Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tonone-ai Skill Gate ReconAudit existing API quality controls — find missing lint rules, gaps in CI gates, and quality debt. Use when asked to "audit our API quality controls", "find missing lint rules", or "assess our API governance".
-
tonone-ai Skill Grid ReconAudit existing layout patterns in a codebase — find ad-hoc spacing, inconsistent grids, and missing primitives. Use when asked to "audit our layout patterns", "we have ad-hoc spacing everywhere", or "our grids are inconsistent".
-
tonone-ai Skill Hunt ReconDesign a threat hunting program — maturity assessment, hunting calendar, and playbook library. Use when asked to "build a threat hunting program", "assess our hunting maturity", or "create a hunt playbook library".
-
tonone-ai Skill Keel AuditOperational efficiency audit — identify waste, redundancy, and friction across processes, tools, and team workflows. Use when asked to "audit our operations for waste", "where are we inefficient", "what tools are we paying for but not using", or "reduce operational overhead".
-
tonone-ai Skill Keep ReconCustomer success reconnaissance — audit current onboarding completion, health signals, NRR, churn patterns, and CS motion. Use when asked to "audit our customer success", "why are customers churning", "what's our NRR", or before designing any CS playbook.
-
outlinedriven-odin-claude-plugin Bundle Skill ScannerUse when a user asks to scan, audit, or validate a skill for security issues. Not for source-code or infrastructure review: use security-review. Not for remote-system changes.
-
outlinedriven-odin-claude-plugin Bundle Docs WritingUse when asked to write, restructure, or audit documentation with Diataxis types, or to draft a feature docs page or diagram source. Not for ADRs or architectural rationale.
-
pramoddutta Skill API Security TestingComprehensive API security testing based on OWASP API Security Top 10 including broken authentication, injection attacks, rate limiting, BOLA/BFLA vulnerabilities, and automated security scanning with ZAP and custom scripts.
-
pramoddutta Skill Csp Security TestingContent Security Policy testing and validation to prevent XSS attacks, data injection, and clickjacking through proper CSP header configuration.
-
tonone-ai Skill Mark ReconAudit existing brand assets and usage — find inconsistencies, off-brand applications, and gaps. Use when asked to "audit our brand assets", "find off-brand usage", or "check brand consistency".
-
tonone-ai Skill Mesh ReconAudit existing service mesh configuration — find mTLS gaps, traffic policy issues, and observability holes. Use when asked to "audit our service mesh", "find mTLS gaps", or "review traffic policy issues".
-
tonone-ai Skill Mock ReconAudit existing mocks and test doubles — find contract drift, missing error cases, and stale fixtures. Use when asked to "audit our mocks", "find stale test fixtures", or "check for contract drift".
-
tonone-ai Skill Move ReconAudit existing animations in a codebase — find inconsistencies, missing reduced-motion support, and performance issues. Use when asked to "audit our animations", "check reduced-motion support", or "our animations are janky".
-
tonone-ai Skill Pave AuditAudit developer experience — measure onboarding time, build speed, deployment friction, and developer satisfaction. Use when asked to "DX audit", "developer experience review", "why is development slow", "onboarding assessment", or "DORA metrics".
-
tonone-ai Skill Plot ReconAudit existing visualizations in a codebase or notebook — find misleading charts and quality issues. Use when asked to "audit our charts", "find misleading visualizations", or "review chart quality".
-
tonone-ai Skill Port ReconAudit multi-language SDK coverage — find missing languages, inconsistencies, and maintenance gaps. Use when asked to "audit our SDK coverage", "find missing language SDKs", or "review SDK maintenance gaps".
-
pramoddutta Skill Xss Testing PatternsCross-site scripting vulnerability testing covering reflected, stored, and DOM-based XSS with sanitization validation and CSP bypass detection.
-
pramoddutta Skill Cors Security TestingTesting Cross-Origin Resource Sharing configurations for misconfigurations, overly permissive policies, and credential handling vulnerabilities.
-
tonone-ai Skill Resp ReconAudit existing incident response capability — playbook coverage, tooling gaps, and readiness. Use when asked to "audit our incident response", "assess IR readiness", or "find playbook coverage gaps".
-
tonone-ai Skill Sast ReconAudit existing application security tooling and code for OWASP Top 10 coverage. Use when asked to "audit our appsec tooling", "check OWASP Top 10 coverage", or "find code security gaps".
-
tonone-ai Skill Siem ReconAudit existing SIEM deployment — log coverage, rule quality, and alert volume. Use when asked to "audit our SIEM", "find log coverage gaps", or "our alert volume is too high".
-
tonone-ai Skill Volt PowerPower management audit — analyze sleep modes, wake sources, power state machines, radio duty cycles, and battery life estimates. Use when asked to "audit power usage", "optimize battery life", "review power management", "why is my battery draining", "power budget analysis", or "sleep mode review".
-
outlinedriven-odin-claude-plugin Bundle Variant HuntUse when a confirmed root cause must be searched across a codebase, turned into a search rule, or seeded from graph neighbors. Not for building the program graph: use build-program-graph.
-
outlinedriven-odin-claude-plugin Bundle Vector ForgeUse when crypto implementations and a vector harness need mutation-driven cross-implementation test vector expansion. Not for Wycheproof: use wycheproof. Not for fuzzing: use fuzz-harness-writing.
-
outlinedriven-odin-claude-plugin Bundle Memory CleanUse when a human asks to audit memory, find stale or duplicate memories, or needs tidy's ICM-state audit. Not for writing new memories: use memory-update.
-
outlinedriven-odin-claude-plugin Bundle Kernel SecurityUse when writing an SELinux or AppArmor policy, a seccomp-bpf filter, enabling CET, PAC, or BTI, or triaging a kernel CVE. Not for KASAN report analysis: use kernel-debugging.
-
outlinedriven-odin-claude-plugin Bundle Zeroize AuditUse when auditing C, C++, or Rust secret-handling code to verify zeroization survives compiler optimization. Not for test vectors: use wycheproof.
-
tonone-ai Skill Zero AuditAudit an existing environment against zero trust principles — find implicit trust and over-privileged access. Use when asked to "audit against zero trust", "find implicit trust", or "find over-privileged access".
-
tonone-ai Skill Audit LegalFull legal compliance audit — contracts, policies, regulatory, IP, corporate hygiene. Use when asked to "run a legal audit", "are we legally compliant", or "full compliance review".
-
tonone-ai Skill Audit ReconSurvey legal artifacts for audit readiness. Use when asked "are we audit ready", "what legal artifacts exist", or "survey our legal docs".
-
tonone-ai Skill Bench ReconAudit existing performance testing — find missing benchmarks, stale baselines, and CI gaps. Use when asked "do we have benchmarks", "audit our performance testing", or "are our baselines stale".
-
tonone-ai Skill Blue DetectDesign detection rules for a threat — SIEM queries, alert logic, and MITRE ATT&CK mapping. Use when asked to "write a detection rule", "how do we detect this attack", or "build a SIEM query for this TTP".
-
tonone-ai Skill Brace ReconSupport operations reconnaissance -- audit current ticket volume, SLA compliance, knowledge base coverage, escalation paths, and CSAT to understand where support is the constraint. Use when asked to "audit our support", "why is our response time bad", "how healthy is our support operation", or "before designing a support system".
-
tonone-ai Skill Cache ReconAudit existing caching implementation — find cache misses, stampedes, and key design issues. Use when asked to "audit our caching", "why is our hit rate low", or "find cache stampedes".
-
tonone-ai Skill Chain ReconAudit existing dependency security — find unscanned packages, license violations, and SBOM gaps. Use when asked to "audit our dependencies", "do we have an SBOM", or "find license violations".
-
tonone-ai Skill Chaos ReconAudit existing resilience — identify untested failure modes and chaos engineering gaps. Use when asked "how resilient are we", "what failure modes are untested", or "find our chaos engineering gaps".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include gate-recon, grid-recon, hunt-recon. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.