Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ulpi-io Skill Newsletter Signup GeneratorWhen the user wants to design, optimize, or audit newsletter signup forms. Also use when the user mentions "newsletter," "email signup," "subscribe form," "email capture," "lead magnet," "newsletter form," "email opt-in," "subscribe CTA," "newsletter signup," or "email list building."
-
ulpi-io Skill Alicloud Security Center Sas TestMinimal smoke test for Security Center SAS skill. Validate read-only query flow.
-
ulpi-io Skill Customer Stories Page GeneratorWhen the user wants to create, optimize, or audit customer stories or case study pages. Also use when the user mentions "case studies," "customer stories," "success stories," "testimonials page," "case study," "customer proof," "social proof page," or "results page."
-
ulpi-io Skill Alicloud Security Content Moderation Green TestSmoke test for alicloud-security-content-moderation-green. Validate minimal authentication, API reachability, and one read-only query path.
-
agents-store Skill N8n CLI Recipesn8n CLI commands for self-hosted instances. Use when executing workflows from command line, exporting/importing workflows and credentials, managing licenses, resetting user accounts, running security audits via CLI, or managing community nodes. Also use when asking about "n8n CLI", "command line", "n8n execute", "export workflow".
-
agents-store Skill History TrackingMemory history and change tracking — view evolution of memories over time, audit modifications, and track knowledge changes. This skill should be used when the user asks to see memory changes, audit modifications, or track how information evolved.
Audited -
agents-store Bundle Code AuditThis skill should be used when the user asks "what is in the code that the documents do not know about", "сверь код с документами", "обнови документы по коду", "изучи код и найди несоответствия", "the docs are out of date, read the code", or runs /macstack-dev:check --code on a project whose macstack/ folder already exists. Enumerates what the code contains, compares it to the client documents and the spec, and proposes edits in the client → generated → macstack.json direction — it never edits a client document on its own.
-
agents-store Skill Config ValidationValidates openclaw.json against official OpenClaw documentation and checks for latest features, deprecated settings, and security issues. Use this skill whenever the user wants to verify their configuration is correct, check if they're using the latest OpenClaw features, audit their openclaw.json for problems, or compare their config against best practices. Also applies when the user says things like "is my config OK", "what am I missing in my setup", or "check my OpenClaw configuration".
-
mkurman Skill ReviewReview code changes for security, performance, bugs, and quality. Reviews staged changes, unstaged changes, specific commits, or PR-ready diffs.
-
mkurman Skill Label Quality AuditAudit label quality using confident learning (Northcutt et al.), cross-validation noise detection, and per-class error analysis. Identifies mislabeled examples for review.
-
mkurman Skill Best PracticesApply modern web development best practices for security, compatibility, and code quality. Use when asked to "apply best practices", "security audit", "modernize code", "code quality review", or "check for vulnerabilities".
Audited -
kevinzai Skill Owasp Top 10Check applications against the OWASP Top 10 vulnerabilities with specific tests, examples, and remediation for each category.
-
kevinzai Skill Security AuditComprehensive security audit combining SAST, DAST, manual code review, and threat modeling for applications.
-
kevinzai Skill Secrets ScannerScan codebases for hardcoded secrets, API keys, tokens, passwords, and credentials with remediation guidance.
-
kevinzai Skill Container SecurityContainer security — image hardening, vulnerability scanning, runtime security, secrets management, and compliance.
-
kevinzai Skill Dependency AuditAudit npm, pip, cargo, and other package dependencies for known vulnerabilities, license compliance, and supply chain risks.
-
kevinzai Skill Variant AnalysisFind variants of known vulnerabilities across a codebase — when one bug is found, systematically find its siblings.
-
kevinzai Skill Incident ResponseSecurity incident response playbook — containment, investigation, remediation, and post-incident review procedures.
-
kevinzai Skill Ccc E2eend-to-end pre-release assessment. Fans out via /ccc-fleet into 3 isolated worktrees (QA audit + unit tests + Playwright E2E), each invoking /ccc-testing sub-skills,…
-
kevinzai Bundle Ccc XrayProject health scorecard — scans current repo across 7 dimensions (quality, docs, tests, deps, security, perf, CI) and returns a markdown table with 0-100 scores +…
-
kevinzai Skill Ccc HardenProduction hardening audit across 11 pillars (Vercel, GitHub, Sentry, PostHog, Stripe, Cloudflare, Secrets/PII). Read-only; --fix applies safe auto-fixes. Use pre-launch. NO PII.
-
kevinzai Skill Ccc UpgradeAudit and update vendor submodules. Lists every submodule under vendor/, fetches latest, reports per-submodule current/latest commits and changed file counts, prompts…
-
kevinzai Skill Ccc ClaudemdAudit the project CLAUDE.md against the codebase — stale paths, dead commands, token waste — fixes applied only after AskUserQuestion approval. Use when: 'audit claude md', 'optimize instructions'.
-
kevinzai Skill Ccc Pro SaasMulti-tenant SaaS scaffolds: row-level security, billing, invitations · Pro tier only
-
kevinzai Skill Ccc Code ReviewReview code changes for security, performance, correctness, and maintainability. Use when: 'review code', 'PR review', 'check changes', 'review my diff', 'is this…
-
kunanonj Skill Cursor Plugin Postman Postman RoutingAutomatically routes Postman and API-related requests to the correct command. Use when user mentions APIs, collections, specs, testing, mocks, docs, security, or Postman.
-
kunanonj Skill Cursor Plugin Posthog Auditing EndpointsAudit every endpoint in a PostHog project for staleness, failed materialisations, and unused materialised versions. Use when the user asks \"what endpoints can I clean up?\", \"are any of my endpoints broken?\", \"which materialised versions are still being called?\", or wants a one-shot cleanup pass over the Endpoints product. Produces a prioritised report grouped by issue type, with recommended
-
kunanonj Skill Cursor Plugin Thermos Thermo Nuclear ReviewComprehensive security and correctness audit of a branch's changes. Use for thermo nuclear, thermonuclear, or deep review requests, or branch/PR diff audits focused on bugs, breaking changes, security issues, devex regressions, and feature-gate leaks.
-
kunanonj Skill Cursor Plugin Posthog Auditing Experiments FlagsAudit PostHog experiments and feature flags for configuration issues, staleness, and best-practice violations. Read when the user asks to audit, health-check, or review experiments or feature flags, check flag hygiene, or verify experiment setup.
-
kunanonj Skill Cursor Plugin Posthog Signals Scout Csp ViolationsFocused Signals scout for PostHog projects collecting Content Security Policy (CSP) violation reports. Watches `$csp_violation` events for fresh blocked-URL clusters, per-directive bursts, page-scoped regressions after deploys, and suspicious third-party domains that may indicate a compromised script. Emits aggregated findings only when a cluster clears the confidence bar; otherwise writes durable
-
kunanonj Skill Cursor Plugin Convex Rule Custom Functions For AuthUse custom functions for data protection - this is Convex's alternative to Row Level Security (RLS)
-
kunanonj Skill Cursor Plugin Posthog Finding Deleted Feature FlagsFind feature flags that were soft-deleted in the active project within a recent time window. Use when the user asks \"what flags were deleted in the last N days\", \"show me recently deleted feature flags\", \"who deleted flag X\", \"audit recent flag deletions\", or anything similar. Handles the non-obvious gotcha that system.feature_flags exposes the deleted boolean but does not expose a deletio
-
kunanonj Skill Cursor Plugin Posthog Diagnosing Endpoint PerformanceDiagnose why a PostHog endpoint is slow or expensive and propose a concrete fix — bump the cache TTL, enable materialisation, restructure variables, or rewrite the query. Use when the user says \"this endpoint is slow\", \"my endpoint times out\", \"we're hitting the cost cap on this one\", or asks \"should I materialise this?\". Focuses on a single named endpoint, not a project-wide audit.
-
kunanonj Skill Cursor Plugin Posthog Signals Scout Anomaly DetectionSignals scout that watches a PostHog project's most-viewed dashboards and insights for recent anomalies — sudden bursts, drops, flat-lines, and trend breaks at the daily or hourly level. It discovers what the team actually looks at (view counts, dashboard access), curates a durable watchlist in the scratchpad, and balances re-checking known high-value insights (exploit) against discovering new one
-
mittuled Bundle Security Compliance EnablerThis skill implements controls and processes to achieve and maintain security certifications. Use when asked to prepare for a SOC 2 audit, implement GDPR controls, or build a compliance program. Also consider when customers require compliance attestations. Suggest when the user pursues certifications without a control implementation plan.
-
mittuled Bundle Continuous Security MonitoringThis skill operates ongoing security monitoring including SIEM correlation, vulnerability scanning, and real-time alerting. Use when asked to set up security monitoring, configure SIEM rules, or investigate security alerts. Also consider when a new service deploys without security observability. Suggest when the user launches infrastructure without detection coverage.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include newsletter-signup-generator, alicloud-security-center-sas-test, customer-stories-page-generator. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.