Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ashutoshsrivastava17 Skill Dependency AuditAudit project dependencies — version currency, known vulnerabilities (CVEs), license compliance, unused dependencies, size impact, and upgrade recommendations. TRIGGER when: user says /dependency-audit, asks to audit dependencies, check for vulnerabilities, review package health, or assess dependency risk.
Audited -
ashutoshsrivastava17 Skill Vendor ShortlistEvaluate and shortlist vendors against weighted criteria — capability, cost, references, security, and support. Produce ranked vendor comparison matrices for informed selection decisions. TRIGGER when: user says /vendor-shortlist, "vendor shortlist", "vendor comparison", "vendor evaluation", "shortlist vendors", "compare vendors", "rank vendors", or asks about evaluating vendor proposals.
Audited -
ashutoshsrivastava17 Skill Service Catalog ReviewReview and maintain service catalogs with ownership, dependencies, SLOs, runbooks, and operational metadata. Identify gaps in service documentation and operational readiness. TRIGGER when: user says /service-catalog-review, "service catalog", "service inventory", "service ownership", "catalog review", or asks to review or audit service documentation.
Audited -
ashutoshsrivastava17 Skill Automation AuditAudit workflows for automation — task inventory, repetition frequency, complexity scoring, tool selection, ROI estimation, and implementation priority. TRIGGER when: user says /automation-audit or asks about automating repetitive tasks.
Audited -
ashutoshsrivastava17 Skill Logistics ReviewReview logistics operations including route optimization, carrier performance, cost benchmarking, lead time analysis, and last-mile delivery assessment. TRIGGER when: user says /logistics-review, "review logistics", "shipping analysis", "freight audit", "carrier review", "transportation analysis".
Audited -
ashutoshsrivastava17 Skill Trade ComplianceEnsure trade compliance — export controls, customs classification, sanctions screening, documentation, and audit readiness. TRIGGER when: user says /trade-compliance or asks about import/export compliance.
Audited -
ashutoshsrivastava17 Skill Compliance TrackingTrack compliance requirements, audits, certifications, and regulatory obligations. Covers SOC2, ISO 27001, HIPAA, GDPR, PCI-DSS, and custom frameworks. TRIGGER when: user asks about compliance tracking, audit preparation, certification status, regulatory requirements, control mapping, or evidence collection.
Audited -
ashutoshsrivastava17 Skill Incident InvestigationInvestigate security incidents end-to-end: evidence collection, timeline reconstruction, indicator of compromise (IOC) analysis, impact assessment, containment steps, and lessons learned. TRIGGER when: user says /incident-investigation, asks about investigating a security incident, needs help with forensic analysis, or wants to build an incident timeline.
-
ashutoshsrivastava17 Skill Incident Response PlanCreate or review security incident response plans — roles, communication trees, containment procedures, evidence preservation, and recovery steps. TRIGGER when: user says /incident-response-plan, "IR plan", "incident response plan", "security incident procedure", "breach response plan", or "CSIRT plan".
Audited -
ashutoshsrivastava17 Skill Third Party Risk ReviewAssess third-party vendor security risks — data access, compliance posture, incident history, and contractual safeguards. Produce vendor security risk ratings with remediation requirements. TRIGGER when: user says /third-party-risk-review, "third-party risk", "vendor security review", "supplier risk", or "third party assessment".
-
ashutoshsrivastava17 Skill Vulnerability AssessmentAssess a project's vulnerability posture — check dependencies, configurations, and common security weaknesses. TRIGGER when: user says /vulnerability-assessment, wants to scan for vulnerabilities, asks about dependency security, or needs a security health check.
Audited -
ashutoshsrivastava17 Skill Data Labeling ReviewReview data labeling quality — evaluate annotation guidelines, measure inter-annotator agreement, track quality metrics, handle edge cases, and optimize labeling pipelines for reliable ML training data. TRIGGER when: user says /data-labeling-review, "data labeling review", "annotation quality", "labeling quality", "label review", "annotator agreement", or "data annotation audit".
-
ashutoshsrivastava17 Skill Integration ReadinessAssess technical and operational readiness for partner integrations. Evaluate API compatibility, data sharing requirements, security posture, and operational workflows to determine launch readiness. TRIGGER when: user says /integration-readiness, "integration readiness", "partner integration", "integration assessment", "technical partnership readiness", or "integration checklist".
Audited -
ashutoshsrivastava17 Skill Procurement ComplianceEnsure procurement compliance — policy alignment, regulatory requirements, audit trail documentation, exception handling, and training. TRIGGER when: user says /procurement-compliance or asks about procurement policy compliance.
Audited -
ashutoshsrivastava17 Skill Security Exception ReviewReview and document security exception requests — evaluate risk, define compensating controls, set expiration dates. Track exception approvals and renewal requirements. TRIGGER when: user says /security-exception-review, "security exception", "exception request", "risk acceptance", or "security waiver".
Audited -
ashutoshsrivastava17 Skill Journey MappingMap customer journeys end-to-end — touchpoints, emotions, pain points, moments of truth, channel transitions, and opportunity identification. TRIGGER when: user says /journey-mapping, "map the customer journey", "touchpoint analysis", "customer journey map", "experience map", "journey audit", or "map how customers interact with us".
-
kunanonj Skill Cursor Review SecurityReview code changes with the Security Review subagent. Computes diffs, launches a security-review subagent, and summarizes findings by severity. Use when the user asks to run /review-security or wants a security-focused code review.
-
kunanonj Skill Cursor Plugin Thermos ThermosLaunch both thermo-nuclear review subagents in parallel, then synthesize their findings. Use for thermos, double thermo review, or combined bug/security and code-quality branch audits.
-
kunanonj Skill Cursor Plugin Ponytail Ponytail AuditWhole-repo audit for over-engineering. Like ponytail-review, but scans the entire codebase instead of a diff: a ranked list of what to delete, simplify, or replace with stdlib/native equivalents. Use when the user says \"audit this codebase\", \"audit for over-engineering\", \"what can I delete from this repo\", \"find bloat\", \"ponytail-audit\", or \"/ponytail-audit\". One-shot report, does not
-
fridrichmethod Bundle Nature ResponseDraft, audit, or revise Nature-style revision correspondence packages: point-by-point reviewer-separated response letters, rebuttal letters, revision cover letters, LaTeX cover/response templates, and red-marked revised-manuscript excerpts. Keep mutually blind reviewers isolated so no reviewer-facing response reveals another reviewer's comments, numbering, recommendation, or author response. Prevent reviewer-driven manuscript accretion by preferring replacement, compression, or SI relocation over appending non-central defense prose. Use for reviewer comments, editor decision letters, pasted editorial emails, response drafts, cover letters, response to reviewers, rebuttal, 修回信, 返修邮件, 编辑邮件, 返修 cover letter, 审稿意见回复, 逐点回复, 大修回复, 小修回复, 回复审稿人, 修改稿回复, 写rebuttal, 回应审稿意见, 标红修改, or LaTeX 模板.
-
fridrichmethod Bundle Regulatory DrafterAutomates the drafting of regulatory documents (e.g., FDA CTD sections) with citation management and audit trails.
-
paperclipai Skill Security ReviewPerform a focused 3-phase security review with vulnerability identification, false-positive filtering, and confidence scoring (>80% exploitability threshold) covering Input Validation, Auth, Crypto, Injection, and Data Exposure
-
paperclipai Skill Skill HealthAudit skill configurations for correctness and freshness
-
paperclipai Skill Security DigestScan security advisories and vulnerability disclosures
-
paperclipai Skill Pragmatic Code ReviewPerform a 7-tier hierarchical code quality review covering Architecture, Functionality, Security, Maintainability, Testing, Performance, and Dependencies with triage levels (Critical/Blocker, Improvement, Nit)
-
paperclipai Skill Security Review ActionGitHub Actions workflow for automated security review on pull requests with confidence-gated PR comments
-
paperclipai Skill Orchestrate ReviewMulti-pass code review orchestration with parallel reviewers for quality, security, performance, and test coverage
-
paperclipai Skill Porters Five ForcesPerform Porter's Five Forces analysis — competitive rivalry, supplier power, buyer power, threat of substitutes, and threat of new entrants
-
dingxingdi Bundle Security Vulnerability RepairUse this skill when the user wants software-fix data focused on identifying, mitigating, or preventing security bugs. Trigger it for requests like 'make security repair tasks', 'generate vulnerability-fixing data', 'ensure the new feature is secure against XSS/injections', or 'create patching tasks for insecure code'. This applies both to patching existing vulnerabilities and securely implementing missing features where the primary challenge is defending against CWEs (like timing side-channels, broken access control, or header injections) during development. Do not use it for ordinary non-security defects.
-
dingxingdi Bundle Integrity Aware Visualization And Design Best Practice AuditSkill: integrity-aware visualization and design best-practice audit
-
ashutoshsrivastava17 Skill Ip ReviewReview intellectual property considerations including patent landscape analysis, trademark conflicts, open-source license compatibility, and trade secret protection strategies. TRIGGER when: user says /ip-review, asks to review IP, check patent risks, assess trademark conflicts, review open-source licenses, or evaluate trade secret protections.
-
ashutoshsrivastava17 Skill Data QualityAssess data quality across six dimensions: completeness, accuracy, consistency, timeliness, uniqueness, and validity. Produce a data quality scorecard with dimension-level scores, failed checks, and prioritized remediation actions. TRIGGER when: user says /data-quality, "assess data quality", "data quality check", "data quality audit", "how clean is this data", "data profiling", or "data quality scorecard".
Audited -
ashutoshsrivastava17 Skill Gitops ReviewReview GitOps practices — repository structure, branching strategy, reconciliation loops, drift detection, secret management, and promotion workflows. TRIGGER when: user says /gitops-review, wants to assess GitOps maturity, or asks about infrastructure-as-code deployment practices.
-
ashutoshsrivastava17 Skill License ReviewReview software and open-source licenses for compatibility, obligations, risks, and compliance. Assess license types and usage context. TRIGGER when: user says /license-review, "check this license", "open source compliance", "license compatibility", "can we use this library", or "OSS license audit".
Audited -
ashutoshsrivastava17 Skill Tech DebtAudit a codebase for technical debt, categorize and prioritize findings, and create a structured remediation plan with effort estimates. TRIGGER when: user says /tech-debt, asks to audit code quality, find technical debt, prioritize refactoring, or plan a cleanup effort.
Audited -
ashutoshsrivastava17 Skill Sla ReviewReview and analyze Service Level Agreements — evaluate SLA terms, measure compliance, identify at-risk commitments, and recommend improvements. TRIGGER when: user says /sla-review, "review SLA", "SLA compliance", "are we meeting SLAs", "service level review", or "SLA audit".
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include cursor-review-security, dependency-audit, vendor-shortlist. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.