Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
kai-cli Bundle SecupdatesSecurity news aggregation from tldrsec, no.security, and other sources. USE WHEN security news, security updates, what's new in security, breaches, security research, sec updates. SkillSearch('secupdates') for docs.
-
kai-cli Skill InvestigationOSINT and people-finding — structured investigations, company intel, due diligence, and ethical people search across public records and social media. USE WHEN OSINT, due diligence, company intel, background check, find person, locate, people search, reconnect, public records, reverse lookup, social media search, verify identity, domain lookup, entity lookup, organization lookup, company lookup, threat intel.
-
kai-cli Bundle WebassessmentWeb security assessment. USE WHEN web assessment, pentest, security testing, vulnerability scan. SkillSearch('webassessment') for docs.
-
zereight Skill RedesignUpgrade an existing website or app to premium quality without breaking functionality — audit the current design, identify generic/AI tells, then apply taste and system rules surgically. Use when the user wants to improve, modernize, polish, or "make better" an existing UI/codebase.
-
zereight Skill ContinuityLearn, record, audit, and apply codebase patterns consistently across a repository by comparing current code to canonical local examples and a repo-local pattern registry. Use when asked to preserve continuity, learn a pattern, check drift, fix inconsistent implementations, migrate code to a local convention, or produce a CI-friendly continuity report.
-
zereight Skill Design ReviewReview or audit a design/UI across 6 weighted dimensions with Nielsen's 10 heuristics and a prioritized findings table. Use when the user wants a design critique, quality score, heuristic evaluation, or audit of an existing screen, page, or product before/after build.
-
zereight Bundle Zereight ReviewComprehensive code review skill for practical PR feedback. Use for feature, bugfix, and refactor reviews. Prioritizes correctness, edge cases, dual-path symptom fixes vs delete-a-path alternatives, logic invariants, async state, flow ownership, ponytail simplicity, motion craft, test quality, OWASP, and actionable feedback.
-
zereight Skill Zereight Debt LogLog an ambiguous or uncertain finding from a code review into a running technical-debt ledger instead of blocking the review on it. Use when a reviewer is unsure whether something is actually wrong ("애매하다", "아리까리하다", "확신이 안 선다", "이건 일단 부채로") and wants to note it and move on rather than raise a blocking comment or start a full audit. Companion to zereight-review. Not for full-repo debt sweeps (see the jjw013/tech-debt-skill audit) and not for ponytail's own deliberate-shortcut markers (see ponytail-debt).
-
pproenca Bundle Feature WorkflowApply whenever the task is to build, add, implement, or extend a FEATURE, endpoint, screen, flow, or job in an existing application — not a one-line fix. Enforces plan-before-code: a completed docs/plans plan must pass the gate (scripts/plan_check.py) before any implementation begins. Drives the inner loop (compose this feature from the existing substrate, build only what's missing, place it via the boundary-discipline skill) and the outer loop (grow the reusable substrate via a promotion ratchet). Use this whenever someone says "build/add/implement X", "plan this feature", "how should I structure this feature", or is about to start writing feature code. Do NOT skip the gate because the feature "seems small"; the gate is what prevents duplication and entanglement. For a pure code review with no new feature, use boundary-discipline AUDIT mode directly instead.
-
pproenca Bundle Boundary DisciplineApply when working on software robustness through "boundaries" — the points where data changes status (untrusted→proven, decided→done, proposed→authoritative, risky→bounded). THREE MODES: AUDIT (find undefended or misplaced boundaries in existing code and report them), IMPLEMENT (place boundaries correctly while building a NEW feature/endpoint/handler/job), and REFACTOR (relocate a known-misplaced boundary, behavior-preserving). Use this whenever the task touches request/queue/webhook handlers, parsing or validation, side effects (DB writes, payments, email, external APIs), transactions or race conditions, or any "where should this validation/check/effect/lock live" question — and whenever someone wants to make invalid states unrepresentable or shrink a blast radius. Select the mode BEFORE doing anything; do NOT audit the codebase when the task is to build a feature.
-
rongxinzy Bundle Process DocDocument a business process — flowcharts, RACI, and SOPs. Use when formalizing a process that lives in someone's head, building a RACI to clarify who owns what, writing an SOP for a handoff or audit, or capturing the exceptions and edge cases of how work actually gets done.
-
rongxinzy Skill Audit SupportPrepare audit-ready request trackers, evidence indexes, walkthroughs, control test workpapers, sample support, and issue responses. Use for internal or external audit support and SOX-style control testing.
-
rongxinzy Skill Finance WorkflowsCoordinate multi-step finance and accounting work across financial statements, journal entries, reconciliations, close, audit support, and variance analysis. Use when a request spans multiple finance processes or needs a controlled workpaper plan.
-
fudesign2008 Bundle Code Design ReviewAuthoritative framework for reviewing the design quality of proposed code changes — before implementation. Evaluates architecture-level quality attributes (testability, modularity, reliability, scalability, dependency direction via ISO 25010 + Clean Architecture + SDP) and code-level metrics (accidental complexity, coupling via Myers/Connascence, cohesion, change amplification, tech debt, cyclomatic/cognitive complexity, Law of Demeter) plus a security pass (OWASP Top 10). Use this skill whenever a proposed solution involves code changes and you need to assess whether the code is well-designed — not just whether it works, but whether it is maintainable, testable, and does not introduce design debt. Triggers — 「代码审查」「代码设计审查」「代码设计质量」「审查代码设计」「代码架构审查」「设计质量评估」「代码质量评审」「这个代码设计合理吗」「耦合度审查」「代码可维护性」 / code design review, code architecture review, design quality assessment, coupling analysis, maintainability review.
-
fudesign2008 Bundle Tech Research WorkflowEnd-to-end technology and competitor research workflow that turns a design-shaping question into a decision-ready, evidence-bound report family: self business audit (asset/hazard inventory with file:line), competitor first-hand runtime testing (five-step evidence method, evolution curves, same-track incident search), three-tier design mapping (copy / copy-the-idea / explicitly-not-copy), reflux loop (first version as constraint probe), layered reports, plus a lean path for single-question research. Triggers — 「技术调研」「竞品调研」「竞品分析」「技术调研报告」「调研报告」「竞品实测」 / tech research workflow, competitor research, competitive analysis, technology research report. Do NOT use for single-question web lookup without design output (use research / effective-web-research), known-bug upstream research routing (known-issue-research), or rewriting an existing design doc into a review doc (tech-review-doc).
-
jaygptpro Skill Amz Competitor AnalysisRun a full competitor analysis for an Amazon product. Compares listings, pricing, images, reviews, ratings, and ad presence against direct competitors, finds the weaknesses to exploit and the strengths to neutralize, and outputs a prioritized attack plan. Use when a user asks to analyze competitors, compare their listing to a rival, find a competitor's weak spots, understand why a competitor outranks them, or plan how to beat a specific ASIN. Trigger phrases: "competitor analysis", "analyze my competition", "beat this competitor", "why is this ASIN ranking", "compare my listing". Works with zero tools. the user pastes competitor listing details and reviews.
-
jaygptpro Skill Amz Attributes CompleterAudit and complete the Amazon Seller Central Attributes section for a listing. Diffs the category template against the filled fields, ranks the missing fields by impact on AI-driven search (Rufus, Alexa+) and traditional ranking, and proposes the optimal values. Use when a user asks about the Attributes section, missing attributes, product attributes, category fields, or "how to fill the back end of my listing". Trigger phrases: "attributes", "attributes section", "category fields", "back end fields", "missing attributes". Works with zero tools.
-
jaygptpro Skill Amz Listing Indexation AuditAudits whether an ASIN is indexed for its top 30 target keywords on Amazon search. Builds a heatmap and diagnoses root cause per missing keyword. A listing can be live but invisible for 40% of its target terms, this finds the gap. Use when a user asks about indexation, why their ASIN does not show up, or organic ranking failure. Trigger phrases: "Amazon indexation check", "ASIN not ranking", "indexed keywords", "why isn't my listing showing up". Works with zero tools.
-
fdiblen Bundle Rseng Code ReviewCovers reviewing existing code and whole projects, not just new diffs: structured codebase audits that produce ranked findings and then implement the agreed improvements, recurring project reviews after major tasks and milestones, review scoping by risk and tier, and turning review findings into tracked work and lessons. Use PROACTIVELY after major tasks and milestones, and when the user asks for a code review, codebase audit or health check of existing code, wants improvements suggested and applied, mentions reviewing the project after a milestone or before a release or submission, or when inherited or long-unreviewed code needs a structured pass. For diff-time pre-review of new work see rseng-pair-programming; for PR-time review process and rules see rseng-version-control-review.
-
fdiblen Bundle Rseng License ComplianceCovers license compliance engineering: auditing the full dependency tree's licenses, compatibility analysis (permissive vs weak vs strong copyleft, GPL interactions, combining and linking), dual and multi-licensing, SPDX expressions and REUSE-compliant repositories, attribution and NOTICE obligations, and license policy in CI. Use when the user asks whether dependencies' licenses are compatible, wants a license audit, considers dual licensing or relicensing, must satisfy GPL/LGPL obligations, mentions SPDX, REUSE, NOTICE files or license scanners, or needs a license recommendation under real constraints. (License basics and first-time license choice: rseng-licensing.)
-
fdiblen Bundle Rseng Dependency ManagementCovers the full lifecycle of third-party dependencies: vetting a library before adoption on every axis that matters - suitability, license, trust and vulnerabilities including the transitive tree, documentation, maintenance and version currency - then keeping dependencies current with lockfiles and automated updates, and replacing them when they rot. Use PROACTIVELY whenever a new dependency is about to be added, when dependencies are outdated or unpinned, when the user asks whether a library is safe or well chosen, mentions dependabot/renovate, transitive dependencies or version pinning, or when an audit is due. (Finding candidates: rseng-software-reuse; deep license analysis: rseng-license-compliance; lockfile mechanics: rseng-reproducible-environments.)
-
mizchi Bundle Dep Lib ReviewPeriodic dependency review for Node.js/pnpm projects — outdated package triage, security audit, update batching strategy (patch/minor/major), validation checklist. Run monthly or before major releases. Use when asked to review or update dependencies in a repo.
-
mizchi Bundle Chezmoi ManagementMeta-skill for mizchi's chezmoi dotfiles. Invoke ONLY when the user explicitly asks to manage / diff / apply chezmoi sources, add a skill to dotfiles, audit the APM vs chezmoi boundary, or initialize a new machine. Covers source location, diff/apply flow, skill addition, pre-push (pkfire + secretlint). Do NOT auto-invoke when the task only happens to touch a path under ~/.claude/, ~/.config/, or ~/.zshrc — consult only on explicit dotfile-management intent.
-
mizchi Bundle Optimizing DescriptionsMeta-skill for auditing and rewriting SKILL.md `description` fields per the agentskills.io optimizing-descriptions framework, layered with mizchi's two-track trigger policy (Meta = explicit-invoke-only, Project = pushy auto-trigger). Invoke ONLY when the user explicitly asks to "optimize a skill description," "audit descriptions," or "rewrite descriptions per agentskills." Do NOT auto-invoke after every SKILL.md edit; description tuning is a deliberate batch, not a per-edit reflex.
-
mizchi Bundle Utels Project BootstrapOne-shot helper for registering a utels.dev project and writing the returned ingest token straight into a wrangler secret. Use when wiring server-side error tracking for a Cloudflare Worker without leaking tokens through the shell.
-
tuya Bundle Smart Panel DevMaster / orchestrator skill for Tuya Ray panel miniapp development. Use this as the SINGLE ENTRY POINT for any panel miniapp task — it covers the full lifecycle (architecture → requirement → coding conventions → upload audit) and dispatches to category- or topic-specific sub-skills (ray-common, smart-ui, charts-library, socket-panel, lamp-panel, robot-vacuum, ipc-panel, electrician-timing, energy-stats, performance-ux-guard, requirement-guide) when deeper detail is needed. Anything from "how do I start a panel project" to "is this ready to upload" routes through here first.
-
servosity Bundle Msp Skills ConciergeUse when the user has msp-skills installed and wants help choosing or installing connectors - it reads the live catalog, learns their PSA/RMM/backup/security/billing stack, recommends the connectors that fit, and installs only the ones they approve. Trigger phrases: `recommend which connectors I should install`, `which msp-skills connector for my stack`, `set up the right connectors for me`, `concierge`, `msp-skills concierge`, `what connectors should I install`, `pick connectors for my MSP`, `using everything you know about me, recommend connectors`.
-
servosity Bundle NerdioThe first non-PowerShell client for the Nerdio Manager for MSP API - cross-account AVD fleet audits, async-job plumbing, and offline search no other Nerdio tool has. Trigger phrases: `list nerdio accounts`, `audit autoscale across customers`, `which AVD hosts are running`, `nerdio billing rollup`, `wait for nerdio job`, `use nerdio`, `run nerdio-cli`.
-
salesforcecommercecloud Bundle B2c EcdnManage eCDN zones, security settings, and edge configuration for B2C Commerce storefronts. Use this skill whenever the user needs to purge CDN cache, provision SSL certificates, configure WAF or firewall rules, set up rate limiting, enable logpush or Page Shield, manage MRT routing, configure mTLS or cipher suites, or optimize edge performance. Also use when troubleshooting CDN-layer issues or managing zone settings -- even if they just say 'clear the cache' or 'block bot traffic on our storefront'.
-
salesforcecommercecloud Skill B2c Bm Users RolesManage Business Manager users, access roles, role permissions, and per-user access keys on a B2C Commerce instance using the b2c CLI. Use this skill whenever the user needs to list or search BM users on a sandbox or production instance, identify which BM user an OAuth token resolves to ("whoami"), assign or revoke instance-level access roles, edit role permissions, look up a user's WebDAV / OCAPI / Storefront access key, or rotate access keys for SSO-managed users. Also use when the user asks "what's my BM login on sandbox X", "rotate my WebDAV password", "how do I make a custom BM role", "audit BM users on this instance", or "delete a stale BM user from a sandbox".
-
salesforcecommercecloud Bundle Sfnext ExtensionsBuild extensions for Storefront Next using target-config.json, target points, extension routes, and translation namespaces. Use when creating modular features, inserting components into UI targets, adding extension routes, adding a section to an existing page, or using SFDC_EXT_ integration markers. Covers the base-audit decision gate (deciding whether to extend at all vs token/variant override), extension structure, targetId configuration, and extension registration in src/extensions/config.json.
-
swestash Bundle Security AuditComprehensive security analysis — OWASP Top 10, auth/authz flows, injection vulnerabilities, data exposure, secrets detection, dependency CVEs, hardening recommendations. Reviews EXISTING code/config — design-time analysis of a system not yet built → threat-modeling.
-
swestash Bundle Code Slop CleanupStrip AI slop from a branch diff before PR — judge each hunk against the surrounding file's conventions, remove without changing behavior, re-run tests. Removal only: hunting bugs → code-reviewing; structural improvement → refactoring; repo-wide audit → technical-debt-review; pruning tests → test-suite-design.
-
swestash Bundle Compliance PrivacyEngineer for regulatory and privacy obligations — GDPR/CCPA privacy-by-design, PII data mapping and minimization, retention and deletion (right to erasure), data subject requests, consent, SOC 2 controls (access, change management, audit logging). Triggers: GDPR, CCPA, SOC 2, HIPAA, compliance, privacy review, PII, personal data, data retention, right to be forgotten, DSR, audit requirements, are we compliant. Vulnerabilities in code → security-audit; attack analysis of a design → threat-modeling.
-
swestash Bundle Dependency ManagementEvaluate, audit, and upgrade project dependencies — assess libraries before adoption, audit CVEs, plan major upgrades, resolve conflicts.
-
swestash Bundle Project DocumentationWrite project docs — README, contributing guides, API docs, changelogs, inline docs — and reconcile existing docs after a change made them wrong. Owns doc drift from the change in front of you; a repo-wide doc-rot audit belongs to technical-debt-review.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include boundary-discipline, feature-workflow, msp-skills-concierge. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.