Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
fabioc-aloha Skill Distribution SecurityDefense-in-depth, PII protection, secrets scanning, and secure packaging for distributed software
-
fabioc-aloha Skill Test Quality AnalysisAnalyze test code quality to detect coverage-only tests, test smells, and low-value assertions. Use when asked to "analyze test quality", "find coverage-only tests", "audit our tests", "are these tests valuable", "find test smells", or "which tests should we delete". Scores tests 1-5 on real value and produces prioritized improvement reports.
-
fabioc-aloha Skill Token Waste EliminationAudit and eliminate token waste from cognitive architecture memory files -- instructions, prompts, skills, and agents
-
fabioc-aloha Skill Extension Audit MethodologySystematic 5-dimension audit framework for VS Code extensions — debug hygiene, dead code, performance, menu validation, dependency cleanup
-
fabioc-aloha Skill Documentation Quality AssuranceSystematic documentation audit, drift detection, preflight validation, and multi-pass quality pipelines
-
fabioc-aloha Skill Fleet ManagementKeep heir projects synchronized with Master Alex brain updates — audit drift, upgrade brains, verify deployments
-
ryan-brosas Bundle Github Repo SetupUse when setting up, governing, or auditing GitHub for a project: create the repository or wire origin, set description and topics, apply namespaced labels, add the PR template and issue forms, configure rulesets with required checks and merge policy, audit the remote for drift, or run a full setup across identity, governance, security, dependencies, and releases.
-
ryan-brosas Bundle Nocodb FoundationUse when building job-queue systems, background/migration jobs, DB-backed caches, streaming data import/export, cross-instance schema serialization with id remapping, or file lifecycle jobs — plus record CRUD funnels (single/bulk), the v1/v2 alias data entry with its shared list engine and nested-link query sanitization, LTAR link engines (nested dispatch, copy/paste swap, display-value linking, cross-base contexts), meta-sync diff/apply machinery (splice diff, pk ratchet, m2m promotion), anonymous shared-view/form security gates AND shared-view metadata projection (related-metas fixpoint, secret stripping), OR pg formula compilation with Airtable IEEE semantics (x/0→±Infinity/NaN CASE ladders, blank→0 coalescing, NaN sort-rank agreement, string-token wire contract) AND drift-hardening seams (per-level nested-lookup link conditions, V2-link conversion guards, import display-value admission): Bull-compatible fallback queue AND Redis variant, versioned migration jobs (incl. EE/CE skew), worker/primary…
-
ryan-brosas Bundle Localterm FoundationUse when building terminal UIs, terminal rendering, pi bash-tool security, daemon power keep-awake, multi-user auth/identity planes (trusted-proxy headers, WebAuthn passkeys, OIDC authorization-code+PKCE, HMAC session cookies), git worktree lifecycle management (porcelain listing, fresh-ref/PR creation, stale sweeps, PTY-occupied delete guards), or scheduled-automation/cron systems: streaming secret redactor, spawn-side env scrub, localterm terminal stack, caffeinate decision machine, Vixie-cron kernel with lossless preset recognition, minute-ticker scheduler, run handoff/claim, downtime reconciliation, and CDP terminal-use.
-
ryan-brosas Skill NPM Trusted PublishingUse when setting up npm publishing from GitHub Actions for a package, adding a publish job or workflow, or answering 'how do I publish this to npm' — the AI does the publishing end to end in GitHub Actions (OIDC trusted publishing, no NPM_TOKEN secret) and guides the human through the one-time npmjs.com settings. Trigger-first; pick over secret-based publishing advice.
-
ryan-brosas Skill Security And HardeningUse when auditing for security vulnerabilities, implementing auth or authz, handling secrets, or hardening against OWASP Top 10 - covers input validation, authentication, dependency auditing, and secure defaults.
-
kernel8901 Bundle Csp GenGenerate Content Security Policy headers for your site. Use when you need to add CSP headers without spending hours reading the spec.
-
kernel8901 Bundle Audit FixerAnalyze npm audit output with AI and get actionable fix suggestions. Use when dealing with security vulnerabilities.
-
dojogenesis Skill ReviewSystematically reviews Playwright test files for anti-patterns, missed best practices, and coverage gaps, producing actionable improvement recommendations. Use when: 'review tests', 'check test quality', 'audit tests', 'improve tests', 'test code review', 'Playwright best practices check'.
-
dojogenesis Skill Zeroize Auditzeroize-audit — Claude Skill
-
dojogenesis Skill Claude Md GuardianCLAUDE.md Guardian
-
dojogenesis Bundle Documentation AuditDocumentation Auditor Skill
-
dojogenesis Skill Skill Audit UpgradeSkill Audit and Upgrade
-
dojogenesis Skill Audit AugmentationAudit Augmentation
-
dojogenesis Skill Differential ReviewDifferential Security Review
-
dojogenesis Skill Audit Prep AssistantAudit Prep Assistant
-
dojogenesis Skill Firebase Apk ScannerFirebase APK Security Scanner
-
ricneves-ai Skill Qms Audit ExpertEspecialista em auditoria interna ISO 13485 para QMS de dispositivos médicos. Cobre planejamento de auditoria, execução, classificação de não conformidades e verificação de CAPA. Use para planejamento de auditoria interna, execução de auditoria, classificação de achados, preparação para auditoria externa ou gestão do programa de auditoria.
-
ricneves-ai Skill Isms Audit ExpertEspecialista em auditoria de Sistema de Gestão de Segurança da Informação (ISMS) para verificação de conformidade ISO 27001, avaliação de controles de segurança e suporte à certificação. Use quando o usuário mencionar ISO 27001, auditoria ISMS, controles do Anexo A, Declaração de Aplicabilidade (SoA), análise de lacunas, gestão de não conformidades, auditoria interna, auditoria de vigilância ou preparação para certificação de segurança.
-
ricneves-ai Skill Changelog GeneratorGerador de Changelog — produz notas de versão consistentes e auditáveis a partir de Conventional Commits, com detecção de bump semântico e renderização de seções Keep a Changelog.
-
ricneves-ai Skill Senior SecurityKit de engenharia de segurança para modelagem de ameaças, análise de vulnerabilidades, arquitetura segura e testes de penetração. Inclui análise STRIDE, orientação OWASP, padrões de criptografia e ferramentas de escaneamento de segurança. Use quando o usuário perguntar sobre revisões de segurança, análise de ameaças, avaliações de vulnerabilidades, práticas de codificação segura, auditorias de segurança, análise de superfície de ataque, remediação de CVE ou melhores práticas de segurança.
-
ricneves-ai Skill Threat DetectionUse ao caçar ameaças em um ambiente, analisar IOCs ou detectar anomalias comportamentais em telemetria. Cobre threat hunting orientado a hipóteses, geração de varredura de IOC, detecção de anomalias por z-score e priorização de sinais mapeados ao MITRE ATT&CK.
-
mattakushi432 Skill Pci DssWhen to activate: PCI DSS, PCI compliance, payment card security, cardholder data, SAQ, QSA, card data environment, tokenization, network segmentation
-
mattakushi432 Skill Iso27001When to activate: ISO 27001, ISMS, information security management, Annex A controls, risk assessment, certification, surveillance audit, Statement of Applicability, ISO 27002
-
mattakushi432 Skill Soc2 PrepWhen to activate: SOC 2, SOC2, trust service criteria, security audit, Type I, Type II, evidence collection, audit preparation, controls, AICPA, vendor security
-
mattakushi432 Skill API SecurityWhen to activate: API security, rate limiting, JWT auth, OAuth2, API keys, WAF, GraphQL security, BOLA, broken object level authorization
-
mattakushi432 Skill Web SecurityWhen to activate: CSP, CORS, XSS prevention, CSRF, SRI, iframe sandbox, Trusted Types, web security headers
-
mattakushi432 Skill Java SecurityWhen to activate: Java security, Spring Security, JWT, OAuth2, SecurityFilterChain, method security, CSRF, CORS, password encoding
-
mattakushi432 Skill Compliance MonitoringWhen to activate: compliance monitoring, continuous compliance, control monitoring, compliance dashboard, policy attestation, compliance calendar, third-party audit, KRI, KCI
-
mattakushi432 Skill Supply Chain SecurityWhen to activate: supply chain security, SBOM, dependency pinning, Sigstore, Cosign, provenance attestation, SLSA framework, software bill of materials
-
sairam0424 Skill Audit LoggingSkill — Audit Logging
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include distribution-security, test-quality-analysis, token-waste-elimination. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.