Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Github Agentic Workflows Tools EcosystemComprehensive guide for all available tools including GitHub, file operations, web, bash, playwright, tool capabilities and limitations, integration patterns, custom tool development, security considerations, and usage examples Use when this capability is needed.
-
tomevault-io Bundle Hakal Team Skills Security Audit MethodologySecurity Audit Methodology
-
tomevault-io Bundle Ldap Injection Anti PatternSecurity anti-pattern for LDAP injection vulnerabilities (CWE-90). Use when generating or reviewing code that constructs LDAP filters, queries directory services, or handles user input in LDAP operations. Detects unescaped special characters in LDAP filters. Use when this capability is needed.
-
tomevault-io Bundle OAUTH Security Anti PatternSecurity anti-pattern for OAuth implementation vulnerabilities (CWE-352, CWE-287). Use when generating or reviewing OAuth/OIDC authentication flows, state parameter handling, or token exchange. Detects missing CSRF protection and insecure redirect handling. Use when this capability is needed.
-
tomevault-io Bundle Padding Oracle Anti PatternSecurity anti-pattern for padding oracle vulnerabilities (CWE-649). Use when generating or reviewing code that decrypts CBC-mode ciphertext, handles decryption errors, or returns different errors for padding vs other failures. Detects error message oracles. Use when this capability is needed.
-
tomevault-io Bundle Path Traversal Anti PatternSecurity anti-pattern for path traversal vulnerabilities (CWE-22). Use when generating or reviewing code that handles file paths, reads or writes files based on user input, or serves static content. Detects joining user input to paths without proper sanitization or validation. Use when this capability is needed.
-
tomevault-io Bundle Timing Attacks Anti PatternSecurity anti-pattern for timing side-channel vulnerabilities (CWE-208). Use when generating or reviewing code that compares secrets, tokens, passwords, or cryptographic values. Detects early-exit comparisons that leak information through timing differences. Use when this capability is needed.
-
tomevault-io Bundle Type Confusion Anti PatternSecurity anti-pattern for type confusion vulnerabilities (CWE-843). Use when generating or reviewing code in dynamic languages that compares values, processes JSON/user input, or uses loose equality. Detects weak typing exploits and type coercion attacks. Use when this capability is needed.
Audited -
tomevault-io Bundle Mdproctor Cc Praxis Security Audit PrinciplesSecurity Audit Principles
-
tomevault-io Bundle Chrome Extension DevelopmentExpert guidelines for Chrome extension development with Manifest V3, covering security, performance, and best practices Use when this capability is needed.
-
tomevault-io Bundle Grc KnowledgeSenior GRC analyst expertise across 15 compliance frameworks — NIST 800-53, FedRAMP, FISMA, CMMC, SOC 2, ISO 27001, PCI DSS, HIPAA, CIS Controls, COBIT, CSA CCM, GDPR, SLSA, OSCAL. Control lookups, cross-framework mapping, document review, audit prep, and operational compliance workflows. Use when this capability is needed.
-
tomevault-io Bundle Full Stack ReviewerComplete codebase audit combining code review, Prisma query optimization, and TypeScript analysis with intelligent routing. Use when asked for a full project review, complete codebase audit, or comprehensive quality check of a full-stack application. Use when this capability is needed.
-
tomevault-io Bundle Rust ImplementationModern Rust production implementation workflow for greenfield features, refactors, ownership design, trait boundaries, public APIs, error handling, maintainable safe Rust, and dependency-minimal code. Use for day-to-day Rust code changes, not primarily tests, crates, async, security, performance, APIs, CLIs, or databases. Use when this capability is needed.
-
tomevault-io Bundle A04 Insecure DesignSkills for exploiting insecure design patterns including race conditions and parameter pollution per OWASP A04:2021. Use when this capability is needed.
-
tomevault-io Bundle Nginx Config OptimizerOptimizes Nginx configurations for performance, security, caching, and load balancing with modern best practices. Use when users request "Nginx setup", "reverse proxy", "load balancer", "web server config", or "Nginx optimization". Use when this capability is needed.
-
tomevault-io Bundle Quality Gates EnforcerEnforces minimum quality thresholds in CI including code coverage, linting, type checking, and security scanning. Provides required checks, PR rules, and automated enforcement. Use for "quality gates", "CI checks", "code quality", or "PR requirements". Use when this capability is needed.
-
tomevault-io Bundle Vercel Expert ReviewExpert-level audit of Vercel deployments covering security, environment variables, deployment protection, firewall, security headers, observability, and performance readiness. Produces an actionable risk register and prioritized fixes. Use when this capability is needed.
-
tomevault-io Bundle Ripgraphics Authorsinfo Python Security ToolsPython Security Tools
-
tomevault-io Bundle Ghwork XExecute iOS Swift/ObjC work with Morph-X blueprint, transform, audit, and memory fingerprinting to reduce template-code repetition risk. Use when this capability is needed.
-
tomevault-io Bundle X Twitter ScraperPer-callback HMAC secret returned by the signed event delivery API. Use when this capability is needed.
-
tomevault-io Bundle Fluentbit ValidatorValidate, lint, audit, or check Fluent Bit configs (INPUT, FILTER, OUTPUT, tag routing). Use when this capability is needed.
-
tomevault-io Bundle Gitlab CI ValidatorValidate, lint, audit, or fix .gitlab-ci.yml pipelines, stages, and jobs. Use when this capability is needed.
-
tomevault-io Bundle Sentry Find BugsFind bugs and security vulnerabilities in code changes. Use when analyzing branch changes, reviewing diffs, or hunting for defects. Use when this capability is needed.
-
tomevault-io Bundle Windsurf Security BasicsApply Windsurf security best practices for workspace isolation, data Use when this capability is needed.
-
tomevault-io Bundle API Filtering SortingBuilds flexible API filtering and sorting systems with query parameter parsing, validation, and security. Use when implementing search endpoints, building data grids, or creating dynamic query APIs.
-
tomevault-io Bundle Fastapi ProjectScaffold and evolve FastAPI projects with uv-based tooling, structured settings, and production-ready observability, resilience, availability, and security patterns aligned with python.instructions.md. Use when this capability is needed.
-
tomevault-io Bundle Doppler Secret ValidationValidate and test Doppler secrets. TRIGGERS - add to Doppler, store secret, validate token, test credentials. Use when this capability is needed.
-
tomevault-io Bundle Vulnerability ScannerAdvanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization. Use when this capability is needed.
-
tomevault-io Bundle Solidity Security ReviewSmart contract security review methodology. Use when auditing Solidity code, analyzing vulnerabilities, or verifying security findings. Use when this capability is needed.
-
tomevault-io Bundle Ralph Feature BootstrapBootstrap a new Ralph feature pack from a source document. Use when the user asks to set up a new Ralph feature, feature pack, or loop from a document/audit/plan and wants the scaffolding created automatically. Use when this capability is needed.
-
tomevault-io Bundle Spring Boot DevelopmentComprehensive Spring Boot development skill covering auto-configuration, dependency injection, REST APIs, Spring Data, security, and enterprise Java applications Use when this capability is needed.
-
tomevault-io Bundle Review Code ArchitectureReview code changes for architectural consistency, correctness risks, security/performance concerns, and verification gaps; produce a prioritized, actionable review report. Use when this capability is needed.
-
tomevault-io Bundle Env LocalctlBootstrap, diagnose (doctor), and reconcile local dev environment from env contract/values/secret refs; generate .env.local and redacted docs/context/env/effective-*. Use when local env is broken or needs syncing. Use when this capability is needed.
-
tomevault-io Bundle Makefile ValidatorValidate, lint, audit, or check Makefiles and .mk files for errors. Use when this capability is needed.
-
tomevault-io Bundle Qms Audit ExpertISO 13485 internal audit expertise for medical device QMS. Covers audit planning, execution, nonconformity classification, and CAPA verification. Use for internal audit planning, audit execution, finding classification, external audit preparation, or audit program management. Use when this capability is needed.
-
tomevault-io Bundle Mysql PatternsMySQL database patterns for query optimization, schema design, indexing, and security. Quick reference for common patterns. Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include github-agentic-workflows-tools-ecosystem, hakal--team-skills--security-audit-methodology, ldap-injection-anti-pattern. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.