Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
aminalam Skill Audit LoggingAudit Logging
-
aminalam Skill EncryptionEncryption for Medical Devices
-
aminalam Skill Secure OtaSecure Over-the-Air Updates
-
aminalam Skill Secure BootSecure Boot Implementation
-
aminalam Skill AuthenticationAuthentication for Medical Devices
-
aminalam Skill Key ManagementCryptographic Key Management
-
aminalam Skill Threat ModelingThreat Modeling for Medical Devices
-
cgyudistira Skill Threat HuntingProactive threat hunting, MITRE ATT&CK framework, and adversary simulation.
Audited -
cgyudistira Skill Mobile SecurityiOS and Android security testing, SSL pinning bypass, and mobile app vulnerabilities.
Audited -
cgyudistira Skill Incident ResponseSecurity incident handling, forensics, and post-incident analysis procedures.
Audited -
cgyudistira Skill Social EngineeringPhishing campaigns, pretexting, and human factor security testing.
Audited -
cgyudistira Skill Zero Trust ArchitectureZero trust principles, microsegmentation, and identity-based security.
Audited -
jgamaraalv Bundle Redis SecurityRedis production hardening — authentication (requirepass/ACL users), TLS, least-privilege ACLs, network restriction (bind, protected-mode, firewall), and disabling dangerous commands. Use when deploying, locking down, or auditing a Redis instance.
-
reggiechan74 Bundle Tenant Credit AnalystUse when assessing a prospective tenant's creditworthiness from financial statements, computing DSCR/current ratio/debt-to-equity, estimating default probability, recommending security structures (deposit, LC, personal guarantee), or sizing financial covenants for a lease.
-
reggiechan74 Skill Objection Handling ExpertUse when a tenant or broker objects that rent is above market, requests higher TI or more free rent, pushes back on a security deposit or personal guarantee, cites competitive properties, demands shorter term or early termination rights, or any time you need to separate legitimate concerns from tactical objections and craft evidence-based responses.
-
furkangonel Skill SimplifyAudit recently changed code for reuse, quality, and efficiency issues using parallel sub-agents, then fix all findings
-
furkangonel Skill Code ReviewSystematic code review SOP covering correctness, security, performance, and maintainability — plus GitHub PR review workflow (diff, inline comments, approve via gh/REST).
-
furkangonel Skill Webhook SubscriptionsDesign, implement, and debug webhook integrations with security and reliability.
-
openjiuwen-ai Bundle Investment Analysis Team8-role debate-pattern investment analysis team with direct peer-to-peer debate for balanced decisions. Use when analyzing a security for investment decision with adversarial debate. Do NOT use for single-perspective analysis or quick price checks.
-
openjiuwen-ai Skill Skill EvaluationEvaluate another skill by inspecting its SKILL.md, referenced assets, and runnable helpers, then write a concise audit report plus a machine-readable score summary. Use when the caller asks to evaluate a skill, assess its readiness, or review quality/safety/testability. Do NOT use when the task is to create a new skill from scratch.
-
open-mercato Skill Om Pre Implement SpecAnalyze a spec before implementation: BC audit, risk assessment, gap analysis. Produces a readiness report with BC violations, missing sections, and suggested improvements. Triggers on "analyze spec", "pre-implement", "spec readiness", "BC analysis", "spec gap analysis".
-
open-mercato Bundle Om Refresh Standalone HarnessRefresh the standalone-app AI harness from an explicit local Git release range. Use for "refresh standalone harness", "release harness audit", "scan release range", `--from/--to`, "odśwież harness", or when platform work changes a module, UMES extension point, installed public contract, generator surface, or release.
-
open-mercato Skill Om Auto Upgrade 0 6 7 To 0 7 0Migrate downstream Open Mercato code from 0.6.7 to 0.7.0 with exact TanStack, settings-group, and removed-env edits; audit auth, search, workflow, facts, Redis, webhook, and security-header changes; validate the app; and report manual work. Use for "upgrade Open Mercato to 0.7.0", "migrate 0.6.7 to 0.7.0", "apply the 0.7.0 upgrade notes", or "zaktualizuj Open Mercato do 0.7.0".
-
x10aix Skill HealthcheckHost security hardening and risk-tolerance configuration for OpenClaw deployments. Use when a user asks for security audits, firewall/SSH/update hardening, risk posture, exposure review, OpenClaw cron scheduling for periodic checks, or version status checks on a machine running OpenClaw (laptop, workstation, Pi, VPS).
-
x10aix Bundle Skill CreatorCreate, edit, improve, or audit AgentSkills. Use when creating a new skill from scratch or when asked to improve, review, audit, tidy up, or clean up an existing skill or SKILL.md file. Also use when editing or restructuring a skill directory (moving files to references/ or scripts/, removing stale content, validating against the AgentSkills spec). Triggers on phrases like "create a skill", "author a skill", "tidy up a skill", "improve this skill", "review the skill", "clean up the skill", "audit the skill".
-
ronniepinnell Skill Audit SkillsEfficiency audit of a skill library on four measured axes — token cost, ceremony/duplication bloat, trigger-description precision, and overlap clusters — plus usage axes when invocation telemetry exists. Every claim carries a number; findings land as diffs and budgets, not advice. Use before tightening skills, after adding many, or as a periodic library health check.
-
ronniepinnell Skill CleanupMass reconciliation when things are out of whack. Audit, triage, fix, verify.
-
ronniepinnell Skill Find BugsFind bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch. ALWAYS run before committing.
-
ronniepinnell Skill Spec AuditCode-vs-spec comparator. Reads the source first-hand and compares it against written specification documents, classifying every divergence as absent, partial, wrong, or extra — with file:line on both sides and an explicit call on which artifact should change. Project rules (CLAUDE.md) outrank specs. Use before PRs, after spec'd feature work, or when spec drift is suspected.
-
ronniepinnell Skill Rules AuditProject-rules enforcer. Reviews recent changes strictly against the binding instructions in CLAUDE.md (and any project rule checklist), flagging every deviation with the exact rule cited and a concrete fix. Deliberately narrow — conformance only, not general code quality. Use after any code change and before commit.
-
ronniepinnell Skill Completion AuditSession/project-scope reality audit. Independently establishes how much of the claimed-done work is genuinely functional, cross-checked against every planning source, and produces a prioritized remediation plan. Use before committing or closing issues, when statuses say done but the system misbehaves, or whenever an honest project snapshot is needed. Supports --task <id> for single-task scope.
-
ronniepinnell Skill Pragmatism AuditOver-engineering review. Examines recently written code for complexity that the project's actual scale and needs don't justify, and proposes the smallest design that still works. Use after implementing a feature or making an architectural decision, before completion review.
-
ronniepinnell Skill Validate CompletionSingle-task completion verifier. When an implementer claims a task or feature is finished, establish whether the goal was genuinely achieved — by executing it when possible, by rigorous inspection when not. Compiling, existing, or green tests are not proof. Use immediately on any "done" claim, before the status is recorded.
-
stephenrogan Skill Competitive Threat AssessorEvaluates the severity of a competitive threat on a specific account by assessing the evaluation stage, trigger, relationship strength, and switching cost. Produces a threat classification with a response framework. Use when asked to assess a competitive signal, evaluate a competitive threat, determine how serious a competitor situation is, prepare a competitive response, or when a customer has mentioned evaluating alternatives. Also triggers for questions about competitive analysis on a specific account, handling competitor mentions, responding to customer evaluations, or assessing the risk of losing an account to a competitor.
Audited -
tim-osterhus Skill Tauri PtyImplementation guardrail for terminal emulator and PTY features in Tauri apps, covering Rust PTY setup, xterm integration, resizing, lifecycle, security, and multi-tab behavior.
-
zts212653 Skill Eval DesignE0资格门+指标出生证+纵向运行拓扑+七公理+五病体检。Use when: 设计、修改或审计eval。Not for: 单次交付(quality-gate)、外部claim(source-audit)、摩擦诊断(code-as-harness)。Output: 指标出生证(纵向eval含触发契约)或病名+处置。
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include audit-logging, encryption, secure-ota. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.