Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
simplefarmer69 Skill Clawhub Skill ScannerSecurity gatekeeper for skill installations. MANDATORY before installing any skill from ClawHub, GitHub, or external sources. Performs deep code analysis to detect malicious patterns, credential access, data exfiltration, command injection, and other security risks. Triggers: "install skill", "clawhub install", "new skill", "add skill", "skill from". Always run this BEFORE installation.
-
simplefarmer69 Skill Domain Authority AuditorUse when the user asks to "audit domain authority", "domain trust score", "CITE audit", "how authoritative is my site", "domain credibility check", "is my domain trustworthy", or "domain credibility score". Runs a full CITE 40-item domain authority audit, scoring domains across 4 dimensions with weighted scoring by domain type. Produces a detailed report with per-item scores, dimension analysis, veto checks, and a prioritized action plan. For content-level assessment, see content-quality-auditor. For link profile details, see backlink-analyzer.
-
openshift-eng Skill Openshift Tls ProfileUse this skill to implement TLS security profiles for operators and workloads on OpenShift. Provides guidance on reading TLS config from APIServer CR and applying it to webhook/metrics servers, HTTP, and gRPC endpoints.
-
rudironsoni Skill Dotnet API SecuritySecures ASP.NET Core APIs. Identity, OAuth/OIDC, JWT bearer, passkeys, CORS, rate limiting.
-
bjornmelin Bundle Rust ExpertCore Rust engineering. Use for implementation, debugging, review, compiler errors, ownership and lifetimes, traits and generics, async and concurrency, typed errors, Cargo and MSRV, crate choice, tests, performance, unsafe and security. Excludes focused product surfaces owned by narrower Rust skills.
-
rudironsoni Bundle Dotnet Security OwaspHardens .NET apps per OWASP Top 10 -- injection, auth, XSS, deprecated security APIs.
-
bjornmelin Bundle Convex AuditAudit Convex—schema, security, runtime edges, migrations, function risk. Triggers—review, contract, remediate. Not greenfield spec (convex-feature-spec).
-
bjornmelin Bundle Rust Mega EngExplicit-only Rust architecture orchestrator. Use only when the user explicitly invokes rust-mega-eng for broad Rust ecosystem architecture, multi-crate workspace strategy, large refactors, release engineering, crate selection portfolios, or end-to-end Rust product planning across CLI, TUI, Tauri, services, libraries, CI, security, and distribution.
-
bjornmelin Bundle Repo ModernizerRepo/monorepo modernization: dependency upgrades, security fixes, deprecation cleanup, framework migrations, dependency-native refactors, and verified hard-cut simplification.
-
bjornmelin Bundle Bun AuditShared Bun audit/remediation router. Use when auditing a repo for Bun-first correctness, explaining findings, listing rules, planning safe fixes, applying low-risk remediations, or validating Bun-related changes.
-
manastalukdar Skill Owasp CheckOWASP Top 10 vulnerability scanning and remediation
-
manastalukdar Skill Devex ReviewAudit the developer experience of your project — setup friction, onboarding clarity, local dev loop speed, tooling consistency, and documentation gaps. Produces a DX scorecard and prioritized improvement list. Inspired by gstack's devex-review skill.
-
manastalukdar Skill Legacy AuditMap modernization opportunities in a legacy codebase — identify unsupported dependencies, architecture seams, and migration paths using strangler fig, adapter, and parallel-run patterns
-
bjornmelin Bundle Notebook Ml ArchitectExpert guidance for auditing, refactoring, and designing machine learning Jupyter notebooks with production-quality patterns. Use when: (1) Analyzing notebook structure and identifying anti-patterns, (2) Detecting data leakage and reproducibility issues, (3) Refactoring messy notebooks into modular pipelines, (4) Generating templates for ML workflows (EDA, classification, experiments), (5) Adding reproducibility instrumentation (seeding, logging, env capture), (6) Converting notebooks to Python scripts, (7) Generating experiment summary reports. Triggers on: ML notebook, Jupyter audit, notebook refactor, data leakage, experiment template, ipynb best practices, notebook to script, reproducibility.
-
manastalukdar Skill Security ScanComprehensive security analysis with vulnerability detection and remediation tracking
-
bjornmelin Bundle Opensrc Inspectopensrc CLI—dep + upstream source. Triggers—impl beyond docs/types, version compare, upgrade diff audit, prewarm w/ `opensrc fetch` then `opensrc path`. Not general web or release-note-only.
-
manastalukdar Skill Dependency AuditComprehensive dependency security and license audit
-
manastalukdar Skill Security HeadersWeb security headers validation and configuration generation
-
bjornmelin Bundle Native ValidationUse this skill for Validation for native motion changes: Expo Doctor, expo install --check, EAS/development build risk, Jest/Reanimated setup, RN tests, platform smoke, and audit report closeout. Trigger on Expo Doctor, expo install --check, EAS build validation, native motion validation, Reanimated Jest, development build proof. Do not use for near-miss tasks outside these boundaries; route to adjacent motion or platform skills when they own the implementation.
-
zocomputer Bundle Clarion Portfolio MonitorFetch live portfolio positions, balances, and daily transactions from TastyTrade. Outputs a structured JSON snapshot and a human-readable summary to ~/clarion/portfolio/. Use when the user asks for portfolio status, net liquidation value (NLV), position P/L, daily fills, or needs current holdings for the investor letter or thesis monitoring. Requires TastyTrade OAuth credentials (client secret + refresh token) stored as Zo secrets.
-
happy-technologies-llc Skill UI ActionsComplete guide to UI Action development including form buttons, list buttons, context menu actions, client-side and server-side scripts, conditions, security, and common patterns
-
happy-technologies-llc Skill Code ReviewReview ServiceNow code for security vulnerabilities, performance issues, and platform best practices
-
happy-technologies-llc Skill Issue SummarizationSummarize GRC issues with context including related risks, controls, compliance gaps, and business impact to generate executive-ready summaries for audit committees
-
happy-technologies-llc Skill Metrics AnalysisAnalyze security operations metrics including MTTD, MTTR, incident volume trends, false positive rates, and analyst workload distribution
-
happy-technologies-llc Skill Acl ManagementComplete access control list management - understanding ACL structure, creating/modifying ACLs, troubleshooting permission issues, and debugging techniques
-
happy-technologies-llc Skill Audit ComplianceComprehensive audit trail analysis, user activity tracking, compliance reporting, and anomaly detection for ServiceNow environments
-
happy-technologies-llc Skill Incident ResponseSecurity incident detection, containment, and response procedures for ServiceNow environments
-
happy-technologies-llc Skill Correlation InsightsCorrelate security incidents with related events, vulnerabilities, and threat intelligence to identify attack patterns and common indicators
-
happy-technologies-llc Skill Secops Incident SummarizationGenerate executive and technical summaries for security incidents including threat classification, affected assets, containment status, and recommended actions
-
happy-technologies-llc Skill Post Incident AnalysisConduct post-incident review for closed security incidents including timeline reconstruction, detection/response gap analysis, and lessons-learned documentation
-
happy-technologies-llc Skill Government Case SummarizationSummarize government and public sector cases with regulatory compliance context, service eligibility tracking, inter-agency coordination, and audit trail documentation
-
happy-technologies-llc Skill Security Recommended ActionsGenerate recommended actions for security incidents based on threat type, severity, affected assets, and playbook alignment. Include containment, eradication, and recovery steps
-
aradotso-security-skills Skill Skill File SecurityBattle-tested security checks for AI coding assistants — 29 categories covering OWASP Top 10, CWE Top 25, and ASVS Level 3
-
aradotso-security-skills Skill Openai Codex SecurityOpenAI Codex Security CLI and SDK for AI-powered vulnerability scanning, validation, and automated security fixes in codebases
-
aradotso-security-skills Skill API Security ChecklistComprehensive API security checklist and best practices for designing, testing, and securing REST, GraphQL, and OAuth APIs
-
aradotso-security-skills Skill Skill Security ScannerClaude Skills security scanning tool that detects malicious code, network requests, file access, and command injection risks before installation
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include rust-expert, convex-audit, rust-mega-eng. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.