Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tryboy869 Bundle Go API Security And Best Practices[Applies to: /*/**/*_api.go] This rule emphasizes security, scalability, and maintainability best practices in Go API development.
-
fdu-ins Skill NorvidizeExtract and audit claims for norvid tracking system
-
outlinedriven-odin-claude-plugin Bundle Review Plugin SubmissionUse when asked to review a plugin for marketplace readiness via a read-only audit of published quality gates. Not for reviewing a PR or code diff: use review.
-
lvtd-llc Bundle Linkedin Article Newsletter WritingPlan, draft, repurpose, and audit LinkedIn articles and newsletters that demonstrate expertise and support a professional content strategy. Use when writing long-form LinkedIn articles, newsletter editions, article teasers, follow-me articles, issue plans, or post-to-newsletter repurposing.
-
lvtd-llc Bundle Documentation Information ArchitectureAudit, organize, and redesign developer documentation information architecture, including content inventory, navigation, landing pages, sequences, hierarchies, webs, breadcrumbs, sidebars, metadata, redirects, migration, platform/tool selection, and maintainable IA decisions. Use when restructuring docs sites, improving findability, planning doc migration, evaluating docs tooling, or organizing large documentation sets.
-
pleaseai Skill Cubic ReviewRun AI-powered code reviews using Cubic CLI to detect bugs, security vulnerabilities, and style issues in local changes. Use when the user says "review my code," "check my changes for bugs," "run cubic review," "review this diff," "pre-commit check," "find issues before I push," "analyze my branch changes," or "code quality check." Triggers on mentions of cubic, code review, diff review, pre-commit checks, bug detection, and code quality validation.
-
outlinedriven-odin-claude-plugin Bundle Crypto Protocol DiagramUse when asked for a sequence diagram of cryptographic protocol semantics from code, prose, RFCs, papers, ProVerif, or Tamarin, or for code/spec divergence. Not for architecture: use embed-diagram.
-
outlinedriven-odin-claude-plugin Bundle Triage Security FindingUse when exactly one concrete security finding with a source anchor needs a verdict before PoC work. Not for projecting batches of findings onto a graph: use project-findings-onto-graph.
-
outlinedriven-odin-claude-plugin Bundle Evaluation Leakage AuditUse when reviewing an evaluation, benchmark, or scoring harness for leakage, or a validation result that looks self-confirming. Modes: leakage, self-audit. Not for one claim: use verify-both-ways.
-
fdu-ins Skill Estate GuardEstate Planning & Legacy Protection for the Owens family. Tracks wills, trusts, beneficiary designations, life insurance, survivor benefits, and powers of attorney. Ensures Lindsey and the kids are protected if something happens to Tory. Triggers on: "Estate plan", "Will", "Life insurance", "Beneficiaries", "What happens if", "Legacy", "Survivor benefits", "Power of attorney", "Trust", "Estate check", "Beneficiary audit", "SGLI", "FSGLI", "Dependent education", "Chapter 35". The only estate plan that fails worse than a bad one is no plan at all.
-
outlinedriven-odin-claude-plugin Bundle Burpsuite Project ParserUse when asked to analyze a Burp Suite .burp project for audit items, request/response metadata, or captured traffic. Modes: parsed (default) and stream. Not for source or remote-system changes.
-
outlinedriven-odin-claude-plugin Bundle Codeql Security AnalysisUse when building or reusing a CodeQL database, running CodeQL security analysis, or modeling project-specific sources and sinks. Not for manual vulnerability review: use confirmed-security-review.
-
tryboy869 Bundle Chrome Extension Dev JS Typescript Cursorrules Pro CursorrulApply for chrome-extension-dev-js-typescript-cursorrules-pro. --- description: General rules and guidelines for developing Chrome extensions, focusing on architecture, security, and performance. globs: **/manifest.json
-
outlinedriven-odin-claude-plugin Bundle Confirmed Security ReviewUse when the user asks for a security review, vulnerability audit, or review of injection, XSS, auth, or crypto. HIGH-confidence findings only. Not for CodeQL analysis: use codeql-security-analysis.
-
outlinedriven-odin-claude-plugin Bundle Smart Contract Audit PrepUse when a smart-contract project must become review-ready before an audit. Not for workflow: use smart-contract-secure-workflow. Not for guidelines: use smart-contract-guidelines-advisor.
-
outlinedriven-odin-claude-plugin Bundle Supply Chain Risk AuditorUse when assessing npm, PyPI, or Go dependency supply-chain risk, with lockfile-absent paths marked unassessable. Not for remote or irreversible changes.
-
outlinedriven-odin-claude-plugin Bundle Developer Experience ReviewUse when dogfooding a developer-facing product or workflow to produce an evidence-backed DX scorecard. Not for visual UI audit: use web-design-review.
-
outlinedriven-odin-claude-plugin Bundle Open Source Readiness AuditUse when the user asks whether a repository is ready for public release or wants a gap assessment. Not for choosing or applying a license: use open-source-license-selection.
-
outlinedriven-odin-claude-plugin Bundle Oauth2 Flow ImplementationUse when asked to implement, debug, validate, or explain an OAuth 2.1 flow: auth code with PKCE, client credentials, device, or refresh. Also for a failing token exchange. Not for irreversible work.
-
outlinedriven-odin-claude-plugin Bundle Token Integration AnalyzerUse when a token implementation or integration needs standards, privilege, nonstandard-behavior, and defensive-integration analysis. Not for source or remote-system changes.
-
outlinedriven-odin-claude-plugin Bundle F Star Effectful VerificationUse when effectful, security-sensitive code needs refinement-typed, SMT-backed verification in F*, in the HACL* or Project Everest style.
-
outlinedriven-odin-claude-plugin Bundle Chain Vulnerability ScannerUse when an Algorand, Cairo, Cosmos SDK, Solana, Substrate, or TON codebase needs vulnerability scanning with reachability-backed findings. Not for non-chain review: use security-review.
-
outlinedriven-odin-claude-plugin Bundle Project Findings Onto GraphUse when SARIF, reviewer annotations, or third-party findings must be projected onto a program graph. Not for building graph: use build-program-graph. Not for triage: use triage-security-finding.
-
pleaseai Bundle Claude Md ImproverAudit and improve CLAUDE.md files in repositories. Use when user asks to check, audit, update, improve, or fix CLAUDE.md files. Scans for all CLAUDE.md files, evaluates quality against templates, outputs quality report, then makes targeted updates. Also use when the user mentions "CLAUDE.md maintenance" or "project memory optimization".
-
pleaseai Bundle Optimize Skill InstructionsReview and improve your skill with actionable recommendations. Reviews the whole bundle, validates syntax and references, explains rubric, shows before/after scores, and edits the SKILL.md and its reference docs. Use when reviewing skill quality, improving a SKILL.md or its reference files, checking scoring dimensions and quick wins, auditing progressive disclosure and orphaned bundle files, generating improvement recommendations, running a post-edit quality audit, creating approval-gated change proposals, or automating the skill review workflow. For the full optimization cycle (review + evals + improve), use `optimize-skill-performance-and-instructions`.
-
pleaseai Skill Two Factor Authentication Best PracticesConfigure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin. Use when users need MFA, multi-factor authentication, authenticator setup, or login security with Better Auth.
-
outlinedriven-odin-claude-plugin Bundle PlanUse when a user commits to a direction and asks to plan, brief, or research it; modes score, breakdown, shape, visual. Not for codebase audit: use plan-review. Not for four-phase review: use autoplan.
-
outlinedriven-odin-claude-plugin Bundle Security Finding VerificationUse when a named security allegation needs a true-positive or false-positive verdict. Not for discovering bugs: use security-review. Not for adding controls: use security-hardening.
-
outlinedriven-odin-claude-plugin Bundle Vulnerability Triage BrocardsUse when a vulnerability report, CVE, bug-bounty submission, or automated finding needs triage before deep verification. Don't use for tasks that require source or remote-system changes.
-
outlinedriven-odin-claude-plugin Bundle No CommentsUse when asked to audit comments in code files and propose structural replacements or deletions with per-candidate approval. Not for deterministic commented-out-code removal: use deslop.
-
outlinedriven-odin-claude-plugin Bundle Smart Contract Secure WorkflowUse when a smart-contract team invokes this before check-in or deployment. Not for audit prep: use smart-contract-audit-prep. Not for guidelines: use smart-contract-guidelines-advisor.
-
outlinedriven-odin-claude-plugin Bundle Function Audit Context AnalyzerUse when asked for audit-context analysis of one function, or to build audit context across codebase before vulnerability hunting. Local write only. Not for vulnerability finding or severity rating.
-
outlinedriven-odin-claude-plugin Bundle Smart Contract Guidelines AdvisorUse when a smart-contract project needs architecture, testing, or a maturity scorecard. Use `guidelines` or `maturity` mode. Not for audits: use smart-contract-audit-prep.
-
pramoddutta Skill Semgrep Sast AnalysisStatic application security testing using Semgrep for finding vulnerabilities, code smells, and enforcing security policies across codebases.
-
nordeim-openclaw-curated-skills Bundle TrustskillTrustSkill v3.1 - Advanced security scanner for OpenClaw skills with 99% false positive reduction. Detects malicious code, hardcoded secrets, vulnerable dependencies, tainted data flows, backdoors, credential theft, privacy file access, command injection, file system risks, network exfiltration, and sensitive data leaks. Features entropy-based secret detection, OSV vulnerability database integration, taint analysis, smart data flow detection, context-aware documentation scanning, and flexible YAML configuration.
-
fdu-ins Skill Actuarial ModelingAnalyzes actuarial modeling systems for loss reserving accuracy, premium pricing methodology, mortality/morbidity tables, stochastic modeling, and capital adequacy per SOA and Solvency II standards. USE THIS SKILL WHEN: - You need to review or audit actuarial models (reserving, pricing, capital) - Someone asks about loss triangle analysis or reserve adequacy - You are evaluating IBNR calculations, chain ladder methods, or Bornhuetter-Ferguson - A project involves insurance pricing, GLM rating models, or ratemaking - You need to assess Solvency II SCR calculations or RBC compliance - Someone mentions actuarial opinions, ASOP compliance, or SOA standards - You are reviewing stochastic models, ESG configurations, or DFA frameworks - A codebase uses actuarial libraries (chainladder, lifetables, ChainLadder R package) TRIGGER PHRASES: "actuarial", "loss reserving", "IBNR", "chain ladder", "premium pricing", "mortality table", "Solvency II", "capital adequacy", "ratemaking", "GLM pricing", "risk-based capital", "re
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include norvidize, linkedin-article-newsletter-writing, estate-guard. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.