Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ai-driven-dev Bundle 04 AuditAudit a codebase read-only across seven quality pillars into one ranked report. Use when the user wants to assess, health-check, or audit a codebase or one pillar. Not for fixing findings, reviewing a change, or checking a feature works.
-
ai-driven-dev Bundle 07 RefactorImprove code across four axes (cleanup, performance, security, architecture) by scanning and fixing, or applying a pushed audit report. Use when the user wants to refactor, optimize, harden, or remove code. Not for read-only diagnosis or adding tests.
-
ai-driven-dev Bundle Aidd Dev 03 AuditPerform deep codebase analysis to identify technical debt, dead code, and improvement opportunities.
-
ai-driven-dev Bundle Aidd Dev 06 RefactorOptimize code for performance and fix security vulnerabilities following OWASP guidelines.
-
ai-driven-dev Bundle Aidd Refine 03 CondenseToggle terse output mode with intensity levels (lite, full, ultra) so prose drops articles, filler, and pleasantries while code, quoted errors, and security warnings stay verbatim. Use when the user says "condense", "condense output", "be more concise", "shorter answers", "tighten output", "/condense", "/condense full", "/condense ultra", or "stop condense". Do NOT use for editing existing prose, summarizing a long document, or compressing source code (only output style is affected, not content).
-
wadewarren Skill Persona It AdminAdminister IT — monitor security and configure Workspace.
-
jovanipink Bundle Source Output Conformance AuditAudit whether exact source identity and expected values survive parsing or extraction, validation, persistence, and readback using source-cited oracles and mutation-sensitive tests. Use for end-to-end source-to-output fidelity claims; use test-quality-review for test-suite quality and authority-boundary-review for ownership architecture alone.
-
bostonaholic Bundle No CommentsRemoves low-value source comments and encodes valid constraints. Invoke ONLY on explicit "remove unnecessary comments", "audit comments", or "/no-comments" intent—never infer cleanup intent.
-
bostonaholic Bundle Reviewing SecurityDefines threat and OWASP review with evidence-rated findings. Load when reviewing a diff for security defects.
-
bostonaholic Bundle Conventional CommentsDefines review labels and decorations. Load when formatting code, design, security, documentation, or UX review comments.
-
bostonaholic Bundle Eng Design Doc ReviewReviews a technical design document with fresh context. Trigger on "review the design doc", "audit 6-design.md", "is this design ready", or "/eng-design-doc-review".
-
hack23 Skill Cis ControlsCIS Controls v8.1 critical security controls for static HTML/CSS websites on GitHub Pages
Audited -
hack23 Skill Threat ModelingComprehensive Hack23 threat modeling process using STRIDE, MITRE ATT&CK, attack trees, and quantitative risk assessment per ISMS Threat_Modeling.md policy
Audited -
hack23 Skill Input ValidationInput validation and sanitization patterns for preventing XSS, injection attacks, and ensuring data integrity
Audited -
hack23 Skill Gh Aw Safe OutputsExpert knowledge in GitHub Agentic Workflows safe outputs - security architecture, sanitization, controlled AI actions, and write operation patterns
Audited -
hack23 Skill Iso 27001 ControlsISO 27001:2022 Annex A controls for static HTML/CSS websites on GitHub Pages
Audited -
hack23 Skill Code Review PracticesCode review best practices, quality gates, security checks, and constructive feedback guidelines for collaborative development
Audited -
hack23 Skill Github Agentic Workflows Tools EcosystemComprehensive guide for all available tools including GitHub, file operations, web, bash, playwright, tool capabilities and limitations, integration patterns, custom tool development, security considerations, and usage examples
Audited -
hack23 Skill Hack23 Isms ComplianceStrategic skill for ensuring all Hack23 repositories comply with ISMS requirements (ISO 27001, NIST CSF 2.0, CIS Controls)
Audited -
hack23 Skill Security DocumentationISMS security documentation standards for Hack23 projects
Audited -
shalomb Skill DoctorAudit branch health, working tree cleanliness, conventional commits, local tests, GitHub CI, and PR well-formedness. Short command alias for branch-doctor.
-
shalomb Bundle Farley TddAudit and score an existing test suite against Dave Farley's Properties of Good Tests using the Farley Index. Use when tests already exist and the question is whether they can be trusted — flaky runs, slow CI, brittle tests, or validating that TDD was actually practised. For writing new code test-first use `test-driven-development`; for reviewing specific tests or a diff use `test-design-review`. Triggers on: 'farley', 'farley index', 'test quality', 'test suite audit', 'flaky tests', 'am I really doing TDD'.
-
shalomb Bundle Harness IdpExecute Harness.io IDP Scaffolder templates and workflows programmatically. Use this skill to list/discover workflows, components, APIs, query the service catalog, and launch infrastructure/deployment configurations. It can manage and audit API keys, track execution status, integrate IDP tasks into pipelines, and discover project infrastructure dependencies or user access control. Trigger this when the user mentions Harness, IDP, Scaffolder, idp.harness.io, templates, entity groups, or Harness service registry/catalog.
-
somtougeh Bundle Improve AnimationsAudit a codebase's motion and return prioritized findings or requested implementation plans. Audit mode is read-only; direct implementation requests use the relevant motion workflow.
2 -
somtougeh Skill Redesign Existing ProjectsAudit and improve the visual design of an existing website or app in its current stack when the user explicitly requests a redesign.
2 -
somtougeh Bundle Improve Codebase ArchitectureAudit a codebase for architectural friction, present visual deepening opportunities, and explore a user-selected candidate.
2 -
drolu Bundle VaptComprehensive vulnerability assessment and penetration testing skill leveraging Secator, NetExec, Metasploit, and raw Python for advanced exploitation chaining across Linux, Windows, Unix, macOS systems, network devices (switches, routers, firewalls), protocols, webapps and APIs (REST, GraphQL, gRPC). Uses OSSTMM and OWASP standards. Supports blackbox, greybox, and whitebox pentests with false-positive resistance, verified exploit confirmation, detailed step-by-step remediation, and full documentation. Use when performing security assessments, penetration tests, vulnerability scans, exploit validation, network enumeration, or security auditing.
-
drolu Bundle CasperEnterprise-grade autonomous penetration testing framework for comprehensive web application and API security assessment using CLI tools, specializing in authorization bypass, injection attacks, business logic flaws, and security reporting
-
drolu Bundle NetopsThe ultimate network troubleshooting skill — a CCIE/RHCE-level reference and decision engine for diagnosing ANY network, connectivity, bandwidth, latency, DNS, TLS, or security problem. Covers packet-level sensors (NetWatch, RustNet, tshark, ngrep, Pktmon), all capture architectures (SPAN/RSPAN/ERSPAN, transparent Linux bridge, L3 gateway, host-based, one-armed SPAN), Windows AND Linux sensor builds, and Cisco native telemetry (SNMP/NETCONF/gNMI/CLI/pyATS). Includes a decision framework that picks the best tool + architecture per symptom, multi-platform command references, and 20+ worked incident scenarios with implementation details, commands, and scripts. Use whenever something is slow, down, dropping, flapping, unreachable, mis-behaving on the wire, or you need to plan/scale a monitoring sensor fleet.
-
drolu Bundle HallmarkAnti-AI-slop design skill for greenfield pages, audits, redesigns, and design extraction from URLs or screenshots. Use when the user asks to build a new app or landing page, wants to redesign something, invokes Hallmark by name, or uses audit/redesign/study.
-
drolu Bundle CasperproEnterprise-grade penetration testing framework using curl + mitmproxy + playwright + python stack for comprehensive web application and API security assessment with traffic interception, browser automation, automated exploitation, WAF bypass, CVSS scoring, and compliance reporting
-
znlgis Skill GeoserverUse when deploying OGC-compliant map services (WMS, WFS, WMTS, WCS) or configuring SLD styling, security, and tile caching. GeoServer: the leading open-source Java map server for publishing spatial data to the web.
-
ziadnagar Bundle Security AuditUse this skill when the user asks to review code for security vulnerabilities, harden an application, audit authentication or authorization logic, check for OWASP Top 10 issues, review secrets management, or assess dependency security. Triggers for 'is this secure', 'security review', 'find vulnerabilities', 'audit this code', 'check for injection', 'harden this', 'review auth logic', or 'check dependencies for CVEs'. Covers web application security, API security, input validation, cryptography usage, and secure configuration.
-
urjuyaimon09 Bundle Openclaw GogGog Google Workspace CLI for Gmail, Calendar, Drive, Contacts, Sheets, and Docs. MIT-0 · Free to use, modify, and redistribute. No attribution required. ⭐ 783 · 135k · 3k current installs · 3k all-time installs by Peter Steinberger · @steipete MIT-0 Security Scan VirusTotal VirusTotal Benign View report → OpenClaw OpenClaw Suspicious medium confidence The skill's instructions look like a legitimate Google Workspace CLI, but the registry metadata and SKILL.md disagree about required binaries/install, and the skill asks you to supply OAuth credentials and run local commands — verify the source before installing or granting account access. Details ▾ ℹ Purpose & Capability The SKILL.md describes a Google Workspace CLI (Gmail, Calendar, Drive, Contacts, Sheets, Docs) and its commands — that purpose aligns with the actions shown. However the registry metadata shown to the platform lists no required binaries or install spec, while the SKILL.md includes metadata that requires the 'gog' binary and e
-
urjuyaimon09 Bundle Openclaw ImsgImsg iMessage/SMS CLI for listing chats, history, watch, and sending. MIT-0 · Free to use, modify, and redistribute. No attribution required. ⭐ 18 · 11.5k · 963 current installs · 981 all-time installs by Peter Steinberger · @steipete MIT-0 Security Scan VirusTotal VirusTotal Suspicious View report → OpenClaw OpenClaw Benign medium confidence The skill's instructions and requirements line up with an iMessage/SMS CLI for macOS, but you should verify the third‑party Homebrew tap and be cautious granting Full Disk Access and Automation permissions. Details ▾ ✓ Purpose & Capability The name/description (iMessage/SMS CLI) match the runtime instructions which call the 'imsg' CLI to list chats, history, watch, and send. Requiring Messages.app to be signed in and macOS permissions (Full Disk Access and Automation) is consistent with reading/sending Messages data. ✓ Instruction Scope SKILL.md only instructs using the 'imsg' CLI and documents expected flags and macOS permissions. It does no
-
urjuyaimon09 Bundle Openclaw GeminiGemini Gemini CLI for one-shot Q&A, summaries, and generation. MIT-0 · Free to use, modify, and redistribute. No attribution required. ⭐ 46 · 25.3k · 1.2k current installs · 1.2k all-time installs by Peter Steinberger · @steipete MIT-0 Security Scan VirusTotal VirusTotal Benign View report → OpenClaw OpenClaw Suspicious medium confidence The skill is generally consistent with a thin wrapper around the Gemini CLI, but there are metadata inconsistencies (SKILL.md advertises a required 'gemini' binary and a brew install while the registry metadata lists no requirements/install), so verify the CLI source before installing. Details ▾ ℹ Purpose & Capability The name/description (Gemini CLI for Q&A/summaries/generation) match the SKILL.md instructions which invoke a local 'gemini' binary. However the top-level registry metadata claims no required binaries or install spec, while SKILL.md's embedded metadata lists requires: ['gemini'] and a brew install for 'gemini-c
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include 04-audit, 07-refactor, aidd-dev:03:audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.