Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tuyv Bundle Linkedin Post WriterDraft a new LinkedIn post from scratch using one of 20 2026 hook formulas (anaphora, R.I.P., time-anchor, curiosity-gap, contrarian, controlled A/B, false-binary, and more) plus a founders-edition angle library, picked by engagement goal (comments, reposts, likes, saves). Runs the humanizer pass and schedules via Publora on approval. Use to write a post, find a hook or proven format, or get founder-specific angles. Not for reviewing existing drafts (use linkedin-humanizer --mode audit).
-
tuyv Bundle Ln 630 Test AuditorUse when auditing the test surface through the evaluation platform with mandatory research, coordinated test audit workers, and structured summaries.
-
tuyv Bundle Avoid AI Writing RouterUse when a request combines AI-writing audit, rewrite, file editing, voice preservation, false-positive interpretation, verification, or when the user invokes Avoid AI Writing without naming a mode.
-
tuyv Bundle Github Sensitive Data CleanupScan and remove sensitive data (secrets, API keys, private domains/IPs, PII) from GitHub repository history. Use this skill whenever the user says "scan sensitive data", "clean git history", "remove secrets from repo", "sanitize GitHub history", "清理敏感数据", "历史重写", "force push", "泄露", or needs to repair a public repo after accidental secret/private context leakage. Also use before any force push to a public repository to verify visibility, backup, and scan results.
-
tuyv Bundle Ln 54 Codebase AuditorAudits cross-cutting codebase health, security and maintainability; not a single-change review or specialist audit.
-
tuyv Bundle Ln 52 Delivery ReviewerReviews a completed change for acceptance, regressions and release risk; read-only, not a whole-codebase audit.
-
tuyv Bundle Ln 512 Tech Debt CleanerAuto-fixes low-risk tech debt (unused imports, dead code, commented-out code) with >=90% confidence. Use when audit findings need safe automated cleanup.
-
tuyv Bundle Ln 621 Security Boundary AuditorChecks application security boundaries: secrets, injection, XSS, input validation, and sensitive env defaults. Use when auditing exploitable code paths.
-
tuyv Bundle Ln 22 Current Architecture DocumenterDocuments current architecture from implementation evidence; does not propose a target or audit fitness.
-
withoneai Skill Security TrailsSecurityTrails through One
-
ndpvt-web Skill More Code Less ReuseAnalyze AI-generated code for redundancy and missed reuse opportunities using semantic clone detection, then refactor to eliminate technical debt. Triggers: 'check for code duplication', 'review AI-generated PR', 'find redundant code', 'reuse audit', 'detect code clones', 'reduce AI code redundancy'
-
ndpvt-web Skill Rvb Automating AI SystemHarden code and AI guardrails through iterative Red Team vs Blue Team adversarial games. Use when the user says 'harden this code', 'find and fix vulnerabilities', 'red team blue team', 'iterative security hardening', 'guardrail optimization', or 'adversarial defense testing'.
Audited -
pku-yuangroup Bundle Retrosynthesis PlanningSearch multi-step retrosynthesis routes from a target to stock with AiZynthFinder, then audit and rank route trees. Use for recursive planning, not mapping, forward prediction, conditions, or yield.
-
revfactory Bundle Cve AnalysisCVE(Common Vulnerabilities and Exposures) analysis methodology, dependency vulnerability also for, CVSS count , vulnerability priority decision guide. 'CVE', 'vulnerability analysis', 'dependency vulnerability', 'CVSS', 'npm audit', 'Snyk', 'Trivy', 'CVE database', 'vulnerability priority' etc. CVE vulnerability analysis this for. vulnerability-scannerof -ize. , actual penetration test executionthis code modification this of scope .
-
revfactory Bundle Refactoring CatalogCode refactoring catalog. An extension skill for architecture-reviewer/performance-analyst that provides Martin Fowler-based refactoring patterns, code smell detection-to-refactoring mapping, SOLID principle violation identification, and complexity measurement criteria. Use when reviewing code structure improvement involving 'refactoring', 'code smells', 'SOLID violations', 'complexity', 'design patterns', 'code quality', etc. Note: direct code modification and security analysis are outside the scope of this skill.
-
revfactory Bundle Finding ClassificationAudit finding classification and reporting framework. Referenced by findings-analyst and recommendation-writer agents when systematically classifying findings and writing improvement recommendations. Used for 'finding classification', 'audit reporting', 'improvement recommendations' requests. Note: legal sanction decisions and disciplinary procedures are out of scope.
-
ndpvt-web Skill Secure Code Generation ViaGenerates secure, vulnerability-free code by applying the SecCoderX reasoning framework — systematically analyzing code for CWE-classified vulnerabilities while preserving full functionality. Combines vulnerability-aware task decomposition with a reasoning-based security audit pass on every code output. Trigger phrases: - "Write secure code for..." - "Generate code without vulnerabilities" - "Security-hardened implementation of..." - "Check this code for CWE vulnerabilities" - "Fix the security issues in this code" - "Write this function with security best practices"
-
ndpvt-web Skill Will It Survive DecipheringAnalyze the survival and maintenance fate of AI-generated code in repositories using survival analysis techniques from Rahman & Shihab (2026). Assess whether AI-authored code is durable or disposable, classify modification types, and predict which code units are modification-prone. Trigger phrases: 'analyze AI code survival', 'is this AI code disposable', 'code survival analysis', 'predict code modification risk', 'compare AI vs human code durability', 'audit AI-generated code maintenance burden'.
-
ndpvt-web Skill The Semantic Trap Fine TunedEvaluate code vulnerability detection for semantic traps -- where analysis fixates on functional context (e.g., "this is crypto code, so it's probably vulnerable") instead of reasoning about the actual root cause of a vulnerability. Applies the TrapEval methodology to distinguish genuine vulnerability reasoning from pattern-matching shortcuts. Trigger phrases: "check this code for vulnerabilities", "is this patch secure", "audit this function for security issues", "compare vulnerable vs patched code", "does this fix actually address the vulnerability", "evaluate my vulnerability detector"
-
ndpvt-web Skill Cutting Gordian Knot DetectingDetect malicious PyPI/NPM packages using behavioral pattern mining and semantic reasoning (PyGuard). Use when: 'scan this package for malware', 'is this PyPI dependency safe', 'audit my requirements.txt for supply chain attacks', 'check this setup.py for suspicious behavior', 'analyze this npm package for data exfiltration', 'detect obfuscated malicious code in this package'.
-
ndpvt-web Skill Redsage Cybersecurity GeneralistApply RedSage's agentic augmentation methodology to cybersecurity assistance: structured threat analysis, vulnerability assessment, tool-command generation, and multi-turn security workflows grounded in MITRE ATT&CK, OWASP, CWE/CAPEC, and penetration testing frameworks. Trigger phrases: - "Analyze this CVE and map it to CWE/CAPEC" - "Help me with penetration testing methodology" - "Explain this MITRE ATT&CK technique" - "Generate security tool commands for this scenario" - "Assess this vulnerability and estimate CVSS" - "Walk me through incident response for this alert"
-
ndpvt-web Skill Artificial Intelligence Open SourceAnalyze open-source projects for sustainability risks and apply AI-driven interventions for bug triaging, community health assessment, vulnerability detection, contributor onboarding, and maintenance automation. Trigger phrases: "analyze OSS health", "assess project sustainability", "triage issues automatically", "detect community smells", "onboard new contributors", "audit OSS security posture"
-
revfactory Bundle Internal Control FrameworkInternal control framework guide. Referenced by scope-designer and checklist-builder agents when designing audit scope and control items. Used for 'COSO', 'internal controls', 'control testing' requests. Note: external audit representation and legal opinion preparation are out of scope.
-
revfactory Bundle Audit Checklist EngineA systematic checklist generation engine for compliance audits. The 'status-auditor' and 'remediation-planner' agents must use this skill's audit framework and checklist templates when conducting status assessments and developing remediation plans. Used for 'audit checklist', 'compliance inspection form', 'compliance status assessment', etc. Note: Law mapping or full orchestration is outside the scope of this skill.
-
yigityildiz0 Skill Brand VoiceDefine, discover, apply, or audit a brand voice across copy, decks, pages, prompts, and product messaging. Use for tone of voice, messaging consistency, editorial rules, brand language, voice guidelines, or brand-copy review. Turkish triggers: marka dili, ses tonu, metin tonunu tutarlı yap, üslup rehberi.
-
yigityildiz0 Bundle Design AuditPremium UI/UX design audit and refinement skill. Conducts systematic visual audits of existing apps and produces phased, implementation-ready design plans..
-
yigityildiz0 Skill Code ReviewerReviews code for bugs, security issues, and quality problems. Use when asked to "review this code", "check my code", "code review", "audit this file", or.
-
yigityildiz0 Skill Security ReviewIdentify security vulnerabilities across 10 domains including OWASP Top 10, race conditions, supply chain risks, and compliance gaps. Use for security audits, penetration test preparation, vulnerability assessment, or as Phase 3 of comprehensive code review. Turkish triggers: güvenlik incelemesi, tehdit ve zafiyet bul, kod veya mimariyi güvenlik açısından denetle.
-
yigityildiz0 Bundle Soc2 ComplianceImplement SOC 2 Type II controls covering Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy). Use when.
-
yigityildiz0 Skill Security AuditorAudits code for security vulnerabilities, exposed secrets, and unsafe patterns. Use when asked to "security audit", "check for vulnerabilities", "is this.
-
yigityildiz0 Bundle Cancel UnsubscribeCancel a subscription or unsubscribe from a service. Works from a description, a pasted charge line, a URL, or a photo/screenshot. Can also audit a full.
-
yigityildiz0 Bundle Pci Dss ComplianceImplement PCI-DSS v4.0 requirements for payment card data security. Use when handling payment card data, preparing for PCI audits, securing payment systems.
-
yigityildiz0 Bundle Safe Skill UpdaterAudit, compare, merge, repair, or improve user-owned Codex and ChatGPT skill variants while preserving proven behavior. Use for skill regression analysis, semantic diffs, trigger repair, host migration, merge/split decisions, and safe rollback. Turkish triggers: becerileri karşılaştır, skill geliştir, birleştir/böl, tetikleyiciyi düzelt, kaliteyi koruyarak güncelle. For downloaded or third-party package safety, use skill-package-security-audit first.
-
yigityildiz0 Bundle Investment Red TeamIndependently challenge and audit an investment recommendation, thesis, valuation, portfolio action, technical setup, fund comparison, crypto analysis, or leveraged-product scenario. Use when the user asks "emin misin?", requests a fresh analysis or second opinion, asks whether a better stock, fund, ETF, gold, crypto, cash, or other relevant alternative exists, is considering a concentrated or high-risk trade, or another finance skill delegates final review. Re-underwrite without anchoring to the prior pick, recompute key numbers, seek disconfirming evidence, compare same-asset and relevant cross-asset challengers plus doing nothing, and return an evidence-based verdict. Do not merely defend, restate, or self-score the original analysis, and do not force a different answer just to appear independent. Turkish triggers: yatırım fikrini yeniden sorgula, emin misin, karşı tez ve alternatifler, bağımsız ikinci görüş.
-
yigityildiz0 Bundle Iso27001 ComplianceImplement ISO 27001:2022 Information Security Management System controls (114 controls across 14 domains). Use when establishing ISMS, preparing for ISO.
-
yigityildiz0 Skill Adversarial VerifierStress-test an implementation with adversarial inputs, boundary cases, contract violations, and security probes, then produce an evidence-backed report. Use.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include linkedin-post-writer, ln-630-test-auditor, avoid-ai-writing-router. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.