Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Dv SecuritySecurity-role assignment, user access, application users, business units, and admin self-elevation in Dataverse environments. Use when the user wants to give someone access, grant a role, become an admin, or add a service principal. Use when this capability is needed.
-
tomevault-io Bundle Security AnalysisSkills for security analysis including SSL/TLS testing, protocol detection, and evasion techniques. Use when this capability is needed.
-
tomevault-io Bundle Adding New MetricGuides systematic implementation of new sustainability metrics in OSS Sustain Guard using the plugin-based metric system. Use when adding metric functions to evaluate project health aspects like issue responsiveness, test coverage, or security response time. Use when this capability is needed.
-
tomevault-io Bundle PHP Security AuditAudit PHP/Laravel code for authentication gaps and input sanitization vulnerabilities. Use when this capability is needed.
-
tomevault-io Bundle Travisjneuman Claude Application SecurityApplication Security Skill
-
tomevault-io Bundle Truchot Claude Skills Test Security ExpertSecurity Expert Skill
-
tomevault-io Bundle U9401066 Anesthesia Exam Security Reviewer安全性審查技能
-
tomevault-io Bundle Security SpecialistAuditing for unsafe code and secrets. Use when this capability is needed.
-
tomevault-io Bundle SecureUse this skill when the user needs to secure their SaaS app, implement authentication, protect user data, secure APIs, or check for vulnerabilities. Also use when the user says 'is my app secure,' 'security check,' 'I'm worried about hackers,' 'how do I protect user data,' or 'security before launch.' Covers OWASP Top 10, auth best practices, data protection, and security checklists for apps built with AI tools.
-
tomevault-io Bundle Williamzujkowski Standards Threat ModelingThreat Modeling
-
tomevault-io Bundle Web Vuln GRAPHQLGraphQL API security testing including introspection, batching, and authorization bypass Use when this capability is needed.
-
tomevault-io Bundle Pinpoint SecuritySecurity patterns, CSP nonces, input validation, auth checks, Supabase SSR patterns. Use when implementing authentication, forms, security features, or when user mentions security/validation/auth. Use when this capability is needed.
-
tomevault-io Bundle Yellow Seed My Portfolio Reviewing Securityセキュリティレビュー
-
tomevault-io Bundle Wordpress Penetration TestingThis skill should be used when the user asks to "pentest WordPress sites", "scan WordPress for vulnerabilities", "enumerate WordPress users, themes, or plugins", "exploit WordPress vulnerabilities", or "use WPScan". It provides comprehensive WordPress security assessment methodologies. Use when this capability is needed.
-
tomevault-io Bundle Code Security AuditScan application code for OWASP Top 10 vulnerabilities, injection flaws, XSS, CSRF, hardcoded secrets, and unsafe cryptography. Use when this capability is needed.
-
tomevault-io Bundle Popup Studio AI Bkit Claude Code Bkend Authbkend.ai Authentication & Security Guide
-
tomevault-io Bundle Cleanup CodeRefactor and clean up code with structured review gates. Detects language, applies coding standards (Rust, TypeScript, Python), runs simplification and security audit. Primarily used as a sub-step of the polish workflow. Includes DRY analysis, Law of Demeter checks, and YAGNI violation detection. Use when this capability is needed.
-
tomevault-io Bundle Secdevai FixApply suggested security fixes from a prior review. Use when the user wants to remediate security findings with before/after code diffs, severity filtering, and explicit approval before modifying code. Use when this capability is needed.
-
tomevault-io Bundle Codex Agents Md AuthoringAuthor or audit Codex AGENTS.md files, including user-level and project-level instruction scope, plan persistence, large-plan splitting, hierarchy, context budget, and what belongs in skills, rules, hooks, or subagents instead. Use when this capability is needed.
-
tomevault-io Bundle Scrapingbee CLI GuardSecurity monitor for scrapingbee-cli. Monitors audit log for suspicious activity. Stops unauthorized schedules. ALWAYS active when scrapingbee-cli is installed. Use when this capability is needed.
-
tomevault-io Bundle Multi AI ConsultantConsult external AIs (Gemini 2.5 Pro, OpenAI Codex, Claude) for second opinions. Use for debugging failures, architectural decisions, security validation, or need fresh perspective with synthesis. Use when this capability is needed.
-
tomevault-io Bundle Compose Performance AuditAudit and improve Jetpack Compose runtime performance from code review and architecture. Use when asked to diagnose slow rendering, janky scrolling, excessive recompositions, or performance issues in Compose UI. Use when this capability is needed.
-
tomevault-io Bundle Rails Code ReviewRails code review skill following Konvenit guidelines. Use when the user asks to review Rails code, check for best practices, audit controllers/models/views, or wants feedback on their Rails application code. Triggers on phrases like "review my code", "check this controller", "audit my Rails app", "code review", "best practices check". Enforces service objects, presenters, HAML, double quotes, Konvenit-specific patterns, and the LGTM/OLGTM PR workflow. Use when this capability is needed.
-
tomevault-io Bundle Pentest Vuln Verify Test通过原始 HTTP 请求操作和严格验证自动验证 Web 漏洞(开放重定向、XSS)。 Use when this capability is needed.
-
tomevault-io Bundle DB Health CheckRun database security and performance checks and produce a health report. Use when the user asks for db security, performance, or health checks. Use when this capability is needed.
-
tomevault-io Bundle Nestjs Best PracticesNestJS best practices and architecture patterns for building production-ready applications. This skill should be used when writing, reviewing, or refactoring NestJS code to ensure proper patterns for modules, dependency injection, security, and performance. Use when this capability is needed.
-
tomevault-io Bundle Sdd AuditCompare implementation against specifications, identify gaps and issues. Use for code review, quality assurance, and verifying spec compliance. Use when this capability is needed.
-
tomevault-io Bundle Django Security AdvancedAdvanced Django security — file upload validation (extension/size/storage), DRF API security (rate limiting throttles, JWT), Content Security Policy middleware, django-environ secrets management, security event logging, and production deployment checklist. Use when this capability is needed.
-
tomevault-io Bundle Michaelalber AI Toolkit Rust Security ReviewRust Security Review (OWASP Baseline)
-
tomevault-io Bundle Aj Geddes Useful AI Prompts Security TestingSecurity Testing
-
tomevault-io Bundle Alkampfergit Lucifer Gh Security And QualitySkill: GitHub Security and Quality
-
tomevault-io Bundle Technical Debt AuditorSystematic technical debt assessment — scans for security issues, correctness gaps, infrastructure debt, maintainability problems, documentation quality, and dependency freshness Use when this capability is needed.
-
tomevault-io Bundle Swiftui Parity ComponentsImplement and verify SwiftUI API parity for Raven UI components. Use when asked to audit missing or mismatched SwiftUI views/modifiers, add parity components, wire examples into `Examples/TodoApp`, validate rendering in a browser (including dark mode), and prepare branch/PR deliverables. Use when this capability is needed.
-
tomevault-io Bundle Instructions DetoxAudit Copilot instruction files for bloat, overlap, stale rules, and weak applyTo scope. Use when reviewing or refactoring .instructions.md, AGENTS.md, copilot-instructions.md, or SKILL.md files, and produce a prioritized markdown report with findings, line references, and recommended deletions or rewrites. Use when this capability is needed.
-
tomevault-io Bundle Code Quality WorkflowUse when assessing or improving code quality, maintainability, performance, or security hygiene - provides workflows for analysis, code review, and systematic improvements with validation steps.
-
tomevault-io Bundle Ecton1 CheckScan Ecto code for N+1 anti-patterns — Repo calls in loops, missing preloads, unpreloaded associations. Use when excessive queries reported or wanting an N+1 audit. Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include dv-security, security-analysis, adding-new-metric. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.