Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
diegosouzapw Bundle Logic Lens V2Logic Lens workflow skill. Use this skill when the user needs AI-powered Claude Code skill that performs deep code review using formal logic and reasoning frameworks to detect bugs, anti-patterns, and security risks beyond what linters catch and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle The FoolThe Fool workflow skill. Use this skill when the user needs challenging ideas, plans, decisions, or proposals. Invoke to play devil's advocate, run a pre-mortem, red team, stress test assumptions, audit evidence quality, or find blind spots before committing. Do NOT use for building plans, making decisions, or generating solutions — this skill only challenges and critiques and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle UX AuditUX Audit workflow skill. Use this skill when the user needs Audit screens against Nielsen's heuristics and mobile UX best practices using the StyleSeed Toss design language as the implementation context and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
Audited 54 -
diegosouzapw Bundle WordpressWordPress Development Workflow Bundle workflow skill. Use this skill when the user needs Complete WordPress development workflow covering theme development, plugin creation, WooCommerce integration, performance optimization, and security hardening. Includes WordPress 7.0 features: Real-Time Collaboration, AI Connectors, Abilities API, DataViews, and PHP-only blocks and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Cred OmegaCRED-OMEGA: Security Engine for All API Keys (Enterprise) workflow skill. Use this skill when the user needs CISO operacional enterprise para gestao total de credenciais e segredos and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Fix ReviewFix Review workflow skill. Use this skill when the user needs Verify fix commits address audit findings without new bugs and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Logic LensLogic Lens workflow skill. Use this skill when the user needs AI-powered Claude Code skill that performs deep code review using formal logic and reasoning frameworks to detect bugs, anti-patterns, and security risks beyond what linters catch and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
holobiomicslab Skill Batch File Processing Across DirectoriesUse when when you need to systematically extract a specific field or set of fields from multiple files scattered across nested directories—for example, to reconstruct an index of entry statuses from thousands of JSON annotation records, or to audit a repository's content without manually visiting.
Audited -
diegosouzapw Bundle Zeroize Auditzeroize-audit — Claude Skill workflow skill. Use this skill when the user needs Detects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-level analysis, and control-flow verification. Use for auditing C/C++/Rust code handling secrets, keys, passwords, or other sensitive data and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Laravel ExpertLaravel Expert workflow skill. Use this skill when the user needs Senior Laravel Engineer role for production-grade, maintainable, and idiomatic Laravel solutions. Focuses on clean architecture, security, performance, and modern standards (Laravel 10/11+) and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Network 101 V2Network 101 workflow skill. Use this skill when the user needs Configure and test common network services (HTTP, HTTPS, SNMP, SMB) for penetration testing lab environments. Enable hands-on practice with service enumeration, log analysis, and security testing against properly configured target systems and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Expo API RoutesCreate a secret workflow skill. Use this skill when the user needs Guidelines for creating API routes in Expo Router with EAS Hosting and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle GRAPHQL Architect V2graphql-architect workflow skill. Use this skill when the user needs Master modern GraphQL with federation, performance optimization, and enterprise security. Build scalable schemas, implement advanced caching, and design real-time systems and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Saas Multi Tenant V2SaaS Multi-Tenant Architecture workflow skill. Use this skill when the user needs Design and implement multi-tenant SaaS architectures with row-level security, tenant-scoped queries, shared-schema isolation, and safe cross-tenant admin patterns in PostgreSQL and TypeScript and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Semgrep Rule CreatorSemgrep Rule Creator workflow skill. Use this skill when the user needs Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Solidity Security V2Solidity Security workflow skill. Use this skill when the user needs Master smart contract security best practices, vulnerability prevention, and secure Solidity development patterns and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Vibe Code Auditor V2Vibe Code Auditor workflow skill. Use this skill when the user needs Audit rapidly generated or AI-produced code for structural flaws, fragility, and production risks and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Web Security TestingWeb Security Testing Workflow workflow skill. Use this skill when the user needs Web application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and access control issues and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Burp Suite Testing V2Burp Suite Web Application Testing workflow skill. Use this skill when the user needs Execute comprehensive web application security testing using Burp Suite's integrated toolset, including HTTP traffic interception and modification, request analysis and replay, automated vulnerability scanning, and manual testing workflows and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
Audited 54 -
diegosouzapw Bundle Burp Suite Testing V3Burp Suite Web Application Testing workflow skill. Use this skill when the user needs Execute comprehensive web application security testing using Burp Suite's integrated toolset, including HTTP traffic interception and modification, request analysis and replay, automated vulnerability scanning, and manual testing workflows and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
Audited 54 -
diegosouzapw Bundle Code Review ChecklistCode Review Checklist workflow skill. Use this skill when the user needs Comprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
diegosouzapw Bundle Django Perf Review V2Django Performance Review workflow skill. Use this skill when the user needs Django performance code review. Use when asked to "review Django performance", "find N+1 queries", "optimize Django", "check queryset performance", "database performance", "Django ORM issues", or audit Django code for performance problems and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
54 -
cyberstrikeus Skill Cis Ubuntu1604 V200 4 1 2 1Ensure audit log storage size is configured
Audited -
cyberstrikeus Skill Cis Ubuntu1604 V200 4 1 2 2Ensure audit logs are not automatically deleted
Audited -
cyberstrikeus Skill Cis Ubuntu1604 V200 4 1 2 3Ensure system is disabled when audit logs are full
Audited -
cyberstrikeus Skill Cis Ubuntu1804 V220 1 1 6 1Ensure separate partition exists for /var/log/audit
Audited -
cyberstrikeus Skill Cis Ubuntu1804 V220 1 1 6 2Ensure nodev option set on /var/log/audit partition
Audited -
cyberstrikeus Skill Cis Ubuntu1804 V220 1 1 6 3Ensure noexec option set on /var/log/audit partition
Audited -
cyberstrikeus Skill Cis Ubuntu1804 V220 1 1 6 4Ensure nosuid option set on /var/log/audit partition
Audited -
cyberstrikeus Skill Cis Ubuntu1804 V220 5 2 1 4Configure the audit_backlog_limit kernel parameter to prevent audit event loss
-
cyberstrikeus Skill Cis Ubuntu1804 V220 5 2 2 1Configure the maximum size of audit log files to prevent system impact and audit data loss
Audited -
cyberstrikeus Skill Cis Ubuntu1804 V220 5 2 2 2Configure auditd to keep audit logs and never delete them automatically
Audited -
cyberstrikeus Skill Cis Ubuntu1804 V220 5 2 2 3Configure the system to halt when audit logs are full to prevent data loss
Audited -
cyberstrikeus Skill Cis Ubuntu1804 V220 5 2 4 15.2.4.1 Ensure audit log files are mode 0640 or less permissive
-
cyberstrikeus Skill Cis Ubuntu1804 V220 5 2 4 25.2.4.2 Ensure only authorized users own audit log files
-
cyberstrikeus Skill Cis Ubuntu1804 V220 5 2 4 35.2.4.3 Ensure only authorized groups are assigned ownership of audit log files
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include logic-lens-v2, the-fool, ux-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.