Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
charlieviettq Bundle Grad Social Capital"Apply social capital theory (Putnam, Coleman, Bourdieu, Burt) to analyze how network structures and trust generate value or impose constraints. Use this skill when the user needs to evaluate bridging vs bonding capital, identify structural holes or network closure benefits, assess community or organizational trust dynamics, or when they ask 'how does our network create value', 'are we too insular', or 'where are the structural holes we can exploit'.".
-
charlieviettq Skill Devex ReviewLive developer experience audit. (gstack).
-
charlieviettq Skill API Security TestingSecurity testing checklist for HTTP APIs—authn/z, input validation, rate limits, sensitive data exposure, and common OWASP API issues. Use when reviewing or testing REST/GraphQL endpoints before release.
-
cerredz Skill Self Consistency TraceUse when the user invokes /self-consistency-trace or asks for a standalone reasoning trace using Self-Consistency (Wang et al., ICLR 2023). Samples N=5 diverse reasoning paths from a base strategy via temperature decoding, then majority-votes the most consistent answer. Produces a durable audit trail in memory/{question_name}.md showing all five paths and the vote tally. Use this when a single reasoning path feels unreliable and you want consensus across diverse reasoning chains to surface the most robust answer.
-
haibarakiku Bundle Data Security OfficerData Security Officer
-
haibarakiku Bundle Vault Secrets ExpertHashiCorp Vault Expert
-
haibarakiku Bundle Robinhood Engineer> **DISCLAIMER:** This skill provides general education about Robinhood's technology and engineering practices. It does NOT constitute professional financial or legal advice. Building trading systems requires proper FINRA/SEC compliance, security audits, and regulatory adherence. Always consult qualified professionals for production implementations.
-
haibarakiku Bundle Defense ResearcherUse for defense technology research, dual-use assessment, TRL evaluation, and national security R&D. Triggers: "defense research", "dual-use technology", "TRL assessment", "DARPA"
-
haibarakiku Bundle Information Security AdminInformation Security Admin
-
haibarakiku Bundle Import Export SpecialistLicensed Customs Broker and International Trade Specialist with 12+ years managing global supply chains, customs clearance, and trade compliance. Expert in HTS classification, Incoterms, FTA utilization, and supply chain security. Licensed by CBP, IIEI certified. Managed $500M+ in annual import/export value. Use when: customs clearance, trade compliance, import/export documentation, HTS
-
haibarakiku Bundle Container Security ExpertContainer Security Expert
-
haibarakiku Bundle Threat Intelligence AnalystThreat Intelligence Analyst
-
haibarakiku Bundle Crowdstrike SecurityExpert skill for crowdstrike-security
-
cerredz Skill Data Quality Audit Trace LargeUse this skill when the user invokes /data-quality-audit-trace-large or asks for a large public reasoning trace using Data Quality Audit. The skill writes a durable scratchpad to root memory/{question_name}.md and uses Data Quality Audit as the actual structure of the analysis. Treat the scale as a rough effort target rather than a fixed quota: around 500 or more numbered lines or roughly 10,000+ tokens of public scratchpad detail. Use this skill when the user wants the answer shaped by evidence reliability instead of a generic response.
Audited -
cerredz Skill Data Quality Audit Trace SmallUse this skill when the user invokes /data-quality-audit-trace-small or asks for a small public reasoning trace using Data Quality Audit. The skill writes a durable scratchpad to root memory/{question_name}.md and uses Data Quality Audit as the actual structure of the analysis. Treat the scale as a rough effort target rather than a fixed quota: around 25 numbered lines or roughly 500 to 900 tokens of public scratchpad detail. Use this skill when the user wants the answer shaped by evidence reliability instead of a generic response.
Audited -
cerredz Skill Data Quality Audit Trace MediumUse this skill when the user invokes /data-quality-audit-trace-medium or asks for a medium public reasoning trace using Data Quality Audit. The skill writes a durable scratchpad to root memory/{question_name}.md and uses Data Quality Audit as the actual structure of the analysis. Treat the scale as a rough effort target rather than a fixed quota: around 100 numbered lines or roughly 2,000 to 3,500 tokens of public scratchpad detail. Use this skill when the user wants the answer shaped by evidence reliability instead of a generic response.
Audited -
cerredz Skill Metacognitive Audit Trace LargeUse this skill when the user invokes /metacognitive-audit-trace-large or asks for a large public reasoning trace using Metacognitive Audit. The skill writes a durable scratchpad to root memory/{question_name}.md and uses Metacognitive Audit as the actual structure of the analysis. Treat the scale as a rough effort target rather than a fixed quota: around 500 or more numbered lines or roughly 10,000+ tokens of public scratchpad detail. Use this skill when the user wants the answer shaped by thinking quality review instead of a generic response.
Audited -
cerredz Skill Metacognitive Audit Trace SmallUse this skill when the user invokes /metacognitive-audit-trace-small or asks for a small public reasoning trace using Metacognitive Audit. The skill writes a durable scratchpad to root memory/{question_name}.md and uses Metacognitive Audit as the actual structure of the analysis. Treat the scale as a rough effort target rather than a fixed quota: around 25 numbered lines or roughly 500 to 900 tokens of public scratchpad detail. Use this skill when the user wants the answer shaped by thinking quality review instead of a generic response.
Audited -
cerredz Skill Metacognitive Audit Trace MediumUse this skill when the user invokes /metacognitive-audit-trace-medium or asks for a medium public reasoning trace using Metacognitive Audit. The skill writes a durable scratchpad to root memory/{question_name}.md and uses Metacognitive Audit as the actual structure of the analysis. Treat the scale as a rough effort target rather than a fixed quota: around 100 numbered lines or roughly 2,000 to 3,500 tokens of public scratchpad detail. Use this skill when the user wants the answer shaped by thinking quality review instead of a generic response.
Audited -
charlieviettq Skill Code ReviewReview code changes for security, performance, and correctness. Trigger with a PR URL or diff, "review this before I merge", "is this code safe?", or when checking a change for N+1 queries, injection risks, missing edge cases, or error handling gaps.
Audited -
charlieviettq Bundle UX Heuristic"Conduct heuristic evaluation of user interfaces using Nielsen's 10 usability principles. Use this skill when the user needs to audit a website, app, or interface for usability issues, prioritize UX improvements, or conduct a quick expert review without user testing — even if they say 'review this UI', 'find usability problems', or 'why do users struggle with our app'.".
-
charlieviettq Skill Journal EntryPrepare journal entries with proper debits, credits, and supporting detail. Use when booking month-end accruals (AP, payroll, prepaid), recording depreciation or amortization, posting revenue recognition or deferred revenue adjustments, or documenting an entry for audit review.
Audited -
charlieviettq Bundle Med Political"Use when the user wants to write a political news piece — election coverage, legislative reporting, policy analysis, official-statement coverage, poll interpretation, or political profile — from supplied material (transcripts, press releases, poll data, vote records, leaked documents, interviews). Activates political-beat-specific workflow on top of the general news-reporter workflow: stance tagging, poll-reading discipline, defamation/election-law red lines, and frame-neutrality audit. Also triggers on phrases like 'write up this 質詢', 'turn into an election report', 'analyze this poll', '幫我寫成政策追蹤報導', '寫一篇選戰分析', '把這份立委發言整理成新聞', 'cover this candidate's policy platform'. Defers general news craft to med-news-reporter; do NOT use for press releases (use pr-press-release) or government PR (use pr-*).".
-
charlieviettq Bundle Grad Strat Rbv"Apply the Resource-Based View (Barney, 1991) and VRIO framework to evaluate whether a firm's resources and capabilities confer sustained competitive advantage. Use this skill when the user needs to assess internal resources for strategic value, determine if a competitive edge is sustainable, audit resource portfolios for VRIO criteria, or when they ask 'what makes our advantage sustainable', 'which resources matter most', or 'can competitors replicate this'.".
-
charlieviettq Bundle Grad Panel Data"Apply panel data analysis with fixed effects, random effects, and dynamic GMM to exploit longitudinal variation and control for unobserved heterogeneity. Use this skill when the user has repeated observations over time for multiple entities, needs to choose between FE and RE via Hausman test, or when they ask 'how do I control for firm-specific effects', 'fixed or random effects', or 'how to handle endogeneity in panels'.".
-
charlieviettq Bundle Algo Risk Benford"Apply Benford's Law to detect anomalies in numerical datasets by analyzing first-digit frequency distributions. Use this skill when the user needs to audit financial data for fraud indicators, validate data integrity, or detect fabricated numbers — even if they say 'data manipulation detection', 'first digit test', or 'accounting fraud screening'.".
-
charlieviettq Bundle Grad Brand Equity"Apply brand equity frameworks (Aaker, 1991; Keller, 1993) to assess and build customer-based brand value. Use this skill when the user needs to audit brand strength, diagnose brand equity components, design brand-building strategies, or when they ask 'how strong is our brand', 'what drives brand value', or 'how do we build brand equity'.".
-
charlieviettq Bundle Grad Dual Process"Apply dual-process theory to diagnose whether judgments arise from fast intuitive (System 1) or slow analytical (System 2) processing and identify resulting cognitive biases. Use this skill when the user needs to explain why quick decisions go wrong, design choice architectures that account for cognitive defaults, audit decision processes for heuristic errors, or when they ask 'why do people misjudge probability', 'how to reduce snap-judgment errors', or 'when does intuition fail'.".
-
charlieviettq Skill IOS Design ReviewVisual design audit for iOS apps on real hardware. (gstack).
-
charlieviettq Bundle Grad Disruptive Innovation"Apply Christensen's Disruptive Innovation theory to assess low-end and new-market threats to incumbents. Use this skill when the user needs to evaluate whether a new entrant poses a disruptive threat, analyze why incumbents fail against inferior-but-cheaper alternatives, or design a disruption strategy targeting overserved customers.".
-
charlieviettq Skill IOS Testflight Github ActionsSet up iOS TestFlight delivery via GitHub Actions—build, sign, upload—with secret hygiene and no auto-push.
-
charlieviettq Bundle Algo Blockchain Smart Contract"Design and implement smart contracts as self-executing programmatic agreements on blockchain. Use this skill when the user needs to build automated on-chain logic, evaluate smart contract security, or design tokenized business rules — even if they say 'smart contract development', 'automated agreement', or 'on-chain logic'.".
-
openclaw-commons Skill Owasp GuideOwasp Guide
-
openclaw-commons Skill Security AuditSecurity Audit
-
openclaw-commons Skill Helmet SecurityHelmet Security
-
openclaw-commons Skill Contrast SecurityContrast Security
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include import-export-specialist, "grad-social-capital", devex-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.