification. Handles static/dynamic analysis, unpacking, and IOC extraction. Use PROACTIVELY for malware triage, threat hunting, incident response, or security research.
-
harshahosur81 Skill Gdpr Data HandlingImplement GDPR-compliant data handling with consent management, data subject rights, and privacy by design. Use when building systems that process EU personal data, implementing privacy controls, or conducting GDPR compliance reviews.
-
harshahosur81 Skill Mtls ConfigurationConfigure mutual TLS (mTLS) for zero-trust service-to-service communication. Use when implementing zero-trust networking, certificate management, or securing internal service communication.
-
harshahosur81 Skill Sast ConfigurationConfigure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when setting up security scanning, implementing DevSecOps practices, or automating code vulnerability detection.
-
harshahosur81 Skill Security HardeningUse when working with security scanning security hardening
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include comprehension-present-missing-understanding, Visual Intelligence System (VIS), kai-taste. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.