Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
komunite Skill Security ChecklistAnalyze and produce a security checklist with structured process, quality checks, and system integration
-
komunite Skill Email Optimization AuditYapılandırılmış süreç, kalite kontrolleri ve sistem entegrasyonu ile bir e-posta optimizasyon denetimi analiz edin ve oluşturun
-
komunite Skill Conversion Rate AuditAnalyze and produce a conversion rate audit with structured process, quality checks, and system integration
-
amey-thakur Skill Bug BountyHunt vulnerabilities in bug bounty programs effectively and within the rules: scope, methodology, safe proof, and reports that get accepted. Use when participating in a bug bounty or coordinated disclosure program.
Audited -
amey-thakur Skill OAUTH FlowsImplement OAuth 2.0 and OpenID Connect flows that bind the request end to end with PKCE, state, and exact redirect allowlists. Use when adding "sign in with" a provider, integrating a third-party API on a user's behalf, or reviewing an OAuth client.
-
amey-thakur Skill API SecuritySecure an API by enforcing per-object authorization, per-caller quota, and schema-validated input on every endpoint. Use when building or reviewing an HTTP or GraphQL API that serves authenticated users, machine clients, or partner integrations.
-
amey-thakur Skill Authn DesignDesign sign-in so credentials are hashed with a slow algorithm, guessing is rate limited, and sessions rotate on login to defeat fixation. Use when building or reviewing registration, login, or password-reset flows.
-
amey-thakur Skill Authz DesignEnforce authorization so access is denied by default and every request re-checks that the caller owns the specific resource, closing IDOR gaps. Use when building endpoints that read or modify data belonging to a particular user or tenant.
Audited -
amey-thakur Skill Crypto UsageUse cryptography by calling vetted libraries with authenticated defaults and storing keys in a KMS, never by designing a scheme. Use when adding encryption, choosing a cipher or mode, or reviewing code that handles keys or ciphertext.
-
amey-thakur Skill Csrf DefenseBlock cross-site request forgery with SameSite cookies, per-session anti-CSRF tokens, and strict HTTP method discipline so a forged cross-origin request cannot act as the user. Use when building state-changing endpoints authenticated by cookies.
-
amey-thakur Skill JWT HandlingUse JSON Web Tokens safely by pinning the algorithm, keeping lifetimes short, and pairing them with a revocation path. Use when issuing or validating JWTs, designing a session scheme around them, or reviewing token-based auth.
-
amey-thakur Skill Ssrf DefensePrevent server-side request forgery by constraining where a user-influenced URL can make the server connect. Use when the server fetches a URL that came from a user: webhooks, link previews, image proxies, PDF renderers, or import-from-URL features.
-
amey-thakur Skill Audit LoggingRecord security-relevant events in a tamper-evident, append-only log that answers who did what and when. Use when building or reviewing logging for authentication, authorization, privilege changes, or access to sensitive data.
-
amey-thakur Skill Rate LimitingLimit requests by the cost they impose and the identity behind them, using token buckets, deliberate keys, and tiered responses to abuse. Use when protecting an API, a login flow, or any expensive endpoint from brute force, scraping, and accidental overload.
-
amey-thakur Skill Automation GuardrailsPut confirmation gates, blast-radius limits, audit trails, and kill switches around automation that can destroy things. Use when building scripts or bots with destructive power.
Audited -
amey-thakur Skill Open Source Review BoardRun an open source review board that gates incoming dependencies on license compatibility, sets the policy for contributing back, and requires a security review before adoption. Use when an organization needs consistent control over which OSS it pulls in and what it publishes.
Audited -
amey-thakur Skill Security Development LifecycleApply Microsoft's Security Development Lifecycle so threat modeling, tooling, and sign-off are built into each phase instead of bolted on before ship. Use when building or shipping software that takes untrusted input or handles sensitive data and you need a repeatable security process, not a one-time audit.
Audited -
komunite Skill Wcag AuditAnalyze and produce a wcag audit with structured process, quality checks, and system integration
-
komunite Skill Content AuditAnalyze and produce a content audit with structured process, quality checks, and system integration
-
amey-thakur Skill Supply Chain SecurityProtect a project and its users from compromised dependencies, publishing credentials, and build pipelines. Use when publishing packages or auditing what your build actually trusts.
-
amey-thakur Skill Event SourcingPersist state as an append-only event log with projections and snapshots, and know when the pattern is overkill. Use when audit history is a first-class requirement or evaluating event sourcing against CRUD.
Audited -
amey-thakur Skill Command Injection DefenseRun external programs without ever building a shell string from untrusted input, using argument arrays that bypass the shell entirely. Use when a program shells out to another binary, especially with any value that came from a user, a file, or the network.
-
amey-thakur Skill Security Incident ResponseRun a security breach through containment, evidence preservation, and notification duties in the right order, under time pressure, without destroying the record you will need. Use when you suspect or confirm a compromise: leaked credentials, unauthorized access, malware, or exfiltrated data.
-
amey-thakur Skill Vulnerability DisclosureReceive, triage, fix, and announce security reports on a coordinated timeline that protects users. Use when running a project that could have security issues, or when you receive a report.
Audited -
amey-thakur Skill Unsafe Code ReviewAudit unsafe blocks by verifying documented invariants, minimizing surface, and testing under sanitizers and Miri. Use when reviewing unsafe Rust, C/C++ interop shims, or any code that bypasses language safety.
Audited -
prism-shadow Skill Peopleops Console ReconciliationUse this skill for PeopleOps Console reconciliation tasks that ask for JSON answers about onboarding closeout, leave source precedence, payroll assignment readiness, recruitment outcomes, document folder readiness, formal notice quality, audit scope, or normalized business labels. Trigger whenever a task mentions People Ops, HRMS, employee onboarding, payroll/leave assignments, recruitment packets, policy cases, folders, notices, or audit events.
-
prism-shadow Skill Peopleops Lifecycle ReconciliationUse this skill for PeopleOps Console tasks that ask Codex to reconcile HR lifecycle records across employees, cases, leave, payroll, recruitment, documents, messages, policies, and audit evidence. Trigger whenever the task mentions onboarding closeout, leave source precedence, payroll assignment readiness, accrual readiness, remote-work exception closeout, folder readiness, formal notices, recruitment reconciliation, candidate outcomes, or normalized PeopleOps answer templates.
-
prism-shadow Skill Payer Ops Structured ReviewProduce structured JSON determinations for payer operations work such as utilization-management authorization review, pharmacy appeal intake, peer-to-peer closure, claim repricing, and finance margin queue analysis. Use when the task provides a payer operations environment plus an answer template and asks Codex to return schema-conformant operational JSON with criteria results, evidence records, calculations, routing, and basis audit fields.
-
prism-shadow Skill Ehr Quality Packet AuditProduce normalized JSON for EHR quality-governance tasks using task-provided schemas and records, including duplicate chart merge readiness packets, referral coordination packets, orthopedic care-transition summaries, ServiceRequest validation, and referral batch audits.
-
prism-shadow Skill Northwind People Lifecycle CloseoutVerify People Ops employee-lifecycle closeouts (leave/payroll precedence, folder readiness, formal-notice quality, audit-scope selection, recruitment reconciliation) against the remote Northwind PeopleOps Console read-only JSON API. Use whenever a task asks to validate/audit/reconcile an onboarding closeout, leave source precedence, payroll assignment readiness, policy-case folder+notice, or recruitment outcome packet.
-
prism-shadow Skill Peopleops Lifecycle ClearanceSolve PeopleOps employee-lifecycle clearance / audit / reconciliation tasks against the read-only Northwind People Lifecycle Portal JSON API. Use when a task asks to verify onboarding closeout, leave source precedence, payroll/accrual readiness, case folder + formal-notice quality, or recruitment reconciliation, and return a normalized JSON answer.
-
prism-shadow Skill Hr Lifecycle Clearance AuditSolve HR employee-lifecycle clearance/audit tasks against the remote Northwind PeopleOps read-only JSON API. Use when a task asks you to inspect leave assignments, payroll/accrual readiness, policy-case folder+notice defects, recruitment handoff, or audit closeout, and return a structured JSON answer.
-
prism-shadow Bundle Cedar Ridge Intake VerificationComplete a Cedar Ridge Intake Coordination Portal intake/audit task. Query the live portal for a roster, batch, or program; reconcile the records against the task's answer_template.json; and return one JSON object built only from the template's controlled values. Use when a task points at the Cedar Ridge portal and supplies an answer_template.json.
-
prism-shadow Skill Northstar Payer ReviewProcess Northstar Health Plan payer-operations review tasks (prior auth, appeals, payment integrity, P2P, margin queues) against the shared Northstar environment API, producing structured JSON determinations with full basis audit trails.
-
prism-shadow Bundle Asteria Fleet ReconciliationSolve Asteria Fleet "Data Quality Hub" reconciliation/certification tasks. Use when a task provides payloads/case_scope.json + payloads/answer_template.json and an environment_access.md pointing at a read-only Fleet Data Quality Hub, and asks for a reconciled/certified JSON audit of a contacts, fuel, freight, or maintenance collection (dedup overlapping source snapshots as of a cutoff, quarantine bad rows, normalize units & currency, resolve identities/categories, rank exceptions, assign opaque control codes, and decide a PASS/PASS_WITH_EXCEPTIONS/HOLD certification).
-
prism-shadow Bundle Portfolio Work ReviewCompute portfolio-mix, SLA-aging, and release-readiness reviews from a shared work-item environment. Use when a task asks for a closed-work portfolio mix vs target, an SLA breach/aging audit, or a release ship-readiness assessment, and points at a shared environment with work items, mix targets, SLA policy, releases, milestones, dependencies, and blockers.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-checklist, email-optimization-audit, conversion-rate-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.