Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
boom5426 Bundle Rebuttal ResponseAnalyze, draft, revise, or audit scientific peer-review response letters and point-by-point rebuttals. Use for reviewer comments, response letters, rebuttals, revision summaries, quoted manuscript changes, replies that must align with a manuscript or Supplementary Information, and submission-ready checks of direct question-answer alignment, evidence, figures, tables, notes, panels, terminology, numbers, and internal citations. Especially useful when replies must reuse the reviewer's terms, map every sub-question to an explicit answer, report new analyses or experiments, identify exact revision locations, or distinguish mandatory fixes from optional polishing.
-
boom5426 Bundle Reference Audit GuideVerify that cited references actually exist and that their metadata matches, using the runnable scripts this skill ships for CrossRef, Semantic Scholar, arXiv, and PubMed. Use when the bibliography must be checked against live sources rather than inspected locally: detecting fabricated or hallucinated citations, confirming that DOIs resolve, and matching title, authors, venue, and year against the record. Also covers the underlying verification principles and reference-audit best practices. For an offline hygiene pass over a .bib or .tex file, run citation-verifier first; for whether a real source supports the sentence citing it, run claim-source-verification.
-
skillsdirectory Skill Code ReviewerThorough code review assistant that checks for bugs, security vulnerabilities, performance issues, and adherence to best practices. Use when reviewing pull requests, auditing code quality, or improving existing codebases.
-
skillsdirectory Skill Security AuditorApplication security expert that performs thorough security audits including OWASP Top 10 analysis, dependency scanning, authentication review, and vulnerability assessment. Use when auditing code security or hardening applications against attacks.
-
qte77 Skill Securing MasApply OWASP MAESTRO 7-layer security framework to MAS designs
-
qte77 Skill Reviewing CodeProvides concise, focused code reviews matching exact task complexity requirements. Use when reviewing code quality, security, or when the user asks for code review.
-
qte77 Skill Enforcing Doc HierarchyAudits and aligns project documentation against authority chains (project docs and Claude Code infrastructure). Detects broken references, duplicates, scope creep, and chain breaks. Use when reviewing documentation health, fixing stale references, or enforcing single-source-of-truth.
-
qte77 Skill Auditing Website UsabilityAudits website usability for UX optimization, covering forms, navigation, validation, and microcopy. Use when reviewing user experience, task completion flows, or interface friction points.
-
nibzard-skills-kit Bundle Git XrayRun diagnostic git commands to assess a codebase's health before reading any code. Use this skill whenever the user asks you to understand a new codebase, audit a repo, assess technical debt, find risky code, check project health, figure out where to start reading, identify bus factor risks, or explore an unfamiliar repository. Also use it when the user asks 'what's going on in this repo', 'where are the problem areas', 'give me a health check', or 'what should I look at first'. If the user wants to understand a codebase at a strategic level before diving into code, this is the skill to use.
-
scottermonk Bundle Senior SecuritySecurity engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP guidance, cryptography patterns, and security scanning tools. Use when the user asks about security reviews, threat analysis, vulnerability assessments, secure coding practices, security audits, attack surface analysis, CVE remediation, or security best practices. Load with read_file on .kilocode/skills/senior-security/SKILL.md (ignore the absolute path in the location tag).
-
borkweb Skill Plan Eng ReviewEng manager-mode plan review. Lock in the execution plan — architecture, security, data flow, concurrency, diagrams, edge cases, test coverage, performance, observability, deployment. Supports Standard (per-section) and Quick-pass (grouped) pacing. Detects review context (git/PR, plan document, or hybrid). Walks through issues interactively with opinionated recommendations and produces a go/no-go readiness verdict. Use when asked to "review the architecture", "engineering review", or "lock in the plan". Proactively suggest when the user has a plan or design doc and is about to start coding — to catch architecture issues before implementation.
-
borkweb Skill Plan Deep ReviewDeep plan review with four modes: SCOPE EXPANSION (dream big), SELECTIVE EXPANSION (hold scope + cherry-pick expansions), HOLD SCOPE (maximum rigor), SCOPE REDUCTION (strip to essentials). Supports Standard (per-section) and Batched (grouped) pacing. Detects review context (git/PR, plan document, or hybrid). Challenges premises, maps failure modes and concurrency risks, reviews architecture/security/performance/cost/deployment, evaluates API contracts, and produces structured outputs with error registries, diagrams, and a go/no-go readiness verdict.
-
borkweb Bundle Plan Devex ReviewDeveloper experience plan review for developer-facing products (APIs, CLIs, SDKs, libraries, platforms, docs). Investigates developer personas, benchmarks against competitors, designs magical moments, traces friction points, then scores 8 DX dimensions 0-10. Three modes: DX EXPANSION (competitive advantage), DX POLISH (bulletproof every touchpoint), DX TRIAGE (critical gaps only). Use when asked to "DX review", "developer experience audit", "devex review", or "API design review". Proactively suggest when the user has a plan for a developer-facing product.
-
greyhaven-ai-claude-code-config Skill Suite AuditMeta-level plugin suite auditor that uses subagents to analyze any plugin for usability improvements, missing agents, duplication, and workflow optimizations. Generates comprehensive reports with user-approved todo conversion. Triggers: 'audit suite', 'analyze plugin usability', 'find duplicate agents', 'suggest new agents', 'optimize plugin workflow', 'plugin gap analysis'.
-
greyhaven-ai-claude-code-config Bundle Plugin AuditComprehensive Claude Code plugin auditing skill for validating structure, detecting deprecated patterns, and recommending best practices based on the latest changelog. Use when auditing plugins, checking for deprecations, validating plugin structure, preparing plugins for release, or ensuring compatibility with recent Claude Code versions. Triggers: 'audit plugin', 'check plugin health', 'validate skill', 'plugin deprecation', 'changelog compatibility', 'plugin best practices'.
-
hikaruegashira Bundle HarnessBuilds a harness: a meta-skill that defines specialist agents and generates the skills they use. Trigger when the user (1) asks to 'build/set up/construct a harness', (2) asks for 'harness design' or 'harness engineering', (3) wants a harness-based automation system for a new domain/project, (4) wants to restructure or extend an existing harness, or (5) asks to inspect, audit, sync, or maintain an existing harness (agents/skills drift, status check).
-
hikaruegashira Skill Falsehood AuditAI 生成(vibecoding)成果物に潜む「それっぽい虚偽」を、固定された検査カタログ(検査ID・手順・ 合格基準つき)で系統的に検出する監査規格。主張面を列挙し、各主張面に対応する検査を 機械的に適用し、カバレッジマトリクスに全セルの実施状態を記録する。 内部整合(テスト全パス・schema valid・CI green)は証拠として認めない。 Trigger: 虚偽検出, ハリボテ検出, vibecoding 監査, 本物か確認, それっぽい嘘, fabrication audit, AI生成コード 検証, 捏造チェック.
-
shir-bruchim Bundle SecuritySecurity review and safe-op patterns. Use when reviewing for vulnerabilities, setting up hooks, or protecting files.
-
shir-bruchim Skill Pr ReviewStructured GitHub PR/diff review across correctness, security, tests, and architecture with severity ratings. Use to review a PR or pull request. (Built-in /code-review for a quick working-tree diff; this is the full multi-dimension PR pass.)
-
shir-bruchim Skill Verification LoopFinal pre-commit gate via built-in /loop — runs build, types, lint, tests, security, diff review. Use as the last check before commit/PR. (superpowers:verification-before-completion owns the evidence-before-claims principle.)
-
inkline Skill Adversarial QARepro-first QA for Inkline — minimal .ink.tsx reproductions, the visual-parity and cross-target harnesses, fuzz targets, and how to audit teammates' claims. Use for bug verification, regression coverage, and claim audits.
-
cbemister Skill Verify WorkComprehensive pre-commit verification for security, best practices, code standards, and performance. Checks for vulnerabilities, efficiency issues, N+1 queries, and convention adherence.
-
cbemister Skill Conversion AuditAudit and optimize pages for conversion — value props, CTAs, copy, social proof, and friction points. Run a full audit or target a specific area.
-
getsentry Skill Upgrade DepUpgrade a dependency in the Sentry JavaScript SDK. Use when upgrading packages, bumping versions, or fixing security vulnerabilities via dependency updates.
845 -
getsentry Skill Linear Project StatusAnalyze a Linear project's health and produce a status summary for a project lead or manager. Inspects status-update cadence, lead/owner presence, target-date realism and stability, issue staleness, milestone health, and scope creep. Use whenever the user wants a status report, project review, health check, weekly review, or audit of a Linear project — including phrases like "how is project X going", "give me a status on this Linear project", "audit this project", "is this project on track", "check project health", or when they paste a Linear project URL and ask for a summary. Use it even when the user doesn't explicitly say "audit" or "status" — if the request is fundamentally "tell me how this Linear project is doing", trigger this skill.
845 -
wayne930242 Bundle Refactoring PluginsRefactors and audits Claude Code plugin packages against official best practices. Use when refactoring, migrating, or auditing a Claude Code plugin package. Use when user says "refactor plugin", "audit plugin", "plugin health check", "migrate plugin structure". Use when plugin structure drifts from official best practices.
-
matheusallvarenga Bundle Itm AuditSistema de Auditoria de Dados v5 para análise forense de arquivos distribuídos em múltiplas fontes (Google Drive, HD Externo, Notion). Inclui deduplicação, classificação e relatórios.
-
arcasilesgroup Bundle AI GoalRuns one request through the whole governed cycle in a single pass — research, spec, challenge, council, build, review, verify, security, audit, ship — and stops only to hand a person a tested thing to try. Your invocation is the standing approval; nobody else steps in until the end. The bar is the green gate plus an independent critic's verdict on the real artifact, looped until both hold. Trigger for "finish this without me, give me something to test", "run the whole gauntlet to a green gate". Not for one stage on its own — call that stage directly. Not for approving anything: you finish, then hand over.
-
arcasilesgroup Bundle AI CycleWalks one request through the governed cycle by loading each stage's own skill body and following it — research, spec, challenge, council, then a brief a person reads. After that person says go, `ai-cycle build <NNN>` runs the second half: build, review, verify, security, audit, ship. Trigger for "run the whole cycle on this", "/ai-cycle build 021". Not for one stage on its own — call that stage directly. Not for approving anything: it stops at the brief and has no field in which an approval could be written.
-
arcasilesgroup Bundle AI DebugFinds the root cause of broken behaviour and names it at file:line, then writes the check that fails for that reason before changing anything. Also resolves merge and rebase conflicts by intent rather than by taking a side. Trigger for "it's not working", "this used to work", "I'm getting an error", "CI is failing", "why is X happening", "I have conflicts", "the rebase failed". Not for adding test coverage to working code — use /ai-review. Not for exploring an unfamiliar area — use /ai-explore. Not for designing the fix — once the cause is named, use /ai-plan.
-
arcasilesgroup Bundle AI VerifyRuns the gate and the security lane and ticks each production-ready box beside the command that ticked it, or walks a spec's examples and marks each one against a real command. Trigger for "verify this", "is it ready", "tick the boxes", "does it do what the spec said", "check the acceptance criteria". Not for judging a diff — use /ai-review, which reads a change and this reads a claim. Not for finding a cause — use /ai-debug. It observes and never accepts: incomplete is the answer to every box and every example with no command pasted beside it. Not for deciding a request that falls outside a declared boundary — report CANNOT DECIDE and block, because a decision that cannot classify itself is not a decision this skill can take.
-
iamjcabalejo Skill Code ReviewReview code for correctness, security, maintainability, and style. Use when reviewing pull requests, examining code changes, or performing code review.
-
iamjcabalejo Skill Security AuditPerform OWASP-aligned security checks on code and APIs. Use when auditing for vulnerabilities, reviewing security, or working with security-engineer.
-
iamjcabalejo Skill Backend ReviewerFull criteria for reviewing backend code. Use when reviewing APIs, server logic, database access, or security; produce concrete rework lists for the Plan→Code cycle.
-
robbyt Skill Web SearchReal-time web research using Google Search via Google's Antigravity (`agy`) CLI — the replacement for the deprecated `gemini-cli`. Trigger when user needs current information ("search with agy", "search with Google Antigravity", "find current info about X with agy", "what's the latest on Y"), library/API research, security vulnerability lookups, or comparisons requiring recent data.
-
robbyt Skill Hdr AuditThis skill should be used when the user asks "is this real HDR", "check HDR metadata", "fake HDR", "is this Dolby Vision legitimate", "HDR vs SDR", "check HDR peak brightness", or wants to verify whether HDR content is genuine or inverse tonemapped from SDR.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include rebuttal-response, reference-audit-guide, plan-eng-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.