Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
stanestane Bundle Game Design Ftue Hero Journey AuditAudit a game's FTUE (First Time User Experience) through the lens of the Hero's Journey / monomyth. Use when reviewing onboarding, tutorial flow, first-session retention, first 30 seconds, early-session emotional hooks, mentor/tutorial character usage, first meaningful action, or whether an FTUE makes the player feel like the hero of the experience rather than a passive victim of UX chores.
-
stanestane Skill Game Design Player Motivation AuditAudit a game, feature, live-ops system, progression loop, social feature, or monetization surface using a Self-Determination Theory-inspired motivation framework. Use when evaluating what kind of motivation a design creates, comparing alternative motivational profiles, diagnosing why a system feels sticky, hollow, exhausting, or dead, checking overreliance on rewards and grind, or assessing whether a feature supports short-term activation, medium-term habit, or long-term player identity.
-
stanestane Bundle Game Design Multiplayer Feature AuditAudit a game, feature, live-ops layer, social system, or multiplayer concept for the quality and fit of its social design. Use when evaluating collaboration, competition, collaborate-to-compete structures, matchmaking, guilds/clubs, synchronous versus asynchronous play, realtime constraints, depth of social interaction, community formation, vanity/status systems, or how to add social play to a mostly single-player game.
-
stanestane Bundle Game Design Big Five Personality AuditAudit a game, feature, progression system, social system, live-ops loop, onboarding flow, monetization surface, or multiplayer space through the lens of the Big Five personality traits (OCEAN): Openness, Conscientiousness, Extraversion, Agreeableness, and Neuroticism. Use when evaluating which personality-style preferences a design feels comfortable for, which kinds of players it energizes or exhausts, how much structure, novelty, social intensity, conflict, or emotional pressure it creates, or when you need a personality-fit lens that is different from archetype or motivation-segment frameworks.
-
stanestane Bundle Game Design Fairness Frustration AuditAudit a game, feature, failure loop, combat encounter, reward system, progression wall, or high-variance mechanic for perceived fairness and frustration. Use when diagnosing whether players feel cheated, whether difficulty feels deserved, whether randomness, feedback, and challenge interact badly, or why a design remains technically functional yet still produces anger, blame, or refusal to retry.
-
stanestane Bundle Game Design Perceived Randomness AuditAudit a game feature, combat system, loot table, reward loop, procedural system, chance mechanic, or uncertainty-driven design by how players are likely to perceive its randomness. Use when you need to evaluate whether a system will feel fair, streaky, rigged, sabotaging, manipulable, or skill-undermining; when players may misread independent events as patterned; or when randomness may sit too close to player action and create frustration. Analyze expectation gaps, gambler's-fallacy-style reactions, hidden pattern-seeking, input-versus-output randomness, perceived fairness, exploit risk, and ways to reshape presentation or mechanics.
-
involvex Skill Nodejs Best PracticesNode.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.
-
valentinnikolaev Bundle Create MemoryBootstrap the first useful durable project-memory baseline from the current repository and its instructions when no usable memory index exists. Use for initial repository memory creation only; do not use to import an external source, record routine facts from ongoing work, audit an existing store, or replace a healthy baseline.
-
jhonatan-oliveiradev Skill Reviewing API SecurityUse when an authorized API or backend boundary needs security review for authentication, object/function/property authorization, resource abuse, business-flow abuse, SSRF, configuration, inventory, and third-party consumption.
-
jhonatan-oliveiradev Skill Reviewing Web SecurityUse when an authorized web application needs a structured security review across access control, sessions, browser-facing controls, input handling, configuration, cryptography, errors, and observability.
-
jhonatan-oliveiradev Skill Threat Modeling ApplicationsUse when a feature, service, or application needs security risks identified from its architecture, assets, trust boundaries, and abuse cases before implementation or release.
-
l4ci Bundle Concise WritingUse when the user wants to write or edit text so it is only as long as it needs to be and carries no signs of AI writing. Anchors to the purpose and reader, then runs the text down a cut ladder (delete whole units before trimming words), scans it against the compressed catalog of AI tells, and reads it aloud, looping draft to audit to final. Guards against over-trimming so the floor stays meaning, not word count. Triggers include "tighten this", "make it shorter", "cut the fluff", "less verbose", "trim this", "de-slop", "this sounds AI-written", "write a concise", "edit for length".
-
dragoon0x Skill M Layout AuditMap all layout patterns. Identify grid/flex, spacing, nesting depth, responsive breakpoints.
-
sylphxai Skill Run Incident ResponseCoordinate a production incident from declaration through mitigation, recovery, and learning. Use for live outages, elevated errors, security events, or material data-integrity risk.
-
stanestane Bundle Game Design Thinking Fast And Slow AuditAudit a game, feature, combat system, economy loop, onboarding flow, puzzle, UI, or design proposal through the lens of fast versus slow thinking inspired by Thinking, Fast and Slow. Use when evaluating whether a design relies on rapid intuitive judgment or deliberate analytical reasoning, whether the intended mode matches the actual demand, where cognitive overload or under-stimulation appears, or how badly the design handles shifts between instinctive and reflective play.
-
stanestane Skill Game Design Player Need Satisfaction AuditAudit a game, feature, live-ops system, onboarding flow, progression loop, social feature, monetization flow, or return loop for player need satisfaction using Self-Determination Theory and the PENS lens. Use when evaluating whether a design is actually fun beyond surface KPIs, diagnosing weak retention or shallow engagement, comparing variants, identifying where a system denies autonomy, competence, or relatedness, or understanding whether a game feels emotionally nourishing or quietly depleting.
-
stanestane Bundle Game Design Goal Density And Immediacy AuditAudit a game, feature, progression loop, return-player experience, metagame layer, or session structure for density of goals, immediacy of goals, safe stopping points, and return triggers. Use when evaluating whether players can quickly find something meaningful to do, whether the game offers enough short-term, mid-term, and long-term goals, whether session lengths are flexible enough for real player schedules, or why a game feels aimless, overwhelming, or unable to fit into fragmented playtime.
-
stanestane Bundle Game Design Granular Player Motivation AuditAudit a game, feature, progression system, social system, live-ops loop, monetization surface, or onboarding flow through a granular player motivation taxonomy. Use when evaluating which player motivation archetypes a design strongly serves, neglects, or actively repels; when comparing a concept against segments such as Steady Advancers, Curious Solvers, Competitive Achievers, Imaginative Creators, Strategic Leaders, Immersed Storywriters, Reward Seekers, Passionate Belongers, and Category Enthusiasts; when translating player research into practical design recommendations; or when you need a more nuanced alternative to a simple Bartle-style motivation read.
-
xopoko Bundle Xcode Project AuditorAudit Xcode project and target overhead across schemes, settings, dependencies, run scripts, module maps, and explicit modules; require approval before changes.
-
xopoko Bundle Apple Firmware InspectorApple firmware: inspect and reverse-engineer IPSWs, kernelcaches, dyld shared caches, private headers, entitlements, Mach-O binaries, KEXTs, and security internals with `ipsw`.
-
xopoko Bundle Appstore Workflow RunnerManage `.asc/workflow.json` automations; define, validate, run, resume, and audit trusted repo-local release/TestFlight flows and step outputs with `asc workflow`.
-
carlheath Bundle SecuritySecurity Specialist - Security architecture, code review, threat modeling, penetration testing. [VAD] OWASP Top 10 review, secure coding, threat modeling, vulnerability assessment. Auth/authz design, cryptography, API security, compliance (GDPR, PCI-DSS, SOC 2). [NÄR] Use when: security, vulnerability, secure, encryption, authentication, authorization, OWASP, penetration test, security review, audit, compliance, CVE [EXPERTISE] Application security, infrastructure security, penetration testing, compliance
-
carlheath Skill Person OsintPerson OSINT — professional person investigation using systematic methodology. [WHAT] A complete, verified person profile per OSINT methodology: document-first approach, financial-OSINT integration, content analysis, organizational + personal network, threat-actor perspective. [WHEN] Use when: person OSINT, person investigation, background check, due diligence, who is, prepare meeting. [LANGUAGE] Configurable. [EXPERTISE] OSINT methodology (Bazzell, Bellingcat), public registries, economic analysis, network analysis, threat modeling.
Audited -
danielleit241 Bundle Hs GitGit operations with conventional commits. Use for staging, committing, pushing, PRs, merges. Auto-splits commits by type/scope. Security scans for secrets.
-
danielleit241 Skill Hs ResearchResearch technical solutions, analyze architectures, gather requirements thoroughly. Use for technology evaluation, best practices research, solution design, scalability/security/maintainability analysis.
-
danielleit241 Bundle Hs Review PrReview a GitHub pull request thoroughly — analyze diff for correctness, security, breaking changes, code quality, and AI-slop patterns. Supports --fix to auto-remediate findings and --reply to post the review back to GitHub via the gh CLI as a formal review.
-
gulmezeren2-byte Skill SkilldoctorDiagnose the Claude Code skills installed on this machine — why one never triggers, and whether Claude can see it at all. Use when the user says a skill isn't firing, isn't triggering, or is being ignored; asks to check, audit, or debug their skills; mentions the skill description budget, truncated skills, or duplicate skills; or asks whether a skill they installed is safe to trust. Runs a deterministic CLI over every installed skill at once, so it catches whole-system problems no single-file check can see.
Audited -
brandonburrus Skill Audit ArchitectureThis skill should be used when evaluating a codebase's architecture and surfacing improvement candidates, including finding refactoring opportunities, consolidating tightly-coupled modules, making code more testable, or when the user says "audit the architecture", "review the structure of this codebase", "why is this so hard to change", or "find tech debt". It also applies when the fix skill escalates after repeated failed fixes in one area. It should not be used for designing new systems (use spec), for implementing the improvements it proposes (use create-code-plan then refactor), or for reviewing a single change (use review-pull-request).
Audited -
brandonburrus Skill Generate Test CasesThis skill should be used when enumerating or planning what test cases to write for a function, module, feature, or spec, covering golden path, error, and edge cases as a reviewed case matrix before any test code exists. It applies when the user says "what should we test", "list the edge cases", "enumerate test cases", "plan the test coverage", or "what cases am I missing", or wants an exhaustive coverage plan up front. It should not be used to write or run the actual test files (use test-writer), to drive test-first implementation (use follow-tdd), or to audit an existing suite against requirements (use test-coverage-requirement-auditor).
Audited -
product-on-purpose Bundle Think Reflective EquilibriumRuns reflective equilibrium (mutual adjustment between considered case judgments, general principles, and background theories) caveat-first. It leads with the weak evidence (philosophically central since Rawls 1971 but empirically untested as a procedure, with three failure modes that bite in a bounded session), then forces the discipline a bare run lacks, namely an explicit revision ledger that records which commitment gave way and why. Use only when reflective equilibrium is asked for by name; for impartial allocation prefer think-veil-of-ignorance-reasoning, for a parties-by-principles audit think-ethical-matrix.
-
jgamaraalv Bundle Websocket SecurityTest WebSocket channels for CSWSH, smuggling, injection, and auth flaws (wsrepl, ws-harness, Burp). Use when an app uses real-time channels, chat, notifications, or WS-backed APIs.
-
jgamaraalv Bundle Backend Delivery LoopContinuous backend delivery loop — cycles subagents through test → diagnose → fix → review → secure → re-test until the suite, quality, and security gates are clean. Use to develop, fix, harden, or finish a backend feature/service/endpoint.
-
jgamaraalv Bundle Nestjs Best PracticesNestJS best practices — 40 rules across modules, DI, error handling, security, performance, testing, database, API design, microservices, and deployment. Use when writing, reviewing, or refactoring NestJS code.
-
jgamaraalv Bundle Owasp Security ReviewOWASP Top 10:2025 Security Review
-
l4ci Bundle Cognitive Bias AuditUse when the user wants to audit a decision, plan, forecast, or analysis for cognitive biases before committing to it, or to stress-test where reasoning might be systematically distorted. Fans out five parallel hunter subagents, one per bias family, each finding where THIS decision is exposed with evidence from the actual reasoning, then ranks the live biases by how much they threaten the call, names the one or two most dangerous, and prescribes specific debiasing moves plus a corrected read in a detailed markdown report. Triggers include "cognitive bias", "audit this decision for bias", "what biases are at play", "debias", "am I fooling myself", "stress-test my reasoning".
-
phuc-nt Bundle Mk GitManage git commits, pushes, PRs, branch merges, and PR review-and-merge automation. Use for commit, push, PR creation, PR merge, CI follow-up, and secret scanning.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security, person-osint, game-design-ftue-hero-journey-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.