Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
openitu Bundle Itu T Recommendation ReviewerReview draft ITU-T Recommendations (and ITU-T | ISO/IEC common texts) for compliance with the ITU-T Author's Guide, presentation rules, and quality checklist before submission for consent/determination/approval. Use this skill whenever the user asks to review, check, audit, proofread, or improve a draft ITU-T Recommendation, standard contribution, amendment, corrigendum, or common text — including requests phrased as "检查/审查/校对 ITU-T 建议书", "does my draft follow ITU-T rules", "prepare my draft for TSB submission", or when a user uploads a document identified as a draft Recommendation. Also use it when authors ask how to correctly structure clauses, references, definitions, figures, tables, or notes in an ITU-T text.
-
pallavkaushish Skill Zero AI SlopA quality check for prose. Apply automatically whenever drafting any writing – an article, post, email, newsletter, essay, landing page, doc or message – so the draft ships clean of AI-tell patterns. Also use when the user asks to clean, de-slop, fix or rewrite an existing draft, or to check, audit or score a piece for AI-sounding writing ("clean this up", "does this sound like AI?", "/zero-ai-slop").
-
pantheraudits Bundle Move AuditorAudits Move contracts (Sui & Aptos) for security bugs.
-
philipgierszal Bundle Architecture Hygiene AuditUse when asked to audit an entire repository for dead code, orphaned files, unused methods or exports, dependency cycles, architecture-rule violations, repository structure problems, or SOLID, separation-of-concerns, DRY, KISS, and YAGNI concerns.
-
psylch Bundle Email Dns HealthAudit and validate email DNS records (SPF, DKIM, DMARC, BIMI, MTA-STS, MX) for any domain. Detect email providers, count SPF DNS lookups, grade overall health A-F, and provide fix guidance. Use when the user says 'check email DNS', 'audit SPF/DKIM/DMARC', 'email deliverability check', 'detect email provider', 'fix email DNS', 'setup email records', 'email health score', or 'update DNS records'.
-
qiaeru Bundle Optimizing Claude MdOptimize a project's CLAUDE.md to be short, specific, and free of duplication. Use when asked to optimize, trim, audit, or improve a CLAUDE.md or AGENTS.md. Scans the existing docs and replaces derivable or duplicated content with on-demand references rather than rewriting it in CLAUDE.md.
-
printagram Bundle Dev TrackerMaintain a structured development journal for software projects that preserves context across Claude Code sessions. Use this skill whenever the user mentions session start, session end, save progress, DEVLOG, DECISIONS, ADR, architecture decision record, project journal, development log, cross-session memory, what was done previously, or asks to resume work on a tracked project — even if they do not explicitly name the skill. Also use when the user wants to initialize tracking files, audit undocumented conventions, or maintain continuity across multiple related work sessions on the same codebase.
-
pygent-ai Bundle Project MaintainerUse when initializing, querying, auditing, or updating a structured `.doc_project_maintainer/` project map; analyzing a repository; documenting modules, directories, cross-boundary flows, source symbols, changes, or decisions; or using that map as scoped context during a bug fix, feature change, or refactor. Route ordinary code changes through scoped maintenance, expand only for boundary or high-risk changes, and reserve full inventory, coverage closure, signing, and trusted symbol audit for explicit knowledge-base or audit delivery.
-
quicksilversurfer Bundle Codebase ExplorerA structured method for exploring and understanding unfamiliar codebases. Use this skill whenever the user asks to explore, understand, audit, review, or navigate a codebase they haven't worked in before. Also trigger when the user says things like "help me understand this code", "what does this repo do", "walk me through this codebase", "explore this project", "I inherited this code", "onboard me to this system", or asks about the architecture, structure, or health of an existing codebase. Trigger even if they just drop a repo path and say "what is this". This skill produces structured understanding — not summaries, but navigable maps of how code actually works.
-
ramyatrouny Bundle IfrsUse when answering questions about IFRS standards, IAS standards, IASB, financial reporting, revenue recognition, lease accounting, impairment, financial instruments, expected credit loss, ECL, hedge accounting, consolidation, business combinations, fair value measurement, first-time adoption, deferred tax, Pillar Two, provisions, insurance contracts, hyperinflation, journal entries, disclosure requirements, IFRS compliance checks, audit support, GAAP differences, goodwill, IFRS 18, IFRS 19, IFRS 20, presentation and disclosure, management-defined performance measures, MPM, IFRS S1, IFRS S2, sustainability disclosure, ISSB, IFRIC, SIC, agenda decision, IFRS for SMEs, Conceptual Framework, EU endorsement, transitioning from local GAAP to IFRS, or reviewing whether a feature, codebase or system produces correct accounting figures — feature review, implementation review, does this code handle revenue correctly, is this implementation IFRS-compliant.
-
ranxi2001 Bundle Humanizer CsRevise AI-assisted software-engineering communication without changing its technical claims. Use for GitHub issues, pull request titles and bodies, code review comments, review replies, maintainer discussions, weekly reports, executive or engineering summaries, status updates, and English-Chinese translation when the text must sound like a precise, credible developer rather than a chatbot or article writer. For reports and summaries, make results, risks, decisions, and next actions easy to scan without replacing evidence. For comments and replies, keep the message incremental and direct. Also use it to audit fabricated verification, vague evidence, inflated certainty, unclear review severity, status drift, terminology drift, excessive politeness, or generic AI phrasing. Do not use it to evade AI-detection systems or bypass repository disclosure and authorship policies.
-
r00tedbrain-backup Bundle Reverse EngineeringExpert-level reverse engineering and binary debugging skill. Use this skill whenever the user wants to analyze, decompile, disassemble, or debug binaries, executables, APKs, iOS apps, firmware, or obfuscated code. Triggers for: static analysis, dynamic analysis, malware analysis, exploit development, CTF challenges, binary patching, anti-debug bypass, protocol reversing, memory forensics, hooking, frida scripting, GDB/LLDB debugging, radare2, Ghidra, jadx, apktool, strings analysis, symbol resolution, or any request involving "reverse engineer", "RE", "decompile", "disassemble", "patch binary", "debug crash", "analyze malware", "bypass protection", "hook function", "intercept traffic", "find vulnerability", or examining unknown file formats. Always load this skill for CTF pwn/rev challenges, app security assessments, and firmware analysis.
-
resonatingloop Bundle Manage Project DocsMaintain repository documentation as a continuity protocol tied to code, tests, contracts, and operational truth. Use when Codex needs to bootstrap or retrofit project docs, resume work in a dormant or unfamiliar repository, draft an implementation spec, reconcile documentation before closing a material change, audit documentation against a live codebase, or promote a recurring failure into a reusable workflow or check.
-
retlehs Bundle Gh ActionsGitHub Actions best practices — current action versions, caching, security, and common patterns. Activate when writing or modifying GitHub Actions workflows.
-
rastian Bundle Behavioral DesignApplies behavioral psychology and behavioral economics to product and UX design. Use when a designer, PM, researcher, or design manager wants to diagnose why users aren't completing a flow, adopting a feature, or changing behavior; design nudges or behavior-change interventions; reduce friction or cognitive load; run a behavioral design workshop or sprint; audit a design for psychological effectiveness; or apply principles like loss aversion, social proof, choice architecture, habit formation, or implementation intentions. Also triggers for: onboarding drop-off, feature adoption, engagement design, conversion optimization, design psychology, behavioral economics, mental models, or behavior change strategy. Guides users through behavioral diagnosis, barrier identification, and intervention design - with ethics review built into every output.
-
rahozosman Bundle Security Architecture IntelligenceAnalyzes codebases for security design flaws, threat modeling gaps: attack surface, auth boundaries, and data flow risks.
-
reversepoco Skill Security ReviewComprehensive security audit. Use when reviewing code for vulnerabilities, before deployments, or when the user mentions security.
-
ray0907 Bundle Security ScanUse when a user asks to scan a repository for dependency vulnerabilities, insecure code patterns, CVEs, or OWASP Top 10 risks.
-
rcarmo Bundle Go AI Upstream SyncSync go-ai with upstream @earendil-works/pi-ai changes — audit upstream version deltas, regenerate models, port API/type/provider changes, update docs, and validate parity.
-
robertsilen Bundle Mariadb AI DbaMariaDB AI DBA — connects to a MariaDB database and produces a factual server inventory covering configuration, schema, performance counters, security, and MariaDB-specific features. Use when the user asks to analyze, audit, health-check, or inventory a MariaDB or MySQL database, or asks for database performance advice with a live server available.
-
rubyroidlabs Bundle Rails Audit SkillPerform comprehensive technical reviews of Ruby on Rails applications. Runs automated analysis tools (RubyCritic, Brakeman, bundler-audit, Gitleaks, Debride, linters, SimpleCov, Rails stats, Rails ERD), analyzes code for architecture, security, authorization (Pundit/CanCanCan), dead code, and design issues, and produces a structured markdown report with prioritized findings and a 0-10 score. Use when the user requests a tech review, code audit, project assessment, or quality analysis of a Rails application.
Audited -
ruoji6 Bundle Audit Skills当用户要求审计 Java、.NET 或 PHP 源码/部署产物/反编译产物/安全发现,并需要默认脚本输出目录、报告输出目录、Java/.NET 反编译与反混淆参考、Java 组件 YAML 正则匹配扫描、确认漏洞判定标准、安全 Payload 和 BurpSuite 原始 HTTP 请求包证据时使用。仅用于授权代码审计和防御性安全验证。
-
robonuggets Skill Doctor PlusRuns Claude Code's built-in /doctor health check, then audits the workspace against the 6 then-and-now context-engineering shifts Anthropic shipped with the Claude 5 models (rules to judgement, examples to interfaces, upfront to progressive disclosure, repeats to tool descriptions, CLAUDE.md memory to auto-memory, simple specs to rich references). Reports findings first, fixes only on approval. Triggers on "/doctor-plus", "doctor plus", "doctor-plus", "extended doctor", "then and now audit", "context checkup".
-
rwshiraishi Bundle App BlueprintPrepare a product build package with requirements, architecture, design, security, tests, and sequenced implementation goals. Use when the user requests a new-product specification, build preparation, or a substantial rewrite plan. Scale to Sketch, Standard, or Full; do not replace a request to implement an existing specification with a new planning exercise.
-
ryjoxtechnologies Skill Octopoda MemoryPersistent memory across sessions — recall, store, share, audit decisions, snapshots, and version history
-
ronantakizawa Bundle Open Source ContributionGuides developers through open source contributions including finding projects, writing PRs, conventional commits, and communicating with maintainers. Covers enterprise standards (Linux Kernel, Apache) and security disclosure. Use when contributing to GitHub/GitLab projects, writing commit messages, responding to code review, or reporting vulnerabilities.
-
sablier-labs Bundle SolanaThis skill should be used when the user asks to "build a Solana program", "write Anchor code", "create a PDA", "work with SPL tokens", "test with anchor-bankrun", "fuzz test with Trident", "secure my Solana program", "create an NFT with MPL Core", "optimize compute units", or mentions Anchor constraints, account validation, CPI patterns, Vitest testing, or Solana security auditing.
-
gmmh1 Skill Tiktok Ads AuditPerform a full TikTok Ads account health check. Triggers on 'audit my TikTok Ads account', 'is this TikTok account set up well', 'inherited this TikTok account, check it', or 'is this account ready to scale'. Broad structural review — for a specific known symptom, use tiktok-ads-optimization instead.
-
gmmh1 Skill Linkedin Ads AuditPerform a full LinkedIn Ads account health check. Triggers on 'audit my LinkedIn Ads account', 'is this LinkedIn account set up well', 'inherited this LinkedIn account, check it', or 'is this account ready to scale'. Broad structural review — for a specific known symptom, use linkedin-ads-optimization instead.
-
gmmh1 Skill Paid Media Cross Platform AuditAudit a business's entire paid media presence across Google, Meta, LinkedIn, and TikTok as one system. Triggers on 'audit my whole paid media presence', 'review all my ad accounts', 'cross-channel advertising audit', or 'inherited a multi-platform ad program, check it all'. Calls into each platform's own -audit skill and adds cross-channel findings those miss individually.
-
cleanexpo Skill Browser AuthDrives an authenticated browser session on synthex.social (or localhost) WITHOUT the flaky Chrome extension. The reliable path is a committed Playwright script (scripts/browser/dashboard-audit.mjs) that logs in with the SYNTHEX_TEST_EMAIL / SYNTHEX_TEST_PASSWORD test account and audits every integration surface. Use whenever asked to "log in", "authenticate", "audit the dashboard", "check what's connected", or before browser-verify / site-smoke-test on /dashboard/* routes.
-
cleanexpo Skill Route AuditorSynthex API route compliance scanner. NEVER apply generic REST conventions without grounding in Synthex's specific security pattern. ALWAYS audit against: getUserIdFromRequestOrCookies() auth, { organizationId } on every query, Zod safeParse() on all mutations, withRateLimit() on AI routes, and migrate diff + db execute for schema changes. Activate on ANY request to audit a route, check API security, review an endpoint, or scan for auth or org-scope issues.
-
cleanexpo Bundle Project ScannerCodebase analysis, dependency auditing, and architecture mapping for the Synthex platform. Scans file structure, dependency health, TypeScript errors, unused exports, security vulnerabilities, and documentation gaps. Use when user says "scan project", "audit dependencies", "check codebase", "architecture map", "security scan", or "code health".
-
tonydzi Skill N8nHealth-check, audit and, on approval, fix a self-hosted n8n automation stack. Health is read-only; any workflow edit goes preview, approval, apply. Triggers: "/n8n", "/n8n health", "/n8n fix <id>", "which workflows are failing".
-
kimtth Skill Security ReviewUse when: review code or a design for security issues across the OWASP Top 10 and common pitfalls.
-
kimtth Skill Threat ModelingUse when: systematically identify threats to a system and decide how to mitigate them.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include gh-actions, itu-t-recommendation-reviewer, zero-ai-slop. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.