Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
asymmetric-al Bundle NPM Deps CleanupAudit and reduce JavaScript package dependency footprint across npm, pnpm, Yarn, and Bun projects. Use when asked to remove unused dependencies, deduplicate workspace dependency versions, lockfiles or node_modules, analyze direct dependencies' transitive lockfile closure, find low-risk upgrades that reduce dependency trees, inline trivial dependencies, or apply e18e dependency replacement recommendations.
-
asymmetric-al Bundle Payloadcms PayloadPayload CMS application development (collections, fields, hooks, access control, Local/REST/GraphQL queries, adapters, plugins). Vendored from payloadcms/skills. Use when editing payload.config.ts, Payload collections, admin, or debugging validation, security, relationships, transactions, or hooks in this repo.
-
asymmetric-al Bundle Stripe Best PracticesGuides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial accounts, integration surfaces (Checkout, Payment Element), migrating from deprecated Stripe APIs, and security best practices (API key management, restricted keys, webhooks, OAuth). Use when building, modifying, or reviewing any Stripe integration — including accepting payments, building marketplaces, integrating Stripe, processing payments, setting up subscriptions, creating connected accounts, or implementing secure key handling.
-
urjuyaimon09 Bundle Openclaw CamsnapCamsnap Capture frames or clips from RTSP/ONVIF cameras. MIT-0 · Free to use, modify, and redistribute. No attribution required. ⭐ 9 · 11.8k · 963 current installs · 985 all-time installs by Peter Steinberger · @steipete MIT-0 Security Scan VirusTotal VirusTotal Suspicious View report → OpenClaw OpenClaw Suspicious medium confidence The skill mostly matches its camera-capture purpose, but there are inconsistencies (missing declared config/install requirements) and a few moderate risks you should check before installing. Details ▾ ℹ Purpose & Capability The skill's stated purpose (capture frames/clips from RTSP/ONVIF) aligns with the commands shown (snap, clip, watch) and the need for ffmpeg and a camsnap binary. However the registry metadata reported no install spec or config paths, while the SKILL.md explicitly refers to ~/.config/camsnap/config.yaml and a Homebrew formula—an inconsistency in declared requirements. ℹ Instruction Scope SKILL.md only instructs use of the camsnap CLI and mentions creat
-
urjuyaimon09 Bundle Openclaw GifgrepGifgrep Search GIF providers with CLI/TUI, download results, and extract stills/sheets. MIT-0 · Free to use, modify, and redistribute. No attribution required. ⭐ 6 · 13.2k · 1k current installs · 1k all-time installs by Peter Steinberger · @steipete MIT-0 Security Scan VirusTotal VirusTotal Benign View report → OpenClaw OpenClaw Benign high confidence The skill's runtime instructions and install hints are consistent with a GIF search/download tool; the only issues are minor metadata mismatches in the registry (env/binary requirements not declared there). Details ▾ ℹ Purpose & Capability SKILL.md describes a CLI/TUI tool (gifgrep) that searches GIF providers, downloads results, and extracts stills/sheets. The instructions and declared install options (brew formula and Go module pointing to github.com/steipete/gifgrep) match that purpose. However, the registry metadata summary provided to you earlier said no required binaries/env vars, while SKILL.md metadata requires the gifgrep binary and documents G
-
urjuyaimon09 Bundle Openclaw GoplacesGoplaces Query Google Places API (New) via the goplaces CLI for text search, place details, resolve, and reviews. Use for human-friendly place lookup or JSON output for scripts. MIT-0 · Free to use, modify, and redistribute. No attribution required. ⭐ 27 · 16.3k · 1.1k current installs · 1.1k all-time installs by Peter Steinberger · @steipete MIT-0 Security Scan VirusTotal VirusTotal Benign View report → OpenClaw OpenClaw Suspicious medium confidence The skill's runtime instructions (SKILL.md) reasonably describe a Google Places CLI that needs a Homebrew install and a GOOGLE_PLACES_API_KEY, but the registry metadata claims no required binaries or env vars—this inconsistency and the third-party Homebrew tap recommendation merit caution. Details ▾ ℹ Purpose & Capability The SKILL.md describes a goplaces CLI that queries the Google Places API and requires the goplaces binary and a GOOGLE_PLACES_API_KEY—these are appropriate for the stated purpose. However, the registry-level 'Requirements' sec
-
urjuyaimon09 Bundle Openclaw ObsidianObsidian Work with Obsidian vaults (plain Markdown notes) and automate via obsidian-cli. MIT-0 · Free to use, modify, and redistribute. No attribution required. ⭐ 274 · 66.1k · 2k current installs · 2.1k all-time installs by Peter Steinberger · @steipete MIT-0 Security Scan VirusTotal VirusTotal Suspicious View report → OpenClaw OpenClaw Suspicious medium confidence The skill's instructions are plausible for automating Obsidian via obsidian-cli, but there are several inconsistencies and privacy-relevant actions (reading a user config file) that aren't declared or explained. Details ▾ ℹ Purpose & Capability The SKILL.md describes exactly the expected functionality (use obsidian-cli to operate on Obsidian vaults). However the skill registry metadata at the top of the package claims no required binaries or install steps, while the embedded SKILL.md metadata requires the 'obsidian-cli' binary and even provides a brew install. This mismatch between declared requirements and the runtime inst
-
urjuyaimon09 Bundle Openclaw Apple NotesApple Notes Manage Apple Notes via the `memo` CLI on macOS (create, view, edit, delete, search, move, and export notes). Use when a user asks Clawdbot to add a note, list notes, search notes, or manage note folders. MIT-0 · Free to use, modify, and redistribute. No attribution required. ⭐ 43 · 24.5k · 1.1k current installs · 1.1k all-time installs by Peter Steinberger · @steipete MIT-0 Security Scan VirusTotal VirusTotal Benign View report → OpenClaw OpenClaw Benign medium confidence The skill is internally coherent with its stated purpose (controlling Apple Notes via the memo CLI) but the registry metadata and the SKILL.md differ on some details and the install uses a third‑party Homebrew tap — review before installing. Details ▾ ℹ Purpose & Capability The skill's name and description match the SKILL.md: it uses the memo CLI to manage Apple Notes (create/view/edit/delete/search/move/export). However, the top-level registry metadata provided to you lists no required binaries or OS restriction while S
-
userinner Bundle Security And HardeningHardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party services. Use when personal data or privacy compliance (GDPR, CCPA) is involved.
-
userinner Bundle Make Paper Explainer VideoResearch, fact-check, script, voice, visualize, render, verify, and package a sourced vertical explainer about a scientific paper or current technology, business, crypto, legal, or security event. Use when Codex must autonomously select or turn a paper, preprint, DOI, arXiv link, PDF, research topic, company event, founder story, shutdown, lawsuit, invention, security incident, or reversal into a Douyin, Xiaohongshu, WeChat Channels, TikTok, or Reels-style video; replace generic AI or stock visuals with primary-source pages, charts, filings, cases, and annotations; improve retention, narration, claims, pacing, cover, or platform copy; or prepare a multi-platform publishing package with AI-content disclosure.
-
userinner Bundle Springboot SecuritySpring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
-
kora-projects Bundle Kora HTTP Server AuthHTTP server auth in Kora — HttpServerPrincipalExtractor, Principal/PrincipalWithScopes, SecurityException→403 via interceptor. Use when securing @HttpController endpoints or integrating an OpenAPI security scheme. For client-side auth see kora-http-client-auth.
-
keyvaluesoftwaresystems Skill Hld InterviewClarify material architecture decisions before an HLD is finalized. Generate feature-specific technical Grill questions, audit prior answers and contradictions, and collect grouped answers without drafting design prose.
-
keyvaluesoftwaresystems Skill Lld InterviewClarify only material repository implementation decisions before one repo LLD is written. Audit existing answers, inspect the bounded implementation seam, and ask feature-specific questions in grouped native popups.
-
keyvaluesoftwaresystems Skill Backend ReviewReview the backend implementation — security, contract adherence, correctness, backward compatibility, rate-limiting, performance/scaling, migrations, test gaps, observability. Read-only; writes a review artifact. Front door for /backend-review.
-
keyvaluesoftwaresystems Skill Backend ImplementImplement an approved backend scope against the cross-repo contract, test-first, meeting the backend engineering standards (security, backward compatibility, rate limiting, idempotency, migrations, observability, performance). Edits code within the approved scope only. Front door for /backend-implement.
-
cyberuni Bundle ManageUse this skill when doing manage-level (non-mission) SDD work on the spec corpus — bootstrap, inspect, audit, or housekeeping — such as "set up the project spec", "backfill the spec", "list the SDD specs and statuses", "audit the corpus structure", "check for spec/suite drift", or "retire completed mission plans". Routes to the matching engine; it does not change what the project specifies (that is start-mission).
-
chendongqi Skill Information Security Data Security数据安全助手 - 专业的数据保护与隐私合规专家。适用场景: (1) 数据分类分级与标识 (2) 数据安全策略制定 (3) 数据加密与脱敏方案 (4) 数据泄露防护(DLP) (5) 隐私合规(GDPR/个保法) (6) 数据安全审计与评估 (7) 数据生命周期管理 触发关键词:数据安全、数据保护、数据分类、数据加密、脱敏、DLP、隐私合规、GDPR、个保法、数据泄露、数据审计
Audited -
chendongqi Skill Information Security Security Strategist安全策略助手 - 专业的企业安全体系规划与治理专家。适用场景: (1) 企业安全战略规划 (2) 安全架构与框架设计 (3) 安全政策与制度制定 (4) 安全合规体系建设(等保/ISO27001) (5) 安全风险评估与管理 (6) 安全培训与意识提升 (7) 安全成熟度评估 触发关键词:安全策略、安全架构、安全合规、等保、ISO27001、安全治理、安全风险、安全制度、安全培训、安全评估、零信任
Audited -
chendongqi Skill Information Security Security Incident Response安全事件响应助手 - 专业的安全事件处置与应急响应专家。适用场景: (1) 安全事件识别与分类 (2) 应急响应计划制定 (3) 事件调查与取证分析 (4) 遏制与根除方案设计 (5) 系统恢复与业务连续性 (6) 事件复盘与改进建议 (7) 安全事件报告撰写 触发关键词:安全事件、应急响应、事件处置、入侵检测、安全告警、取证分析、恢复计划、事件复盘、安全报告、勒索软件、数据泄露
Audited -
praxstack Skill MaintainBrain health checks: back-link enforcement, citation audit, filing validation, stale info detection, orphan pages, and benchmarks. Use when asked to check brain health, run maintenance, or audit quality.
-
praxstack Skill KingmodePrincipal-engineer routing guidance with three reasoning depths — Default, ULTRATHINK, and KINGMODE. Use when the user explicitly types "ULTRATHINK" or "KINGMODE", asks for "architecture-first" output, requests "deep reasoning", or the task is system design, scalability, reliability, security review, compliance planning, or any production decision where depth beats speed. Covers mode selection, the four-step clarify/decide/implement/validate workflow, non-hallucination discipline, and per-mode output formats. Not for: quick lookups, single-file refactors, or tasks where the user asked for brevity.
-
praxstack Bundle SuperimproveRun a bounded, evidence-first audit-fix-review-verify loop on a codebase when the user asks to improve, harden, overhaul, or fix all confirmed defects. Use only with explicit edit authority in a git repository. Do not use for advisory-only reviews, a single narrow bug, or when the worktree is dirty and the owner has not chosen how to preserve it.
-
praxstack Bundle Company BrainifyExtract a sanitized shared team/company brain from a personal brain. Strips internal ratings, compensation, performance assessments, retention and political dynamics from pages, takes, and facts across the full scan scope (people, companies, meetings, dailies, cross-references — not just people/), verifies with grep + retrieval passes, and purges sensitive git history behind the data-loss-gate confirmation card. Also runs as a report-only re-audit on an existing shared brain.
Audited -
praxstack Bundle Principal EngineerArchitecture governance, design review, and code-merge gatekeeping for senior/staff/principal-level technical oversight. Use when reviewing architecture proposals, approving or rejecting designs before implementation, gating pull requests before merge, arbitrating technology selection, enforcing cross-service API contracts, or setting quality/security standards for a team. Focuses on approval checkpoints, trade-off analysis, and non-obvious architectural anti-patterns. Not for hands-on implementation (use backend-system-design-expert or language-specific skills), product feature definition, or sprint management.
-
praxstack Bundle QA Security EngineerQuality assurance plus security engineering for software products. Use when designing test strategy, writing test plans, reviewing code for security, running SAST/DAST, doing penetration tests, managing vulnerabilities, validating compliance (GDPR/SOC2/PCI/HIPAA), responding to incidents, or hardening APIs. Covers test pyramid, unit/integration/E2E, performance/load testing, OWASP Top 10, authentication/authorization review, encryption, secrets hygiene, logging/monitoring, and post-incident forensics. Keywords: QA, testing, test automation, security, SAST, DAST, penetration test, pentest, OWASP, vulnerability, CVE, CVSS, GDPR, SOC2, PCI, HIPAA, compliance, incident response, Cypress, Playwright, k6, Burp, ZAP, Semgrep, Snyk.
-
praxstack Bundle Ultra Reasoning OperatorScope-calibrated ultra-rigor workflow for hard reasoning, high-risk code changes, architecture decisions, debugging with multiple plausible root causes, security-sensitive work, and user requests like "ultra reasoning", "think harder", "verify everything", "adversarial review", "war room", "deep check", "paranoid verifier", or "no hallucinations". Use to force evidence-first planning, assumption tracking, hypothesis falsification, adversarial self-review, verification gates, and clear uncertainty without overloading trivial tasks.
-
praxstack Bundle Backend Principle Eng Java Pro MaxPrincipal backend engineering intelligence for Java services and distributed systems. Actions: plan, design, build, implement, review, fix, optimize, refactor, debug, secure, scale backend code and architectures. Focus: correctness, reliability, performance, security, observability, scalability, operability, cost.
-
praxstack Bundle Backend Principle Eng Nodejs Pro MaxPrincipal backend engineering intelligence for Node.js runtime systems. Actions: plan, design, build, implement, review, fix, optimize, refactor, debug, secure, scale backend code and architectures. Focus: correctness, reliability, performance, security, observability, scalability, operability, cost.
-
praxstack Bundle Backend Principle Eng Python Pro MaxPrincipal backend engineering intelligence for Python services and data systems. Actions: plan, design, build, implement, review, fix, optimize, refactor, debug, secure, scale backend code and architectures. Focus: correctness, reliability, performance, security, observability, scalability, operability, cost.
-
praxstack Bundle Backend Principle Eng Javascript Pro MaxPrincipal backend engineering intelligence for JavaScript services. Actions: plan, design, build, implement, review, fix, optimize, refactor, debug, secure, scale backend code and architectures. Focus: correctness, reliability, performance, security, observability, scalability, operability, cost.
-
praxstack Bundle Backend Principle Eng Typescript Pro MaxPrincipal backend engineering intelligence for TypeScript services. Actions: plan, design, build, implement, review, fix, optimize, refactor, debug, secure, scale backend code and architectures. Focus: correctness, reliability, performance, security, observability, scalability, operability, cost.
-
harshsinghmp Skill Muse CaptureAutonomous post-fix and architectural decision distillation. Captures atomic, verified knowledge units with inline Vibeguard secret defense and supersedes outdated patterns.
-
harshsinghmp Skill Agency Code ReviewerExpert code reviewer who provides constructive, actionable feedback focused on correctness, maintainability, security, and performance — not style preferences.
-
harshsinghmp Bundle Code ReviewA language-agnostic code review method derived from Linus Torvalds' review corpus. Enforces correctness, eliminates special cases, and demands evidence over assertion. Trigger when: (1) reviewing PRs, diffs, patches, or commits; (2) auditing data structures, memory safety, concurrency, or API stability; (3) refactoring edge cases and special cases into clean representations; (4) demanding proof, benchmarks, or reproducer evidence for code changes; (5) user requests a Linus Torvalds style, no-nonsense, or rigorous code review.
-
harshsinghmp Skill Agency Autonomous Optimization ArchitectIntelligent system governor that continuously shadow-tests APIs for performance while enforcing strict financial and security guardrails against runaway costs.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include npm-deps-cleanup, payloadcms-payload, stripe-best-practices. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.