Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
viasrijan Skill Web Quality Audit---
-
viasrijan Skill Security And HardeningUse when handling user input, auth, secrets, or external integrations — prevent OWASP Top 10, enforce auth patterns, secrets management, and dependency auditing.
-
yangwhale Bundle Memory Gc记忆系统自动 GC — audit 当前 MEMORY.md / shared/ / disk memory 文件健康度。**Pressure-driven 不是 time-driven** — 没积累就不该清, cold ≠ garbage, 没新东西不要找事清。当用户说「memory audit」「记忆 GC」「记忆清理」「sleep gc」「/memory gc」「/memory audit」「check memory health」时触发。
-
yangwhale Bundle Memory Lint全面 memory 重构战役 — 不只 audit,是把"2026-05-22 战役"完整流程做一遍(健康审计 → 集群合并 → 孤儿处理 → 死链修复 → 小爱回归测试 → 备份)。当用户说「memory lint」「/memory lint」「记忆大扫除」「memory 大整理」「memory 重构」时触发。跟 memory-gc skill 互补 — memory-gc 只 audit,memory-lint 是大手术。
-
onedro1d Bundle Sc AuditSecurity auditor for smart contracts - identifies vulnerabilities, logic flaws, reentrancy, access control issues, MEV/economic attacks, and oracle manipulation. Use when auditing Solidity, Vyper, or Rust/Anchor contracts, reviewing PRs for security issues, checking for exploits, or analyzing DeFi protocols. Triggers on "audit", "security review", "vulnerability", "exploit", "reentrancy", "access control", "MEV", "frontrunning".
-
onedro1d Bundle Code ReviewerComprehensive code review for quality, architecture, and performance. Use when reviewing PRs, auditing code quality, checking coding standards, evaluating design patterns, identifying performance bottlenecks, or analyzing technical debt. Triggers on "review", "audit", "analyze code", "check quality", "code smell".
-
onedro1d Bundle Backend Service AuditorAudit backend services for security, reliability, performance, and operability issues. Use when reviewing APIs, microservices, workers, or backend code changes. Triggers on "audit backend", "security review", "service audit", "API audit", "check vulnerabilities", "review microservice", "backend security", "audit API", "review service".
-
onedro1d Bundle Dependency Risk AuditorAnalyze third-party dependencies for security, maintenance, and lock-in risk. Use when auditing dependencies, reviewing new packages, or assessing supply chain security. Triggers on "dependency audit", "package risk", "supply chain", "vulnerable dependencies", "license check", "outdated packages", "dependency review", "npm audit", "security scan".
-
onedro1d Bundle Microservices ArchitectDesign and architect microservices following Chris Richardson's Microservices Patterns. Use when designing services, APIs, data flows, or evaluating architecture decisions. Guides full workflow from feature intake to production-ready design with observability, async patterns, security, testing, and deployment strategies.
-
onedro1d Bundle Test Quality GatekeeperAssess whether tests actually protect the system from regressions. Use when reviewing test coverage, evaluating test quality, or identifying missing tests. Triggers on "test review", "test quality", "coverage gaps", "missing tests", "test assessment", "regression protection", "flaky tests", "test audit".
-
dennisonbertram Skill Go DepsManage Go module dependencies: tidy, update, vendor, audit, and analyze dependency trees with go mod and govulncheck. Trigger: when managing Go dependencies, go mod tidy, go get update, go module graph, govulncheck, vendor dependencies, go module audit
-
dennisonbertram Skill NPM DepsManage npm dependencies: audit, update, dedupe, outdated, lockfile, workspaces, and package tree analysis. Trigger: when managing npm packages, npm outdated, npm update, npm audit, npm install, package.json dependencies, node_modules, npm ci, npm dedupe
-
dennisonbertram Skill NPM AuditAudit npm dependencies for known vulnerabilities and suggest fixes. Trigger: when scanning npm packages for security issues, auditing JavaScript dependencies, checking Node.js vulnerabilities
-
dennisonbertram Skill Snyk ScanScan code and dependencies for vulnerabilities with Snyk: snyk test, snyk monitor, snyk code test, fix guidance, severity thresholds, CI integration. Trigger: when using Snyk, snyk test, snyk monitor, vulnerability scanning, dependency security, snyk code, SAST scanning, CVE scan
-
dennisonbertram Skill Dotenv AuditAudit .env files and environment variable usage to prevent secret leaks in commits, logs, and error messages. Trigger: when auditing secrets, checking for exposed credentials, reviewing environment variable handling
-
rvdbreemen Skill InitInitialize ADR Kit in a project. Use for adr-kit init, first-time ADR setup, architecture audit, managed guidance, and the pre-commit gate.
-
rvdbreemen Skill AuditAre we still on course? Lint the decisions and judge the code in one run. Use for ADR audit, architecture drift, a whole-codebase compliance check, or a governance report. Read-only.
-
rvdbreemen Skill SetupThe one entry point for installing ADR Kit in a project (R19). Modes: register (default), adopt (audit + propose ADRs, /adr-kit:init), hooks (/adr-kit:install-hooks), upgrade (/adr-kit:upgrade).
-
lazygophers Bundle Cortex Lintlint / 校验 / 体检 / audit / 死链 / 孤儿 / 规范化 / frontmatter — cortex 知识库与记忆树的合规检查与可逆 autofix。覆盖 wikilink 死链、frontmatter 缺字段、命名违规、目录同构、孤儿页、等级语义反写、脚本目录用途混淆等 7 类规则。默认 --fix 落盘修复;--check opt-in 仅预览。
-
misonl Bundle Vulnerability Scanner高级漏洞分析原则。覆盖 OWASP 2025、供应链安全、攻击面建模与风险优先级排序。
-
openshift Skill Drift WatchUse when the user asks whether derived artifacts or paired sources are stale or drifting — "is anything stale", "check for drift", "are the feeds/graphs/findings-db current", "did inputs change since the graph was built", "run the drift report" — or on a regular cadence. Runs the deterministic staleness/drift checker over feeds, findings.db, repo-/portfolio-graph vs the inputs inventory, repo-liveness, corpus registration, finding-identity stamping across every audit report, ADR-registry pins, external-tool freshness (installed scanners vs latest upstream releases), docs-product-map version enumeration (declared doc versions vs the live docs.redhat.com landing pages — catches FUTURE product-doc versions the variance lane isn't covering), pqc-facts stamps/schema provenance, and dated policy provenance; writes drift-report.{json,md} to progress-tracker/metrics/drift/.
-
openshift Skill Check Skill SecurityUse before committing any new or edited skill or script to the traust repo, or when asked "does this skill degrade our security posture", "run the security-posture check", "is this skill safe to add" — runs python3 -m traust.cli check skill-security, the security-posture guard the pre-commit hook enforces alongside the alignment gate. Verifies privileged skills declare allowed-tools confinement, untrusted-content readers carry the adversarial-content doctrine, no git network command takes an ungated non-literal URL (the confirmed-RCE class from the 2026-07 self-audit), no shell-execution constructs or ps-visible Authorization headers, no fixed /tmp state paths, no unpinned runtime installs, no raw-egress tool grants, headless agents under repo-config isolation, and target-build invocations routed through the safe_exec sandbox.
-
openshift Bundle Pqc ReadinessAssess a repository's post-quantum TLS readiness. Use when asked whether a repo can negotiate ML-KEM hybrid TLS, who controls that choice, or to emit a pqc-readiness report. Walks the TLS control chain from platform down to app, consulting capability notes for version meaning.
-
openshift Bundle Crypto AnalysisUse when you need to understand a crypto decision point — probe what crypto is configured, trace who owns the decision (governance chain), and confirm with runtime evidence. Probe-driven via python3 -m traust.cli adapters crypto-audit.
-
openshift Bundle Dependency WatchUse on the daily continuous-operations cadence, or when the user asks to "check for new dependency CVEs", "run the deps lane", "watch dependencies", or "file dependency vulnerabilities" — runs the advisory-driven dependency chain end to end: refresh the vulnerability feeds, sweep new advisories against the audited fleet, run /impact-analysis reachability on hits, and route affected repos' findings into their disposition ledgers as event-carried findings (gate A15 — the baseline is never written), so a newly disclosed dependency CVE becomes an owned, SLA-clocked finding the same day. Orchestrator-neutral — invocable identically from an operator session, cron, Source Code Intelligence, or any enterprise scheduler.
-
openshift Skill Secure Rpm AuditUse when the user asks to perform a security audit, security review, or vulnerability assessment of an RPM packaging repository (CentOS Stream / Fedora / RHEL dist-git) — a repo containing a .spec file, downstream patches, and a sources lookaside manifest — using OWASP ASVS, the SEI CERT C/C++ Coding Standards, Fedora Packaging Guidelines, SLSA, and OpenSSF Scorecard.
-
mulesoft Skill Manage Portal ApplicationsManage the applications that hold API credentials inside an API Experience Hub portal. Use when a portal consumer needs to list their applications, check if a name is available, create a new application, update metadata, rotate the client secret, or delete an application they no longer use.
-
mulesoft Skill Apply Policy To API InstanceApply a policy to an existing API Manager instance. Use when the user wants to add a policy, enforce security, configure rate limiting, apply OAuth2, set up IP allowlisting, or protect an API with any policy template from the catalog.
-
nirholas Skill Reputation AuditAI risk-scores an account's own posts across professional, hostile, legal, and spam exposure, produces a 0-100 reputation score with a shareable card, and offers one-click cleanup of what it flags. Use when a user wants to audit their own timeline for embarrassing or risky posts, "clean up my account before a job search", or check what they said that could come back to bite them.
Audited -
rocm Skill Architecture TradeoffUse when architectural decisions involve competing quality attributes (performance vs modifiability, availability vs consistency, security vs usability), when the user says "tradeoff analysis", "ATAM", "quality attributes", "what are we giving up", or when a design choice affects multiple non-functional requirements in tension.
-
davila7 Skill Code Quality GateRun all code quality checks (security, complexity, test coverage) on the current PR and post a combined report as a GitHub PR comment. Use before merging a PR, during code review, or when asked to check code quality.
-
davila7 Skill Code Review ChecklistReview code against a standard checklist covering security, correctness, performance, and readability. Use when asked to review code, check a PR, or audit changes.
-
cboone Bundle Set Up Secret ScanningSet up secret scanning with gitleaks and TruffleHog GitHub Actions workflows and optional gitleaks configuration. Use when the user says "add secret scanning", "set up secret scanning", "set up gitleaks", "set up trufflehog", "scan for secrets in CI", or wants to detect leaked credentials in a repository. Both tools run on pushes to `main`, on pull requests, and on `workflow_dispatch`; gitleaks does fast pattern matching, TruffleHog adds verification-based scanning. Pairs with handle-secrets for application-level secret hygiene.
-
hiai-gg Skill Review RlsReview Row Level Security posture for a Supabase project: which tables have RLS enabled, which policies exist, and whether anon/authenticated access is over-permissive. Use when auditing a Supabase app's access control or before exposing a table via the API.
-
hiai-gg Skill Review Cloudflare ConfigReview a Cloudflare account/zone configuration for correctness and security: Workers, DNS, rules, cache, and settings. Use when onboarding to a Cloudflare setup, auditing configuration, or checking for misconfigurations.
-
shenyuannext Bundle Wepr Geo Panorama Audit开展品牌 GEO 全景诊断,覆盖官网采集、公开事实交叉核验、内容资产分析及站内外机会地图。适用于项目启动、季度复盘和投入前评估;不用于 AI 问答平台采样、单页诊断、文章或标题创作、后端归因设计及执行路线图拆解。
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-and-hardening, web-quality-audit, memory-gc. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.