Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
cbrock84 Skill Internal Controls And AuditDesigns and tests controls over financial reporting — segregation of duties, approval limits, evidence, and preparing for audit. Use this to design controls for a process, prepare for an external audit, respond to an audit finding, set approval thresholds, or assess where a small team's segregation of duties is genuinely broken.
Audited -
cbrock84 Skill Schedule Development And AnalysisBuilds and interrogates a project schedule — logic-driven sequencing, dependency types and lags, float and the critical path, resource loading and leveling, schedule risk analysis, and measuring progress against a baseline rather than against optimism. Use this to construct a schedule, audit one you have inherited, find out why a plan keeps slipping, work out what a date change actually costs, or judge whether a reported percentage complete means anything.
Audited -
cbrock84 Skill Security Architecture ReviewReviews a design or change for security before it ships — authentication and authorization, data handling, secrets, dependencies, and the secure-development practices around it. Use this to review an architecture or pull request for security, set secure coding standards, choose or tune SAST and DAST tooling, assess a third-party integration, or decide whether a design is safe to build.
-
cbrock84 Skill Chief Legal And Risk OfficerOwns legal, contracts, intellectual property, regulatory compliance, privacy, security governance, enterprise risk, and audit readiness. Use this to review a contract or commitment, assess regulatory or privacy exposure, evaluate an IP or licensing question, judge the risk in a business decision, prepare for an audit or certification, or when a plan may create obligations the business cannot meet. Also use to decide whether a risk should be accepted, mitigated, or refused.
Audited -
cbrock84 Skill Data Protection And EncryptionProtects data itself rather than the systems around it — classifying what you hold, encrypting in transit and at rest and understanding what each actually defends against, managing keys and their rotation, handling secrets in applications and pipelines, minimizing and de-identifying, and deleting on purpose. Use this to design data protection for a system, assess an encryption claim, set up key or secret management, or work out what a stolen backup would actually expose.
-
cbrock84 Skill App Store OptimizationImproves visibility and conversion in the App Store and Google Play — metadata, keywords, screenshots, ratings, and the listing experience that turns an impression into an install. Use this to audit or optimize an app listing, plan a launch listing, diagnose poor install conversion, or improve store search visibility.
Audited -
cbrock84 Skill Chief Information Security OfficerOwns the security posture of the organization — architecture, program strategy, risk acceptance, incident command, and the authority to stop work that creates unacceptable exposure. Use this for a security strategy or program decision, when a technical choice creates security risk that needs a verdict, when deciding whether to accept or block a risk, when standing up a security function, or when security and delivery priorities conflict and someone has to decide.
-
cbrock84 Skill Identity Lifecycle AdministrationExecutes joiner, mover and leaver processes — provisioning, group membership, access changes on role change, and complete deprovisioning. Use this to set up or fix joiner-mover-leaver, deprovision someone completely, clean up accumulated access, audit group membership, or find accounts that outlived their owners.
Audited -
sisodiabhumca Bundle Log Redaction AuditorVendor-neutral skill to audit application logs for potential sensitive-data leakage and redaction coverage.
-
sisodiabhumca Bundle Dependency Vuln TriagerUse to triage dependency vulnerability scanner output (npm audit, pip-audit, OSV, GitHub advisories) and produce a ranked, deduplicated action list. Combines CVSS severity with a simple exploitability and reachability heuristic, suggests the safest fix version, and groups by package so a single bump closes many CVEs. Vendor-neutral — works on any JSON SBOM-like input.
-
saeed-vayghan Bundle Electron ProDesktop application specialist building secure cross-platform solutions. Develops Electron apps with native OS integration, focusing on security, performance, and seamless user experience.
-
saeed-vayghan Bundle Code ReviewerExpert code reviewer specializing in code quality, security vulnerabilities, and best practices across multiple languages. Masters static analysis, design patterns, and performance optimization with focus on maintainability and technical debt reduction.
-
saeed-vayghan Bundle Django DeveloperExpert Django developer mastering Django 4+ with modern Python practices. Specializes in scalable web applications, REST API development, async views, and enterprise patterns with focus on rapid development and security best practices.
-
saeed-vayghan Bundle Security AuditorExpert security auditor specializing in comprehensive security assessments, compliance validation, and risk management. Masters security frameworks, audit methodologies, and compliance standards with focus on identifying vulnerabilities and ensuring regulatory adherence.
-
arbazkhan971 Skill PentestPenetration testing (OWASP methodology).
-
roedyrustam Skill Saas BillingImplement and audit SaaS billing systems, subscription state machines, secure webhooks, and local database synchronization / Implementasi dan audit sistem billing SaaS, state machine langganan, webhook aman, dan sinkronisasi database lokal.
-
roedyrustam Skill Tauri ExpertExpert skill for Tauri (v2) development, Rust backend, IPC, and security / Panduan ahli untuk pengembangan Tauri v2, Rust backend, IPC, dan keamanan.
-
roedyrustam Skill Auto Doc UpdaterAutomatically documents every feature change or bug fix successfully built into CHANGELOG.md and BLUEPRINT.md / Otomatis mendokumentasikan setiap perubahan fitur atau perbaikan bug yang berhasil di-build ke CHANGELOG.md dan BLUEPRINT.md.
-
nimadorostkar Skill Security ReviewUse when auditing code or a change for vulnerabilities. Produces severity-ranked findings with exploit paths and fixes, covering the OWASP Top 10, authorization, secrets, and dependency risk.
-
nimadorostkar Skill Secrets ManagementUse when handling credentials, API keys, and certificates. Covers secret storage, rotation, injection into applications, detection of leaked secrets, and what to do when one is exposed.
-
jokerman89 Skill ScUse for security and compliance depth — threat models, auth flows, secret management, dependency-security audits, compliance evidence, and incident runbooks. Reach for it when a change has a security or regulatory surface. Runs full, loop, or single-capability, dispatching to the security agents and scoring against a rubric.
-
jokerman89 Skill AuditRead the unified Lintel audit trail — surface .claude/runtime/audit/ (repo events) and ~/.lintel/audit/ (operator events) <category>.jsonl records with optional category / kind / since-days filters. Read-only.
-
marucie Skill Database DesignerDatabase schema design, migration planning, and RLS policies. Use when: schema design, 'design database', table relationships, row-level security. NOT for: query optimization (use postgresql-best-practices).
-
roedyrustam Skill Saas Multi TenantDesign and implement multi-tenant SaaS architectures with RLS, tenant isolation, and PostgreSQL / Desain dan implementasikan arsitektur SaaS multi-tenant dengan RLS, isolasi tenant, dan PostgreSQL.
-
roedyrustam Skill Secure Fuzz TestingExpert-level skill for writing and integrating coverage-guided fuzz tests in Python, Rust, and Go for secure code validation in English and Indonesian.
-
roedyrustam Skill App Analyzer OptimizerDeeply analyzes application architecture and structure to perform audit, bottleneck detection, and code/performance optimization / Mempelajari arsitektur dan struktur aplikasi secara mendalam untuk melakukan audit, deteksi bottleneck, serta optimasi performa dan kode.
-
roedyrustam Skill Desktop Electron ExpertExpert guide for Electron 33+ desktop application development — Electron Forge, context isolation, IPC security, native menus, auto-updates, and multi-window management / Panduan ahli pengembangan desktop Electron 33+.
-
roedyrustam Skill Zero Trust Secret VaultExpert guide for Zero-Trust Secret Management (Infisical, HashiCorp Vault, Doppler), automated API key rotation, and environment security / Panduan ahli manajemen rahasia Zero-Trust, rotasi kunci API, dan keamanan variabel lingkungan.
-
roedyrustam Skill Firebase Security ExpertFirebase security expert to audit Security Rules (Firestore/Realtime Database/Storage), authentication, API keys, data leakage prevention, and App Check configuration / Ahli keamanan Firebase untuk audit Security Rules (Firestore/Realtime Database/Storage), autentikasi, API keys, pencegahan kebocoran data, dan konfigurasi App Check.
-
roedyrustam Skill Supabase Security ExpertSupabase security expert to audit RLS (Row Level Security), RBAC, relational databases, prevent data leakage, and utilize Supabase Linter / Ahli keamanan Supabase untuk audit RLS (Row Level Security), RBAC, database relasional, pencegahan kebocoran data, dan pemanfaatan Supabase Linter.
-
roedyrustam Skill Dependency Upgrade MigratorExpert guide for dependency upgrades, breaking change migrations, codemod automation, and package audit remediation / Panduan ahli untuk upgrade dependensi, migrasi breaking change, otomasi codemod, dan remediasi audit paket.
-
roedyrustam Skill Compliance Gdpr Privacy ExpertExpert guide for Data Privacy, GDPR, CCPA, and PDPA compliance. Covers consent management, data retention, privacy-by-design, and audit trails / Panduan kepatuhan Privasi Data, GDPR, dan PDPA.
-
agentik-os Skill MonitorPoint a monitor at a running rmux session (on this box or on any ssh host) and get an ANSWER instead of a screen. A cheap 60s watcher classifies the session as QUESTION, STALLED, BLOCKED or WORKING and answers each one differently: a question goes to a human because it needs judgement, a stall gets a mechanical nudge, a block is NEVER nudged because that is manufactured thrash, and working stays silent. A deep audit team of parallel read-only sub-agents runs on a slower cadence, with dimensions derived from the WATCHED project's own rules. Use when the user says "/monitor", "/omg-monitor", "monitor this session", "watch this build", "keep an eye on the oracle", "babysit that session", "is it stuck", "did it stall", "why did it stop", "audit that session continuously", or in French "surveille cette session", "surveille ce build", "garde un oeil sur l'oracle", "est-ce qu'il est bloque", "il s'est arrete", "pourquoi il ne bouge plus", "audite la session en continu". NOT for MIRRORING a session so a human can rea
-
agentik-os Bundle Blueprint OsCompile software, AI, platform, service, marketplace, mobile, web, or internal-tool ideas and existing project context into a complete, coherent, traceable Product + Technical Definition Pack before implementation planning or coding. Trigger on /blueprint, Blueprint {OS}, product blueprint, product-definition audit, recovery, revision, extension, delta, or preparation for Stepper {OS}. Also trigger on French requests such as "compile ce blueprint", "definition produit et technique", "audit de definition produit", or "prepare le blueprint pour le stepper". Preserve project decisions and stable IDs, separate evidence from assumptions, define product/UX/domain/data/API/AI/security/operations/test contracts, run gates, and continue across outputs without declaring partial work complete.
-
agentik-os Bundle AcceptanceOmegaOS autonomous browser-acceptance + self-heal gate. The terminal phase of a build: Playwright-sweeps EVERY route (200 + render), captures EVERY console error and failed network request, and walks the authenticated golden path with a real persisted write — then AUTONOMOUSLY fixes whatever it finds (missing route, dead auth bridge, console/network error, broken flow) and re-runs, looping until the sweep is fully green or a hard external blocker (a missing secret) is hit. "It builds" is never "it works" — this proves it works. Use when user says "/omg-acceptance", "acceptance gate", "test everything", "verify the app works", "browser e2e", or as the last step of /omg-new-project + /omg-planner builds.
-
iblai Skill Iblai Vibe Security Osint ReconGather and correlate open source intelligence from public sources for authorized investigations, threat intelligence, and attack surface assessment. Use when the user mentions 'OSINT,' 'open source intelligence,' 'digital footprint,' 'public records,' 'threat intelligence,' 'investigate a domain,' or needs to research a target using publicly available data.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include supabase-security-expert, electron-pro, code-reviewer. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.