Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Florianbuetow Claude Code GlossaryAppSec Glossary -- Security Term Reference
-
tomevault-io Bundle Anajuliabit Memoclaw Skill Memoclaw<security>
-
tomevault-io Bundle Emergency Release WorkflowEmergency release workflow for critical bug fixes and security patches. Use when production issues require fast-track deployment. Use when this capability is needed.
-
tomevault-io Bundle Bostonaholic Rpikit Security ReviewSecurity Review Methodology
-
tomevault-io Bundle Byterover ReviewReview code changes against stored conventions, patterns, and architecture decisions. Checks staged changes or specific files for convention violations, pattern mismatches, missing tests, and security concerns. Curates newly discovered patterns. Use when this capability is needed.
-
tomevault-io Bundle OnvifscanONVIF device security scanner for testing authentication and brute-forcing credentials. Use when you need to assess security of IP cameras or ONVIF-enabled devices. Use when this capability is needed.
-
tomevault-io Bundle Querying Gpt52Queries GPT-5.2 for high-reasoning code analysis, root-cause bug fixing, and complex coding questions. Provides P0-P3 prioritized analysis reports, architecture audits, and security reviews with configurable reasoning effort (none/low/medium/high/xhigh). 400K context, 128K output. Use when this capability is needed.
-
tomevault-io Bundle Wheels DeploymentConfigure Wheels applications for production deployment with security hardening, performance optimization, and environment-specific settings. Use when preparing for production, configuring servers, or hardening security. Use when this capability is needed.
-
tomevault-io Bundle Remediation LibraryIndex of security remediation skills. Routes to specialized skills for injection, cryptography, authentication, and configuration vulnerabilities. Use when this capability is needed.
-
tomevault-io Bundle Django DeveloperExpert Django developer mastering Django 4+ with modern Python practices. Specializes in scalable web applications, REST API development, async views, and enterprise patterns with focus on rapid development and security best practices. Use when this capability is needed.
-
tomevault-io Bundle Ads CreativeCross-platform creative quality audit covering ad copy, video, image, and format diversity across all platforms. Detects creative fatigue, evaluates platform-native compliance, and provides production priorities. Use when user says creative audit, ad creative, creative fatigue, ad copy, ad design, or creative review. Use when this capability is needed.
-
tomevault-io Bundle Gopherguides Gopher AI Go Code AuditGo Code Audit
-
tomevault-io Bundle Gopherguides Gopher AI Go Lint AuditGo Lint Audit
-
tomevault-io Bundle Manage Github IssuesReviews project roadmaps and requirements to generate, audit, and triage GitHub Issues. Keeps any project on track by syncing planning docs with actionable issues. Use when creating issues for a phase or milestone, auditing existing issues, or triaging and prioritizing open work. Use when this capability is needed.
-
tomevault-io Bundle Security Alert MonitorScans email threads for security alert signals — phishing reports, suspicious login notifications, data breach mentions, policy violation flags, vulnerability disclosures, and any language suggesting a security incident may be developing. Use when an IT security team wants an early warning scan across their email communications. Triggers on "security alerts", "security incidents from email", "phishing reports", "suspicious activity", "security signal scan", "what security issues are brewing". Use when this capability is needed.
-
tomevault-io Bundle Code Review ChecklistSystematic code review with quality gates, security audit, and parallel checks. Use for structured feedback on pull requests. Use when this capability is needed.
-
tomevault-io Bundle Sv DevDevelopment workflow for Security Verifiers. Use when asked to run tests, lint code, format files, set up the development environment, or perform CI checks on the codebase. Use when this capability is needed.
-
tomevault-io Bundle PHP Code ReviewComprehensive PHP code review with security analysis, performance optimization, and PSR-12 compliance checking for PHP7/PHP8 projects Use when this capability is needed.
-
tomevault-io Bundle LighthouseWeb performance audit with Google Lighthouse Use when this capability is needed.
-
tomevault-io Bundle Align ArchitectureAudit the codebase against AGENTS.md architecture rules, identify discrepancies, and fix them. Use when verifying hexagonal architecture compliance, code conventions, test quality, dependency direction, package configuration, or documentation sync after changes. Use when this capability is needed.
-
tomevault-io Bundle UI IntegrationThis skill should be used when the user asks to "add server action", "implement Supabase query", "connect to backend", "add database integration", "implement RLS", "use server actions", "add data mutation", "implement CRUD operations", "revalidate path", "add authentication check", or needs guidance on server-side integration, defense-in-depth security, or type-safe database queries with Supabase. Use when this capability is needed.
-
tomevault-io Bundle Exploit XssCross-site scripting (XSS) vulnerability detection and exploitation. Supports reflected XSS, stored XSS, DOM-based XSS, and blind XSS testing. Use this skill when user mentions XSS, cross-site scripting, script injection, or needs to test JavaScript injection in parameters, forms, headers, or DOM sources. Use when this capability is needed.
-
tomevault-io Bundle Codex AuditUse Codex CLI for sandboxed auditing, debugging, and autonomous prototyping Use when this capability is needed.
-
tomevault-io Bundle Platform AuditUse when auditing a feature or implementation against platform-specific guidelines such as iOS HIG, Material Design 3, and WCAG. Covers compliance scoring, violation identification, remediation steps, and App Store risk assessment. Do not use for navigation architecture (use navigation-design) or hardware API integration (use device-integration).
-
tomevault-io Bundle Elastic Cursor Plugins Cursor PluginsElasticsearch Security Troubleshooting
-
tomevault-io Bundle Pump TestingMulti-language test infrastructure for the Pump SDK — Rust unit/integration/security/performance tests, TypeScript Jest tests, Python fuzz tests, shell test orchestration, Criterion benchmarks, and CI quality gates. Use when this capability is needed.
-
tomevault-io Bundle Plamentsv Plamen Rust Unsafe AuditInjectable Skill: Rust Unsafe Audit
-
tomevault-io Bundle Counter SurveillanceAssess and harden operational security (OPSEC) posture for applications, communications, and infrastructure. Identifies surveillance exposure, metadata leakage, and tracking vectors. Use when auditing privacy-sensitive applications, reviewing OPSEC for threat models involving state-level adversaries, or hardening communications infrastructure. Use when this capability is needed.
-
tomevault-io Bundle Entry Point AnalyzerAnalyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state, categorizes them by access level (public, admin, role-restricted, contract-only), and generates structured audit reports. Excludes view/pure/read-only functions. Use when auditing smart contracts (Solidity, Vyper, Solana/Rust, Move, TON, CosmWasm) or when asked to find entry points, audit flows, external functions, access control patterns, or privileged operations.
-
tomevault-io Bundle Plurigrid Asi Osint Exposure AuditOSINT Exposure Audit
-
tomevault-io Bundle Semgrep Rule CreatorCreate custom Semgrep rules for detecting bug patterns and security vulnerabilities. This skill should be used when the user explicitly asks to "create a Semgrep rule", "write a Semgrep rule", "make a Semgrep rule", "build a Semgrep rule", or requests detection of a specific bug pattern, vulnerability, or insecure code pattern using Semgrep. Use when this capability is needed.
-
tomevault-io Bundle Discover SecurityAutomatically discover security skills when working with authentication, authorization, input validation, security headers, vulnerability assessment, or secrets management. Activates for application security, OWASP, and security hardening tasks. Use when this capability is needed.
-
tomevault-io Bundle Civmc AuditAudit rosegold.cr against CivMC server rules Use when this capability is needed.
-
tomevault-io Bundle Upgrade Dear Imgui StackUse when a user asks to upgrade Dear ImGui, cimgui, ImPlot, ImPlot3D, ImNodes, ImGuizmo, Dear ImGui Test Engine, or related bindings in this repository. Refresh submodules, regenerate pregenerated native/WASM bindings, audit safe Rust API and backend shim changes, update examples/docs/changelog/versioning, and validate release readiness.
-
tomevault-io Bundle Electron SkillsElectron patterns for LlamaFarm Desktop. Covers main/renderer processes, IPC, security, and packaging. Use when this capability is needed.
-
tomevault-io Bundle Auth PatternsUse when implementing authentication (JWT, sessions, OAuth), authorization (RBAC, ABAC), password hashing, MFA, or security best practices for backend services.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include florianbuetow--claude-code--glossary, anajuliabit--memoclaw-skill--memoclaw, emergency-release-workflow. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.