Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
bromso Skill Soc2 PrepPrepare for SOC 2 audit — policies, controls, evidence collection
-
bromso Skill HipaaAssess HIPAA compliance — Privacy Rule, Security Rule, Breach Notification, BAAs
-
bromso Skill Legal AuditAudit current legal posture — identify gaps in policies, contracts, and compliance
-
bromso Skill Siem SetupDesign SIEM architecture, correlation rules, and dashboards
-
bromso Skill API SecurityAudit API security
-
bromso Skill Iac SecurityScan infrastructure-as-code for misconfigurations
-
bromso Skill Pentest PlanPlan penetration testing scope, methodology, and rules of engagement
-
bromso Skill Threat IntelResearch threat intelligence for a specific technology or threat actor
-
bromso Skill Recovery PlanDesign disaster recovery and system restoration procedures
-
bromso Skill Risk AppetiteEstablish risk tolerance levels and acceptance criteria
-
bromso Skill Secure CodingReview code for OWASP Top 10 vulnerabilities and secure coding practices
-
gaelic-ghost Bundle Inspect Macos Runtime ActivityCorrelate suspicious macOS process, file, network, permission, and log activity. Use for unexpected processes, downloads, open files, DNS, privacy prompts, alerts, file mutations, injected executables, and Endpoint Security evidence.
-
gaelic-ghost Bundle Research Macos Security ControlResearch one macOS security control on an exact build, separating public contracts, private evidence, and hypotheses. Use for TCC, sandbox, entitlements, Gatekeeper, XProtect, Hardened Runtime, SIP, or system-policy changes.
-
gaelic-ghost Bundle Choose Macos Virtualization ShapeChoose the smallest macOS-hosted boundary for development, compatibility, or authorized security research. Use when deciding among the host, containers, container machine, full Linux or macOS VMs, remote systems, or physical Macs.
-
gaelic-ghost Bundle Macos Sandbox File Access WorkflowDesign and diagnose macOS file access. Use for App Sandbox, App Groups, user selection, security-scoped bookmarks across relaunches, helpers or extensions, stale access, TCC overlap, POSIX or ACL, Data Vault, and SIP denials.
-
gaelic-ghost Bundle Swiftui Performance AuditDiagnose SwiftUI rendering, scrolling, update, CPU, memory, image, layout, and animation performance from code and evidence. Use when a SwiftUI feature is slow, janky, broadly invalidating, memory-heavy, or needs a code-first audit before Instruments capture.
-
gaelic-ghost Skill Auth Authorization WorkflowPlan, implement, test, and diagnose server-side Swift authentication and authorization for Vapor and Hummingbird services, including Basic and Bearer auth, JWT, sessions, OAuth or OIDC handoffs, password hashing, token lifecycle, middleware placement, request context, route protection, authorization policy, security-sensitive tests, and deployment secret handoffs.
Audited -
gaelic-ghost Bundle Perform Apple Dynamic AnalysisPlan and record bounded dynamic analysis of Apple binaries using supported LLDB, Xcode, Instruments, unified logging, Simulator, physical-device, macOS VM, or research-device surfaces. Use when Codex must verify a static hypothesis at runtime, launch or attach, inspect images, memory regions, registers, exceptions, or generated data, correlate runtime addresses, or explain how Developer Mode, signing, get-task-allow, SIP, security policy, Rosetta, hardware, and exact OS build constrain the observation.
-
gaelic-ghost Bundle Report Apple Security ResearchTurn Apple-platform security research evidence into a reproducible, exact-build technical report. Use when Codex must document affected hardware and OS builds, expected and observed behavior, a minimal test case, artifact hashes, crash or sysdiagnose evidence, impact, mitigations, version bounds, beta revalidation, unresolved questions, or a handoff to the current Apple Security Research, Security Bounty, or Security Research Device reporting process.
-
gaelic-ghost Bundle Audit Apple Signing And ContainmentAudit Apple code signatures, code directories, CDHashes, authorities, Team IDs, designated requirements, provisioning profiles, entitlements, hardened runtime, library validation, notarization, App Sandbox, SIP, Data Vaults, and platform-binary context. Use when Codex must explain an Apple artifact's declared identity and containment state, compare original and re-signed copies, or separate signed claims from access observed at runtime.
-
clowlove Bundle Blockchain Security Auditor专注智能合约漏洞检测、形式化验证、漏洞利用分析和审计报告编写的安全审计专家,服务于 DeFi 协议和区块链应用。
-
clowlove Bundle Engineering Security Engineer专业应用安全工程师,专注于威胁建模、漏洞评估、安全代码审查、安全架构设计和事件响应,服务于现代 Web、API 和云原生应用。
-
clowlove Bundle Engineering Threat Detection Engineer专精于 SIEM 规则开发、MITRE ATT&CK 覆盖度映射、威胁狩猎、告警调优和检测即代码流水线的安全运营检测工程专家。
Audited -
melodic-software Bundle Quality GateSingle-lens review checkpoint between 'code works' and 'code is ready'. Routes to self, code, architecture, security, spec, close-out, downstream, pr, criteria, slice, or restatement mode and delegates to the matching reviewer. Use when the user says 'review this', 'self-review', 'quality gate', 'code review', 'architecture review', 'security review', 'does this match the spec/issue/plan', or 'close-out review' / 'review the container' for a shipped spec container, or after implementation completes. Downstream mode covers 'what could this break', 'blast radius', 'what else does this touch', 'who calls this'. Breakage outside the diff on a change already written; assessing a plan's reach before implementation is '/planning:plan' and '/planning:devils-advocate', and a rename sweep is '/docs-hygiene:rename-references audit blast'.
-
melodic-software Bundle Sweep AllCompose this plugin's discipline correctors into ONE batched pass. Requires conversation-inheriting fork subagents (`subagent_type: fork`); without fork mode it degrades to the posture digest and audits nothing. At conversation start it instead reports a cheap posture digest (which disciplines are in scope) with no audit. Use when: 'sweep all disciplines', 'ground ourselves', 're-anchor everything', 'run the whole re-anchor bundle', 'posture batch', 'set our posture before we start', 'batch the correctors', or at conversation start to set posture across every standing discipline at once. Membership is each corrector's own tier metadata; for a single discipline, invoke that corrector directly.
-
melodic-software Bundle CompressCompress (tighten, shorten, trim) markdown files by dropping flavor, filler, hedging, articles, while preserving all content (directives, qualifiers, thresholds, examples), with a mandatory semantic-diff subagent that reverts any SEMANTIC LOSS or AMBIGUITY. Use when: 'compress this doc', 'tighten markdown', 'cut prose', 'shorten without losing meaning', 'trim onboarding doc', or verbose prose in docs/, READMEs, rule bodies, skill bodies, or third-party pasted text. Actions: default (snapshot → backend → semantic-diff subagent → revert-pass → markdownlint) and audit (read-only dry-run classifying SKIP/COMPRESS/UNCERTAIN per file); empty target + clean tree in an interactive session offers a confirmation-gated repo-wide run (audit-first interview with prescribed defaults) instead of the no-op; flags: --force (bypass <3% revert rule), --keep-snapshot; not for: session compaction (/compact), markdown noise classification (/audit-noise), code-comment trimming, or content relocation/SSOT consolidation (/extract-sso
-
melodic-software Bundle DeltaReport only what changed in the enforcement surface since the last audit. Re-runs `overengineering:audit`, compares this run's findings spine against the one the previous cycle left behind, and captures a fresh baseline for the next run. The report covers new clutter, verdict moves, closures, and status changes, filtered through a configurable noise budget, so a recurring run is a short delta instead of the whole surface again. Read-only always: it never invokes or enters `overengineering:realign`, never writes a Status, and never touches the surface it reads; verdict changes queue for the human. A first run establishes a baseline and reports no deltas. Use when the ask is for what moved since the last enforcement audit ('what changed since the last audit', 'did any verdict move') or for a recurring, scheduled enforcement check ('run the enforcement audit on a schedule'). Pass layers to scope the pass and `unattended` for a scheduled or dispatched run; both pass straight through to the audit.
-
melodic-software Bundle Security ReviewCI security-review lane for a GitHub pull request. Logic, trust-boundary, and Actions security findings static analysis misses. Use when: 'CI security review', 'claude-security-review lane', '/review:security-review', or a reusable workflow invokes the org security-review plugin command.
-
melodic-software Bundle StatelessInspect and turn off Claude Code's auto memory, the notes Claude writes itself per repo under ~/.claude/projects/<project>/memory/. Use when: 'make Claude stateless', 'stop Claude remembering', 'disable auto memory', 'turn off auto-memory', 'purge/clear/delete auto memory', 'wipe what Claude saved about this repo', 'does Claude have saved memories'. Actions: status (default, memory + settings across all scopes), disable (autoMemoryEnabled:false + CLAUDE_CODE_DISABLE_AUTO_MEMORY), purge (destructive delete, confirm-gated). Auto-memory only, not CLAUDE.md/rules (use /claude-memory:audit) and not transcripts/history.
-
melodic-software Bundle Audit SizeMeasure lines per file for the changed files, a path, or the whole tree: total, blank, comment, and code lines when `scc` resolves, total and non-blank lines from a bundled counter otherwise, per lane (TypeScript/JavaScript, Python, Bash, Go; C# files are counted too). Each file is reported beside a configurable reference with its provenance (default 1000 non-blank lines, the plugin's own number and not ISO-backed; 500 selectable; an ISO/IEC 5055 §8.2.115 function-percentage mode selectable), and the report never emits a finding, a severity, or an exit-code gate. Use when: 'how long are these files', 'lines per file', 'file size audit', 'which files are too big', 'LOC per file', 'is this file over 1000 lines', 'count lines in the change'; for cyclomatic or cognitive complexity use /code-metrics:audit-complexity, and for a repo-wide dashboard this is the wrong tool (it measures a change).
-
melodic-software Bundle JustifyJustify the existence of any artifact you point at: was there a reason for this when it was built, and does that reason still hold today. Walks one target you name (a path, a `path#heading`, or a kind-prefixed identifier) and reports a verdict on the evidence-earned-keep ladder, each row carrying how much evidence supports it. Read-only: it reports and then discusses, never applies a remedy, and writes its findings to the memory tier; the one tracked write, persisting the resolved home to the concern file, needs explicit confirmation. Use when: 'justify this', 'does this need to exist', 'why is this here', 'is this still valid', 'earn its keep', 'justify the existence of'. With no target it never sweeps; it uses what the session has been discussing, else offers to rank candidates by age, else asks. Not for the enforcement surface (hooks, CI lanes, gate scripts, branch protections), which routes to the sibling `audit` skill, and not for applying a fix, which routes to the owner named in the finding.
-
melodic-software Bundle RealignExecute an enforcement-surface audit's findings behind an explicit per-item human gate. Consumes the findings artifact either producer wrote. It never scans or re-judges the surface itself. For each finding the operator accepts, it drives interview → explore and research → plan → implement through presence-gated skill composition, executing every removal down the rollback ladder: config-disable first, observe for a window with a stated end date, delete last with a recorded rationale. Unproven items route to a time-boxed ablation batch; security-class items surface the capped verdict's evidence and wait for the human's own call; remediation owned by an upstream or a forge control plane becomes a delegation rather than a local patch. Use when the ask is to act on an enforcement-surface audit's findings ('realign our enforcement surface', 'the audit says retire it, do it'), to retire or peel back automation already judged, or to start or advance an ablation window ('disable this gate and observe it'). This is th
-
melodic-software Bundle WorktreeManage git worktree lifecycle for parallel-session isolation: create (guided naming via EnterWorktree), status (PR + staleness inventory), cleanup (file-lock-aware removal), audit (infrastructure health). Use when: 'create worktree', 'worktree status', 'clean up worktrees', 'orphaned worktrees', or proactively when on main before writing code, not for PR lifecycle (use /pull-request).
-
melodic-software Bundle Audit PassRun ONE coordinated, ordered, resumable pass over a named target repository: a three-scope inventory first (managed policy read-only, user scope routed as recommendations, project scope), then delegated checks lane by lane, findings persisted per lane so an interrupted run resumes instead of restarting, and one human gate for the whole pass instead of one per skill. Adds run semantics, not checks: every check belongs to the plugin that owns it and is invoked presence-gated. Read-only on bare invocation; edits only behind an explicit --fix override, and never to managed policy or user-scope files. Use when: 'audit pass', 'run one pass over this repo', 'coordinate the audit skills', 'audit this repo end to end', 'resume the audit', 'one reconciled findings report', 'sweep all three scopes', or before a release that needs a single diffable findings artifact.
-
melodic-software Bundle Audit NoiseClassify tracked markdown for nine noise shapes — historical citations, ghost refs to ephemeral paths, "Why this file exists" preambles, hard-coupled consumer lists, scope/loading meta-commentary, plan/changeset references, conversational antecedents ("as you asked"), tracker/PR back-references, and prohibitions with no positive alternative — emitting Tier 1 (remove/relocate), Tier 2 (review needed), and Tier 3 (likely legitimate) findings with per-shape treatment guidance; read-only on audited files. Use when: 'audit markdown noise', 'declutter', 'check for stale citations', 'find ghost refs', 'classify preamble', 'strip conversational residue from a doc', 'find negations without a positive', 'sweep a rule/skill/convention doc for noise', or before editing any tracked .md — not for prose flavor/compression (use /compress), structural markdown lint (your repo's markdown linter), or the same residue shapes inside code comments (use /code-tidying:audit-comment-residue, which owns non-markdown files).
-
melodic-software Bundle ApplyApply a prior /repo-fleet-hygiene:audit action-plan JSON behind one fleet confirmation: default dry-run re-derives branch/worktree tips and prints the ordered batch; --apply mutates only after interactive confirmation or --yes. Owns batched merged-local-branch deletion with fail-closed OID refresh; cleans merged/prunable/missing worktrees in plan order (branches before worktrees). Use when: 'apply fleet plan', 'execute fleet cleanup', 'batch delete merged branches', 'one confirmation for fleet cleanup'.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include quality-gate, stateless, apply. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.