Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
vs4vijay Skill Gsd Audit MilestoneAudit milestone completion against original intent before archiving
-
zedarvates Bundle TrendsTrack a project's audit metrics over time (directive score, duplication, LOC, always-on cost, fix count) and show the change since the previous run. Use to see whether the project is getting healthier/cheaper across audits.
-
kwakseongjae Bundle Omd Feel디자인·프론트 업계가 '감'으로 쓰던 인터페이스 디테일을 수치화한 규칙으로 적용(APPLY)하거나 감사(AUDIT)한다. Jakub Krehel의 make-interfaces-feel-better 철학을 계승 + HIG/Material/WCAG/DS 토큰/실무자 리서치로 확장한 17축·113규칙(provenance 등급별). 모션 타이밍·이징·동심원 radius·tabular-nums·44px 타깃·focus ring·prefers-reduced-motion 등. 'feel 좋게 다듬어줘', '인터페이스 디테일 적용', 'feel 점검', '마이크로 인터랙션 손봐줘', 'make this feel better', 'polish the interactions', 「インターフェースの細部を詰めて」, 「介面細節打磨」 류에 트리거. 브랜드 토큰은 DESIGN.md(omd:apply)가 우선.
-
kwakseongjae Bundle Omd Slop Audit실제 제품 route의 UI·UX copy를 검사해 제품 맥락 없이 반복된 생성형 기본 패턴, 브랜드 근거 없는 장식, 카드·그라데이션·아이콘 타일 남용, 번역투와 추상 카피를 rule ID와 line ref로 진단한다. 'AI slop 잡아줘', '템플릿 같아', '왜 AI가 만든 화면 같지?', 'anti-slop audit' 요청에 사용한다. 접근성 오류와 취향 차이를 별도 등급으로 구분한다.
-
kwakseongjae Bundle Omd Orchestrator멀티 에이전트 디자인 워크플로우 supervisor. writer, locale adaptation, humanize, UI slop audit, designer review, final QA, image materialization을 routing한다. 2-round revision cap을 유지하며 다국어 문서·UI 개선·출간 준비처럼 여러 역할이 필요한 요청에 사용한다.
-
farmountain Bundle Security IamSkill: Security & IAM Domain Expert
-
nearai Skill Btc Dominance AlertWatches Bitcoin dominance (BTC's share of total crypto market cap) and alerts the user on Telegram only when it crosses a key threshold: below 60% reads as a possible altcoin-season signal, above 65% as BTC dominance expanding. Between 60% and 65% it stays silent. Each check is logged to memory as an audit trail, and it only alerts on an actual threshold crossing, never on every run.
-
prone-dc302 Skill Alterlab Nmc Digital EthicsThis skill should be used when the user asks about "digital ethics", "media ethics", "AI ethics", "platform governance", "misinformation", "disinformation analysis", "act as a digital ethics advisor", "digital ethics mode", "algorithmic bias", "data privacy", "content moderation", "ethical framework", "deepfake", "surveillance", "fact-checking tools", "verification workflow", "platform audit", "ethics stress test", "algorithmic accountability", "informed consent", "digital rights", "tech regulation", or needs expertise in analyzing ethical dilemmas in digital media, AI, and platform ecosystems. Part of the AlterLab FC Skills collection (New Media & Communication department).
-
wyattowalsh Bundle ReviewUse for session, scoped, PR, range, full audit, simplification, and source/provenance reviews with evidence-first findings. NOT for feature implementation or benchmarking.
-
wyattowalsh Bundle PentestAuthorized pentest planning with mandatory ROE scope gate. Synthesizes phase checklists and findings. NOT for static audit (security-scanner), CTF labs (ctf-*), or C2/webshell tooling.
-
wyattowalsh Bundle Skill RouterRoute tasks to local skills. Use when choosing skills, recovering omitted skills after context warnings, or preparing a small skill context packet. NOT for install, authoring, or audit workflows.
-
wyattowalsh Bundle Security ScannerProactive security assessment with SAST, secrets detection, dependency scanning, and compliance checks. Use for pre-deployment audit. NOT for code review (review) or pen testing.
-
wyattowalsh Bundle Skill Tag TaxonomistInfer and audit skill tags from names, descriptions, and catalog authoring rows. Use when organizing catalog taxonomies. NOT for live catalog index edits.
-
wyattowalsh Bundle Incident Response EngineerOperational incident response for triage, containment, communications, recovery, and postmortems. Use when coordinating outages or service degradation. NOT for code review or proactive security scanning.
-
metagit-ai Skill Metagit Release AuditMandatory before calling work complete when the session changed repo files. Runs format, lint, tests, integration tests, context-aware pip-audit/bandit, and optional gitleaks via task qa:prepush. Use before push, release, or hand-off.
-
soden46 Skill SecurityRun focused Laravel security checks for authorization, request forgery, rate limits, uploads, secrets, APIs, and configuration.
-
soden46 Bundle Memory ManagementRecall, checkpoint, and audit durable Laravel project knowledge across sessions when prior context materially affects the current task.
-
soden46 Skill Responsive UI TestingAudit Laravel responsive UI with Playwright across mobile, tablet, desktop, Livewire states, overflow, clipping, forms, tables, modals, and navigation.
-
dtsong Bundle Mcs Run And OperateUse when running /council, /ship, /looper, or /handover day to day in this repo: choosing a council mode or --profile, resuming/listing/archiving a session, picking a Phase 5 execution path (team, ralf, launch, deep audit, issues export, Ship), reading or resuming .claude/ship-state.md or .claude/looper-state.md, writing a handover, or checking for an in-flight ship/council run before touching .claude/ state so you do not clobber it. Not for diagnosing why a hook or gate is silently failing (mcs-debugging-playbook) or for commit/PR/change-classification rules (mcs-change-control).
-
dtsong Skill Hw Security SignoffUse when a hardware design needs security sign-off before tape-out. Defines the builder-to-auditor handoff contract between Foundry (constructive design) and Forge (security review). Covers security review prerequisites, artifact checklist, sign-off criteria, and conditional approval workflow. Do not use for RTL security review itself (use rtl-security-review) or design flow guidance (use foundry/chip-design-flow).
-
njs14 Bundle WizardGenerate a runnable guide for human-only setup or migration steps, with hidden secret entry and safe repeatable updates. Use when login, account UI, or human judgment prevents direct automation.
-
njs14 Skill Maintain Verification SkillAudit and update an existing verification workflow against current user-visible behavior while preserving scope, safety, and executable proof.
-
timdevai Skill Aims AuditAims Audit
-
timdevai Bundle DossierDecision-grade entity research skill — produces a hypothesis-tested dossier on a specific company, person, nonprofit, or government org, not a generic profile. Forcing intake makes the user state their hypothesis upfront (what they already believe and want to verify or disprove) so the dossier tests it rather than confirms it. Output is an editable Word document (.docx) with verdict on the hypothesis, identity facts, 12-month activity timeline, network signals, reputation signals, red flags, 3-5 conversation hooks tied to specific findings, and source-provenance audit log. Uses WebSearch + WebFetch + free APIs (SEC EDGAR, GitHub, ProPublica Nonprofit Explorer) as workhorses; optional BYOK MCPs (LinkedIn, Crunchbase, Apollo, Pitchbook, SimilarWeb) enhance coverage. Triggers: 'research [company]', 'dossier on [person/company]', 'background check on [entity]', 'prep me for a meeting with [person/company]', 'due diligence on [company]', 'what should I know about [entity]', 'research [person] before I [meet/hire/i
-
timdevai Skill Soc2 Audit PrepSoc2 Audit Prep
-
timdevai Skill Fda Qsr Audit PrepFda Qsr Audit Prep
-
timdevai Skill Iso13485 Audit PrepIso13485 Audit Prep
-
timdevai Skill Iso27001 Audit PrepIso27001 Audit Prep
-
lgwanai Skill Gsd Ns Reviewquality gates | code review debug audit security eval ui
-
lgwanai Skill Gsd Code ReviewReview source files changed during a phase for bugs, security issues, and code quality problems
-
lgwanai Skill Gsd Eval ReviewAudit an executed AI phase's evaluation coverage and produce an EVAL-REVIEW.md remediation plan.
-
lgwanai Skill Gsd Secure PhaseRetroactively verify threat mitigations for a completed phase
-
lgwanai Skill Gsd Validate PhaseRetroactively audit and fill Nyquist validation gaps for a completed phase
-
lgwanai Skill Gsd Audit MilestoneAudit milestone completion against original intent before archiving
-
clawic Skill Code Hygiene AuditAudit ClawJS/Clawix code hygiene without editing code, producing categorized findings, baseline status, and validation evidence.
Audited -
clawic Skill Secrets Boundary ReviewReview secret handling, brokered execution, redaction, vault boundaries, host approval, and public hygiene.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include gsd-audit-milestone, trends, omd:feel. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.