Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ascend-ai-coding Bundle External Mindstudio Document UX Review当用户希望你像第一次接触项目的人一样,真实按仓库的 README、安装文档或 quick start 跑一遍,并判断“新人能不能走通”“文档是否可用”“哪里会卡住”“安装/启动说明是否对新手友好”时,使用这个 skill。它适用于 repo onboarding audit、documentation UX review、quickstart validation、README walkthrough、按文档验证安装与运行并输出问题报告的场景;即使用户只是说“按 README 试一下”“帮我检查这个仓库文档能不能跑通”“看看 quick start 为什么带不动新人”,也应触发。不要用于纯翻译、润色、摘要、风格对比、治理项检查,或只想直接修环境/修单个报错而不做完整文档体验审查的请求。
-
ferroxlabs Skill Subscription AuditInventories all recurring subscriptions, memberships, and automatic charges. Identifies unused, duplicated, or low-value subscriptions and builds a cancellation priority list with estimated annual savings. Produces a complete subscription inventory with keep/cancel/downgrade recommendations. Use when the user wants to review their subscriptions, reduce recurring charges, or find hidden monthly costs. Do NOT use for full budget creation (use budget-planning), one-time expense analysis (use spending-analysis), or business SaaS audit.
Audited 37 -
ferroxlabs Skill Retirement PlannerComprehensive retirement planning using the 25x rule, 4% safe withdrawal rate, Social Security optimization, 401k employer match maximization, Roth vs Traditional IRA analysis, catch-up contributions, retirement age scenarios, and withdrawal strategies. Use when the user asks about retirement planner, or needs help with comprehensive retirement planning using the 25x rule, 4% safe withdrawal rate, social security optimization, 401k employer match maximization, roth vs traditional ira analysis, catch-up contributions, retirement age scenarios, and withdrawal strategies. Do NOT use when the request requires professional financial advice or falls outside the scope of retirement planner.
Audited 37 -
aws-samples Bundle Mq DiagnosticsUse this skill to investigate and troubleshoot Amazon MQ problems (ActiveMQ and RabbitMQ) by analyzing broker health, connectivity, performance, engine-specific issues, maintenance, and security using structured runbooks. Activate when: broker creation failures, broker health degraded, storage full, connection failures, TLS issues, VPC access problems, message throughput low, consumer lag, memory pressure, ActiveMQ-specific issues, network of brokers problems, RabbitMQ-specific issues, quorum queue problems, version upgrades, configuration changes, authentication failures, encryption issues, or the user says something is wrong with Amazon MQ without naming specific symptoms.
-
aws-samples Bundle Efa DiagnosticsUse this skill to investigate and troubleshoot Elastic Fabric Adapter (EFA) problems by analyzing EFA creation, attachment, driver installation, libfabric, MPI communication, NCCL, performance, bandwidth, security groups, placement groups, SageMaker integration, and following structured runbooks. Activate when: EFA creation failures, attachment errors, driver issues, libfabric problems, MPI errors, NCCL failures, performance degradation, bandwidth limitations, security group misconfigurations, placement group issues, SageMaker EFA problems, or the user says something is wrong with EFA.
-
aws-samples Bundle Efs DiagnosticsUse this skill to investigate and troubleshoot Amazon EFS problems by analyzing file system configurations, mount targets, security groups, and following structured runbooks. Activate when: mount failures, NFS timeouts, throughput issues, burst credit depletion, security group blocks, access point problems, EFS CSI driver errors, lifecycle policy issues, replication failures, encryption problems, or the user says something is wrong with EFS without naming specific symptoms.
-
aws-samples Bundle Ses DiagnosticsUse this skill to investigate and troubleshoot Amazon SES problems by analyzing sending failures, deliverability, reputation, receiving rules, templates, configuration sets, sandbox limitations, security, and quota issues following structured runbooks. Activate when: send failures, bounce handling, complaint handling, reputation issues, DKIM/SPF/DMARC failures, suppression list problems, receipt rule errors, S3 action failures, template errors, personalization issues, configuration set problems, event destination failures, sandbox limitations, production access requests, IAM permission errors, SMTP credential issues, sending limits, rate throttling, or the user says something is wrong with SES without naming specific symptoms.
-
aws-samples Bundle Kinesis DiagnosticsUse this skill to investigate and troubleshoot Amazon Kinesis Data Streams and Amazon Kinesis Data Firehose problems by analyzing stream configurations, shard throughput, consumer lag, producer failures, Firehose delivery issues, Lambda transformations, capacity management, data integrity, and security. Activate when: write/read throttling, hot shards, resharding failures, iterator age lag, KCL checkpoint issues, enhanced fan-out problems, Lambda consumer errors, PutRecords partial failures, KPL aggregation issues, Firehose S3/OpenSearch/ Redshift/HTTP delivery failures, Lambda transformation errors, data format conversion problems, on-demand scaling issues, provisioned shard management, data loss investigation, ordering guarantees, encryption configuration, cross-account access, or the user says something is wrong with Kinesis without naming specific symptoms.
-
aws-samples Bundle Detective DiagnosticsUse this skill to investigate and troubleshoot Amazon Detective problems by analyzing behavior graphs, data sources, investigation workflows, and following structured runbooks. Activate when: Behavior graph creation failures, data source enablement issues, finding investigation problems, entity profile errors, anomaly detection issues, admin account configuration, member invitation failures, GuardDuty integration problems, Security Hub integration issues, data volume concerns, retention questions, IAM permission errors, cross-account access issues, or the user says something is wrong with Detective without naming specific symptoms.
-
aws-samples Bundle Qdeveloper DiagnosticsUse this skill to investigate and troubleshoot Amazon Q Developer problems by analyzing code suggestions, security scanning, code transformation, IDE integration, customization, billing, and following structured runbooks. Activate when: code suggestions not working, security scan failures, code transformation errors, IDE plugin issues, customization problems, billing questions, or the user says something is wrong with Q Developer.
-
aws-samples Bundle Rds Oracle DiagnosticsUse this skill to investigate and troubleshoot Amazon RDS for Oracle problems by analyzing instance configurations, performance metrics, connectivity, parameter groups, and following structured runbooks. Activate when: launch failures, instance class issues, storage problems, high CPU or Oracle wait events, SGA/PGA memory pressure, I/O bottlenecks, connection failures, TNS errors, listener issues, parameter group problems, Oracle init parameter tuning, session/process limits, backup failures, snapshot restore, point-in-time recovery, read replica issues, Multi-AZ failover, Data Pump migration, DMS issues, character set problems, TDE encryption, SSL/native network encryption, Oracle audit, version upgrades, patching, or the user says something is wrong with RDS Oracle without naming specific symptoms.
-
davidcastagnetoa Bundle Security ReviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
-
ascend-ai-coding Bundle External Gitcode Ascend Security Code Review多语言安全代码审查 (Security Code Review)。对 Python、C++、Shell、Markdown 文件进行系统性安全漏洞检测与修复指导。覆盖 OWASP Top 10、CWE Top 25、CERT 安全编码标准。当用户提及以下内容时,务必使用此技能:安全审查、安全代码审查、security review、code review 中的安全检查、漏洞扫描、安全合规检查(CWE/CERT/OWASP)、编写安全代码、检查代码安全性、推理服务安全审计、多模态 Token 安全校验、JSON 嵌套深度攻击防护。即使用户没有明确说'安全审查',只要涉及代码安全性评估、漏洞检测、安全最佳实践,都应触发此技能。
Audited -
delorenj Skill Gsd ProgressCheck project progress, show context, and route to next action (execute or plan). Use --forensic to append a 6-check integrity audit after the standard report.
1 -
delorenj Skill Gsd Audit UatCross-phase audit of all outstanding UAT and verification items
1 -
delorenj Skill Gsd Ns Reviewquality gates | code review debug audit security eval ui
1 -
ferroxlabs Skill Audience AnalysisCreates detailed audience persona documents with demographics, pain points, vocabulary mapping, content preferences, and behavioral insights. Use when the user needs to define their target audience, create buyer personas, build audience profiles, or understand who their content serves. Do NOT use for content auditing (use `content-audit`), editorial planning (use `editorial-calendar`), or voice and tone documentation (use `voice-tone-guide`).
Audited 37 -
ferroxlabs Skill Spending AnalysisAnalyzes the user's spending history against their stated values and financial goals. Identifies misalignments between what the user says they value and where they actually spend money, then recommends specific reallocation amounts to bring spending in line with priorities. Use when the user wants to understand their spending patterns, find misalignments, or optimize how their money is distributed across categories. Do NOT use for setting up expense tracking (use expense-tracking-setup), creating a budget (use budget-planning), or auditing subscriptions only (use subscription-audit).
Audited 37 -
ferroxlabs Skill Legal Cease And DesistDraft a cease-and-desist letter for trademark, copyright, IP misuse, defamation, breach of contract or unpaid debt, choosing tone deliberately (professional, firm, litigation-threat) and assembling the evidence section, the specific demand and the response deadline. Use when the user needs a formal written demand that a behaviour stop. Do NOT use for a platform takedown of hosted content (use legal-dmca) or for drafting the agreement being breached (use sentry-contracts-and-terms). Template only — a letter that threatens litigation can create liability of its own, so have an attorney review high-stakes versions before sending.
Audited 37 -
aws-samples Bundle Securitylake DiagnosticsUse this skill to investigate and troubleshoot Amazon Security Lake problems by analyzing lake creation, source configuration, subscriber management, OCSF schema mapping, Athena query integration, cross-account/region setup, rollup regions, custom sources, data retention, and IAM/Lake Formation permissions following structured runbooks. Activate when: lake creation failures, source ingestion issues, subscriber access problems, OCSF normalization errors, Athena query failures, cross-account collection issues, rollup region sync problems, custom source delivery failures, retention policy issues, Lake Formation permission errors, or the user says something is wrong with Security Lake without naming specific symptoms.
-
modu-ai Skill Commerce Automation Audit[책임 경계] 셀러 운영 자체 진단 + 자동화 우선순위 점수 산정 + 3 Phase 로드맵 자동 생성 전담. "커머스 업무 자동화" 프레임워크(6대 영역 A-F + 3 자동화 유형 + 4단계 설계 프로세스)를 자연어로 wrapping. 페어 스킬 commerce-integrated-strategy(매출 향상 전략 1장)와 명확히 구분 — 본 스킬은 운영 자동화 진단·로드맵, 페어는 매출 향상 즉시 실행 전술. 다음과 같은 요청 시 반드시 이 스킬을 사용하세요: "자동화 진단해줘", "내 매장 자동화 우선순위", "ROI 자동화 영역 찾아줘", "자동화 로드맵 만들어줘", "Quick Wins Phase 진단", "반복형 판단형 창의형 분류", "RPA 도입 검토", "AI Copilot 적용", "HITL 검수 지점 설계", "조직 규모별 자동화 도구 추천". 6대 영역 (A 상품운영 / B 가격&프로모션 / C 주문&정산 / D 재고&물류 / E 마케팅&고객 / F 데이터&경영) 진단 + 자동화 3분류 + 우선순위 점수 (빈도×시간×오류비용÷복잡도) + 5대 KPI + 3 Phase 로드맵. ai-slop-reviewer 자동 체이닝 (진단 보고서 텍스트 산출물). 슬롭 검수 직후 moai-writer:korean-humanize으로 한국어 AI 티를 제거합니다 (슬롭 검수 다음, 필수). 이커머스 운영 자동화 가능성 자가 진단 + 우선순위·로드맵 생성.
-
modu-ai Bundle Commerce Integrated Strategy선행 스킬 산출물(commerce-market-research·commerce-jtbd-persona·commerce-product-naming·cs-channel-message·commerce-detail-page-copy 결과)과 매장 운영 데이터를 종합해 매출 향상 통합 전략 1장 + 실행 우선순위 Top 3을 자동 생성하고, 채널 믹스·가격·프로모션 캘린더·리텐션·KPI까지 단계별(런칭/성장/안정)로 설계합니다. 다음과 같은 요청 시 반드시 이 스킬을 사용하세요: "오늘 배운 것 종합 전략으로 정리해줘", "통합 전략 뽑아줘", "실행 우선순위 정해줘", "매출 올리는 전략 1장", "지금 당장 해야 할 것 Top3", "ROAS 개선 전략", "채널별 매출 비교 분석", "커머스 전략 짜줘", "채널 믹스 추천해줘", "가격 전략 세워줘", "프로모션 캘린더 만들어줘", "리텐션 전략 추천", "이커머스 KPI 대시보드 설계" 매크로 전략 모드(채널 믹스·3단계 가격·시즌 프로모션 캘린더·재구매 자동화·KPI 대시보드 references 제공) + 통합 1장 모드(선행 산출물 종합) 2계층으로 동작하며, 전략 1장 직후 moai-coworker:ai-slop-reviewer를 자동 체이닝합니다. [책임 경계] 본 스킬은 이커머스 셀러 즉시 실행 전술 + 채널 전략. 중장기 사업 전략은 moai-consultant:consult-strategy, 운영 자동화 진단은 moai-seller:commerce-automation-audit 사용.
-
acaprino Bundle Defect Taxonomy16 macro-categories and 140+ subcategories of source-code failure modes, with CWE and OWASP mappings, fix patterns, and review frameworks. TRIGGER WHEN: an audit needs structured defect classification, a detection strategy, or severity calibration; loaded by code-auditor, security-auditor, and ui-race-auditor.
-
acaprino Bundle Marketplace AuditValidates the integrity of any Claude Code plugin marketplace. Use PROACTIVELY before any commit that modifies plugin files or marketplace.json. TRIGGER WHEN: verifying marketplace.json integrity, finding orphan plugins/skills/agents/commands, checking dependency resolution or cycles, confirming documented plugin counts still match README and docs tables, or checking naming conventions. DO NOT TRIGGER WHEN: content quality review (use marketplace-review) or scaffolding new plugins (use marketplace-scaffold-plugin / skills-creator).
-
acaprino Bundle Python CommentsGrade and rewrite code prose against antirez's 9-type taxonomy, mapped to PEP 257. TRIGGER WHEN: the user asks to improve comments, add docstrings, review comment quality, or audit documentation in a Python codebase.
-
acaprino Skill Xterm DebugScan for known pitfalls, then analyze the architecture for race conditions and fragile assumptions. TRIGGER WHEN: the user reports a bug or asks to audit an existing xterm.js integration (render glitches, key handling, resize, PTY issues, addon conflicts). DO NOT TRIGGER WHEN: implementing a new feature (use /xterm:xterm-implement).
-
maxrave-dev Skill Room Kmp SetupSet up one Room database shared across Android, JVM/desktop and iOS with an expect/actual builder per platform, a bundled SQLite driver chosen once at the injection site, and a per-architecture audit of the driver artifact. Use when adding Room to a Kotlin Multiplatform module, when one target fails at the first database connection while the others work, or when a target compiles but its generated database implementation is missing.
-
maxrave-dev Skill Arm64 Native Gap AuditAudit every native dependency for a slice on a CPU architecture before promising that target in a multiplatform desktop build — one missing native takes the whole target down at first use rather than at build time, so make the audit a repeatable command over the resolved artifacts and re-run it on every dependency bump; reach for it when deciding whether to add an ARM64 target, or when a build that packaged and installed cleanly dies the first time it touches the database, the renderer or the media layer.
-
team-telnyx Skill Telnyx Account GoManage account balance, payments, invoices, webhooks, and view audit logs and detail records. This skill provides Go SDK examples.
-
team-telnyx Skill Telnyx Account CurlManage account balance, payments, invoices, webhooks, and view audit logs and detail records. This skill provides REST API (curl) examples.
-
team-telnyx Skill Telnyx Account JavaManage account balance, payments, invoices, webhooks, and view audit logs and detail records. This skill provides Java SDK examples.
-
team-telnyx Skill Telnyx Account RubyManage account balance, payments, invoices, webhooks, and view audit logs and detail records. This skill provides Ruby SDK examples.
-
team-telnyx Skill Telnyx Account PythonManage account balance, payments, invoices, webhooks, and view audit logs and detail records. This skill provides Python SDK examples.
-
team-telnyx Skill Telnyx Account JavascriptManage account balance, payments, invoices, webhooks, and view audit logs and detail records. This skill provides JavaScript SDK examples.
-
hybridlabor-api Skill UX AuditUse when auditing screens against Nielsen's heuristics and mobile UX best practices within the StyleSeed Toss design language context.
-
hybridlabor-api Skill Tdmcp Quality AuditRun or maintain the full tdmcp repo quality-audit team: command sweeps, all package/Makefile/CI gates, security review, usability/flow review, refactor/test-gap analysis, coverage hardening, QA, and follow-up fix waves. Use whenever the user asks for a complete audit, improve repo/code quality, test all commands, find security/usability failures, refactor debt, add missing tests, re-run the audit, continue a previous quality wave, or verify the repo is ready.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include external-mindstudio-document-ux-review, subscription-audit, retirement-planner. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.