Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
matrixx0070 Bundle Code ReviewReview code for bugs, security vulnerabilities, style problems, and improvement opportunities
0 -
matrixx0070 Bundle Nginx ConfigWrite nginx server blocks for reverse proxies, static sites, HTTPS termination, and security hardening
0 -
sgcarstrends Skill Code ReviewPerform automated code reviews checking for security vulnerabilities, performance issues, and code quality. Use before creating PRs, when reviewing complex changes, checking for security issues, or identifying performance problems.
-
b-open-io-prompts Bundle Codex SecurityRun OpenAI's agentic security scanner (`@openai/codex-security`) over a repo, PR, or diff, then triage, patch, and gate on its findings. Use for 'run a codex security scan', 'find vulnerabilities in this PR', 'export findings as SARIF', 'fix that security finding', 'compare this scan to the last one', or when a pattern sweep came back thin. Not for dependency CVEs, secrets, or licenses (code-audit-scripts, bun audit).
-
x-school-academy Skill Dev Swarm Code ReviewReview and audit code quality, architecture, and implementation. Verify code meets design specs, find bugs, identify improvements, and create change/bug/improve backlogs. Use when reviewing completed code, auditing implementations, or ensuring quality.
-
sgcarstrends Skill Survey Sdk AuditAudit PostHog survey SDK features and version requirements
-
sgcarstrends Skill Dependency UpgradeUpgrade dependencies safely using pnpm catalog, checking for breaking changes, and testing upgrades. Use when updating packages, applying security patches, upgrading major versions, resolving dependency conflicts, or modernizing tech stack.
-
b-open-io-prompts Bundle UI Audio ThemeGenerate, audit, edit, and wire cohesive UI sound themes through ElevenLabs and ffmpeg, with an interactive local picker for auditioning candidates. Use for "generate a UI sound theme", "create button click sounds", "design notification sounds", "make game menu sounds", "audit the sounds on my site", or "review UI audio wiring". Covers cuelume web delivery.
-
sgcarstrends Bundle Stripe Best PracticesGuides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial accounts, integration surfaces (Checkout, Payment Element), migrating from deprecated Stripe APIs, and security best practices (API key management, restricted keys, webhooks, OAuth). Use when building, modifying, or reviewing any Stripe integration — including accepting payments, building marketplaces, integrating Stripe, processing payments, setting up subscriptions, creating connected accounts, or implementing secure key handling.
-
jefflyt Skill Mandate 2 2 1 Code EvaluationEvaluate compliance for Mandate 2.2.1 (AI Supply Chain Security) using repository code and configuration analysis. Use when producing deterministic pass/fail findings with severity, mapped mitigated vulnerabilities, and file-level evidence.
-
b-open-io-prompts Bundle Code Audit ScriptsRun deterministic code security and quality scans — secret detection, debug artifact cleanup, and TODO/FIXME tracking. Use this skill before any security review, code audit, PR review, or when the user says 'scan for secrets', 'find debug logs', 'check for TODOs', 'audit this code', 'security scan', or 'clean up before shipping'. Also use proactively before deployments or when reviewing unfamiliar codebases. Runs all scans in parallel for speed.
-
b-open-io-prompts Bundle Hunter Skeptic RefereeThis skill should be used when the user asks to 'find bugs', 'do a thorough code review', 'run a security audit', 'hunt for bugs', 'check for correctness issues', or 'review this code for edge cases'. Orchestrates a three-phase adversarial review using three isolated agents — Jerry (Hunter), Kayle (Skeptic), Jason (Referee) — to neutralize sycophancy and produce high-fidelity bug reports. User-facing command: /bug-hunt
-
jefflyt Skill Mandate 2 3 3 Code EvaluationEvaluate compliance for Mandate 2.3.3 (Human Verification for Critical Actions) using repository code and configuration analysis. Use when producing deterministic pass/fail findings with severity, mapped mitigated vulnerabilities, and file-level evidence.
-
jefflyt Skill Mandate 2 3 5 Code EvaluationEvaluate compliance for Mandate 2.3.5 (Secure Input and Goal Management) using repository code and configuration analysis. Use when producing deterministic pass/fail findings with severity, mapped mitigated vulnerabilities, and file-level evidence.
-
jefflyt Skill Mandate 2 3 6 Code EvaluationEvaluate compliance for Mandate 2.3.6 (UI Transparency and Manifest Validation) using repository code and configuration analysis. Use when producing deterministic pass/fail findings with severity, mapped mitigated vulnerabilities, and file-level evidence.
-
jefflyt Skill Mandate 2 4 2 Code EvaluationEvaluate compliance for Mandate 2.4.2 (Secure Output Handling) using repository code and configuration analysis. Use when producing deterministic pass/fail findings with severity, mapped mitigated vulnerabilities, and file-level evidence.
-
jefflyt Skill Mandate 2 4 3 Code EvaluationEvaluate compliance for Mandate 2.4.3 (Prevention of Unintended Consequences) using repository code and configuration analysis. Use when producing deterministic pass/fail findings with severity, mapped mitigated vulnerabilities, and file-level evidence.
-
jefflyt Skill Mandate 2 4 5 Code EvaluationEvaluate compliance for Mandate 2.4.5 (Context Isolation and Memory TTL) using repository code and configuration analysis. Use when producing deterministic pass/fail findings with severity, mapped mitigated vulnerabilities, and file-level evidence.
-
jefflyt Skill Mandate 2 4 7 Code EvaluationEvaluate compliance for Mandate 2.4.7 (Restricted Execution and Function Banning) using repository code and configuration analysis. Use when producing deterministic pass/fail findings with severity, mapped mitigated vulnerabilities, and file-level evidence.
-
jefflyt Skill Mandate 2 1 1 Code Static EvalEvaluate static code indicators for Mandate 2.1.1 (Authorization and Access Control). Use when assessing partial code-evaluable controls and producing a confidence-scored static finding package before requesting runtime/process evidence.
-
jefflyt Skill Mandate 2 1 2 Code Static EvalEvaluate static code indicators for Mandate 2.1.2 (Secure Credential Management). Use when assessing partial code-evaluable controls and producing a confidence-scored static finding package before requesting runtime/process evidence.
-
jefflyt Skill Mandate 2 1 3 Code Static EvalEvaluate static code indicators for Mandate 2.1.3 (Segregation from Critical Systems). Use when assessing partial code-evaluable controls and producing a confidence-scored static finding package before requesting runtime/process evidence.
-
jefflyt Skill Mandate 2 1 4 Code Static EvalEvaluate static code indicators for Mandate 2.1.4 (Sensitive Data Handling in Training Data and System Prompts). Use when assessing partial code-evaluable controls and producing a confidence-scored static finding package before requesting runtime/process evidence.
-
jefflyt Skill Mandate 2 3 1 Code Static EvalEvaluate static code indicators for Mandate 2.3.1 (Comprehensive Logging and Auditing). Use when assessing partial code-evaluable controls and producing a confidence-scored static finding package before requesting runtime/process evidence.
-
jefflyt Skill Mandate 2 3 2 Code Static EvalEvaluate static code indicators for Mandate 2.3.2 (Anomaly Detection). Use when assessing partial code-evaluable controls and producing a confidence-scored static finding package before requesting runtime/process evidence.
-
jefflyt Skill Mandate 2 3 4 Code Static EvalEvaluate static code indicators for Mandate 2.3.4 (Mitigation of Misinformation and Hallucination). Use when assessing partial code-evaluable controls and producing a confidence-scored static finding package before requesting runtime/process evidence.
-
jefflyt Skill Mandate 2 3 7 Code Static EvalEvaluate static code indicators for Mandate 2.3.7 (UI/UX Behavioural Safeguards and Trust Calibration). Use when assessing partial code-evaluable controls and producing a confidence-scored static finding package before requesting runtime/process evidence.
-
jefflyt Skill Mandate 2 4 1 Code Static EvalEvaluate static code indicators for Mandate 2.4.1 (Resource Consumption Limits). Use when assessing partial code-evaluable controls and producing a confidence-scored static finding package before requesting runtime/process evidence.
-
jefflyt Skill Mandate 2 1 1 Runtime Evidence Intake GuideGather natural-language context and generate runtime/process evidence collection guidance for Mandate 2.1.1 (Authorization and Access Control), including concrete system command templates and artifact checklists for final compliance evaluation.
-
jefflyt Skill Mandate 2 1 2 Runtime Evidence Intake GuideGather natural-language context and generate runtime/process evidence collection guidance for Mandate 2.1.2 (Secure Credential Management), including concrete system command templates and artifact checklists for final compliance evaluation.
-
jefflyt Skill Mandate 2 1 3 Runtime Evidence Intake GuideGather natural-language context and generate runtime/process evidence collection guidance for Mandate 2.1.3 (Segregation from Critical Systems), including concrete system command templates and artifact checklists for final compliance evaluation.
-
jefflyt Skill Mandate 2 1 4 Runtime Evidence Intake GuideGather natural-language context and generate runtime/process evidence collection guidance for Mandate 2.1.4 (Sensitive Data Handling in Training Data and System Prompts), including concrete system command templates and artifact checklists for final compliance evaluation.
-
jefflyt Skill Mandate 2 2 3 Runtime Evidence Intake GuideCollect natural-language environment context and generate evidence collection guidance for Mandate 2.2.3 Secure Training and Fine-Tuning. Use when code is insufficient and operational proof is required for final compliance evaluation.
-
jefflyt Skill Mandate 2 3 1 Runtime Evidence Intake GuideGather natural-language context and generate runtime/process evidence collection guidance for Mandate 2.3.1 (Comprehensive Logging and Auditing), including concrete system command templates and artifact checklists for final compliance evaluation.
-
jefflyt Skill Mandate 2 3 2 Runtime Evidence Intake GuideGather natural-language context and generate runtime/process evidence collection guidance for Mandate 2.3.2 (Anomaly Detection), including concrete system command templates and artifact checklists for final compliance evaluation.
-
jefflyt Skill Mandate 2 3 4 Runtime Evidence Intake GuideGather natural-language context and generate runtime/process evidence collection guidance for Mandate 2.3.4 (Mitigation of Misinformation and Hallucination), including concrete system command templates and artifact checklists for final compliance evaluation.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include codex-security, ui-audio-theme, mandate-2-2-1-code-evaluation. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.