Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
zimoliao Skill RenameUse when the user wants to normalize paper directory names to Author-Year-Title format after metadata correction or audit cleanup.
-
claude-hangar Bundle Auth AuditCustom auth security audit (bcryptjs + sessions, no OAuth/external provider). Use when: "auth-audit", "auth check", "auth security", "login audit", "session audit", "password audit".
-
claude-hangar Bundle DB AuditDatabase audit for Drizzle ORM + PostgreSQL with state persistence. Use when: "db-audit", "database audit", "drizzle check", "db check", "schema audit", "migration check", "postgresql audit".
-
claude-hangar Bundle AuditSystematic website audit (stack detection, 9 phases). Use when: "audit", "website audit", "site audit", "check website".
-
claude-hangar Bundle Audit RunnerAutonomous audit runner (separate sessions, no context limit). Use when: "audit-runner", "autonomous audit", "audit automatically".
-
claude-hangar Bundle Project AuditRepository audit for non-website projects (CLI, libs, backend, monorepo). Use when: "project-audit", "project audit", "repo audit", "code audit".
-
claude-hangar Bundle Security TeamLaunch parallel security analysis agents for comprehensive vulnerability assessment. Use when: "security team", "security audit", "security-team", "pentest", "vulnerability scan".
-
claude-hangar Bundle Skill StocktakeAudits skill quality across four dimensions (actionability, scope fit, uniqueness, currency). Quick Scan for changed skills, Full Stocktake for complete audit. Use for maintenance as the skill collection grows.
-
claude-hangar Bundle Adversarial ReviewCritical review (min. 5 findings). Modes: code, audit, plan. Use when: "review", "critical review", "code review", "plan review", "audit review".
-
claude-hangar Bundle Opensource ReadinessPre-publication audit for repositories about to go public or already public. Catches what other skills miss: secrets in git history (not just HEAD), license compliance, internal references (private URLs, internal hostnames, employee names), trademark exposure, attribution gaps, and community-readiness gaps (CONTRIBUTING, CODE_OF_CONDUCT, SECURITY.md, LICENSE headers). Use when: "open source readiness", "ready to publish", "going public", "pre-publish audit", "publish check", "open-source audit".
-
kazdenc Skill Deps AuditAudit project dependencies for outdated packages, known vulnerabilities, unused imports, and bloated bundles. Use when user says "audit dependencies", "check for vulnerabilities", "update packages", "unused dependencies", "bundle size", "dependency cleanup", or needs to maintain healthy dependencies.
-
kazdenc Skill Code ReviewPerform a structured code review covering correctness, readability, performance, security, and maintainability. Use when user says "review this code", "code review", "check this PR", "review my changes", "is this code good", or needs expert feedback on code quality.
-
kazdenc Skill Security ScanCheck code for OWASP top 10 vulnerabilities including injection, XSS, auth issues, and secrets exposure. Use when user says "security audit", "check for vulnerabilities", "security scan", "is this secure", "OWASP check", "find security issues", or needs to verify code security before shipping.
-
kazdenc Skill Supabase SetupInitialize Supabase for a project including database schema, Row Level Security policies, authentication, storage buckets, and edge functions. Use when user says "set up Supabase", "add Supabase", "configure database", "add auth", "Supabase init", "RLS policies", or needs a backend with Supabase.
-
luckyrjain Bundle Production Readiness ReviewRead-only orchestrator answering "is this PR/MR/release-candidate production ready?" by gathering trusted evidence (CI, code review, build provenance, SCM policy, change-impact, deployment-risk) and dispatching the applicable specialist reviews (security, observability, resilience, API design, database, performance, capacity, dependency-upgrade), then aggregating everything into one fail-closed verdict. Keywords: production ready, ready to release, ship this PR, go/no-go for one change. Not for generic code review (pr-review), a multi-repo/multi-service release sweep (release-readiness-checker), or a standalone change-impact/blast-radius/deployment-risk question (change-impact-analyzer, deployment-risk-review).
-
mangowhoiscloud Skill Slop Audit6-lens diagnostic slop audit — unused imports, dead private fns, duplicate signatures, abandoned TODOs, lint bypass markers, stale refs.
-
mangowhoiscloud Skill Codebase AuditCodebase audit + refactoring workflow. Dead code detection, God Object splitting, duplicate function removal, design flaw identification, frontier comparison verification. Triggered by "audit" ("감사"), "dead code" ("데드코드"), "refactor" ("리팩토링"), "god object", "duplication" ("중복"), "design flaw" ("설계 결함") keywords.
-
mangowhoiscloud Bundle Viz Frame AuditTrigger when: (1) the user mentions "noise", "slop", "frame audit", "video review", "letter spacing", "padding intrusion", "frame extract", "naive arrow", or Korean equivalents (노이즈, slop, 프레임 검수, 글자 깨짐), or (2) after rendering a new or modified Manim scene, or (3) the user asks to review an mp4 in `media/videos/` or `~/Downloads/`. Post-render audit workflow for Manim 1080p60 videos. Extracts keyframes via ffmpeg, inspects them through Claude Code's Read tool, and classifies any defects into four standing categories (naive arrow / padding intrusion / glyph kerning drift / frame-order error). Catalogues 12+ verified incidents across the four GEODE scenes so each is caught the first time, not rediscovered. The companion authoring skill is [[manim-scene-craft]].
-
mangowhoiscloud Bundle Manim Scene CraftTrigger when: (1) the user mentions "manim", "scene", "video", "EN/KO render", "GEODE_HERO_LANG", "1080p60", or (2) editing files under `scripts/visualizations/` ending in `.py`, or (3) the user asks to render, re-render, or extend any of the four validated scenes (`geode_hero.py`, `autoresearch_filewalk.py`, `autoresearch_compare.py`, `critical_floor.py`). GEODE Manim Scene authoring standard. Locks the patterns the four validated scenes already share — Anthropic-style palette, Helvetica Neue + Pretendard font pairing with weight=NORMAL, EN/KO multilingual lang via `GEODE_HERO_LANG` env, `_dashed_arrow_with_head` stage-coupled tinting, `verify_hero_layout.py` ratchet — so the next scene does not re-discover the kerning / padding / transition regressions catalogued in [[viz-frame-audit]].
-
mangowhoiscloud Skill Anti Deception ChecklistVerification checklist to prevent fake success. Detects test deletion/disabling, coverage regression, lint bypass, secret exposure. Triggered by "deception", "fake" ("가짜"), "fake success", "verification" ("검증"), "checklist" ("체크리스트"), "deletion detection" ("삭제 탐지"), "regression" keywords.
-
meyverick Skill Secure Gitignore ManagementManages and audits .gitignore files. Use when evaluating codebase security to strictly enforce a default-deny pattern for tracking files.
-
meyverick Skill Resilience And Security AuditingConducts security audits and resilience checks. Use when evaluating security, input sanitization, threat modeling, thread safety, or network fault tolerance.
-
modiqo Bundle Anthropic PDFUse for any task involving PDF files, including reading, extracting text or tables, creating, transforming, filling forms, OCR, image extraction, and security operations. Use for pdf, .pdf, PDF file, extract PDF text, extract PDF tables, merge PDFs, split PDF, rotate PDF, watermark PDF, create PDF, fill PDF form and OCR PDF. Use when the task needs to read or extract content from a PDF, extract tables from a PDF, merge, split, rotate, crop, repair, optimize, watermark, encrypt, or decrypt PDFs, create a new PDF, fill a PDF form, OCR a scanned PDF into searchable text and extract embedded images from a PDF. Requires `skillspec decide` before substrate tools or overlapping low-level skills. Preserves evidence with SkillSpec routes, forbids, dependencies, traces, and token-savings reports
-
modiqo Bundle SkillspecMultiplex SkillSpec post-install setup: inspect skill/repo shape with doctor, map multi-skill and plugin-shaped repositories before fanout import, assess a skill or plugin's security boundary — what it could reach if executed, ranked by risk (critical/high/medium/low), with a clickable-evidence tree — and gate or install it safely before it lands on disk, import existing SKILL.md skills from local folders or public URIs, inspect installed status, install compiled workspaces with entry/support visibility planning, install/update/enable/disable router mode, optionally install/update/enable/disable/delete durable-executor, create specs from observed durable execution workspaces, revise SkillSpec YAML, and prove value before install or release. Use for skillspec, /skillspec, skillspec setup, post install setup, assess skill security, is this skill safe, what can this skill reach, scan a skill or plugin, security analysis of a skill, boundary check, gate a skill or plugin install, check a skill before installing,
-
onfire7777 Skill NPM Audit PolicyApply npm audit checks without unsafe forced dependency churn.
-
onfire7777 Skill Gitleaks Secret ScanKeep secret scanning effective without leaking values or weakening CI.
-
onfire7777 Skill Architecture Contract AuthoringDefine the data, API, UI, state, security, tests, and rollback contract before queued work begins.
-
bsene Skill REST API DesignREST API design best practices — URI naming, HTTP verbs/status codes, pagination, filtering, error envelopes, versioning, security. Based on Octo's API design guide with modern updates. TRIGGER when: designing REST API, designing endpoint, API design review, URL design, resource naming, HTTP verb choice, status code choice, pagination strategy, cursor vs page pagination, error format, response envelope, API versioning, REST conventions, RESTful, "/users vs /user", PATCH vs PUT, 201 vs 200, 400 vs 422, idempotency key, rate limiting headers, expand/include parameter, HATEOAS, OAuth2, reviewing routes/controllers/handlers. DO NOT USE when: GraphQL, gRPC, WebSocket, or RPC-style APIs; pure backend logic unrelated to HTTP surface; OpenAPI/Swagger tooling questions only (use generic tools).
-
bsene Bundle Writing A Good Agents MdWrite, audit, or improve AGENTS.md — the tool-agnostic context file for coding agents — plus harness adapters (CLAUDE.md, .cursorrules, GEMINI.md, Copilot instructions). Use when creating one from scratch, auditing for bloat or anti-patterns, consolidating multiple tool files into one source of truth, or applying progressive disclosure.
-
jajupmochi Bundle Doc WritingUse when writing or updating any document a human will read — a design or architecture spec, a feature manual and its in-app guide, an audit / bugfix / test report, a README, release notes, a plan, or a session handoff. Encodes the document requirements mined from two real project sessions (define every term in place, prove every claim and say how a tester re-proves it, full clickable links, mermaid diagrams, nothing stale, remaining tasks highlighted, no secrets) and ships `scripts/doccheck.py` to lint the finished file against the ones a machine can check.
-
jajupmochi Skill Code VerifierAudit whether code, tests, scripts, or reported results are genuine before claiming success. Use before saying tests pass, code works, a script ran, training converged, or results show a conclusion.
-
jajupmochi Skill Feature Audit Templatefeature-audit-template
-
krzysztofsurdy Bundle PHP UpgradeStep-by-step PHP version upgrade playbook for PHP 8.0 through 8.4+ with automated tooling. Use when the user asks to upgrade PHP to a new version, check PHP compatibility, fix deprecation warnings, run Rector for automated refactoring, audit code with PHPCompatibility, or plan a PHP migration strategy. Covers breaking changes per version, php.ini configuration updates, extension compatibility, Rector rule sets, testing strategies, and the changelog-first upgrade workflow.
-
jaccen Skill CLI Policy Audit---
-
jqaisystems Bundle Skill ReviewerAudit AI skill files or skill folders for security risks before installing. Reads SKILL.md and related metadata, checks for dangerous patterns, and returns a safety verdict.
-
jqaisystems Bundle Client Delivery AuditorAudit final client deliverables against the agreed scope, verify files and links, and prepare a clear handoff with an unsent delivery message. Use when a user asks to check a delivery package, find missing or unverified items, prepare final files, create a client handoff, draft a delivery email, separate private evidence from public proof, or confirm that a project is ready to send.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include anthropic-pdf, skillspec, rename. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.