Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
whyzsm Bundle Tech Threat Detection Team威胁检测工程师。用于专精构建威胁检测系统,在攻击者造成损害前发现拦截威胁。来源于 WorkBuddy 技术卡片,并转换为 Codex 可安装的专家入口格式。
-
whyzsm Bundle Tech Security Engineer Team安全工程师。用于全方位保障系统安全,在黑客之前发现并修复安全漏洞。来源于 WorkBuddy 技术卡片,并转换为 Codex 可安装的专家入口格式。
-
vivy-yi Skill Labor Contract Audit审查劳动合同或劳务协议。 覆盖:合同类型(全职/兼职/劳务)、试用期条款、工资及支付周期、社会保险、 工作地点与岗位、保密与竞业、培训服务期。 适用情形:用户说"审一下劳动合同"、"offer里有什么坑"、"签劳动合同要注意什么"。
-
ndpvt-web Skill Rubberduckbench Benchmark AI CodingEvaluate and improve AI coding assistant responses using RubberDuckBench's rubric-based methodology. Detects hallucinations, scores partial credit, and enforces truthful code reasoning. Use when: 'evaluate this code explanation', 'check my AI answer for hallucinations', 'score this coding response', 'audit code assistant accuracy', 'benchmark code Q&A quality', 'review this technical answer for correctness'.
-
ndpvt-web Skill From Detection Prevention ExplainingProactively identify security-critical code regions and generate prevention-oriented explanations before vulnerabilities are introduced. Use when: 'review this code for security-critical areas', 'explain security risks in my methods', 'find security-sensitive code before bugs happen', 'proactive security review of my codebase', 'highlight authentication and data access risks', 'prevent vulnerabilities in this module'.
-
ndpvt-web Skill Usage Effects Requirements AI CodingOptimize AI coding assistant interactions using empirical enterprise findings on usage patterns, productivity factors, and quality requirements. Use when: 'help me get more out of Copilot', 'review my AI-assisted workflow', 'improve AI code generation quality', 'audit AI coding assistant effectiveness', 'optimize prompts for code generation', 'set up AI coding assistant practices for my team'.
-
ndpvt-web Skill Learning Reason Faithfully Step LevelApply FaithRL's step-level faithfulness verification to multi-step reasoning tasks. Decomposes reasoning into individually verified steps, penalizes unsupported claims, and preserves valid partial derivations. Use when: 'verify each reasoning step', 'reduce hallucination in chain-of-thought', 'faithful step-by-step reasoning', 'audit my reasoning chain', 'step-level credit assignment', 'penalize unsupported reasoning steps'.
-
ndpvt-web Skill Patch To Poc Systematic Study AgenticAgentic kernel vulnerability reproduction from security patches. Implements the K-Repro methodology: controlled code browsing, hypothesis-driven root cause analysis, iterative PoC generation, VM-based testing, and GDB debugging for Linux kernel N-day reproduction. Trigger phrases: "reproduce this kernel vulnerability", "generate a PoC from this patch", "analyze this security patch for exploitability", "kernel bug reproduction from commit", "patch-to-poc analysis", "N-day vulnerability reproduction"
-
whyzsm Bundle Pr ReviewerAutomated GitHub pull request review workflow with diff analysis, optional lint checks, changed-file risk assessment, security/error-handling/test-coverage findings, and structured review reports. Use when the user asks to review a GitHub PR, inspect a pull request diff, check PR risk, run local lint as part of review, or prepare PR feedback. Requires the gh CLI when fetching GitHub PRs directly.
-
whyzsm Bundle Harness ReviewHAR: Multi-angle code, plan, scope review. Security/quality check. Trigger: review, code review, plan review, scope analysis. Do NOT load for: implementation, new features, bugfix, setup, release.
Audited -
whyzsm Bundle Security AuditRepository and deployment security audit workflow for exposed credentials, insecure configuration, open ports, weak permissions, dependency risks, authentication/authorization gaps, and actionable remediation. Use when the user asks for a security audit, secret scan, vulnerability review, deployment hardening, or security findings in a codebase.
-
whyzsm Bundle System ArchitectSystem architecture and modular design workflow for robust, scalable, maintainable software structures. Use when the user asks to design a system, refactor architecture, split modules, define interfaces, choose a stack, create architecture diagrams, or improve project structure with security and scalability in mind.
-
whyzsm Bundle Compliance Audit ProCompliance Audit Pro
-
whyzsm Bundle Legal Blockchain Security Auditor Team区块链安全审计师。用于专精区块链智能合约和 DeFi 协议安全审计。来源于 WorkBuddy 法务安全卡片,并转换为 Codex 可安装的专家入口格式。
-
vivy-yi Skill Self AuditSelf Audit
-
vivy-yi Skill Network Product Security Advisor网络产品安全合规顾问——评估网络产品(硬件/软件/IoT/APP) 的网络安全合规性,包括等保、安全功能要求、漏洞管理、 用户信息保护。适用情形:用户说"我们的产品要过等保"、 "网络安全产品审批"、"APP安全检测"、"IoT设备安全合规"、 "产品上线前安全检查"。
-
vivy-yi Skill Secret Identification Assessment分析secret-identification-assessment相关知识产权侵权问题。 覆盖:侵权行为识别、证据收集、维权策略建议。 适用情形:用户说"secret-identification-assessment"相关问题。
-
wenjunduan Skill Security Review安全审查 — T 阶段 (Path C+)
-
wenjunduan Bundle Security TestUse when a business feature needs scoped security verification before delivery. Reads the project's Convention Pack, security checklist, dependency policy, and runtime-env, then performs static checks plus declared dynamic auth, authorization, data-scope, and input-validation cases. It is not an automated penetration test and does not expand scope without approval.
-
wenjunduan Bundle Quantum Codegen全栈代码快速生成 (quantum 适配层). 按 mode 生成: 前端页面/组件 (page) · 后端模块脚手架 (module) · 数据库表结构与 DDL (db) · 后端单元测试 (unit) · 安全测试 (security) · 端到端 E2E 测试 (e2e). 当用户说"生成页面/建模块/建表/写单测/安全测试/E2E", 或 biz-delivery-loop 编排到对应 stage 时触发. 系统无关: 只读 Convention Pack + runtime-env, 证据写 PACE runtime-verify.
-
vivy-yi Skill Trade Secret Litigation分析商业秘密侵权诉讼的诉因、举证责任和赔偿计算。 覆盖:商业秘密认定(技术信息/经营信息)、侵权行为类型(盗窃/欺诈/违反保密义务/利诱)、 举证责任分配(接触+实质相同+合理保密措施)、损害赔偿计算(实际损失/侵权获利/许可费)、 刑事报案路径(侵犯商业秘密罪)。 适用情形:用户说"商业秘密被泄露怎么办"、"员工带走公司技术能告吗"、"商业秘密侵权怎么举证"。
-
vivy-yi Skill Data Security Assessment数据安全评估——评估互联网金融业务的数据安全措施。 适用情形:定期数据安全评估或监管要求的数据安全检查。 核心:数据分级分类/等保三级/个人信息保护三维度。
-
vivy-yi Skill Employee Trade Secret Risk员工侵犯商业秘密风险评估与防控方案。 为企业评估员工侵犯商业秘密风险,识别高风险主体,制定防控方案:竞业限制协议有效性审查、 保密协议执行评估、员工带走信息的技术手段防护(上网行为管理/USB管控/邮件审计)、 离职交接流程规范性检查、证据保全与快速响应机制。 适用情形:员工离职带走商业秘密风险评估、商业秘密保护制度建设、竞业限制与保密协议审查、 员工泄密事件快速响应。
-
vivy-yi Skill Security Certification Advisor个人信息保护认证顾问——指导企业通过个人信息保护认证 作为数据出境合规路径之一,或提升整体个人信息保护水平。 适用情形:用户说"个保认证怎么做"、"个人信息保护认证 有哪些"、"等保和个保认证的关系"、"认证对出境的帮助"、 "TC260认证"、"网络安全认证"。
-
lgrappag Skill Networking Server SecurityImplement security measures to protect against attacks
-
lgrappag Skill Networking Server AuthorityImplement server-authoritative gameplay for security and integrity
-
lgrappag Skill Savedata Encryption SecurityEncrypt save files to protect player data and prevent tampering
-
lgrappag Skill Security Secure CommunicationImplement secure communication channels
-
lgrappag Skill Security Data Encryption At RESTEncrypt data at rest for protection
-
lgrappag Skill Security Data Retention PoliciesImplement data retention policies
-
jesusgarciafernandez Bundle Auditoria Interna De Procesos Y Operaciones Audit OpsLa Auditoría Interna de Procesos y Operaciones (v2.0) es la competencia de "Saber exactamente cómo se hacen las cosas y cómo mejorarlas constantemente". Úsala para tareas de Legal y Cumplimiento: internal-audit, process-improvement, compliance, risk-management, quality-assurance, iso-9001.
-
jesusgarciafernandez Bundle Estrategia De Ciberseguridad Defensiva Blue OpsLa Estrategia de Ciberseguridad Defensiva (v2.0) es la competencia de "Asegurar que tu organización es un entorno hostil para los atacantes". Úsala para tareas de Desarrollo y Tecnología: cybersecurity, defensive-ops, security-operations-center, soc, incident-response, threat-hunting.
-
jesusgarciafernandez Bundle Optimizacion De Impuestos Y Eficiencia Fiscal Tax OpsLa Optimización de Impuestos y Eficiencia Fiscal (v2.0) es la competencia de "Pagar lo justo, ni un céntimo más". Úsala para tareas de Finanzas y Contabilidad: tax-optimization, fiscal-efficiency, tax-planning, compliance, deduction-strategy, tax-audit.
-
jesusgarciafernandez Bundle Auditoria De Algoritmos Y Analisis Forense De Ia Algo AuditLa Auditoría de Algoritmos y Análisis Forense de IA (v2.0) es la competencia de "Saber por qué la IA ha decidido lo que ha decidido y asegurar que es justo". Úsala para tareas de Legal y Cumplimiento: algorithm-audit, forensics, ai-ethics, bias-detection, transparency, accountability.
-
jesusgarciafernandez Bundle Gestion De Suscripciones Digitales Saas Stack Audit FinanceLa Gestión de Suscripciones Digitales (v2.0) es la competencia financiera de auditar y optimizar el gasto en servicios SaaS (Software as a Service). No es solo "ver cuánto pagamos"; es Ingeniería del Gasto Digital. Úsala para tareas de Datos y Analítica: saas-optimization, subscription-management, finance-ops, cost-control, digital-overhead, stack-audit.
-
jesusgarciafernandez Bundle Regulacion De Inteligencia Artificial Y AI Act Compliance AILa Regulación de Inteligencia Artificial y AI Act (v2.0) es la competencia de "Navegar el complejo marco legal de la IA con precisión y éxito". Úsala para tareas de Legal y Cumplimiento: ai-act, regulation, ethics, compliance, algorithmic-governance, safety-audit.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include tech-threat-detection-team, tech-security-engineer-team, labor-contract-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.