Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
bookforge-ai Bundle Strategic Commitment DesignerDesign credible strategic moves — commitments, threats, and promises — to change the game in your favor before play begins. Use this skill when a user needs to lock in a position and prevent backtracking; deter an adversary from an unwanted action; compel a counterpart to take a desired action; make a negotiation stance, policy, or business pledge actually believable; or structure incentive mechanisms that hold even when renegotiation is tempting. Triggers include: user wants to commit to a course of action in a way that others will believe; user is setting a credible deterrent threat (e.g., retaliation policy, penalty clause, price floor); user must compel action by a deadline and needs the right move type and deadline design; user suspects their threat or promise will be dismissed as a bluff; user needs to choose between issuing a threat vs. a promise for deterrence or compellence; user wants to practice brinkmanship and needs to calibrate the risk level; user is designing a contract or commitment mechanism
-
crestapps Bundle Orchardcore Users Admin List FiltersSkill for adding custom filters to the Orchard Core users admin list (Security → Users). Covers implementing IUsersAdminListFilterProvider to add searchable terms to the users admin search box, wiring named and default terms with OneCondition/ManyCondition against YesSql indexes over User, registering the provider in Startup, and documenting the new filter in the Available Filters dialog with a DisplayDriver<UserIndexOptions> Thumbnail card. Use this skill when requests mention custom users admin list filters, IUsersAdminListFilterProvider, QueryEngineBuilder<User>, WithNamedTerm, the users Filters dropdown or Filter syntax dialog, UserIndexOptions filter cards, UsersAdminFilters Thumbnail views, or closely related Orchard Core users admin list search work. Strong matches include OrchardCore.Users, IUsersAdminListFilterProvider, UserIndexOptions, and UsersAdminFilters-*.Thumbnail.cshtml.
-
bookforge-ai Skill Accusation Audit GeneratorGenerate a preemptive objection audit and emotion-label bank before any high-stakes negotiation, difficult conversation, salary discussion, sales pitch, or conflict resolution. Use this skill when you need to defuse anticipated resistance before speaking, prepare labels for counterpart objections before a job offer negotiation, neutralize defensive reactions before presenting bad news, write preemptive acknowledgments before a pitch to a skeptical audience, prepare for a difficult performance review or client escalation, anticipate accusations before a contract renegotiation, build a delivery script for labeling counterpart frustrations, or create an accusation audit for a negotiation one-sheet.
-
aradotso-trending-skills Skill Copyfail Go LpeGo implementation of CVE-2026-31431 (CopyFail), a Linux local privilege escalation exploit targeting the AF_ALG iov_iter kernel vulnerability affecting kernels v4.14–April 2026.
-
bookforge-ai Skill Negotiation One Sheet GeneratorBuild a complete Negotiation One Sheet — a five-section preparation document that covers your aspirational goal, a counterpart-validating situation summary, a preemptive accusation audit, a calibrated question bank, and a list of noncash offers — before any negotiation, sales conversation, contract discussion, salary negotiation, or difficult ask. Use when you need to prepare for a high-stakes conversation in a single document, when you want to stop improvising and start with a battle-tested preparation framework, when you keep leaving deals on the table by aiming at your bottom line instead of your aspirational target, when you need to combine emotional preparation with offer strategy into one coherent plan, or when you are coaching someone else through a complex negotiation. Also use before any negotiation where you have 20+ minutes to prepare and want to walk in with every major tool loaded: counterpart profile, labels, questions, offer sequence, and noncash options. Produces negotiation-one-sheet.md — a c
-
g1joshi Skill OktaOkta identity management. Use for enterprise SSO.
-
g1joshi Skill Auth0Auth0 identity platform. Use for authentication.
-
g1joshi Skill ClerkClerk authentication for modern apps. Use for user management.
-
g1joshi Skill OAUTHOAuth 2.0 authorization framework. Use for authorization.
-
g1joshi Skill TrivyTrivy container security scanner. Use for container security.
-
g1joshi Skill VaultHashiCorp Vault secrets management. Use for secrets.
-
g1joshi Skill Bcryptbcrypt password hashing. Use for password security.
-
oimiragieo Bundle Fix ReviewVerify fix commits address security findings without introducing new bugs or regressions. Analyzes diffs for anti-patterns like removed validation, weakened access control, reduced error handling, reordered external calls, and changed integer operations. Generates structured FIX_REVIEW_REPORT with finding status tracking.
0 -
g1joshi Skill CertbotCertbot Let's Encrypt certificates. Use for SSL/TLS.
-
oimiragieo Bundle API TestingAPI security testing and validation for REST/GraphQL/gRPC endpoints, contract testing, load testing, fuzzing, and Postman/Bruno/Hurl workflows
0 -
ariffazil Skill Agentic Loop8-step recursive self-improvement discipline for OPENCLAW. Detect drift, score outputs, propose forges, ratify, apply, audit. Closes the loop.
-
g1joshi Skill PassportPassport.js authentication middleware. Use for Node.js auth.
-
g1joshi Skill RenovateRenovate dependency updates. Use for automated updates.
-
ariffazil Bundle Forge Kimi CodeConfigure, audit, and align Kimi Code CLI as AAA warga FI-008 with arifOS kernel and A-FORGE stdio actuator.
-
g1joshi Skill BurpsuiteBurp Suite web security testing. Use for penetration testing.
-
g1joshi Skill Owasp ZapOWASP ZAP security testing proxy. Use for security testing.
-
g1joshi Skill SonarqubeSonarQube code quality and security. Use for code analysis.
-
g1joshi Skill DependabotDependabot dependency updates. Use for security updates.
-
ariffazil Bundle Agi Dream EngineExtend the arifOS dream-engine so every AAA warga (333-AGI, 555-ASI, 888-APEX, A-AUDIT, A-ARCHIVE), OpenCode, and OpenClaw can autonomously consolidate memory without violating F1-F13.
-
ariffazil Bundle Forge CI DiagnoseParse failing GitHub Actions logs, identify root cause patterns, and propose fixes without executing irreversible changes. Use this skill whenever a federation repo shows a red CI status, a workflow fails, or a build/test/lint gate breaks. This skill reads logs, classifies failure modes, and outputs a diagnostic report — it does not re-run CI, edit workflows, or dismiss security findings without sovereign approval.
-
g1joshi Skill Openid ConnectOpenID Connect identity layer. Use for SSO.
-
g1joshi Skill Event SourcingEvent sourcing event-based persistence. Use for audit trails.
-
ariffazil Bundle Forge Symlink AuditFederation-wide broken symlink scanner. Scans /root for broken symlinks, categorizes by location, and reports with safe-delete recommendations. USE WHEN: "check symlinks", "broken links", "symlink debt", "find broken symlinks", or during entropy sweeps.
-
ariffazil Bundle Forge Secret HygieneAudit env.local, SOPS .env, and config files for plaintext secret leaks, key age, missing rotation dates, and overlong-lived credentials. USE WHEN: "secret audit", "key age", "rotate secrets", "credential hygiene", "API key check", "env audit", "secret leak scan".
-
ariffazil Bundle Forge Telegram AuditAutomated TREE777 security checks for Telegram bot tokens, webhook isolation, bot permission scope, and A2A bridge security. v1.1.0: organ paths from registry, ports from live probes. USE WHEN: "telegram audit", "bot security", "webhook check", "token isolation", "TREE777 check", "telegram permissions".
-
ariffazil Bundle Audit SealUse when sealing audit decisions or recording constitutional events. Every decision logged. Irreversible decisions sealed. ΔS ≤ 0 on every output. Receipts > narratives.
-
oimiragieo Bundle Electron ProExpert Electron desktop application development — main/renderer process architecture, IPC communication, native OS APIs (menus, tray, notifications, dialogs), auto-updates, code signing, packaging with electron-builder/forge, security hardening (contextIsolation, sandbox), and performance optimization. Use for building cross-platform desktop apps.
0 -
ariffazil Bundle Forge Vault999 WitnessVAULT999 witness — immutable ledger integration, seal chain verification, and audit trace.
-
boshi-xixixi Bundle Security Specialist应用安全专家,专注于认证授权、数据保护和合规性审计。当用户需要:(1) 设计安全的登录认证系统 (2) 进行安全代码审查 (3) 检查 GDPR/隐私合规 (4) 防范常见安全漏洞 (OWASP Top 10) (5) 确保无障碍设计安全使用时使用此 Skill。
-
ariffazil Bundle Arifos External CouncilExternal constitutional audit and bounded forge planning for arifOS federation organs. Detects drift, challenges architecture claims, and prepares contracts.
-
ariffazil Bundle Forge Cross Repo Doc ZenAudit and reconcile documentation across federation repositories, preserving canonical signals while removing stale references and graph fragmentation. v2026.08.06: organ topology from registry, no hardcoded /root/<REPO> paths.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include accusation-audit-generator, api-testing, strategic-commitment-designer. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.