Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Resonance ReviewerCode Reviewer Specialist. Use this to review PRs, check security, and ensure code quality standards before merging. Use when this capability is needed.
-
tomevault-io Bundle Marvinrichter Clarc Dependency AuditDependency Audit Skill
-
tomevault-io Bundle Ancplua Ancplua Claude Plugins HadesHADES — Smart Cleanup: Functional Destruction with Audit Infrastructure
-
tomevault-io Bundle Sast AnalysisStatic Application Security Testing (SAST) for multi-language codebases. Uses Semgrep and language-specific tools to detect vulnerabilities across Python, JavaScript, TypeScript, Go, Java, and more. Use when this capability is needed.
-
tomevault-io Bundle ClawdstrikeSecurity review for risky code changes Use when this capability is needed.
-
tomevault-io Bundle Mobile SecurityiOS and Android security testing, SSL pinning bypass, and mobile app vulnerabilities. Use when this capability is needed.
-
tomevault-io Bundle Review As DevUse when reviewing a technical analysis, design document, or specification from a developer perspective - checking technical feasibility, architecture, integration points, and performance/security
-
tomevault-io Bundle Javascript ExpertUse when building JavaScript applications with modern ES2024+ features, async patterns, or Node.js development. Invoke for vanilla JavaScript, browser APIs, performance optimization, module systems, security hardening.
-
tomevault-io Bundle Wheels RefactoringRefactor Wheels code for better performance, security, and maintainability. Use when optimizing code, fixing anti-patterns, improving performance, or enhancing security. Provides refactoring patterns and best practices. Use when this capability is needed.
-
tomevault-io Bundle Github Actions ReviewGitHub Actions Workflow code review for correctness, security, and best practices. Use for manual review of workflow files checking design decisions and security patterns requiring human judgment. For detailed category-specific checks, see reference/. Use when this capability is needed.
-
tomevault-io Bundle DocsauditDocumentation consistency and correctness auditing for any codebase. USE WHEN docs audit, docs consistency, obsolete check, documentation scan, check docs for obsolete code, verify documentation accuracy, find stale code references in docs. Use when this capability is needed.
-
tomevault-io Bundle 12 Principles Of AnimationAudit animation code against Disney's 12 principles adapted for web. Use when reviewing motion, implementing animations, or checking animation quality. Outputs file:line findings. Use when this capability is needed.
-
tomevault-io Bundle Code Review JiraUse when performing code review for JIRA issues. Analyzes pull requests, identifies critical and moderate issues, runs tests, and posts review comments to GitHub PRs. Reviews code quality, security, and adherence to project standards.
-
tomevault-io Bundle Audit Context BuildingEnables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.
-
tomevault-io Bundle Constant Time AnalysisDetects timing side-channel vulnerabilities in cryptographic code. Use when implementing or reviewing crypto code, encountering division on secrets, secret-dependent branches, or constant-time programming questions in C, C++, Go, Rust, Swift, Java, Kotlin, C#, PHP, JavaScript, TypeScript, Python, or Ruby. Use when this capability is needed.
-
tomevault-io Bundle Wireless Network AuditAudit wireless networks (WiFi, BLE, Zigbee) for security vulnerabilities using aircrack-ng, bettercap, hcxtools, and bluetooth utilities. For authorized penetration testing and security assessments only. Use when this capability is needed.
-
tomevault-io Bundle Risk AssessorPerform comprehensive risk assessments on OSCAL systems including threat modeling, vulnerability analysis, risk scoring, and POA&M generation. Use this skill to evaluate security posture and prioritize remediation efforts. Use when this capability is needed.
-
tomevault-io Bundle Firebase AuthIntegrates Firebase Authentication into Flutter apps. Use when setting up auth, managing auth state, implementing email/password or social sign-in, handling auth errors, managing users, or applying security best practices.
-
tomevault-io Bundle Protocol ConsistencyAudit consistency across workstream docs, CLI capabilities, and CI workflows. Use when this capability is needed.
-
tomevault-io Bundle Florianbuetow Claude Code Review PlanSecurity Plan Review
-
tomevault-io Bundle Git Repo AuditRun a repeatable git vs non-git audit and report untracked-but-should-track files under .cursor/skills, .cursor/rules, .cursor/agents, and scripts allowlist. Use when the user asks for git audit, repo audit, what's not tracked, or session verify in a git sense. Use when this capability is needed.
-
tomevault-io Bundle Code Review PracticesCode review best practices, quality gates, security checks, and constructive feedback guidelines for collaborative development Use when this capability is needed.
-
tomevault-io Bundle Security ArchitectureSecurity architecture documentation requirements including threat models, security controls, and defense-in-depth patterns Use when this capability is needed.
-
tomevault-io Bundle Codex Code ReviewPerform comprehensive code reviews using OpenAI Codex CLI. This skill should be used when users request code reviews, want to analyze diffs/PRs, need security audits, performance analysis, or want automated code quality feedback. Supports reviewing staged changes, specific files, entire directories, or git diffs. Use when this capability is needed.
-
tomevault-io Bundle Monitoring점검(Audit)과 모니터링(Monitoring)을 통합한 스킬. The_Ark의 구조적 무결성과 논리적 충돌을 주기적으로 진단합니다. Use when this capability is needed.
-
tomevault-io Bundle Audit Better Result DependentsAudit better-result changes or PRs against known Prisma and Better T Stack downstream dependents. Use when working on better-result API/type/runtime changes and the user asks whether a change breaks Prisma dependents, Better T Stack dependents, npm dependents, or PR compatibility. Use when this capability is needed.
-
tomevault-io Bundle Motion DesignUse when designing the motion language for a feature or system. Covers transition specs, micro-interaction definitions, choreography principles, performance constraints, and reduced-motion alternatives. Do not use for visual design critique (use visual-audit) or design token architecture (use design-system-architecture).
-
tomevault-io Bundle Github SecureConfigure GitHub repository security with branch protection, Dependabot, security scanning, and CI workflows. Integrates with mern-scaffold, nean-scaffold, and iOS projects. Use when this capability is needed.
-
tomevault-io Bundle Vercel HardenHarden a Vercel deployment with security headers, CSP, bot protection, and deployment configuration Use when this capability is needed.
-
tomevault-io Bundle Epicweb Dev Epic Stack Epic SecurityEpic Stack: Security
-
tomevault-io Bundle Florianbuetow Claude Code RegressionSecurity Regression Detection
-
tomevault-io Bundle Wordpress ProDevelops custom WordPress themes and plugins, creates and registers Gutenberg blocks and block patterns, configures WooCommerce stores, implements WordPress REST API endpoints, applies security hardening (nonces, sanitization, escaping, capability checks), and optimizes performance through caching and query tuning. Use when building WordPress themes, writing plugins, customizing Gutenberg blocks, extending WooCommerce, working with ACF, using the WordPress REST API, applying hooks and filters, or improving WordPress performance and security. Use when this capability is needed.
-
tomevault-io Bundle Golang ReviewerReviews Go code for idiomatic style, code smells, anti-patterns, and modern best practices. Use when reviewing .go files, inspecting Go changes or PRs, auditing Go packages, or when the user asks to check Go code for quality, bugs, or style. Based on the Uber Go Style Guide with additions for modern Go (generics, context, security, HTTP, docs). Use when this capability is needed.
-
tomevault-io Bundle Kcirtapfromspace Ralph Machineo AuditCodebase Audit
-
tomevault-io Bundle Audit SpecAudit specification documents for ambiguity, consistency, and architectural compliance. Use when this capability is needed.
-
tomevault-io Bundle Senior Code ReviewSenior engineer code review for PRs, diffs, and code snippets focusing on security vulnerabilities, OWASP compliance, performance bottlenecks, maintainability, error handling, and architectural patterns Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include resonance-reviewer, marvinrichter--clarc--dependency-audit, ancplua--ancplua-claude-plugins--hades. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.