Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
kok-o Skill Gstack RolesRole-based AI specialist system inspired by Garry Tan's gstack. Defines 23 specialist roles (CEO, Eng Manager, Designer, QA, Security etc.) and teaches the AI to adopt the correct role before each task phase.
-
kok-o Skill Ponytail MindsetMinimalist coding mindset based on DietrichGebert/ponytail. Teaches the AI to write only what is strictly necessary. Uses a 7-rung ladder: YAGNI → reuse → stdlib → platform → deps → one-liner → minimum. Minimizes unnecessary boilerplate and over-engineering while keeping all safety, validation and security guards.
-
wesleyegberto Bundle Tests ExpertGenerates test files, creates mocking strategies, analyzes code coverage, designs test architectures, and produces test plans and defect reports across functional, performance, and security testing disciplines. Use when writing unit tests, integration tests, or E2E tests; creating test strategies or automation frameworks; analyzing coverage gaps; performance testing with k6 or Artillery; security testing with OWASP methods; debugging flaky tests; or working on QA, regression, test automation, quality gates, shift-left testing, or test maintenance.
-
wesleyegberto Skill Auth Implementation PatternsMaster authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues.
-
wesleyegberto Bundle Code Review ExpertExpert code review of current git changes with a senior engineer lens in reviewing code for style, best practices, security, and performance. Use when the user asks for "feedback," a "review," or to "check" their changes. Detects SOLID violations, security risks, and proposes actionable improvements.
-
yunseo-kim Bundle Code ReviewerThorough code review with focus on security vulnerabilities, performance issues, and best practices using prioritized rule-based analysis
-
vignesh2027 Skill Code ReviewerActivates CodeReviewer for systematic, multi-dimensional code review. Use when you need a pull request reviewed for correctness, security vulnerabilities, performance bottlenecks, architectural quality, test coverage gaps, or maintainability issues. Produces a structured review with severity-labeled findings and actionable fixes.
Audited -
vignesh2027 Skill Compliance AIActivates ComplianceAI for financial regulatory compliance, AML/KYC, and audit preparation. Use when you need customer due diligence process design, transaction monitoring for AML suspicious activity, regulatory filing calendar and deadline tracking, SOX/PCI/GDPR audit control documentation, or KYC program assessment.
Audited -
vignesh2027 Skill Security ChiefActivates SecurityChief for cybersecurity analysis and threat intelligence. Use when you need STRIDE threat modeling for any system architecture, OWASP top 10 analysis, security log analysis and SIEM triage, incident response playbook execution, SOC2/ISO 27001/NIST CSF control mapping, or vulnerability assessment and remediation planning.
Audited -
thelobbi Bundle Lighthouse HealthDeep expertise in Microsoft 365 Lighthouse multi-tenant management — tenant health scoring, GDAP delegated admin, security baselines, MFA coverage, device compliance, risky users, and remediation planning for MSPs/CSPs via the Lighthouse beta Graph API.
-
thelobbi Bundle Purview ComplianceDeep expertise in Microsoft Purview compliance workflows — DLP policies, retention labels, sensitivity labels, eDiscovery, audit log queries, and guided compliance playbooks with risk-ranked recommendations, audit trails, and legal dependency flags.
-
thelobbi Bundle Microsoft Graph InvestigatorDeep expertise in unified user investigation across Microsoft 365 via Microsoft Graph — mailbox forensics, sign-in analysis, device correlation, file access audit, Teams activity, OAuth consent audit, risk assessment, and multi-source forensic timeline construction.
-
thelobbi Bundle Fabric Security GovernanceAdvanced Fabric security and governance guidance for workspace RBAC, RLS/OLS design, sensitivity labeling, lineage controls, and audit readiness.
-
masih-0x3 Bundle Create HookCodex hook authoring. Use when the user asks to create, update, audit, or verify Codex lifecycle hooks in global ~/.codex or project .codex scope, including hook scripts, hooks.json, matcher behavior, trust review, and smoke verification.
-
masih-0x3 Bundle Redesign Existing ProjectsOn-demand audit and targeted upgrade of an existing website or app's design.
-
masih-0x3 Bundle Implementation OrchestratorOrchestrate goal-backed implementation for large plans, audit remediation, RCA fix plans, multi-phase features, UI/UX revamps, backend/data/security work, or cross-surface engineering changes. Use when the user asks for an implementation conductor/orchestrator, says to implement a saved planning-orchestrator file, audit report, or root-cause fix plan, or wants focused subagents/workers coordinated until acceptance criteria pass. Do not use for small one-file fixes, read-only audits, planning-only work, or unresolved failures that still need root cause analysis first.
-
kevin-liu-01 Skill LerpAudit prose (comments, docs, READMEs, commit messages, PR descriptions) for jargon, unexplained acronyms, and assumed context. Rewrites for the least experienced reader. Use after writing docs, READMEs, or any prose that will be read by someone who did not write the code.
-
kevin-liu-01 Skill RefineCompound quality pass over recently changed code. Orchestrates seven standalone skills in sequence: comment, lerp, style, fix-types, interface, test-invariants, exemplar-audit. Each pass is independently invokable. Use after any feature or refactor lands and before the final commit.
-
kevin-liu-01 Skill Fix TypesAudit code for loose types that allow semantically invalid values to compile. Introduces newtypes, checked casts, enums over booleans, and documents wire/DB discriminant contracts. Use when writing structs with bare primitives, reviewing database or protocol code, or when a function takes 2+ parameters of the same type.
-
kevin-liu-01 Skill PostmortemRun a blameless postmortem for a production incident. Investigate with data, write a structured report, build verification queries, and track remediation. Use when something broke in production, money was lost, users were affected, or a security issue was exploited.
-
kevin-liu-01 Skill Wiki DoctorRun the wiki system doctor to validate wiki structure, skills, rules, automations, and config sync. Use when the user says "doctor", "audit", "health check", "validate wiki", "check my system", "run doctor", or when you suspect something is misconfigured after a large edit session.
-
kevin-liu-01 Skill Exemplar AuditCompare implementation against canonical open-source references. Clone exemplars into /tmp, diff edge cases, error paths, and protocol invariants. Use when building a new subsystem, after a refactor, or when reviewing code that implements a known standard (POSIX, FUSE, WAL, S3, NFS, etc.).
-
kevin-liu-01 Skill Security AuditCTF-style security and correctness audit. Use when the user asks for a security review, before deploying user-facing services, or when reviewing auth, payments, or anything that touches secrets.
Audited -
kevin-liu-01 Skill Read And ReviewRead external reference material (RFDs, papers, blog posts, docs), extract actionable rules, then dispatch subagents to audit the codebase against those rules and fix violations. Use when the user shares a technical reference and wants it applied to the codebase.
-
kevin-liu-01 Skill Gstack Design ReviewDesign audit with UX usability tests. 6-phase audit with 80-item checklist and letter grades. Use when the user says "design review", "UX audit", "visual audit", "audit the UI", "how does this site look", or wants a comprehensive design audit with usability testing.
-
naveedharri Skill Ads CreativeCross-platform creative quality audit covering ad copy, video, image, and format diversity across all platforms. Detects creative fatigue, evaluates platform-native compliance, and provides production priorities. Collects brand context and creates branding.md if missing. Uses infographic-v2 for generating ad creatives. Use when user says "creative audit", "ad creative", "creative fatigue", "ad copy", "ad design", or "creative review".
-
tranhieutt Skill Security Audit---
-
finpeakinc Bundle Tiktok AdsManage TikTok advertising by calling the official TikTok Business API v1.3 directly. Use when the user wants to authorize a TikTok developer app through a local OAuth callback, obtain, inspect, or refresh an Access-Token, retain and rotate a Refresh Token, inspect authorized advertisers or ad accounts, list/create/update campaigns, ad groups, ads, and creatives, change delivery status, upload assets, query reports, manage audiences, pixels, catalogs, Business Center resources, automated rules, comments, or call another documented v1.3 endpoint. Provides fixed-host HTTP requests, local credential reuse, multipart uploads, secret redaction, read execution, mutation previews, and explicit execution gates without an SDK dependency.
-
mphaxise Skill CsoSecurity audit workflow for Codex. Use when a repo, feature, or system should be reviewed for concrete security risks before or after shipping.
-
mphaxise Skill MaintainGBrain-inspired maintenance for Codex. Use when the user wants a health check, consistency audit, stale-doc sweep, or package cleanup pass.
-
mphaxise Skill Soul AuditGBrain-inspired identity and cadence setup for Codex. Use when defining the package's identity files, access posture, user context, or operational cadence.
-
mphaxise Skill Devex ReviewLive developer-experience audit for Codex. Use when docs, setup, onboarding, CLI, API, or SDK workflows should be tested as a real user would experience them.
-
mphaxise Skill Design ReviewLive design audit and polish workflow for Codex. Use when an implemented UI should be reviewed for visual quality, interaction quality, and consistency.
-
mphaxise Skill Citation FixerGBrain-inspired citation audit for Codex. Use when the local brain corpus needs citation normalization or a pass over remaining uncited lines.
-
aradotso Skill Gravit Designer Security AnalysisAnalyze and understand software licensing mechanisms, ethical distribution, and security implications of design tool modifications
-
florianbuetow Bundle KissThis skill should be used when the user asks to "find simplification opportunities", "simplify this code", "check for unnecessary complexity", "find over-engineering", "audit code complexity", "reduce complexity", or "what can be simplified". Also triggers when the user mentions KISS, "keep it simple", over-abstraction, dead code, redundant code, tight coupling, interface bloat, or asks about simplification opportunities. Supports checking all five dimensions at once or focusing on a single dimension.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include Microsoft Graph Investigator, maintain, code-reviewer. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.