Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
adamriofc Skill Pkwt Pkwtt CheckerAudit contract employment limits (PKWT max 5 years) and calculate mandatory PKWT Compensation Payout under PP No. 35/2021.
Audited -
adamriofc Skill Tax Risk AnalysisAnalyze Indonesian corporate tax compliance risks, transfer pricing / affiliate transaction indicators (PMK 172/2023), and SP2DK audit triggers.
Audited -
adamriofc Skill Contract ReviewerAudit commercial and vendor agreements to identify hidden risks, asymmetrical clauses, and compliance issues under Indonesian law, outputting a Contract Risk Score (0-100).
Audited -
adamriofc Skill Tax Audit PreparationStructure tax audit defense packages, DJP SP2DK response letters, and tax equalisation reconciliation statements.
Audited -
adamriofc Skill Haki Trademark CheckAudit trademark availability, DJKI Nice Classifications (Kelas Merek 1-45), and rejection risks under UU No. 20/2016.
Audited -
adamriofc Skill Transfer Pricing AuditAudit intercompany transactions, Thin Capitalization debt-to-equity ratio (DER 4:1 max ceiling), interest deduction barriers, and secondary dividend tax adjustments under PMK 172/2023.
Audited -
jordancoin Bundle Xcode Build OrchestratorOrchestrate Xcode build optimization by benchmarking first, running the specialist analysis skills, prioritizing findings, requesting explicit approval, delegating approved fixes to xcode-build-fixer, and re-benchmarking after changes. Use when a developer wants an end-to-end build optimization workflow, asks to speed up Xcode builds, wants a full build audit, or needs a recommend-first optimization pass covering compilation, project settings, and packages.
-
jordancoin Bundle Swiftui PerformanceAudit and improve SwiftUI runtime performance. Use when diagnosing slow rendering, janky scrolling, high CPU, memory usage, excessive view updates, layout thrash, body evaluation cost, identity churn, view lifetime issues, lazy loading, Instruments profiling guidance, and performance audit requests.
-
jordancoin Skill Code Review ChecklistComprehensive code review guidelines for iOS/Swift covering architecture, performance, security, and best practices
-
involvex Bundle Code ReviewerComprehensive code review skill for TypeScript, JavaScript, Python, Swift, Kotlin, Go. Includes automated code analysis, best practice checking, security scanning, and review checklist generation. Use when reviewing pull requests, providing code feedback, identifying issues, or ensuring code quality standards.
-
agentic-in Skill SherlockOSINT username search across 400+ social networks. Hunt down social media accounts by username.
-
agentic-in Bundle 1passwordSet up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in, and reading/injecting secrets for commands.
-
agentic-in Bundle Oss ForensicsInvestigate open-source supply-chain incidents with evidence collection, recovery, IOC tracking, and structured forensic reporting.
-
poorvith-mp Bundle PricingSet tiers, value metric, trial versus freemium and price changes, and audit the pricing page. Use when determining price levels, packaging tiers, or freemium models.
-
poorvith-mp Bundle Conversion AuditAudit a page or form for friction and return a prioritised change list with expected lift. Use when auditing landing pages, signup forms, or checkout drop-offs.
-
adamriofc Skill Porter Five ForcesAnalyzes industry structure and competitive intensity using Michael Porter's Five Forces Framework (Supplier Power, Buyer Power, Threat of Substitutes, Threat of New Entrants, Industry Rivalry).
Audited -
jurgendn Skill Argument AuditInteractively audit whether stated evidence or premises establish a claim in a proof, essay, research conclusion, or everyday argument. Use when the user asks "does my evidence support this claim", "is this reasoning valid", "check the logic", "does the conclusion follow", "poke holes in my reasoning", or provides a claim and its support. Proceed Socratically, one question at a time, then converge on a validity verdict plus the smallest fix or counterexample. Use theorem-and-claim-audit instead for a direct report-style audit of formal math or ML claims; citation-auditor to verify whether a source supports an attribution; paper-argument-planner to build a paper's full claim spine; and professor-critic to grade a finished artifact against a named reader.
-
jurgendn Bundle Paper To CodeReproduce a paper's method in minimal, direct PyTorch when no official code is available, to check whether the method works as claimed. Use whenever the user says "reproduce this paper", "implement this paper's method", "there's no code for this paper", "I want to check if this paper actually works", "turn this algorithm/equation into code", or shares a paper/arXiv link and wants a working implementation of its core mechanism. The output is a small, single-file, readable implementation plus staged verification gates (shape checks → overfit tiny batch → baseline comparison at toy scale) and an explicit assumptions ledger for everything the paper left underspecified. Do NOT use for designing training recipes for your own experiments (pytorch-training-recipe / jax-training-recipe), auditing an existing released artifact (reproducibility-audit), or structuring a research repo (research-codebase).
-
jurgendn Skill Citation AuditorAudit a paper's bibliography and inline citations for correctness — verifying papers exist, claims match what the cited paper actually says, attribution is accurate, and no citations are hallucinated or misattributed. Use whenever the user wants to check their references before submission, suspects a citation is wrong, wants to verify a specific claim is supported by the cited source, or has received a reviewer comment about incorrect citations. Also use when writing literature-heavy sections and needing to verify that a cited paper actually says what you think it says. This skill catches hallucinated titles/authors, citation telephone (claims distorted through secondary sources), missing citations on factual claims, and wrong-paper citations (citing a follow-up when the original should be cited).
-
jurgendn Bundle Venue TargetingSelect and prioritize publication venues (conferences, workshops, journals) for a research paper. Use whenever the user asks where to submit, which conference fits best, whether a paper is ready for a top venue, how to resubmit after rejection, or when comparing venues like NeurIPS vs. ICLR vs. ICML vs. ACL vs. EMNLP vs. CVPR vs. AAAI vs. ICDM vs. journals. Also use when the user has a contribution in hand and needs to decide between tier levels, theory vs. empirical tracks, workshop vs. main track, or short vs. long paper format. If the paper isn't ready for any venue yet, use submission-readiness-audit first.
-
jurgendn Bundle Apply Package AuditorAudit a full PhD or research-application package for declared-theme fit, coherence, missing evidence, narrative consistency, program fit, recommender risk, and deadline priorities. Use this skill whenever the user asks whether their whole application is ready, how to prioritize fixes before deadlines, whether their CV/SOP/research statement/faculty fit/recommenders align, whether the SOP and letters actually answer the programme's declared theme, specialisation, or track, or what weaknesses an admissions committee may notice across materials. Every audit runs the declared-theme screen first, before any academic- or faculty-fit finding, searching the web for the live official programme page whenever the target is not already known from the conversation.
-
jurgendn Bundle Peer Review WriterWrite a peer review of someone else's paper for a conference or journal — structured summary, evidenced strengths and weaknesses, calibrated scores, and constructive questions. Use whenever the user is the REVIEWER: "I have to review this paper", "help me write a review for NeurIPS/ICML/ACL/a journal", "is this weakness worth rejecting over", "how do I phrase this criticism", "draft my review from these notes", "what score should I give", or they share a manuscript they were assigned. Also use for meta-reviews, emergency reviews, and for serving on a program committee or as area chair — "I'm on the PC for X", "how does bidding/COI work", "how do I manage subreviewers", "I'm an area chair, how do I run the discussion". Do NOT use when the user is the AUTHOR: responding to reviews of their own paper is reviewer-response-strategist, pre-submission self-auditing is submission-readiness-audit, and mining a paper for research openings for their own work is gap-finder.
-
jurgendn Bundle Apply Dossier EvaluatorScore and evaluate a further-education application dossier (PhD, research master's, scholarship/fellowship, or research internship) against a reproducible rubric, and check eligibility for cross-border and scholarship programs. Use this skill whenever the user asks to "rate my profile", "score my application", "how strong is my dossier", "am I competitive for a PhD/scholarship", "evaluate me for VEF/DAAD/Fulbright/Erasmus/MSCA", "does my Vietnamese BSc qualify for an EU PhD", "what's my admit/funding chance", or wants a graded scorecard with per-dimension reasoning rather than a prose readiness report. Distinct from apply-package-auditor, which produces a qualitative coherence audit with no scores; use this skill when the user wants numbers, tiering, eligibility verdicts, or scholarship-mission fit. Use apply-profile-reader first if no structured profile exists yet.
-
jurgendn Skill Flow Phd ApplicationOrchestrate a complete PhD / research-program application package end-to-end — from reading the applicant's materials through CV, program & faculty fit, SOP, recommender strategy, professor outreach, a final package audit, and interview preparation once shortlists arrive. Use whenever the user wants to drive the whole application rather than one piece: "help me with my PhD applications", "where do I start with my application", "manage my application process", "I'm applying to PhD programs, what's the plan", "get my materials ready", or hands over a folder of CV/transcripts/notes and asks for the path to submission. This is a ROUTER that sequences existing singleton skills with stage gates; it does not write the SOP, CV, or emails itself. For a single piece, invoke that skill directly (e.g. apply-sop-writer, apply-cv-builder). For driving a research paper use flow-paper-lifecycle.
-
jurgendn Bundle Reproducibility AuditAudit whether a result can actually be reproduced from the available code, data, configs, and documentation. Use before trusting a benchmark claim or releasing your own work. Use for replication, code release checks, paper artifact sanity checks, lab handoffs, catching missing seeds/configs/data before results are cited, or whenever "works on my machine" is a risk. If the user wants to plan what to include in a public artifact package, use artifact-release-packager instead; this skill's job is to test whether reproduction is possible and where it breaks.
-
jurgendn Skill Theorem And Claim AuditPressure-test mathematical arguments, derivations, and ML paper claims, and deliver a written report-style audit. Use for theorem sketches, proof outlines, step-by-step derivations, ML paper claims, reviewer-mode critique, hidden assumptions, skipped proof steps, invalid generalization, weak empirical support, overclaimed conclusions, or whenever a result looks cleaner or stronger than expected — including "check my derivation", "which step breaks", "did I drop a constant", "does this algebra hold", or "audit this proof". Use argument-audit instead when the user wants to be walked Socratically to the weak link rather than handed a report, or when the claim is an essay/application/everyday argument rather than a formal or empirical one.
-
jurgendn Bundle Professor CriticCritique a FINISHED artifact the way the specific person who will judge it actually would — a strict-professor teardown with a verdict, not encouragement. Use when the user has something done and wants to know if it survives contact with its real reader: "tear this apart", "would a reviewer reject this", "be brutal, don't be nice", "how will my advisor read this proof step", "will a professor reply to this cold email", "grade this like an admissions committee", "poke holes in my abstract". Requires a named reader and an acceptance bar; refuses to grade blind. Distinct from peer-review-writer (there the user is the REVIEWER of someone ELSE's paper; here it is the user's OWN artifact); from submission-readiness-audit (a paper-only, whole-paper author checklist, not a named-reader verdict on any artifact); and from knowledge-debt-audit (which probes the user's UNDERSTANDING, not the artifact). Do NOT use on mid-draft or thinking-stage work — a REJECT verdict on something unfinished only demoralizes.
-
jurgendn Bundle Figure Table PlannerPlan, audit, or revise the figures, tables, captions, and visual evidence for a research paper. Use this skill whenever the user asks what figures or tables they need, whether a result should be a plot or table, how to present experiments, how to design ablation tables, how to make captions self-contained, what belongs in the appendix, or whether the current visual evidence supports the paper's claims. This skill is especially useful after experiment design and before writing the Results section.
-
jurgendn Bundle Artifact Release PackagerPlan and audit research artifact releases for papers, including code, data, models, configs, checkpoints, scripts, environment files, licenses, and artifact evaluation instructions. Use this skill whenever the user wants to release a paper codebase, prepare an artifact evaluation package, map paper tables to reproduction commands, write release instructions, check whether a repository supports the paper's claims, or package models/data safely. Use reproducibility-audit to test whether results can be reproduced; use this skill to decide what to include and how to present the release.
-
jurgendn Bundle Submission Readiness AuditAudit a research paper, draft, appendix, or submission package before deadline. Use this skill whenever the user asks if a paper is ready to submit, wants a pre-submission checklist, needs to find reviewer-obvious weaknesses, check claim/evidence consistency, verify figures and tables are referenced, inspect limitations/ethics/reproducibility statements, or prepare camera-ready materials. This is the final gate after argument planning, experiment analysis, and results writing.
-
jurgendn Bundle Knowledge Debt AuditDetect when AI assistance has produced output you cannot regenerate yourself, call the loan before it compounds, and re-probe repaid debt on a spaced, variable-cue schedule. "Get the work done" is not "I understand it." Trigger when the user is about to BUILD ON an AI-produced result ("before I extend this", "am I understanding this or just getting it done", "check whether I really get this"), wants a standing audit ("what am I in debt for", "what could I not rebuild alone"), or starts a session or periodic review in a workspace with `debt-ledger.yaml`. Two modes — REACTIVE (circuit breaker at the borrow moment) and PERIODIC (statement of account plus due re-probes). Probe UNDERSTANDING of the load-bearing step, never RECALL of incidentals. Do NOT use to generate practice (concept-exercise-generator) or teach a concept fresh (professor-mentor-technical-teaching).
-
markoblogo Bundle System Zoom OutGo up one layer of abstraction and explain how a local piece of code fits into the larger system. Use when the current focus is too narrow, the user is unfamiliar with an area, an audit needs broader context, or a refactor should be explained through modules, seams, and callers instead of line-by-line detail.
-
markoblogo Bundle Brief First ExecutionCreate a single working brief before substantial implementation, audit, or migration work. Use when tasks are non-trivial, risks are real, or the session is likely to drift without one source of truth for scope, non-goals, verification, and done criteria.
-
markoblogo Bundle Social Publishing GateReview and route social content before publishing. Use when drafting, adapting, auditing, scheduling, or monitoring posts for LinkedIn, X, Threads, Telegram, newsletters, or other distribution channels where brand voice, factual claims, platform fit, approvals, and no-spam guardrails matter. Enforce draft -> audit -> approval -> publish -> monitor, and never post or message externally without explicit user approval.
-
markoblogo Bundle Delivery Baseline AuditAudit claimed delivery against the starting baseline and the current working tree. Use when a task has declared deliverables, when a long run might say 'done' before shipping real changes, or when final verification must check the actual artifact set rather than only the transcript or commits.
-
peterbamuhigire Bundle Distinctive By DesignUse when a UI, website, dashboard, deck, or rendered artefact needs one defensible visual signature before high-fidelity build. Do not use for detailed token production or final QA; route those to the relevant design-system or audit skill after direction is chosen.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include Code Review Checklist, pkwt-pkwtt-checker, tax-risk-analysis. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.