Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
peterbamuhigire Bundle Color System And PaletteUse when building a cross-format colour system with an authored anchor, perceptual ramps, semantic roles, contrast contracts, and theme mappings. Unlike color-selection, this operationalises a palette; focused contrast audit routes to accessible-color-and-contrast.
-
peterbamuhigire Bundle Trust Credibility And Social ProofUse when selecting, verifying, and placing testimonials, reviews, logos, ratings, usage numbers, certifications, guarantees, security cues, awards, team credentials, or case-study proof. Use landing-page-and-conversion-design to compose the whole page and design-ethics-and-anti-dark-patterns for persuasion review.
-
peterbamuhigire Bundle Heuristic Evaluation And Design CritiqueUse when an existing interface or flow needs an expert, no-users inspection against Nielsen/Tognazzini heuristics with screen evidence and 0–4 severity. Do not use for empirical usability testing or a broad 0–100 visual audit; route those to research or design-audit.
-
sidchaudhary Bundle Product FeedSets up the product catalog and the product sets that let ads pull live inventory instead of static images, treating each set as its own promise: best sellers, under fifty, new arrivals. Use after tracking is verified, for stores with more SKUs than per-product creative can cover. Boundary: `product-catalog-audit` and `shopping-feed` check an outbound feed for disapprovals and attribute breakage; this builds the sets themselves. Requires `meta-pixel` to pass first, or it automates showing people the wrong products.
Audited -
sidchaudhary Bundle Ppc ReportingTurns a Google Ads account into five to seven numbers tied to the business outcome, each carrying its formula, its target and its caveat, starting from what the business needs rather than from whatever the platform puts on the dashboard. Use weekly for an owner update that has to fit one screen. Boundary: `facebook-ads-audit` is the paid-social equivalent and `google-ads-review` explains what moved between two periods; this decides which numbers get watched. `kpi-dashboard` designs whole-product dashboards instead.
Audited -
sidchaudhary Bundle Daily Ad CheckThe read-only morning pass over one ad account: last seven complete days against the prior seven, budget going nowhere, ads fading, tests starved of spend, tracking that broke, and the single next test worth running, capped at five findings and changing nothing. Use daily, or on any account somebody else manages as an accountability check. Boundary: `daily-sales-report` reads a whole store's orders, revenue and total spend; this looks only inside the ad account, and `facebook-ads-audit` is the weekly decision review.
-
sidchaudhary Bundle Paid Media AuditTriages paid ad spend, using ROAS, CAC, and spend concentration across channels, campaigns, and audiences, to find where budget is being wasted rather than assuming the ad account is the whole problem. Use when CPA is rising, ROAS is falling, or the team wants to know which campaigns or audiences to cut before adding more budget. Boundary: pairs with `conversion-funnel`, which diagnoses drop-off at a specific page or funnel step; this works one level up, at the level of which channels, campaigns, and audiences are burning spend.
-
sidchaudhary Bundle Facebook Ads AuditReads a Meta ad account the way an analyst with no account to keep would: results broken out by angle, an explicit caveat on platform-reported return and attribution, and the three decisions the numbers actually support, with gaps named rather than filled with optimism. Use weekly, or before any decision to scale, kill or rebuild. Boundary: `ppc-reporting` is the Google equivalent, `paid-media-audit` triages waste across every channel at once, and `weekly-report` writes the whole-business readout.
-
sidchaudhary Bundle Budget ReallocationRanks every line on both platforms by what a conversion actually costs there, names which are donors and which are recipients, and models three transfer sizes with the projected conversions and blended return for each, including moving money between platforms rather than only within one. Proposes scenarios for approval and moves nothing. Use when the split between platforms was set by history rather than by evidence. Boundary: `scaling-facebook-ads` adds budget to one proven winner in small steps without resetting its learning, `paid-media-audit` finds waste without proposing where it should go instead, and `stockout-alerts` pauses for stock reasons; this shifts money between existing lines.
Audited -
sidchaudhary Bundle Cost Per AcquisitionTakes results from both ad platforms at once and returns one ranked list of why acquisition cost moved, each cause carrying a severity and the evidence behind it, and including the read neither account can produce alone: whether the two are bidding into the same people and inflating each other. Use when acquisition cost climbed on both platforms and the reason is not obvious in either one. Boundary: `daily-ad-check` and `daily-ad-check` look only inside one paid-social account, `google-ads-troubleshooting` works one search account's serving levels in dependency order, and `paid-media-audit` triages waste across every channel without joining platforms; this one joins two and ranks causes.
-
sidchaudhary Bundle Checkout OptimizationAudits a cart and checkout flow directly, using screenshots or a walkthrough plus policy details, to find specific friction points in forms, payment coverage, trust signals, and step count. Use when cart abandonment is high, checkout conversion is weak, or the team wants a pre-launch or pre-scale checkout review. Boundary: differs from `conversion-funnel`, which diagnoses funnel drop-off against conversion benchmarks; this is a direct UX audit of the checkout flow itself, not a benchmark comparison.
-
yuniorglez Bundle PDF ProMaster of PDF engineering, specialized in AI-driven extraction, high-fidelity Generation (Puppeteer), and PDF 2.0 Security.
-
lloyd3126 Bundle Koyfin Advanced SearchUse Koyfin's Advanced Search in the Codex in-app browser to disambiguate securities or search transcripts by terms, dates, event types, companies, lists, and sectors. Trigger when a ticker has multiple listings or a user needs transcript/security search results; keep the workflow read-only.
-
lloyd3126 Bundle Koyfin Security ResearchUse Koyfin through the Codex in-app browser to resolve an exact stock, ETF, index, or other security and perform read-only research across Snapshot, analyst estimates, financial analysis, news, filings, transcripts, and charts. Trigger when a user asks to investigate one security or compare its current research fields; never guess Koyfin internal security IDs.
-
lloyd3126 Bundle K12ea Ptst Public ResourcesUse the Codex in-app browser to read and verify public resources in the 國中小代理代課教師人才庫媒合專區: site map, news and announcement details, county recruitment/support measures, job-seeker guidance, laws index, FAQ search/accordion, about page, teaching links, privacy, and information-security pages. Trigger for requests about public PTST guidance or current hr.k12ea.gov.tw/ptst announcements and reference pages.
-
tfcbot Skill Audit Account HealthAudit a connected Zernio account's token and permissions.
-
justaname-id Bundle SlitherSlither static analyzer for Solidity — installation, detector categories, triage workflow, custom detectors, printers, CI integration, and configuration. Run fast security scans on Hardhat and Foundry projects with 90+ built-in detectors.
-
justaname-id Bundle Evm NftsERC-721 and ERC-1155 NFT development patterns for EVM chains. Covers minting, metadata, royalties, marketplace integration with Seaport, and security pitfalls. Uses OpenZeppelin v5.6.1.
-
justaname-id Bundle HyperlaneHyperlane permissionless interoperability — Mailbox messaging, Interchain Security Modules (ISM), Warp Routes for token bridging, hooks, interchain accounts, and permissionless deployment to any chain. Covers Hyperlane SDK, contract interfaces, and custom security configurations.
-
justaname-id Bundle LayerzeroLayerZero V2 cross-chain messaging — OApp framework, OFT (Omnichain Fungible Token), DVN configuration, executor setup, message options, and cross-chain deployment patterns. Covers lz-oapp contracts, EndpointV2 interface, message lifecycle, and security configuration across Ethereum, Arbitrum, Base, Optimism, and Polygon.
-
justaname-id Bundle Code ReconDeep architectural context building for security audits. Use when conducting security reviews, building codebase understanding, mapping trust boundaries, or preparing for vulnerability analysis. Inspired by Trail of Bits methodology.
-
justaname-id Bundle VulnhunterSecurity vulnerability detection and variant analysis skill. Use when hunting for dangerous APIs, footgun patterns, error-prone configurations, and vulnerability variants across codebases. Combines sharp edges detection with variant hunting methodology.
Audited -
justaname-id Bundle OpenzeppelinOpenZeppelin Contracts v5 for building secure smart contracts. Covers ERC-20/721/1155 tokens, access control (Ownable, AccessControl, AccessManager), security utilities (ReentrancyGuard, Pausable, SafeERC20), upgradeable contracts (UUPS, Initializable), and Defender integration. Use when writing Solidity contracts that need battle-tested, audited building blocks.
-
fritzprix Bundle Vitepress Doc SyncAnalyze recent git commits and codebase changes to update, synchronize, and align VitePress documentation (docs/user/ and website/). Use when the user requests to update documentation from git diffs, sync VitePress docs, audit doc gaps, or update user guides after code changes. Triggers on "vitepress 문서 현행화", "git 변경사항으로 문서 업데이트", "최신 git commit 반영하여 docs 업데이트", "vitepress-doc-sync", "sync docs with git", "update vitepress docs", "doc sync".
-
fritzprix Bundle Review Local ChangesComprehensive review and audit of uncommitted local code changes in git working copy (staged, unstaged, untracked). Use when asked to review local changes, audit git diff, check uncommitted work before commit/PR/push, or inspect working copy edits for potential bugs, security issues, formatting, or regression risks.
-
fritzprix Bundle Consensus DelegationUse when the user needs to evaluate the same question from different perspectives by orchestrating multiple specialized child sessions, collecting their independent conclusions, and reconciling disagreements through parent-mediated follow-ups. Suitable for code review triangulation, architecture or risk assessment, security vs performance tradeoff analysis, or any bounded decision that benefits from 2-4 distinct expert viewpoints—not for persistent teams (teamwork/org) or single one-off delegation (delegate).
-
ninjasln-labs Skill Audit ItemTrack audit/review findings as numbered issue files (.scratch/neonforge-v1/audit-items/NNN-slug.md) with id, severity, source audit, status (open/fixed/recorded), fix commit, regression test, and closing evidence, plus a summary index README that stage-gate enumerates. Use when an audit or review produces findings ("把审计发现入账" / "审计项"). NOT for: finding the issues (use code-review or the audit itself) — this skill only tracks them.
-
ninjasln-labs Skill Skill EvalBehaviorally evaluate a skill: define 3-5 representative tasks, run each N>=3 times with and without the skill loaded in fresh agents, compare pass rates, and report a comparison table plus concrete improvement items that feed back into the skill's SKILL.md. Use when a skill changes, at quarterly evaluation, or when accepting a new skill. NOT for: static description compliance — use skill-description-audit.
-
ninjasln-labs Skill Stage GateRun a stage-completion gate for staged delivery (spec-kit): read the stage spec's DoD assertions and execute each one — unit tests, dual tsc, interaction tests, behavioral acceptance, coverage matrix, open audit items, push state — reporting PASS/FAIL per assertion with fresh command evidence. Verifies only, never fixes. Use when a stage is claimed complete or on "run the stage gate" / "跑阶段门禁". NOT for: single-shot verification (use verification-before-completion) or executing a plan (use executing-plans).
-
ninjasln-labs Bundle Security ScanSecurity scan: scan code for security vulnerabilities including OWASP Top 10, secrets, and misconfigurations, with severity thresholds. Use when you need comprehensive security analysis of a codebase.
-
ninjasln-labs Skill Coverage MatrixGenerate or maintain the coverage matrix (docs/tests/coverage-matrix.md): scan unit test names (describe/it in tests/unit/), the timeline event registry (TIMELINE_EVENT_SPECS in src/domain/timeline.ts), and stage-spec DoD assertions, then produce the three-way matrix (invariants<->tests / events<->tests / DoD<->gate) and flag gaps (invariant without test, event without assertion) into audit items. Use when at a stage end ("更新覆盖矩阵") or after adding invariants/events. NOT for: runtime enforcement — the matrix is a human-checked artifact, never a test gate.
-
ninjasln-labs Skill Dependency ScanDependency scan: detect CVEs and security issues in project dependencies. Use when you need to analyze packages for known vulnerabilities across npm, pip, cargo, and other ecosystems.
-
ninjasln-labs Skill Product Doc AuditProduct Document Audit: three-layer audit of a product documentation set (0-1 phase docs): 1) completeness against the 0-1 delivery doc panorama (required/optional), 2) each doc by type-specific checkpoints and core review dimensions, 3) cross-validate alignment. Produces readiness score (0-100), Critical/Major/Minor grading, authority rulings, deliverability judgment, and PRODUCT-DOC-AUDIT.md without modifying audited docs. Supports final project acceptance (four-layer go/no-go). Use when auditing or cross-validating product docs (PRDs, design docs, specs, domain docs, launch docs) for readiness, grading, contradictions, or go/no-go delivery decisions.
-
ninjasln-labs Bundle Deep Codebase AnalysisDeep codebase analysis: read and analyze an entire software project's source to understand architecture, communication, design patterns, and business flows. Use when the user asks to analyze the overall structure of a whole codebase (exploring a new system, understanding architecture before maintenance, or scoping a refactor). NOT for: single-file edits, auditing one skill's SKILL.md, or reviewing a small diff — those belong to code-review / skill-description-audit.
-
cwinvestments Skill Memstack Business GdprUse this skill when the user says 'GDPR', 'data protection', 'privacy compliance', 'DPA', 'DSAR', 'data subject request', 'cookie consent', 'privacy audit', 'CCPA', or asks 'do I need GDPR for this repo'. Scans the repository to detect what personal data is collected, classifies sensitivity, determines whether GDPR applies and how critical it is, then reports required roles, obligations, and remediation. Do NOT use for general security audits (use owasp-top10) or contract drafting (use contract-template).
Audited -
cwinvestments Skill Memstack Business LicensingUse this skill when the user says 'licensing', 'license audit', 'can I use this commercially', 'OSS license check', 'license compatibility', 'GPL', 'MIT', 'AGPL', 'copyleft'. Scans the repository for every dependency and asset license, then produces a per-package verdict table: ready for commercial use, citation/attribution required, more information needed, or commercial use not allowed. Do NOT use for vulnerability scanning (use dependency-audit) or contract drafting (use contract-template).
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include color-system-and-palette, trust-credibility-and-social-proof, heuristic-evaluation-and-design-critique. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.