Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
yue-zhou1 Skill Crypto Audit ContextBuilds initial audit context for ZK and cryptographic code before vulnerability hunting. Use when starting a crypto audit, mapping trust boundaries, prioritizing code paths, or applying dimensional analysis to protocol values.
-
yue-zhou1 Skill Crypto Report WriterWrite final audit findings for ZK and cryptographic reviews. Use when a finding has survived verification and needs to be turned into clear report prose with severity, impact, root cause, and test evidence.
-
yue-zhou1 Skill Side Channel AuditorAudit timing, cache, memory-access, and power-analysis leakage patterns, including compiler and feature-flag regressions that break constant-time assumptions.
-
yue-zhou1 Skill Dkg Threshold AuditorAudit DKG, threshold-signature, and FROST/MuSig-style code for rogue-key, nonce-binding, share-verification, and session-isolation failures. Use when reviewing key aggregation, VSS share checks, threshold reconstruction, or concurrent signing state.
-
yue-zhou1 Skill Hash Function AuditorAudit ZK-friendly hash functions (Poseidon, Rescue, MiMC, Pedersen) for parameter selection, sponge construction, domain separation, and algebraic attack resistance.
-
yue-zhou1 Skill Pqc Signature AuditorAudit post-quantum signature implementations — ML-DSA (FIPS 204), SLH-DSA (FIPS 205), FN-DSA/Falcon (pending standardization), and stateful hash signatures XMSS/LMS/HSS (NIST SP 800-208) — for rejection-sampling correctness, hedged/deterministic signing modes, verification bound enforcement, and one-time-signature state management. Use when reviewing PQ signing, verification, or OTS index/state persistence.
-
yue-zhou1 Skill Folding Scheme AuditorAudit folding scheme and IVC implementations for accumulator soundness, step circuit binding, cycle-of-curves correctness, and running instance completeness. Use when reviewing Nova, HyperNova, ProtoStar, or custom folding-based proof systems in Rust.
-
yue-zhou1 Skill Ethereum Crypto AuditorAudit Rust application code that uses Ethereum cryptography. Use when reviewing secp256k1/ECDSA usage, keccak/EIP-712 hashing, BN254/BLS12-381 precompile interaction, KZG/EIP-4844 patterns, or alloy/ethers-rs API usage.
-
yue-zhou1 Skill Threshold Ecdsa AuditorAudit threshold ECDSA implementations (GG18, GG20, CGGMP21, Lindell-style) for Paillier modulus validity, MtA/MtAwc range-proof gaps, share-conversion soundness, resharing and concurrent-session isolation, and identifiable-abort leakage. Use when reviewing multi-party ECDSA keygen, signing, or resharing.
-
yue-zhou1 Skill Onchain Verifier AuditorAudit Solidity, Vyper, or Huff proof-verifier contracts for pairing precompile misuse, missing scalar-field checks on public inputs, calldata decoding errors, and verification-key provenance or upgrade risks. Use when reviewing on-chain SNARK/STARK verifier contracts or EIP-196/197/2537 precompile call sites.
-
yue-zhou1 Skill Privacy Protocol AuditorAudit shielded-pool and mixer protocol logic: nullifier derivation, uniqueness, and spent-set semantics; note/value commitments and ownership binding; deposit/withdraw front-running; and state-transition replay domains. Use when reviewing privacy-protocol design above the circuit and Merkle layers.
-
yue-zhou1 Skill Signature Scheme AuditorAudit classical signature schemes — generic ECDSA across curves, Schnorr/ BIP-340, EdDSA/Ed25519, RSA-PSS and PKCS#1 v1.5 — for verification-equation correctness, malleability, canonical encoding, public-key validation, and hash/prehash semantics. Use for standalone signature library review outside Ethereum application encoding, BLS, or threshold protocols.
-
yue-zhou1 Skill Commitment Scheme AuditorAudit polynomial commitment schemes (KZG, FRI, IPA, Pedersen) for degree bound enforcement, evaluation proof verification, trusted setup provenance, and batch opening soundness.
-
yue-zhou1 Skill Encryption Scheme AuditorAudit encryption implementations for AEAD nonce handling, decrypt oracle behavior, associated-data binding, key-derivation misuse, and decrypt-error side effects.
-
yue-zhou1 Skill Formal Verification BridgeBridge validated audit findings into optional external formal-verification tooling (Ecne, Picus, Circomspect) with explicit environment checks, reproducible exports, and tool-scoped caveat capture.
-
yue-zhou1 Skill Differential Test Harness GenGenerate cross-implementation differential test harnesses for cryptographic code: official test-vector and Wycheproof replay, normalization of error/result semantics, deterministic corpus capture, and evidence handoff to crypto-fp-check. User-triggered only — never auto-invoked by the audit flow.
-
skills-agents-co Skill Expense Access AuditGenerate the onboarding or offboarding checklist for the expense/card tool, and audit it against the HRIS to catch terminated people with active cards or missing approvers. Use on a new hire, a termination, or a periodic access review.
-
skills-agents-co Skill Equity ReconciliationReconcile equity records against the HRIS to catch termination-date mismatches and active grants for terminated employees. Use periodically and before any capital raise or audit.
-
skills-agents-co Skill Code ReviewerReviews code for bugs, security issues, performance problems, and style — with specific, actionable feedback
-
kaiohenricunha Skill Security ReviewAnalyze a diff or changed files for common security vulnerabilities (injection, XSS, SSRF, secrets). Defaults to staged changes. Triggers on: "security review", "check for secrets", "vulnerability scan".
-
kaiohenricunha Bundle Terragrunt SpecialistDeep-dive Terragrunt hierarchy review, DRY pattern audits, and run-all orchestration analysis. Use for structured investigations of multi-environment Terragrunt layouts, dependency graphs, remote state config, and hook correctness. Triggers on: "Terragrunt audit", "run-all review", "dependency block", "DRY pattern review", "env hierarchy audit", "mock_outputs", "terragrunt hooks".
-
socketdev Bundle UpdatingRun repo maintenance: updates, lockstep, submodules, security, coverage, audits.
-
socketdev Bundle Auditing GhaAudit Actions permissions/allowlists against the fleet baseline; --conform fixes drift.
-
socketdev Bundle Patching FindingsFix verified security findings with minimal patches and independent review before validation.
-
socketdev Bundle Scanning SecurityRun AgentShield, zizmor, and Socket dependency scans into a graded security report.
-
socketdev Bundle Triaging FindingsVerify raw security findings, dedupe them, rerank exploitability, and assign owners.
Audited -
socketdev Bundle Updating SecurityResolve Dependabot alerts by bumping, overriding, patching, or dismissing with evidence.
-
socketdev Bundle Auditing API SurfaceAudit package exports for dead, internal-only, or weakly-consumed subpaths before pruning.
-
dss-time Bundle Safe Code ReviewReview a concrete diff or PR through three independent axes: repository conformance, change-intent fidelity, and operational safety, then deduplicate evidence-backed findings. Use automatically for broad change review, not specialist-only security, performance, API, or migration assessment. Read-only: never implement fixes without a separate explicit request and write authorization. 通过仓库符合度、变更意图忠实度和运行安全三个独立轴审查具体 Diff 或 PR,再对有证据的问题去重。适合自动承接广泛变更审查,不吸收单一安全、性能、API 或迁移专项。本 Skill 只读;没有独立明确请求和写权限时绝不实施修复。
-
dss-time Bundle Repo Doctor RouterExplicit routing entrypoint that recommends one verified Repo Doctor Skill and fast, standard, or audit mode from the current repository state, or returns a registered workflow when detailed routing is requested. Use only when the user explicitly invokes the Router or asks for Repo Doctor routing. Do not execute the recommendation, route ordinary factual questions, invent aliases, or bypass permission gates. 显式路由入口:根据当前仓库状态推荐一个已核验 Repo Doctor Skill 及 fast、standard 或 audit 模式;用户要求详细路由时再返回注册工作流。仅在用户显式调用 Router 或明确要求 Repo Doctor 路由时使用。不得执行推荐、路由普通知识问答、编造别名或绕过权限门禁。
-
dss-time Bundle Configuration AuditExplicit-invocation audit of configuration sources, precedence, overrides, defaults, validation, drift, dangerous settings, undocumented variables, and credential-commit risk using repository evidence. Do not trigger for one settled config edit, read sensitive values, connect to external environments, or modify configuration. 仅显式调用:基于仓库证据审计配置来源、优先级、覆盖、默认值、校验、漂移、危险设置、未文档化变量和凭据误提交风险。不得因一个已确定配置修改而触发,不读取敏感值、不连接外部环境,也不修改配置。
-
dss-time Bundle Skill Quality AuditPerform a strictly read-only, pre-release quality audit of one AI Skill, a Pack, a plugin, or a Skills repository across structure, triggering, workflow, progressive resources, bilingual cross-platform output, safety, and publishing integration. Use when maintainers want findings, severity, evidence, and a release recommendation; do not audit ordinary application code or PRs, run a broad project health check, gate a product release candidate, or automatically fix files. 对一个 AI Skill、Pack、插件或 Skills 仓库执行严格只读的发布前质量审计,覆盖结构、触发、工作流、渐进资源、双语跨平台产物、安全和发布集成。维护者需要发现、严重度、证据和发布建议时使用;不用于普通应用代码或 PR 审查、广泛项目体检、产品候选版本门禁,也不自动修复文件。
-
dss-time Bundle Project Health CheckExplicit-invocation broad repository diagnosis across architecture, correctness, security, performance, dependencies, tests, and general release risk. Do not trigger for a bounded file, error, diff, or simple request. Use a specialized review for one dependency upgrade, API contract, migration, dead-code candidate, security surface, performance regression, configuration scope, or release candidate. 仅显式调用的全仓库诊断,覆盖架构、正确性、安全、性能、依赖、测试和一般发布风险。不得因单个文件、明确报错、Diff 或简单请求而触发。单一依赖升级、API 契约、迁移、死代码候选、安全边界、性能回归、配置范围或候选版本应使用对应专项 Skill。
-
dss-time Bundle Requirements To SpecConvert requirements whose material product, data, security, permission, compatibility, and acceptance decisions are already closed into a structured, implementable, testable specification. Use when a clarification summary or settled discussion is ready for specification and only non-blocking assumptions remain; stop and route material open decisions to requirements-clarification. Do not use for task decomposition, implementation planning, code explanation, bug fixing, or direct edits. 将产品、数据、安全、权限、兼容性和验收等重大决策已经闭合的需求整理为结构化、可实施、可验证的规格。用于已有澄清摘要或讨论已定稿、只剩非阻塞假设时;发现重大未决决策必须停止并转交 requirements-clarification。不用于拆工作项、制定实施计划、解释代码、修 Bug 或直接修改。
-
dss-time Bundle Security Focused ReviewExplicit-invocation scoped security review that establishes assets, trust boundaries, attacker prerequisites, and evidence-backed findings across the named security surface. Do not trigger for general code review, run attacks, access production, reveal credentials, or implement fixes. 仅显式调用:针对指定安全边界建立资产、信任边界和攻击前提,并输出有证据的专项发现。不得因普通代码审查而触发,不执行攻击、不访问生产、不显示凭据,也不实施修复。
-
dss-time Bundle Dependency Upgrade AnalysisExplicit-invocation analysis of one defined dependency upgrade using manifests, lockfiles, repository usage, and verified official release evidence, covering compatibility, security, licensing, validation, and rollback. Do not trigger for ordinary code changes or modify manifests or lockfiles. 仅显式调用:基于 manifest、锁文件、仓库用法和已验证官方发布资料分析一个已定义的依赖升级,覆盖兼容、安全、许可证、验证和回滚。不得因普通代码变更而触发,也不修改 manifest 或锁文件。
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include crypto-audit-context, crypto-report-writer, side-channel-auditor. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.