Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
lidge-jun Bundle Jaw Dev BackendMUST USE for backend, API, server, or database work — API design, architecture, database optimization, security hardening, error handling, middleware, observability, queues, and long-lived connections. Triggers: backend, API, REST, GraphQL, schema, migration, query optimization, middleware, OTel, caching, Result pattern, server, 백엔드, API 작업, 마이그레이션, 쿼리 최적화.
-
lidge-jun Bundle Jaw Dev TestingMUST USE for testing, QA, regression protection, and release verification — unit, integration, API, contract, Playwright E2E, CI, security-scan, coverage, and TDD strategy. Triggers: write tests, regression test, Playwright, E2E, contract test, coverage, CI flake, TDD, test, testing, QA, 테스트, 회귀 테스트, 품질 게이트.
-
lidge-jun Bundle Skill StocktakeAudit skills and commands for quality. Supports Quick Scan (changed only) and Full Stocktake modes with batch evaluation.
-
lidge-jun Skill Postgres PatternsPostgreSQL database patterns for query optimization, schema design, indexing, and security.
-
lidge-jun Skill Verification LoopMulti-phase verification system for code changes — build, types, lint, tests, security, diff.
-
lidge-jun Skill Django VerificationVerification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.
-
lidge-jun Bundle Jaw Dev ScaffoldingMUST USE for project setup, feature scaffolding, structural audits, or documentation scaffolding — applies the Lidge Standard, colocation, public boundary exports, repo-first convention reuse, and source-of-truth doc planning. Triggers: scaffold, scaffolding, new project, init project, new feature, add module, project setup, structure audit, architecture docs, source-of-truth docs, monorepo setup, API docs, 스캐폴딩, 새 프로젝트, 새 기능, 구조 점검, 모듈 추가.
-
lidge-jun Skill Springboot SecuritySpring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
-
lidge-jun Skill Quality NonconformanceQuality control, non-conformance investigation, root cause analysis, corrective action, and supplier quality management in regulated manufacturing. Includes NCR lifecycle, CAPA systems, SPC interpretation, and audit methodology across FDA, IATF 16949, and AS9100 environments.
-
lidge-jun Bundle Security Best PracticesPerform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.
-
lidge-jun Bundle SemgrepRun Semgrep static analysis scan on a codebase using parallel subagents. Automatically detects and uses Semgrep Pro for cross-file analysis when available. Use when asked to scan code for vulnerabilities, run a security audit with Semgrep, find bugs, or perform static analysis. Spawns parallel workers for multi-language codebases and triage.
-
lidge-jun Bundle Insecure DefaultsDetects fail-open insecure defaults (hardcoded secrets, weak auth, permissive security) that allow apps to run insecurely in production. Use when auditing security, reviewing config management, or analyzing environment variable handling.
-
lidge-jun Bundle Differential ReviewPerforms security-focused differential review of code changes (PRs, commits, diffs). Adapts analysis depth to codebase size, uses git history for context, calculates blast radius, checks test coverage, and generates comprehensive markdown reports. Automatically detects and prevents security regressions.
-
lukasa1993 Bundle Tanstack AI MemoryUse when wiring memoryMiddleware from @tanstack/ai-memory into a chat() call — covers the recall/save adapter contract, scope shape and server-side scope security, the recall-inject / deferred-save lifecycle, choosing an adapter (inMemory, redis, hindsight, mem0, honcho), and devtools events.
-
lukasa1993 Bundle Tanstack AI SandboxRun harness adapters (Claude Code, Codex, OpenCode) INSIDE isolated sandboxes via defineSandbox + withSandbox + a provider (localProcessSandbox / dockerSandbox). Covers declarative provisioning: createSecrets + secret/bearer, skills (agentSkill/gitSkill/mcpSkill/ fileSkill), plugins, instructions returns canonical AGENTS.md + symlinks projected per harness; shallow-clone default with depth opt-out; serial/parallel setup callback over a persistent shell; snapshot-after-setup default with snapshotMaxAge TTL. It also covers portable snapshots after a successful terminal run with withPersistence before withSandbox and memorySandboxSnapshots for local examples. It covers named saves with snapshots.save, selected-checkpoint forks with snapshots.fork, and authorized artifact reads with snapshots.readArtifact. See docs/sandbox/portable-snapshots.md. It covers defineWorkspace (git/setup/scripts/skills/secrets/ instructions/plugins) ... Use whenever a harness adapter needs a sandbox or when building sandbox providers.
-
shengdabai Bundle Dependency GuardDependency security & health audit across npm/Python/Go/Ruby/Java/Rust/PHP. Use when the user mentions dependency vulnerabilities, CVE scan, npm audit, outdated packages, license compliance, supply-chain / typosquatting risk, bundle-size bloat, or asks to audit / update / harden project dependencies. Produces a prioritized remediation plan with severity ratings and update PR scaffolding.
-
shengdabai Bundle Opc Resource AuditInventory all founder resources across 8 categories for a one-person company. Use when Codex needs to systematically confirm what resources the founder has — experience, network, skills, relationships, channels, assets, time/money constraints, hard limits — by first doing a broad scan of each category, then drilling into specifics (distribution, usable portions, how to use, cost of use), and producing a confirmed detailed resource inventory written to `opc-doc/`. Does NOT analyze directions, preferences, suitability, or risk tolerance — those belong to downstream skills.
-
shengdabai Bundle Devex ReviewLive developer experience audit. Uses the browse tool to actually TEST the developer experience: navigates docs, tries the getting started flow, times TTHW, screenshots error messages, evaluates CLI help text. Produces a DX scorecard with evidence. Compares against /plan-devex-review scores if they exist (the boomerang: plan said 3 minutes, reality says 8). Use when asked to "test the DX", "DX audit", "developer experience test", or "try the onboarding". Proactively suggest after shipping a developer-facing feature. (gstack) Voice triggers (speech-to-text aliases): "dx audit", "test the developer experience", "try the onboarding", "developer experience test".
-
shengdabai Bundle Plan Devex ReviewInteractive developer experience plan review. Explores developer personas, benchmarks against competitors, designs magical moments, and traces friction points before scoring. Three modes: DX EXPANSION (competitive advantage), DX POLISH (bulletproof every touchpoint), DX TRIAGE (critical gaps only). Use when asked to "DX review", "developer experience audit", "devex review", or "API design review". Proactively suggest when the user has a plan for developer-facing products (APIs, CLIs, SDKs, libraries, platforms, docs). (gstack) Voice triggers (speech-to-text aliases): "dx review", "developer experience review", "devex review", "devex audit", "API design review", "onboarding review".
-
shengdabai Bundle Chezmoi DotfilesSecure dotfiles management with chezmoi. Use when helping users initialize chezmoi repositories, add/manage dotfiles, handle secrets with age encryption, create templates for multi-machine configs, troubleshoot chezmoi issues, or review dotfiles for security. Always checks for security implications before adding files.
-
allinherog-star Bundle AI Audit Website网站诊断助手适合市场营销、运营、software、教育培训在用户提出“网站哪里拖后腿”这类问题,需要快速拆解目标、判断重点并形成可执行结果时使用,帮助基于输入材料生成研究摘要、关键发现、引用/验证清单。
-
pooriaarab Bundle Design ContextCreate, audit, or migrate repository design context. Use when a repo needs canonical .agents/brand.md and .agents/design.md files, a live /design.md document, a /brand page, or a fleet-wide design-context review. Ground every rule in the product and code. Never invent tokens for surfaces that do not exist.
-
pooriaarab Skill Ad Auto OptimizerOperate live paid-ad experiments on a fixed schedule (e.g. every 6h) as an autonomous optimizer that reads every platform, then adjusts within hard guardrails — auto-applying only the safe/reversible levers and recommending (never silently making) the learning-resetting ones. Covers the lever tree (creative kill-gate, audience widen, landing-page test, budget/bid tilt, feature-utilization audit), the auto-apply-vs-recommend split, anti-thrash rules, spend-cap guardrails, and loud escalation on the events that actually matter (first signup, a channel finally serving, a kill, tracking shipping). Also encodes the operating truths that only surface after many cycles: ad-platform reporting is unreliable (verify with authoritative queries before acting), delivery-solved is not conversion-solved (stop tuning a stage you already fixed), you cannot optimize what you cannot measure, and budget optimizers concentrate spend (so fund few powered cells, not many starved ones). Pairs with ad-experiments (which designs the e
-
pooriaarab Skill Ad Conversion HubDesign and operate a shared ad-conversion hub for multiple ad platforms — canonical event taxonomy, consent gating, SHA-256 identity hashing, stable client/server deduplication, first-party click-id capture, platform adapter secrets, absent-secret no-ops, retry and failure isolation, server-side proof, and reconciliation against payment-provider truth. Use when a product sends one purchase, signup, lead, or subscription event to Google, Meta, Reddit, Microsoft, TikTok, LinkedIn, Pinterest, DSP, regional, CTV, or emerging ad platforms.
-
pooriaarab Skill Dependency HygieneKeep a Cloudflare Workers product rebuildable across long gaps by pinning Bun and Wrangler, committing and validating lockfiles, grouping automated dependency updates, triaging production-relevant CVEs, rotating leaked secrets, and retiring abandoned deployments. Use when the user asks for 'dependency hygiene', 'dependency maintenance', 'update dependencies across repos', 'audit old repos', 'fix a stale lockfile', 'pin Bun', 'set up Dependabot', 'set up Renovate', 'triage dependency alerts', 'scan for leaked secrets', 'rotate repository secrets', or 'archive an abandoned product'. Skip an active outage or customer-facing failure and use incidents for that.
-
pooriaarab Skill Ad Platform CredentialsObtain, verify, and store server-side conversion credentials for Meta, GA4, Google Ads, and LinkedIn. Use when a Meta CAPI token cannot read pixel metadata, a GA4 Measurement Protocol secret is blocked by acknowledgement, Google Ads shows Explorer Access, or you need to know which token type to use.
-
deciqai Skill Tax Prep Pre File Audit PremortemActivate when: a return has aggressive/uncertain positions (large Schedule C losses, high meals/vehicle, hobby-vs-business, real-estate professional status, R&D/ERC-type credits, crypto); before releasing a complex return; client says 'will this get me audited?'. Do NOT activate when: simple W-2-only standard-deduction return; the question is a straight lookup. More: deciqai.com/s/tax-prep-pre-file-audit-premortem
-
samarv Skill Strategy Choice CascadeA framework for defining a strategy through five integrated choices. Use it when launching a new product, facing a competitive threat, or when current performance falls short of goals.
-
samarv Skill Friction Logging And UX ReviewsA systematic method for auditing user experiences by role-playing specific personas to identify "broken edges." Use this during product development, before major launches, or as a recurring audit to maintain a high bar for craft.
-
iamwaqargulzar Bundle Competitor ProfilingWhen the user wants to research, profile, or analyze competitors from their URLs. Also use when the user mentions 'competitor profile,' 'competitor research,' 'competitor analysis,' 'profile this competitor,' 'analyze competitor,' 'competitive intelligence,' 'competitor deep dive,' 'who are my competitors,' 'competitor landscape,' 'competitor dossier,' 'competitive audit,' or 'research these competitors.' Input is a list of competitor URLs. Output is structured competitor profile markdown files. For creating comparison/alternative pages from profiles, see competitors. For sales-specific battle cards, see sales-enablement.
-
iamwaqargulzar Bundle Social Quality AuditorUse when the user asks to "audit our social presence" or "is this batch safe to publish"; runs either the typed ECHO asset gate or a separate program-maturity profile, with channel-truth, claim, disclosure, manipulation, UGC-rights, and denominator checks. Not for creator deliverables — use creator-content-auditor; not for launch readiness — use launch-readiness-auditor. 社媒资产门/运营成熟度/发布前放行
-
iamwaqargulzar Bundle Narrative Drift MonitorUse when the user asks to "check if our surfaces have drifted from the canon", "watch for competitor repositioning", or "define when we should reposition"; produces a drift report — self-drift per flagship surface vs the narrative-registry canon over time (via wayback.py, change history Measured with as-of dates), competitor-repositioning alerts, an explicit repositioning-trigger condition set, and a D1/W1/M1 message-shift retro (intended vs actual pull-through, evidence-labeled) — feeding the TALE L drift-audit sub-items and the narrative-whiplash guardrail fact base. Not for the first-time consistency check before a surface ships — use narrative-cascade-planner; not for computing the TALE profile result or running the vetoes — use narrative-quality-auditor; not for echo-rate / AI-answer resonance measurement — use narrative-resonance-monitor. 自漂移监测/竞品重定位告警/重定位触发/叙事漂移复盘
-
iamwaqargulzar Bundle Launch Readiness AuditorUse when the user asks to "audit our launch plan", "are we ready to launch", or evaluate launch execution/outcomes; runs one typed RAMP preflight, execution, or outcome profile without mixing time horizons. Not for recording launch state — use launch-registry; not for running launch day — use launch-day-conductor. 发布就绪审计/RAMP分阶段评估/发布前放行
-
iamwaqargulzar Bundle Narrative Quality AuditorUse when the user asks to "audit our brand narrative" or "is this message on-canon"; runs separate typed TALE truth, system, or effectiveness profiles and never averages them into one composite. Checks differentiation, canon, landing consistency, and evidence integrity. Not for launch readiness — use launch-readiness-auditor; not for social operations — use social-quality-auditor. 品牌叙事分层审计/发布前一致性放行
-
iamwaqargulzar Bundle Dynamic Content PersonalizerUse when the user asks to "personalize the email", "add merge tags / dynamic content", "set up conditional blocks per segment", or "make first-name and product-recommendation fields fall back safely"; produces a merge-tag map with per-tag fallbacks, conditional-block rules with per-segment variations, a fallback-safety audit, and a PII guard on what may render, informing the SEND E (Engagement/personalization) dimension. Not for building the segments — use list-segment-builder; not for writing the base copy — use email-creative-builder; not for scoring EQS or running vetoes — use email-quality-auditor. 邮件个性化/合并标签/条件内容块/兜底默认值
-
joogy06 Skill MongodbUse when installing, configuring, developing with, or managing MongoDB — replica sets, sharding, aggregation framework, indexing strategies, schema design patterns, security (SCRAM/x.509/LDAP), backup and restore (mongodump/mongorestore, filesystem snapshots, Atlas backup), monitoring (mongostat/mongotop/Atlas), performance tuning, and change streams. Covers MongoDB 7.x/8.x and Atlas.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include jaw-dev-backend, jaw-dev-testing, skill-stocktake. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.