Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
retlehs Bundle Gh ActionsGitHub Actions best practices — current action versions, caching, security, and common patterns. Activate when writing or modifying GitHub Actions workflows.
-
rastian Bundle Behavioral DesignApplies behavioral psychology and behavioral economics to product and UX design. Use when a designer, PM, researcher, or design manager wants to diagnose why users aren't completing a flow, adopting a feature, or changing behavior; design nudges or behavior-change interventions; reduce friction or cognitive load; run a behavioral design workshop or sprint; audit a design for psychological effectiveness; or apply principles like loss aversion, social proof, choice architecture, habit formation, or implementation intentions. Also triggers for: onboarding drop-off, feature adoption, engagement design, conversion optimization, design psychology, behavioral economics, mental models, or behavior change strategy. Guides users through behavioral diagnosis, barrier identification, and intervention design - with ethics review built into every output.
-
rahozosman Bundle Security Architecture IntelligenceAnalyzes codebases for security design flaws, threat modeling gaps: attack surface, auth boundaries, and data flow risks.
-
reversepoco Skill Security ReviewComprehensive security audit. Use when reviewing code for vulnerabilities, before deployments, or when the user mentions security.
-
ray0907 Bundle Security ScanUse when a user asks to scan a repository for dependency vulnerabilities, insecure code patterns, CVEs, or OWASP Top 10 risks.
-
rcarmo Bundle Go AI Upstream SyncSync go-ai with upstream @earendil-works/pi-ai changes — audit upstream version deltas, regenerate models, port API/type/provider changes, update docs, and validate parity.
-
robertsilen Bundle Mariadb AI DbaMariaDB AI DBA — connects to a MariaDB database and produces a factual server inventory covering configuration, schema, performance counters, security, and MariaDB-specific features. Use when the user asks to analyze, audit, health-check, or inventory a MariaDB or MySQL database, or asks for database performance advice with a live server available.
-
rubyroidlabs Bundle Rails Audit SkillPerform comprehensive technical reviews of Ruby on Rails applications. Runs automated analysis tools (RubyCritic, Brakeman, bundler-audit, Gitleaks, Debride, linters, SimpleCov, Rails stats, Rails ERD), analyzes code for architecture, security, authorization (Pundit/CanCanCan), dead code, and design issues, and produces a structured markdown report with prioritized findings and a 0-10 score. Use when the user requests a tech review, code audit, project assessment, or quality analysis of a Rails application.
-
ruoji6 Bundle Audit Skills当用户要求审计 Java、.NET 或 PHP 源码/部署产物/反编译产物/安全发现,并需要默认脚本输出目录、报告输出目录、Java/.NET 反编译与反混淆参考、Java 组件 YAML 正则匹配扫描、确认漏洞判定标准、安全 Payload 和 BurpSuite 原始 HTTP 请求包证据时使用。仅用于授权代码审计和防御性安全验证。
-
robonuggets Skill Doctor PlusRuns Claude Code's built-in /doctor health check, then audits the workspace against the 6 then-and-now context-engineering shifts Anthropic shipped with the Claude 5 models (rules to judgement, examples to interfaces, upfront to progressive disclosure, repeats to tool descriptions, CLAUDE.md memory to auto-memory, simple specs to rich references). Reports findings first, fixes only on approval. Triggers on "/doctor-plus", "doctor plus", "doctor-plus", "extended doctor", "then and now audit", "context checkup".
-
rwshiraishi Bundle App BlueprintPrepare a product build package with requirements, architecture, design, security, tests, and sequenced implementation goals. Use when the user requests a new-product specification, build preparation, or a substantial rewrite plan. Scale to Sketch, Standard, or Full; do not replace a request to implement an existing specification with a new planning exercise.
-
ryjoxtechnologies Skill Octopoda MemoryPersistent memory across sessions — recall, store, share, audit decisions, snapshots, and version history
-
ronantakizawa Bundle Open Source ContributionGuides developers through open source contributions including finding projects, writing PRs, conventional commits, and communicating with maintainers. Covers enterprise standards (Linux Kernel, Apache) and security disclosure. Use when contributing to GitHub/GitLab projects, writing commit messages, responding to code review, or reporting vulnerabilities.
-
sablier-labs Bundle SolanaThis skill should be used when the user asks to "build a Solana program", "write Anchor code", "create a PDA", "work with SPL tokens", "test with anchor-bankrun", "fuzz test with Trident", "secure my Solana program", "create an NFT with MPL Core", "optimize compute units", or mentions Anchor constraints, account validation, CPI patterns, Vitest testing, or Solana security auditing.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include gh-actions, behavioral-design, security-architecture-intelligence. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.