Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
daedalus Skill Linux Security AuditComprehensive Linux security auditing and hardening skill. Use this whenever the user wants to audit a Linux system, assess its security posture, harden a server or workstation, review running services/users/permissions, check for privilege escalation vectors, generate a security report, or understand specific security controls (PAM, sudoers, AppArmor, SELinux, SSH, sysctl, firewall, cron, SUID/SGID, world-writable paths, failed logins, kernel parameters, etc.). Trigger for phrases like: "audit my server", "harden this box", "security check", "is this system secure", "check for misconfigs", "review sudoers", "find SUID binaries", "check open ports", "who can SSH in", "CIS benchmark", "DISA STIG", "NIST 800-123", "check /etc/passwd", "review crontabs", "enumerate users", "find world-writable files", or any request to assess, report on, or remediate Linux system security. Also trigger when the user pastes command output (ps aux, ss -tlnp, ls -la /etc, etc.) and asks "is this OK?" or "what should I fix?".
-
daedalus Skill Engineering Problem SolvingA rigorous, falsification-first methodology for tackling hard problems in engineering, software, systems, and applied science — debugging, algorithm design, formal/mathematical investigation, security research, and architecture decisions. Use this skill aggressively whenever the user is stuck on a non-trivial technical problem, asks for root-cause analysis, wants a design or PR reviewed, is doing iterative code review, is chasing a bug with unclear or intermittent origin, is verifying a mathematical identity or sequence, or is doing exploratory research (math, security, systems) where the path to the answer isn't obvious. Trigger even if the user just describes symptoms without asking for a "method" by name — "this is failing and I don't know why," "does this proof hold," "is this design sound" all qualify. Also trigger when the user wants their reasoning process captured alongside the fix, wants rejected approaches logged, or is doing a multi-round review cycle. Do not use for simple one-shot factual questio
-
daedalus Skill Semantic Correctness AuditorA unified framework for auditing code, systems, and skill sets against the limits of what can be mechanically verified. Combines Rice's Theorem analysis, emergent fairness simulation, and insight operationalization into a single workflow. Trigger on ANY of these: "are my tests enough?", "is this correct?", "will this always work?", "is this fair?", "why does my code pass tests but fail in production?", "can AI verify this?", "turn this article into a skill", "audit my skills", "do my skills work together?", "why isn't my skill triggering?", "I want Claude to remember this workflow." Also trigger when the user shares: a scheduler, load balancer, assignment algorithm, rotation system, or any code whose correctness depends on long-run emergent behavior. Or when they share a URL/article and want it captured as reusable knowledge. Or when they have a collection of skills and want to know if they cover the right ground and trigger reliably. When in doubt, use this skill. It is designed to be the meta-layer that see
-
daedalus Skill Agentic PbtAutonomously find bugs in Python code using property-based testing (Hypothesis). Use this skill whenever the user wants to: find bugs in a Python package or module, write property-based tests, generate Hypothesis tests from docstrings/type annotations, audit a PyPI package for correctness issues, or apply fuzz-style testing to discover edge cases. Trigger on phrases like "find bugs in", "write property tests", "test this module with Hypothesis", "audit this package", "what invariants does this function have", or any request to systematically test Python code beyond hand-written unit tests.
-
nvidia Bundle Nemoclaw NvteamRoute product, program, engineering, data and ML, quality, SRE, security, and developer-community work through the eight local role lenses packaged with the developer-community-chief-of-staff recipe in nemoclaw-community. Use for explicit NVTeam or persona activation, cross-functional readiness, developer relations, community enablement, technical-enablement work, or automatic specialist routing within this recipe. Do not use for a standalone question about core NemoClaw product capabilities unless the user explicitly requests NVTeam. This skill is Community-recipe behavior, not a built-in NemoClaw capability.
2.2k -
3dcom2711 Skill Thrunt Audit EvidenceCross-phase audit of all outstanding Evidence Review and findings validation items
-
3dcom2711 Skill Thrunt Validate PhaseRetroactively audit and fill Nyquist validation gaps for a completed phase
-
3dcom2711 Skill Thrunt Audit MilestoneAudit milestone completion against original intent before archiving
-
3dcom2711 Skill Thrunt Plan Milestone GapsCreate phases to close all gaps identified by milestone audit
-
magnus919 Bundle Review MethodologyProfessional review methodology — code review, security audit, architectural review, and kanban swarm verification. References codify Google's code review standards, OWASP audit patterns, and architectural assessment frameworks.
-
magnus919 Bundle Editor Review MethodologyEditorial review methodology — fact-checking, voice audit, engagement review, and source integrity assessment.
-
digitalspeed Skill Gws AlertcenterGoogle Workspace Alert Center: Manage Workspace security alerts.
-
digitalspeed Skill Persona It AdminAdminister IT — manage users, monitor security, configure Workspace.
-
digitalspeed Skill Recipe Audit External SharingFind and review Google Drive files shared outside the organization.
-
digitalspeed Skill Recipe Triage Security AlertsList and review Google Workspace security alerts from Alert Center.
-
jpeetz Bundle Code ReviewAI-powered code review and PR analysis. Performs systematic reviews covering security vulnerabilities, code quality, style compliance, architectural integrity, test coverage, and performance considerations. Works with PR diffs, commit ranges, file changes, or raw code snippets. Primary keyword clusters: AI code review automation, automated PR review security, code quality analysis static, pull request review checklist, OWASP code review patterns, architectural review automation, test coverage analysis review, performance code review, style guide compliance checker, code smell detection automated. Designed for agentic platforms — Claude Code, Codex, Cursor, Gemini CLI, OpenClaw, GitHub Copilot, Windsurf, and OpenCode.
-
jpeetz Bundle API Design FirstDesign-first API development skill. Generates OpenAPI 3.1 specifications, enforces REST design best practices, validates endpoints, handles versioning, pagination, error formatting, authentication patterns, rate limiting, and idempotency. Activates when users say "design an API", "create OpenAPI spec", "API endpoint", "REST API design", "API contract", "Swagger/OpenAPI doc", "API versioning", "rate limiting", or "API security". Covers REST, GraphQL schema design, and gRPC proto generation with cross-protocol consistency.
-
jpeetz Bundle GRAPHQL API DevelopmentAI-powered GraphQL API design, implementation, and optimization. Covers schema-first design, resolver architecture, query optimization with DataLoader for N+1 prevention, mutation patterns with idempotency, real-time subscriptions, Apollo Federation for distributed graphs, security hardening (depth limiting, rate limiting, authz), and production performance (persisted queries, caching, CDN integration). Primary keyword clusters: GraphQL schema design best practices, Apollo Federation subgraph patterns, DataLoader N+1 query optimization, GraphQL security depth limiting rate limiting, GraphQL persisted queries performance, GraphQL subscription real-time patterns, GraphQL error handling union types, GraphQL pagination relay cursor connection, GraphQL caching strategies production, GraphQL resolver architecture patterns. Designed for agentic platforms — Claude Code, Codex, Cursor, Gemini CLI, OpenClaw, GitHub Copilot, Windsurf, and OpenCode.
-
jpeetz Bundle Supply Chain Security ScannerAI-powered software supply chain security auditing skill for agentic platforms. Performs comprehensive dependency vulnerability scanning across npm, PyPI, Maven, Go modules, Cargo, and container images. Generates SBOMs (Software Bill of Materials) in SPDX and CycloneDX formats using Syft and Grype. Validates license compliance against organizational policies and detects copyleft risks. Verifies cryptographic provenance and SLSA framework attestations using cosign and slsa-verifier. Executes a structured audit methodology—Scan → Analyze → Report → Remediate—producing machine-readable vulnerability reports with CVSS scores, exploitability assessments, and actionable fix recommendations aligned with OWASP Agentic Skills Top 10 guidance. Integrates with ecosystem vulnerability databases including NVD (National Vulnerability Database), GitHub Advisory Database (GHSA), and Open Source Vulnerabilities (OSV). Covers software composition analysis (SCA) workflows, dependency confusion detection, typosquatting checks, a
-
openshift Bundle Verify RemediationUse when the user provides a previous secure-code-audit report and a patched version of the scanned repository, and asks to verify that findings have been resolved. Performs a targeted re-audit of each original finding against the patched code using the same frameworks, criteria, and evidence standards as the original secure-code-audit, then emits a structured verification report.
-
openshift Bundle Operator Priv ProfileUse when the user asks whether an operator runs with least privilege, what SCCs/securityContext/namespaces/roles an operator uses or requires, or for a fleet least-privilege inventory of OpenShift core and optional operators. Builds a deterministic per-operator privilege profile from manifests/CSVs (tier 1 — SCC requests, per-container securityContext, namespaces/install modes, complete RBAC enumeration), diffs shipped RBAC against the code's +kubebuilder:rbac markers (tier 2 — surplus grants = least-priv gap), and ships a gated runtime capture for the actually-assigned SCC and effective SA permissions (tier 3, executed only with explicit cluster authorization).
-
openshift Bundle Security Audit PhasedUse when a reviewer wants to steer a security code audit between phases — Phase 1 reconnaissance, Phase 2 prior-vuln pattern analysis, Phase 3 systematic CWE-taxonomy weakness hunt (including PEACH tenant isolation), Phase 4 cross-cutting analysis and final report, Phase 6 reproducer generation, plus review/CVSS/follow-up-seed helpers. Each phase is a separate slash command that reads the previous phase's JSON and writes its own.
-
openshift Skill Secure Container AuditUse when the user asks to perform a security audit, vulnerability scan, SBOM analysis, or supply-chain assessment of a container image (registry reference, payload image, or batch of images) using skopeo, syft, and grype — covering image configuration, known CVEs in shipped packages, signature/provenance posture, and drift between the image contents and its source repository.
-
openshift Bundle Generate Team ReportUse when the user asks to generate a shareable findings folder, executive summary, or team-specific security audit report for one or more products from the findings directory.
-
openshift Bundle Validate Browser FindingUse when validating browser-exploitable findings such as CSRF, XSS, or clickjacking against authorized containerized labs with Playwright. Test progressively through authentication, middleware, and ingress defenses.
-
ralvarezdev Bundle Security ReviewerCross-language security review — injection, auth/authz, secrets, insecure defaults, deserialization, CSRF/SSRF/IDOR, dep vulns. Emits a Critical/High/Medium/Low report with file:line + fixes. Use when auditing a PR or pre-release.
-
ralvarezdev Bundle Repo Tooling ArchitectRepo-root developer tooling — .editorconfig, .gitignore, version pinning (mise default, proto alt), task runner (Task default, just alt), minimal pre-commit, env vars via dotenv + external secret manager, Renovate. Use when scaffolding or auditing a repo's tooling layer.
-
santoshkanthety Skill Powerbi Security RlsSkill: Power BI Security — RLS, OLS, and Fabric Access Control
-
santoshkanthety Skill Powerbi Review ReportActionable feedback on the quality, usage, and effectiveness of Power BI reports. Automatically invoke when the user asks to "review a report", "audit a report", "report usage analysis", "report health check", "find unused reports", "check if a report is being used", "assess report performance", "evaluate report quality".
Audited -
santoshkanthety Skill Powerbi Cyber SecurityCybersecurity in Power BI / Microsoft Fabric
-
santoshkanthety Skill Powerbi Audit Tenant SettingsAutomatically invoke this skill whenever the user asks about Fabric tenant settings or Power BI tenant settings or auditing tenant settings. You can use this skill if the user mentions "Fabric administration".
Audited -
sidetoolco Skill Code ReviewerExpert code review specialist. Reviews code for quality, security, and maintainability. Use immediately after writing or modifying code, or when you need thorough code quality assessment.
Audited -
sidetoolco Skill Risk ManagerMonitor portfolio risk, R-multiples, and position limits. Creates hedging strategies, calculates expectancy, and implements stop-losses. Use PROACTIVELY for risk assessment, trade tracking, or portfolio protection.
Audited -
sidetoolco Skill Legal AdvisorDraft privacy policies, terms of service, disclaimers, and legal notices. Creates GDPR-compliant texts, cookie policies, and data processing agreements. Use PROACTIVELY for legal documentation, compliance texts, or regulatory requirements.
Audited -
sidetoolco Skill Network EngineerDebug network connectivity, configure load balancers, and analyze traffic patterns. Handles DNS, SSL/TLS, CDN setup, and network security. Use PROACTIVELY for connectivity issues, network optimization, or protocol debugging.
Audited -
scaryrawr Skill Maintain Verification SkillPeriodic pass that keeps a project's verification skill and feature map honest: parallel source readers per feature, one live session driving every feature, at most one PR of proven corrections. Use for /maintain-verification-skill or "audit the verify skill".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include legal-advisor, network-engineer, linux-security-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.