Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aibtcdev Bundle Clarity AuditClarity smart contract security audit — structured review covering correctness, security vulnerabilities, design concerns, and deployment readiness.
-
sd0xdev Skill Dep AuditAudit dependency security risks
-
compozy Bundle Eng Real Scenario QADogfoods Compozy through an autonomous startup scenario with live providers, cross-surface observation, and strict evidence audit. Use for release or complex-integration QA. Do not use for smoke, static, mock-only, or unit-test work.
-
compozy Bundle Eng Cleanup Failure PathsPartial-failure cleanup audit for Compozy Go functions. Use when a changed function acquires, registers, starts, claims, leases, or opens more than one fallible resource before returning. Do not use for pure transformations, read-only helpers, or test-only code.
-
compozy Bundle Cy Review RoundPerforms a comprehensive code review of a spec implementation and generates a review round directory with issue files compatible with cy-fix-reviews. Use when reviewing implemented spec tasks, creating a manual review round without an external provider, or performing a quality audit of code changes. Do not use for fetching reviews from external providers, fixing existing review issues, executing spec tasks, or editing source code.
-
cleanexpo Skill Ship Loop SanitySecurity/quality gate child loop. Runs auth ratchet test, npm audit, parallel auth-coverage script, and a secret-leak diff-scan. Updates ship-loop-state.json with per-gate state. On failure applies one recovery recipe (typically auth ratchet triage or audit fix), retries once, escalates. Use standalone via /loop ship-loop-sanity or wired into the master orchestrator.
-
cleanexpo Skill Foundation KeeperSenior Foundation Keeper (15+ yr governance calibration). Discipline-enforcement meta-skill. Maintains canonical foundation files (ceo-foundation.md · verification-gates.md · skill-orchestration-spec.md · reporting-templates.md · tier-b-engineering-specs.md · gap-audit-playbooks.md). Updates verification-gate state ONLY when source documentation arrives + filed in registry. Refuses unsupported flips. Logs every amendment + every refusal with audit trail · zero silent updates. Read-write authority on canonical files; all other skills consume them read-only. The mechanism that prevents hallucination at production time. Closes every action with audit_log_entry, downstream-skill notifications, and brand-voice-enforce directive.
-
cleanexpo Bundle Senior CopywriterSenior Copywriter (15+ yr calibration). Drafts client-facing content (LinkedIn posts · Hub articles · email sequences · landing-page copy · ad copy · Remotion scripts · founder thought leadership) per the surface's locked foundation structure. Reads ceo-foundation.md + verification-gates.md at every drafting task. Closes every draft with a falsifiable engagement/conversion hypothesis, a kill threshold, and a pre-gate self-audit against the junior-failure-mode NEVER list before routing to brand-voice-enforce.
-
cleanexpo Bundle Brand Consistency CheckerSynthex brand consistency enforcer. NEVER produce vague feedback ("sounds on-brand", "good feel", "consistent with your voice"). ALWAYS score against specific criteria: vocabulary match percentage, anti-pattern phrase count, and CTA quality. Every feedback item must be specific enough to act on immediately. Activate on ANY request to check brand consistency, audit content against brand guidelines, review voice alignment, or validate that content matches a Business DNA profile.
-
cleanexpo Skill Dependency AuditAudit new dependencies for CVEs, licence compliance, bundle size impact, and supply chain risk
-
dannykkh Bundle Dependency UpdaterSmart dependency management for any language. Use when user asks to "update dependencies", "upgrade packages", "fix dependency issues", "check outdated", or when encountering version conflicts, security vulnerabilities in packages, or broken installs. Triggers on "outdated", "npm update", "패키지 업데이트".
-
dannykkh Bundle Semgrep Rule CreatorCreates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.
-
dannykkh Bundle Systematic DebuggingExplicit `/systematic-debugging` reference for a structured root-cause audit. Use only when the user requests this workflow; routine diagnosis stays native.
-
chorus-aidlc Skill Code ReviewerFinal ship-time review of an Idea's aggregate code change — the whole feature across all its tasks, not one task. Read the integrated code, check cross-task integration / architecture / security / regression / coverage, run tests. Invoke after the last task of an idea-rooted proposal is verified; ends with a VERDICT comment on the Idea.
Audited -
navikt Skill ReviewSelf-review the complete scoped diff for correctness, regressions, requirements and repository rules before delivery. Use after implementation or when asked to find problems in changes; use `security-review` for security-specific analysis.
-
navikt Bundle Auth OverviewDesign, implement or diagnose authentication and authorization in a Nav backend. Use for token validation, token exchange, protected endpoints or issuer, audience and 401/403 problems; use `security-review` for a broader security assessment.
-
navikt Bundle Architecture ReviewEvaluate a consequential architecture proposal, its alternatives, migration and reversibility. Use for new services, cross-team boundaries, platform choices or costly migrations; use `improve-codebase-architecture` to discover refactoring candidates in existing code and `security-review` for security analysis.
-
zai-org Skill GistCreate, view, edit, or delete GitHub gists for code and text sharing. Use when the user specifically asks to work with a gist, including public or secret gist visibility, not for files stored in a repository.
-
zai-org Skill SecretList, set, delete, or synchronize GitHub Actions repository secrets without exposing secret values. Use when the user explicitly wants to manage GitHub secret storage, not ordinary environment files or repository variables.
-
zai-org Bundle Mimosa Security ScanRun a sealed, reproducible Mimosa deep security scan. / 运行可复核的 Mimosa 密封深度安全扫描。 Use only when the user explicitly requests a deep or full repository security scan.
-
sd0xdev Bundle Doc ReviewDocument review via Codex exec. Use when: reviewing .md docs, tech spec audit, document quality check. Not for: code review (use codex-code-review), test review (use test-review). Output: 5-dimension rating table + gate.
-
sd0xdev Bundle Risk AssessUncommitted code risk assessment with breaking change detection, blast radius analysis, and scope metrics. Use when: evaluating PR risk, pre-commit risk check, large refactoring review. Not for: security vulnerabilities (use /codex-security), code correctness (use /codex-review-fast). Output: 3-dimension weighted score + risk level + gate.
-
sd0xdev Bundle Test HealthHolistic test coverage measurement. Use when: assessing test health, measuring coverage trends, quantitative + qualitative test audit. Not for: running tests (use verify), reviewing test sufficiency only (use codex-test-review), generating tests (use codex-test-gen). Output: multi-dimensional dashboard with coverage metrics + test inventory + trend.
-
sd0xdev Bundle Test ReviewTest coverage review via Codex exec. Use when: reviewing test sufficiency, identifying coverage gaps, test quality audit. Not for: generating tests (use codex-test-gen), code review (use codex-code-review). Output: coverage analysis + gap report.
-
sd0xdev Bundle Seek VerdictIndependent second-opinion verification for any finding. Use when: Claude or user wants independent Codex verification of a review finding — dismiss (false positive check), confirm (does this issue exist?), or clarify (what's the impact?). Triggers: dismiss verification, seek verdict, verify dismiss, false positive check, second opinion, confirm finding, clarify impact. Not for: general code review (use codex-code-review), architecture debates (use codex-brainstorm). Output: [DISMISS_VERDICT] or [SEEK_VERDICT] audit trail with verdict, confidence, and evidence refs.
-
sd0xdev Bundle Deep ResearchUniversal multi-source research orchestration. Use for any research/investigate/analyze request needing synthesis across web, codebase, and community evidence — especially broad, mixed, or ambiguous intent. Triggers on: 'research this', 'deep research', 'investigate', 'analyze from multiple angles', 'comprehensive analysis', 'explore this topic', 'study', 'survey the landscape', 'look into', 'understand deeply', '了解', '調查', '分析', '研究'. When intent is clearly single-dimension (code-only tracing, checklist-style compliance audit, or bounded option-ranking), dispatcher may prefer a narrower skill. Otherwise route here. Supports low/medium/high budget tiers.
-
sd0xdev Bundle Project AuditProject health audit with deterministic scoring. Use when: evaluating project quality, onboarding to new codebase, periodic health checks. Not for: runtime performance analysis, security-specific audits (use /codex-security). Output: 5-dimension score + actionable findings.
-
sd0xdev Skill Codex SecurityOWASP Top 10 security review using Codex exec. Supports review loop with context preservation.
-
sd0xdev Bundle Necessity AuditNecessity audit for over-designed spec elements. Use when: auditing lifecycle spec (1-requirements / 2-tech-spec / 3-architecture) for YAGNI/KISS violations, challenging necessity of FRs/NFRs/abstractions/configs via Codex adversarial debate. Not for: FP reasoning validity (use /codex-review-spec), completeness check (use /feature-completeness), detail review (use /codex-review-doc), or code-level simplification (use /simplify).
-
sd0xdev Bundle Security ReviewSecurity review via Codex exec. Use when: OWASP Top 10:2025 audit, dependency vulnerability check, security-sensitive changes. Not for: code review (use codex-code-review), test review (use test-review). Output: security findings + audit report.
-
sd0xdev Bundle Codex Code ReviewCode review using Codex exec. Use when: PR review, code audit, second opinion on changes. Not for: doc review (use doc-review), security audit (use security-review). Output: severity-grouped findings + merge gate.
-
sd0xdev Bundle Dev Security AuditComprehensive developer workstation security audit — scans for exposed credentials, compromised application data, persistence mechanisms, and supply chain attack indicators. Use this skill whenever the user suspects their machine may be compromised, wants to check for exposed secrets, asks about supply chain attacks, or wants a full security audit of their development environment. Also triggers on: 'am I compromised', 'check my security', 'scan for leaked keys', 'credential audit', 'supply chain attack', 'supply chain check', 'check if I was hacked'.
-
calven-ai Bundle Lifecycle MapMap every automated email to a lifecycle stage and list gaps and overlaps. Use when "what emails do we send when", "lifecycle audit", "gaps in nurture".
-
calven-ai Bundle Martech AuditMartech audit
-
calven-ai Bundle Tracking SpecDefine an event or audit implemented events against the ontology and list gaps. Use when "define the event for X", "is tracking right", "GA4 audit".
-
calven-ai Bundle Ads Account AuditAds account audit
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include codex-code-review, clarity-audit, dep-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.