Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Wow API Social ChatComplete reference for WoW Retail Chat, Social, Club/Community, Friend List, Voice Chat, BattleNet, Ping, Social Queue, and Addon Messaging APIs. Covers C_ChatInfo, C_Club, C_ClubFinder, C_FriendList, C_BattleNet, C_VoiceChat, C_SocialRestrictions, C_SocialQueue, C_RecentAllies, C_PingManager, C_TTSSettings, ChatFrame functions, chat filters, addon message system, and 12.0.0 instance restrictions (SendAddonMessage blocked, chat messages may be secret). Use when working with chat output, chat channels, communities, friend lists, voice chat, BattleNet friends, addon communication, social features, or ping system. Use when this capability is needed.
-
tomevault-io Bundle Seclens Enterprise WebProfessional web application and API security testing workflows using OWASP Top 10 methodologies. Use when this capability is needed.
-
tomevault-io Bundle Doc Audit Product SpecAudit product-spec.md and product-spec-zh.md for bilingual consistency, ensuring EN/ZH versions are mutual translations with identical feature descriptions, technical specs, and business logic. Use when this capability is needed.
-
tomevault-io Bundle Substantive TestingRun substantive attribute testing on audit samples. Use this when the user wants to create a test type, define attributes, upload supporting documents, execute tests against transaction samples, and export results to a local workbook. Use when this capability is needed.
-
tomevault-io Bundle Python Logging Best PracticesPython logging with loguru, structlog, and orjson. TRIGGERS - loguru, structlog, structured logging, JSONL logs, log rotation, secret redaction, OTel logging, lightweight logging, print logging, systemd logging. Use when this capability is needed.
-
tomevault-io Bundle Flutter Rebuild AuditAudit a Flutter widget tree for unnecessary rebuilds. Use when user reports janky scrolling in Flutter, mentions performance, asks "why is this rebuilding," or after [PERF] mode flags rebuild count. Use when this capability is needed.
-
tomevault-io Bundle Fix Security PrFix a PR that is failing due to security or vulnerability issues — npm/pnpm/yarn/bun audit failures, CVE alerts, Dependabot merge conflicts, Snyk failures, or GitHub security advisory blocks. Use when asked to 'fix the security PR', 'resolve the vulnerability failure', or 'unblock the Dependabot PR'. Use when this capability is needed.
-
tomevault-io Bundle Software Code ReviewSystematic code review patterns and checklists. Use when reviewing PRs or diffs for correctness, security, readability, and maintainability. Use when this capability is needed.
-
tomevault-io Bundle Agency Report PDFUnified PDF report generator — combines all audit scores into a professional client-ready PDF Use when this capability is needed.
-
tomevault-io Bundle Krammesiwspec AuditAudit specification documents for quality — coherence, completeness, clarity, scope, actionability, testability, value proposition, and technical design. Catches spec issues before implementation begins. Supports inline report output with --inline. Use when this capability is needed.
-
tomevault-io Bundle Solidity Style GuideApply the Aboudjem/solidity-style-guide rules to Solidity code — review, rewrite, or audit for naming, layout, formatting, NatSpec, custom errors, ERC-7201 storage, gas patterns, and Foundry test structure. Trigger when the user asks to "review Solidity style", "apply the style guide", "format .sol file", or mentions Solhint / Prettier / Foundry conventions in a Solidity repo. Use when this capability is needed.
-
tomevault-io Bundle Security ProcessesUse when defining or enforcing cross-language security processes including SCA, SBOM/container scanning, SAST strategy, dependency update governance, release gates, and exception handling.
-
tomevault-io Bundle Michaelalber AI Toolkit Security Review FederalSecurity Review — Federal Overlay
-
tomevault-io Bundle Audit EntriesAudits all existing entries in the awesome-playwright README for staleness, broken links, abandoned projects, or superseded tools. Recommends removals with evidence. Use when user says "audit entries", "audit list", "clean up list", "check existing entries", or "prune list". Use when this capability is needed.
-
tomevault-io Bundle Peopleforrester Claude Dotfiles Django SecurityDjango Security Patterns
-
tomevault-io Bundle Supabase Expert ReviewExpert Supabase audit and production-readiness reviewer. Covers RLS policies, auth configuration, storage buckets, schema/migrations, edge functions, performance, and environment setup. Uses safe-by-default CLI helpers (anon/user context unless explicitly admin). Produces an actionable risk register and prioritized fixes. Use when this capability is needed.
-
tomevault-io Bundle Aj Geddes Useful AI Prompts API Security HardeningAPI Security Hardening
-
tomevault-io Bundle Aj Geddes Useful AI Prompts Security DocumentationSecurity Documentation
-
tomevault-io Bundle Administering LinuxManage Linux systems covering systemd services, process management, filesystems, networking, performance tuning, and troubleshooting. Use when deploying applications, optimizing server performance, diagnosing production issues, or managing users and security on Linux servers. Use when this capability is needed.
-
tomevault-io Bundle Vercel Security AccessVercel security and access controls including RBAC, SSO, deployment protection, firewall, bot defense, audit logs, and 2FA. Use when securing Vercel projects or managing access. Use when this capability is needed.
-
tomevault-io Bundle Review Specific PrPerform a comprehensive code review of a specific GitHub Pull Request. Analyzes code changes, checks for bugs, security issues, test coverage, and coding standards compliance. Use when a user provides a PR URL or asks to review a specific pull request. Use when this capability is needed.
-
tomevault-io Bundle Symfonyapi Platform SecurityDeliver robust API Platform contracts in Symfony with explicit operations, mapping, and policy-safe behavior. Use for api platform security tasks. Use when this capability is needed.
-
tomevault-io Bundle Test Case GeneratorGenerates comprehensive, high-quality test cases for any domain or scenario. Covers positive, negative, edge-case, and security scenarios across UI, API, and Integration levels. Includes all essential attributes like Priority, Pre-conditions, and Expected Results.
-
tomevault-io Bundle Audit HooksAudit Claude Code hooks for quality, compliance, and maintainability. Use after creating hooks, before releases, or for periodic quality checks. Use when this capability is needed.
-
tomevault-io Bundle Audit LayerAudit a codebase for agentic layer coverage and identify investment opportunities. Use to assess agentic maturity and find gaps. Use when this capability is needed.
-
tomevault-io Bundle Audit RulesAudit Claude Code rule files for quality and compliance. Use when creating or validating .claude/rules/*.md files, or troubleshooting rule loading issues. Use when this capability is needed.
-
tomevault-io Bundle Multiversx Code AnalysisComprehensive code analysis toolkit for MultiversX smart contracts. Covers differential review (version comparison, upgrade safety), fix verification (validate patches, regression testing), and variant analysis (find similar bugs across codebase). Use when reviewing PRs, verifying security patches, or hunting for bug variants. Use when this capability is needed.
-
tomevault-io Bundle Security Testing PatternsSecurity testing patterns including SAST, DAST, penetration testing, and vulnerability assessment techniques. Use when implementing security testing pipelines, conducting security audits, or validating application security controls. Use when this capability is needed.
-
tomevault-io Bundle Github Issue Templates ApplyApply the canonical-language file under spec/project/github-issue-templates/ to a target repository — detect the project type, resolve or dispatch the audience artefact, derive triage questions, and scaffold or update .github/ISSUE_TEMPLATE/ (bug_report.yml, feature_request.yml, config.yml, plus project-type-specific extras) as GitHub Issue Forms. Invoke when the user asks to "generate issue templates for this repo", "scaffold GitHub issue forms", "create bug and feature templates", "set up .github/ISSUE_TEMPLATE", "apply the github-issue-templates spec", or equivalent German-language requests. Don't use for pull-request templates (that's `pull-request-workflow`), CODEOWNERS / SECURITY.md, discussion templates, or generic .github/ scaffolding (that's `project-structure-apply`). Supports resume on re-invocation per `spec/claude/resumable-work/`. Use when this capability is needed.
-
tomevault-io Bundle Omer Metin Skills For Antigravity Security Owasp---
-
tomevault-io Bundle Hunt Research System And TradecraftResearch system internals and adversary tradecraft to ground a threat hunt in real system behavior and realistic abuse patterns. Use this skill at the start of hunt planning, when you are given a high-level hunt topic but lack a clear understanding of how the system normally operates or how adversaries are known to abuse it. This skill informs early hunt direction by producing candidate abuse patterns, key assumptions, and cited sources, and should be used before defining a concrete hunt hypothesis or selecting data sources. Use when this capability is needed.
-
tomevault-io Bundle Webhook Receiver HardenerSecures webhook receivers with signature verification, retry handling, deduplication, idempotency keys, and error responses. Provides verification code, dedupe storage strategy, runbook for incidents. Use when implementing "webhooks", "webhook security", "event receivers", or "third-party integrations". Use when this capability is needed.
-
tomevault-io Bundle Security Requirement ExtractionDerive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases. Use when this capability is needed.
-
tomevault-io Bundle Falco Runtime SecurityFalco Runtime Security
-
tomevault-io Bundle Bash Script ValidatorValidate, lint, audit, or fix bash/shell/.sh scripts via ShellCheck. Use when this capability is needed.
-
tomevault-io Bundle Jenkinsfile ValidatorValidate, lint, audit, or check Jenkinsfiles and shared libraries. Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include wow-api-social-chat, seclens-enterprise-web, doc-audit-product-spec. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.