Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Geomap VisualizationUse this skill when asked to create geographic maps, visualize attack origins on a world map, show location-based data, or display IP geolocation. Triggers on keywords like "geomap", "world map", "geographic", "attack map", "show on map", "visualize locations", "attack origins", or when analyzing data with latitude/longitude coordinates.
-
tomevault-io Bundle Glab AttestationWork with GitLab attestations for software supply chain security including artifact verification and provenance. Use when verifying software artifacts, managing attestations, or working with supply chain security. Triggers on attestation, verify artifact, provenance, supply chain security. Use when this capability is needed.
-
tomevault-io Bundle Omer Metin Skills For Antigravity Security Hardening---
-
tomevault-io Bundle Code Review CriteriaCode review criteria covering code quality, best practices, bugs, performance, and security concerns. Applied by code review and fix agents. Use when this capability is needed.
-
tomevault-io Bundle Authentication TracingUse this skill when asked to trace authentication flows, analyze SessionId chains, investigate token reuse vs interactive MFA, or assess geographic anomalies in sign-ins. Triggers on keywords like "trace authentication", "trace back to interactive MFA", "SessionId analysis", "token reuse", "geographic anomaly", "impossible travel", or when investigating suspicious sign-in locations. This skill provides forensic analysis of Entra ID authentication chains to distinguish legitimate activity from credential/token theft.
-
tomevault-io Bundle Honeypot InvestigationUse this skill when asked to analyze, investigate, or report on honeypot server security. Triggers on keywords like "honeypot investigation", "analyze honeypot", "honeypot security", "honeypot report", or when a server name is mentioned with honeypot analysis context. This skill provides comprehensive security analysis including attack patterns, threat intelligence correlation, IP enrichment, vulnerability assessment, and executive report generation.
-
tomevault-io Bundle Saas Multi TenantDesign and implement multi-tenant SaaS architectures with row-level security, tenant-scoped queries, shared-schema isolation, and safe cross-tenant admin patterns in PostgreSQL and TypeScript. Use when this capability is needed.
-
tomevault-io Bundle Somnio Software Somnio AI Tools Flutter Health AuditFlutter Project Health Audit - Modular Execution Plan
-
tomevault-io Bundle Project Pull RequestUse when creating, updating, or reviewing a telegram-webapp-auth GitHub Pull Request. Defines dev-targeted branch flow, maintenance-mode constraints, assignee defaults, Conventional-style titles, required PR template sections, test evidence, security notes, and post-create reporting rules.
-
tomevault-io Bundle Compliance FrameworksSecurity and privacy compliance patterns for B2B SaaS (SOC 2, GDPR). Use for audit preparation, control design, compliance gap analysis, or building compliance into features. Use when this capability is needed.
-
tomevault-io Bundle Dependency AuditorCheck dependencies for known vulnerabilities using npm audit, pip-audit, etc. Use when package.json or requirements.txt changes, or before deployments. Alerts on vulnerable dependencies. Triggers on dependency file changes, deployment prep, security mentions. Use when this capability is needed.
-
tomevault-io Bundle Access Audit And ReviewsAccess audits and periodic reviews ensure that users have appropriate Use when this capability is needed.
-
tomevault-io Bundle Technical Writing StyleguideTechnical writing styleguide for clear, consistent documentation. Use when writing, editing, or reviewing technical content, guides, tutorials, or documentation. Triggers on article review, writing style, brand names, grammar check, screenshot guidelines, guide audit, technical docs. Use when this capability is needed.
-
tomevault-io Bundle Brutal Exhaustive AuditUse when you need an absolutely thorough, no-shortcuts, multi-pass audit of the entire product. Covers build verification, route checking, data flow tracing, user flow testing, and edge case validation. Forces file-by-file verification with explicit tracking. Creates an actionable task list. Cannot cut corners.
-
tomevault-io Bundle Brendankowitz Fhirpath Lab Dotnet Wa Security ReviewWell-Architected Security Review
-
tomevault-io Skill API Fuzzing For Bug BountyThis skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques.
-
tomevault-io Bundle Davila7 Claude Code Templates Security Ownership MapSecurity Ownership Map
-
tomevault-io Bundle Credential ManagerMANDATORY security foundation for OpenClaw. Consolidate scattered API keys and credentials into a secure .env file with proper permissions. Use when setting up OpenClaw, migrating credentials, auditing security, or enforcing the .env standard. This is not optional — centralized credential management is a core requirement for secure OpenClaw deployments. Scans for credential files across common locations, backs up existing files, creates a unified .env with mode 600, validates security, and enforces best practices. Use when this capability is needed.
-
tomevault-io Bundle Security Vulnerability AuditWorkflow for auditing security vulnerabilities using Trunk (Trivy and OSV-scanner). Use when checking for project vulnerabilities, hard-coded secrets, or repairing security flaws. Use when this capability is needed.
-
tomevault-io Bundle API Security CheckerAudit API security for OWASP Top 10 vulnerabilities, authentication issues, and authorization flaws. Use when securing APIs, fixing security vulnerabilities, or implementing security best practices. Use when this capability is needed.
-
tomevault-io Bundle A08 Data Integrity FailuresSkills for exploiting software and data integrity failures including HTTP request smuggling per OWASP A08:2021. Use when this capability is needed.
-
tomevault-io Bundle Openclaw Secret Scanning MaintainerTriage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs. Use when this capability is needed.
-
tomevault-io Bundle Security Essentials PackCurated bundle of essential security skills for building secure applications. Includes threat modeling, hardening guides, audit checklists, compliance frameworks, and contract analysis. Use when establishing security practices for a project. Use when this capability is needed.
-
tomevault-io Bundle Ca Policy InvestigationUse this skill when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy bypass/manipulation. Triggers on keywords like "Conditional Access", "CA policy", "device compliance", "policy bypass", "53000", "50074", or when investigating why a user was blocked then suddenly unblocked. This skill provides forensic analysis of CA policy modifications correlated with sign-in failures.
-
tomevault-io Bundle Dependency AuditAudit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns. Use when the user mentions 'dependency audit,' 'npm audit,' 'CVE,' 'vulnerable packages,' 'supply chain security,' 'outdated dependencies,' 'known vulnerabilities,' 'security advisory,' 'package security,' 'framework vulnerability,' 'is this package safe,' or needs to check whether their stack has known security issues. Use when this capability is needed.
-
tomevault-io Bundle Security InitInitialize Claude Code security settings with intelligent file denial patterns based on your project's technology stack. Use when this capability is needed.
-
tomevault-io Bundle Devbooks Convergence Auditdevbooks-convergence-audit:以证据优先、声明存疑的原则评估 DevBooks 工作流收敛性,检测"西西弗斯反模式"和"假完成"。主动验证而非信任文档声明。用户说"评估收敛性/检查升级健康度/西西弗斯检测/工作流审计"等时使用。 Use when this capability is needed.
-
tomevault-io Bundle Django Perf Review V2Django Performance Review workflow skill. Use this skill when the user needs Django performance code review. Use when asked to \"review Django performance\", \"find N+1 queries\", \"optimize Django\", \"check queryset performance\", \"database performance\", \"Django ORM issues\", or audit Django code for performance problems and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off. Use when this capability is needed.
-
tomevault-io Bundle Django Security ScanDefensive security scan for Django and Django REST Framework projects. Detects DEBUG=True in production, wildcard ALLOWED_HOSTS, SECRET_KEY in source, missing CSRF, raw ORM queries with string formatting, mark_safe on user input, AllowAny on mutating DRF views, and ModelSerializer fields="__all__" leaking sensitive fields. Invoke when the user asks to "review", "audit", or "scan" a Django project. Use when this capability is needed.
-
tomevault-io Bundle Project Master GovernanceRepository-scoped governance skill for the ATS CV Scoring System case study. Use when work must be checked against scope, requirements, quality gates, privacy-by-design, traceability, and portfolio readiness, or when coordinating other review skills in this repo. Use when this capability is needed.
-
tomevault-io Bundle Helixdevelopment Helixagent Scanning Database SecurityDatabase Security Scanner
-
tomevault-io Bundle Length Extension Attacks Anti PatternSecurity anti-pattern for hash length extension vulnerabilities (CWE-328). Use when generating or reviewing code that uses hash(secret + message) for authentication, API signatures, or integrity verification. Detects Merkle-Damgard hash misuse. Use when this capability is needed.
-
tomevault-io Bundle Missing Input Validation Anti PatternSecurity anti-pattern for missing input validation (CWE-20). Use when generating or reviewing code that processes user input, form data, API parameters, or external data. Detects client-only validation, missing type checks, and absent length limits. Foundation vulnerability enabling most attack classes. Use when this capability is needed.
-
tomevault-io Bundle Missing Security Headers Anti PatternSecurity anti-pattern for missing security headers (CWE-16). Use when generating or reviewing web application code, server configuration, or HTTP response handling. Detects missing CSP, HSTS, X-Frame-Options, and other protective headers. Use when this capability is needed.
-
tomevault-io Bundle Password Based Authentication PatternSecurity pattern for implementing password-based authentication. Use when designing login systems with username/password, implementing password storage, hashing, salting, peppering, password policies, or password reset flows. Specialization of the Authentication pattern. Use when this capability is needed.
-
tomevault-io Bundle Transparent Encrypted Storage PatternSecurity pattern for full-disk or database-level encryption at rest. Use when implementing Transparent Data Encryption (TDE), full-disk encryption, or when storage infrastructure should handle encryption without application changes. Addresses "Leak data at rest" problem. Use when this capability is needed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include geomap-visualization, glab-attestation, omer-metin--skills-for-antigravity--security-hardening. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.