Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
bookforge-ai Bundle Learning Practice AuditorAudit any set of study habits, training program, or course design for ineffective learning practices and replace them with evidence-based alternatives. Use this skill when someone wants a study habits audit, suspects they are making learning mistakes, reports that their studying is not working, relies on rereading, highlighting, or cramming, wonders whether their training design actually produces learning, or asks "what am I doing wrong?" Also triggers on: ineffective studying complaints, rereading concerns, learning styles assumptions, cramming before an exam, blocked practice schedules, highlighting as primary review method, "I study for hours but nothing sticks," or any study strategy review. Works for individual learners, teachers, corporate trainers, instructional designers, and coaches. Detects five named anti-patterns — rereading trap, massed practice delusion, illusions of knowing cluster, learning styles myth, errorless learning myth — with mechanism explanations, severity ratings, and direct routing
-
bookforge-ai Bundle Learning Calibration AuditDiagnose and correct false confidence in learning mastery using cognitive science research. Use when you feel confident about a topic but keep failing tests, want to audit your metacognition for illusions of knowing, are preparing for a high-stakes assessment and need to verify actual mastery, or suspect your study method is producing Dunning-Kruger overconfidence. Also use for: identifying which of 7 specific cognitive distortions — fluency illusion, hindsight bias, Dunning-Kruger overconfidence, curse of knowledge, false consensus, imagination inflation, social memory contamination — is inflating your self-assessment accuracy; distinguishing reliable mastery indicators (delayed recall, novel problem transfer, peer explanation) from unreliable ones (rereading fluency, immediate recall, familiarity warmth); selecting calibration instruments (self-quizzing, cumulative quizzing, peer instruction) matched to the specific distortions detected; designing a dynamic testing cycle (assess → identify gaps → target pra
-
bookforge-ai Bundle Curse Of Knowledge DetectorDiagnose a draft for the Curse of Knowledge — the expert blind spot that makes insiders write copy full of unexplained jargon, buried assumptions, strategy-level abstractions, and tacit shared context that lose non-expert audiences. Use this skill whenever reviewing a pitch, announcement, explainer, landing page, onboarding doc, slide, internal memo, or technical write-up for clarity to a non-expert. Activate when the user says things like "why isn't my message landing", "make this clearer", "my audience doesn't get it", "I can't tell if this is too technical", "diagnose this draft", "is this too jargony", "expert blind spot", "tapper listener", "translate for non-experts", "audit this for jargon", "I'm too close to this", or provides a draft plus an audience description and asks for a clarity critique. Also triggers when a user complains that smart readers stare blankly at their copy, when an explainer is full of acronyms, when an announcement leads with context instead of news, or when a strategy deck reads
-
bookforge-ai Bundle Source IncorporatorIncorporate quoted, paraphrased, and summarized sources into research writing by applying a 3-branch selection decision tree, 3 integration methods for quotations, and a 5-mechanism inadvertent plagiarism prevention checklist. Use this skill when drafting or revising a paper that uses sources and you need to decide whether to quote, paraphrase, or summarize a passage; when you need to weave quotations into your prose grammatically and meaningfully; when you need to make explicit to readers why evidence is relevant; when you must choose a citation style; or when you want to audit a draft for the five most common forms of inadvertent plagiarism before submitting.
-
crestapps Skill Orchardcore Reverse ProxySkill for configuring reverse proxy support in Orchard Core. Covers forwarded headers middleware (X-Forwarded-For, X-Forwarded-Proto, X-Forwarded-Host), configuration sources (admin UI vs file-based), security considerations for trusted proxies, and multi-tenancy forwarding. Use this skill when requests mention Orchard Core Reverse Proxy, Configure Reverse Proxy Support, Enabling the Reverse Proxy Feature, Configuration Options, Admin UI Configuration (Scenario 1), File-Based Configuration (Scenario 2), or closely related Orchard Core implementation, setup, extension, or troubleshooting work. Strong matches include work with OrchardCore.ReverseProxy, ConfigureReverseProxySettings, OrchardCoreBuilder, CreateBuilder, appsettings.json. It also helps with Admin UI Configuration (Scenario 1), File-Based Configuration (Scenario 2), Partial Override Configuration (Scenario 3), plus the code patterns, admin flows, recipe steps, and referenced examples captured in this skill.
-
bookforge-ai Bundle Desirable Difficulty ClassifierClassify any learning activity, practice structure, or instructional design element as a desirable difficulty (strengthens encoding) or undesirable difficulty (creates friction without learning benefit). Use this skill when an instructional designer, trainer, teacher, or learner wants to audit a course design, training session, study method, or practice regimen for evidence-based difficulty management — even if they don't use the phrase "desirable difficulty." Applies to onboarding programs, corporate training, academic course design, self-study plans, coaching sessions, and skill development programs. Identifies which of six proven difficulty strategies are present or absent (spacing, interleaving, variation, retrieval, generation, elaboration) and generates specific redesign recommendations. Do NOT use this skill to build a full study schedule (use retrieval-practice-study-system), to assess learner readiness or aptitude, or to evaluate content quality unrelated to difficulty structure.
-
bookforge-ai Bundle Conversation Data Quality AnalyzerAnalyze customer conversation notes or transcripts after a meeting to classify every statement as fact, compliment, fluff, or idea — separating real signal from noise. Use this skill whenever the user wants to review interview notes, check whether a customer call produced reliable data, figure out if enthusiastic feedback was genuine interest or polite lies, identify bad data patterns in a transcript, audit whether a conversation that "went great" actually produced usable facts, or suspects they are collecting compliments instead of validated evidence — even if they don't mention "data quality" or "bad data." Do NOT use this skill to write or improve questions before a conversation (use conversation-question-designer) or to evaluate whether a meeting produced real commitment signals like time, reputation, or money (use commitment-signal-evaluator).
-
crestapps Bundle Orchardcore Permission ProvidersSkill for implementing Orchard Core permission providers. Covers the PermissionProvider pattern, default stereotypes, OrchardCoreConstants role names, and where to place reusable static permission instances and reusable content-part models. Use this skill when requests mention Orchard Core Permission Providers, Create a Permission Provider, Recommended Project Placement, Static Permission Definitions in a Core Project, PermissionProvider Class, Registering the Provider, or closely related Orchard Core implementation, setup, extension, or troubleshooting work. Strong matches include work with CrestApps.Sports.Teams.Core, OrchardCore.Security.Permissions, CrestApps.Sports.Teams.Core.Permissions, CrestApps.Sports.Teams, OrchardCore.Modules. It also helps with permission provider examples, PermissionProvider Class, Registering the Provider, Content Part Placement Guidance, plus the code patterns, admin flows, recipe steps, and referenced examples captured in this skill.
-
bookforge-ai Bundle Strategic Commitment DesignerDesign credible strategic moves — commitments, threats, and promises — to change the game in your favor before play begins. Use this skill when a user needs to lock in a position and prevent backtracking; deter an adversary from an unwanted action; compel a counterpart to take a desired action; make a negotiation stance, policy, or business pledge actually believable; or structure incentive mechanisms that hold even when renegotiation is tempting. Triggers include: user wants to commit to a course of action in a way that others will believe; user is setting a credible deterrent threat (e.g., retaliation policy, penalty clause, price floor); user must compel action by a deadline and needs the right move type and deadline design; user suspects their threat or promise will be dismissed as a bluff; user needs to choose between issuing a threat vs. a promise for deterrence or compellence; user wants to practice brinkmanship and needs to calibrate the risk level; user is designing a contract or commitment mechanism
-
crestapps Bundle Orchardcore Users Admin List FiltersSkill for adding custom filters to the Orchard Core users admin list (Security → Users). Covers implementing IUsersAdminListFilterProvider to add searchable terms to the users admin search box, wiring named and default terms with OneCondition/ManyCondition against YesSql indexes over User, registering the provider in Startup, and documenting the new filter in the Available Filters dialog with a DisplayDriver<UserIndexOptions> Thumbnail card. Use this skill when requests mention custom users admin list filters, IUsersAdminListFilterProvider, QueryEngineBuilder<User>, WithNamedTerm, the users Filters dropdown or Filter syntax dialog, UserIndexOptions filter cards, UsersAdminFilters Thumbnail views, or closely related Orchard Core users admin list search work. Strong matches include OrchardCore.Users, IUsersAdminListFilterProvider, UserIndexOptions, and UsersAdminFilters-*.Thumbnail.cshtml.
-
bookforge-ai Skill Accusation Audit GeneratorGenerate a preemptive objection audit and emotion-label bank before any high-stakes negotiation, difficult conversation, salary discussion, sales pitch, or conflict resolution. Use this skill when you need to defuse anticipated resistance before speaking, prepare labels for counterpart objections before a job offer negotiation, neutralize defensive reactions before presenting bad news, write preemptive acknowledgments before a pitch to a skeptical audience, prepare for a difficult performance review or client escalation, anticipate accusations before a contract renegotiation, build a delivery script for labeling counterpart frustrations, or create an accusation audit for a negotiation one-sheet.
-
aradotso-trending-skills Skill Copyfail Go LpeGo implementation of CVE-2026-31431 (CopyFail), a Linux local privilege escalation exploit targeting the AF_ALG iov_iter kernel vulnerability affecting kernels v4.14–April 2026.
-
bookforge-ai Skill Negotiation One Sheet GeneratorBuild a complete Negotiation One Sheet — a five-section preparation document that covers your aspirational goal, a counterpart-validating situation summary, a preemptive accusation audit, a calibrated question bank, and a list of noncash offers — before any negotiation, sales conversation, contract discussion, salary negotiation, or difficult ask. Use when you need to prepare for a high-stakes conversation in a single document, when you want to stop improvising and start with a battle-tested preparation framework, when you keep leaving deals on the table by aiming at your bottom line instead of your aspirational target, when you need to combine emotional preparation with offer strategy into one coherent plan, or when you are coaching someone else through a complex negotiation. Also use before any negotiation where you have 20+ minutes to prepare and want to walk in with every major tool loaded: counterpart profile, labels, questions, offer sequence, and noncash options. Produces negotiation-one-sheet.md — a c
-
g1joshi Skill OktaOkta identity management. Use for enterprise SSO.
-
g1joshi Skill Auth0Auth0 identity platform. Use for authentication.
-
g1joshi Skill ClerkClerk authentication for modern apps. Use for user management.
-
g1joshi Skill OAUTHOAuth 2.0 authorization framework. Use for authorization.
-
g1joshi Skill TrivyTrivy container security scanner. Use for container security.
-
g1joshi Skill VaultHashiCorp Vault secrets management. Use for secrets.
-
g1joshi Skill Bcryptbcrypt password hashing. Use for password security.
-
oimiragieo Bundle Fix ReviewVerify fix commits address security findings without introducing new bugs or regressions. Analyzes diffs for anti-patterns like removed validation, weakened access control, reduced error handling, reordered external calls, and changed integer operations. Generates structured FIX_REVIEW_REPORT with finding status tracking.
0 -
g1joshi Skill CertbotCertbot Let's Encrypt certificates. Use for SSL/TLS.
-
oimiragieo Bundle API TestingAPI security testing and validation for REST/GraphQL/gRPC endpoints, contract testing, load testing, fuzzing, and Postman/Bruno/Hurl workflows
0 -
ariffazil Skill Agentic Loop8-step recursive self-improvement discipline for OPENCLAW. Detect drift, score outputs, propose forges, ratify, apply, audit. Closes the loop.
-
g1joshi Skill PassportPassport.js authentication middleware. Use for Node.js auth.
-
g1joshi Skill RenovateRenovate dependency updates. Use for automated updates.
-
ariffazil Bundle Forge Kimi CodeConfigure, audit, and align Kimi Code CLI as AAA warga FI-008 with arifOS kernel and A-FORGE stdio actuator.
-
g1joshi Skill BurpsuiteBurp Suite web security testing. Use for penetration testing.
-
g1joshi Skill Owasp ZapOWASP ZAP security testing proxy. Use for security testing.
-
g1joshi Skill SonarqubeSonarQube code quality and security. Use for code analysis.
-
g1joshi Skill DependabotDependabot dependency updates. Use for security updates.
-
ariffazil Bundle Agi Dream EngineExtend the arifOS dream-engine so every AAA warga (333-AGI, 555-ASI, 888-APEX, A-AUDIT, A-ARCHIVE), OpenCode, and OpenClaw can autonomously consolidate memory without violating F1-F13.
-
ariffazil Bundle Forge CI DiagnoseParse failing GitHub Actions logs, identify root cause patterns, and propose fixes without executing irreversible changes. Use this skill whenever a federation repo shows a red CI status, a workflow fails, or a build/test/lint gate breaks. This skill reads logs, classifies failure modes, and outputs a diagnostic report — it does not re-run CI, edit workflows, or dismiss security findings without sovereign approval.
-
g1joshi Skill Openid ConnectOpenID Connect identity layer. Use for SSO.
-
g1joshi Skill Event SourcingEvent sourcing event-based persistence. Use for audit trails.
-
ariffazil Bundle Forge Symlink AuditFederation-wide broken symlink scanner. Scans /root for broken symlinks, categorizes by location, and reports with safe-delete recommendations. USE WHEN: "check symlinks", "broken links", "symlink debt", "find broken symlinks", or during entropy sweeps.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include accusation-audit-generator, api-testing, learning-practice-auditor. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.