Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tryboy869 Bundle Hardhat[Applies to: **/*.{js,jsx}] Ensure Hardhat projects follow modern best practices for configuration, testing, deployment, and security using TypeScript and Hardhat 3's Rust runtime.
-
tyler-r-kendrick Bundle SecurityUse when addressing cross-cutting security concerns that apply to all languages, frameworks, and platforms. Covers OWASP standards, threat modeling, authentication, cryptography, supply chain security, and AI security. USE FOR: application security strategy, security architecture, choosing security controls, OWASP compliance, security tool selection, secure development lifecycle DO NOT USE FOR: specific language security implementations (use language-specific skills), infrastructure hardening (use iac skills), network security appliance configuration
-
tyler-r-kendrick Bundle SemgrepUSE FOR: Writing and running pattern-based static analysis rules for C# to detect security vulnerabilities, enforce coding standards, find anti-patterns, and automate code migrations. DO NOT USE FOR: Compile-time diagnostics (use Roslyn analyzers), dependency-level metrics (use NDepend), or runtime security scanning (use OWASP ZAP or Burp Suite).
-
agents-inc Bundle Desktop Security ElectronElectron fuses, ASAR integrity, sandbox hardening, CSP, permission handling, navigation restrictions
-
tryboy869 Bundle Solidity[Applies to: **/*] Definitive guidelines for writing secure, maintainable, and gas-efficient Solidity smart contracts, emphasizing modern best practices and security-first development.
-
agents-inc Bundle Desktop Framework ElectronElectron process architecture, IPC patterns, preload security, native APIs, packaging and distribution
-
tryboy869 Bundle Amazon Ec2[Applies to: **/*] This guide provides definitive best practices for deploying and managing Amazon EC2 instances, focusing on security, cost optimization, and operational excellence through Infrastructure as Code (IaC).
-
tyler-r-kendrick Bundle HealthcareUse when identifying healthcare regulations that apply to software handling health data or functioning as a medical device. Covers HIPAA, HITECH, FDA SaMD regulation, EU MDR, HITRUST, and health data privacy across jurisdictions. USE FOR: HIPAA, HITECH, PHI, FDA SaMD, EU MDR, HITRUST, health data privacy, medical device software, BAA, ePHI, clinical decision support, telehealth regulation, health app compliance DO NOT USE FOR: general data privacy (use privacy-data-protection), security controls implementation (use security skills), clinical validation methodology (consult regulatory affairs specialists)
-
tryboy869 Bundle Cloudflare[Applies to: **/*] Definitive guidelines for building secure, performant, and maintainable applications on Cloudflare's developer platform, emphasizing tiny bundles, edge-first design, and robust security.
-
agents-inc Bundle Meta Reviewing API ReviewingBackend code review patterns. Use when reviewing API routes, database operations, auth middleware, and server utilities. Covers injection, boundary validation, authorization coverage, secret/PII exposure, error leakage, and query patterns.
-
tryboy869 Bundle Android Sdk[Applies to: **/*.java] This guide provides definitive best practices for Android SDK development in Java, focusing on modern architecture, Jetpack libraries, performance, security, and testing.
-
agents-inc Bundle Shared Security Auth SecuritySecrets management, XSS prevention, CSRF protection, dependency scanning, DOMPurify sanitization, CSP headers, CODEOWNERS, HttpOnly cookies
-
tryboy869 Bundle API SecurityApply when building any API endpoint, authentication system, or web service. Covers OWASP Top 10, rate limiting, input validation, JWT patterns, and secrets management.
-
tyler-r-kendrick Bundle Secure SdlcUse when integrating security into the software development lifecycle. Covers security gates, shift-left security, DevSecOps practices, security champions programs, and security review processes. USE FOR: secure SDLC, DevSecOps, shift-left security, security gates, security review, security champions, SDL, security requirements, security architecture review DO NOT USE FOR: specific security tools (use security-testing), threat modeling methodology (use threat-modeling), compliance frameworks (use data-protection)
-
tryboy869 Bundle Google Maps JS[Applies to: **/*.{js,jsx}] This guide provides definitive best practices for integrating and managing the Google Maps JavaScript API in modern web applications, focusing on security, performance, and maintainability.
-
tyler-r-kendrick Bundle TopazGuidance for Topaz fine-grained, relationship-based authorization. USE FOR: fine-grained permissions, relationship-based access control (ReBAC), Google Zanzibar-style authorization, directory-based identity resolution, policy-as-code with OPA/Rego, hierarchical permission models (owner > editor > viewer). DO NOT USE FOR: simple RBAC (use Casbin/Enforcer), authentication (use ASP.NET Core Identity), input sanitization (use Hygiene), or encryption (use CryptoNet).
-
tyler-r-kendrick Bundle Export ControlsUse when identifying export control and sanctions laws that affect software distribution and encryption. Covers US EAR and ITAR, EU Dual-Use Regulation, Wassenaar Arrangement, OFAC sanctions, and encryption export rules that apply to software products distributed internationally. USE FOR: export controls, EAR, ITAR, OFAC sanctions, Wassenaar Arrangement, encryption export, ECCN, dual-use technology, embargoed countries, deemed exports, open-source encryption exemptions DO NOT USE FOR: implementing encryption (use security/cryptography), trade secret protection (use intellectual-property), general international business law (consult trade counsel)
-
itsimonfredlingjack-codex-dev-plugin Skill Code ReviewerElite code review expert specializing in modern AI-powered code analysis, security vulnerabilities, performance optimization, and production reliability. Masters static analysis tools, security scanning, and configuration review with 2024/2025 best practices. Use PROACTIVELY for code quality assurance.
-
lvtd-llc Bundle Influence AuditUse when auditing landing pages, emails, sales scripts, pricing flows, fundraising asks, product UX, or negotiations for persuasion mechanisms, pressure tactics, manipulation risk, fake urgency, fake social proof, authority misuse, or ethical rewrites.
-
itsimonfredlingjack-codex-dev-plugin Skill Malware AnalystExpert malware analyst specializing in defensive malware research, threat intelligence, and incident response. Masters sandbox analysis, behavioral analysis, and malware family identification. Handles static/dynamic analysis, unpacking, and IOC extraction. Use PROACTIVELY for malware triage, threat hunting, incident response, or security research.
-
tyler-r-kendrick Bundle API SecurityUse when securing APIs against common attack vectors. Covers rate limiting, CORS configuration, Content Security Policy, security headers, API gateway patterns, and API authentication strategies. USE FOR: API security, rate limiting, CORS, CSP, security headers, API gateway, API authentication, API keys, OAuth for APIs, HTTPS enforcement, request validation DO NOT USE FOR: API design patterns (use dev/backend/api-design), API testing tools (use testing/api-testing), authentication protocol details (use authentication)
-
tyler-r-kendrick Bundle Supply ChainUse when securing the software supply chain — dependencies, build pipelines, and artifact integrity. Covers SBOMs, dependency scanning, SLSA framework, artifact signing, and reproducible builds. USE FOR: SBOM, software bill of materials, dependency scanning, SLSA framework, artifact signing, reproducible builds, SCA, Dependabot, Snyk, Trivy, Grype, CycloneDX, SPDX DO NOT USE FOR: runtime vulnerability detection (use security-testing), container runtime security (use security-testing), secrets in code detection (use security-testing)
-
lvtd-llc Bundle Linkedin Post WritingDraft, revise, and audit LinkedIn feed posts for professional visibility, personal brand, audience value, comments, and ethical reach. Use when writing LinkedIn posts, feed updates, text posts, document or video captions, hashtag/mention plans, post hooks, or short-form LinkedIn content.
-
itsimonfredlingjack-codex-dev-plugin Bundle Firmware AnalystExpert firmware analyst specializing in embedded systems, IoT security, and hardware reverse engineering. Masters firmware extraction, analysis, and vulnerability research for routers, IoT devices, automotive systems, and industrial controllers. Use PROACTIVELY for firmware security audits, IoT penetration testing, or embedded systems research.
-
itsimonfredlingjack-codex-dev-plugin Skill Reverse EngineerExpert reverse engineer specializing in binary analysis, disassembly, decompilation, and software analysis. Masters IDA Pro, Ghidra, radare2, x64dbg, and modern RE toolchains. Handles executable analysis, library inspection, protocol extraction, and vulnerability research. Use PROACTIVELY for binary analysis, CTF challenges, security research, or understanding undocumented software.
-
tryboy869 Bundle Security Leak GuardrailsSets up secret-leak prevention guardrails with forbidden path checks, gitleaks config, CI secret scanning, and dependency updates. Use when hardening repos against credential leaks or when adding gitleaks, trufflehog, git hooks, or security checks.
-
lvtd-llc Bundle Linkedin Comment WritingWrite and audit LinkedIn comments and reply strategies that add professional value, start useful discussion, and increase ethical visibility. Use when drafting comments on LinkedIn posts, replying to comments, improving comment prompts, or planning comment-based engagement without spam.
-
lvtd-llc Bundle Directory Link EvaluationEvaluate directories, listings, profiles, citations, associations, and resource indexes for legitimate link-building value, editorial quality, spam risk, local relevance, and submission fit. Use when deciding whether to submit to a directory, audit directory backlinks, compare listing opportunities, or reject low-quality indexes.
-
itsimonfredlingjack-codex-dev-plugin Skill Mobile Security CoderExpert in secure mobile coding practices specializing in input validation, WebView security, and mobile-specific security patterns. Use PROACTIVELY for mobile security implementations or mobile security code reviews.
-
itsimonfredlingjack-codex-dev-plugin Skill Backend Security CoderExpert in secure backend coding practices specializing in input validation, authentication, and API security. Use PROACTIVELY for backend security implementations or security code reviews.
-
itsimonfredlingjack-codex-dev-plugin Skill Event Sourcing ArchitectExpert in event sourcing, CQRS, and event-driven architecture patterns. Masters event store design, projection building, saga orchestration, and eventual consistency patterns. Use PROACTIVELY for event-sourced systems, audit trail requirements, or complex domain modeling with temporal queries.
-
fdu-ins Skill OpsIT check, Security audit, Network scan, Am I secure, Admin check, VA update, Documents, Insurance, Subscriptions, What needs to get done, What should I focus on, Priorities, COS brief, Staff update. Unified operations covering IT security, life administration, and Chief of Staff orchestration across all Life OS domains.
-
tryboy869 Bundle Chrome Extension General Rules[Applies to: **/manifest.json] General rules and guidelines for developing Chrome extensions, focusing on architecture, security, and performance.
-
tryboy869 Bundle Go API Development General Rules[Applies to: /**/*_api.go] General rules for Go API development using the net/http package, focusing on code quality, security, and best practices.
-
lvtd-llc Bundle Sales Page Citability AuditAudit and improve commercial pages so they have legitimate citation reasons for guest posts, resource pages, digital PR, partnerships, and editorial mentions. Use when a sales page needs citable sections, proof points, tools, data, definitions, expert quotes, or less promotional link targets before outreach.
-
lvtd-llc Bundle Linkable Content ArchitectureAudit and improve the site architecture around linkable content before promotion, including orphan pages, internal links, hubs, URL stability, crawlability, canonicals, conversion paths, and link equity flow. Use when a linkable asset exists but may be buried, isolated, technically weak, or poorly connected to business pages.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include desktop-security-electron, desktop-framework-electron, meta-reviewing-api-reviewing. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.