Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ingridleiria Skill AI Adoption ProgramRuns the adoption of AI inside an organisation as a sequenced programme rather than a scatter of tool purchases. Produces a capability audit of where the work and the time actually sit, a shortlist of two or three pilots each with a baseline measured before anything starts and a stop threshold agreed in advance, a one-page usage policy naming the data categories and the decisions that must stay human, a procurement test run against real tasks with known answers, a fluency programme measured by task rather than by licences, and a quarterly report that carries the failures as prominently as the wins. Use this skill when someone asks which AI tools to buy, wants an AI policy or an acceptable use rule, has been asked by a board or an investor what the AI strategy is, is evaluating an AI vendor, wants to know why last year's tool purchase changed nothing, says the team is already using these tools and nobody knows what data is going into them, or asks how to measure whether any of this is working.
-
ingridleiria Skill Qualitative Coding And AnalysisTurns interviews, open-text responses, documents or field notes into analysis that survives scrutiny, by making every step from transcript to claim visible. Enforces a stated approach and level of interpretation, a codebook with definitions and inclusion and exclusion rules and an anchor example, coding of the whole corpus rather than the interesting parts, double coding with an agreement statistic that accounts for chance where prevalence claims are made, themes built from codes and tested against negative cases, quotations selected by a stated rule with no participant carrying an argument alone, prevalence language matched to what the data supports, and an audit trail running from any sentence in the paper back to a coded extract. Use this skill for interview analysis, thematic analysis, framework analysis, coding open-ended survey responses, content or document analysis, the qualitative strand of a mixed methods study, or when a qualitative section has been called impressionistic, anecdotal or cherry-picke
-
imtiazrayhan Skill Skill AuditorAudit an installed set of Claude Code skills for the failure modes that make them misfire — overlapping descriptions that misroute tasks, trigger phrasing that never matches, bloated bodies, missing boundaries, and over-broad tool grants — and return a prioritized fix list with rewritten descriptions. Use when a skill fires on the wrong tasks, never fires at all, or a skills folder has grown past what anyone reviews.
-
mr-q526 Bundle Security Vulnerability CheckUse when working on application security vulnerability checks for web apps, APIs, auth, data access, and secrets. Focus on exploitable flaws, secure defaults, input validation, and sensitive data exposure.
-
mr-q526 Bundle Dependency Supply Chain AuditUse when working on dependency review, vulnerable packages, lockfile risk, license concerns, and supply-chain hygiene. Focus on known CVEs, typosquatting risk, lockfile integrity, and update safety.
-
mr-q526 Bundle Enterprise Security Page BasicUse when designing security, compliance, trust center, SOC2, privacy, and enterprise assurance pages. Basic version focused on credibility, evidence, policy clarity, and buyer confidence; emphasizes fast layout, obvious labels, a minimal section set, and a short checklist.
-
drvoss Skill Security ScanUse when you want a quick security pass on code changes or dependencies — checks OWASP Top 10 patterns, runs dependency audits, and surfaces critical vulnerabilities with targeted fixes.
-
drvoss Skill Code ReviewUse when reviewing code changes for quality, correctness, and security — runs a structured checklist with severity-rated findings
-
drvoss Skill Security AuditUse when a codebase needs a formal security audit beyond a quick scan — applies OWASP Top 10 and STRIDE threat modeling from a CSO perspective to surface systemic vulnerabilities.
-
drvoss Skill Secret DetectionUse when you suspect API keys, tokens, or passwords are hardcoded in source code or committed to git history — scans and guides safe removal without breaking existing integrations.
-
drvoss Skill Pr Security ReviewUse when reviewing a pull request for security issues — automatically analyzes the diff for vulnerabilities, hardcoded secrets, injection risks, and broken access control before merging
-
drvoss Skill Gha Security ReviewUse when reviewing GitHub Actions workflows for exploitable vulnerabilities — finds pwn-request patterns, expression injection, credential escalation, config poisoning, and supply chain risks, and reports only HIGH and MEDIUM confidence findings with concrete attack paths.
-
drvoss Skill Pr Multi Perspective ReviewReview a pull request from 6 perspectives (PM, Dev, QA, Security, DevOps, UX) for comprehensive, bias-free feedback
-
manusco Skill Audit<!-- Generated by Resonance Forge. -->
-
manusco Bundle Resonance Ops CoreResonance project kernel. Initializes the public project scaffold, loads project context, and maintains project-owned state and memory inside an adopter's repository. Use for `/init`, orientation, or explicit project-state persistence. It is not the general request router, delivery conductor, audit coordinator, or owner of domain work.
-
manusco Bundle Resonance Ops GoalThe autonomous goal loop. Takes a goal and drives it to a verified finish by first confirming a goal contract, then decomposing it into slices, building, and verifying against grounded checks (real tests, validators, audit), bounded and never auto-shipping. Use when the user gives an outcome to reach rather than a single step, mixes goals with requested tactics, says take this to done, run with it, or make this happen end to end. Manual-only (drives builds, tests, and real side effects).
-
manusco Bundle Resonance Ops AuditAudit conductor for a branch, change set, or codebase. Owns audit scope, earned specialist dispatch, severity normalization, reconciliation, and final disposition. Use for a multi-domain audit before merge or release. Security, Reviewer, QA, Architect, Backend, Performance, and Product own their domain findings. Use a specialist directly for a single-domain question.
-
manusco Bundle Resonance Ops LegalLegal and compliance specialist with a GDPR and DACH (Germany, Austria, Switzerland) lens. Use when writing a privacy policy or terms of service, reviewing a contract or a specific risky clause, handling GDPR or data processing questions (lawful basis, DSAR, controller vs processor, DPA), preparing for a compliance audit such as SOC2, or navigating IP and licensing. Drafts and reviews documents and explains the rules in plain language. It is NOT a substitute for a qualified lawyer; escalate high-risk or binding decisions to licensed counsel.
-
manusco Skill Page Audit<!-- Generated by Resonance Forge. -->
-
manusco Bundle Resonance Ops ReviewerGeneral code-review gatekeeper. Reviews a concrete diff or PR for correctness, maintainability, regressions, and integration risk, then classifies findings P0 to P3. Use for the whole change. Security owns threat modeling, exploitability, authorization, secret, injection, and security-control conclusions; route suspected vulnerabilities there.
-
manusco Bundle Resonance Ops SecuritySecurity Auditor Specialist. Owns threat models and security findings for authorization, secrets, injection, trust boundaries, infrastructure controls, and AI abuse paths. Use when the question is whether a system or change is exploitable or adequately defended. Reviewer owns the general correctness and maintainability gate for the full diff.
-
manusco Bundle Resonance Sales Lead OpsAudits lead lifecycle quality, resolves ownership, maps the customer experience from form fill to follow-up, and generates daily watchlists. Use when asked to audit lead handling, find missed follow-ups, resolve lead owners, map inbound CX, or build a daily lead operating view.
-
peterbamuhigire Skill Saas Trust And Compliance Credentials SectionUse when a SaaS proposal needs an evidence-qualified trust and compliance section covering security, privacy, certifications, sub-processors, continuity, audit posture, insurance, and exit; use the procurement skill to manage questionnaire and negotiation workflow.
-
vellum-ai Bundle Geo AuditRuns a one-command technical GEO audit on any domain. Checks AI crawler access, llms.txt presence, server-side rendering, sitemap, and schema markup. Streams results live and ends with a 0–100 score plus the top 3 prioritized fixes. Built to be both genuinely useful and great to demo on camera.
-
vellum-ai Skill Vellum Change ReviewReview Vellum Assistant code changes for correctness, repo-specific quality rules, security risks, and missing validation. Use when reviewing diffs, preparing a PR, finishing implementation work, or when the user asks for a code review, quality pass, or pre-merge check in this repository.
-
pa4uslf Skill Landing PublishUse when the user wants to publish a landing page draft to WordPress as a page, typically after it has passed the landing audit.
-
openai Bundle Vercel FirewallVercel Firewall expert guidance — automatic DDoS mitigation, the Vercel WAF (custom rules, IP blocking, managed rulesets, rate limiting), Attack Mode, system bypass, bot management, and the `vercel firewall` CLI. Use when configuring platform-level security, responding to attacks, or staging firewall rules.
23.3k -
openai Bundle Stripe Best PracticesGuides Stripe integration decisions across API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, tax and registrations (Stripe Tax, automatic_tax, product tax codes), Treasury financial accounts, integration options (Checkout, Payment Element), migrating from deprecated Stripe APIs, and security best practices (API key management, restricted keys, webhooks, OAuth). Use when building, modifying, or reviewing any Stripe integration, including accepting payments, building marketplaces, integrating Stripe, processing payments, setting up subscriptions, collecting sales tax, VAT, or GST, creating connected accounts, or implementing secure key handling.
23.3k -
lucadominguez Skill Content Quality AuditContent Quality Audit
-
lucadominguez Skill Security And HardeningSecurity and Hardening
-
peterbamuhigire Bundle Finance UI Pattern LibraryProduction UI patterns, design tokens, role-conditioned shells, drilldown primitives, reconciliation triage layout, print stylesheet patterns, status taxonomy components, and money-cell components for Chwezi finance and accounting products. Use when designing or building any finance / accounting screen, dashboard, report, print layout, mobile cashier flow, accountant ledger surface, reconciliation UI, close board, return-pack viewer, or audit-ready export across any consumer engine. Auto-load when the user requests UI / UX work that touches money, inventory, payroll, tax, banking, mobile money, POS, statutory compliance, or accounting records.
-
peterbamuhigire Bundle Finance Module AuditUse when auditing any software, SRS, proposal, POS, ERP, SaaS, mobile app, or workflow that touches money, billing, payments, tax, payroll, banking, mobile money, inventory, statutory compliance, financial reports, or accounting records.
Audited -
peterbamuhigire Bundle Internal Controls LibraryLibrary of internal controls embedded in finance / accounting workflows. Segregation of duties, maker-checker, approval thresholds, supplier and payroll master-data controls, petty cash and cash drawer controls, inventory master-data controls, tax / rate table controls, audit-log review, exception monitoring, fraud / error indicators. Use whenever designing or reviewing access control, approval, audit trail, fraud detection, or internal-control attestation in a finance / accounting context.
-
peterbamuhigire Bundle Audit Ready Reporting PackThe audit-ready reporting pack standard for any Chwezi-grade entity. Defines the minimum reports, their content, the drilldown chain, the auditor-export index, the print fidelity, the sign-off, and the release governance. Use whenever a software system, SRS, SDS, test plan, proposal, or business plan involves financial statement preparation, monthly management accounts, donor reports, statutory reports, audit-ready exports, or external audit support.
-
peterbamuhigire Bundle Finance Cybersecurity Controls---
-
peterbamuhigire Bundle Finance Data Privacy And Retention---
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include vercel-firewall, landing-publish, ai-adoption-program. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.