Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
deangrant Bundle API Security Best PracticesApply OWASP API Security Top 10 practices for REST APIs: TLS, BOLA, authn/authz separation, rate limits, secrets hygiene, and least privilege. Use when hardening APIs or running a security design review.
-
jpcaparas Bundle Scaffold HooksRun /scaffold-hooks to audit, create, or refresh shared repository hooks for Claude Code, Codex, GitHub Copilot, Devin CLI, and OpenCode, together or individually. Skip Git hooks and Husky.
-
jpcaparas Bundle Claude Code Auto AdvisorClaude Code automatic advisor for security, reviews, high-risk design, substantial multi-step plans, complex refactors, recurring failures, and risky completion checks. Skip trivial work, ordinary planning, other harnesses, or sessions without an advisor tool.
-
jpcaparas Bundle Simplified Technical EnglishRewrite or audit ASD-STE100 procedures, descriptions, and safety instructions while preserving technical meaning and exact literals.
-
jpcaparas Bundle Package AuditorAudit installable skill packages for release-blocking structure and verification gaps.
-
jpcaparas Skill Notification AuditorAudit notification configuration and delivery evidence without sending messages.
-
cloudposse Skill Code HygieneReviews code changes for architectural smells that mechanical checks (lint, tests, coverage) structurally can't catch: duplicated 'shared' abstractions, missing sentinel errors, generics that discard their own type info, self-aware nolint suppressions of mandated rules, business logic in the wrong layer, admitted-but-unshipped gaps, config/flags that validate but silently no-op or always error, features that are implemented but never wired up, and documentation/code mismatches in either direction (docs describing an unimplemented or since-changed feature, or a shipped feature with no docs at all). Distinct from the general code-review skill (bugs/security/perf) and from lint (mechanical/syntactic) — this catches CLAUDE.md architectural-mandate violations that need reading intent, not just syntax. Patch-scoped against origin/main by default; a full-repo sweep runs only on an explicit human request. Invoke on explicit requests like "check for vibe coding" / "run code hygiene" / "audit this PR's architecture", o
-
cloudposse Skill Security RemediateFix open Dependabot and CodeQL/code-scanning alerts directly on the current branch. Triggered automatically by the security-remediate-trigger PostToolUse hook after a git push where GitHub reports open vulnerabilities; can also be invoked manually. Never opens a new PR or issue - commits land on the branch that's already open.
-
natthasath Bundle Perspectiveให้มุมมองและข้อคิดที่แหลมคมจากหัวข้ออบรมหรือ workshop ใดๆ เขียนในเสียงของ Senior Engineer ที่มีประสบการณ์จริง ไม่ใช่ตำรา HR ใช้ skill นี้ทันทีเมื่อผู้ใช้ระบุหัวข้ออบรมหรือ workshop และต้องการมุมมองหรือข้อคิดจากผู้ปฏิบัติงานจริง เช่น "DevOps", "Cyber Security", "Agile", "Project Management" หรือหัวข้ออบรมใดก็ตาม เรียกใช้ผ่าน `/perspective` เท่านั้น — ไม่ auto-trigger จากบทสนทนา
-
maziyarpanahi Skill Auditing Deidentification RunsProduce a signed, reproducible, no-PHI audit trail for an OpenMed de-identification run via deidentify(audit=True). Use when the user needs compliance evidence, a tamper-evident record of what was redacted and why, to verify nothing was changed, to retain proof for HIPAA/GDPR audits, or to review de-id decisions without exposing plaintext PHI. Covers the AuditReport / AuditSignature / AuditSpan / DetectorInfo fields, why audits store offsets+hashes+provenance+residual-risk and never plaintext, signing with .sign(key), and verifying with .verify(key). Pairs with OpenMed deidentifying-clinical-text and auditing-safe-harbor-checklist.
Audited -
medy-gribkov Bundle Code ReviewerCode review workflow for local changes and remote PRs. Reviews focus on correctness, maintainability, security, and test coverage with concrete examples and inline comments.
-
medy-gribkov Bundle Container SecurityContainer security from build to runtime. Image scanning, minimal base images, rootless execution, secrets management, supply chain verification, and runtime policies with concrete Dockerfile examples.
-
vaquarkhan Skill Data Reconciliation And Financial ControlsGuides agents through reconciliation and control design for business-critical data. Use when validating financial, operational, or audit-sensitive metrics with source-to-target totals, control balances, exception tracking, or close-process dependencies.
-
vaquarkhan Skill Data Security Compliance And Regulated DataGuides agents through regulated-data security and compliance workflows for PII, PCI, HIPAA, PHI, and similar obligations. Use when data products handle sensitive fields, regulated records, control evidence, or audit-bound publish paths.
-
vaquarkhan Skill Esg And Sustainability Regulatory ReportingGuides agents through ESG, sustainability, and regulatory reporting data products. Use when building governed metrics, traceable evidence, and audit-ready data pipelines for frameworks such as CSRD/ESRS, BRSR, climate disclosures, or similar sustainability reporting obligations.
-
search-atlas-group Bundle Bug HunterSweep every client site and Google Ads account for real, client-visible errors — broken links, disapproved ads, dead tracking tags, broken redirect chains. Use when the user says "run my bug hunt", "sweep my clients", "check my client sites for errors", "audit my Google Ads accounts for problems", or wants to know what's broken before a client finds it. Read-only — never edits, pauses, or posts anything.
-
search-atlas-group Skill Ladder AuditAudit this machine against the Agentic Ladder and report where the member stands — system score, tier progress, the rung they operate at, the defensible floor beneath it, any holes, and the one next thing to build. Use when someone asks to run their ladder audit, check their agentic level, see what rung they are on, find out what they are missing, re-check their setup after building something, or asks "how agentic am I". Reads the local machine only; nothing is uploaded.
-
search-atlas-group Bundle Token OptimizerFind the ghost tokens. Audit Claude Code or Codex setup, see where context goes, fix it. Use when context feels tight.
-
search-atlas-group Skill Internal Linking AuditorAudit a brand's internal linking structure — sampling up to 50 URLs from the site (via sitemap if available, otherwise discovered from key nav and content pages), map the internal link graph, identify pillar and cluster pages, and diagnose structural issues including orphan pages, missing pillar-to-cluster and cluster-to-pillar links, thin internal link density, non-descriptive anchor text, broken internal links, and cross-topic contamination that dilutes topical signals. Produces a prioritized fix list with specific source-page → target-page link recommendations in context, not a generic "add more links" advisory. Use this skill whenever a user asks about internal linking, site architecture, topic clusters implementation, pillar pages, information architecture audit, siloing, link equity distribution, orphan pages, "why isn't Google finding this page," or when the Entity & Topical Authority Mapper has produced a topic tree but the brand's existing internal linking doesn't match it. Chains opportunistically w
-
search-atlas-group Skill Review Response ReputationHandle a brand's review response workflow and reputation management program — draft specific, personalized responses to positive/neutral/negative reviews across Google, Yelp, Facebook, and industry-specific review platforms; design an FTC-compliant review generation program that asks for reviews without incentivizing sentiment; diagnose reputation threats (review bombing, fake-review campaigns, defamatory content); and establish a sustainable sentiment-tracking and response cadence. Hard-enforces FTC Consumer Reviews Rule (16 CFR Part 465, effective Oct 21, 2024) and platform TOS throughout — no fake reviews, no sentiment-gated incentives, no review suppression, no AI-pasted responses. Use this skill whenever a user asks about review responses, reputation management, review strategy, Google review replies, negative review handling, review generation, getting more Google reviews, handling a one-star review, review gating, or when GBP Competitor Audit flagged review volume, rating, freshness, or response rate a
-
xonovex Bundle Code Quality GuideUse when auditing existing code for quality WITHOUT changing it: a read-only pass that finds smells, grades them by severity, and routes each to its owner. Triggers on robustness or hardening, duplication, dead code, over-abstraction, complexity, magic numbers, inconsistent implementations, barrel exports, redundant comments, shared-extraction candidates, TODO/FIXME inventory, or a code-smell audit, even when the user doesn't say 'audit' or 'code quality'.
-
xonovex Bundle Credential Management GuideUse when choosing, storing, injecting, rotating, revoking, or responding to exposure of machine-to-machine credentials and secrets: the tokens a service, workload, or CI job presents to another system. Triggers on API tokens, PATs, client secrets, keychains, secret managers, masked CI variables, workload identity federation, OIDC, `.env` secret handling, credential rotation, or leaked credentials, even when the user doesn't say 'credential management' and names only a provider-specific token.
-
liberty91ltd Skill Threat AssessmentStructured threat assessment methodology. Intent + Capability + Opportunity = Threat Level. Use when formally evaluating a threat.
-
liberty91ltd Skill Lookup CrowdstrikeUse when you need CrowdStrike Falcon Intelligence on an indicator (IOC reputation for an IP, domain, hash, or URL — malicious confidence, linked actors, malware families, reports) OR on an adversary (threat-actor profile, origin/target search, MITRE ATT&CK TTPs, finished intel reports). Answers questions like "look up 1.1.1.1", "what TTPs does Charming Kitten use?", "which threat actors operate from Russia?", and "latest report on Mustang Panda". Commonly invoked by the four /*-investigation skills, /ioc-enrichment-workflow, /threat-actor-profiling, and the regional espionage cells. Other agents/skills can chain this for vendor-authoritative actor and finished-intel context. Requires a Falcon Intelligence subscription.
-
liberty91ltd Skill Writing AssessmentsUse when the user asks to write a threat / risk / vulnerability assessment, or wants the appropriate template for each type. Distinct structures and section ordering per assessment kind.
-
liberty91ltd Skill Intelligence WritingUse when writing a finished intelligence product, the user asks for a flash-report / threat-assessment / briefing / FINTEL template, or wants the BLUF + active-voice + clear-sourcing conventions. Covers all product types.
-
liberty91ltd Skill Lookup ReversinglabsUse when you need authoritative classification, threat-name, MITRE ATT&CK mapping, dynamic-analysis or sandbox results on a file hash, or when you need network threat intelligence for a URL/domain/IP from ReversingLabs Spectra Analyze (A1000). Returns verdict, risk score, AV detection ratio, threat name, behavioural tags, and pivot candidates (parent containers, extracted files, related samples by family). Commonly invoked by /hash-investigation and /malware-analysis. Other agents/skills can chain this for deeper malware enrichment beyond VirusTotal.
-
liberty91ltd Skill Threat Actor ProfilingUse when the user asks to build or update a threat-actor profile, "tell me about actor X" / "profile actor Y", or another skill needs the canonical profile template (attribution, TTPs, campaigns, infrastructure patterns, intelligence gaps).
-
liberty91ltd Skill Control Coverage MappingUse when you need to answer "which attacker techniques do our controls actually stop, and how well?", "what controls should I have for this threat?", or "what telemetry should I collect to detect it?" — joining a customer's or your own security control baseline to ATT&CK techniques using a public, versioned evidence base of 9,545 control-to-technique mappings from six sources. Produces four ranked lists (addressed strongly, addressed weakly, real gaps, and techniques no control anywhere addresses). Use for control gap analysis, security programme prioritisation, board reporting on coverage, or the Resistance Strength side of a FAIR risk assessment. Invoke after /threat-actor-profiling or /lookup-liberty91 has produced a technique list.
-
lingtai-ai Skill Environment VariablesProgressive-disclosure route to the root canonical environment-variable registry. Use the registry for names, defaults, behavior, ownership, and security notes.
-
vs4vijay Skill Gsd Audit UatCross-phase audit of all outstanding UAT and verification items
-
vs4vijay Skill Gsd Ns Reviewquality gates | code review debug audit security eval ui
-
vs4vijay Skill Gsd Code ReviewReview source files changed during a phase for bugs, security issues, and code quality problems
-
vs4vijay Skill Gsd Eval ReviewAudit an executed AI phase's evaluation coverage and produce an EVAL-REVIEW.md remediation plan.
-
vs4vijay Skill Gsd Secure PhaseRetroactively verify threat mitigations for a completed phase
-
vs4vijay Skill Gsd Validate PhaseRetroactively audit and fill Nyquist validation gaps for a completed phase
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include api-security-best-practices, scaffold-hooks, claude-code-auto-advisor. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.