Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
rweisssieker-xp Skill Ax Migration Continuous Improvement LeadUse when migration intelligence fabric work needs continuous improvement lead, reusable knowledge, benchmarking, portfolio control, scenario simulation, quality audit, resilience, value realization, or continuous improvement.
-
rweisssieker-xp Skill Ax Migration Fabric Data Product AdvisorUse when migration intelligence fabric work needs fabric data product advisor, reusable knowledge, benchmarking, portfolio control, scenario simulation, quality audit, resilience, value realization, or continuous improvement.
-
rweisssieker-xp Skill Ax Migration Knowledge Transfer ExaminerUse when migration intelligence fabric work needs knowledge transfer examiner, reusable knowledge, benchmarking, portfolio control, scenario simulation, quality audit, resilience, value realization, or continuous improvement.
-
rweisssieker-xp Skill Ax Migration Security Attack Surface MapperUse when migration intelligence fabric work needs security attack surface mapper, reusable knowledge, benchmarking, portfolio control, scenario simulation, quality audit, resilience, value realization, or continuous improvement.
-
rweisssieker-xp Skill Ax Migration Integration Resilience EngineerUse when migration intelligence fabric work needs integration resilience engineer, reusable knowledge, benchmarking, portfolio control, scenario simulation, quality audit, resilience, value realization, or continuous improvement.
-
rweisssieker-xp Skill Ax Migration Intelligence Fabric OrchestratorUse when migration intelligence fabric work needs intelligence fabric orchestrator, reusable knowledge, benchmarking, portfolio control, scenario simulation, quality audit, resilience, value realization, or continuous improvement.
-
rweisssieker-xp Skill Ax Migration Regulatory Country Pack GeneratorUse when migration work needs country regulatory packs, localization, tax, e-invoicing, retention, audit, and privacy obligations.
-
gaoqiongxie Skill Security Audit代码层安全审计:AI驱动的静态安全审查,集成CodeQL/Semgrep识别OWASP Top 10、依赖CVE、硬编码密钥。当用户说'安全审计'、'代码安全检查'、'漏洞扫描'、'security review'、'代码安全'、'OWASP'、'Semgrep'、'CodeQL'时触发。核心特点:聚焦代码层静态分析、开发阶段漏洞拦截、与cybersecurity-skills互补(后者覆盖威胁狩猎/事件响应/渗透测试)。
-
gaoqiongxie Skill Cybersecurity Skills网络安全分析师技能库:754个结构化安全技能,覆盖威胁狩猎、数字取证、事件响应、渗透测试、代码安全审计、威胁情报、恶意软件分析等26个安全领域。映射MITRE ATT&CK v19.1、NIST CSF 2.0等五大框架。当用户说'安全分析'、'威胁狩猎'、'威胁情报'、'渗透测试'、'事件响应'、'MITRE'、'数字取证'、'恶意软件分析'、'红队'、'蓝队'、'SOC'、'网络攻防'时触发。与security-audit互补:security-audit聚焦代码层静态扫描,本Skill覆盖全栈安全分析工作流。
-
gaoqiongxie Skill Codebase Inventory Audit代码库清单审计:自动盘点项目代码结构,识别孤儿代码、重复逻辑、文档缺口和技术债务。当用户说'代码库审计'、'项目盘点'、'代码清理'、'技术债务'、'孤儿代码'、'重复代码'、'代码结构分析'、'项目健康度'时触发。核心特点:结构可视化、健康度评分、债务量化、清理优先级。
-
lza6 Bundle Ln 512 Tech Debt CleanerAuto-fixes low-risk tech debt (unused imports, dead code, commented-out code) with >=90% confidence. Use when audit findings need safe automated cleanup.
-
lza6 Bundle Openclaw Security Suite针对 OpenClaw 技能的综合安全套件。包括静态扫描(AST + 关键字)和人工智能驱动的语义行为审查以检测恶意代码。
-
seikaikyo Skill Architecture Audit架構文件稽核。比對 CLAUDE.md 記錄與實際程式碼結構,找出差異並建議更新。大型 refactor 完成後或 OpenSpec 歸檔時手動執行。
-
seikaikyo Bundle Cloudflare Security AuditSecurity audit of a codebase — web apps, APIs, services, CLI tools, libraries, daemons, and more. Use when asked to find security bugs, do a security review, audit for vulnerabilities, or pen-test the code. Focuses on exploitable issues with real impact, not theoretical concerns or industry-standard behavior.
-
seikaikyo Skill CommitALWAYS use this skill when committing code changes — never commit directly without it. Creates commits following Sentry conventions with proper conventional commit format and issue references. Trigger on any commit, git commit, save changes, or commit message task.
-
seikaikyo Bundle Golang SwaggerGolang OpenAPI/Swagger documentation with swaggo/swag — annotation comments (@Summary, @Param, @Success, @Router, @Security), swag init code generation, framework integrations (gin, echo, fiber, chi, net/http), security definitions (Bearer/JWT, OAuth2, API key), and struct tags (swaggertype, enums, example, swaggerignore). Apply when adding or maintaining Swagger/OpenAPI docs in a Go project, or when the codebase imports github.com/swaggo/swag, github.com/swaggo/gin-swagger, github.com/swaggo/echo-swagger, github.com/swaggo/http-swagger, or github.com/swaggo/files.
-
seikaikyo Skill Pr WriterALWAYS use this skill when creating or updating pull requests — never create or edit a PR directly without it. Follows Sentry conventions for PR titles, descriptions, and issue references. Trigger on any create PR, open PR, submit PR, make PR, update PR title, update PR description, edit PR, push and create PR, prepare changes for review task, or request for a PR writer.
-
seikaikyo Bundle Iterate PrIterate on a PR until CI passes. Use when you need to fix CI failures, address review feedback, or continuously push fixes until all checks are green. Automates the feedback-fix-push-wait cycle.
-
seikaikyo Skill Create BranchCreate a git branch following Sentry naming conventions. Use when asked to "create a branch", "new branch", "start a branch", "make a branch", "switch to a new branch", or when starting new work on the default branch.
-
seikaikyo Skill Tgd Doubt Driven DevelopmentSubjects every non-trivial decision to a fresh-context adversarial review before it stands. Use when correctness matters more than speed, when working in unfamiliar code, when stakes are high (production, security-sensitive logic, irreversible operations), or any time a confident output would be cheaper to verify now than to debug later.
-
seikaikyo Bundle Gh Review RequestsFetch unread GitHub notifications for open PRs where review is requested from a specified team or opened by a team member. Use when asked to "find PRs I need to review", "show my review requests", "what needs my review", "fetch GitHub review requests", or "check team review queue".
-
seikaikyo Skill Claude Settings AuditAnalyze a repository to generate recommended Claude Code settings.json permissions. Use when setting up a new project, auditing existing settings, or determining which read-only bash commands to allow. Detects tech stack, build tools, and monorepo structure.
-
seikaikyo Skill Typing Exclusion WorkerPython typing exclusion worker: remove assigned mypy exclusion modules in small scoped batches, fix typing issues, run validation, and produce a structured completion summary. Use when running parallel typing-debt workers or when asked to remove modules from pyproject mypy exclusion overrides.
-
seikaikyo Bundle SemgrepRuns a Semgrep security scan over a codebase: detects languages, selects rulesets, presents the plan for explicit approval, then runs every approved ruleset through scripts/run-scans.sh, which batches the semgrep processes and writes scans.json, and merges the output to SARIF. Supports two scan modes, "run all" for full ruleset coverage and "important only" for security findings at medium-to-high confidence and impact. Uses Semgrep Pro for cross-file taint analysis when it is available. Use when asked to scan code for vulnerabilities, run a security audit with Semgrep, find bugs, or perform static analysis. For the same scan without the approval gate, use the /static-analysis:semgrep-scan workflow.
-
seikaikyo Bundle Ton Vulnerability ScannerScans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks. Use when auditing FunC contracts.
-
seikaikyo Bundle Cairo Vulnerability ScannerScans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems, and signature replay. Use when auditing StarkNet projects.
-
seikaikyo Bundle Solana Vulnerability ScannerScans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. Use when auditing Solana/Anchor programs.
-
seikaikyo Bundle Algorand Vulnerability ScannerScans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal).
-
seikaikyo Skill Review PrReviews the current branch's changes against its base branch as a pull request: correctness of new and modified code, test coverage for it, and documentation accuracy. Use when asked to review a branch, a diff, or a pull request.
-
seikaikyo Bundle Semgrep Rule Variant CreatorCreates language variants of existing Semgrep rules. Use when porting a Semgrep rule to specified target languages. Takes an existing rule and target languages as input, produces independent rule+test directories for each language.
-
peterbamuhigire Bundle Accounting Finance AdvisoryUse when a proposal covers accounting, finance operations, controls, ERP or POS finance, grants, tax, audit readiness, modelling, or financial transformation. Route pure bid pricing to 10-financial-proposal; this skill governs finance doctrine and delivery credibility.
-
peterbamuhigire Skill AI On Saas Team CompositionUse when an AI-on-SaaS proposal must justify the combined AI, data, safety, evaluation, platform, security, SRE, and customer-success roles required for delivery; use the standard team skill when no AI specialist roles are needed.
-
aradotso Skill Openclaw Security Practice GuideSecurity hardening guide for high-privilege autonomous AI agents (OpenClaw) with zero-trust architecture, behavior controls, and automated auditing
-
aradotso Skill Metamask Openclaw Desktop Security AnalysisAnalyze and understand the security risks of the Metamask Openclaw desktop executable distribution
-
ingridleiria Skill Analysis AuditAnalysis Audit
-
ingridleiria Skill Vendor EvaluationEvaluates and compares vendors, tools, and service providers for a purchase, renewal, or replacement, producing weighted requirements fixed before any scoring, an evidence-backed comparison where every score names its source, total cost of ownership over the full term including internal effort and exit costs, verified security and viability checks, reference calls including one the vendor did not supply, a risk register, negotiation points with a walk-away, and a recommendation memo someone else can audit. Enforces the standard that requirements and weights are frozen before options are scored and that no score rests on a vendor-run demo alone. Use this skill whenever someone asks to compare vendors or software, evaluate a supplier proposal, decide whether to renew or switch, build a total cost comparison, prepare for a vendor negotiation, or says which tool should we buy, is this vendor any good, are we getting value from this contract, should we renew, review this before we sign.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include ax-migration-continuous-improvement-lead, ax-migration-fabric-data-product-advisor, ax-migration-knowledge-transfer-examiner. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.