Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tomevault-io Bundle Spec To ImplementationImplement Solidity functions from inline comment-level specs while updating NatSpec and surfacing assumptions. Use after scaffolding to produce faithful, audit-ready implementations before tests or refactors. Use when this capability is needed.
-
tomevault-io Bundle Security Implementation GuideComprehensive security patterns for authentication, authorization, input validation, and common vulnerability prevention Use when this capability is needed.
-
tomevault-io Bundle MavenMaven build expertise for this multi-module Java project. Use when working with pom.xml files, managing dependencies, running builds or tests for specific modules, configuring or troubleshooting plugins (surefire, jacoco, shade, spotless, pitest, owasp), regenerating OpenAPI sources, building the JMH benchmark JAR, or releasing to Maven Central. Use when this capability is needed.
-
tomevault-io Bundle Helixdevelopment Helixagent Finding Security MisconfiguratioFinding Security Misconfigurations
-
tomevault-io Bundle Verifiable Token Based Authentication PatternSecurity pattern for self-contained token authentication (e.g., JWT). Use when implementing stateless authentication, designing tokens with embedded claims, or building systems where tokens contain principal information and can be verified without server-side storage. Specialization of Authentication pattern. Use when this capability is needed.
-
tomevault-io Bundle Jeremylongshore Claude Code Plugins Plus Skills Secret ScannSecret Scanner
-
tomevault-io Bundle Verygoodopensource Vgv AI Flutter Plugin Vgv AI Flutter PlugSecurity
-
tomevault-io Bundle Capi Test Naming VerifierThis skill should be used when the user asks to "verify C API test naming", "check test naming convention", "validate test names", "C API test naming compliance", "test naming verification", "ensure test naming consistency", "audit test names", "review test naming", or mentions verifying that C API unit test names follow the standardized naming convention methodNameTestScenario. Use when this capability is needed.
-
tomevault-io Bundle Quality Attributes TaxonomyUse when working with the "-ilities" framework for non-functional requirements. Use when defining NFRs, evaluating architecture trade-offs, or ensuring quality attributes are addressed in system design. Covers scalability, reliability, availability, performance, security, maintainability, and more.
-
tomevault-io Bundle Helixdevelopment Helixagent Langchain Security BasicsLangChain Security Basics
-
tomevault-io Bundle Excessive Data Exposure Anti PatternSecurity anti-pattern for excessive data exposure (CWE-200). Use when generating or reviewing API responses, database queries, or data serialization. Detects returning more data than necessary including internal fields, sensitive attributes, and related records. Use when this capability is needed.
-
tomevault-io Bundle Insufficient Randomness Anti PatternSecurity anti-pattern for insufficient randomness vulnerabilities (CWE-330). Use when generating or reviewing code that creates security tokens, session IDs, encryption keys, nonces, or any security-critical random values. Detects use of Math.random() or predictable seeds. Use when this capability is needed.
-
tomevault-io Bundle Session Based Access Control PatternSecurity pattern combining session authentication with authorization. Use when implementing web application security requiring both user authentication via session IDs and authorization checks for resource access. Combines Opaque token-based authentication with Authorisation pattern. Use when this capability is needed.
-
tomevault-io Bundle Mobile VulnerabilitiesOWASP Mobile Top 10 vulnerability knowledge base for identifying, assessing, and remediating security risks in mobile application environments. Use when this capability is needed.
-
tomevault-io Bundle Pentest Whitebox Code ReviewSource code security audit using backward taint analysis, slot type classification, render context verification, and 3-phase parallel review producing an exploitation queue. Use when this capability is needed.
-
tomevault-io Bundle Spring Boot VerifyVerify Spring Boot 4.x projects for correct dependencies, configuration, and migration readiness. Use when analyzing pom.xml, build.gradle, application.yml, discussing Spring Boot project setup, dependency versions, configuration validation, version compatibility, migration to Spring Boot 4, deprecated dependencies, or when user mentions "verify project", "check dependencies", "upgrade Spring Boot", "migration readiness", "Jackson 3", "@MockBean deprecated", or "Spring Security 7". Use when this capability is needed.
-
tomevault-io Bundle Nest ReviewReview NestJS code for best practices, security, and maintainability. Use when reviewing backend code. Use when this capability is needed.
-
tomevault-io Bundle Adaptive Enforcement Lab Claude Skills Secret Scanning IntegSecret Scanning Integration
-
tomevault-io Bundle Adaptive Enforcement Lab Claude Skills Security Scanning WorSecurity Scanning Workflows
-
tomevault-io Bundle Programing Best PracticesSearchable knowledge base of 152+ programming best practices across 30+ languages and frameworks. BM25-powered search over curated resources from industry leaders (Google, Airbnb, Uber, Mozilla, Shopify, OWASP). Use when this capability is needed.
-
tomevault-io Bundle Spring Boot REST API StandardsProvides REST API design standards and best practices for Spring Boot projects. Use when creating or reviewing REST endpoints, DTOs, error handling, pagination, security headers, HATEOAS and architecture patterns.
-
tomevault-io Bundle Jeremylongshore Claude Code Plugins Plus Skills Audit TrailAudit Trail Helper
-
tomevault-io Bundle Jeremylongshore Claude Code Plugins Plus Skills Hipaa AuditHipaa Audit Helper
-
tomevault-io Bundle Install AdvancedInstall the optional advanced security-audit layer on top of the core AV set — Lynis (system hardening audit), chkrootkit (second-opinion rootkit scanner), AIDE (file integrity DB), debsecan (Debian/Ubuntu CVE scanner). Lets the user pick a subset; doesn't force the full stack. Triggers on "install lynis", "add advanced AV tools", "install rootkit/audit tools". Use when this capability is needed.
-
tomevault-io Bundle Golang Security AuditorGolang Security Auditor Use when this capability is needed.
-
tomevault-io Bundle Guomeiqing Security AuditScan your OpenClaw configuration for security risks and harden it with guided fixes. Supports three hardening levels. Use when asked to "security check", "安全检查", "security audit", "harden my setup", "安全加固", or "安全扫描". Use when this capability is needed.
-
tomevault-io Bundle Eng Security SafetyApply proactive threat modeling, least-privilege design, and safety guardrails before delivering any code or infrastructure change. Use when this capability is needed.
-
tomevault-io Bundle Owasp Mobile Security CheckerUse when performing security audits, vulnerability assessments, or compliance checks on Flutter or mobile applications. Covers OWASP Mobile Top 10 (2024) — hardcoded secrets (M1), insecure storage (M9), weak cryptography (M10), network issues (M5), and 6 more categories with automated scanners and remediation guidance.
-
tomevault-io Bundle Helixdevelopment Helixagent Assisting With Soc2 Audit PreparAssisting With Soc2 Audit Preparation
-
tomevault-io Bundle Jeremylongshore Claude Code Plugins Plus Skills Security ProOverview
-
tomevault-io Bundle Jeremylongshore Claude Code Plugins Plus Skills Soc2 Audit HOverview
-
tomevault-io Bundle Jeremylongshore Claude Code Plugins Plus Skills Scanning ConScanning Container Security
-
tomevault-io Bundle Jeremylongshore Claude Code Plugins Plus Skills Security IncOverview
-
tomevault-io Bundle Encrypting And Decrypting DataValidate encryption implementations and cryptographic practices. Use when reviewing data security measures. Trigger with 'check encryption', 'validate crypto', or 'review security keys'. Use when this capability is needed.
-
tomevault-io Bundle Jeremylongshore Claude Code Plugins Plus Skills Security MisOverview
-
tomevault-io Bundle Jeremylongshore Claude Code Plugins Plus Skills Content SecuContent Security Policy Generator
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include spec-to-implementation, security-implementation-guide, maven. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.