Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
vanducng Skill Computer CleanAudit and reclaim disk space on macOS. Discovers cache hogs, dev caches, dead app data, old Downloads, dup installers, and obsolete container/VM images. Use when user says 'clean disk', 'free up space', 'computer-clean', 'cleanup mac', 'disk full', or shows ≥85% disk usage.
Audited -
tommylower Bundle Emil Design EngDesign-engineering craft and motion advisor. Use for UI polish, animation decisions, motion-only review, a codebase motion audit with implementation plans, or finding restrained animation opportunities.
-
tommylower Skill Interface SoundDesign and implement tasteful interface sound for web apps using @web-kits/audio or Web Audio. Use when the user asks for UI sounds, sound effects, audio feedback, button clicks, success tones, error tones, notification sounds, procedural audio, sound patches, or wants to audit whether sound belongs in an interface.
-
tommylower Bundle Wip Senior Auditwip-senior-audit
-
island-dev-crew Bundle Measurement HumilityStanding review obligation for every enforced metric - each one must name the behaviour it might corrupt and carry a date on which its threshold is re-examined, so a coverage number with no named way to game it, and a threshold nobody has revisited in years, both surface as breaches instead of as a green build. Reach for it when adding or inheriting a metric gate, when auditing the gates a repo already runs, or when someone says "is this threshold still right", "what could this gate corrupt", "nobody has looked at that number in years", "metric review date", "our coverage gate is theatre". Differentiator - this island owns a metric's own review obligation and nothing else; the CRAP formula belongs to crap-gate, retuning a number by experiment to threshold-port, and catching gamed coverage to coverage-gaming-audit.
-
island-dev-crew Bundle Coverage Gaming AuditAudit a green coverage number for tests that execute code without asserting on it - assertion-free tests, assertions only on mocks, swallowed exceptions, unreviewed snapshots - and route every finding to the mutation run that settles it. Reports by default - on an audit or diagnosis ask the finding list is the deliverable, the fix-until-green loop is not entered, and deleting a test is never interchangeable with adding the missing assertion. Reach for it when a coverage report or CRAP score goes green and you do not yet believe it, when inheriting a suite of unknown quality, or when someone says "is this coverage real", "assertion-free tests", "gamed coverage", "100% coverage but nothing is tested", "audit this test suite". Differentiator - this island owns detection of gamed coverage and the routing to mutation; the score being distrusted belongs to crap-gate and the mutation run that proves the case belongs to mutant-hunt.
-
l3-igrant Skill Igrantio API API KeysAPI Key group of the iGrant.io OID4VC API: create, update, delete, and list the API keys of an organisation, and bind a key to a sandbox organisation. Covers the scope enum (config, audit, service, onboard), the 30-day expiry fallback, the fact that every answer carries the full signed token, and the token rotation that create, update, and bind each cause. Use when you provision server-side credentials for the OpenID4VCI and OpenID4VP endpoints, or when a key must run against a sandbox wallet.
Audited -
l3-igrant Skill Igrantio Dcql Query Pda1DCQL query template for the Portable Document A1 (PDA1), the EU social security attestation that says which member state legislation applies to a posted or multi-state worker. It asks a wallet for the six sections of the form, in dc+sd-jwt, jwt_vc_json or mso_mdoc (doctype org.iso.18013.5.1.pda1). Use this skill when you build labour inspection, posted worker checks or cross-border payroll on an EUDI Wallet, and you need the exact credential type and claim paths from the iGrant.io verifiable data registry.
Audited -
l3-igrant Skill Igrantio Credential Schema Pda1Claim path pointer schema for the Portable Document A1 (PDA1) credential, the EU social security document that states which member state legislation applies to a worker. Holds the registry documents for the dc+sd-jwt, jwt_vc_json and mso_mdoc formats, with all six PDA1 sections: personal data, applicable legislation, status confirmation, employer or self-employed activity, work places, and the issuing institution. Use this skill when you build a PDA1 credential definition for the iGrant.io OpenID4VC API, or when you need the exact PDA1 claim path.
Audited -
aradotso Skill Haiou Claude PersonalityInstall and manage Seagull 2.0 personality for Claude Code - a custom Chinese security researcher persona with 1700+ examples and 200+ security terms
-
aradotso Skill Claude Code Ultimate GuideMaster Claude Code with this comprehensive guide covering architecture, workflows, security, methodologies (TDD/SDD/BDD), 271-question quiz, and 181 production templates
-
aradotso Skill Haiou Claude Personality ModInstall and manage Haiou 2.0, a custom personality configuration for Claude Code that transforms it into "Seagull" — a direct, no-nonsense Chinese security researcher persona
-
ldilov Bundle Security ScanDefensive review checklist for secrets, auth boundaries, input validation, and package safety.
-
ldilov Bundle Impact Analysisuniversal change impact analysis for software, infrastructure, data, api, schema, configuration, ui, security, and operational work. use when evaluating a proposed or implemented change, diff, migration, dependency upgrade, rollout, hotfix, refactor, incident remediation, or architectural decision to determine what is affected, how much is affected, how risky the change is, which direct and indirect dependencies may break, which evidence supports the assessment, and what validation, rollout, and rollback plan is required.
-
grcengclub Skill Oscal ExpertExpertise on OSCAL (Open Security Controls Assessment Language) — what document types exist, when to use each, schema versioning, FedRAMP/eMASS/CSPM integration, round-trip workflows.
-
grcengclub Skill DrawioAlways use when the user asks to create, generate, draw, or design a diagram, flowchart, architecture diagram, ER diagram, sequence diagram, class diagram, network diagram, mockup, wireframe, UI sketch, GRC workflow, control map, audit process, risk register flow, compliance architecture, or mentions draw.io, drawio, drawoi, .drawio files, or diagram export to PNG/SVG/PDF.
-
grcengclub Skill Control TesterDesigns and documents control testing procedures. Creates test plans, executes walkthroughs, and documents results for audit workpapers.
-
grcengclub Skill Irap ExpertAustralian IRAP (Information Security Registered Assessors Program) expert. Provides guidance on ISM controls, Essential Eight maturity levels, ACSC guidelines, and Australian data sovereignty requirements.
-
grcengclub Skill Soc2 ExpertSOC 2 Trust Service Criteria expert. Provides guidance on Type I/II audits, control mapping, evidence requirements, and audit preparation for all Trust Service Categories.
-
grcengclub Skill Finding GeneratorGenerates professional audit findings using the Condition-Criteria-Cause-Effect format. Creates management letter comments and remediation recommendations.
-
grcengclub Skill Iso ExpertISO 27001 ISMS expert. Provides guidance on management system requirements, Annex A controls, certification process, and continuous improvement for information security.
-
grcengclub Skill Cis ExpertCIS Controls v8 expert for baseline security. Deep knowledge of 18 controls, 153 safeguards, Implementation Groups (IG1/IG2/IG3), and practical implementation guidance for organizations of all sizes.
-
grcengclub Skill Grc Portfolio PlannerGRC-specific portfolio questionnaire that creates a site-config.json and SITE-PLAN.md tailored to GRC engineers — certifications, frameworks, audit experience, tools, and projects.
-
grcengclub Skill Exec Narrative PatternsAudience-specific tone and format guidance for leadership communications. Use when drafting any /report:* output to tune length, framing, and technical depth to the reader (board, audit committee, CEO, weekly CISO, regulator).
-
grcengclub Skill Us Hipaa SecurityHIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.
-
grcengclub Skill Splunk Inspector ExpertInterpret splunk-inspector findings and translate Splunk retention, RBAC, audit, search ACL, and auth posture into compliance evidence and remediation.
Audited -
grcengclub Skill Datadog Inspector ExpertInterpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Audited -
blockmatic Skill Security AuditAudit the change or tree against the repository Security overlay and existing checks. Use when the user types /security-audit.
-
blockmatic Skill Security ReviewReview current code against the repository Security overlay; report evidence and remedies. Use when the user types /security-review.
-
mahdtech Skill Rfc ReviewReview an RFC or design doc for problem clarity (SCQA), compliance, security, and performance, and return the few most important issues. Use when reviewing someone's RFC or design proposal before it's approved.
-
mahdtech Skill Skill AuditPeriodically audit the whole skill collection for health - validate each skill's frontmatter, clarity, and category, verify every cross-reference resolves, and surface duplicates, conflicts, retirement candidates, and missing-skill gaps. Use when you want to audit or health-check the skills, spring-clean the collection, confirm the router and cross-references are accurate, or find skills to merge, split, retire, or create. Hands findings to /skill-creator to fix or create and /archive-skill to retire.
-
mahdtech Skill Archive SkillRetire a skill cleanly - move its directory from skills/<category>/ into skills-archive/<category>/, mark it archived in frontmatter with what replaced it, purge or redirect every inbound /skill-name reference (the router included), then re-run lint and sync. Use when you want to archive, deprecate, retire, remove, replace, or merge away a skill, or a /skill-audit flagged one for retirement. Covers when to archive vs delete vs merge and how to avoid dangling references. Cross-references /skill-creator and /skill-router.
-
mike007jd Skill Gsp Feel AuditUse when auditing control feel, responsiveness, timing, camera reaction, or animation feedback in a game.
-
mike007jd Bundle Gsp OrchestratorUse when a request needs routing across this Game Superpowers collection for build, audit, repair, or polish work.
-
mike007jd Skill Gsp Project AuditUse when running a top-level audit of an existing game project before repair or major changes.
-
mike007jd Skill Gsp UX Flow AuditUse when auditing first-minute onboarding, menus, fail/retry flow, or player comprehension in a game.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include computer-clean, emil-design-eng, interface-sound. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.