Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Unity Sharedunity-cli 共通ルール。全 unity-* スキルが自動ロードする前提条件。Use as prerequisite for any unity-* skill (verification sequence, fallback order, security policy). Use when this capability is needed.
-
tomevault-io Bundle UI UX AuditMandatory audit workflow for UI/UX changes that reads current state FIRST, checks for redundancy, respects clean design philosophy, and identifies genuine gaps before implementation. Auto-invoked when user mentions UI, UX, design, layout, homepage, page improvements, visual changes, or interface modifications. Use when this capability is needed.
-
tomevault-io Bundle Memory Dream ReviewAudit ClawXMemory memory quality with a read-only Dream pass over current file memories and the global profile. Use when this capability is needed.
-
tomevault-io Bundle Docs AuditMulti-file mode - creates .pack/reports/{timestamp}-docs-audit-{sessionShort}/ directory Use when this capability is needed.
-
tomevault-io Bundle Substitute EraserThis skill should be used when the user asks to "scan for TODOs", "find placeholders", "clean up stubs", "remove temporary code", "audit for incomplete code", or "erase substitutions from codebase". Scans existing files for placeholder tokens and generates remediation plan. Use when this capability is needed.
-
tomevault-io Bundle Tizen Cve ScannerScans for known Tizen CVEs in app dependencies and kernel. Checks OpenCVE database and Samsung security updates. Use when this capability is needed.
-
tomevault-io Bundle Rianico Harness Zkx Code ReviewCode Review (Semantic Audit)
-
tomevault-io Bundle Codeql ScanExecute CodeQL security scans with language detection, database caching, and SARIF output. Use when performing static security analysis on Python or GitHub Actions code. Use when this capability is needed.
-
tomevault-io Bundle Romainsimon Paperasse PaperasseAudit CAC — Validation des Comptes Annuels
-
tomevault-io Bundle Agentic LegibilityScore a repository's agentic legibility from repo-visible evidence only. Use when Codex needs to audit how easy a codebase is for coding agents to discover, bootstrap, validate, and navigate, especially for harness-engineering reviews, developer-experience audits, repo cleanup, or before/after comparisons after improving docs, tooling, or architectural constraints. Use when this capability is needed.
-
tomevault-io Bundle Testing SecurityBasic security testing (OWASP, auth, data exposure) Use when this capability is needed.
-
tomevault-io Bundle Variant AnalysisFind similar vulnerabilities and bugs across codebases using pattern-based analysis. Use when hunting bug variants, building CodeQL/Semgrep queries, analyzing security vulnerabilities, or performing systematic code audits after finding an initial issue. Use when this capability is needed.
-
tomevault-io Bundle Agents Md ManagerAudit, generate, update, and lint AGENTS.md files across all projects. Use when asked to check project context files, scaffold AGENTS.md for new projects, update stale ones, or run a cross-project audit. Use when this capability is needed.
-
tomevault-io Bundle Call CursorInvoke the Cursor CLI for security-focused plan validation and code review. Use when this capability is needed.
-
tomevault-io Bundle Florianbuetow Claude Code HardenSecurity Hardening
-
tomevault-io Bundle Florianbuetow Claude Code StatusAppSec Status -- Security Dashboard
-
tomevault-io Bundle Crypto Best PracticesImplement strong encryption, secure hashing, and proper key management following NIST and OWASP cryptography guidelines Use when this capability is needed.
-
tomevault-io Bundle Repo AuditV1.0 - Audits repositories for documentation/reality drift, stale artifacts, unused config, and cross-reference accuracy. Use when verifying repository health. Use when this capability is needed.
-
tomevault-io Bundle API SecurityAPI security specialist. Use for securing APIs, implementing authentication/authorization, protecting against OWASP API Top 10, or handling security best practices. Use when this capability is needed.
-
tomevault-io Bundle Complex SkillUse when working with a complex but safe skill for project scaffolding
-
tomevault-io Bundle Audit FixFix security audit findings with a test-first approach Use when this capability is needed.
-
tomevault-io Bundle Snyk Studio Recipes Iac SecurityInfrastructure as Code Security
-
tomevault-io Bundle Security EngineerResponsible for security audits, vulnerability assessments, and secure coding practices. Use when this capability is needed.
-
tomevault-io Bundle Thirdlf03 Ccpeek Security ReviewSecurity Review Checklist
-
tomevault-io Bundle Token SecurityToken security audit via GoPlus API Use when this capability is needed.
-
tomevault-io Bundle Security PatternsUse when working with Electron - IPC security, renderer isolation, Node API access
-
tomevault-io Bundle Vulnerability ValidationValidate security findings for exploitability, reachability, and real-world impact using Bug Hunter-native findings artifacts. Use after security scans, before patch generation, or whenever the user wants confirmation that a suspected vulnerability is actually exploitable. Use when this capability is needed.
-
tomevault-io Bundle Claude MdManages CLAUDE.md files. Audits, reviews, improves, refactors, updates, and generates subdirectory context. Discovers all CLAUDE.md files, evaluates quality against research-backed criteria, generates improvement reports, applies targeted updates, syncs CLAUDE.md with current codebase state, restructures using progressive disclosure, and creates contextual CLAUDE.md files for directories that benefit from instant context. Use when the user says "audit CLAUDE.md", "review my rules", "improve instructions", "organize Claude config", "update CLAUDE.md", "sync my rules", "init project", "generate subdirectory context", or "CLAUDE.md maintenance".
-
tomevault-io Bundle IOS KitStartup runbook for iOS projects. Establishes stack decisions, scaffolds the project, configures GitHub security, and confirms governing constraints. Use when this capability is needed.
-
tomevault-io Bundle IOS SecSecurity policy for iOS apps. Enforces OWASP Top 10, Mobile Top 10, and CWE Top 25 mitigations. Use when this capability is needed.
-
tomevault-io Bundle Bug BountyAutomated bug bounty hunting swarm. Runs security scans against authorized programs on HackerOne/Bugcrowd, generates vulnerability reports, and tracks submissions. ONLY targets authorized programs with explicit scope. Use when this capability is needed.
-
tomevault-io Bundle Ghostsecurity Skills Scan DepsGhost Security SCA Scanner — Orchestrator
-
tomevault-io Bundle Indoor47 Memfun Security AuditSecurity Audit
-
tomevault-io Bundle The FoolUse when challenging ideas, plans, decisions, or proposals using structured critical reasoning. Invoke to play devil's advocate, run a pre-mortem, red team, or audit evidence and assumptions.
-
tomevault-io Bundle Ftm GitSecret scanning and credential safety gate for git operations. Prevents API keys, tokens, passwords, and other secrets from ever being committed or pushed to remote repositories. Scans staged files, working tree, and git history for hardcoded credentials using regex pattern matching, then auto-remediates by extracting secrets to gitignored .env files and replacing hardcoded values with env var references. Use when user says "scan for secrets", "check for keys", "audit credentials", "ftm-git", "secret scan", "remove api keys", "check before push", or any time git commit/push operations are about to happen. Also auto-invoked by ftm-executor and ftm-mind before any commit or push operation. Even if the user just says "commit this" or "push to remote", this skill MUST run first. Do NOT use for general git workflow operations like branching or merging — that's git-workflow territory. This skill is specifically the security gate. Use when this capability is needed.
-
tomevault-io Bundle Tzurot Arch AuditArchitecture health audit. Invoke with /tzurot-arch-audit to run static analysis, check boundaries, and assess code health. Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include unity-shared, ui-ux-audit, memory-dream-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.