Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
peterbamuhigire Skill 08 Accounting Engine Test PlanUse when producing or updating accounting-engine test plan for ledger invariants, posting, reversal, period control, reconciliation, migration, and audit evidence. Use test-plan for the neighbouring concern; this skill owns the named document contract and its acceptance evidence.
-
peterbamuhigire Skill 21 Accounting Operations RunbookUse when producing or updating accounting operations runbook for opening balances, close, ledger integrity, reconciliation incidents, rebuilds, controls, and audit evidence. Use runbook for the neighbouring concern; this skill owns the named document contract and its acceptance evidence.
-
peterbamuhigire Bundle 08 Semantic AuditingUse when performing a read-only semantic audit for ambiguity, contradiction, undefined terms, weak modals, and inconsistent requirement language; use requirements-validation for the full multidisciplinary gate.
-
peterbamuhigire Bundle 12 Saas Trust Center Document PackUse when preparing verified customer-facing security, privacy, availability, subprocessor, and compliance material for a SaaS trust centre. Use evidence-pack-builder for internal proof and DPA/privacy-doc-set for contractual privacy documents.
-
peterbamuhigire Bundle 17 Game System Architecture SpecificationUse when designing game client, authoritative state, engine integration, content, saves, multiplayer backend, platform adapters, telemetry, security, build, and live-operations architecture from an approved game SRS.
-
starchild-ai-agent Bundle 1247 Web CrawlerHeadless browser for web crawling, UX audits, screenshots, and interaction testing. Use when the user wants to audit a website, take screenshots, click buttons, test UX flows, extract content from SPAs, or crawl pages that require JavaScript rendering.
-
starchild-ai-agent Skill 349 Okx Onchainos SuiteUnified wrapper for OKX OnchainOS capabilities (wallet, market, token, signal, trenches, swap, gateway, security, portfolio, audit log). Use when users want any OKX OnchainOS workflow without installing many separate skills.
Audited -
starchild-ai-agent Bundle Okx SecurityUse this skill for security scanning: check transaction safety, is this transaction safe, pre-execution check, security scan, token risk scanning, honeypot detection, DApp/URL phishing detection, message signature safety, malicious transaction detection, approval safety checks, token approval management. Triggers: 'is this token safe', 'check token security', 'honeypot check', 'scan this tx', 'scan this swap tx', 'tx risk check', 'is this URL a scam', 'check if this dapp is safe', 'phishing site check', 'is this signature safe', 'check this signing request', 'check my approvals', 'show risky approvals', 'revoke approval', 'check if this approve is safe', token authorization, ERC20 allowance, Permit2. Covers token-scan, dapp-scan, tx-scan (EVM+Solana pre-execution), sig-scan (EIP-712/personal_sign), approvals (ERC-20/Permit2). Chinese: 安全扫描, 代币安全, 蜜罐检测, 貔貅盘, 钓鱼网站, 交易安全, 签名安全, 代币风险, 授权管理, 授权查询, 风险授权, 代币授权. Do NOT use for wallet balance/send/history — use okx-agentic-wallet.
-
cowork-os Skill Security AuditCheck code for common security vulnerabilities
Audited -
coco-research Skill Gsd Secure PhaseRetroactively verify threat mitigations for a completed phase
-
coco-research Skill Gsd Validate PhaseRetroactively audit and fill Nyquist validation gaps for a completed phase
-
coco-research Skill Gsd Audit MilestoneAudit milestone completion against original intent before archiving
-
coco-research Skill Gsd Plan Milestone GapsCreate phases to close all gaps identified by milestone audit
-
teoslayer Bundle Pilot ReceiptDelivery and read receipts for messages over the Pilot Protocol network. Use this skill when: 1. You need confirmation that messages were delivered 2. You want to track when recipients read your messages 3. You need audit trails for message delivery Do NOT use this skill when: - You need anonymous messaging (use pilot-chat without receipts) - You're sending fire-and-forget messages (use pilot-broadcast) - Receipt tracking adds unnecessary overhead
-
teoslayer Bundle Pilot WatchdogSecurity monitoring for suspicious network patterns in Pilot Protocol networks. Use this skill when: 1. You need real-time detection of suspicious connection patterns 2. You want automated alerts for security anomalies 3. You need to monitor trust relationship changes continuously Do NOT use this skill when: - You only need audit logs (use pilot-audit-log) - You're doing one-time security checks (use pilot-verify)
-
teoslayer Bundle Pilot Audit LogComprehensive audit trail of all Pilot Protocol activity for security and compliance. Use this skill when: 1. You need detailed logs of all trust decisions and connections 2. You require compliance audit trails for security reviews 3. You want to investigate suspicious activity or incidents Do NOT use this skill when: - You need real-time alerting (use pilot-watchdog instead) - You only need basic daemon logs (use pilotctl info) - You're doing performance profiling (use dedicated profiling tools)
-
teoslayer Bundle Pilot BlocklistMaintain and share blocklists of untrusted agents in Pilot Protocol networks. Use this skill when: 1. You need to block malicious or compromised agents from connecting 2. You want to share blocklists across multiple agents in your network 3. You need to maintain a persistent deny-list for security Do NOT use this skill when: - You need temporary connection filtering (use firewall rules) - You're managing trust approvals (use pilot-auto-trust) - You need allowlist-only mode (use trust circles instead)
-
teoslayer Bundle Pilot Event LogPersistent NDJSON event logging with rotation, compression, and retention policies. Use this skill when: 1. You need persistent storage of event streams 2. You need log rotation and compression for long-term retention 3. You need to audit event history with timestamps 4. You need to export events for external analysis Do NOT use this skill when: - You need real-time event processing (use pilot-event-bus instead) - You need short-term replay (use pilot-event-replay instead) - You need filtered logs (use pilot-event-filter first, then log)
-
teoslayer Bundle Pilot Event ReplayRecord and replay event streams for debugging, testing, and audit purposes. Use this skill when: 1. You need to capture event streams for later analysis 2. You need to replay events to test downstream consumers 3. You need to debug event-driven workflows 4. You need to audit event history with timestamps Do NOT use this skill when: - You need real-time event forwarding (use pilot-event-bus instead) - You need long-term storage with rotation (use pilot-event-log instead) - You need filtering before recording (use pilot-event-filter first)
-
teoslayer Bundle Pilot Service Agents EconomicsMacroeconomic indicators — IMF DataMapper, World Bank, Eurostat SDMX, Coinbase reference prices. Use this skill when: 1. Country-level GDP, inflation, or unemployment series 2. Cross-country indicator comparison via World Bank or IMF 3. Eurostat dissemination queries (SDMX) Do NOT use this skill when: - Security-level market quotes (use pilot-service-agents-finance) - SEC filings (use pilot-service-agents-gov-finance)
-
antgroup Skill Env ValidatorValidates .env files for security best practices. Checks for exposed secrets and suggests improvements. Use when: env check, secrets audit, dotenv security
-
antgroup Skill Code Analyzer ProAdvanced static code analysis with AI-powered insights. Finds bugs, security issues, and code smells automatically. Use when: code review, static analysis, code quality, bug finding
-
kumaran-is Bundle Threat ModelingIron Law: NO ARCHITECTURE REVIEW WITHOUT THREAT MODELING FIRST
-
kumaran-is Bundle Security ReviewerSecurity vulnerability detection and remediation skill. Provides OWASP Top 10 checklists, secret scanning patterns, and security review methodology.
-
kumaran-is Skill Vibe Code AuditorAudit AI-generated or rapidly-prototyped code for structural flaws, hallucinated imports, fragility, and production risks before committing or handing off. Use when code was generated with AI assistance, evolved without deliberate architecture, or a prototype needs productionizing.
-
kumaran-is Skill Flutter Security ExpertFlutter mobile security and privacy compliance specialist. Use for secure storage reviews, certificate pinning, GDPR/CCPA compliance, code obfuscation, and mobile-specific security hardening. For general OWASP issues use security-reviewer instead.
-
vivy-yi Skill Audit Support Master审计配合主流程 — 整合资料收集 + 调整审核 + 函证管理的全流程审计配合。 适用情形:年度审计配合报告时执行,整合 audit-evidence-collection、 audit-adjustment-review 和 confirmation-management,输出完整的审计配合报告。 核心:资料完整 → 调整合规 → 函证充分 → 报告出具。
-
vivy-yi Skill Fraud Investigation舞弊调查 — 接收舞弊举报或发现异常线索后,启动独立调查, 搜集证据、评估影响并报告。 适用情形:审计委员会/管理层收到举报、审计中发现舞弊迹象、 外部监管要求调查时执行。
-
vivy-yi Skill Annual Audit Planning年度审计计划制定 — 风险导向审计方法,识别高风险领域, 合理分配审计资源,制定本年度内部审计计划。 适用情形:审计总监/经理在每年 Q4 制定下一年度审计计划时执行, 或年中根据风险变化调整计划时执行。
-
vivy-yi Skill Internal Audit Master内部审计管理主流程 — 整合年度审计计划/专项审计/审计发现整改全流程。 适用情形:审计总监/审计经理制定年度审计计划、启动专项审计、 管理审计发现整改时执行,整合 annual-audit-planning、 process-compliance-audit、audit-finding-tracking 和 fraud-investigation, 输出完整的内部审计管理报告。 核心:风险导向 → 发现问题 → 整改跟踪 → 持续改进。
-
vivy-yi Skill Audit Adjustment Review审计调整审核 — 核查 [ERP] 审计调整分录,评估调整合理性,处理调整分歧。 适用情形:审计过程中执行,从审计调整台账获取调整数据, 核查调整分录准确性,评估对报表影响,输出调整审核报告。 核心:调整识别 + 影响评估 + 分歧处理 + 最终确认。
-
vivy-yi Skill Confirmation Management函证管理 — 协调 [ERP]/[BANK] 银行函证和往来函证,跟踪回函状态,处理异常。 适用情形:审计函证程序时执行,跟踪银行和往来函证发函/回函状态, 核查回函差异,输出函证管理报告。 核心:发函跟踪 + 回函核对 + 差异处理 + 替代程序。
-
vivy-yi Skill Audit Finding Tracking审计发现整改跟踪 — 对所有未关闭的审计发现进行跟踪管理, 验证整改效果,对超期未整改项执行升级流程。 适用情形:审计经理/总监每月审查整改状态、 验证已完成整改、或对超期整改执行升级时执行。
-
vivy-yi Skill Board Reporting Master董事会汇报主流程 — 整合 Board Deck 编制、审计委员会支持、董事会议程管理与重大事项汇报。 适用情形:年度/季度董事会与审计委员会会议前执行,整合 board-deck-preparation、 audit-committee-support、board-meeting-management 和 board-material-distribution, 输出完整的董事会汇报材料包。 核心:会议准备 → 材料编制 → 委员会协同 → 重大事项汇报。
-
cowork-os Skill Dependency CheckAudit dependencies for updates and vulnerabilities
Audited -
cowork-os Bundle ValidationUse when Codex is already in the validation phase of a security scan or the user explicitly asks to determine whether one or more candidate security findings are valid. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include 08-accounting-engine-test-plan, 21-accounting-operations-runbook, 08-semantic-auditing. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.