Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
calven-ai Bundle Data Hygiene AuditData hygiene audit
-
nroze22 Skill Code ReviewReview code for quality, security, regulatory compliance, and clinical trial domain correctness. Enforces 21 CFR Part 11, HIPAA, and OWASP standards for Talosix EDC systems.
-
nroze22 Skill Security AuditComprehensive security audit for Talosix clinical trial EDC software. Covers OWASP Top 10, HIPAA, 21 CFR Part 11, authentication, authorization, encryption, dependency scanning, and PHI protection.
-
nroze22 Skill Audit PreparationPrepare for regulatory audits and inspections from FDA, EMA, and sponsors including checklist generation, document review, gap analysis, CAPA preparation, and common findings remediation.
-
nroze22 Skill Database MigrationPlan and execute database migrations with zero-downtime for Talosix EDC systems. Covers rollback strategy, data validation, audit trail preservation, and PostgreSQL-specific patterns.
-
nroze22 Skill Reconcile PaymentsReconcile invoices and payments for Talosix. Flag anomalies and discrepancies, maintain audit trail documentation, and support compliance reporting.
-
nroze22 Skill Sales Rfp ResponseGenerate comprehensive RFP responses for Talosix clinical trial EDC, addressing security questionnaires, vendor assessments, compliance certifications, and therapeutic area tailoring.
-
nroze22 Skill Error Handling StrategyDesign error handling patterns for Talosix EDC systems with structured logging for audit trails, user-friendly error messages, recovery patterns, and clinical trial data integrity protection.
-
gabrielmoreira Skill Wiki LintAudit and maintain the health of the Obsidian wiki. Use this skill when the user wants to check their wiki for issues, find orphaned pages, detect contradictions, identify stale content, fix broken wikilinks, or perform general maintenance on their knowledge base. Also triggers on "clean up the wiki", "what needs fixing", "audit my notes", or "wiki health check". Add --consolidate to switch from report-only to act-and-report mode (the "dream cycle"): fixes broken links, adds missing cross-references for orphans, corrects lifecycle states, demotes stale peripheral pages, normalizes tag aliases, and adds contradiction callouts — all with a dry-run preview and explicit user confirmation before any writes.
17 -
ranbot-ai Skill 7Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
6 -
ranbot-ai Skill FirebaseFirebase gives you a complete backend in minutes - auth, database, storage, functions, hosting. But the ease of setup hides real complexity. Security rules are your last line of defense, and they're o
Audited 6 -
ctct-ct2 Bundle Ctct Security PatrolOpenClaw 安全巡检工具,一键执行系统安全扫描并生成通俗易懂的报告。 使用场景:用户说"安全巡检"、"安全检查"、"安全审计"、"巡检"、"security audit"、"检查安全"、"系统安全"等。 触发条件:任何与 OpenClaw 安全检测、审计、巡检相关的请求。
-
leeguooooo Bundle Project SanitizerBinary analysis methodology + project sanitization workflow. Phase 1 covers the analysis playbook (function fingerprinting, XREF chokepoint heuristic, Swift/ObjC metadata + C++ RTTI exploitation, dynamic hooking trade-offs, backtrace at symptom, string xrefs incl. Swift small-string-optimization, differential analysis, observation-system awareness, anti-analysis awareness for Frida/self-hashing/PT_DENY_ATTACH, iOS FairPlay decryption, AI-assisted signature recovery), the five-layer verification protocol, OLLVM-family deobfuscation (Hikari/O-MVLL/goron/Pluto), and packaged desktop app analysis (Electron ASAR, Tauri Brotli). Phase 2 removes sensitive analysis artifacts and replaces internal RE terminology with neutral project language before sharing. Use for binary analysis, RE workflows, security audits, deobfuscation, '反汇编', '逆向', '脱敏'.
-
mozilla Bundle Update DepsAudit and update dependencies across Python, npm, and pre-commit ecosystems
-
agricidaniel Skill MintIntelligent Linux system assistant for Cinnamon-based desktops - directive-based workflows for security, updates, GPU, desktop customization, and troubleshooting
-
1837620622 Bundle Vensim SkillUse when the user needs Vensim/system-dynamics CLD/SFD modeling, .mdl sketch audit/repair/layout, simulation, nodata diagnosis, scenario comparison, or charts for coursework, policy, management, population, or supply-chain models.
-
1password Skill Security AwarenessTeaches AI agents to recognize and avoid security threats during normal activity. Covers phishing detection, credential protection, domain verification, and social engineering defense. Use when building agents that access email, credential vaults, web browsers, or sensitive data.
Audited -
20041002liu-cloud Bundle PDF Word Reader ZhEnd-to-end document understanding for `.pdf`, `.docx`, and `.pptx` (auto convert to PDF). Use when users ask to read, summarize, extract, analyze, compare, audit, or fully understand document content with evidence-based chunk citations.
-
2389-research Bundle Documentation AuditThis skill should be used when verifying documentation claims against codebase reality. Triggers on "audit docs", "verify documentation", "check docs", "docs accurate", "documentation drift", "before release", "after refactor", "docs don't match". Uses two-pass extraction with pattern expansion for comprehensive detection.
-
2389-research Bundle Sift Codebase AuditUse when asked to run SIFT (Structural Inspection for Technical Simplification), audit a codebase for simplification or refactoring opportunities, review structural complexity or tech debt, find invalid-state representations, or produce a prioritized simplification plan. A read-only, whole-repository audit covering data structures, state representation, control flow, algorithms, schemas, lifecycle/concurrency, and ownership boundaries. Not for single-file or diff-scoped reviews; recommends but never applies changes.
-
3paws-ai Bundle Appstore ReviewApp Store review readiness audit for iOS apps. Scans the codebase, entitlements, Info.plist, privacy manifests, paywall/subscription UI, and metadata for anything that could trigger a warning or rejection during App Store review. Invoke explicitly when preparing a submission. Do NOT trigger automatically.
-
cesarmdz Bundle Laravel Production ReadinessAI-optimized production readiness skill for Laravel projects. Evaluates architecture, security, database safety, performance, quality gates, deployment safety, and Git workflow before shipping code.
-
cesarrivasp Bundle Feature SpecCreate, audit, and keep-in-sync multi-doc feature specs from a single source of truth (a facts registry), so no two docs ever contradict. Use when the user wants to write a feature spec / design doc set, audit spec docs for consistency, or validate that every shared datum matches across documents.
-
cheshiremew Bundle Project Steward从项目过程与结果提炼治理方法并在明确要求时自我进化;按实施计划审计完成度,研究整理仓库,预防返工,沿根因修复跨层缺陷,治理架构、目录职责、用户链、UI/UX、文档、日志、环境与发布。Use for project-history learning/evolution; audit a plan or repository; understand or organize a codebase; inspect external-tool compatibility, durable operations, and project governance. Excludes isolated function, security, dependency, CI, or monitoring-only work.
-
childerolando Bundle Repository GovernanceGovern substantial AI-assisted repository changes. Use when a change has architectural impact (boundaries, invariants, new abstractions), or when the user explicitly asks to create, bootstrap, audit, harden, redesign, or modify repository governance.
-
tomevault-io Bundle Code ReviewToolkit for performing structured code reviews. Covers identifying bugs, security issues, performance problems, and style violations. Use when asked to review code changes, pull requests, or individual files. Use when this capability is needed.
-
tomevault-io Bundle FuzzSet up and run fuzz testing to discover crashes, edge cases, and security vulnerabilities. Use when user says "fuzz test", "fuzz this function", "find edge cases", or wants to stress-test input handling with randomized data. Use when this capability is needed.
-
88plug Bundle World FirstUse when the goal is to produce and defensibly claim a genuine world-first, invention, novel algorithm/protocol/kernel/mechanism, or "nobody has done this" capability — and to prove the claim rather than assert it. Triggers on intent like "invent", "world-first", "first-ever", "beat the incumbent with something new", "break all dogma", "is this novel?", "prove this is new", or any push to build a mechanism a competitor structurally cannot. Also use to audit an in-flight "first" claim for overclaim before it ships, is committed, benchmarked-for-publication, or sent externally. This is the packaging of the INVENTION PLAYBOOK: confirmed-limit entry → TRIZ ideation → the removed-constraint test → refute-then-build vs a tuned baseline → provenance search → certify → kill failure modes. Reach for it by default on invention and novelty-claim work; skip only for routine feature work with no novelty claim attached.
-
ahmad-g1 Skill Ppc Audit LiteFree edition. Run the census half of a senior-level Amazon PPC audit — admissibility checks, coverage mapping, and duplicate-serve detection priced as a real number. Use when someone uploads or pastes an Amazon search term report or bulk file, or asks to review, clean up, or find waste in an Amazon advertising account. Produces counted, priced findings that need no statistical machinery. The verdict half — affordability, harvest/negate decisions, and bid derivation — requires the full PPC Operator Toolkit.
Audited -
akshay7273 Bundle Skill Advisories CheckCheck an OpenClaw or ClawHub skill against public security advisories before installation.
-
aparnabuilds Bundle HumanizerAudit, rewrite, or draft text so it carries zero AI-writing tells and makes only honest, sourced, self-consistent claims. Built from Wikipedia's "Signs of AI writing" (WikiProject AI Cleanup), open-source detector heuristics, and a writing-integrity contract. Use for ALL writing and editing tasks (blogs, LinkedIn, Quora, PR, case studies, emails, landing pages, executive ghostwriting) even when the user doesn't say "humanize". Also trigger when asked to detect AI patterns, de-AI a draft, audit claims, or check whether text would pass as human. Applies to everything except code and raw data.
-
avivavi Skill TokenscopeJudgment-layer review of Claude Code token usage. Use when the user asks to audit token costs, review Claude Code spending, check context waste, or interpret a tokenscope report. Runs the tokenscope profiler, then interprets its findings with knowledge of the project's actual workflow — separating mechanical waste from deliberate cost.
Audited -
bernhardjackiewicz Bundle Icca HarnessICCA names the four separated roles that carry the method: Implementer, Checker, Control, Auditor. Mandatory development workflow for any task that changes production code, fixes a bug, adds a feature, performs a refactor, or creates a commit. MUST be loaded before implementation begins. Keeps the orchestrator's context lean (delegation to a cheaper implementer tier, index navigation, evidence ledger) and enforces Commit Contract, Red Proof, frozen acceptance tests, delegated implementation, independent verification, bounded repair loops, Commit Gate, and requirement-first audit via global hooks.
-
tomevault-io Bundle Dependabot Alerts UpdateAutomatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files across monorepo workspaces. Use when user mentions Dependabot alerts, security vulnerabilities, or wants to update vulnerable dependencies automatically. Use when this capability is needed.
-
tomevault-io Bundle Cq AI Deterministic Security Scanning With Ternary PolarityCode Query with AI-enhanced deterministic analysis via SplitMix ternary classification Use when this capability is needed.
-
tomevault-io Bundle Provectus Awos AwosCode Audit — Orchestrator
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include firebase, data-hygiene-audit, code-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.