Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ashfordeou Bundle Internal Quality AuditUse when you must plan and score an internal quality audit program under an AS9100-style quality management system: compute the audit due date from the last audit date, the base interval and the process risk category, check auditor independence and competence for the assigned audit scope, size the record sample from the lot size and confidence level, and categorize an audit finding by impact severity, containment need and systemic spread. Produces the audit schedule, the auditor assignment verdict, the sample size, the finding classification, and the closure verdict that gate an internal audit program. Trigger: internal-quality-audit, audit-schedule, auditor-independence, audit-sample-size, finding-classification, closure-verification.
-
mturac Skill Click Path Auditユーザー向けボタン/タッチポイントを完全な状態変更シーケンスを通して追跡し、機能が個別に機能するが互いにキャンセルされたり、間違った最終状態を生成したり、UIを矛盾した状態にしたままにするバグを見つけます。次の場合に使用します:体系的なデバッグがバグを見つけたが、ユーザーは壊れたボタンを報告する場合、または共有状態ストアに触れる主要なリファクター後。
-
mturac Skill Production Audit日本語翻訳:このファイルは production-audit 用の日本語翻訳が必要です
-
tuyv Bundle Comet ReviewManually review the implementation diff for the current Comet change. Report correctness, security, and edge-case issues without advancing the workflow.
-
tuyv Bundle Avoid AI WritingAudit and rewrite content to remove AI writing patterns ("AI-isms"). Use this skill when asked to "remove AI-isms," "clean up AI writing," "edit writing for AI patterns," "audit writing for AI tells," or "make this sound less like AI." Supports a detect-only mode, an edit-in-place mode for files, an optional voice profile (casual / professional / technical / warm / blunt), and an iterate-to-convergence pass.
-
tuyv Bundle Github ArchiveInvestigate GitHub security incidents using tamper-proof GitHub Archive data via BigQuery. Use when verifying repository activity claims, recovering deleted PRs/branches/tags/repos, attributing actions to actors, or reconstructing attack timelines. Provides immutable forensic evidence of all public GitHub events since 2011.
-
ashfordeou Bundle Airworthiness LiaisonUse when you must manage DO-178C airworthiness and certification liaison for an airborne software item: confirm the certification basis items with evidence, score stage-of-involvement audit readiness against the software level threshold, and track open liaison items to closure before authority audits. Produces the certification-basis coverage account, the SOI readiness verdict, and the open-item action flags that keep the certification plan on schedule. Trigger: airworthiness liaison, certification liaison, soi audit, certification basis, authority communication, audit readiness.
-
ashfordeou Bundle Fod ControlUse when you must audit a foreign object debris (FOD) prevention program for aerospace production: classify the FOD zone from the part criticality and debris exposure, compute the FOD risk score, derive the FOD sweep interval and the tool-control and housekeeping controls for the zone, reconcile the issued tool count against the returned tools, and score the program against the required control set for the audit verdict with findings. Produces the zone class, the risk score, the sweep interval, the tool-count reconciliation result, the control completeness, and the fod-pass or fod-fail verdict that gates the FOD prevention assessment. Trigger: FOD prevention, foreign object debris, FOD zone classification, FOD risk score, FOD sweep interval, tool count reconciliation, FOD audit.
-
ashfordeou Bundle Backstepping ControlUse when you must design and simulate the backstepping control law for a second-order strict-feedback plant x1_dot = x2 + f1(x1), x2_dot = u + f2(x1, x2) tracking a reference: choose the virtual control that stabilizes the first error variable z1 = x1 - x1d, propagate the inner-state mismatch z2 = x2 - alpha1 as the second error variable, differentiate the virtual control analytically along the plant, and assemble the final control from the recursion so the composite Lyapunov function V2 = (z1^2 + z2^2)/2 decays at the design rates set by c1 and c2. Produces the error-variable and virtual-control histories, the analytic virtual-control derivative, the closed-loop command, the quadratic-Lyapunov decay audit, and the tracking-error history that gate a backstepping control assessment. Trigger: backstepping-control, integrator-backstepping, strict-feedback, virtual-control, control-lyapunov-function, recursive-control-design, backstepping-control-law, error-variable-recursion.
-
sheshiyer Skill Conducty Code ReviewStandalone post-implementation code review across a whole branch or PR. Goes beyond the in-cycle spec/quality reviewers (which check single prompts) to assess the diff holistically — security, correctness, perf, idioms, dead code, hidden coupling, test depth. Writes a `Code Reviews/Code Review YYYY-MM-DD HHmm.md` note to the vault linked back to the plan. Use when the user says "review my changes", "review this PR", "code review", "is this branch good", or after a plan finishes but before [[conducty-ship]].
-
sheshiyer Skill Conducty Vault GraphVault hygiene audit — finds orphaned notes, broken wikilinks, stale context, never-consumed designs, missing index entries, and unused improvement experiments. Writes a `Vault Audit YYYY-MM-DD HHmm.md` report. Use when the user says "vault audit", "vault health", "find orphans", "stale context", "vault graph", "what's broken in the vault", or weekly as a hygiene cycle.
-
sheshiyer Skill Configuring Tauri CspConfigure Content Security Policy (CSP) in Tauri v2 apps to prevent XSS and restrict where the webview loads resources. USE WHEN setting or hardening CSP in tauri.conf.json, debugging blocked scripts/styles, or tightening webview trust boundaries.
-
sheshiyer Skill Python Backend OrchestratorRoute a Python backend task to the right specialist — idiomatic Python, pytest/TDD, the Django stack (patterns, TDD, security, Celery, verification), FastAPI services, and the ML lane (PyTorch, recsys pipelines, MLE workflow). USE WHEN building, testing, securing, or shipping a Python web/ML backend but the specific framework or concern hasn't been named yet.
-
sheshiyer Skill Configuring Tauri HTTP HeadersConfigure HTTP response headers in Tauri v2.1+ webview responses, covering security headers, custom headers, and CORS from the allowlist. USE WHEN adding security headers, setting CORS for cross-origin requests, or customizing webview response headers.
-
sheshiyer Skill Systems Languages OrchestratorRoute a systems-language task to the right skill among 7 specialists — Go (patterns, testing), C++ (Core Guidelines coding standards, GoogleTest/CTest testing), and Perl (modern 5.36+ patterns, Test2 testing, taint/injection security). USE WHEN a user is writing, reviewing, testing, or hardening Go, C++, or Perl code but hasn't named the language axis or the specific concern.
-
sheshiyer Skill Managing Tauri Plugin PermissionsConfigure Tauri plugin permissions, capabilities, and security, including platform-specific and window-targeted capabilities and custom scoped permissions. USE WHEN setting up Tauri capabilities, granting plugin permissions to windows or platforms, or authoring custom plugin permissions with scopes.
-
ashfordeou Bundle Active Disturbance Rejection ControlUse when you must design and simulate an active-disturbance-rejection-control law for a second-order plant with an unknown total disturbance: run the linear-extended-state-observer with bandwidth-parameterized observer gains placing every observer pole at omega_o to estimate the state and the total disturbance, cancel the estimate with the disturbance-rejection term divided by the plant-gain estimate b0, and close the outer loop with the bandwidth-parameterized PD law on the estimated states placing the tracking poles at omega_c. Produces the observer-gain triple from the (s + omega_o)^3 expansion, the disturbance-cancellation audit of the rejection term, and the tracking-error, command and total-disturbance-estimate histories that gate an active disturbance rejection control assessment. Trigger: active-disturbance-rejection-control, linear-extended-state-observer, adrc, bandwidth-parameterization, total-disturbance-estimate, disturbance-rejection-term, observer-gain-parameterization.
-
tuyv Bundle Gke ProductionizeOrchestrates comprehensive production readiness reviews and assessments for GKE clusters and workloads across scalability, security, reliability, observability, backup/DR, and cost optimization. Use when asked to productionize, prepare, assess, audit, or review a GKE cluster or workload before going live to production. Don't use for deep-dive single-domain implementation (use specific domain skills like gke-workload-scaling, gke-platform-security, gke-workload-security, gke-service-networking, gke-reliability instead).
-
tuyv Bundle Managing DotfilesUse when adding, changing, deploying, onboarding, or auditing Jesse's dotfiles — the symlink-based config system in ~/git/dotfiles (public) and ~/git/dotfiles-private (private), deployed across his Mac + Linux fleet. Covers the update workflow, the manifest, OS-splitting, secrets, new-machine onboarding, and the audit process.
-
tuyv Bundle CompanionUse when managing local SKILL.md packages with Companion: validate, publish, update, resolve dependencies, declare secrets, environment variables, or hosted SQLite state tables, query skill state, install updates, audit skills, check workspace versions, or self-update this Companion skill through the Companion workspace API.
-
tuyv Bundle Github Evidence KitGenerate, export, load, and verify forensic evidence from GitHub sources. Use when creating verifiable evidence objects from GitHub API, GH Archive, Wayback Machine, local git repositories, or security vendor reports. Handles evidence storage, querying, and re-verification against original sources.
-
tuyv Bundle Gha Security ReviewGitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to "review GitHub Actions", "audit workflows", "check CI security", "GHA security", "workflow security review", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.
-
tuyv Bundle Audit AugmentationAugments Trailmark code graphs with external audit findings from SARIF static analysis results, weAudit annotation files, and version-gated Trailmark 0.4.x binary-analysis graph exports. Maps findings to graph nodes by file and line overlap, creates severity-based subgraphs, and enables cross-referencing findings with pre-analysis data (blast radius, taint, etc.). Use when projecting SARIF results onto a code graph, overlaying weAudit annotations, importing binary graph findings, cross-referencing Semgrep, CodeQL, or binary-analysis findings with call graph data, or visualizing audit findings in the context of code structure.
-
tuyv Bundle Claude Settings AuditAnalyze a repository to generate recommended Claude Code settings.json permissions. Use when setting up a new project, auditing existing settings, or determining which read-only bash commands to allow. Detects tech stack, build tools, and monorepo structure.
-
tuyv Bundle Google Mobile Ads ValidateValidates a project's Google Mobile Ads (GMA) SDK integration for iOS, Android, or Unity projects. Use when conducting a full pre-launch audit of an app that integrates GMA SDK or when validating any individual GMA SDK integration checks, such as when validating ad unit IDs and ad formats, SKAdNetwork IDs, mediation adapter SDK version compatibility, or ad preloading.
-
tuyv Bundle 1password使用 1Password CLI (op) 管理密码和 API credentials。保存、查询、读取 API key/token,注入环境变量到脚本。当用户提到保存密码、保存 API key、查询密码、1password、op CLI、secret 管理时使用此 skill。
-
tuyv Bundle Post Patch ValidationValidates security patches with reproducible baseline-versus-patched evidence, including original exploits, root-cause variants, behavior preservation, regressions, and newly introduced security failures. Use after a patch exists and before accepting, merging, or reporting it as fixed; also use when an AI-generated patch, remediation commit, pull request, or proposed upstream fix needs adversarial post-patch validation across any language.
-
tuyv Bundle Git Safety NetAudits, preserves, recovers, and safely retires local Git state: unpushed or wrong-branch commits, dirty or detached worktrees, forgotten duplicate clones of the same repo, untracked work no bundle can back up, orphaned stashes, dangling commits, stale branches, and squash/rebase merge uncertainty. Use when the user fears work was lost; asks to recover a commit or branch; asks whether a worktree, clone, or scratch directory can be deleted; wants everything converged onto one main branch; or needs proof that cleanup will not drop work. Use it even after an audit reported clean — the usual gap is scope: every in-repo command is blind to a second clone elsewhere on disk. Triggers on "did I lose work", "is everything merged", "is anything else lost", "safe to delete this clone", "clean up old branches/stashes", "only keep one main branch", "git reflog", "dangling commits", "分支灾难", "误删分支/commit", "worktree 能删吗", "还有没有丢的东西", "只保留一个主分支". Covers local-Git forensics, not GitHub PR/API operations or routine sync.
-
javimosch Skill Hefestoai AuditorStatic code analysis tool. Detects security vulnerabilities, code smells, and complexity issues across 17 languages. All analysis runs locally — no code leaves your machine.
-
javimosch Skill Threat ModelingThreat Modeling Expert
-
javimosch Skill Pls Audit WebsiteWebsite Audit
-
caishengold Skill Audit Report Writer当需要撰写审计报告相关专业文案、行业指南、科普文章时使用。触发场景:审计报告/内审。当用户提到"审计报告"、"审计报告"、"内审"、"audit"、"report"时应触发此技能。
Audited -
caishengold Skill Energy Audit Writer当需要编写能源审计报告、节能诊断、能效评估时使用
Audited -
tuyv Bundle Happy App AuditAudit a local macOS app's telemetry / reporting behavior using static analysis only. Reverse-engineers an .app bundle to identify embedded SDKs (AppLog/TEA, Parfait, TTNet, mars, MMKV, Sentry, Firebase, Bugly, Umeng, etc.), mapped upload endpoints, local on-disk queues, and privacy-relevant fields — without packet capture, network requests, debugger attach, or DRM bypass. Use when user asks to investigate, audit, or reverse-engineer a macOS app for telemetry, reporting, data upload, privacy, or SDK fingerprinting. Targets /Applications, ~/Applications, /Library/Input Methods, /Library/PrivilegedHelperTools, and similar local install paths.
-
tuyv Bundle Open Source Prep帮用户把私有项目整理成可开源的仓库。核心能力:(1) 扫描源码和 git 历史中的密钥/token 泄漏;(2) 根据项目场景推荐开源协议(MIT / Apache 2.0 / GPL 等)并生成 LICENSE;(3) 补齐 README 免责声明、CONTRIBUTING.md、SECURITY.md、.gitignore 等开源必备文档;(4) 检查 bundle identifier、package.json 等所有权/商标隐患。触发词:「开源」「open source」「选择协议」「LICENSE」「准备开源」「检测密钥」「secret scan」「上传 github」。
-
tuyv Bundle Linkedin RepurposerRepurpose existing content into a native LinkedIn post. Take a tweet, thread, YouTube video, blog, or newsletter and rebuild it for LinkedIn: re-hook before the fold, expand to the 900 to 1300 char sweet spot, add whitespace and a CTA, move links to the first comment, run the humanizer, publish via Publora on approval. Not for writing from scratch (use linkedin-post-writer), not for auditing a draft (use linkedin-humanizer --mode audit).
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include hefestoai-auditor, internal-quality-audit, click-path-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.