Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
hack23 Skill Open Source PolicyOpen source governance, security posture badges, license compliance, SBOM generation, and vulnerability management for transparency-driven development
Audited -
hack23 Skill Crypto Best PracticesImplement strong encryption, secure hashing, and proper key management following NIST and OWASP cryptography guidelines
Audited -
hack23 Skill Security Architecture ValidationSecurity architecture review, control validation, penetration testing guidance, and compliance verification for the CIA platform
Audited -
hack23 Skill Hack23 Information Security PolicyHack23 Information Security Policy integration for SDLC — developer-facing mapping of ISP requirements to daily engineering activities, tooling, and evidence
Audited -
rweisssieker-xp Skill Evidence Pack AuditCreate audit-ready evidence packs with masking, chain of custody, evidence quality grades, and validation artifacts.
-
rweisssieker-xp Skill Admin Execution ModeGenerate guarded admin execution previews with policy gates, confirmation tokens, audit records, and rollback/validation metadata.
-
rweisssieker-xp Skill Web Portal OperationsConfigure, validate, or run the local AXPA RBAC web portal with token-based dashboard access and audit logging.
-
rweisssieker-xp Skill Management Report GeneratorGenerate executive and change-control reports for AX 2012 performance findings with risk, impact, evidence, recommendations, and audit-ready action plans.
-
rweisssieker-xp Skill Governance Extension AnalysisGenerate governance artifacts such as runbooks, RACI, business impact timeline, suppression governance, data quality checks, and audit exports.
-
cyberuni Bundle Improve SkillAudit, improve, or write a SKILL.md — check description trigger coverage, structure, security, and agentskills.io compliance. Use when reviewing or creating a skill for Claude Code, Cursor, Codex, Copilot CLI, or any agentskills-compatible runtime, even if the user says "my skill isn't triggering", "review before I publish", or "check this skill."
-
ferroxlabs Skill Ferrox Audit FixYou want issues found, classified, fixed, tested and committed without steering each one
37 -
ferroxlabs Skill Ferrox Audit UatYou want every outstanding verification item across all steps gathered in one place
37 -
ferroxlabs Skill Ferrox Ns Reviewquality gates | code review debug audit security eval ui
37 -
ferroxlabs Skill Ferrox Code ReviewYou want the code checked for bugs, security issues and quality before it goes anywhere
37 -
ferroxlabs Skill Ferrox Audit MilestoneA milestone looks done and you want it checked against what you originally asked for
37 -
yue-zhou1 Skill Fhe AuditorAudit FHE implementations for noise-budget accounting, bootstrapping correctness, modulus-switching safety, plaintext leakage, and key-switch parameter integrity.
-
yue-zhou1 Skill Mpc AuditorAudit MPC implementations for garbled-circuit integrity, oblivious transfer misuse, share validation, Beaver triple authenticity, and transcript/session binding issues.
-
yue-zhou1 Skill Vdf AuditorAudit VDF implementations for sequentiality assumptions, Wesolowski/Pietrzak verifier soundness, challenge derivation integrity, and modulus/group setup risks.
-
yue-zhou1 Skill Vrf AuditorAudit Verifiable Random Function implementations (RFC 9381 ECVRF and RSA-FDH-VRF) for key validation, ciphersuite/suite-string domain separation, encode-to-curve and cofactor handling, proof-to-hash ordering, and uniqueness/pseudorandomness assumptions, plus application-level output grinding. Use when reviewing VRF provers, verifiers, or consumers of VRF outputs (leader election, lotteries, randomness beacons).
-
yue-zhou1 Skill Audit CommonProvides shared severity, testing-evidence, and finding-contract references for ZK and cryptographic audit skills. Use when classifying findings, checking whether test evidence is sufficient, or writing findings in a consistent structure.
-
yue-zhou1 Skill Noir AuditorAudit Noir circuits for unconstrained function boundary failures, oracle validation gaps, Brillig/ACIR consistency issues, and witness-generation soundness bugs.
-
yue-zhou1 Skill Zkbugs IndexQueryable index of real-world ZKP vulnerabilities. Use when a Phase 2 audit skill identifies a suspicious pattern and needs to check whether a similar bug has been documented before — or when a confirmed finding needs to be recorded. Covers circom, noir, halo2, cairo, zkVM, and custom DSLs. Backed by upstream community corpus (zksecurity/zkbugs) and configurable organization findings repo.
-
yue-zhou1 Skill Zkvm AuditorAudit zkVM guest programs and proof systems for memory consistency, continuation proof soundness, precompile safety, and guest-host boundary violations across SP1, RISC Zero, and Valida.
-
yue-zhou1 Skill Cairo AuditorAudit Cairo and Starknet code for hint validation failures, felt252 overflow, builtin misuse, and Sierra-to-CASM soundness gaps. Use when reviewing Cairo contracts, prover hints, or Starknet-specific proof construction.
-
yue-zhou1 Skill Lattice AuditorAudit lattice-based cryptography for LWE/RLWE parameter soundness, noise sampling correctness, rejection-sampling safety, and decryption-failure assumptions.
-
yue-zhou1 Skill Pqc Kem AuditorAudit standardized post-quantum KEM implementations — currently ML-KEM / FIPS 203 — for encapsulation/decapsulation conformance, implicit-rejection correctness, ciphertext and key validation, compression/rounding, and decapsulation-failure oracle resistance. Use when reviewing ML-KEM/Kyber APIs, serialization, or decapsulation paths.
-
yue-zhou1 Skill Fuzz Harness GenGenerate cargo-fuzz targets for Rust cryptographic code. User-triggered only and never auto-invoked by the audit flow. Produces crash and edge-case evidence for crypto-fp-check.
-
yue-zhou1 Skill Kani Harness GenGenerate Kani proof harnesses for Rust crypto code. User-triggered only — never auto-invoked by the audit flow. Produces formal verification evidence for crypto-fp-check.
-
yue-zhou1 Skill Dependency AuditorAudit cryptographic dependency sets for vulnerable versions, security-significant feature flags, advisory coverage, transitive risk, and stale fork provenance.
-
yue-zhou1 Skill Randomness AuditorAudit randomness and nonce lifecycles: CSPRNG/DRBG initialization and reseeding, entropy availability, fork/clone/snapshot duplication, deterministic nonce derivation (RFC 6979, EdDSA), and reuse across retries, crashes, persistence, and concurrent state. Use when any secret-dependent random value's generation or lifetime is in question.
-
yue-zhou1 Skill Rust Crypto SafetyReview Rust cryptographic code for implementation-level security bugs. Use when auditing constant-time behavior, secret zeroization, panic and overflow hazards, unsafe blocks, unchecked constructors, feature flags, or dependency hygiene in crypto crates.
-
yue-zhou1 Skill Zk Circuit AuditorAudit ZK circuits, proof systems, and verifier code for soundness and transcript failures. Use when reviewing witness constraints, Fiat-Shamir flows, KZG/PCS setup assumptions, public input encoding, or recursive proof threading.
-
yue-zhou1 Skill Crypto Audit RouterRoute a full cryptographic or ZK audit across the framework. Use when you need to decide which skill should run next, which domain auditors apply, or how to move from initial context to verified finding, report, and index flow.
-
yue-zhou1 Skill Ecc Pairing AuditorAudit elliptic-curve, pairing, and BLS signature code for point-validation, subgroup, serialization, DST, and pairing-equation failures. Use when reviewing deserialization, `hash_to_curve`, aggregate verification, or batch pairing logic.
-
yue-zhou1 Skill Fiat Shamir AuditorAudit Fiat-Shamir transcript implementations for completeness, domain separation, challenge derivation order, and public input binding across interactive-to-non-interactive proof transforms.
-
yue-zhou1 Skill Merkle Tree AuditorAudit Merkle tree implementations for second-preimage attacks, leaf-node domain separation, sparse tree edge cases, and proof verification soundness.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include ferrox-audit-fix, ferrox-audit-uat, ferrox-code-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.