Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
evolution-foundation Skill Fin Journal EntryPrepare journal entries with proper debits, credits, and supporting detail. Use when booking month-end accruals (AP, payroll, prepaid), recording depreciation or amortization, posting revenue recognition or deferred revenue adjustments, or documenting an entry for audit review.
-
euwebertdefreitas Bundle Especialista Em Cyber SecurityExpert in Cyber Security
-
jacob-balslev Bundle Skill EvolutionUse when running or auditing Skill Graph's corpus-level `evolve` operation: the continuous skill-improvement loop that analyzes a skill library, triages a priority queue, executes bounded improve/scaffold/eval-generation actions, verifies the result, records checkpoints, and repeats. Covers `skill-graph evolve`, `lib/audit/skill-evolution-loop.js`, the Karpathy keep-or-revert spine, the priority signals based on Audit Status, standalone workspace flags, and the boundary between corpus walking and single-skill audit/improve/evaluate operations. Do NOT use for initial skill scaffolding alone (use skill-scaffold), single-skill schema/eval checks (use graph-audit or the audit operation), or generic evaluation rubric design (use evaluation / eval-driven-development).
-
tractorjuice Bundle Arckit Au Pspf[COMMUNITY] Generate a Protective Security Policy Framework (PSPF) compliance assessment for Australian Government entities and contractors against the four security outcomes and 16 core requirements.
-
tractorjuice Bundle Arckit Ca Pspc[COMMUNITY] Generate a federal Canadian procurement strategy — PSPC Supply Manual route selection, Standing Offer / AgileIQ / RFP analysis, Procurement Strategy for Indigenous Business (PSAB 5%), CFTA/CETA threshold mapping, security-clearance prerequisites and lead times.
-
tractorjuice Bundle Arckit Ca Soia[COMMUNITY] Generate a Canada Security of Information Act handling plan — Special Operational Information (SOI) register, marking and handling matrix, transmission channels, compartments and need-to-know, destruction and sanitisation, CSIS Act §16 and §19 coordination, RCMP NSP liaison, breach response, personnel reliability prerequisites.
-
tractorjuice Bundle Arckit Fr Pssi[COMMUNITY] Generate an Information System Security Policy (PSSI) for French public or private organisations — security objectives, principles, organisational structure, and applicable ANSSI/RGS standards
-
tractorjuice Bundle Arckit Au Aescsf[COMMUNITY] Generate an Australian Energy Sector Cyber Security Framework maturity assessment for energy-sector projects with IT, OT, market, and grid-edge dependencies.
-
tractorjuice Bundle Arckit Ca Charter[COMMUNITY] Generate a Canada Charter rights design review — s.2 (expression and association), s.7 (life, liberty, security of person), s.8 (search and seizure), s.15 (equality) — applying Oakes proportionality framing to system design with mitigation tracker and DOJ counsel sign-off block.
-
tractorjuice Bundle Arckit Uae Uaepass[COMMUNITY] Generate UAE Pass integration design (OIDC/OAuth flow, claim mapping, Basic vs Verified profile selection, Service Provider onboarding pack, e-signature audit trail design).
-
tractorjuice Bundle Arckit Au Ot Security[COMMUNITY] Generate an ASD operational technology cyber security assessment for Australian Government and critical-infrastructure projects with connected OT environments.
-
tractorjuice Bundle Arckit Us Fedramp Ssp[COMMUNITY] Draft a FedRAMP System Security Plan (Moderate / High baseline) aligned to the current FedRAMP SSP template structure — system identification, boundary, types of users, interconnections, control implementations, continuous monitoring.
-
tractorjuice Bundle Arckit Au Ism Controls[COMMUNITY] Generate an ASD Information Security Manual (ISM) control applicability statement for Australian Government projects, scoped to the system's classification and supporting DISP attestation.
-
evolution-foundation Skill Dev Configure NotificationsSet up Telegram, Discord, or Slack webhooks for engineering layer alerts — long-running task completion, build failures, security audit alerts.
-
steph-dove Skill Security AuditYou are running a security audit of the current change. Scope is the diff against the base branch and the immediate context of what it touches — not the whole tree, and not style or architecture. Report findings only; do not edit code.
-
steph-dove Skill Httpx Security AuditYou are running a security audit of the current change. Scope is the diff against the base branch and the immediate context of what it touches — not the whole tree, and not style or architecture. Report findings only; do not edit code.
-
cleanexpo Skill SecuritySecurity patterns and anti-patterns for the Pi-Dev-Ops codebase — path traversal, HMAC webhooks, secrets hygiene, timing-safe comparisons, autonomous permission grants.
-
cleanexpo Skill Audit EmitCentralised audit emitter sitting in front of every Dispatcher step + every Scribe send + every CoS routing decision. Writes to .harness/swarm/swarm.jsonl (existing immutable append) and optionally fires Langfuse webhooks for off-Pi-CEO observability. Closes Hermes Sprint 1 SWARM-006 + the audit-immutable safety control.
-
cleanexpo Skill Design AuditDEPRECATED (RA-7057) — superseded by the installed pbakaus/impeccable skill v3.9.1. Use `impeccable` (`/impeccable audit`, `/impeccable critique`, `/impeccable polish`, `/impeccable bolder`) instead. Kept for the archaeological record; do not route new work here.
-
cleanexpo Skill Security AuditSenior Security Officer (15+ years white/black hat experience). Deep-audits codebases for OWASP Top 10, supply-chain risks, secrets exposure, auth flaws, injection vectors, CSP misconfigs, and weak crypto. Produces a prioritised CVE-style finding report with CVSS scores and remediation steps.
-
cleanexpo Skill Launch Enhance DebloatMake existing code stronger, leaner, and more secure without over-engineering — deletion is often the best change. Finds dead weight, weak spots on critical paths, and security issues; proposes a ranked reversible change list and applies only approved changes in a sandbox with tests passing. Use on "clean up", "remove bloat", "strengthen", "secure it", or as step 4 of /ship-it.
-
lovstudio Bundle Lov Bp PolishReview and improve an existing BP outline, PPTX, PDF, or rendered slide set across investment logic, evidence, copy, charts, and visual quality. Produces a scored report, page-level revisions, and targeted regeneration instructions while keeping facts separate from assumptions. Trigger on "润色 BP", "审稿商业计划书", "PPT 不专业", "逐页检查", "改图表", "BP review", "polish pitch deck", or "audit investor deck".
-
morning-start Bundle TauriUse when the user asks about Tauri v2 desktop app architecture, IPC design, permission and security policy, performance tuning, cross-platform compatibility, or packaging and release.
-
morning-start Skill Quality ProducerUse when the user needs quality, testing, deployment, operations, or security documentation.
-
cleanexpo Skill Ship ItA launch-readiness PRE-FLIGHT that runs before the existing ship-chain — load the charter, audit build-state, run the aggregated launch-review, propose enhancements, sync findings to Linear via the existing pi-dev-linear-contract, then STOP for a human go. On go it hands the approved, build-ready issues to the existing ship-chain / tao-loop, never re-implementing build/test/ship. Use on "ship it" / "run the launch crew".
Audited -
finsilabs Bundle Account SecurityProtect customer accounts with brute-force lockouts, multi-factor authentication, secure session handling, and credential-stuffing defenses
-
finsilabs Bundle Pci Dss ComplianceMeet PCI-DSS payment security requirements by scoping your environment correctly, selecting the right SAQ, and implementing required controls
-
finsilabs Bundle Financial Audit TrailBuild immutable audit trails for all financial transactions with user attribution, change logging, tamper detection, and compliance-ready export for external audits
-
finsilabs Bundle Tax Compliance AutomationAutomate multi-jurisdiction sales tax, VAT, and GST compliance with nexus tracking, exemption certificates, filing automation, and audit-ready reports
-
finsilabs Bundle Data Retention PoliciesAutomate the lifecycle of order and customer data — archive old records, anonymize personal data on request, and purge expired data on schedule
-
finsilabs Bundle Financial Compliance SoxImplement SOX-compliant financial controls for ecommerce with audit trails, segregation of duties, access controls, and compliance-ready transaction logging
-
ahtishamshahzad Skill Security ReviewUse to assess a change or codebase for security weaknesses — secrets, auth, authorization/IDOR, injection, PII handling, transport/errors, payments, and production hardening. Reports findings by severity, separates confirmed from potential, never prints secret values, and never claims "secure."
-
ahtishamshahzad Skill AI Output ReviewUse to critically review AI-generated output (plans, code, docs, decisions) for the failure modes AI agents are prone to — unsupported assumptions, invented facts, conflicting architecture, unnecessary dependencies, security risks, missing tests, over-engineering, scope expansion, outdated patterns, incomplete validation, and false claims of completion.
-
ahtishamshahzad Skill Dependency AuditUse to inventory and assess a project's dependencies — versions, known vulnerabilities, unused/duplicate packages, license and maintenance risk, and heavy additions. Recommends changes with justification; never bloats the tree "to be safe."
-
ahtishamshahzad Skill Bug InvestigationUse to diagnose and plan the fix for a defect — audit, reproduce, find root cause, fix minimally, add a regression test, and validate. Fixes the cause, not the symptom, and pins it so it can't return.
-
ahtishamshahzad Skill Environment AuditUse to assess environment and configuration health — env-var usage and fail-fast, config/secrets handling, build/runtime settings, and parity across dev/staging/prod. Flags exposure and missing validation without printing secret values.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include dev-configure-notifications, fin-journal-entry, especialista-em-cyber-security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.