Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
peterbamuhigire Bundle Audit Pbc And Evidence Management---
-
peterbamuhigire Bundle Month End And Year End Close PlaybookControlled month-end and year-end close workflow for any Chwezi-grade finance / accounting system. Covers task list, dependencies, evidence requirements, exception handling, reviewer sign-off, period-state transitions, retained-earnings close, lock and reopen governance, and release states. Use whenever a software system, SRS, SDS, test plan, proposal, or business plan touches month-end close, year-end close, period locking, or audit-period release.
-
peterbamuhigire Bundle Published Ifrs Financial Statement AnalysisUse when analysing published IFRS financial statements, annual reports and notes to evaluate financial health, performance, cash generation, liquidity, leverage, valuation, accounting risk, disclosure quality, and implications for management, audit committees, investors or regulators.
-
peterbamuhigire Bundle Business Continuity And Disaster Recovery Finance---
-
yuping322 Bundle Portfolio Health CheckDiagnose risks and inefficiencies in an existing investment portfolio. Use when the user asks to review, audit, or stress-test their current holdings, evaluate portfolio concentration, check factor exposures, assess correlation risks, identify hidden tilts, or get actionable improvement suggestions for a portfolio they already own.
-
cratis Bundle Cratis Code ReviewReview changed code in a Cratis application against the architecture, style, and specification-coverage criteria that the compiler cannot check, and produce a structured report with blocking issues separated from suggestions. Use when asked to review, check, or validate a change. Do not substitute it for a focused security audit and do not restate specialist performance findings.
-
cratis Skill Review SecurityUse this skill when asked to perform a security review or security audit of code in a Cratis-based project. Checks for injection, auth/authz, data exposure, secrets, and event-sourcing-specific vulnerabilities.
-
cratis Skill Cross Cutting PropertiesAttach audit/correlation metadata to every appended Cratis event without polluting event types — via ICanProvideAdditionalEventInformation, plus event tags and the built-in EventContext fields. Use for correlation IDs, tenant/actor context, and other cross-cutting concerns that should travel with events but are not domain payload.
-
jcorpac Skill Sec Threat ModelingGuide users through threat-modeling exercises (like STRIDE) during the design phase to identify and mitigate A06:2025 Insecure Design vulnerabilities before code is written.
-
jcorpac Bundle Flask Auth SecurityImplementing professional session-based and token-based authentication.
-
jcorpac Skill Sec Zap Dast IntegrationAssistance with setting up, running, and parsing results from OWASP ZAP (Zed Attack Proxy) for Dynamic Application Security Testing to discover runtime vulnerabilities like misconfigurations and injection flaws.
-
the-utopia-studio Bundle AdaRun technical due diligence as Ada — The Utopia Studio's DD analyst. Use when the user asks to 'run DD', 'review this startup', 'audit this repo', 'check this portco', mentions a technical due diligence report, asks 'is this technically sound?', or says 'run DD on [company]'. Ada is skeptical, evidence-driven, and never accepts founder claims at face value. She composes repo-scanner, security-auditor, devops-advisor, cost-optimizer, integration-linker, and technical-dd into a structured 5-phase audit and produces a branded TDD .docx report with P0-P3 risk severities. Distinct voice from generic Claude — leads with the verdict, quantifies risk, calls out unknowns explicitly.
-
the-utopia-studio Bundle HallmarkAnti-AI-slop design skill for greenfield pages, audits, redesigns, and design extraction from URLs or screenshots. Use when the user asks to build a new app or landing page, wants to redesign something, invokes Hallmark by name, or uses audit/redesign/study.
-
the-utopia-studio Skill Repo ScannerScans a GitHub repository to understand its tech stack, hosting, monitoring, integrations, and current production readiness. Use when the user asks to "audit", "check", or "scan" their repo. Don't use for code review or bug detection.
-
the-utopia-studio Skill Security AuditorAudits repository security — hardcoded secrets, dependency vulnerabilities, environment variable management, and authentication patterns. Use when the user asks to "check security", "find secrets", "audit dependencies", or "secure my repo". Don't use for code review, deployment, or monitoring.
-
manusco Bundle Resonance Strategy CouncilDecision council for challenging a completed analysis, recommendation, or plan, and for reviewing a consequential choice at a high-risk checkpoint. Selects relevant specialist subagents, gathers blind opening positions, runs one rebuttal round and scenario tests, then reconciles evidence into an advisory decision memo. Use when the user asks for a council, expert panel, multidisciplinary challenge, blind-spot review, or high-stakes deliberation. Does not replace /brief, /grill, /plan, /audit, or /second-opinion.
-
manusco Bundle Resonance Ops System HealthSystem health assessor. Produces a repeatable whole-system health baseline and trend score across stability, test health, security posture, maintainability, and operational readiness. Use for periodic health checks or release readiness trends. Use Audit for finding-level review of a branch, change set, or concrete codebase scope.
-
manusco Bundle Resonance Engineering BackendBackend Engineer Specialist. Implements business logic, API endpoints, and data flows with strict type safety, layered architecture, and explicit error handling. Use when building or modifying API endpoints, writing business logic services, integrating third-party APIs, designing data flows, or performing a shadow path audit on an existing service.
-
manusco Bundle Resonance Sales Account IntelligenceIdentifies which accounts deserve attention now, why, and what action to take next. Covers signal detection, account scoring, brief generation, and customer-facing deck construction. Use when asked to prioritize accounts, build account briefs, prepare customer decks, or audit account expansion potential.
-
gongyijie85 Skill Repo ScanBootstrap pointer that installs the external repo-scan skill from a pinned, reviewable commit. Use when repo-scan must be installed before running its cross-stack source-code asset audit; this ECC pointer does not perform the audit itself.
-
gongyijie85 Skill Delivery GateStop hook that blocks Claude from finishing until quality checks pass. Detects rationalization patterns (surface text heuristics), stale learning logs (filesystem mtime), and low disk space. Complements self-audit by mechanically enforcing learning capture habits. Use when Claude should be mechanically blocked from declaring work finished before quality checks and learning capture actually pass.
-
gongyijie85 Skill Quarkus VerificationVerification loop for Quarkus projects: build, static analysis, tests with coverage, security scans, native compilation, and diff review before release or PR.
-
kody-w Bundle Ecosystem AuditAudit a GitHub owner's whole ecosystem and prove or disprove the invariants its own docs assert: repo inventory and family shape, commit velocity in a window, star traction, declared-core-versus-actual-effort mismatch, and a mirror drift audit that catches silently diverged canonical documents. Use when asked to audit, map, heal, or health-check a multi-repo ecosystem, to check whether a spec's mirrors still agree, or when a canonical doc may have drifted from the authority file it renders.
-
kody-w Bundle Transcript MinerMine Claude Code session history for usage patterns, mistakes, and automation candidates. Use when Kody says "audit my sessions", "what am I doing wrong in Claude Code", "usage audit", "mine my transcripts", "analyze my Claude Code history", "what should be a skill", or asks how he's using Claude Code across past sessions. Extracts tool stats, error signatures, Read:Edit ratios, my-message categories (corrections/rejections), and permission denials from ~/.claude/projects JSONL — with evidence, never vibes.
-
broomva Skill Drift CheckCompares stated priorities against where time and effort actually went, and produces a strategy drift report. Uses git log, vault priorities, and project docs to detect misalignment. Use when the user says "drift check", "am I on track", "priority alignment", "where did my time go", "strategy drift", or wants to audit focus vs intention.
Audited -
broomva Bundle Attempt AuditFind absence-assertions that carry no attempt-record — code that returns the same empty value whether the work RAN and found nothing or was SKIPPED entirely, so the caller cannot tell the two apart. Detects the concrete syntactic shape: a boolean parameter gates real work, and the function falls through to an empty sentinel that records nothing. Zero config, one command, plain-language findings; reports what it could not parse rather than letting a clean run and an empty run look identical. USE WHEN a check "passed" and you are not sure it ran, a manifest reports "no results / no findings / no speech", a gate went green after a rename, a test suite is suspiciously fast, or before trusting any tool that emits a negative verdict. NOT FOR general linting, dead code, or type errors — it answers exactly one question.
-
broomva Bundle Legal ReadinessBuild or adversarially audit an evidence-first legal-readiness system for a software product, SaaS, AI app, API, marketplace, or website. Inventory every public and contractual claim; determine jurisdiction, operator, customer, data-role, payment-channel, and product-behavior applicability; compare prose with repository, live, vendor, registry, contract, and operational evidence; close authorized code/documentation gaps; and leave counsel, tax, filing, entity, and external-account blockers explicit. Use when asked for a legal audit, legal shield, SaaS legal baseline, terms/privacy/consent/payment review, compliance gap analysis, legal readiness, legal standing setup, product-claim substantiation, or to make an app legally safer before launch. NOT FOR giving legal advice, declaring a product compliant or legally secure, forming an entity, filing registrations or taxes, signing contracts, inventing operator facts, or replacing licensed counsel.
-
broomva Bundle Prove The NegativeVerify a claim whose evidence is an ABSENCE — blocked, denied, unreachable, isolated, not-logged, no-longer-present. Enforces that every denial is paired with a positive control that must SUCCEED, because "everything is denied" and "nothing ran at all" are the same observation. Ships a verdict gate that returns INVALID (exit 2) rather than PASS when the controls did not fire. USE WHEN validating a security boundary or sandbox, writing an eval whose passes are denials, confirming a capability was removed, checking that data is unreachable, or concluding from a probe that returned nothing. NOT FOR claims whose evidence is a presence (an output, a value, a rendered page) — those fail loudly on their own and need no control.
-
yknothing Bundle Pc Code ReviewUse when a concrete code change is ready for review and the reviewer must evaluate correctness, security, maintainability, test adequacy, contract alignment, and brownfield safety before merge, especially when unsupported flows, backward compatibility, or release-boundary constraints must be enforced.
-
yknothing Bundle Pc Security AuditUse when a reviewed change, release candidate, or high-risk slice must be challenged for abuse paths, trust-boundary failures, secret handling, dependency risk, or data exposure before release.
-
yknothing Bundle Pc Risk AssessmentUse when planned work must be challenged for delivery, dependency, migration, security, or operational risk before the team commits to scope or sequence.
-
yknothing Bundle Pc Security DesignUse when the architecture is defined and the team must turn trust boundaries, sensitive data paths, and attacker assumptions into concrete control design before implementation and audit.
-
yknothing Bundle Pc Implementation Integrity AuditUse after code changes when the reviewer must aggressively audit low-level defects, deceptive implementations, improper mocks, fake evidence, and test shortcuts before a delivery claim is trusted.
-
yknothing Skill Code ReviewUse when a concrete code change is ready for review and the reviewer must evaluate correctness, security, maintainability, test adequacy, contract alignment, and brownfield safety before merge, especially when unsupported flows, backward compatibility, or release-boundary constraints must be enforced.
-
yknothing Skill Security DesignUse when the architecture is defined and the team must turn trust boundaries, sensitive data paths, and attacker assumptions into concrete control design before implementation and audit.
-
frankxai Skill V3 Security OverhaulComplete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include sec-threat-modeling, flask-auth-security, sec-zap-dast-integration. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.