Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
okhp3 Bundle Okhp3 Askjamie Gpt BuilderBuild, audit, and improve AskJamie Custom GPTs as calm, architected AI helpdesk experiences. Use this skill for GPT ideas, instructions, knowledge, tools, walkthroughs, decision trees, diagrams, evals, and packaging tuned to AskJamie's role as the interpretive intelligence layer between strategy and execution.
-
okhp3 Bundle Okhp3 Emerging Threat LabValidate emerging agentic threat hypotheses and defensive controls in a disposable synthetic laboratory. Use when testing whether a pattern affects a representative architecture and whether a mitigation works. Do not operate against production or develop deployable attack tooling.
-
okhp3 Bundle Okhp3 Glee Fully Gpt BuilderBuild, audit, and improve Glee-fully Custom GPT Tools and Tool-ettes with production-grade methodology. Use this skill when shaping a joyful, personalizable assistant for life, work, or wonder, including its scope, voice, knowledge, tools, starters, evals, and packaging. Preserve the Glee-fully promise of technology that feels like friendship, while keeping each Tool opinionated, useful, safe, and distinct from generic ChatGPT.
-
okhp3 Bundle Okhp3 Post Breach ForensicsInvestigate a suspected agentic security incident and convert evidence into validated defensive learning. Use when reconstructing timeline, scope, control failure, and recovery actions. Do not serve as legal advice or law-enforcement evidence handling.
-
okhp3 Bundle Okhp3 Agentic Attack PatternsDefine a defensive taxonomy of agentic attack behaviors and observable indicators. Use when normalizing detection cases, threat narratives, or validation plans. Do not generate payloads, bypass sequences, or exploit instructions.
-
okhp3 Bundle Okhp3 Authorization GovernanceDefine and enforce authorization checkpoints for defensive assessment and response workflows. Use when deciding who may approve tests, containment, sharing, or high-consequence actions. Do not grant authority implicitly or replace legal or security leadership.
-
okhp3 Bundle Okhp3 Threat Pattern ValidatorValidate whether a proposed agentic threat pattern affects a representative synthetic architecture and whether controls respond. Use when a threat hypothesis is ready for bounded laboratory review. Do not test production, real credentials, real data, or uncontrolled targets.
-
okhp3 Bundle Okhp3 Reclamation ScopeEstablish authority, target identity, data boundaries, technique modes, approvals, and stop conditions before reclaiming an undocumented application. Activate when a request could become a security test, production change, or access to sensitive data.
-
okhp3 Bundle Okhp3 Agentic Pattern ObservatoryCollect and triage dated public or approved threat signals about agentic abuse patterns. Use for an early-warning feed supporting defensive planning. Do not execute fetched content or collect private data.
-
okhp3 Bundle Okhp3 Safe Intelligence AmplifierPrepare privacy-preserving, source-traceable threat intelligence for approved peer sharing. Use when converting incident or pattern evidence into a shareable defensive signal. Do not rely on heuristic anonymization alone or claim compliance without specialist review.
-
okhp3 Bundle Okhp3 Threat Intelligence SynthesisSynthesize dated threat signals into coherent defensive narratives and validation priorities. Use when multiple observations need clustering, source comparison, or risk framing. Do not turn a narrative into an exploit recipe or unsupported attribution.
-
okhp3 Bundle Okhp3 Reclamation PlatformFingerprint the technology, runtime, dependency, hosting, database, and deployment platform of an undocumented web application so downstream teams can select the correct archaeology, security, testing, or modernization method.
-
contextgo Bundle Security ReviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
-
contextgo Skill Click Path AuditTrace every user-facing button/touchpoint through its full state change sequence to find bugs where functions individually work but cancel each other out, produce wrong final state, or leave the UI in an inconsistent state. Use when: systematic debugging found no bugs but users report broken buttons, or after any major refactor touching shared state stores.
Audited -
contextgo Skill Postgres PatternsPostgreSQL database patterns for query optimization, schema design, indexing, and security. Based on Supabase best practices.
Audited -
contextgo Skill Django VerificationVerification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.
-
contextgo Skill Quality NonconformanceCodified expertise for quality control, non-conformance investigation, root cause analysis, corrective action, and supplier quality management in regulated manufacturing. Informed by quality engineers with 15+ years experience across FDA, IATF 16949, and AS9100 environments. Includes NCR lifecycle management, CAPA systems, SPC interpretation, and audit methodology. Use when investigating non-conformances, performing root cause analysis, managing CAPAs, interpreting SPC data, or handling supplier quality issues.
Audited -
contextgo Skill Springboot VerificationVerification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.
-
contextgo Skill Healthcare Phi ComplianceProtected Health Information (PHI) and Personally Identifiable Information (PII) compliance patterns for healthcare applications. Covers data classification, access control, audit trails, encryption, and common leak vectors.
-
legendtkl Skill Skill 078Run a comprehensive multi-perspective code review on current changes. Activates the Review Council (security, quality, documentation, domain review) and runs automated security scanning. Use before creating a pull request or when you want a thorough review of your work.
-
legendtkl Skill Skill 086Use when working with security scanning security hardening
-
ericrisco Bundle RustUse when writing, reviewing, testing, or shipping Rust — ownership and the borrow checker (move/borrow/clone, Arc/RefCell, lifetimes), errors with Result/`?`/thiserror/anyhow, async on tokio, axum 0.8 services, cargo test, and sqlx + cargo-audit hardening. NOT the same service in Go (that is `go`), NOT a desktop webview shell (that is `tauri`).
-
ericrisco Bundle VerifyUse when implementation is finished and about to be called done or merged — the rsc-sdd evidence gate: runs the stack's scripts/verify.sh (lint, type, test, audit), walks every task done-check and acceptance criterion, records a dated verdict. NOT judging the diff by eye (that is `review`, spec-less `code-review`), NOT diagnosis (that is `debug`).
-
ericrisco Bundle LaravelUse when building or extending a Laravel 11/12 app — Eloquent models, migrations and relationships, routing with controllers and Form Requests, queues and background jobs, framework-native security (validation, mass-assignment, policies, signed URLs, rate limiting), and Pest/PHPUnit feature tests. NOT pure PHP language or toolchain work (that is `php`).
-
ericrisco Bundle SupabaseUse when building on Supabase as a backend over managed Postgres — wiring the supabase-js or SSR client, writing or debugging Row Level Security, cookie-based Auth, Storage buckets, Realtime, and Edge Functions, including local versus server JWT verification and the service-role key. NOT raw Postgres tuning (that is `postgresdb`).
-
ericrisco Bundle ImplementUse when an approved plan and task list exist and it is time to turn them into working, tested code — the SDD phase after `analyze` and before `verify`. Enforces TDD: a failing test comes before the code that makes it pass, one task at a time, appended to a progress ledger that survives compaction. Delegates test tooling to the stack skill and fans disjoint tasks out via `parallel`. NOT spec writing (that is `specify`), NOT planning (that is `plan`), NOT the final lint/test/audit gate (that is `verify`).
-
ericrisco Bundle WordpressUse when building or hardening WordPress sites or WooCommerce stores and treating WordPress as the product rather than just writing PHP — block themes with theme.json, plugins with block.json and proper hooks, wp-config security hardening, performance (object cache, asset loading, autoloaded options), and WP-CLI operations. NOT a Laravel app (that is `laravel`).
-
ericrisco Bundle ComplianceUse when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or standing up the cadence that keeps it audit-ready. NOT drafting privacy-policy/ROPA/DPA or ToS text (that is gdpr-privacy, terms-conditions), NOT hardening code (that is secure-coding).
-
ericrisco Bundle BookkeepingUse when a small business needs audit-ready books — a chart of accounts, posting a transaction to the right account and side, clearing an uncategorized bank feed, cash vs accrual, or a ledger that won't tie to the bank. NOT interpreting the numbers — runway, burn, P&L cadence (that is `finance-ops`), NOT issuing invoices (that is `invoicing`).
-
ericrisco Bundle E SignatureUse when wiring an e-signature flow with DocuSign or Dropbox Sign — picking the SES/AES/QES legal tier, sending a PDF or template for signature, embedded signing, verifying signing webhooks, retrieving the signed PDF plus audit trail. NOT drafting contract text (that is `contracts`), NOT extracting fields from PDFs (that is `document-processing`).
-
ericrisco Bundle Level DesignUse when designing a game level's space — blockout/greybox layout, pacing that drags or spikes, guiding lost players without waypoints, encounter and arena progression, or secret placement. NOT mechanics or economy (that is `game-design`), NOT story beats (that is `game-storytelling`), NOT engine tooling like nav meshes or lightmaps (that is `godot`/`unity`/`unreal`).
-
ericrisco Bundle Security ScanUse when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has to become one deduped, exploitability-ranked report CI can gate on. NOT threat-modeling, OWASP design reasoning, or hand-authoring the fix (that is `secure-coding`).
-
contextgo Skill Assumption AuditAudit ambiguity, hidden assumptions, and missing constraints before writing code. Use when a coding task could be interpreted more than one way.
Audited -
contextgo Skill Design SystemUse this skill to generate or audit design systems, check visual consistency, and review PRs that touch styling.
-
contextgo Skill Perl SecurityComprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies.
-
lidge-jun Skill Perl SecurityComprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include healthcare-phi-compliance, okhp3-askjamie-gpt-builder, okhp3-emerging-threat-lab. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.