Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
stijnman Skill Exposed Service TriageTriages exposed TCP listeners found by security audits. Use for: exposed port, what is listening, fix exposed service, open port.
Audited -
stijnman Bundle Drive Github Skill AuditCompare Google Drive skill definitions with a GitHub skills repository and identify Drive skills not yet published. Use for: audit Drive skills, compare Drive and GitHub SKILL.md files, find unpublished skills, skill-library inventory.
Audited -
stijnman Skill Skill Collection BootstrapperAudit a skills repository, identify coverage gaps, validate SKILL.md files, and prepare an approval-gated installation plan. Use for: bootstrap skills, complete skill collection, install skill repository, validate skill library.
Audited -
kinginyellows Skill Gt AmendFold working-tree changes into the current branch commit, audit them, and re-submit via Graphite. Use when user says "amend this", "add this to the current PR", "fold this fix in", or has follow-up edits for an already-submitted branch. Not for starting new work — use the smart-submit skill instead.
-
kinginyellows Skill Audit ReviewRun 1-3 parallel quick-audit passes (code quality, security, error handling) over a diff and gate on findings. Use when smart-submit or gt-amend need to audit uncommitted changes before committing.
-
kinginyellows Skill Smart SubmitStage, audit, commit, and submit uncommitted changes via Graphite, with parallel code-review agents. Use when user says "submit this", "ship it", or "commit and push", or has uncommitted work to turn into a PR. Requires uncommitted changes — a clean, already-committed branch needs only gt submit; amending an already-submitted branch is the gt-amend skill.
-
kinginyellows Skill CI ConventionsShared CI conventions reference (not an executable action) — validation rules, failure patterns (F01-F12), error catalog, and security patterns. Consult when agents or commands need CI-specific validation or pattern-matching reference.
-
kinginyellows Skill Docs ConventionsShared documentation conventions — templates, diagram type selection, staleness detection, severity classification. Use when agents need doc generation or audit context.
-
kinginyellows Bundle Compound LifecycleAudit, refresh, and consolidate `docs/solutions/` to keep the institutional knowledge catalog from rotting. Use when a `docs/solutions/` sweep is needed or after `knowledge-compounder` flags an older entry as superseded.
-
bbrysonelite-max Bundle BlueprintUse when defining the golden lead and money-in-hand buyer for a vertical BEFORE any scraping or enrichment is built — stage #1 of The Refinery. Runs a demand-first, recursive who/what/when/where/why/how inquiry (research + operator confirmation) and emits a Golden Lead Definition grounded in a confirmed paying buyer, plus an audit-trail inquiry tree. Trigger on "define the golden lead", "who would pay for this lead", "blueprint a lead for {industry}".
-
bbrysonelite-max Bundle Failure ModesA comprehensive, grounded method (FMEA + pre-mortem + red-team) that sweeps every failure surface of a target — software, module, process, or workflow — names every way it can fail from the micro level to the macro level, then INVERTS each failure into the specific designed strength that cancels it. Exhaustive by design; produces concrete security/UI/UX/reliability improvements as output. Distinct from blind-spots-audit (which finds unknown-unknowns) — this is the systematic sweep of mostly-known surfaces. Use when Brent says "failure modes", "how can/would this fail", "how do I fail", "FMEA", "pre-mortem", "fortify/harden this", "stress every surface", "where is this weak", "make it bulletproof", or before shipping / when designing for robustness.
-
bbrysonelite-max Bundle Skills LibrarianMaintain Brent's INSTALLED skill library — audit ~/.codex/skills for integrity (name↔folder mismatches, missing SKILL.md, stray files, dead symlinks, inactive-profile leaks), reconcile it against the Git-backed codex-skills/SKILLS-INDEX.md (what's new vs stale), and regenerate that index preserving his categories. Read-only audit by default; fixes are per-item approved; it QUARANTINES cruft to the dump, never deletes. The maintenance complement to skill-miner (miner finds new skills; librarian keeps the shelf clean). Use when Brent says "skills librarian", "clean up my skills", "skills are a mess", "dedupe my skills", "update the skills index", "what skills do I have", or after building/installing skills.
-
bbrysonelite-max Bundle Assumptions AuditUse when a proposal, plan, or design needs its assumptions challenged against available evidence before implementation begins.
-
bbrysonelite-max Bundle AI Evaluation AuditUse when an implemented AI feature needs its planned evaluation dimensions, guardrails, and evaluation infrastructure checked before deployment.
-
bbrysonelite-max Bundle Production Gate AuditUse when auditing a project for production readiness, preparing a repo for solo-founder AI-assisted development, adding CI/branch-protection enforcement, verifying Stripe/webhook safety, tenant isolation, connector validation, or deciding which tests are missing or weak. Builds ONE clean production gate covering 10 unique risks — no duplicate coverage, no cosmetic tests. Audit and enforcement only, not a feature-building skill.
-
bbrysonelite-max Bundle Requirements Coverage AuditUse when requirements or acceptance criteria need traceability to tests and executable proof before work is declared complete.
-
farmage Bundle Wordpress ProDevelops custom WordPress themes and plugins, creates and registers Gutenberg blocks and block patterns, configures WooCommerce stores, implements WordPress REST API endpoints, applies security hardening (nonces, sanitization, escaping, capability checks), and optimizes performance through caching and query tuning. Use when building WordPress themes, writing plugins, customizing Gutenberg blocks, extending WooCommerce, working with ACF, using the WordPress REST API, applying hooks and filters, or improving WordPress performance and security.
-
wsxwj123 Bundle CheckInvoke after any implementation task completes or before merging. Reviews the diff, auto-fixes safe issues, runs specialist security and architecture reviewers on large diffs. Also handles issue/PR triage when the user mentions issues, PRs, or batch review. Not for exploring ideas or debugging.
-
copyleftdev Skill UunetEngineer at global scale in the style of UUNET (now Verizon Business). Emphasizes massive infrastructure resilience, "plumbing" the internet, pragmatic problem solving, and the evolution from moving bits to securing them (DBIR). Use when designing backbone networks, security operations centers, or large-scale distributed systems.
-
copyleftdev Skill Forensics TeamAnalyze network traffic and security incidents with the depth of an "Ultimate Forensics Team". Emphasizes deep packet analysis (PCAP) as the source of truth, OSI layer decomposition, and the use of native Linux tools to uncover temporal patterns, attack types, and attribution.
-
copyleftdev Bundle Roth Detection EngineeringApply Florian Roth's detection engineering methodology with YARA and Sigma rules. Emphasizes portable detection logic, community sharing, and signature quality. Use when creating detection rules that work across platforms.
-
copyleftdev Bundle Lampson System DesignDesign systems using Butler Lampson's principles of abstraction, interfaces, and practical wisdom. Emphasizes clean abstractions, security foundations, and time-tested design hints. Use when making architectural decisions, designing APIs, or building systems that must evolve over decades.
-
copyleftdev Bundle Rodriguez Threat Hunter PlaybookApply Roberto Rodriguez's threat hunting methodology with the Threat Hunter Playbook and HELK. Emphasizes documented hunts, open source infrastructure, and data-driven hunting. Use when building hunting programs or developing hunt playbooks.
-
copyleftdev Bundle Mitre Attack FrameworkApply the MITRE ATT&CK framework for threat intelligence and detection. Provides a universal taxonomy of adversary tactics, techniques, and procedures (TTPs). Use when mapping threats, building detections, or assessing defensive coverage.
-
apidojo-io Skill Building Full Social Audit For BrandBuilds a comprehensive social media audit for a brand across all major platforms using apidojo's multi-platform scrapers. Triggers when the user asks to: do a social media audit for a brand, build a full social media presence report, analyze a brand's performance across all social platforms, create a cross-platform social media benchmark, audit a competitor's entire social media strategy, build a social media scorecard for a brand, or create a comprehensive social media analysis covering Twitter Instagram TikTok and YouTube. Returns per-platform metrics, follower counts, engagement rates, content mix, posting frequency, and overall brand health score. Ideal for social media managers, brand strategists, and agency teams doing comprehensive brand audits.
Audited -
apidojo-io Skill Analyzing Competitor Twitter Profile ContentExtracts and analyzes tweet history from competitor or brand Twitter profiles using apidojo's Twitter Profile Scraper on Apify. Triggers when the user asks to: get all tweets from a competitor's Twitter account, analyze what a company posts on Twitter, audit a brand's tweet history, track what topics a competitor covers on X, compare Twitter content strategy between brands, extract posts from a company's Twitter timeline, or monitor a competitor's messaging and announcements on Twitter. Returns tweet text, engagement metrics (likes, retweets, replies, views), and author data. Ideal for competitive intelligence teams, PR analysts, and brand strategists.
Audited -
bokuwalily Skill Pre Completion Self Audit何かを実装・実行・配線した後、「完了」と言う前に必ず実行する敵対的セルフ監査。予測できる不具合(並行/失敗時/冪等/境界/セキュリティ)を自分で洗い出して潰し、監査表で先回り報告する。ユーザーに「漏れ全部潰してる?」と聞かせない。
-
bokuwalily Skill Claude Plugin Context Auditセッション開始が重い/応答が直近指示を取りこぼす/context bloatが疑われるとき、SessionStartで注入される全ソース(プラグイン・rules/ecc・obsidian文脈・auto-memory・remember)のトークン内訳を測定して刈り込み候補を特定したいとき
-
bokuwalily Skill Memory Md Inject Bloat Auditinject_bytes が cc-self-audit 閾値(40KB)の75%超を超えた時に MEMORY.md が支配的な原因であることを診断し、不要エントリを刈り込む手順。2026-08-05に inject_bytes=34.9KB(87%閾値)・MEMORY.md=26KB(70%占率)を検出したパターンの再利用版。
Audited -
bokuwalily Skill Git Prepush Secret Remote Checkgit pushやパブリック公開の直前に実行する。リモートURLが自分のリポジトリを指しているか確認し、ステージ・差分内のAPIキー/トークン/PII漏洩をスキャンする。複数セッションで「サードパーティforkへのwrong-remote」と「PII流出」が実際に発生したことへの対策。
-
bokuwalily Skill IOS Permission Key Security MatrixiOSアプリのproject.yml / Info.plistの差分をセキュリティレビューするとき、各 NSXxx キーが「追加専用」か「フル読み書き」かを判定する。XcodeGen project.yml の変更レビュー時に発火する。
Audited -
bokuwalily Skill Xcodegen Project Yml Security ReviewiOS XcodeGen の project.yml diff をセキュリティレビューするとき。変更がビルド番号・Info.plist キー・権限文字列などに限定される場合の判定フロー。
-
kinginyellows Bundle Semgrep ConventionsShared conventions for Semgrep integration — triage state mappings, API patterns, fix strategy decision tree, rate limits, and security rules. Use when commands or agents need Semgrep-specific validation, error handling, or API reference.
-
kinginyellows Bundle Ce Compound RefreshRefresh stale learning docs and pattern docs under docs/solutions/ by reviewing them against the current codebase, then updating, consolidating, replacing, or deleting the drifted ones. Trigger this skill when the user asks to refresh, audit, sweep, clean up, or consolidate stale docs in docs/solutions/ (phrases like "refresh my learnings", "audit docs/solutions/", "clean up stale learnings", "consolidate overlapping docs", "compound refresh", "/ce-compound-refresh"), or when ce-compound has just captured a new learning and flagged a specific older doc in docs/solutions/ as now inaccurate or superseded — invoke with the narrow scope hint ce-compound provides. Also trigger when the user points at a specific learning or pattern doc under docs/solutions/ and calls it stale, outdated, overlapping, or drifted. Do not trigger for general refactor, migration, debugging, or code-review work unless the user has explicitly directed attention to docs/solutions/ itself.
-
hamza-ali-shahjahan Skill Go LiveGuided, stateful provisioning of a product's production stack — deep-links, key-format validation, a secrets backend (fnox recommended, or user-touched .env.local), a resumable ledger, CLI automation after signup, and a blocking A1–A10 live gate. Hands off to /security-check → /ship. The walked version of SETUP.md.
-
hamza-ali-shahjahan Skill Factory LaunchLaunch the factory's control plane — scaffold and fill FACTORY-ORDERS (weekly mandate + hard budget), STANDING-ORDERS (autonomous-program authority), HEARTBEAT (weekly pulse), and write lifecycle gates for every registered product. A deliberate one-time ritual (re-run to audit); invoke as /factory-launch, not auto-triggered.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include wordpress-pro, exposed-service-triage, drive-github-skill-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.