Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
wanshuiyin Skill Integrity ForensicsRun the Anti-Autoresearch integrity-forensics DETERMINISTIC slice (numeric core + rules-only reporter) against a paper via a SHA-pinned thin launcher, then convert the verdict into a typed policy gate (BLOCK/WARN/NO_NEW_BLOCKER) and an append-only obligations ledger. Codex-native limitation: upstream ships no Codex-native auditor pack, so the full nine-dimension semantic sweep requires a Claude Code session — this pack runs the honestly-scoped deterministic-only mode (it can flag, it can never say CLEAN). Use when user says "integrity forensics", "forensic audit this paper", "投稿前自查诚信".
-
rysweet Bundle Code PhilosophyMulti-pass code philosophy audit skill. Performs three distinct passes over target code to verify adherence to the project's PHILOSOPHY.md principles. Produces a structured report with findings and delegates fixes to dev-orchestrator. This is an advisory audit-only skill — it does not modify code directly.
-
jovanipink Bundle Code Change ReviewReview an exact code change for correctness, regressions, security, compatibility, test quality, and maintainability using the diff and repository evidence. Use before commit, pull request, merge, or release when the user wants findings rather than implementation.
-
jovanipink Bundle Prelaunch ReadinessAudit whether a web property, service, application, or major relaunch is ready for public use, separating repository checks from provider and live-runtime evidence. Use for launch checklists, release readiness, and go or no-go reviews.
-
jovanipink Bundle Change Impact AnalysisAnalyze the blast radius of a proposed or completed change across callers, contracts, storage, jobs, clients, security, rollout, and operations. Use before review, merge, or release when downstream effects may be missed; do not substitute speculation for traced dependencies.
-
cwinvestments Skill Memstack Development API DesignerUse this skill when the user says 'design API', 'API endpoints', 'REST API', 'API designer', 'route structure', 'API architecture', or is designing RESTful API routes, request/response schemas, and endpoint organization. Do NOT use for API security audits or database design.
Audited -
cwinvestments Skill Memstack Security Secrets ScannerUse this skill when the user says 'scan for secrets', 'check for leaked keys', 'secrets scanner', 'hardcoded credentials', 'API key leak', or needs to detect exposed secrets in source code. Do NOT use for dependency vulnerabilities or RLS auditing.
-
cwinvestments Skill Memstack Development Code ReviewerUse this skill when the user says 'review code', 'code review', 'check my code', 'audit this', 'review PR', 'review changes', 'what's wrong with this', or is requesting a structured review of code quality, security, performance, or maintainability. Do NOT use for refactoring plans or test generation.
Audited -
cwinvestments Skill Memstack Security Dependency AuditUse this skill when the user says 'dependency audit', 'npm audit', 'pip audit', 'cargo audit', 'security vulnerabilities', 'outdated packages', 'supply chain', or needs to scan project dependencies for vulnerabilities, abandoned packages, and upgrade risks. Do NOT use for application-level security or secrets scanning.
Audited -
aviskaar Bundle CisoUse this skill when you need enterprise security strategy, risk governance, board-level security reporting, security program design, or orchestration of any security domain (SOC/operations, compliance, infrastructure, application, AI ethics). Trigger for CISO-level decisions, enterprise risk posture assessment, security budget planning, or when multiple security domains must be coordinated simultaneously.
-
aviskaar Skill Threat HunterUse this skill when you need proactive threat hunting campaigns, MITRE ATT&CK-based hunt hypotheses, IOC sweeps, behavioral anomaly investigation, threat intelligence integration, adversary emulation planning, SOC analyst triage support, SIEM query development (KQL/SPL/YARA), or automated threat detection engineering. Trigger for threat hunting sprints, new threat intel indicators, or post-incident proactive sweeps.
Audited -
aviskaar Skill Sre OperationsUse this skill when you need SRE (Site Reliability Engineering) security integration, ITIL process design, Six Sigma quality improvement for security, Global Delivery Framework implementation, reliability-security SLO/SLA design, runbook creation with security gates, capacity planning with security constraints, or operational excellence programs. Trigger for SRE buildout, operational transformation, or reliability + security convergence programs.
Audited -
aviskaar Skill Security TrainerUse this skill when you need security awareness training program design, phishing simulation campaigns, role-based security curriculum development, CISO dashboard design, security metrics reporting, social engineering defense training, developer secure coding training, AI security awareness training, regulatory compliance training (GDPR, HIPAA, PCI), new employee security onboarding, or tabletop exercise facilitation. Trigger for annual training programs, new hire onboarding, or security culture improvement initiatives.
Audited -
aviskaar Skill Compliance AuditorUse this skill when you need audit evidence collection, control testing, SOC 2 readiness assessment, NIST CSF gap analysis, ISO 27001 implementation, HIPAA compliance review, SOX IT controls testing, GDPR audit, CCPA compliance assessment, EU AI Act conformity assessment, policy review, third-party vendor risk assessment, or GRC platform management. Trigger for audit preparation, control testing cycles, or regulatory readiness reviews.
Audited -
aviskaar Skill Incident ResponderUse this skill when you need incident response execution, breach containment, forensic investigation, regulatory breach notification, root cause analysis, post-incident review, change management integration, problem management, or tabletop exercise design. Trigger for active security incidents, suspected breaches, ransomware events, insider threat investigations, or post-incident improvement programs.
-
aviskaar Skill Security OperationsUse this skill when you need SOC (Security Operations Center) setup or management, threat detection and hunting programs, incident response coordination, SIEM configuration and tuning, security monitoring strategy, SRE security integration, or security operations metrics and KPIs. Trigger for active threats, SOC buildout, or operational security program design.
Audited -
aviskaar Bundle Application SecurityUse this skill when you need application security program design, secure SDLC implementation, SAST/DAST/SCA toolchain setup, OWASP Top 10 remediation, API security, penetration testing coordination, vulnerability management, bug bounty program management, security code review standards, or web application firewall configuration. Trigger for secure development practices, release security gates, or vulnerability remediation programs.
-
aviskaar Bundle Compliance GovernanceUse this skill when you need regulatory compliance strategy, framework gap analysis, audit preparation, policy management, or risk governance across SOC 2, NIST CSF, ISO 27001, HIPAA, SOX, GDPR, CCPA, EU AI Act, PCI-DSS, or industry-specific standards. Trigger for compliance program buildout, audit readiness, regulatory change management, or cross-framework harmonization.
-
aviskaar Skill Network Data SecurityUse this skill when you need network security architecture, firewall policy design, IDS/IPS configuration, DNS security, email security (DMARC/DKIM/SPF), SSL/TLS certificate lifecycle management, DDoS protection, data loss prevention (DLP), PII/PHI data protection controls, encryption implementation (at-rest and in-transit), database security hardening, data classification, or information security governance. Trigger for network design reviews, data security programs, or encryption strategy.
Audited -
bobo070314 Bundle Security AuditStatic code security auditor (SQLi/XSS/secrets/command injection)
-
jh941213 Skill Harness Audit하네스(hooks, skills, agents, rules) 전체 건강도를 진단하고 점수 산출. 대상: ~/.claude 전역 하네스 (프로젝트 진단은 harness-diagnostics). Triggers on: harness audit, 하네스 진단, 설정 점검, 하네스 점검. NOT for: 코드 작성, 구현.
-
jh941213 Skill Harness Diagnostics에이전트 하네스 12원칙 기반 자가 진단 및 개선 제안. 자동 발동 없음 — /harness-diagnostics 로 수동 실행 (인자로 setup/audit/maintenance 모드 선택). NOT for: 코드 구현, 버그 수정, 테스트 작성.
-
mathews-tom Bundle Pr ReviewDiff-based PR review across code quality, test coverage, silent failures, type design, and comment quality with severity-ranked findings. Triggers on: "review my PR", "review this code", "check my changes", "audit this PR", "code review". NOT for pre-landing gate, use pre-landing-review.
-
mathews-tom Bundle Plan ReviewPre-implementation plan audit stress-testing scope, assumptions, risks, and failure modes before code is written. Triggers on: "review this plan", "is this plan solid", "what am I missing", "challenge my assumptions", "stress-test this", "/plan-review".
-
mathews-tom Bundle Env ValidatorValidates .env files against code references and manifests for missing vars, type mismatches, insecure defaults, and unused entries. Triggers on: "validate env file", "check environment variables", "missing env vars", "check .env", "dotenv validation". NOT for secret scanning, use repo-sentinel.
-
mathews-tom Bundle Citation AuditVerify that every citation in a manuscript is real, correctly attributed, and accurately described. Detects ghost papers, wrong arXiv IDs, inverted claims, and dead links by fetching each cited work. Optional fix mode applies bib metadata corrections and surfaces prose rewrites for claim errors. Triggers on: "check my citations", "verify references", "citation audit", "are my references real", "check bib", "reference check", "bib audit", "citation verification". Companion to manuscript-review (Pass 5 hygiene); this skill audits factual truth.
-
mathews-tom Bundle Arxiv PreflightPre-submission validation audit for arXiv papers across TeX source, PDF, figures, metadata, bibliography, file organization, and common-error scans. Produces pass/fail report with specific fixes per arXiv requirement. Triggers on: "check my arXiv submission", "validate for arXiv", "arXiv preflight", "ready for arXiv", "arxiv check", "arxiv submission readiness". Companion to manuscript-review (prose), manuscript-provenance (code), arxiv-figures, arxiv-package.
-
mathews-tom Bundle Figure RhetoricEvaluate whether figures and plots in a manuscript effectively communicate the claims they support. Audits chart-type fit, axis design, visual hierarchy, data density, caption interpretation, perceptual accuracy, and narrative arc across 8 dimensions. Triggers on: "do my figures work", "check my plots", "are my graphs clear", "figure audit", "do my figures support my claims", "visualization review", "figure rhetoric", "plot review", "chart critique", "visual argument check". Companion to manuscript-review §12 (legibility) and figure-table-quality (rendering).
-
mathews-tom Bundle Dependency AuditAudits direct and transitive dependencies for license compliance, maintenance health, CVEs, abandoned packages, and bloat. Triggers on: "audit dependencies", "license check", "dependency health", "abandoned packages", "unused dependencies", "license compliance", "supply chain", "dependency risk".
-
mathews-tom Bundle Manuscript ReviewPre-publication manuscript audit producing a section-level refactoring report with citation hygiene and submission-readiness checks. Triggers on: "review my paper", "check before submission", "is this ready to submit", "pre-pub checklist", "refactor my paper", "check my references", "does the abstract work".
-
mathews-tom Bundle Pre Landing ReviewGate-oriented safety audit for code changes before landing, using a checklist with two-pass severity triage. Triggers on: "is this safe to land", "pre-landing review", "safety check before merge", "gate check", "/pre-landing-review". NOT for diff review, use pr-review.
-
mathews-tom Bundle Architecture ReviewerArchitecture reviews across 7 dimensions (structural, scalability, enterprise readiness, performance, security, ops, data) with scored reports. Triggers on: "review architecture", "critique design", "audit system", "assess scalability", "enterprise readiness", "technical due diligence". NOT for diagrams, use architecture-diagram.
-
amazon-quick Bundle Hedis Measure SpecificationInterpret Healthcare Effectiveness Data and Information Set (HEDIS) quality measure logic: denominator, numerator, exclusions, continuous enrollment, audit readiness, and Star Rating care gap prioritization. Use when asked to 'interpret a HEDIS measure', 'evaluate continuous enrollment', 'apply HEDIS exclusions', 'check NCQA audit readiness', 'calculate a measure rate', 'prioritize care gaps', or any HEDIS specification reasoning
-
amazon-quick Skill Compliance AutomationGenerates draft compliance policies for SOC 2 Type I/II, ISO 27001, and HIPAA frameworks. Produces evidence collection checklists, control mapping matrices, and gap analysis reports from existing documentation. Use when asked to 'prepare for SOC 2 audit', 'generate compliance policies', 'map controls to framework', 'audit prep', 'compliance gap analysis', or 'ISO 27001 readiness'.
Audited -
amazon-quick Skill Vulnerability Report SummarizerTransforms raw vulnerability scan output (Nessus, Qualys, OWASP ZAP, or similar) into executive-ready security reports. Scores findings by Common Vulnerability Scoring System (CVSS), maps to MITRE ATT&CK where applicable, prioritizes remediation, and produces both technical and executive summaries. Use when asked to 'summarize this vulnerability scan', 'create security report', 'prioritize these vulnerabilities', 'executive summary of scan results', or 'remediation plan from scan'.
Audited -
somtougeh Bundle DeslopRemove AI slop from code or writing. Use for branch code cleanup (redundant comments, defensive over-engineering, type hacks, over-abstraction) or for prose drafts that need less AI-sounding language while preserving voice. Also use when the user asks whether writing reads as AI, to audit or scan for slop patterns without rewriting. Triggers: deslop, no-ai-slop, remove AI slop, clean up this branch, is this AI, less AI-sounding, humanize this draft.
2
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include integrity-forensics, code-philosophy, code-change-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.