Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
kubernetes-sigs-kueue Skill Authn Authz RelaxationFlag AuthN/AuthZ relaxation — webhook token skipping, failurePolicy Ignore, missing SubjectAccessReview, wildcard RBAC, privileged pod specs (CWE-269, CWE-287, CWE-306, CWE-862, CWE-863).
-
kubernetes-sigs-kueue Skill Information DisclosureFlag information-disclosure patterns — full-object logging, request echoing, credentials in status/annotations, kubeconfig logging, secret-bearing status (CWE-200, CWE-522, CWE-532, CWE-552).
-
sendaifun Bundle VulnhunterSecurity vulnerability detection and variant analysis skill. Use when hunting for dangerous APIs, footgun patterns, error-prone configurations, and vulnerability variants across codebases. Combines sharp edges detection with variant hunting methodology.
-
apecloud Bundle Kubeblocks Configure TlsAccess-security capability entry for TLS and mTLS on existing KubeBlocks clusters. Use when the user wants to enable, verify, or rotate encrypted database connections. Do not use this as a create-time primary entry; create-time routing still starts at preflight plus the dedicated engine skill.
-
agile-v Skill Agile V AdrAuthoring, approval, immutability, and supersession of Architecture Decision Records (ADRs) in the Agile V lifecycle. Load when recording a significant, long-lived architectural, platform, tooling, or security decision.
-
nodejsmith Skill CLI AuditUse when the user says: "audit this CLI", "CLI quality check", "full CLI review", "CLI UX audit". Comprehensive CLI tool quality audit across all dimensions — hardening, output, clarity, affordances, and complexity.
-
apecloud Skill Kubeblocks Manage AccountsAccess-security capability entry for account, password, and credential handling on existing KubeBlocks clusters. Use when the user wants to retrieve, rotate, reset, or preconfigure database credentials. Do not use this as a create-time primary entry; create-time routing still starts at preflight plus the dedicated engine skill.
-
agile-v Skill Threat ModelerSTRIDE threat modeling and privacy impact assessment to generate security/privacy requirements. Use before requirement-architect to shift security left.
-
willyu1007 Bundle Review Code ArchitectureReview code changes for architectural consistency, correctness risks, security/performance concerns, and verification gaps; produce a prioritized, actionable review report.
-
natea Skill N8n Security TestingCredential exposure detection, OAuth flow validation, API key management testing, and data sanitization verification for n8n workflows. Use when validating n8n workflow security.
-
telum-ai Bundle Speck LarpExercises real user or operator jobs. Use after audit before story, epic, or project validation.
-
telum-ai Bundle Speck AuditAudits implemented work adversarially. Use after implementation and before any story or epic validation.
-
telum-ai Bundle Epic ValidateValidates an epic across completed stories and audit evidence. Use at the epic prove gate before retrospective.
-
telum-ai Bundle Story ValidateValidates a story after audit and declares readiness. Use at the story prove gate before retrospective.
-
brite-nites Skill Flow PreflightFoundation sub-skill for the flow-architecture plugin (implements CDR-023). Runs at the start of every FDA orchestrator (`/flow:start-project`, `/flow:retrofit-project`, `/flow:add-domain`, `/flow:add-sub-flow`, `/flow:audit`) to verify the environment, discover existing FDA artifacts on the filesystem, classify the run mode, confirm Linear scope (writing `.flow/config.json` on first run via the embedded Q36 7-step bootstrap), and emit the Q12.5 structured preamble that downstream sub-skills consume. Read-only EXCEPT the atomic-rename `.flow/config.json` write on first successful confirmation or stale-config replacement.
-
brite-nites Skill Issue Quality GateApply 7 quality checks to a single Linear issue object. Returns pass/fail per check. Phase 1 audit and Phase 2 scope both consume this skill.
-
hack23 Skill Isms ComplianceISMS policy alignment and compliance verification for Hack23 AB security standards (ISO 27001, NIST CSF 2.0, CIS Controls v8.1)
-
hack23 Skill Incident ResponseSecurity incident detection, analysis, containment, and recovery per NIST SP 800-61r2 and ISO 27035
-
telum-ai Bundle Story ImplementImplements analyzed story work. Use after required spec, plan, tasks, and story analysis before speck-audit.
-
djankies Skill Reviewing SecurityAutomated tooling and detection patterns for JavaScript/TypeScript security vulnerabilities. Provides scan commands, vulnerability patterns, and severity mapping—not output formatting or workflow.
-
djankies Skill Sanitizing User InputsSanitizing and validating user input to prevent XSS, injection attacks, and security vulnerabilities in TypeScript applications
-
hack23 Skill Secure Code ReviewSecurity code review using OWASP Top 10, input validation, and Hack23 ISMS secure development policy for TypeScript/MCP
-
hack23 Skill Security By DesignAPI security, MCP tool security, input validation, rate limiting, audit logging, secure authentication, and defense-in-depth principles
-
hack23 Skill Open Source GovernanceOpen source governance, security badges, license compliance, SBOM, supply chain security, and vulnerability management per Hack23 Open Source Policy
-
florinsenoner Skill Convex AuditAudit Convex bandwidth and function call consumption, identify optimizations, and plan fixes
-
b-open-io-prompts Bundle SetupAudit which bOpen plugins, CLIs, env keys, third-party skills, agents, and hooks are installed across the harness, then emit a runtime-tailored instruction plan with optional user-triggered installation of selected dependencies. Use for "bopen setup", "setup ui", "harness install", "audit my setup", "install everything", or "unified installer". For a single hook, use hook-manager.
-
hack23 Skill Github Agentic WorkflowsGitHub Agentic Workflows (gh-aw) — markdown-defined AI automation with Copilot/Claude/Codex, safe outputs, 5-layer security, and Continuous AI patterns
-
hack23 Skill Vulnerability ManagementSystematic vulnerability lifecycle management with SLAs aligned with OWASP, NIST, and CIS Controls for Node.js/TypeScript
-
hack23 Skill Secure Development LifecycleComprehensive SDLC security practices with DevSecOps automation, OWASP Top 10, supply chain security (OSSF/SLSA)
-
joaquimscosta Bundle DiataxisAudit, classify, validate, and scaffold documentation using the Diataxis framework (Tutorials, How-to guides, Reference, Explanation). Use when user mentions "diataxis", "documentation framework", "quadrant", "doc audit", "doc coverage", "collapsed document", "tutorial vs how-to", "quadrant purity", "documentation types", or wants to classify docs by type.
-
joaquimscosta Bundle Dependabot ReviewReviews open Dependabot PRs, classifies by risk (patch/minor/major, security, lockfile-only), and merges safe ones or advises on what to do. Use when user mentions "dependabot", "dependabot PRs", "dependency updates", "merge dependabot", "review dependabot", "dependency PRs", "bump PRs", "update dependencies", or runs /dependabot-review command.
-
florinsenoner Skill Convex Security AuditDeep security review patterns for authorization logic, data access boundaries, action isolation, rate limiting, and protecting sensitive operations
-
florinsenoner Skill Security Best PracticesPerform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
-
packmindhub Skill Improve Claude MdAudit and improve the CLAUDE.md files listed in the run worklist: apply only high/medium priority fixes, create the ones that are missing, and delete instructions already fully covered by a repository skill. Driven non-interactively by a GitHub workflow (.github/workflows/weekly-claude-md-improver.yml owns the schedule and resolves the worklist, which differs per repository); not intended for interactive use.
-
packmindhub Skill Feature Flags AuditAudit and inventory all feature flags declared in the Packmind codebase. Use when the user asks to list, audit, review, or inventory feature flags, asks which flags are active, wants to know what a flag gates, or asks which flags are opened to a given domain/user. Produces a synthetic markdown table with each flag key, its audience, an inferred functional description, its active/orphan status, and its usage locations.
-
b-open-io-prompts Bundle ConfessProactive self-audit covering incomplete changes, untested assumptions, pattern violations, buried concerns, and cleanup debt. Invoke before ending a session, marking a task done, or saying "complete", and when the user asks "are you sure?", "did you miss anything?", "anything else?", or "audit your work". Do not wait to be asked.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include agile-v-adr, threat-modeler, authn-authz-relaxation. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.