Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ffsshhttiikk Skill Incident Response And ForensicsDetecting, responding to, and investigating security incidents with forensic analysis techniques
-
ffsshhttiikk Skill Security AutomationAutomating security scanning, compliance checks, incident response, and remediation workflows
-
ffsshhttiikk Skill Event SourcingArchitectural pattern storing state changes as immutable events for complete audit trail and temporal queries
-
yejiming Bundle Okx SecurityUse this skill for security scanning: check transaction safety, is this transaction safe, pre-execution check, security scan, token risk scanning, honeypot detection, DApp/URL phishing detection, message signature safety, malicious transaction detection, approval safety checks, token approval management. Triggers: 'is this token safe', 'check token security', 'honeypot check', 'scan this tx', 'scan this swap tx', 'tx risk check', 'is this URL a scam', 'check if this dapp is safe', 'phishing site check', 'is this signature safe', 'check this signing request', 'check my approvals', 'show risky approvals', 'revoke approval', 'check if this approve is safe', token authorization, ERC20 allowance, Permit2. Covers token-scan, dapp-scan, tx-scan (EVM+Solana pre-execution), sig-scan (EIP-712/personal_sign), approvals (ERC-20/Permit2). Chinese: 安全扫描, 代币安全, 蜜罐检测, 貔貅盘, 钓鱼网站, 交易安全, 签名安全, 代币风险, 授权管理, 授权查询, 风险授权, 代币授权. Do NOT use for wallet balance/send/history — use okx-agentic-wallet.
-
yejiming Skill Okx Audit LogUse this skill when the user asks to export audit logs, find audit log location, view command history, 导出日志, 查看日志, 日志路径, 操作记录, 调用记录, 命令历史. Do NOT use for wallet balance, token search, swap, or any other on-chain operation — use the corresponding skill instead.
Audited -
yejiming Bundle Simple EarnBinance Simple-earn request using the Binance API. Authentication requires API key and secret key.
-
yejiming Bundle Sub AccountBinance Sub-account request using the Binance API. Authentication requires API key and secret key.
-
yejiming Bundle Gate Dex MarketGate DEX READ-ONLY market data lookup skill. For data queries that NEVER execute on-chain transactions: check token prices, view K-line charts, browse token rankings, discover new tokens, analyze holders, run security audits, view trading volume and liquidity. This skill only READS data — it never buys, sells, swaps, transfers, or modifies wallet state.
-
yejiming Skill Okx X402 PaymentThis skill should be used when the user encounters an HTTP 402 Payment Required response, wants to pay for a payment-gated API or resource, or mentions 'x402', 'pay for access', '402 payment', 'payment-gated URL', or 'sign x402 payment'. Primary path signs via TEE with a wallet session (JWT); fallback path guides local EIP-3009 signing with the user's own private key if they have no wallet. Returns the payment proof (signature + authorization) that the caller can attach as a payment header to access the resource. Do NOT use for swap or token transfers — use okx-dex-swap instead. Do NOT use for wallet balance or portfolio queries — use okx-agentic-wallet or okx-wallet-portfolio. Do NOT use for security scanning — use okx-security. Do NOT use for transaction broadcasting — use okx-onchain-gateway. Do NOT use for general programming questions.
-
yejiming Bundle RaydiumAudit Raydium liquidity positions before capital is deployed. Analyze pool depth, concentration, liquidity quality, structural risks, and parameter changes so users can make cleaner LP decisions.
-
yejiming Bundle Gate Info RiskcheckToken and address risk assessment. Use this skill ONLY when the user's query is exclusively about token/contract/address security with no other analysis dimensions. Trigger phrases: is this token safe, check contract risk, is this address safe, honeypot, rug. If the query ALSO mentions fundamentals, technicals, news, sentiment, or any other analysis dimension, use gate-info-research instead — it handles multi-dimension queries in a single unified report. Address risk mode (is this address safe) is exclusive to this skill and must NOT be routed to gate-info-research.
-
yejiming Bundle PancakeswapAudit PancakeSwap liquidity positions before capital is deployed. Evaluate depth, concentrated-liquidity setup, range risk, pool quality, and approval friction before users provide liquidity.
-
yejiming Bundle Gate Info CoinanalysisSingle-coin comprehensive analysis. Use this skill ONLY when the user asks to analyze one coin with no additional explicit dimension (e.g., no separate risk check, no separate trend-only request). Trigger phrases: analyze SOL, how is BTC, is ETH worth buying. If the query ALSO mentions security/risk, event attribution, multi-coin comparison, or any other analysis dimension beyond single-coin comprehensive, use gate-info-research instead — it handles multi-dimension queries in a single unified report.
-
nahisaho Skill Co Scientist Audit ReportResearch audit report skill. Systematic quality assessment of experimental designs, statistical analyses, reproducibility, and reporting standards compliance. Use when working with systematic quality assessment of experimental designs, statistical analyses, reproducibility.
-
yejiming Bundle Trailofbits SkillsSecurity testing skills from creators of Slither, Echidna, Medusa. Smart contract vulnerability scanners, property-based testing, static analysis, and audit tools from Trail of Bits.
-
yejiming Bundle Crypto Intel Security ScannerSmart Contract Security Scanner
-
yejiming Bundle Smart Contract Security ScannerSolidity Security Analyzer
-
yejiming Bundle Use Developer Controlled WalletsCreate and manage Circle developer-controlled wallets where the application retains full custody of wallet keys on behalf of end-users. Covers wallet sets, entity secret registration, token transfers, and balance checks via the developer controlled wallets SDK. Triggers on: developer-controlled wallets, dev-controlled wallets, create wallet, wallet set, entity secret, transfer tokens, check balance, EOA wallet, SCA wallet, initiateDeveloperControlledWalletsClient, createWalletSet, createWallets, custody wallet.
-
ffsshhttiikk Skill HttpsHTTPS and TLS security
Audited -
ffsshhttiikk Skill OwaspPractical application and coding skills for Owasp
Audited -
ffsshhttiikk Skill SecuritySecurity best practices and patterns
-
ffsshhttiikk Skill DevsecopsSecurity integration in DevOps practices
Audited -
mittuled Bundle Ip AssignmentThis skill ensures all intellectual property is properly assigned to the company from founders, employees, and contractors. Use when asked to draft IP assignment agreements, audit IP ownership, or prepare for due diligence. Also consider when new founders or contractors join without signed assignments. Suggest when the user is about to engage contractors without IP transfer provisions.
-
mittuled Bundle Security Auditor LegalThis skill conducts legal review of security audit findings to assess regulatory disclosure obligations. Use when asked to evaluate breach notification triggers, assess regulatory reporting requirements from security findings, or determine disclosure obligations. Also consider when a penetration test reveals a vulnerability involving personal data. Suggest when the user receives audit findings without legal review.
-
mittuled Bundle Security AuditorFinds vulnerabilities in code and configuration before attackers do, protecting the product and its users. Use when asked to security auditor. Suggest when relevant.
-
mittuled Bundle Security Reviewer LegalThis skill reviews security architecture and practices for legal and regulatory compliance. Use when asked to assess whether security controls meet legal requirements, review data protection measures for regulatory adequacy, or evaluate encryption and access controls against compliance standards. Also consider when designing security architecture for regulated data. Suggest when the user builds security controls without considering legal requirements.
-
npbuilds Bundle Xy DetectorDetect XY-pattern problem statements where someone asks about an attempted solution rather than the underlying goal. Use during binding-vow's Phase 6 audit, or directly when a question feels narrowly mechanical for the apparent stakes. Returns the inferred underlying goal Y if a pattern is detected, plus a reformulated statement, or 'no XY pattern' otherwise.
-
npbuilds Bundle Scope BounderSurface the scope boundaries (time period, population, context) of a problem statement and check whether they are explicit and defensible. Thin coordinator over philosophy/logic/assumption-excavator with depth=surface and category=scope. Use in binding-vow's Phase 6 audit. Returns explicit/implicit/missing assessment per boundary type plus reformulation hints.
-
npbuilds Skill Statement AuditRoute a candidate problem statement through the audit battery — XY-pattern detection, answerability, falsifiability, scope bounding, and the six-axis grader. Activate at six-eyes Phase 6 (Audit) to catch the standard failure modes before a statement is accepted, and to decide whether the re-state loop must fire. This director owns the "is this statement actually sound?" question.
-
mittuled Bundle Penetration TesterThis skill conducts penetration tests against systems to identify exploitable vulnerabilities. Use when asked to pen test an application, validate security controls, or simulate an attacker. Also consider when a major release ships without offensive testing. Suggest when the user relies solely on automated scanners for security validation.
-
mittuled Bundle Secure Code ReviewerThis skill reviews code for security vulnerabilities including OWASP Top 10 and language-specific risks. Use when asked to review code for security, audit a pull request for vulnerabilities, or assess third-party library safety. Also consider when a new developer joins and submits their first PR. Suggest when the user merges code without security review.
-
mittuled Bundle Security ReviewerThis skill reviews backend code for security vulnerabilities including injection, auth flaws, and data exposure. Use when asked to perform a security review, audit authentication logic, or check for OWASP Top 10 issues. Also consider when a service handles PII or payment data. Suggest when a PR modifies authentication, authorization, or data-handling code.
-
mittuled Bundle Security Baseline SetupThis skill establishes the security baseline configuration for all systems at project inception. Use when asked to set up security defaults, harden a new environment, or configure initial security controls. Also consider when a new project starts without security foundations. Suggest when the user provisions infrastructure without hardening.
-
mittuled Bundle Financial Audit PreparerThis skill prepares the company for financial audits including documentation, schedules, and auditor coordination. Use when asked to prepare for an annual audit, compile audit schedules, or coordinate with external auditors. Also consider when the company is approaching its first audit or when audit findings from prior years need remediation. Suggest when the user is planning a fundraise that will require audited financials.
-
mittuled Bundle Copy Implementation ReviewerThis skill reviews implemented copy in the product for accuracy and consistency with design specifications. Use when asked to review shipped copy, audit UX writing quality, or check copy against the content design spec. Also consider when a release is about to ship and no copy review has been performed. Suggest when the user notices copy inconsistencies in a recently deployed feature.
-
mittuled Bundle Compliance Ga Reviewer EngThis skill reviews engineering deliverables for compliance with security and regulatory requirements at general availability. Use when asked to sign off on a GA release, audit compliance controls, or verify regulatory readiness. Also consider when a product ships to regulated markets. Suggest when the user prepares a GA release without a compliance checkpoint.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include Incident Response and Forensics, Security Automation, Event Sourcing. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.