Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
tuanductran Skill Skill VetterSecurity-first vetter for SKILL.md files — checks permissions, suspicious patterns, and metadata before installing or publishing skills. Useful for validating third-party skills for this repo.
-
tuanductran Bundle Hr System IntegrationHelp HR technology teams plan and manage integrations between HR systems (HRIS, ATS, payroll, LMS, benefits platforms) so data flows accurately across the HR tech stack. Use when asked to integrate our HRIS with [system], plan a system integration for HR tools, fix data sync issues between systems, design an HR tech integration architecture, or audit our HR system integrations.
-
jsgforever Bundle Validating Csrf ProtectionValidate CSRF protection implementations for security gaps. Use when reviewing form security or state-changing operations. Trigger with 'validate CSRF', 'check CSRF protection', or 'review token security'.
-
jsgforever Bundle Scanning Container SecurityUse when you need to work with security and compliance. This skill provides security scanning and vulnerability detection with comprehensive guidance and automation. Trigger with phrases like "scan for vulnerabilities", "implement security controls", or "audit security".
-
jsgforever Bundle Ring Requesting Code ReviewGate 4 of development cycle - dispatches 6 specialized reviewers (code, business-logic, security, test, nil-safety, consequences) in parallel for comprehensive code review feedback.
-
jsgforever Bundle Performing Penetration TestingPerform security penetration testing to identify vulnerabilities. Use when conducting security assessments. Trigger with 'run pentest', 'security testing', or 'find vulnerabilities'.
-
jsgforever Bundle Responding To Security IncidentsGuide security incident response, investigation, and remediation processes. Use when you need to handle security breaches, classify incidents, develop response playbooks, gather forensic evidence, or coordinate remediation efforts. Trigger with phrases like "security incident response", "ransomware attack response", "data breach investigation", "incident playbook", or "security forensics".
-
jsgforever Bundle Checking Infrastructure ComplianceUse when you need to work with compliance checking. This skill provides compliance monitoring and validation with comprehensive guidance and automation. Trigger with phrases like "check compliance", "validate policies", or "audit compliance".
-
jsgforever Bundle Implementing Database Audit LoggingUse when you need to track database changes for compliance and security monitoring. This skill implements audit logging using triggers, application-level logging, CDC, or native logs. Trigger with phrases like "implement database audit logging", "add audit trails", "track database changes", or "monitor database activity for compliance".
-
jsgforever Skill Trivy Offline Vulnerability ScanningUse Trivy vulnerability scanner in offline mode to discover security vulnerabilities in dependency files. This skill covers setting up offline scanning, executing Trivy against package lock files, and generating JSON vulnerability reports without requiring internet access.
-
dabit3 Bundle GodmodeJailbreak LLMs: Parseltongue, GODMODE, ULTRAPLINIAN.
-
dabit3 Skill SherlockOSINT username search across 400+ social networks. Hunt down social media accounts by username.
Audited -
dabit3 Bundle 1passwordSet up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in, and reading/injecting secrets for commands.
-
dabit3 Bundle Web PentestAuthorized web application penetration testing — reconnaissance, vulnerability analysis, proof-based exploitation, and professional reporting. Adapts Shannon's "No Exploit, No Report" methodology with hard guardrails for scope, authorization, and aux-client leakage. Active testing against running applications you own or have written authorization to test.
-
dabit3 Bundle Oss ForensicsSupply chain investigation, evidence recovery, and forensic analysis for GitHub repositories. Covers deleted commit recovery, force-push detection, IOC extraction, multi-source evidence collection, hypothesis formation/validation, and structured forensic reporting. Inspired by RAPTOR's 1800+ line OSS Forensics system.
-
dabit3 Skill Requesting Code ReviewPre-commit review: security scan, quality gates, auto-fix.
Audited -
egohygiene Bundle CodeqlComprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI. This skill should be used when users need help with code scanning configuration, CodeQL workflow files, CodeQL CLI commands, SARIF output, security analysis setup, or troubleshooting CodeQL analysis.
-
egohygiene Skill Synapse CreationCreate, refine, connect, audit, or migrate atomic Mind Garden synapses from developed knowledge. Use when evaluating the Synapse Test, reconciling duplicate insights, writing source-linked knowledge notes, adding relationships, organizing lifecycle metadata, or reviewing an existing synapse corpus.
-
rheinmir Skill Skill ProvenanceGhi và kiểm provenance (nguồn + sha256 checksum) cho skill — dùng khi 'cài skill từ ngoài', 'skill này từ đâu', 'audit nguồn skill', 'checksum skill', 'supply-chain skill', phát hiện skill bị sửa lén; bổ trợ orca-sec-scans. Chạy fdk/tools/skill-provenance.py. /skill-provenance
-
griddynamics Bundle SecurityRun authorized, evidence-preserving security reviews and prepare remediation inputs.
-
griddynamics Bundle Solr SchemaTo design and audit Solr schemas: field types, analyzers, docValues, solrconfig.
-
griddynamics Bundle Security FlowWorkflow for authorized, evidence-preserving security review and remediation-task preparation.
-
clawlink-hq Skill NPMNPM integration for AI agents via ClawLink — browser login, no API key setup. Connect NPM through ClawLink's hosted setup to search packages, get download stats, check security advisories, and browse registry metadata. Use this skill when the user wants to work with NPM (Developer Tools) — connect NPM, read or update NPM data, or take actions in NPM from chat instead of saying you cannot access it.
-
dasexperten Bundle Process Audit ExpertProcess Audit Expert
-
jsgforever Bundle Security SuiteComposable binary security suite for static analysis, dynamic tracing, contract capture, baseline drift, and policy gating. Triggers: "binary security", "reverse engineer binary", "black-box binary test", "behavioral trace", "baseline diff", "security suite".
-
jsgforever Bundle Paper AuditUnified paper audit for Chinese and English papers. Use when reviewing paper quality, pre-submission checks, or doing adversarial reviews.
-
jsgforever Bundle Latex Paper EnAudit and improve English LaTeX academic papers. Use when writing, reviewing, or compiling IEEE, ACM, Springer, NeurIPS, and ICML papers.
-
jsgforever Bundle Breaking Change DetectorAudit 6 categories of breaking changes with executable checks for contracts, API diffs, serialized state, and event types.
-
jsgforever Bundle Analyzing DependenciesCheck dependencies for known security vulnerabilities and outdated versions. Use when auditing third-party libraries. Trigger with 'check dependencies', 'scan for vulnerabilities', or 'audit packages'.
-
jsgforever Bundle Checking Owasp ComplianceCheck compliance with OWASP Top 10 security risks and best practices. Use when performing comprehensive security audits. Trigger with 'check OWASP compliance', 'audit web security', or 'validate OWASP'.
-
openharmonyinsight Bundle Openharmony CppExpert coding guide for OpenHarmony C++ development. Use this skill when writing, refactoring, or reviewing C++ code for OpenHarmony projects. It enforces strict project-specific conventions (naming, formatting, headers) and critical security requirements (input validation, memory safety).
-
openharmonyinsight Bundle Dsoftbus Safety GuardOpenHarmony软总线代码安全检视专家 - 全面检查C/C++代码的安全编码规范和日志规范。 涵盖40+条安全规则,包括指针安全、内存管理、锁管理、敏感信息保护等关键领域。 提供跨文件调用分析和控制流分析,生成详细的代码审查报告。 仅在用户输入包含"软总线安全卫士"时触发。 ⚠️ 重要:此技能为只读审查工具,不修改源文件。
-
openharmonyinsight Bundle Docs Check Zh CnCheck whether OpenHarmony API documentation follows the required templates and whether public API docs, system API docs, error code docs, and interface declarations/comments/implementations are consistent. Use when the user asks to review API doc quality, compare docs against code, audit error code docs, fill missing interface documentation, or generate a doc issue report.
-
tuanductran Bundle Hr Recruitment OperationsHelp TA operations leaders design and run the operational backbone of recruiting — requisition workflows, ATS process design, recruiting SLAs, and reporting cadence. Use when asked to design our requisition approval workflow, build recruiting SLAs, set up ATS stages and workflows, audit our recruiting process for bottlenecks, or build a recruiting operations dashboard.
-
winsorllc Bundle Sop EngineExecute multi-step Standard Operating Procedures (SOPs) with approval gates, state persistence, and execution tracking. Use when you need to run complex, multi-step workflows that require human approval, conditional branching, and audit trails.
-
winsorllc Skill Code ReviewAutomated code review and analysis. Use when: user wants to review code changes, check for issues, analyze complexity, or perform security scans.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include skill-vetter, hr-system-integration, validating-csrf-protection. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.