Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ragnarok22 Bundle Dependency Risk AuditReview Python dependencies for known security advisories, stale version pins, and unsafe upgrade paths. Use when users ask for dependency security reviews, requirements or lockfile audits, upgrade planning, pre-release risk checks, or remediation prioritization for Python projects.
-
swiftyjunnos Bundle Code ReviewerConduct thorough code reviews of implemented features. Use this skill after implementation is complete to review code quality, security, performance, and requirements compliance. Creates structured review reports in context/ directory with actionable feedback and approval status.
-
radkomih Bundle Code ReviewReviews code for quality, security, maintainability, and adherence to Clean Code principles. Use ANY time code is written, modified, or shared — including PR reviews, post-implementation checks, refactoring analysis, or whenever the user asks whether code looks right. Don't wait for an explicit review request; if code was just changed or written, this skill applies.
-
jayteealao Bundle DiataxisWrite or review documentation using the Diátaxis framework. Use when the user asks for a tutorial, how-to guide, technical reference, explanation/conceptual doc, README, a documentation plan, or a review/audit of existing docs. Classifies the request into the right quadrant and enforces boundary discipline between them (learning vs task vs lookup vs understanding). For documentation produced as a stage of an /wf lifecycle workflow, use /wf docs instead.
-
ssojet Bundle Oidc Hosted Page JavaImplement "Sign in with SSO" in Java Spring Boot applications using SSOJet OIDC with Spring Security.
-
radkomih Skill Secure Reliable SystemsUse when designing, implementing, or reviewing systems for security and reliability — covers threat modeling, least privilege, resilience patterns, secure deployment, incident response, and security culture. Based on Google's "Building Secure and Reliable Systems".
-
kaichen Skill Codebase Evidence ReviewUse this when the user asks to research, review, audit, explain, or trace behavior in a codebase, repository, PR, spec, architecture doc, or local implementation. This skill should trigger for phrases like "基于 codebase", "从头梳理", "review", "audit", "看源码", "研究这份 codebase", "这个流程怎么跑", or when a symptom may be explained by local source. It enforces source-backed findings, exact file/function references, and verification before claims.
-
shawn-sandy Bundle Security ScrubScans code and diffs for secrets and sensitive data. Detects credentials, tokens, and PII to prevent leaks before sharing. Use when the user asks to check for secrets or review a diff for leaks.
-
shawn-sandy Bundle Reviewing TestsAudits tests for quality, coverage, and code alignment. Identifies gaps, redundant tests, and misaligned assertions. Use when the user asks to review, audit, or improve a test suite.
-
shawn-sandy Bundle Agentic Memory ManagementAudits and optimizes CLAUDE.md project memory files. Checks adherence to Claude Code best practices and produces actionable fixes. Use when the user asks to audit, optimize, or diagnose a CLAUDE.md.
-
alexander-danilenko Bundle TestingApply these opinionated testing conventions whenever writing, reviewing, or planning tests: what earns a test and what is coverage theatre, asserting outputs rather than mock calls, the three modes (functional, performance, security), naming and isolation rules, where to mock, and reporting findings for coverage rather than self-filtering. Includes house Jest standards for NestJS unit and contract tests, TDD discipline, and test-report structure.
-
ai-coding-shield Bundle AI Coding ShieldSecurity auditing tool for AI development workflows, rules, skills, and MCPs.
-
toruai Skill Dev RcThe last gate before merge — QA, security audit, review and changelog, with objective pass conditions.
-
toruai Skill Dev SecurityAudit the code for vulnerabilities, leaked secrets and risky dependencies before it ships.
-
zirui-song Skill Referee PanelUse before sending a design or draft to a coauthor or referee — launches five parallel adversarial subagents (identification, power, literature, data provenance, independent replication) against the research design in the repo, each citing file:line evidence, then synthesizes one threat memo ranked by probability-right × damage-if-right. Trigger phrases include "referee panel", "attack this design", "what would a referee say", "adversarial review of my paper".
-
lnsd Skill Code ReviewReview code changes for bugs, guideline violations, security, and quality. Use when reviewing PRs, code changes, or before commits.
-
google Skill Secops TriageExpert guidance for security alert triage. Use this when the user asks to "triage" an alert or case.
14.4k -
complianceascode Skill Create RuleCreate a new security rule with all required components
-
complianceascode Skill Onboard ControlOnboard a new security policy as a control file. Parse the document, create control file structure, and map existing rules to requirements.
-
thewaywithin Skill Code Review LoopRun a scored, converge-or-cap code-review loop on a diff or surface — a read-only critic raises evidence-backed findings, a read-write fixer addresses only those findings, then re-audit until two clean rounds or a cap. Use when reviewing a PR, hardening a changed file, or iterating to a clean bill of health without reward-hacking.
-
thewaywithin Skill Saas MultitenancyImplement multi-tenancy in SaaS applications — organisation/workspace isolation, row-level security (RLS), tenant routing, role-based access control, and tenant lifecycle management. Use when building tenant, organisation, workspace, RLS, or multi-tenant data-isolation features.
-
yila-ai Bundle Academic HumanizerUse when researchers ask to remove generic, templated, or AI-like patterns from Chinese or English academic prose, make an AI-assisted draft sound more like the author's own scholarly voice, or audit a paper for “AI味”. Preserve every scientific claim, number, equation, citation, limitation, and uncertainty. Not for detector evasion or ordinary translation and grammar-only editing.
-
yila-ai Bundle Science Research WritingUse when researchers need to plan, draft, revise, or audit an empirical research paper from their own materials, including Introduction, Methods, Results, Discussion, Conclusion, Abstract, and Title, with evidence-preserving and target-journal-aware guidance.
-
hive-intel Skill Hive Security RiskUse this skill before the user signs, approves, swaps, connects a wallet to a dApp, or touches an unknown contract, URL, or transaction payload — any "should I sign/approve/ape/connect" moment, even when the user only implies the transaction. Runs token, address, approval, phishing, and simulation risk checks and reports severity, evidence, and remediation instead of guessing. For research-style "is this token worth a look" questions use hive-token-diligence.
-
hive-intel Skill Hive Token DiligenceUse this skill whenever the user asks whether a specific token is real, legit, liquid, well-held, enriched, investable, or worth researching — "is this token a scam", "run diligence on 0x…", "who holds this", "does it have real liquidity" — even if they never say "diligence". Investigates metadata, market context, holders, DEX liquidity, enrichment, and risk signals for an exact chain and contract. For pre-transaction risk checks (approvals, signing, swap simulation) use hive-security-risk; for pool-level depth and trade flow use hive-dex-pool-analysis; for Solana mints use hive-solana-analysis.
-
hive-intel Skill Hive Wallet InvestigationUse this skill whenever the user wants to look inside a wallet or address — portfolio, holdings, balances, transfers, PnL, NFT exposure, DeFi positions, whale moves, "what does this address hold", "trace this wallet's activity" — even if they just paste an address. Requires wallet address and chain before executing Hive wallet tools. For Solana wallets use hive-solana-analysis; for "is this address malicious" risk checks use hive-security-risk.
-
ott-cybersecurity-llc Bundle Code UnderstandingProvides adversarial code comprehension for security research, mapping architecture, tracing data flows, and hunting vulnerability variants to build ground-truth understanding before or alongside static analysis.
-
ott-cybersecurity-llc Skill Github ArchiveInvestigate GitHub security incidents using tamper-proof GitHub Archive data via BigQuery. Use when verifying repository activity claims, recovering deleted PRs/branches/tags/repos, attributing actions to actors, or reconstructing attack timelines. Provides immutable forensic evidence of all public GitHub events since 2011.
-
ott-cybersecurity-llc Bundle Github Evidence KitGenerate, export, load, and verify forensic evidence from GitHub sources. Use when creating verifiable evidence objects from GitHub API, GH Archive, Wayback Machine, local git repositories, or security vendor reports. Handles evidence storage, querying, and re-verification against original sources.
-
ebal5 Bundle Coupling Design Advisor設計時(事前)の対話型アドバイザ。候補案を3次元(統合強度・距離・変動性)で評価し 均衡度を比較、推奨案と ADR 形式の出力を返す。 発火条件(以下のドメイン語のいずれかを含むときにのみ発火する): - 「結合バランス」「均衡結合」「均衡度」「3 次元モデル」 (本スキル固有の用語 — 必須条件) - 上記語のいずれかを伴う以下の文脈: - 「新しいマイクロサービスの境界を引きたい」 - 「モジュール分割/統合」「サブドメイン境界」の設計判断 - 「イベント駆動 vs 直接呼び出し」の結合バランス評価 - 「結合バランスで設計レビューしたい」という明示的依頼 発火しない: - 「A案 vs B案 どちらが良い」のみの一般的な技術選定・UI/DB 設計(ドメイン語を伴わない) - 既存コードの計測 → coupling-audit(未実装) - 純粋な実装タスク
-
heikopanjas Skill C ConventionsC coding conventions and best practices for C17 development. Use when writing, reviewing, or refactoring C code to ensure security, const-correctness, platform portability, and consistent parameter and naming conventions.
-
kanyun-inc Skill Code Confidence MapAssesses code comprehensibility and maintainability risk. Use when the user asks about code confidence, risk, maintainability, tech debt, code health, or whether code is safe to change. Also use when the user asks to analyze code quality, scan for risks, check if code is messy or complex, audit code, do a code checkup, find weak spots, assess what needs refactoring, or asks about code trust, hidden risks, gotchas, or onboarding to a codebase.
-
raphaelmansuy Skill Multi Tenant PostgresImplement multi-tenant PostgreSQL database layer with row-level security. Use for database schema design, tenant isolation, migrations, connection pooling, and data access patterns. Triggers on "database schema", "PostgreSQL", "multi-tenant", "row-level security", "RLS", "database migration", "sqlc", or when implementing the data layer for AgentStack.
-
bntvllnt Bundle Oss ReadinessOpen-source/public release readiness gate. Audit repos for OSS basics, scaffold missing public-release files, generate llms.txt + llms-full.txt, validate CI, and sync version references. Triggers: "oss", "/oss", "open source readiness", "release readiness", "public release", "go public", "oss audit", "llms.txt", "generate llms", "version bump docs", "scaffold OSS files", "release title", "release messaging", "release notes", "announcement quality".
-
groupzer0 Bundle Security PatternsSecurity vulnerability detection patterns including OWASP Top 10, language-specific vulnerabilities, and remediation guidance. Load when reviewing code for security issues, conducting audits, or implementing authentication/authorization.
-
nicholasgriffintn Skill Security ReviewA specialist skill for security reviews, threat modeling, and remediation guidance. Use for auth/permissions changes, secrets or PII handling, public endpoints, or dependency upgrades.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include ai-coding-shield, diataxis, codebase-evidence-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.