Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
paulpas Skill Event SourcingPersists application state as an append-only immutable event log, enabling full state reconstruction, audit trails, temporal queries, and snapshot-based performance optimization for complex domain models.
Audited -
paulpas Skill Dast ToolingImplements Dynamic Application Security Testing (DAST) methodologies to identify runtime vulnerabilities during the execution phase of applications.
Audited -
paulpas Skill Sast ToolingImplements Static Application Security Testing (SAST) methodologies to identify vulnerabilities in source code during development phases.
Audited -
paulpas Skill Onepassword APIImplements 1Password Connect/SCIM API integration (Vaults, Items, Fields, Provisioning, Service Accounts) using onepasswordconnectsdk Python SDK with Connect server authentication, item CRUD, SCIM user/group provisioning, and secret reference patterns.
Audited -
paulpas Skill Security Review"Security-focused code review identifying vulnerabilities like injection" XSS, insecure deserialization, and misconfigurations, with remediation guidance
Audited -
paulpas Skill Auth PatternsImplements authentication patterns using OAuth2, OIDC, JWT, and SAML protocols for secure user management, including token handling, verification, and refresh flows.
Audited -
paulpas Skill CorosyncConfigures Corosync Cluster Engine v3.x messaging layer including totem protocol, quorum models, nodelist management, knet/udpu transports, and security for Pacemaker HA clusters.
Audited -
paulpas Skill Plaid APIImplements Plaid API integration (Auth, Transactions, Identity, Investments, Income) using plaid-python SDK with Link token flow, webhook verification, access token storage security, and financial data synchronization patterns.
Audited -
paulpas Skill Vault APIImplements HashiCorp Vault API integration (KV Secrets Engine, PKI, Transit, Auth Methods, Leasing & Renewal) using hvac Python SDK v2.4+ with proper authentication, secret leasing, TTL management, and encryption as a service patterns.
Audited -
paulpas Skill Juice Shop"'OWASP Juice Shop guide: Web application security testing with intentionally" vulnerable Node.js/Express application for learning and practice'
Audited -
paulpas Skill Code Review"Analyzes code diffs and files to identify bugs, security vulnerabilities" code smells, and architectural concerns, producing a structured review report with prioritized, actionable feedback
Audited -
paulpas Skill XML SecurityPrevents XML External Entity (XXE) injection, entity expansion attacks, and DTD abuse by securing XML parsers with safe configurations, input validation, and defense-in-depth patterns across Python, Java, PHP, Node.js, and Go.
Audited -
paulpas Skill Framework EvaluationRuns automated empirical evaluation of software frameworks through reproducible benchmark harnesses, dependency graph security auditing, integration feasibility testing, and maintenance cost modeling to produce quantitative selection data.
Audited -
paulpas Skill Production ReadinessEvaluates service readiness against Google SRE PRR framework covering reliability, observability, scalability, security, data management, deployment engineering, cost governance, and documentation for safe production deployment.
Audited -
paulpas Skill Spring Security CoreImplements Spring Security 6.x filter chain configuration, JWT authentication filters, method-level security with @EnableMethodSecurity, password encoding, and CORS/CSRF handling for production Spring Boot applications.
Audited -
paulpas Skill Url Parsing SecuritySecures URL parsing and query string handling against ampersand injection, double-encoding bypasses, parser inconsistencies, and parameter pollution across Python, Node.js, and Go applications.
Audited -
paulpas Skill Process Security Policy"Creates or updates SECURITY.md defining the vulnerability reporting process" disclosure timeline, and supported versions for CNCF projects
Audited -
paulpas Skill API Design PrinciplesImplements modern API design principles (REST resource modeling, GraphQL schema design, standardized error responses, versioning strategies, and security best practices) for production-grade backend services.
Audited -
paulpas Skill API Security PatternsImplements API security patterns including authentication middleware, JWT token validation and rotation, rate limiting with sliding windows, input sanitization, CORS configuration, and OWASP API Security Top 10 compliance for production services.
Audited -
paulpas Skill Security ArchitectureDesigns secure system architecture with threat modeling (STRIDE), defense-in-depth layers, zero-trust principles, and authentication patterns for production systems.
Audited -
paulpas Skill Security Owasp Top 10Provides an in-depth analysis of the OWASP Top 10 vulnerabilities, along with strategies to mitigate them effectively in software applications.
Audited -
paulpas Skill Websocket SecurityHardens WebSocket connections against cross-site hijacking, DoS attacks, and message flooding through origin validation, authentication, rate limiting, connection limits, and secure transport enforcement.
Audited -
paulpas Skill Auth0 API SkillsImplements Auth0 API functionalities (user CRUD, authentication flows, actions/hooks, organizations/multi-tenancy) for secure identity and access management in web and mobile applications.
Audited -
paulpas Skill REST API Security PatternsImplements REST API security patterns including OAuth 2.1 / OIDC authorization flows with PKCE, JWT access token vs opaque refresh token strategies, API key authentication, rate limiting headers, and CORS configuration for production APIs.
Audited -
paulpas Skill Software Quality AssuranceOrchestrates comprehensive software quality assurance including static analysis, fuzzing, load testing, security scanning, dependency auditing, and compliance validation to ensure production-ready software meets all quality thresholds.
Audited -
paulpas Skill Hashicorp VaultImplements HashiCorp Vault for secure secret management, including features for dynamic secrets, access control, and secret revocation.
Audited -
paulpas Skill Framework Evaluation CriteriaSystematically elicits evaluation criteria across technical, team, ecosystem, security, deployment, integration, cost, and viability dimensions to prevent hype-driven framework selection. Produces structured requirement matrices, weighted scoring frameworks, and decision records with documented trade-offs.
Audited -
paulpas Skill Authentication Design PatternsImplements production authentication architecture including JWT token lifecycle, OAuth 2.0 flows, session management, MFA/TOTP, API key auth, and password hashing strategies with security-first design patterns.
Audited -
paulpas Skill Dependency Supply Chain SecurityImplements end-to-end software dependency supply chain security including SBOM generation (SPDX/CycloneDX), SLSA attestation levels, exact version pinning, Sigstore/cosign verification, CI scanning pipelines, transitive vulnerability management, and reproducible build patterns.
Audited -
paulpas Skill Event Sourcing PatternImplements event sourcing pattern (event store, aggregate roots, projections, snapshots, event replay) to maintain complete audit trail and reconstruct state from immutable event history.
Audited -
paulpas Skill Framework RequirementsDefines, evaluates, and validates software framework requirements including non-functional criteria (performance, security, extensibility), weighted selection scoring matrices, proof-of-concept feasibility testing, and architecture decision records for production-grade applications.
Audited -
paulpas Skill Tool Evaluation WorkflowApplies a structured evaluation framework to select tools, libraries, and frameworks based on technical fit, community health, security posture, performance benchmarks, and total cost of ownership for software projects.
Audited -
paulpas Skill Configuration Management PatternsDesigns production configuration management with schema validation, hierarchical merging of config sources, hot reload capabilities, secret injection from vaults, and environment-specific defaults for reliable deployment.
Audited -
paulpas Skill Dependency Vulnerability ScanningImplements dependency vulnerability scanning mechanisms to identify known security vulnerabilities in third-party libraries and dependencies.
Audited -
paulpas Skill Hashicorp Vault PatternsImplements HashiCorp Vault API strategies for secure access and management of secrets in modern applications while minimizing risk and ensuring compliance with security regulations.
Audited -
nota-america Skill Persona It AdminAdminister IT — monitor security and configure Workspace.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include event-sourcing, dast-tooling, sast-tooling. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.