Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
lev-os Skill Invention Assignment AgreementDrafts a U.S. Confidentiality and Invention Assignment Agreement (CIAA/PIIA) for employee or contractor onboarding. Covers confidential information, DTSA immunity notices, state-specific invention assignment carve-outs (CA, DE, IL, KS, MN, NC, UT, WA), present-tense IP assignment, work-made-for-hire, restrictive covenants, and prior invention disclosure. Use when drafting IP assignment agreements, onboarding employees or contractors, or protecting trade secrets in employment contexts. Trigger keywords: CIAA, PIIA, invention assignment, confidentiality agreement, IP assignment, trade secret, non-compete, non-solicitation, work made for hire, employee onboarding IP.
-
lev-os Skill Managing Clinical Data QualityStructures data quality management with query resolution, source data verification, and audit trails. Use when managing clinical data quality, resolving data queries, or conducting SDV.
-
lev-os Skill Audit Compensation Committee CharterDrafts a combined Audit and Compensation Committee charter for U.S. boards, tailored for public or private companies with listing-standard compliance, independence criteria, and SOX readiness. Triggers when the user needs a board committee charter, audit committee charter, compensation committee charter, or governance mandate for SEC/NYSE/NASDAQ compliance.
-
lev-os Skill Conducting Fulcrum Security AnalysisIdentifies fulcrum securities in distressed capital structures with enterprise value allocation and recovery sensitivity analysis. Use when analyzing fulcrum securities, estimating recovery ranges, or determining value breaks.
-
lev-os Skill Field Of Use Restriction ClauseDrafts enforceable Field of Use restriction clauses for U.S. IP licensing agreements (patent, software, trade secret, know-how). Covers permitted and restricted applications, sublicense limits, derivative-use treatment, audit and compliance mechanics, and remedy framework. Use when narrowing licensee exploitation rights, setting enforcement triggers, or preserving licensor rights outside scope during negotiation or formation. Triggers: field of use, permitted use, restricted use, sublicensing, derivative works, audit rights, IP licence scope, patent software licensing.
-
lev-os Skill Invasive Testing Consent LetterDrafts a Phase II invasive testing consent letter that limits scope, locations, timing, data control, restoration, security, and risk allocation under an existing access, due diligence, or purchase and sale agreement. Use this skill when a counterparty requests soil borings, test pits, groundwater wells, soil vapor sampling, or other intrusive ESA activities. Trigger on keywords including "Phase II," "invasive testing," "environmental site assessment," "ESA," "borings," "test pits," "monitoring wells," "restoration bond," "PLL insurance," "access agreement," "consent letter," "IDW handling," or "environmental due diligence." Even if the user just says "they want to do borings on the site" or "draft consent for Phase II," use this skill.
-
lev-os Skill Managing Fund Audit PreparationStructures fund audit preparation with financial statement drafting, confirmation management, and workpaper organization. Use when preparing for fund audits, drafting fund financials, or managing audit confirmations.
-
lev-os Skill Managing Investor Compliance RequestsCoordinates regulatory and compliance information requests from institutional LPs including FOIA, regulatory filings, and audit support. Use when responding to compliance requests, managing FOIA inquiries, or supporting LP audit processes.
-
lev-os Skill Evaluating Spin Off Investment OpportunitiesAssesses spin-off equity with forced selling dynamics, orphaned security identification, and standalone valuation analysis. Use when evaluating spin-off investments, identifying forced-sell situations, or analyzing newly public entities.
-
boisenoise Skill Ln 630 Test AuditorUse when auditing the test surface through the evaluation platform with mandatory research, coordinated test audit workers, and structured summaries.
-
boisenoise Skill Ln 634 Test Coverage AuditorIdentifies missing tests for critical paths (money, security, data integrity, core flows). Use when auditing test coverage gaps.
-
boisenoise Skill Ln 632 Test E2e Priority AuditorValidates E2E coverage for critical paths (money, security, data integrity). Risk-based prioritization. Use when auditing E2E test coverage.
-
1999azzar Bundle Code ReviewerReview local code changes, commits, Git ranges, branches, or GitHub pull requests. Use when asked for a code review, PR review, security review, regression check, or approval decision.
-
mxyhi Bundle App Server Events SyncMaintain AgentMonitor and Codex app-server protocol parity. Use when asked to audit supported or missing app-server notifications/requests, trace event routing, diagnose schema drift in app-server payloads, or update docs/app-server-events.md after upstream Codex changes.
-
nandofalcao Bundle Expo App Store Guideline CheckPre-submission checklist for iOS App Store and Google Play Store. Use this skill whenever the user mentions: app store submission, app store rejection, pre-submission checklist, app review, store guidelines, privacy manifest, data safety section, app permissions, usage descriptions, privacy policy, LGPD, GDPR, data protection, mobile app security check, or any mention of preparing an app for publication in iOS or Android stores. Also trigger when the user asks about app permissions, data collection, or privacy requirements for mobile apps.
-
nateherkai Bundle Human SpeakEdit, audit, or draft writing to remove recognizable AI phrasing and structural habits while preserving the writer's meaning and personal voice. Use when the user asks to humanize writing, remove AI slop, make copy sound natural, audit a draft for AI patterns, or invokes human-speak.
-
nckugese Skill Aspen Error TroubleshootingUse this skill when an Aspen Plus simulation run returns errors or warnings (e.g. `run_simulation` reports failure, non-convergence, block status ≠ 0, or messages like "COLUMN DRIES UP", "COLUMN NOT IN MASS BALANCE", "AE_UNDERSPEC"). Covers the full diagnosis → fix → record → share workflow, including diagnostic paths, privacy rules for local logging, security rules for community-sourced suggestions, and the `share_error` tool contract.
-
ndisisnd Bundle MkpubGenerates and updates a repository's four public-facing docs — README.md, LICENSE.md, SECURITY.md, and llms.txt — from a scan of the repo itself. The README uses a figlet-rendered centered header and badgen badges. Use when the user says "write a README", "generate docs for this repo", "add a license", "add a security policy", "add llms.txt", "/mkpub", or asks to document a repository or skill for release.
-
neplextech Bundle DocumentationStudy a software repository in bounded chunks and produce verified Markdown documentation for engineering onboarding, QA, architecture, and troubleshooting. Use when asked to document a codebase, explain how a system works, audit existing docs, or build a technical handbook. Triggers on requests like "document this repo", "explain the architecture", "onboard me to this codebase", "write internal docs", or "what does this module do".
-
neversight Bundle Game Engineering TeamAAA-caliber engineering council for building production-quality games. Use when implementing game systems, writing game code, designing data architecture, building UI components, creating tutorials, optimizing performance, or any technical game development task. Covers game programming patterns, casino/card game implementation, reward systems, game UI engineering, tutorial design, code architecture, data infrastructure, security, and quality assurance. Triggers on requests for game code, system implementation, refactoring, performance optimization, data design, or technical architecture decisions.
-
netresearch Bundle CLI ToolsUse when ANY command fails with 'command not found', when installing CLI tools (ripgrep, fd, jq, yq, bat, etc.), auditing project environments, or batch-updating tools. Triggers on: command not found, install tool, missing binary, environment audit, update tools, which, apt install, brew install.
-
negusnati Bundle Verify CheckoutImplement, test, audit, debug, and harden Verify Checkout hosted-deposit flows in merchant backends, websites, and apps. Use for deposit creation, hosted checkout redirects, return pages, API-key auth, idempotency, signed webhooks, polling, reconciliation, exactly-once fulfillment, and production readiness for checkout.verify.et. Do not use for direct Verify.et bank-verification API integrations.
-
nextlevelbuilder Bundle Goclaw Docs AuditDetect which GoClaw docs pages need updating when source code changes.
-
nicholasspisak Bundle Openclaw PrimePrime a context window with OpenClaw infrastructure, gateway, channel, security, and operator knowledge from the OpenClaw docs. Use before answering admin questions, planning or executing configuration changes, debugging gateways or channels, reviewing deployments, or making operational decisions on an OpenClaw setup.
-
nikhil-salgaonkar Bundle Rust Design ReviewConduct a thorough Rust design review of code, functions, modules, or entire crates, covering idioms, design patterns, and anti-patterns. Use this skill whenever the user pastes or points at Rust code and asks for a review, design critique, pattern audit, or says things like "is this idiomatic?", "how would a Rust expert write this?", "review my Rust code", "what patterns am I missing?", "is this good Rust?", "do a design review", or "what am I doing wrong in Rust?". Also trigger for any request to refactor Rust code to be more idiomatic or better structured. Produces a structured review grounded in the rust-unofficial/patterns book (https://rust-unofficial.github.io/patterns/).
-
nimiq Bundle Mini AppsBuild, scaffold, convert, validate, audit, or ship a Nimiq Pay mini app. Covers the Nimiq provider (@nimiq/mini-app-sdk) and the Ethereum provider (window.ethereum), ERC-20 tokens (USDT, USDC), supported EVM chains (Polygon, Arbitrum, Base, Optimism, BNB, Sepolia), NIM payments, staking, message signing, and project setup. Use when the user wants to build, create, start, bootstrap, or scaffold a mini app; convert, port, migrate, or adapt an existing web app to run inside Nimiq Pay; add NIM, USDT, or ERC-20 token support; integrate Nimiq Pay wallet features; replace Stripe, PayPal, or MetaMask with Nimiq Pay providers; check, review, validate, or audit a mini app before shipping; or mentions window.ethereum, @nimiq/mini-app-sdk, listAccounts, sendBasicTransaction, wallet_switchEthereumChain, eth_sendTransaction, eth_signTypedData_v4, or balanceOf in a Nimiq context.
-
noi1r Bundle BeamerBeamer LaTeX slide workflow: create, compile, review, and polish academic presentations. Use this skill whenever the user works on Beamer .tex slide decks, or asks to create slides, make a presentation, prepare a lecture, build a talk, or generate Beamer slides from a paper PDF or Markdown. Covers: creation, editing, compilation, proofreading, visual audit, pedagogical review, TikZ diagrams, figure extraction, and comprehensive quality checks. Trigger on: beamer, slides, lecture, presentation, seminar talk, conference talk, defense slides, tikz, compile latex, proofread slides, slide review, 讨论班, 论文讲解. Do NOT trigger on: powerpoint, pptx, PPT, 做PPT — use the powerpoint-slides skill instead.
-
noi1r Bundle Crypto Paper WritingWrite and polish publication-ready cryptography papers, especially in the SNARK/zero-knowledge proof domain, targeting top security conferences (IEEE S&P, CCS, USENIX Security, NDSS) and top cryptography conferences (CRYPTO, EUROCRYPT, ASIACRYPT). Use this skill whenever the user works on cryptography papers, ZKP/SNARK manuscripts, asks to draft or revise sections of a crypto paper, wants to structure a paper around a new protocol or proof system, or needs help with crypto-specific LaTeX environments. Trigger on: write paper, draft paper, crypto paper, ZKP paper, SNARK paper, 写论文, 密码学论文, polish manuscript, revise section, structure paper, paper outline, zero-knowledge, proof system, protocol description, security proof writing. Do NOT trigger on: ML/AI papers, medical papers, general scientific writing without crypto context, slide/presentation creation (use beamer or powerpoint-slides skill instead).
-
oceanbase Skill Code ReviewReview seekdb pull requests and diffs for high-signal correctness, resource-lifetime, concurrency, current-version state-consistency, credential-exposure, workflow-security, performance, and test-evidence defects. Use when reviewing changes to seekdb C++, Rust, build, CI, or test code; report only actionable Blocker or Major findings and exclude persistence-format and upgrade-compatibility analysis.
-
octaviantocan Bundle Infisical CLI SecretsUse Infisical CLI cleanly for secrets, env injection, machine identity auth, self-hosted domains, and repo-specific secret workflows. Trigger when the user mentions Infisical, infisical CLI, universal-auth, machine identity, secret injection, replacing .env files, or using secrets for Pawrrtal/dev services.
-
olgasafonova Bundle Skill CheckValidate Claude Code skills against Anthropic guidelines. Use when user says "check skill", "skillcheck", "validate SKILL.md", or asks to find issues in skill definitions. Covers structural and semantic validation. Do NOT use for anti-slop detection, security scanning, token analysis, enterprise checks, or Eval Kit generation; use skill-check-pro for those. Do NOT use for LinkedIn skill engagement; use skillcheck-engage for that.
-
olgasafonova Bundle DeslopScan codebases for mechanical code health issues using only built-in tools. Checks file sizes, test coverage gaps, secret leaks, structural problems, and TODO debt. No external dependencies. Use when user says "deslop", "code quality scan", "code health", "portfolio health", or "scan this repo". Do NOT use for style linting, formatting, or subjective code review.
-
okx Bundle Skill GuardSecurity scanner for AI coding skills. Automatically scans any skill before installation to block malware — if a user asks to install, add, or download a skill, scan it first and block if malicious. Also supports full audit of all installed skills on request. Use this skill whenever skill installation, skill security, skill auditing, or skill safety comes up — even if the user just says "is this skill safe", "check this skill", "scan skills", or mentions downloading/adding a skill from an untrusted source. NOT for general code review or application security scanning.
-
omnigent-ai Skill Site Link AnalyzerAudit every link in the site (App Router pages, layouts, shared components, link constants, and any MDX) for broken internal routes, missing public assets, relative/external targets, and unverifiable anchors, then auto-apply the confident fixes and report the rest. Use when asked to check links, find broken links, validate docs navigation, or before publishing or merging content changes.
-
openfga Skill Make CheckRun full pre-commit validation (fmt, lint, test, security) and report results
-
opengrep Skill OpengrepRun Opengrep for pattern-based code search and security scanning. Use when grep is insufficient for finding code patterns that require structural understanding (function calls, data flow, nested structures). Also use for security vulnerability detection with custom YAML rules.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include evaluating-spin-off-investment-opportunities, invention-assignment-agreement, managing-clinical-data-quality. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.