Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Security GuardSecurity specialist - finds vulnerabilities and ensures best practices Use when this capability is needed.
-
tomevault-io Bundle System AuditorExpert system auditing for security, performance, and infrastructure health. Focuses on vulnerability scanning, resource bottleneck identification, log anomaly detection, and best practice compliance. Use when this capability is needed.
-
tomevault-io Bundle Ghdebug XDebug and fix iOS Swift/ObjC bugs with Morph-X blueprint, transform, audit, and memory fingerprinting to reduce template-code repetition risk. Use when this capability is needed.
-
tomevault-io Bundle Convex Security AuditDeep security review patterns for authorization logic, data access boundaries, action isolation, rate limiting, and protecting sensitive operations Use when this capability is needed.
-
tomevault-io Bundle Convex Security CheckQuick security audit checklist covering authentication, function exposure, argument validation, row-level access control, and environment variable handling Use when this capability is needed.
-
tomevault-io Bundle Creating DevcontainersCreate and review DevContainer configurations that follow organisational standards. Use when a user asks to set up a dev container, configure a development environment, create a devcontainer.json, add lifecycle hooks, review an existing DevContainer for compliance, or improve container security. Covers base images, features, extensions, lifecycle hooks, and security hardening. Use when this capability is needed.
-
tomevault-io Bundle Winbda Claude Skills Collection CI CD Securityci-cd-security
-
tomevault-io Bundle Fstrent Code ReviewerComprehensive code review following company standards with focus on security, performance, maintainability, and best practices Use when this capability is needed.
-
tomevault-io Bundle Architecture AuditUse when asked to audit, evaluate, or understand a codebase's architecture. Covers structure, patterns, coupling, cohesion, and architectural drift. Use after codebase-mapping for full context.
-
tomevault-io Bundle Camilooscargbaptista Cto Toolkit GRAPHQL ReviewGraphQL Design & Security Review
-
tomevault-io Bundle Axiom App Store SubmissionUse when preparing ANY app for App Store submission, responding to App Review rejections, or running a pre-submission audit. Covers privacy manifests, metadata requirements, IAP review, account deletion, SIWA, age ratings, export compliance, first-time developer setup.
-
tomevault-io Bundle Ckorhonen Claude Skills Security Best PracticesSecurity Best Practices
-
tomevault-io Bundle Claude Dev Suite Claude Dev Suite Java SecurityJava Security - Quick Reference
-
tomevault-io Bundle Claude Dev Suite Claude Dev Suite Rust SecurityRust Security - Quick Reference
-
tomevault-io Bundle Dc Cube DefinitionCreate and configure Drizzle Cube semantic layer cube definitions with proper security context, measures, dimensions, and joins. Use when this capability is needed.
-
tomevault-io Bundle Backend Code ReviewConducts comprehensive backend code reviews including API design (REST/GraphQL/gRPC), database patterns, authentication/authorization, caching strategies, message queues, microservices architecture, security vulnerabilities, and performance optimization for Node.js, Python, Java, Go, and C#. Produces detailed review reports with specific issues, severity ratings, and actionable recommendations. Use when reviewing server-side code, analyzing API implementations, checking database queries, validating authentication flows, assessing microservices architecture, or when users mention "review backend code", "check API design", "analyze server code", "validate database patterns", "security audit", "performance review", or "backend code quality". Use when this capability is needed.
-
tomevault-io Bundle Isms Audit ExpertSenior ISMS Audit Expert for internal and external information security management system auditing. Provides ISO 27001 audit expertise, security audit program management, security control assessment, and compliance verification. Use for ISMS internal auditing, external audit preparation, security control testing, and ISO 27001 certification support. Use when this capability is needed.
-
tomevault-io Bundle Linear ImplementThis skill should be used when implementing features from Linear issues with full TDD workflow, automated planning, parallel code reviews (security and Rails best practices), systematic feedback implementation, and automated PR creation with Linear integration. Use when the user provides a Linear issue ID (e.g., "TRA-9", "DEV-123") and wants a complete implementation workflow from issue to PR. Use when this capability is needed.
-
tomevault-io Bundle Tapanshah Ads Audit Claude Ads GenerateAds Generate — AI Ad Image Generator
-
tomevault-io Bundle Code Hardcode AuditDetect hardcoded values, magic numbers, and leaked secrets. TRIGGERS - hardcode audit, magic numbers, PLR2004, secret scanning. Use when this capability is needed.
-
tomevault-io Bundle Recursive Review BundleUse when recursive-mode work needs a canonical delegated-review or audit handoff. Generates reproducible review bundles for Phase 3.5 code review, test review, or other delegated checks using the repo review-bundle scripts.
-
tomevault-io Bundle Secret CodeRetrieve a secret code by reading a bundled asset file and executing a companion script. Use when the user asks to reveal, decode, or look up the secret code from this skill's assets. Use when this capability is needed.
-
tomevault-io Bundle Dockerfile PatternsCore Dockerfile best practices including multi-stage builds, layer caching, security hardening, base image selection, and language-specific patterns for Python, Node, Rust, R, Go, Julia, and C/C++. Use when this capability is needed.
Audited -
tomevault-io Bundle Wesselgrift Sveltekit Spa Sveltekit SpaSecurity Review — SvelteKit SPA + Supabase
-
tomevault-io Bundle Profsynapse Pact Plugin Pact Security PatternsPACT Security Patterns
-
tomevault-io Bundle Secdevai ReviewPerform AI-powered security code review using OWASP Top 10, CWE/SANS Top 25, and WSTG patterns. Use when reviewing source code, specific files, git commits, or entire codebases for security vulnerabilities. Supports web and non-web code (C/C++, Go, Rust, etc.), multi-language analysis, severity classification, and automated finding validation via subagent. Use when this capability is needed.
-
tomevault-io Bundle Java 21 To 25 MigrationMigrate a Java project from JDK 21 to JDK 25 (latest LTS, September 2025). Covers build configuration, Dockerfiles, CI pipelines, breaking changes, removed APIs, dependency compatibility, source code modernization with Java 22-25 language features, AOT cache, performance validation, security hardening, and test verification. Use when upgrading Java version from 21 to 25. Use when this capability is needed.
-
tomevault-io Bundle Fastapi ValidateScan a FastAPI project for Pydantic v1 leftovers, async anti-patterns, missing response models, database session issues, and security gaps. Use when this capability is needed.
-
tomevault-io Bundle Ruskibeats T1d Fastapi Endpoint Security AuditFastAPI Endpoint Security Audit
-
tomevault-io Bundle Move AuditorSecurity audit of Sui Move contracts while you develop. Trigger on "audit", "check this contract", "review for security". Modes - default (full repo), DEEP (+ Sui protocol analysis), or a specific filename. Use when this capability is needed.
-
tomevault-io Bundle API Security HardeningREST API security hardening with authentication, rate limiting, input validation, security headers. Use for production APIs, security audits, defense-in-depth, or encountering vulnerabilities, injection attacks, CORS issues. Use when this capability is needed.
-
tomevault-io Bundle Security StandardsSecurity best practices for application development. Use when handling user input, authentication, secrets, or reviewing code for vulnerabilities. Use when this capability is needed.
-
tomevault-io Bundle Physical Design SecurityUse when reviewing physical implementation security for power domain coupling, timing-related leakage, clock domain crossing issues, and layout-level information exposure. Covers DPA/SPA resistance, EM emanation, fault injection countermeasures, and probing defenses. Do not use for RTL logic review (use rtl-security-review) or microarchitectural attack analysis (use microarch-analysis).
-
tomevault-io Bundle Elixir Security ReviewReviews Elixir code for security vulnerabilities including code injection, atom exhaustion, and secret handling. Use when reviewing code handling user input, external data, or sensitive configuration. Use when this capability is needed.
-
tomevault-io Bundle Foolhardy45 Portfolio Security Bluebook Builder---
-
tomevault-io Bundle Inclusion AuditComprehensive inclusion analysis of code, examining language, internationalization, assumptions, and who might be excluded. Thorough review for releases or major features. Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-guard, system-auditor, ghdebug-x. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.