Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
revenuecat Skill SecurityUse this skill when hardening a RevenueCat integration on Android. Covers Trusted Entitlements response verification (INFORMATIONAL vs ENFORCED), why the server is always the authority, API key hygiene (public SDK key vs secret REST key), anonymous user identity, and purchase token protections RevenueCat provides automatically.
Audited -
fortunto2 Bundle Solo Skill AuditUse when "audit skill", "review skill quality", "check skill", "skill score", "skill checklist", "is this skill good", or evaluating skill against best practices. Do NOT use for KB audits (/audit) or code review (/review).
-
kdlbs Bundle VerifyRun a broad local verification audit only when the user explicitly requests it or PR/CI remediation requires it.
-
fabricioctelles Bundle Slop EvalObjectively evaluate a UI/web design against the pols.dev anti-slop design law: detect catalogued slop tells with cited evidence, score 8 weighted axes (color, type, components, layout, motion, execution, signature, cohesion), and emit a Slop Report with a 0–100 Slop Index and grade. Use when the user asks to "evaluate design slop", "slop report", "is this design AI slop", "audit this landing page design", "de-slop review", or wants an objective score of how generic/machine-made a design looks. To fix text (not design), use human-ai or humanizar skills instead.
-
modra40 Bundle Rust Principal EngineerPrincipal/Senior-level Rust playbook for architecture, ownership, async systems, error handling, observability, security, testing, and production readiness. Use when: designing Rust services or CLIs, reviewing unsafe/concurrent code, debugging panics and performance regressions, hardening APIs, or preparing a codebase for production.
-
modra40 Bundle Istio Principal EngineerPrincipal/Senior-level Istio playbook for service mesh architecture, traffic policy, identity, security, observability, and operating multi-tenant mesh platforms in production. Use when: designing mesh adoption, reviewing traffic policy and mTLS posture, debugging sidecar or ambient behavior, or operating Istio at scale.
-
modra40 Bundle Vault Principal EngineerPrincipal/Senior-level Vault playbook for secrets architecture, authn/authz, dynamic secrets, PKI, tenancy, and operating secure secret-management platforms in production. Use when: designing secret platforms, reviewing auth methods and policies, operating Vault clusters, or hardening access to sensitive systems.
-
modra40 Bundle Golang Mastery SkillPrincipal/Senior-level Go (Golang) playbook for architecture, idiomatic code, concurrency, testing, performance, reliability, security, observability, and production readiness. Use when: designing services/APIs/CLIs, doing large refactors, running code reviews, debugging races/leaks, tuning performance, hardening security, and shipping to production.
-
modra40 Bundle Opensearch Principal EngineerPrincipal/Senior-level OpenSearch playbook for index architecture, relevance, observability workloads, cluster tuning, security, and operating search/logging platforms at scale. Use when: designing search or logging clusters, reviewing mappings and analyzers, tuning cluster performance, or operating OpenSearch in production.
-
modra40 Bundle Keycloak Principal EngineerPrincipal/Senior-level Keycloak playbook for identity architecture, realms and clients, federation, authorization, operational security, and operating IAM platforms at scale. Use when: designing IAM platforms, reviewing SSO and OAuth/OIDC flows, operating Keycloak clusters, or governing identity for many teams and applications.
-
blakehastings Skill Nuget Trusted PublishingPlaybook for releasing a .NET NuGet library (not a CLI) to nuget.org with release-please + MinVer + OIDC Trusted Publishing, so no long-lived API key is stored. Use when setting up or debugging NuGet package publishing, GitHub Actions release workflows, the NuGet/login OIDC step, a trusted-publishing policy, release-please Release PRs, MinVer tag-driven versions, or a multi-package monorepo. Covers the hard gotchas: the "Actions can't create pull requests" toggle, first-release 1.0.0 vs Release-As, the 401 workflow-file mismatch, the NUGET_USER secret, id-token permission, and NU5104.
-
akillness Bundle RalphmodeConfigure Claude Code, Codex CLI, and Gemini CLI for Ralph-style automation with fewer approval prompts while keeping project boundaries, secret denylists, and sandbox-first safety rules intact.
42 -
steveclarke Skill 1passwordFetch secrets and create/manage 1Password items via CLI. Use when needing API keys, tokens, or credentials, or storing new secrets. Ask for the op://Vault/Item/field reference, not the secret itself.
-
steveclarke Skill Claude MdCreate, edit, audit, trim, or optimize any CLAUDE.md file. Triggers on 'init claude.md', 'update claude.md', 'audit my claude config', or any CLAUDE.md content task.
-
steveclarke Skill Doc AuditDoc Audit
-
matematicsolutions Skill Klauzule Kontraktowe PlLista kontrolna klauzul umownych dla polskiej kancelarii - przechodzi umowę po 41 kategoriach klauzul (taksonomia CUAD zlokalizowana do PL/UE) i oznacza, które są obecne, których brakuje i które są ryzykowne, z kotwicą do polskiego przepisu (KC, prawo autorskie, KP). Inny niz contract-review-pl (bulk audit portfela do tabeli) - ten skupia sie na JEDNEJ umowie i pyta "czego tu nie ma i co tu gryzie". Uzywaj gdy: "sprawdz klauzule w tej umowie", "czego brakuje w umowie", "spotting klauzul", "lista kontrolna kontraktu", "review pojedynczej umowy", "jakie klauzule ryzykowne", "audyt jednej umowy", przed podpisem / w negocjacji / przy DD pojedynczego kontraktu.
Audited -
matematicsolutions Skill Matematic Expert PanelGeneruje warsztat "MateMatic Expert Panel" - multi-perspective analiza casu kancelarii przez 5-7 ekspertow z roznych dziedzin (compliance officer, IT security, etyk AI, partner zarzadzajacy, junior prawnik, klient kancelarii, regulator). Cherry-pick patternu SuperClaude Business Panel mode (MIT) - 9 modeli person, scoring, decision matrix. Output - 90-min warsztat fakturowany 5-15k PLN dla zarzadu kancelarii + raport pozegnal. Uzywaj gdy kancelaria pyta o wieloperspektywiczna analize ryzyka AI, decyzje strategiczne wdrozenia AI, drugi opinion od ekspertow, war-gaming wdrozenia, pre-mortem nowego narzedzia. Trigger - "expert panel", "panel ekspertow", "wieloperspektywiczna analiza", "war game AI", "pre-mortem", "drugi opinion AI", "warsztat decyzyjny", "multi-perspective", "decision matrix AI". Bazuje na SuperClaude-Org/SuperClaude_Framework (MIT) - cherry-pick mode, NIE pelna instalacja frameworka.
Audited -
matematicsolutions Skill Matematic Konstytucja AIGeneruje "Konstytucje AI" dla kancelarii prawnej - dokument governance definiujacy zasady uzycia AI w organizacji, na bazie cherry-pick patternu github/spec-kit (constitution -> spec -> plan -> tasks). 6 sekcji - mission, principles (max 9 articles), boundaries, governance roles, audit, evolution. Output - dokument PDF/MD 10-25 stron + plan wdrozenia 6-8 tygodni (AI Implementation Playbook). Uzywaj gdy kancelaria pyta o AI governance, polityke AI, etyke AI, AI policy, regulamin AI, Konstytucja AI, zasady AI w kancelarii, AI Act compliance, RODO + AI. Trigger - "Konstytucja AI", "polityka AI", "AI governance dla kancelarii", "zasady AI", "regulamin AI", "audyt AI policy", "AI Act compliance", "wdrozenie AI plan", "AI Implementation Playbook". Bazuje na github/spec-kit (MIT) - cherry-pick methodology pattern, NIE pelna instalacja.
Audited -
matematicsolutions Skill Legal Request Router PlKlasyfikator zadania prawnego - patrzy na zapytanie (i opcjonalnie deliverable) i decyduje, ktora sciezka weryfikacji uruchomic: zwykla odpowiedz, weryfikacja cytatow (citation-grounding-pl), kontradyktoryjna debata (adversarial-legal-review-pl) czy paczka audytowa (legal-ai-audit-bundle). Ocenia zlozonosc i ryzyko, zwraca decyzje routingu z uzasadnieniem. To warstwa NAD warstwa weryfikacji - chroni przed paleniem tokenow na rutynie i przed przepuszczeniem spraw wysokiej stawki bez kontroli. Uzywaj gdy: "co z tym zrobic", "czy to wymaga debaty", "jaka sciezka", "rozdziel zadanie", "klasyfikuj zapytanie", "czy to high-stakes", "routing", "triage zadania prawnego", na poczatku obslugi nowego zapytania prawnego zanim wybierzesz narzedzia.
Audited -
n-n-code Skill SecurityEvidence-grounded threat modeling, vulnerability review, and secure implementation. Use for explicit security audits or primary risks involving authorization, untrusted input, external requests, parsers/uploads, secrets, sensitive data, isolation, or release integrity. Not for routine implementation or non-security red-teaming. Add `security-identity-access` for identity and tenant authorization.
-
n-n-code Skill Story ClarifierDraft, synthesize, rewrite, tighten, or split rough tickets, conversations, user stories, feature definitions, and acceptance criteria into testable story cards or split story sets, or audit existing story inputs with a separate readiness report. Use for ambiguous story-level product behavior or when supplied discussion and artifacts must be consolidated without interviewing; not for PRDs, test strategy, repository scouting, implementation planning, or coding.
-
n-n-code Skill Backend GuidanceBaseline overlay for routine thin HTTP, gRPC, or message-consumer implementation and review; use `backend-systems-guidance` for multi-layer, data-access, transaction, reliability, or trust-boundary work. Compose with matching implementation guidance. Not for outbound-client-only or security-audit tasks.
-
n-n-code Skill Recursive ThinkingAdversarial review workflow for pressure-testing an existing candidate plan, diagnosis, design, argument, proposal, or recommendation. Use when the user asks to challenge its assumptions, run a premortem, play devil's advocate, red-team a non-security decision, or identify what would change the conclusion. Do not use for open-ended exploration (use thinking) or exploit-focused security review (use security as primary).
-
nielsmadan Bundle Review ProductReview a product from the user's perspective — build/refine a user persona, map their use cases (jobs-to-be-done), then audit the product for friction, gaps, and things to add or change. Triggers "review product", "product review", "review from the user's perspective", "product/UX critique", "what's missing for users". Use --live to also exercise the running app.
-
nielsmadan Bundle Review SecuritySecurity audit for vulnerabilities, secrets, and unsafe patterns. Use before releases, after adding auth code, or when reviewing third-party integrations.
-
peterbamuhigire Bundle Linux SysadminUse when a Debian/Ubuntu or RHEL-family server request needs routing across provisioning, security, services, networking, recovery, databases, containers, storage, performance, or compliance; use linux-troubleshooting when an unexplained symptom spans components.
-
peterbamuhigire Bundle Linux Firewall SslUse when inspecting or changing UFW/firewalld policy, issuing or renewing Certbot certificates, or validating host TLS exposure; use linux-webstack for application-server faults.
-
peterbamuhigire Bundle Linux Sysctl TuningUse when measured Linux performance evidence justifies persistent network, queue, writeback, swap, or congestion-control sysctl changes on Debian/Ubuntu or RHEL-family hosts. Profile first; use linux-server-hardening for security sysctls.
-
peterbamuhigire Bundle Linux Server HardeningUse when an authorised operator wants to remediate verified Linux security findings interactively across SSH, firewall, MAC, services, permissions, and updates; use linux-security-analysis first.
-
peterbamuhigire Bundle Linux Security AnalysisUse when performing a read-only, evidence-backed Linux security assessment across kernel, identity, network, services, storage, backups, and packages; use linux-server-hardening to remediate.
Audited -
peterbamuhigire Bundle Linux Log ManagementUse when inspecting time-bounded journald or service logs, correlating web/database/security events, or managing logrotate retention; use linux-observability for forwarding and linux-troubleshooting for multi-subsystem incidents.
-
peterbamuhigire Bundle Linux Intrusion DetectionUse when operating fail2ban, investigating its bans, or running qualified rkhunter/chkrootkit checks; use linux-auditd-rules or linux-file-integrity for compliance-grade auditing.
-
peterbamuhigire Bundle Linux Ngo Cyber ResilienceUse when designing or reviewing practical Linux security and incident resilience for NGOs, civil-society organisations, or small mission-led teams; use linux-server-hardening for host controls and linux-disaster-recovery for backup restoration.
-
kdlbs Skill Code ReviewReview changed code for quality, security, and architecture compliance. Use only when the user explicitly requests local review or a PR finding requires it.
-
tetherto Bundle Qv Pr ReviewDeep-dive review of any GitHub PR in tetherto/qvac. Validates gitflow, CI, title/body format, code quality, security, and applicable repo rules. Posts a PENDING review with inline comments. Use when reviewing a PR, given a PR link, or invoking /qv-pr-review.
-
tetherto Bundle Qv Devops Pr ReviewPR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling). Use when reviewing a PR that touches DevOps paths or invoking /qv-devops-pr-review.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include ralphmode, linux-sysadmin, security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.