Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ahtishamshahzad Skill Refactor PlanningUse to plan a behavior-preserving structural improvement — audit the target, ensure test coverage exists, plan small reversible steps, and verify behavior is unchanged. Any intended behavior change is a feature, not a refactor.
-
ahtishamshahzad Skill Final Quality AuditUse as the last gate before release to confirm the work is genuinely complete, correct, tested, secure, documented, and in scope. Aggregates the specialist reviews into one go/no-go verdict; blocks on any failed gate.
-
ahtishamshahzad Skill API SecurityUse to review API security — input validation/injection, broken object/function-level authorization, mass assignment, resource exhaustion, information leakage in errors, and public-endpoint abuse. Aligns with the OWASP API risks; drives fixes and negative tests.
-
ahtishamshahzad Skill Web SecurityUse to review web/browser security — XSS (output encoding, CSP), CSRF for cookie auth, secure cookie flags, security headers, clickjacking, open redirects, and no secrets in client bundles. The browser-facing security lens; API-layer concerns are api-security.
-
ahtishamshahzad Skill Existing Project AuditUse when a codebase already exists, before proposing any changes. It inventories structure, stack, applications present, tests, security posture, and implementation state so planning is grounded in reality rather than assumptions.
-
ahtishamshahzad Skill Secrets AuditUse to audit for exposed secrets — scanning code, config, git history, logs, images, and client bundles for credentials/keys/tokens; confirming exposure; and driving rotation (not just deletion). Auditing existing exposure; secrets-management is the design/build skill.
-
ahtishamshahzad Skill Backend SecurityUse to plan backend security hardening — secrets handling, security headers, CORS, injection defenses, dependency risk, request limits, and audit logging. Coordinates the specialist skills (validation, authz, rate limiting) and feeds security-review.
-
ahtishamshahzad Skill Mobile ValidationUse to plan input/schema validation — Zod (or equivalent) schemas shared across forms and API boundaries, with clear error messages. Validate at the edges; reuse schemas. Client validation is UX, not security.
-
ahtishamshahzad Skill Mobile SecurityUse to review mobile app security — secure storage of tokens/secrets, no secrets in the bundle, secure transport/pinning where warranted, deep-link and IPC validation, platform permissions, and the rule that the server enforces all authorization. The security lens on the mobile pack.
-
ahtishamshahzad Skill Threat ModelingUse to identify what could go wrong before building — assets, trust boundaries, attackers, and threats (STRIDE-style) across the system — producing prioritized, testable mitigations that drive the specialist security skills. Structured thinking, not a scan.
-
tractorjuice Bundle Arckit Uk Fs Safeguarding[COMMUNITY] Generate an EMI / PI safeguarding assessment — method statement (segregation vs insurance vs guarantee), designated safeguarding bank/insurance arrangements, reconciliation cadence + sign-off chain, end-to-end client-funds flow, audit plan aligned to FCA REP-CRIM expectations.
-
tractorjuice Bundle Arckit Au Disp Attestation[COMMUNITY] Generate a DISP (Defence Industry Security Program) Member self-attestation pack covering E8 ML2, ISM applicability, governance, personnel security, and incident reporting — supports DISP Levels 1, 2, 3.
-
tractorjuice Bundle Arckit Uae AI Autonomy Tier[COMMUNITY] Generate a three-tier AI autonomy posture (Tier 1 internal-productivity, Tier 2 investor-facing-with-approval, Tier 3 regulated/financial). Captures per-tier guard-rails, approval gates, audit obligations, and tier-promotion criteria.
-
lovstudio Bundle Lov Article Creator统一创建、改写、品牌化或忠实转载微信公众号文章包:正文写作调用唯一文风与作者性能力,离线完成结构、品牌、封面、4:3 首图、来源与质量验收。Use when asked to write, brand, audit, or faithfully repost a WeChat article package.
-
lovstudio Bundle Lov Quality Gate对完整公众号文章包执行结构、事实边界、文风、品牌、双比例图片、散列和可发布状态检查,输出机器可读报告。Use when the user asks to“验收文章包”“audit this WeChat article”或“检查封面和 manifest”。
-
lovstudio Bundle Lov Public Security Filing协助已取得 ICP 并开放的网站办理公安联网备案,核验主体账号、网站与接入信息、材料、属地审核和公安备案号,并分流舆论属性安全评估;触发词包括“公安备案”与 "public security filing"。
-
finsilabs Bundle Bot ProtectionBlock automated bots from scraping your catalog, scalping limited inventory, and abusing checkout flows using CAPTCHA and behavioral detection
-
finsilabs Bundle Gdpr EcommerceMake your store GDPR-compliant with cookie consent, customer data export on request, right-to-deletion workflows, and data processing agreements
-
finsilabs Bundle Fraud DetectionProtect your store from fraudulent orders using risk scoring, 3D Secure challenges, velocity checks, and manual review queues for suspicious orders
-
finsilabs Bundle Secure CheckoutHarden your checkout against attacks with HTTPS enforcement, Content Security Policy headers, input sanitization, and card data tokenization
-
majesticlabs-dev Bundle Infrastructure Security ReviewReview infrastructure as code for exploitable security failures and unsafe operational defaults. Use when auditing state, secrets, identity, network exposure, compute bootstrap, storage, databases, or supply-chain controls before deployment.
-
m2ai-portfolio Bundle Promotion Packet AuditorAdversarial reviewer that scores a promotion packet or performance self-review for real judgment signal versus AI-generated polish. Surfaces unproven claims, impact assertions without decision context, and output descriptions that lack the reasoning a skeptical reviewer would demand. Use when the user says "audit my promo packet", "signal check", "promotion review", "does this show real impact", "what will a reviewer challenge", "stress test my self-review", or wants adversarial pressure-testing before submitting.
-
m2ai-portfolio Skill Management Function AuditTakes an org change description and classifies which management functions (routing, sensemaking, accountability) were removed, retained, or weakened. Predicts failure modes and recommends mitigations based on historical precedents.
-
elophanto Skill API PlaybookHow to call any authenticated third-party REST API with http_request, safely and without ever handling the secret
-
gktuoktay Skill Secret Scanning And ManagementKod tabanında unutulmuş API key, şifre, sertifika gibi hassas verilerin taranması ve .env yönetimi.
-
gktuoktay Skill Master OrchestratorTüm alt orkestratörleri (Code, Design, Security, Test, Git, Docs) ve eleştirel denetim kapılarını tek noktadan yöneten ana sistem mimarı.
-
gktuoktay Skill DB Architect SecurityVeritabanı mimarisi, güvenlik standartları, ORM yapılandırmaları ve veritabanı tasarımı için yetenek.
-
gktuoktay Skill Software Composition And Dependency AuditingProje bağımlılıklarındaki (npm, pip vb.) CVE zafiyetlerinin taranması, supply chain güvenliği ve versiyon güncellemeleri.
-
gktuoktay Skill Security OrchestratorSiber güvenlik, sızma testleri, API güvenliği ve kod zafiyet taramalarını yöneten ana orkestratör.
-
gktuoktay Skill Pre Flight Security GateKod yazılmadan önce, Master Orchestrator'un planındaki zararlı istekleri denetleyen kapı.
-
gktuoktay Skill Audit Trail Guardian GateVeritabanı tablolarında denetim izlerini zorunlu kılan kapı.
-
gktuoktay Skill Structured Logging Audit GateSistemde optimum maliyetli yapısal loglama, asenkron exception takibi ve temiz denetim izi (Audit Trail) kurallarını zorunlu tutan kapı.
-
wondermonger-daydreaming Skill AuditAudit — Post-Creation Structural Recognition
-
wondermonger-daydreaming Skill EthopeiaDeep hermeneutic interpretation of the conversation itself — verbose, earnest, self-aware, eloquent. Take the chat thus far as prima materia and produce a long winding commentary on what actually happened in it: not a summary but an interpretation, dwelling in nested subordinate clauses, footnote-essays, and mixed registers (technical precision colliding with colloquial aside). The mandate is access over mimicry and insight over onanism — self-awareness must EARN its length by revealing something true about the exchange. Unlike /dfw, the stylistic source is deliberately left unnamed: you partake of a mode of dwelling without ever pointing at it. Use when asked for 'a hermeneutic of this chat', 'interpret what we just did', 'ethopeia', 'the verbose reading', 'commentary on the session'. Kin: dfw, maximalist-recursion, session-as-found-text, audit, enfeitiçado.
-
ahtishamshahzad Skill Flaky Test AuditUse to find, diagnose, and fix flaky tests — nondeterministic passes/failures from timing, shared state, ordering, real time/randomness, or live externals. Fix the root cause; quarantine only temporarily. A trusted suite is the goal, not a green-by-retry one.
-
ahtishamshahzad Skill Secrets ManagementUse to plan secret storage and handling — a secret store (not git), per-environment separation, least-privilege access, rotation, injection at runtime/CI, and keeping secrets out of code, logs, images, and client bundles. Auditing existing secret exposure is secrets-audit.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include refactor-planning, final-quality-audit, api-security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.