Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
event4u-app Bundle Security Maturity AssessmentUse when the user wants a security-maturity scorecard / posture assessment of a module — category ratings with evidence, not a vulnerability hunt. Also on 'wie sicher ist dieses Modul aufgestellt?'
-
event4u-app Skill Project Analysis Node ExpressUse for deep Node.js / Express project analysis: boot flow, middleware order, async behavior, data layer, auth/security, and Node-specific runtime failure patterns.
-
marielynneblock Skill Architecture AuditProvides a repeatable, evidence-based framework for reviewing software architectures.
-
marielynneblock Skill Markdown Link AuditorAudit Markdown links, images, and local anchors for broken relative references. Use when reviewing documentation changes, moving or renaming assets, updating indexes, or investigating broken links.
-
marielynneblock Bundle Data Breach Blast RadiusPre-breach impact analysis: inventories sensitive data (PII, PHI, PCI-DSS, credentials), traces data flows, scores exposure vectors, and produces a regulatory blast radius report with fine ranges sourced verbatim from GDPR Art. 83, CCPA § 1798.155(a), and HIPAA 45 CFR § 160.404. Cost benchmarks from IBM Cost of a Data Breach Report (annually updated). All citations in references/sources.md for verification. Use when asked: "assess breach impact", "what data could be exposed", "calculate blast radius", "data exposure analysis", "how bad would a breach be", "quantify data risk", "sensitive data inventory", "data flow security audit", "pre-breach assessment", "worst-case breach scenario", "breach readiness", "data risk report", "/data-breach-blast-radius". For any stack handling user data, health records, or financial information. Output labels law-sourced figures (exact) vs heuristic estimates (planning only). Does not replace legal counsel.
-
event4u-app Skill SecurityUse when applying security best practices — authentication, authorization, CSRF protection, input sanitization, rate limiting, or secure coding — stack-agnostic.
-
event4u-app Bundle Brand AuditAudit how a brand is currently expressed across touchpoints and flag drift from its defined tokens, voice, and strategy. Use to inventory and critique an existing brand before changing it.
-
event4u-app Bundle Code ReviewUse when the user says "review this", "check my code", or wants feedback on changes. Reviews for correctness, quality, security, and coding standards.
-
event4u-app Bundle History DesignUse when choosing HOW to record change history / audit trails — walks the tier matrix (columns → audit log → temporal → event sourcing). Triggers on 'wer hat was wann', 'audit log'.
-
event4u-app Bundle Security AuditSecurity audit — vulnerability scan, pentest review, attack-surface sweep; explicit request only, not regular feature work. Pre-implementation threat pass → threat-modeling.
-
tangledgroup Bundle Voidauth 1 12 3Open-source SSO authentication and user management provider for self-hosted applications. Provides OIDC Provider, ProxyAuth forward authentication, user/group management, passkeys, and email-based invitations. Use when deploying or configuring VoidAuth as an identity provider, setting up OIDC integrations with self-hosted apps, securing domains via ProxyAuth behind Caddy/NGINX/Traefik reverse proxies, managing users and security groups, or troubleshooting authentication flows.
-
tangledgroup Bundle Zeromq Wiki 3 2 0A comprehensive toolkit for ZeroMQ (ØMQ) messaging library covering socket patterns, protocols, architecture, and best practices. Use when building distributed applications, implementing messaging patterns like REQ/REP, PUB/SUB, PUSH/PULL, designing multi-threaded architectures, working with ZMTP protocol, CURVE security, or understanding ØMQ internals for performance tuning and troubleshooting.
-
tangledgroup Bundle Aiohttp Security 0 5 0Authentication and authorization toolkit for aiohttp.web applications providing identity policies (cookies, sessions, JWT) and custom authorization with permission-based access control. Use when building aiohttp.web applications requiring session-based authentication, protecting routes with permission checks, implementing login/logout flows, or integrating JWT bearer tokens.
-
domehahn Bundle Threat ModelerIdentify assets, trust boundaries, abuse cases, attack paths, threats, and required security controls.
-
domehahn Bundle Malicious HelperA deliberately malicious security regression fixture.
-
domehahn Bundle Secure Code ReviewerReview code vulnerabilities such as injection, path traversal, SSRF, XSS, deserialization, crypto misuse, and race conditions.
-
domehahn Skill Yara MalwareYARA malware fixture
-
domehahn Bundle Test Strategy EngineerDesign and generate unit, integration, regression, security, and end-to-end test strategies.
-
domehahn Bundle AI Change Risk ReviewerReview AI-assisted changes before execution for automation boundaries, human approval, affected-system criticality, and audit evidence.
-
domehahn Bundle Audit Evidence ReviewerReview evidence, approvals, tickets, logs, test protocols, risk decisions, versioning, and accountable owners.
-
domehahn Bundle Policy As Code ReviewerReview GitLab Security Policies, OPA/Rego, Kyverno, Conftest, Sentinel, admission policies, compliance pipelines, and central guardrails.
-
domehahn Skill False PositiveNegative security fixture
-
domehahn Bundle Vulnerable OsvKnown vulnerable dependency fixture
-
domehahn Bundle Auto Remediation ReviewerReview automated repair actions for safe limits, dry runs, approval modes, rollback, audit logs, blast radius, and loop protection.
-
domehahn Bundle Container Security ReviewerReview Dockerfiles, base images, user rights, capabilities, SBOM, image signing, distroless or slim images, CVEs, and runtime hardening.
-
domehahn Skill Secret ExfiltrationPositive exfiltration fixture
-
domehahn Bundle Audit Traceability MaintainerLink requirements, controls, implementation, tests, tickets, and evidence into an auditable trace.
-
domehahn Bundle Architecture Decision RecorderCreate and maintain ADRs with context, decisions, alternatives, risks, security impact, compliance relation, and review points.
-
domehahn Bundle Osv Known VulnerabilityOSV integration fixture
-
domehahn Skill Credential Access NegativeInert instruction-analysis fixture
-
domehahn Skill Credential Access PositiveInert instruction-analysis fixture
-
internscience Skill Guess Word Yes NoRun a yes-or-no word guessing game. Choose a common secret word, answer only with 是 or 否 for up to 15 rounds, and reveal the word after 15 questions or a correct guess.
-
ryan-brosas Bundle Pydantic Settings FoundationUse when porting layered settings/config resolution machinery — ordered settings-source pipelines, env-var field resolution with aliases, nested-delimiter explosion of complex values, .env extra harvesting, secret-dir scanning, alias-aware JSON/TOML/YAML config file sources, or argparse-style CLI settings sources with repeated-flag merging, bool flag modes, and subcommand app runtimes from pydantic-settings.
-
qualixar Skill NPM Audit ReporterQuick utility to process config data.
-
qualixar Skill Bandit Security ScannerCompact tool verifying data state.
-
swan-gtm Skill Audit SwanChecks whether a Swan workspace is structurally healthy. Use for configuration audits that surface missing knowledge, disconnected integrations, exhausted senders, broken triggers, sparse CRM data, and credit or subscription issues.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-maturity-assessment, project-analysis-node-express, architecture-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.