Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
irinabuht12-oss Skill Reddit Ads AuditReddit Ads Audit
-
irinabuht12-oss Skill Ad Extension Audit21/ Ad Extension Audit — Google
-
irinabuht12-oss Skill Landing Page Audit10/ Landing Page Audit — Google + Meta
-
irinabuht12-oss Skill Linkedin Ads AuditLinkedIn Ads Audit
-
irinabuht12-oss Skill AI Visibility Audit1/ AI Visibility Audit
-
irinabuht12-oss Skill Landing Page Audit 39Landing Page Audit
-
poorvith-mp Bundle Unity MultiplayerBuild Netcode for GameObjects, Relay and Lobby, server authority and lag compensation. For exploit defense, see anti-cheat. Use when implementing Netcode for GameObjects or sync.
-
quixiai Skill Host NodeUse an explicitly paired companion node for approved Apple apps, Shortcuts, secret-safe 1Password, fixed host commands, or a fresh screen capture
-
rweisssieker-xp Skill Topdesk SchemaDesign, review, and validate database schemas for TOPdesk-like service-management apps. Use for incident/change/asset/person/operator/branch schemas, TOPdesk external IDs, relationships, constraints, indexes, migrations, audit/history tables, SLA tables, AI suggestion tables, ERDs, reporting views, and schema-to-Power-BI preparation.
-
rweisssieker-xp Skill Topdesk ChangesTOPdesk Change Management design and reporting. Use for change templates, standard/simple/extensive changes, activities, approvals, risk/impact, scheduling, linked incidents/assets, change audit, change KPIs, and change workflow tests.
-
rweisssieker-xp Bundle Topdesk PowerbiBuild, review, and validate Power BI reporting for TOPdesk data. Use for TOPdesk dashboards, semantic models, DAX measures, Power Query/OData extraction, row-level security, KPI definitions, report pages, reconciliation against TOPdesk selections/exports, refresh design, and BI data-quality checks.
-
rweisssieker-xp Skill Topdesk SecuritySecurity, privacy, compliance, and governance for TOPdesk apps, integrations, Power BI reports, and AI/KI features. Use for DSGVO/GDPR, PII, branch/customer permissions, operator roles, audit logging, secrets, API users, row-level security, retention, AI governance, and safe automation controls.
-
rweisssieker-xp Bundle Topdesk Tenant DriftCompare TOPdesk tenant field catalogs, OData/API exports, option sets, categories, statuses, priorities, operator groups, and KPI dependency maps to detect drift risks for Power BI, AI/KI, automations, security, and operations.
-
rweisssieker-xp Skill Topdesk Action SequencesTOPdesk Action Sequences and automation design. Use for action sequence triggers, webhooks, API calls, payload mapping, idempotency, retries, error handling, safe automation boundaries, audit logging, and automation monitoring.
-
rweisssieker-xp Bundle Topdesk Readiness ScoringScore TOPdesk reporting, AI/KI, data trust, automation, security/privacy, tenant mapping, and operations readiness from evidence checklists, proof-of-value inputs, production gates, or project intake artifacts.
-
rweisssieker-xp Bundle Topdesk Automation SandboxReview TOPdesk action sequences, webhooks, scheduled jobs, integration scripts, and automation designs for trigger quality, payload mapping, idempotency, retry behavior, rollback, dead-letter handling, PII, audit, human approval, and production go/no-go risk.
-
wonderslife Bundle Expert Security安全专家提供代码漏洞扫描、OWASP Top 10合规检查和安全编码建议。当用户需要安全审计、漏洞扫描、渗透测试准备或安全编码时调用。支持中文触发:安全审计、漏洞扫描、安全编码、OWASP、渗透测试、代码安全。
-
wonderslife Bundle System Architect系统架构师角色,设计健壮、可扩展、可维护的软件架构。强制执行行业标准(PEP 8、ESLint),模块化设计和安全最佳实践。当用户想要启动新项目、重构现有项目或讨论高层系统设计时使用此技能。此技能专注于项目初始化、技术栈选择和代码标准。支持中文触发:系统架构、项目初始化、技术栈、项目搭建、代码规范。
-
gajetoso Bundle Tax PlanningWhen the user wants to optimize tax liability or ensure tax compliance. Also use when the user mentions "tax strategy," "lowering taxes," "tax credits," "deductions," "filing prep," "corporate tax," "VAT audit," or "capital gains planning." Use this for both individual and corporate tax.
-
gajetoso Bundle Esg ReportingWhen the user wants to prepare, audit, or analyze Environmental, Social, and Governance (ESG) reports. Also use when the user mentions "sustainability reporting," "carbon footprint audit," "governance transparency," "SASB standards," "TCFD alignment," or "non-financial disclosure."
-
gajetoso Bundle Sox ComplianceWhen the user wants to plan or execute SOX 404 control testing, select audit samples, build testing workpapers, or classify control deficiencies. Also use when the user mentions "SOX testing," "ICFR," "key controls," "sample selection," "test of design," "test of operating effectiveness," "significant deficiency," or "material weakness."
-
gajetoso Bundle Audit ChecklistWhen the user wants to perform an internal audit, review controls, or prepare for an external financial audit. Also use when the user mentions "internal controls," "compliance check," "preparing for audit," "Sox compliance," "audit readiness," "checking for gaps," or "inventory audit." Use this for both operational and financial audits.
-
gajetoso Bundle Earned Value MgmtWhen the user wants to track the financial progress of a large project. Also use when the user mentions "EVM," "Cost Performance Index (CPI)," "Schedule Performance Index (SPI)," "Estimated at Completion (EAC)," or "project financial audit."
-
gajetoso Bundle Variance AnalysisWhen the user wants to analyze the difference between actual and standard costs in manufacturing. Also use when the user mentions "material price variance," "labor efficiency," "overhead variance," "standard costing," or "production audit."
-
gajetoso Bundle Financial AnalysisWhen the user wants to perform a deep dive into a company's financial performance. Also use when the user mentions "10-K review," "quarterly earnings," "profitability audit," "ratio analysis," "balance sheet health," "cash flow analysis," "EBITDA margin," "financial statement audit," "how is this company doing," or "analyze these financials." Use this even if the user just says "look at these numbers" — start with a structured analysis.
-
gajetoso Bundle Forensic AccountingWhen the user wants to investigate financial discrepancies, fraud, or hidden assets. Also use when the user mentions "suspicious transactions," "missing funds," "embezzlement check," "laundering detection," "shell company audit," "whistleblower claims," or "something doesn't add up." Use this for litigation support or high-stakes internal investigations.
-
gajetoso Bundle AI Anomaly DetectionWhen the user wants to use machine learning to detect fraud, errors, or unusual patterns in high-volume financial data. Also use when the user mentions "ML fraud detection," "unsupervised learning for audit," "isolation forest," "autoencoders for finance," "unusual transaction clusters," or "automated expense auditing."
-
dolphinai2026 Bundle Agentic Memory RefreshRefresh stale learning and pattern docs under docs/solutions/ by reviewing them against the current codebase, then updating, consolidating, or deleting drifted ones. Use when the user asks to "refresh my learnings", "audit docs/solutions/", "clean up stale learnings", or "consolidate overlapping docs", or when agentic-memory-compound flags an older doc as superseded. Do not trigger for general refactor, debugging, or code-review work unless the user has explicitly pointed at docs/solutions/.
-
davila7 Bundle Dependency AuditAudit npm or pip dependencies for outdated packages and known vulnerabilities. Use when checking package health, preparing for a release, reviewing dependencies before merging a PR, or when asked about outdated packages or security advisories.
-
davila7 Skill Code Quality AuditRun a comprehensive code quality audit covering security, performance, and maintainability. Use for quarterly audits, pre-release reviews, or when onboarding to a large codebase.
-
openaisec Bundle Ctf PwnProvides binary exploitation techniques for CTF challenges. Use when you already have a vulnerable native target or service and need to turn memory corruption or low-level primitives into code execution or privilege escalation, such as buffer overflows, format strings, heap bugs, ROP, ret2libc, shellcode, kernel exploitation, seccomp bypass, sandbox escape, or Windows/Linux exploit chains. Do not use it when the main blocker is understanding what the binary does; use reverse engineering first. Do not use it for pure web bugs, disk or packet forensics, or standalone crypto/math challenges.
-
openaisec Bundle Audit SkillsSecurity audit workflow for authorized Java, .NET, PHP source and deployment artifact review.
-
openaisec Bundle Game HackingAuthorized game security, reverse engineering, protocol analysis, memory analysis, hook, and automation workflow guide.
-
deagentic Bundle Security ExpertUse when authentication, encryption, secrets handling, access control, cryptography, key management, or threat modeling needs review. Invoke for any security-sensitive code — if in doubt, invoke it.
-
deagentic Bundle Code ReviewerUse when code has been written or modified and needs a quality, security, correctness, or ADR coverage review. Always invoke before merging any library change. Catches what linters can't — bugs, security holes, race conditions, and ADR-missing violations.
-
penghang1223 Skill API SecurityAPI Security Scanner
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include host-node, reddit-ads-audit, ad-extension-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.