Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Tags CleanupAnalyze and clean up Forest knowledge base tags. Use when asked to "clean tags", "fix tags", "tag audit", "tag hygiene", or "normalize tags". Audits tag entropy, finds duplicates and format violations, then applies fixes via the Forest CLI. Use when this capability is needed.
-
tomevault-io Bundle Califio Skills SkillsPHP Unserialize Surface Audit
-
tomevault-io Bundle Test OciRun the TMI comprehensive test suite against Oracle ADB (OCI) including unit tests, integration tests, API tests, and CATS security fuzzing. Use when asked to run tests against Oracle database. Use when this capability is needed.
-
tomevault-io Bundle Kedro Org Kedro KedroSecurity Scan
-
tomevault-io Bundle Jamie8johnson Cqs Audit---
-
tomevault-io Bundle Jkheadley Instar Instariterative-converging-audit — Audit to Convergence, Not to Exhaustion-of-Patience
-
tomevault-io Bundle Pr ReviewerReview GitHub pull requests for code quality, security, and best practices. Use for automated PR feedback and approval workflows. Use when this capability is needed.
-
tomevault-io Bundle SoloditSearch Solodit for similar smart contract security findings. Use when reviewing vulnerabilities, comparing to known issues, or researching prior art from real audits. Use when this capability is needed.
-
tomevault-io Bundle Miro Code ReviewUse when the user wants to create a visual code review on a Miro board from a pull/merge request (GitHub, GitLab, or any forge), local uncommitted changes, or a branch comparison — produces a file-changes table, summary/architecture/security docs, and architecture diagrams, then links them back from the PR/MR.
-
tomevault-io Bundle Iso 27001ISO 27001:2022 requirements, control implementation, documentation requirements, and audit preparation Use when this capability is needed.
-
tomevault-io Bundle NodejsNode.js server development patterns including async patterns, error handling, and security best practices. Use when this capability is needed.
-
tomevault-io Bundle Review Multi PerspectiveMulti-perspective code review using four parallel constructive reviewers (conservative, security, usability, speed) followed by a sequential adversarial gap-analysis pass. Each reviewer uses a two-phase inventory-then-assess approach for systematic coverage. Findings are synthesized, deduplicated, verified, and presented as a prioritized remediation plan. Use when this capability is needed.
-
tomevault-io Bundle Nexios OverviewTeach Nexios comprehensively to AI editors and coding agents as an external async Python web framework. Use when Codex needs to explain or generate Nexios code with concept-by-concept guidance, runnable examples, and best practices across app setup, ASGI basics, routing, handlers, request inputs, responses, middleware, dependency injection, authentication, sessions, cookies, security, pagination, WebSockets, events, OpenAPI, testing, templating, static files, uploads, and CLI workflows. Prefer this skill for tutorial-style answers, onboarding, code generation, and framework learning rather than repo-specific debugging or source edits. Use when this capability is needed.
-
tomevault-io Bundle DepscanRun OWASP Depscan for advanced Software Composition Analysis with VDR, CSAF, and license compliance. Use when scanning dependencies with deep SCA, generating VEX documents, SBOM+VDR analysis, or comprehensive license auditing. Use when this capability is needed.
-
tomevault-io Bundle Vuln CheckThis skill should be used when the user asks to "check vulnerabilities", "check for security issues in dependencies", "run vuln-check", "check CVEs", or discusses dependency security scanning. Provides Go module vulnerability scanning using govulncheck. Use when this capability is needed.
-
tomevault-io Bundle DepsguardInstall and run DepsGuard, a zero-dependency CLI that scans and fixes package manager configs (npm, pnpm, yarn, bun, uv) for supply chain security best practices. Use when this capability is needed.
-
tomevault-io Bundle ReviewerMUST BE USED for code review. Use PROACTIVELY when /review command is invoked or after any code changes to check correctness, architecture, and security. Use when this capability is needed.
-
tomevault-io Bundle Barmplus Locklens LocklensDependency Audit
-
tomevault-io Bundle Doc AuditExpert in auditing Sphinx/RST documentation for Drift project. Use when validating code examples and removing subjective language before release. Use when this capability is needed.
-
tomevault-io Bundle Symfony Symfony SymfonySymfony Security Triage
-
tomevault-io Bundle Docs Coverage And Route Integrity AuditAudit docs.json route integrity, legacy path drift, and potential orphan docs files in v2. Use when this capability is needed.
-
tomevault-io Bundle 1password Scam ScamSecurity Awareness Expert
-
tomevault-io Bundle Create AuditCreate a new audit module for the check-ai scanner. Use this skill when the user wants to add a new audit section that checks for specific files, directories, or patterns in a repository. The skill generates a properly structured .mjs file in src/audits/ that is automatically loaded by the scanner. Use when this capability is needed.
-
tomevault-io Bundle Stash Supply Chain SecuritySupply-chain security controls for the @cipherstash/stack monorepo. Covers post-install script policy (onlyBuiltDependencies), install cooldown (minimumReleaseAge), lockfile integrity (blockExoticSubdeps + lockfile registry check), frozen-lockfile CI, registry pinning (.npmrc), Dependabot cooldown, and CODEOWNERS. Use when modifying CI workflows, pnpm config, dependency updates, .github/dependabot.yml, or anything that touches how packages enter the build. Use when this capability is needed.
-
tomevault-io Bundle Review Agents MdAudit Dograh `AGENTS.md` files for drift against the live repo and for bad scope boundaries between parent and child docs. Use when the user asks to review existing AGENTS files, identify stale guidance, decide whether a subtree needs its own `AGENTS.md`, or update the `AGENTS.md` hierarchy under the repo root, `api/`, or `ui/`. Use when this capability is needed.
-
tomevault-io Bundle Eigent AI Eigent EigentSecurity Auditor Guide
-
tomevault-io Bundle Go Deps Security UpgradeRun a grouped, bisectable Go dependency security sweep on the Fission repo. Use when the user asks to upgrade outdated/vulnerable Go dependencies, run a dep security pass, or process CVE findings from govulncheck. Produces one commit per logical dependency group on a dedicated branch so failures are attributable and revertable. Use when this capability is needed.
-
tomevault-io Bundle Burp SuiteWeb application security testing with Burp Suite. Use when this capability is needed.
-
tomevault-io Bundle SignetCryptographic signing for every tool call with Ed25519 audit trail Use when this capability is needed.
-
tomevault-io Bundle Rube De Cc Skills UpdateUpdate: Issue Audit & Cleanup
-
tomevault-io Bundle Code Review HelperUse when working with a safe skill that helps with code review tasks
-
tomevault-io Bundle NsjailUse when configuring Linux sandboxing with nsjail, generating security profiles, or configuring process isolation for skills.
-
tomevault-io Bundle FridayAudit listing image and layout notes — first-impression hero, info hierarchy, lifestyle vs studio, copy density, trust signals, compliance — into a follow-up checklist. Use when this capability is needed.
-
tomevault-io Bundle Colorscheme ReviewRead-only audit of the token colorscheme for palette integrity, module conformance, and toolchain health Use when this capability is needed.
-
tomevault-io Bundle Go SecSecurity patterns, OWASP, authentication, authorization Use when this capability is needed.
-
tomevault-io Bundle Plan AuditAudit an implementation against a plan (docs/codex-plans/*). Use when a user asks to check for gaps, logic errors, or missing tests relative to a plan or Work Items. Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include tags-cleanup, califio--skills--skills, test-oci. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.