Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
harshahosur81 Skill Solidity SecurityMaster smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.
-
harshahosur81 Skill Firmware AnalystExpert firmware analyst specializing in embedded systems, IoT security, and hardware reverse engineering. Masters firmware extraction, analysis, and vulnerability research for routers, IoT devices, automotive systems, and industrial controllers. Use PROACTIVELY for firmware security audits, IoT penetration testing, or embedded systems research.
-
harshahosur81 Skill Reverse EngineerExpert reverse engineer specializing in binary analysis, disassembly, decompilation, and software analysis. Masters IDA Pro, Ghidra, radare2, x64dbg, and modern RE toolchains. Handles executable analysis, library inspection, protocol extraction, and vulnerability research. Use PROACTIVELY for binary analysis, CTF challenges, security research, or understanding undocumented software.
-
enuno Skill Deep ResearchResearch a topic thoroughly in this repo and return a structured summary with file references. Use when you need to understand how something works, find patterns across modules, or audit implementations.
1 -
jamie-bitflight Bundle Audit Skill CompletenessEvaluate a single skill's quality against its stated purpose. Classifies the skill's purpose type, then scores applicable quality categories — universal dimensions always apply; structural dimensions (scripts, references, assets) are scored only when warranted by the skill's purpose. A focused 20-line behavioral skill with no bundled resources scores fully on all applicable categories. Use when auditing skill quality, checking marketplace readiness, evaluating skill completeness, performing pre-publication evaluation.
-
jamie-bitflight Bundle Designing UI For CLIUse before any CLI/TUI display code is written, modified, or audited — runs the 7-stage discipline (Context, Register, Shape brief, Implement, Critique, Audit, Polish) for Typer, Rich, Textual, and Questionary work, grounded in per-project PRODUCT.md and DESIGN.TUI.md/DESIGN.md. Triggers on output formatting, display design, interactive prompts, visual consistency, TUI layout, progress display, dashboard design, design audit, design polish, design critique, shape brief, register decision (brand-cli vs product-cli), and AI-slop checks.
-
harshahosur81 Skill Mobile Security CoderExpert in secure mobile coding practices specializing in input validation, WebView security, and mobile-specific security patterns. Use PROACTIVELY for mobile security implementations or mobile security code reviews.
-
harshahosur81 Skill Security DependenciesYou are a security expert specializing in dependency vulnerability analysis, SBOM generation, and supply chain security. Scan project dependencies across multiple ecosystems to identify vulnerabilitie
-
harshahosur81 Skill Backend Security CoderExpert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.
-
harshahosur81 Skill Threat Modeling ExpertExpert in threat modeling methodologies, security architecture review, and risk assessment. Masters STRIDE, PASTA, attack trees, and security requirement extraction. Use PROACTIVELY for security archi
-
criptogus Skill Benjamin GrahamBenjamin Graham - O pai do Value Investing e Security Analysis
-
criptogus Skill Security SecretsProteção de secrets - Nunca exponha credenciais em logs, terminal ou git
-
harshahosur81 Skill Attack Tree ConstructionBuild comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders.
-
harshahosur81 Skill Stride Analysis PatternsApply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.
-
harshahosur81 Skill App Code ArchitectureExpert code reviewer for app development. Audits code quality, performance, scalability, security, and architectural patterns with measurable standards.
-
jamie-bitflight Bundle Complete ImplementationUse when all tasks for a feature are marked COMPLETE — runs holistic quality gates including code review, feature verification, integration check, documentation drift audit and update, and context refinement. Creates follow-up plans when issues are found.
-
harshahosur81 Skill Anti Reversing TechniquesUnderstand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Use when analyzing protected binaries, bypassing anti-debugging for authorized analysis, or understanding software protection mechanisms.
-
harshahosur81 Skill Threat Mitigation MappingMap identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control effectiveness.
-
harshahosur81 Skill Auth Implementation PatternsMaster authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues.
-
harshahosur81 Skill Security Requirement ExtractionDerive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases.
-
henryhawke Bundle Code ReviewUse when reviewing code changes, PRs, or doing quality analysis. Covers security vulnerability detection, performance analysis, architectural review, Flutter/Dart patterns, Edge Function patterns, and actionable feedback with confidence-based filtering.
-
henryhawke Skill Supabase RlsUse for designing and implementing Supabase Row Level Security (RLS) policies. Covers policy patterns for CRUD operations, auth integration, role-based access, multi-tenant isolation, performance optimization, and security auditing with get_advisors.
-
tyler-r-kendrick Bundle AuthenticationUse when designing or implementing authentication and authorization systems. Covers OAuth 2.0, OpenID Connect, RBAC, ABAC, Zero Trust architecture, session management, and multi-factor authentication across all platforms. USE FOR: OAuth 2.0, OpenID Connect, OIDC, RBAC, ABAC, Zero Trust, session management, MFA, JWT, token management, SSO, identity federation DO NOT USE FOR: cryptographic primitives (use cryptography), API rate limiting and headers (use api-security), specific identity provider setup (use platform-specific skills)
-
henryhawke Skill Review SecurityReview code changes with Security Review subagent.
-
tyler-r-kendrick Bundle Static AnalysisUse when setting up or improving static analysis tooling — type checking, linting, security scanning (SAST), and code formatting. Covers cross-platform tools including TypeScript, mypy, ESLint, Biome, Ruff, Semgrep, CodeQL, Roslyn analyzers, Prettier, Black, and dotnet format with configuration examples and CI integration patterns. USE FOR: linting, type checking, SAST, code formatting, Semgrep rules, ESLint configuration, Roslyn analyzers DO NOT USE FOR: runtime testing (use unit-testing or integration-testing), E2E tests (use e2e-testing), performance profiling (use performance-testing)
-
henryhawke Skill Architecture OptimizerReview and optimize codebases for scalability, cost efficiency, and architectural coherence. Use when you need to identify disconnected code patterns, ensure UI components integrate seamlessly, verify end-to-end implementations, reduce backend costs, or audit features for cohesion. Triggers include architecture reviews, cost optimization requests, integration audits, and scalability analysis.
-
tyler-r-kendrick Bundle JotUSE FOR: Persisting and restoring application state such as window positions, user preferences, form values, and UI settings in desktop applications (WPF, WinForms, Avalonia). DO NOT USE FOR: Server-side configuration management, web application session state, database-backed settings, or security-sensitive credential storage.
-
henryhawke Bundle Subject Systems AuditorEnd-to-end audit for one explicit subject (service, feature, workflow, API, system idea, or capability) across every system touchpoint. Use when a user asks to audit/review/assess one subject for bugs, regressions, security gaps, performance or cost issues, architecture risks, missing tests, operational gaps, and concrete optimization or innovation opportunities.
-
tyler-r-kendrick Bundle EnforcerGuidance for Casbin.NET authorization library (Enforcer). USE FOR: access control list (ACL) enforcement, role-based access control (RBAC), attribute-based access control (ABAC), policy management, multi-tenant authorization, API endpoint protection. DO NOT USE FOR: authentication or login flows (use ASP.NET Core Identity), encryption (use CryptoNet), relationship-based access control with graph traversal (use Topaz), or input sanitization (use Hygiene).
-
tyler-r-kendrick Bundle Data ProtectionUse when implementing data protection controls for compliance and privacy. Covers encryption at rest and in transit, PII handling, data classification, GDPR, CCPA, HIPAA requirements, and data retention policies. USE FOR: data encryption, PII handling, GDPR, CCPA, HIPAA, data classification, data retention, data masking, tokenization, privacy by design, data minimization DO NOT USE FOR: cryptographic algorithm selection (use cryptography), access control design (use authentication), audit logging (use logging-monitoring)
-
tyler-r-kendrick Bundle Threat ModelingUse when identifying and prioritizing security threats during system design. Covers STRIDE and DREAD frameworks, threat modeling processes, data flow diagrams for security, and integrating threat analysis into the SDLC. USE FOR: STRIDE, DREAD, threat modeling, data flow diagrams for security, attack surface analysis, security design review, threat prioritization DO NOT USE FOR: runtime vulnerability scanning (use security-testing), incident response (use logging-monitoring), specific vulnerability remediation (use owasp)
-
tyler-r-kendrick Bundle CryptonetGuidance for CryptoNet cryptography library in .NET. USE FOR: RSA encryption/decryption, symmetric AES encryption, X.509 certificate-based crypto, self-signed certificate generation, key pair management, encrypting sensitive data at rest. DO NOT USE FOR: password hashing (use ASP.NET Core Identity), TLS/HTTPS configuration, JWT token signing (use Microsoft.IdentityModel), or authorization (use Casbin/Enforcer).
-
tyler-r-kendrick Bundle Financial RegulationUse when identifying financial regulations that apply to software handling payments, banking, or financial data. Covers PCI DSS, PSD2/PSD3, SOX, AML/KYC, Dodd-Frank, MiFID II, open banking, and fintech licensing across jurisdictions. USE FOR: PCI DSS, PSD2, PSD3, SOX, AML, KYC, Dodd-Frank, MiFID II, open banking, fintech licensing, payment processing compliance, money transmission, crypto regulation DO NOT USE FOR: payment gateway integration (use platform-specific skills), encryption implementation (use security/cryptography), financial data modeling (use dev/backend/data-modeling)
-
tryboy869 Bundle Vercel[Applies to: **/*] This guide outlines definitive best practices for developing and deploying applications on Vercel, ensuring optimal performance, security, and cost-efficiency.
-
tryboy869 Bundle C Sharp[Applies to: **/*] This guide defines definitive C# coding standards and best practices for our team, covering naming, formatting, modern language features, performance, security, and error handling to ensure consistent, maintainable, and high-quality code.
-
tyler-r-kendrick Bundle Event DrivenEvent-Driven Architecture (EDA), Event Sourcing, and CQRS -- complementary but independent patterns for building reactive, scalable systems with rich audit trails and temporal queries. USE FOR: event-driven architecture, event sourcing, CQRS, event stores, projections, eventual consistency, compensating transactions, temporal queries DO NOT USE FOR: messaging channel patterns (use dev/integration-patterns), message routing (use dev/integration-patterns/message-routing), domain modeling (use domain-driven-design)
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include solidity-security, firmware-analyst, reverse-engineer. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.