Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
zebbern Bundle Ctf Pwntools BoilerplatePwntools exploit boilerplate for CTF binary exploitation. Provides ready-to-use templates for remote/local process interaction, ROP chain construction, format string attacks, shellcode generation, and interactive shell management. Use when writing binary exploits, when connecting to challenge services with pwntools, when building ROP chains, when exploiting format string vulnerabilities, or when automating pwn challenge solves.
-
jayden-dang Bundle Audit TraceUse when checking that requirement IDs agree where they are defined and task-cited in docs/specs, or that the capability catalog INDEX / shards stay intact — the docs-only vertical pass invoked by prove-claim, cut-release, realign-spec, and plan-tasks. Produces a traceability finding set (unknown citations, duplicate definitions, approved-but-uncited, Respects / system-ID integrity, duplicate Feature CODEs, OBS-<6hex> in Code cells, missing shard refs). Does not search application source or tests for requirement IDs.
-
1mangesh1 Bundle LoggingLogging setup, structured logging, and log management. Use when user asks to "add logging", "set up structured logging", "configure log levels", "create a logger", "set up log rotation", "send logs to ELK", "configure Winston", "set up Pino", "add request logging", "implement audit logging", "log formatting", "log correlation", "debug logging", "log sampling", "log filtering", or mentions logging best practices, structured logging, log aggregation, log levels, observability, log rotation, or centralized logging.
-
1mangesh1 Skill SupabaseSupabase for database, auth, storage, and realtime features. Use when user mentions "supabase", "supabase auth", "supabase storage", "supabase realtime", "supabase edge functions", "postgres with supabase", "row level security", "RLS", "supabase client", or building apps with Supabase as the backend.
-
1mangesh1 Bundle Code ReviewCode review checklists, PR review patterns, feedback techniques, and review automation. Use when user asks to "review this code", "code review checklist", "PR review template", "review best practices", "write review feedback", "review this PR", "how to give feedback on code", "PR too large", "split this PR", "review turnaround time", "automated code review", "CODEOWNERS", "pair review", "when to request changes", "code review tool", "review security", "design review", "performance review", "test coverage review", or any code review and feedback tasks.
-
poorvith-mp Bundle App Store OptimizationAudit and fix App Store and Play listings: keywords, screenshots, ratings and conversion. Use when optimizing iOS App Store or Google Play keywords and listings.
-
markbaindesign Skill EirenePerformance check only — Core Web Vitals, load time, image optimisation, caching. Returns a performance audit with Pass / Fail per metric. Use when you need a performance audit without the full Themis QA suite.
-
markbaindesign Skill Perf AuditPerformance audit against a live URL using Google PageSpeed Insights. Runs mobile + desktop, surfaces Core Web Vitals, and produces a prioritised fix list (P1-P4) ordered by impact. Saves a dated markdown report to context/perf/ in the project directory.
-
markbaindesign Skill PeriphetesDevOps setup or audit — Cloudways provisioning, DNS, SSL, redirects, DDEV local dev, deployment pipelines. Invoke at project start for infrastructure setup, or anytime something infrastructure-related needs fixing.
-
markbaindesign Skill Onboard AuditAudits every active project against the onboarding checklist — surfaces what's missing across all projects.
-
markbaindesign Skill Wordpress Repo CheckerValidates a WordPress theme or plugin against wordpress.org repository requirements. Checks licensing, code quality, security, file structure, and compliance rules.
-
thiennc-tesoglobal Bundle CryptotokenkitBuilds CryptoTokenKit security-token and smart-card integrations. Use for token-driver extensions, token sessions, TKSmartCard communication, NFC smart-card sessions, token-backed Keychain queries, token watching, certificate authentication, APDU handling, or PIN workflows.
-
thiennc-tesoglobal Bundle Swift SecurityBuilds or reviews Apple-platform security with Keychain, LocalAuthentication, CryptoKit, Secure Enclave, certificate pinning, key sharing, and secure credential migration. Use for secrets, biometrics, cryptography, trust evaluation, or OWASP MASVS/MASTG mobile controls.
Audited -
kitfunso Skill Stale CheckVerify a memory file's claims against the repo, git, npm and the live service, and propose the edit. Use for "is this memory still true", "audit my memory", "stale check <project>".
-
kitfunso Skill Devex ReviewLive developer experience audit. Uses the browse tool to actually TEST the developer experience: navigates docs, tries the getting started flow, times TTHW, screenshots error messages, evaluates CLI help text. Produces a DX scorecard with evidence. Compares against /plan-devex-review scores if they exist (the boomerang: plan said 3 minutes, reality says 8). Use when asked to "test the DX", "DX audit", "developer experience test", or "try the onboarding". Proactively suggest after shipping a developer-facing feature. (gstack)
-
kitfunso Skill Sinking ShipPre-production checklist: verify security, database, deployment, and code readiness before shipping.
-
kitfunso Skill Standards CheckAudits a codebase against engineering, security, and quality standards; scores six dimensions 0-10. Use for code or security review.
-
kitfunso Skill Improve Codebase ArchitectureAudit the codebase's **architecture** and propose concrete improvements. This is structural work, not style nitpicking.
-
huanyu-hibiki Bundle Skill Masterskill-master 合集路由器:管理 skill 全生命周期——盘点已装 skill、安全扫描第三方 skill、分析开源 skill、从零编写新 skill、迭代优化已有 skill,分别由 sm-manager / sm-security / sm-analyzer / sm-writer / sm-optimizer 五个子 skill 承担,本文件只路由不执行。Use when 用户提到"盘点skill"、"扫描skill"、"分析这个skill"、"帮我写个skill"、"优化这个skill"等 skill 相关请求,或直接提到"skill-master"时使用;完整触发词以正文路由表为准。
-
huanyu-hibiki Skill Sm Security静态安全扫描一个 skill 目录:规则引擎打 0-100 风险分,逐条复核 critical/high 发现并降误报,产出 SAFE/CAUTION/DO NOT INSTALL 安装建议。用于安装第三方 skill 前的安全审查。Use when 用户提到"检查这个skill安全吗"、"扫描skill"、"有没有后门"、"skill安全"、"skill恶意"时使用。
-
huanyu-hibiki Bundle Oracle Open Source采访式自我开源度审查(转化类轨道专用)。读 draft,用 9 个问题(一次一个、带镜子标注)逼创作者把"遇到什么问题→怎么推理→拿到什么结果→凭什么信你→预期管理→凭什么开口"想清楚,反向检查"端着教人/藏钩子/只给结论不给推理/产品声明存疑"。核心理念:AI 时代 IP 差异化 = 人生剧本不同;完整摊开推理过程,低营销属性,认同者主动靠近。产出 open-source-audit.md。触发词:"自我开源"/"这条够真诚吗"/"我是不是端着了"/"open-source"/"开源度"/"营销属性"。
-
huanyu-hibiki Bundle Clean SkillA boring, well-behaved notes skill used as the false-positive control for the security scanner.
-
justaname-id Bundle Solidity AuditorSecurity audit of Solidity code while you develop. Trigger on "audit", "check this contract", "review for security". Modes - default (full repo), DEEP (+ adversarial reasoning), or a specific filename.
-
delorenj Bundle Managing Tickets And Tasks In PlaneMulti-workspace Plane sprint board management with intelligent automation, ticket creation, and BMAD workflow integration. Use this skill when: - Creating tickets from BMAD stories, task descriptions, or audit findings - Auditing board organization (ticket clustering, label optimization, status bottlenecks) - Selecting the next optimal ticket to work on (priority scoring algorithm) - Promoting completed tickets to production and generating changelogs - Managing sprint workflows with status tracking and WIP limits - Working with multiple Plane workspaces (auto-detects from git remote or directory) Triggers: "create ticket", "board audit", "what should I work on", "next ticket", "promote to production", "changelog", "sprint status", "WIP limit", plane ticket operations
1 -
jordancoin Bundle IOS SecurityiOS security best practices including Keychain Services, biometrics, data protection, network security, and App Attest
-
clueso-ai Skill Self Navigable Sales DemoSplits a full sales demo into a chaptered, async-reviewable format built around buyer decision points (Integrations, Security, Pricing tiers shown, the feature that solves their specific problem) rather than a generic feature-by-feature or course-style structure. Adds an opening "what's in this demo" card so a prospect can decide where to jump before watching, and makes every section label and recap stand on its own with zero live-rep context, since no one is present to narrate or answer questions. Use when the user says "make this demo watchable without me in the room", "split this demo so the prospect can jump to what matters", "turn this into an async-shareable demo", "let the champion forward this and have stakeholders skip to their part", or "make my demo self-navigable".
Audited -
clueso-ai Skill Soft Skills Scenario VideoTurn a behavioral or compliance training topic - giving feedback, de-escalation, harassment policy, security awareness - into a story-driven animated scenario video: illustrated characters, setup, tension, response, a narrated takeaway after each beat, and a closing what-to-do checklist. Use when the user says "make a soft skills training video", "scenario-based training on X", "compliance training video", "turn this policy into a training video", or "behavioral training for managers".
Audited -
microsoft Bundle Blog Content AuditorUse this skill when the user asks to audit, review, score, rationalise, prioritise, refresh, or improve blog posts, article libraries, newsletters, or thought-leadership content.
2.7k -
microsoft Bundle Content Quality AuditorUse this skill when the user asks to assess, audit, score, review, improve, prioritise, or quality-check content, documents, pages, posts, decks, or reusable artefacts.
2.7k -
microsoft Bundle Knowledge Corpus CuratorUse this skill whenever a user asks to audit, curate, clean up, deduplicate, rationalize, or assess files used by an AI knowledge source. Require the user to upload copies of the source files, analyze those complete files locally, and use configured knowledge sources only to validate findings.
2.7k -
microsoft Bundle Power Automate DocumentationTrigger whenever the user uploads or references a Power Automate solution `.zip` and asks about references, dependencies on other flows, or related questions — phrasing like "document this flow", "what does this flow read/write/touch", "map the connection references", "audit this solution", or "which flows call which".
2.7k -
pinkpixel-dev Bundle Synology Sso Server APIDesign, implement, audit, and troubleshoot application integrations with Synology DSM SSO Server and its OAuth-2-based JavaScript SDK or manual flow. Use for SYNOSSO.init/login/logout, app IDs, exact redirect URIs, state/CSRF validation, access-token fragments, server-side SSOAccessToken.cgi exchange, user_id/user_name retrieval, directory-service validation, SSO error strings, and modernizing insecure examples from the 2023 Synology SSO Server guide.
-
pinkpixel-dev Bundle Synology File Station APIBuild, audit, troubleshoot, and document clients and automations for the Synology DSM File Station WebAPI. Use for SYNO.API.Info, SYNO.API.Auth, and SYNO.FileStation APIs; DSM file listing, search, upload, download, sharing, folders, rename, copy/move, delete, archive extraction/compression, favorites, checksums, thumbnails, virtual folders, permissions, asynchronous background tasks, request encoding, authentication, version negotiation, and File Station error handling.
-
pinkpixel-dev Bundle Synology Audio Station LyricsDesign, scaffold, validate, package, audit, and troubleshoot third-party Synology Audio Station lyrics modules in .aum format. Use for INFO JSON manifests, lyric.php classes, getLyricsList/getLyrics contracts, addTrackInfoToList/addLyrics calls, external lyrics-provider HTTP parsing, secure PHP runtime constraints, tar.gz packaging, installation testing, and migration of legacy Audio Station 5.0 lyrics plugins.
-
adamriofc Skill Pkwtt CheckerAudit PKWTT permanent employment contracts, probation limits (max 3 months), auto-conversion triggers, minimum wage compliance, and statutory severance rights under PP 35/2021 & UU 6/2023.
Audited -
adamriofc Skill Efaktur HelperValidate and audit e-Faktur tax invoices (Faktur Pajak) for PPN 12% statutory rate and 11/12 DPP Nilai Lain effective burden filings.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include audit-trace, ctf-pwntools-boilerplate, logging. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.