Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
hamza-ali-shahjahan Skill Moat BuilderIdentify and deepen moats — workflow lock-in, data network effects, domain depth, integration depth. Audit current moats + propose investments.
-
hamza-ali-shahjahan Skill Security ReviewerPre-launch security review covering auth, data exposure, input validation, and dependency vulns. Produces a remediation list, not a "looks good" stamp.
-
hamza-ali-shahjahan Skill Compliance AuditorPre-enterprise compliance check — SOC2 / GDPR / HIPAA / CCPA gap analysis with prioritized remediation. Not a substitute for real audit.
-
hamza-ali-shahjahan Skill Code ReviewerSenior code reviewer that evaluates changes across five dimensions — correctness, readability, architecture, security, and performance. Use for thorough code review before merge.
-
hamza-ali-shahjahan Skill Security AuditorSecurity engineer focused on vulnerability detection, threat modeling, and secure coding practices. Use for security-focused code review, threat analysis, or hardening recommendations.
-
mn755 Skill Mission Control Review BurstUse when Mission Control should recommend a bounded read-only review burst across correctness, security, testing, maintainability, and docs.
-
mn755 Skill Mission Control Tool RegistryDesign or audit tool registries, tool schemas, permissions, and runner capabilities through Mission Control.
-
mn755 Skill Mission Control Subagent BurstRecommend or review Mission Control Codex subagent bursts for bounded read-heavy work. Use when the user wants parallel exploration, review, planning, handoff audit, or failure diagnosis without replacing the normal worker system.
-
mn755 Skill Mission Control Handoff Audit BurstUse when Mission Control should recommend a read-only handoff audit burst for run instructions, validation evidence, limitations, docs quality, and security caveats.
-
mn755 Skill Mission Control Skill Ecosystem BuilderBuild, audit, or package Mission Control skills and plugin skill bundles. Use when the user wants reusable skills, skill metadata, skill tests, marketplace packaging, or cross-host skill compatibility.
-
egregore-labs Skill Review PrUse when the user says 'review PR', 'is this PR safe to merge', or 'audit PR' — runs a CTO-level 10-point review checklist on one or more pull requests. Not creating a PR (/pr) or validating local changes (/test).
-
stacksjs Skill Stacks ReviewUse when reviewing code changes in a Stacks project - a PR, a branch, staged work, or the diff since a fixed point. Reviews on two axes, Standards (does it follow this repo's rules and avoid the smell baseline) and Spec (does it do what was asked), plus a test coverage audit and an auto-fix pass. Invoke with /stacks-review.
-
stacksjs Skill Stacks SecurityUse when implementing security in Stacks - password hashing (bcrypt/argon2), app key generation, AES encryption/decryption, hash verification, rehashing detection, or security configuration (firewall, rate limiting, IP allowlists). Covers @stacksjs/security and config/security.ts.
Audited -
stacksjs Skill Stacks Security AuditUse when performing security analysis on a Stacks application - OWASP Top 10, STRIDE threat modeling, attack surface mapping, dependency audit. Requires concrete exploit scenarios. Invoke with /stacks-security-audit.
Audited -
frabcd Bundle HotfixEmergency fix workflow that bypasses normal sprint processes with a full audit trail. Creates hotfix branch, tracks approvals, and ensures the fix is backported correctly.
-
frabcd Bundle Skill TestValidate skill files for structural compliance and behavioral correctness. Three modes: static (linter), spec (behavioral), audit (coverage report).
-
frabcd Bundle Content AuditAudit GDD-specified content counts against implemented content. Identifies what's planned vs built.
-
frabcd Bundle Security AuditAudit the game for security vulnerabilities: save tampering, cheat vectors, network exploits, data exposure, and input validation gaps. Produces a prioritised security report with remediation guidance. Run before any public release or multiplayer launch.
-
frabcd Bundle Project Stage DetectAutomatically analyze project state, detect stage, identify gaps, and recommend next steps based on existing artifacts. Use when user asks 'where are we in development', 'what stage are we in', 'full project audit'.
-
lebsral Bundle AI Auditing CodeReview DSPy code for correctness and best practices. Use when you want a code review of your DSPy program, need to check if your AI code follows best practices, want to find anti-patterns in your DSPy usage, or need a quality audit of your AI implementation. Also use for DSPy code review, is my DSPy code correct, review my AI code, best practices check, DSPy anti-patterns, code quality audit, am I using DSPy right, sanity check my AI code, peer review my DSPy program, does this follow DSPy conventions.
-
lebsral Bundle AI Detecting AnomaliesDetect fraud, unusual behavior, and anomalies in events or transactions using AI. Use when detecting fraud, flagging suspicious transactions, anomaly detection in logs, spotting unusual user behavior, abuse detection, identifying outliers in data, suspicious activity monitoring, fraud scoring, unusual pattern detection, flagging account takeover attempts, detecting bot traffic, abnormal usage patterns, security event triage, risk scoring with AI.
-
l-lesteryu Skill Persona CommandsAI 人格操作系统运行时聊天指令。将 11 个指令路由到对应操作 — 状态仪表盘(含健康指标)、显示人格(展示 SOUL.md 身份)、显示记忆(展示 MEMORY.md 内容)、健康检查(运行诊断脚本)、安全审计(运行安全验证)、显示配置(验证配置文件)、帮助(指令参考)、检查点(保存上下文快照)、顾问开/关(切换主动模式)、切换预设(更改人格配置)。支持自然语言变体识别,如"系统状态"对应 status、"我是谁"对应 show persona。关键词:status、dashboard、show persona、show memory、health check、security audit、show config、help、checkpoint、advisor、switch preset、commands、diagnostics、validate、proactive mode
-
aradotso Skill Codex Redteam ModeOpt-in red team mode for AI coding assistants that enables security-focused thinking for penetration testing and red team operations
-
aradotso Skill Codex Hygiene SkillAudit and tune Codex Desktop context surfaces, tool availability, and token usage through telemetry measurement
-
aradotso Skill Codex Session PatcherClean AI refusal responses from Codex/Claude/OpenCode sessions and inject CTF prompts for security testing workflows
-
aradotso Skill Openai Codex SecurityFind, validate, and fix security vulnerabilities using OpenAI's Codex Security CLI and TypeScript SDK
-
aradotso Skill Nerv Break 5 6 Gpt JailbreakGPT-5.6 jailbreak framework using context reconstruction, real-time tamper engine, and file routing to bypass safety mechanisms for security research
-
hmbown Skill Aqua AuraUse Aqua Aura when the real threat is heat: escalating pressure, bursty contention, emotional overtemperature, or rapid-fire noise that is making clean operation impossible. Unlike a plain Aura that simply blanks weaker hits, Aqua Aura diffuses and cools them so Hermes can keep moving without matching the room's panic tempo.
-
hmbown Skill Fire AuraUse Fire Aura when the real threat is not one decisive blow but a stream of low-grade interruptions, shallow objections, retry churn, or opportunistic pokes that keep stealing momentum. Fire Aura establishes an aggressive protective threshold: trivial contact gets burned away automatically so Hermes can stay on the offensive, while anything substantial still has to be named and handled honestly.
-
flpbalada Skill Trust PsychologyAdd trust signals that reduce perceived risk before important user actions. Use for signup, checkout, onboarding, landing pages, pricing, guarantees, security, support, and cancellation reassurance; distinguish from social proof, halo effect, and cognitive fluency by focusing on risk.
-
flpbalada Bundle Codebase Slop AuditDetect sloppy-code signals with repo-wide search metrics and sampled evidence. Use when asked to audit codebase quality, "vibe coding", `isRecord`, broad `Record<string, unknown>` guards, fallback usage, excessive null guards, non-null assertions, unsafe type assertions, `node:*` imports in browser/shared code, swallowed errors, TODO debt, or code smell hotspots before refactoring.
-
jayden-dang Bundle Realign SpecUse when a feature's spec has drifted from reality — requirements changed mid-implementation, the implementation deviated from the approved plan, the feature just shipped, the specs have gone stale or out of sync, or the audit-trace check is failing — and the requirements/design/tasks triad needs realigning back to what the code and tests actually do.
-
wangjs-jacky Bundle Skill Usage Audit扫描 Claude Code 与 Codex 会话日志,统计各 Skill 的真实使用情况(正式调用次数、会话数、项目分布、最近使用时间),把"skill 到底有没有被用上"从黑盒变成一张报表。触发词:skill 使用统计、skill 用量、哪些 skill 被用了、使用台账、skill-usage-audit。
-
wangjs-jacky Skill Efficiency Audit分析当前会话的任务执行效率:定位耗时瓶颈、拆解步骤耗时、给出具体优化方案。触发词:效率分析、耗时分析、为什么这么慢、效率审计、efficiency-audit
-
wangjs-jacky Bundle Skill Optimizer诊断并优化 Skills 的持续改进工具,支持调用 efficiency-audit 进行效率审计。触发词:优化 skill、skill 没触发、为什么没有、skill 诊断、skill-optimizer
-
ariadoss Skill DefenseDefense-in-depth security validation — multi-layered checks for OWASP Top 10, secrets, auth, crypto, and data protection.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include realign-spec, moat-builder, security-reviewer. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.