Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
xspoonai Bundle Defi Safety ShieldComprehensive DeFi safety monitoring - scan tokens for risks, detect phishing, audit wallet approvals, and score protocol safety
-
xspoonai Bundle Bridge Security WatchdogReal-time bridge security monitoring tool that analyzes TVL changes, tracks large withdrawals, and generates comprehensive safety scores (0-100) to detect exploits and help users avoid compromised bridges. Monitors Stargate, Wormhole/Portal, Across, Hop, and major cross-chain bridges using on-chain data and multi-dimensional risk assessment.
-
xspoonai Bundle Security Vulnerability ScannerEnterprise security vulnerability scanner that detects OWASP Top 10 vulnerabilities, provides CVSS-based risk scoring, generates remediation guidance, checks for known CVEs, and produces SBOM reports
-
xspoonai Bundle Rug Pull Probability ScorerAdvanced token safety analyzer that evaluates smart contracts, holder distribution, liquidity status, and on-chain metrics to calculate a comprehensive safety score (0-100). Detects honeypots, centralization risks, liquidity locks, and malicious contract patterns using real-time blockchain data and multiple security APIs.
-
xspoonai Bundle Smart Contract AuditorAutomated smart contract security auditor using source code analysis, function signature intelligence, and multi-source security data. Zero configuration, no API keys required.
-
spike-faye-lei Skill Overleaf SyncTwo-way sync between a local paper directory and an Overleaf project, so ARIS audit/edit workflows stay on the local copy while collaborators edit in the Overleaf web UI. Use when user says "同步 overleaf", "overleaf sync", "推送到 overleaf", "connect overleaf", "Overleaf 桥接", "pull overleaf", "push overleaf", or wants to bridge their ARIS paper directory with an Overleaf project.
-
spike-faye-lei Skill Citation AuditZero-context verification that every bibliographic entry in the paper is real, correctly attributed, and used in a context the cited paper actually supports — catching hallucinated authors, wrong years, fabricated venues, version mismatches, and wrong-context citations. Use when user says "审查引用", "check citations", "citation audit", "verify references", "引用核对", or before submission to ensure bibliography integrity.
-
h-mmer Skill LearnRecord a platform response and update learning. Usage: /learn <report_id> <status> [--bounty 500] [--vuln-type XSS]
-
h-mmer Skill DupcheckCheck if a vulnerability has already been reported. Searches platform hacktivity + local findings. Usage: /dupcheck <vuln_type> e.g. /dupcheck XSS in search endpoint
-
h-mmer Skill FullscanFull security assessment with brain coordination. Multi-phase, skips known-exhausted areas, builds on prior knowledge.
-
h-mmer Bundle Hunt Business LogicHunting skill for business-logic vulnerabilities (CWE-840 Business Logic Errors, CWE-841 Improper Enforcement of Behavioral Workflow, CWE-639 Authorization Bypass via User-Controlled Key in business contexts, CWE-362 race conditions on financial flows). Built from 44 corpus reports plus 8.8K shared-platform reports across HackerOne, Bugcrowd, Huntr, GitHub Security Advisories, plus 2024-2026 meta verified against NVD — Lilishop coupon overpurchasing (CVE-2024-50654 CVSS 7.5), WWBN AVideo wallet double-spend TOCTOU (CVE-2026-34368, GHSA-h54m-c522-h6qr), Keycloak 2FA bypass (CVE-2025-3910, GHSA-5jfq-x6xp-7rw2), AlegroCart 1.2.9 negative-quantity price manipulation (Andrey Stoykov SecLists Apr 2025), Bagisto cart price manipulation (Rudransh Singh Rajpurohit Sep 2025), Doppler free-trial reset (Aditya Sunny Dec 2024), Stripe hasEverTrialed bypass (better-auth
-
h-mmer Bundle SastSource code vulnerability hunting (SAST). Decomposes analysis into specialized passes: map entry points, map dangerous ops, trace flows, find gaps, adversarial validation, exploit. Usage: /sast <repo_path> [--lang c|cpp|rust|java|python|go|php] [--min-score 4] [--max-files 30] [--skip-static] [--best-of N]
-
h-mmer Bundle QuickscanRun a quick security scan on a target. Consults the Brain first, validates scope, runs passive recon + vuln scan in parallel.
-
is-bo Skill Forge APIAudit API contracts, boundary validation, authorization, consistency, pagination, errors, and idempotency.
-
is-bo Skill Forge DocsVerify that user, contributor, architecture, operations, security, and release documentation is accurate and executable.
-
is-bo Skill Forge CacheFirst decide whether caching is justified, then audit keys, invalidation, consistency, privacy, and failure behavior.
-
is-bo Skill Forge OfflineAudit local persistence, queued actions, synchronization, conflicts, revocation, privacy, and recovery under intermittent connectivity.
-
is-bo Skill Forge DiscoverBuild an evidence-backed application profile and architecture map before any specialized audit begins.
-
is-bo Skill Forge PaymentsAudit money movement, pricing, entitlements, provider events, reconciliation, idempotency, and sensitive data boundaries.
-
is-bo Skill Forge SecurityPerform a threat-informed audit of trust boundaries, injection, secrets, browser controls, dependencies, and abuse cases.
-
is-bo Skill Forge ReliabilityAudit timeouts, retries, overload, dependencies, degradation, consistency, and operational objectives.
-
is-bo Skill Forge IntegrationsAudit outbound and inbound integrations for authentication, validation, failure isolation, drift, and replay safety.
-
is-bo Skill Forge Supply ChainInspect dependencies, build integrity, provenance, releases, licenses, actions, and secret exposure across the delivery chain.
-
is-bo Skill Forge InfrastructureAudit infrastructure as code, network and identity boundaries, encryption, state, drift, and least privilege.
-
xspoonai Bundle License AuditDescription
-
xspoonai Bundle Security LintingAutomated security scanning for Python code using Bandit.
-
xspoonai Bundle Mempool Intrusion Detection SystemReal-time blockchain intrusion detection system that monitors mempool for exploit attempts and automatically executes defensive responses using ML classification and gas-optimized front-running
-
xspoonai Bundle Security AuditSmart contract security audit assistant powered by Solodit API. Search 50,000+ vulnerabilities, fetch contracts from 40+ chains, run static analysis, generate PoC exploits and audit reports.
-
qa-aman Skill Pentest ScopeWrite a penetration test scope document. Use when the user says "pentest scope", "pen test scope document", "penetration testing scope", "scope of engagement", "rules of engagement", "what to include in a pentest", "security assessment scope", "red team scope", "bug bounty scope", or needs to define the boundaries, objectives, and rules for a penetration testing engagement - even if they don't explicitly say "scope".
-
qa-aman Skill Pitch NarrativeUse when the user says "write my pitch", "help me tell my startup story", "craft my investor narrative", "why now slide", "what's our secret", "how do I explain what we do", "make my pitch compelling", "pitch deck story", "elevator pitch", "why will we win", "contrarian insight", or wants to build a persuasive, coherent narrative around their startup for investors, press, or recruiting.
-
qa-aman Bundle Audit WorkpaperWrite a clear, reviewable audit workpaper documenting procedures, evidence, and conclusions. Use when an auditor says "write a workpaper", "document this audit procedure", "tick and tie this", "I need to document my testing", "substantive testing workpaper", "controls testing documentation", "audit evidence memo", "prepare the workpaper for this balance", "document the audit steps I performed", or needs to capture any audit work in a format that supports review and sign-off. Also trigger when someone has completed audit testing and needs to write it up even if they don't use the word "workpaper".
-
qa-aman Skill Dependency MappingSurface and visualize hidden dependencies blocking delivery. Use when the user says "map our dependencies", "what's blocking what", "dependency audit", "why are teams blocked", "we have a bottleneck", "draw out the dependencies", or asks to identify cross-team blockers - even if they don't explicitly say "dependency mapping". Based on "Making Work Visible" by Dominica DeGrandis (time theft, invisible work, flow blockers).
-
garphengate Skill Security ReviewerA pre-launch defensive pass anyone on the team can run in an afternoon. Use before shipping anything public-facing or after inheriting a project with unknown security posture.
-
garphengate Skill Time Audit AnalystSet up the lightest time-tracking format that still supports leak-finding and utilization math; use when starting tracking or after abandoning a heavier system.
-
uphiago Skill Hunt Prototype PollutionHunt client-side and server-side prototype pollution for XSS, auth bypass, and RCE.
Audited -
uphiago Skill Mid Engagement Ir DetectionMethodology for detecting client SOC patches, attacker activity, and security-state changes that occur DURING a red-team engagement — and converting those observations into deliverable findings. Built from authorized red-team work where the client patched a confirmed SQLi within 30 minutes of detection AND an external attacker locked multiple new accounts during a single test session. Use when (a) running ANY active engagement against a monitored target, (b) a previously-confirmed finding stops reproducing, (c) baseline timing shifts unexpectedly, or (d) you notice response patterns changing during testing.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include defi-safety-shield, Bridge Security Watchdog, security-vulnerability-scanner. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.