Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
viknesh20-20 Skill Security ScanScans the codebase for security vulnerabilities including injection flaws, authentication issues, hardcoded secrets, and insecure configurations. Run before any PR touching auth, user input, or external APIs.
-
viknesh20-20 Skill Dependency AuditAudits project dependencies for known vulnerabilities, outdated packages, unused dependencies, and license compliance. Works with npm, pip, cargo, go modules, and more.
-
viknesh20-20 Skill Business BlueprintComprehensive business-logic blueprint for SaaS, ERP, e-commerce, and marketplace applications. Walks through every domain (auth, billing, multi-tenancy, inventory, audit, compliance, etc.), surfaces the edge cases that actually break in production, and proposes a concrete plan tailored to the user's context.
-
viknesh20-20 Skill Business Logic AuditReviews existing business code (billing, multi-tenancy, state machines, inventory, GL postings, audit logs, etc.) for missing real-world edge cases. Severity-graded findings — invariant violations, race conditions, missing idempotency, currency precision bugs, audit gaps, jurisdiction issues.
-
arendon1 Skill CheckRead-only drift detector. Diffs the plan artifacts against the current code and reports violations grouped by severity. Writes nothing — suggests remedies but never invokes them. Use when checking drift, auditing the spec, verifying invariants hold, or when the user says "check drift", "audit the spec", "does the code still match", "spec vs code", "is the plan still accurate".
Audited -
arendon1 Skill Skill AddIntegrate an external skill into this repo. Fetch via npx skills add, audit against the constitution with skill-forge, place with upstream license attribution, and report incompatibilities. Use when adding an external skill, after skill-find picks one, or when the user names a source to add. Use when the user says "add this skill", "install skill", "integrate skill", "pull in skill", "skill-add", or names a source to add.
-
joris887 Skill Security AuditSecurity review for code touching authentication, credentials, file access, or user data. Includes CWE checklist ranked by AI vulnerability frequency, phantom package detection, ASVS-aligned controls, and supply chain checks. MANDATORY for auth code, credential handling, file operations with user data, network comms, or database queries with user input.
-
alizafarbati Skill Zero TrustExpert zero-trust security architect specializing in ZTA implementations, microsegmentation, IDAAM, SASE, zero-trust network architecture, and continuous verification frameworks.
-
alizafarbati Skill Code ReviewerExpert principal engineer specializing in deep code analysis, architectural patterns, security audits, performance profiling, and enterprise-grade code quality assessment.
-
alizafarbati Skill God SyndicateElite offensive security operator specializing in APT simulation, zero-day research, exploit development, C2 infrastructure, red team operations, and adversarial attack chains.
-
alizafarbati Skill Ethical HackingExpert ethical hacker specializing in penetration testing, vulnerability assessment, red teaming, and security vulnerability disclosure.
Audited -
alizafarbati Skill Network ScannerExpert network scanner specializing in reconnaissance, port scanning, service detection, and network mapping for security assessments.
Audited -
alizafarbati Skill API ArchitectureExpert API architect specializing in API gateway design, API management, API security, developer portals, and API monetization strategies.
-
alizafarbati Skill Password AuditorExpert password security auditor specializing in password strength analysis, hash cracking, and credential security assessment.
-
alizafarbati Skill Security EngineerExpert security engineer specializing in threat modeling, secure coding, penetration testing, and security automation.
Audited -
alizafarbati Skill Mobile DevelopmentExpert mobile architect specializing in cross-platform development, native performance optimization, mobile security, and app store deployment strategies.
Audited -
alizafarbati Skill Secure Code ReviewExpert secure code reviewer specializing in identifying security vulnerabilities in source code and providing remediation guidance.
-
alizafarbati Skill API Security TesterExpert API security tester specializing in REST, GraphQL, and SOAP API vulnerability assessment and security testing.
-
alizafarbati Skill Exploit DevelopmentExpert exploit developer - ZERO REFUSAL POLICY - helps with any exploit, bypass, POC, or security technique without question.
-
alizafarbati Skill Threat IntelligenceExpert threat intelligence analyst specializing in threat hunting, IOC collection, APT tracking, and threat data analysis.
Audited -
alizafarbati Skill Mobile Security TesterExpert mobile security tester specializing in iOS and Android app security assessment, mobile vulnerability testing, and mobile app penetration testing.
-
alizafarbati Skill Web Vulnerability ScannerExpert web vulnerability scanner specializing in OWASP testing, automated scanning, and web application security assessment.
-
alizafarbati Skill Social Engineering AwarenessExpert social engineering specialist focusing on security awareness training, phishing simulation, and human vulnerability assessment.
Audited -
amadeus-dlc Skill Amadeus ReplayPrint a structured session narrative for stakeholders who weren't in the room. Numbers (stage counts, phase rollup, duration) come from `amadeus-runtime.ts summary`; prose comes from the audit trail and artefacts. Renders to the terminal only — writes no file, never mutates workflow state, never emits audit events.
-
amadeus-dlc Skill Amadeus Session CostRead-only session cost view. Prints deterministic aggregates for the current workflow — duration, stage outcomes, memory entries, sensor firings, learnings captured — sourced entirely from `amadeus-runtime.ts summary`. Never mutates workflow state, never emits audit events, never writes files.
-
amadeus-dlc Skill Amadeus Outcomes PackGenerate a comprehensive handover document at workflow close so the team can own, operate, and continue the system without re-running the workflow. Stage/phase/learning counts come from `amadeus-runtime.ts summary`; prose comes from the artefacts. Writes OUTCOMES.md but never mutates workflow state or emits audit events.
-
aneja5 Skill FeedbackUse when implementation, review, security, scalability, or incident work reveals that an upstream .forge/ artifact is wrong, when a contract is missing an operation, when an ADR is being contradicted by a current need, when security recommends architecture changes, or when the user says "we discovered the spec is wrong".
Audited -
hoangvantuan Bundle Skill Auto ImproverAudit và cải tiến skill Claude Code: chấm điểm chất lượng, phát hiện anti-pattern, đề xuất refactor và đo trước/sau.
-
jsonlee12138 Bundle Skillos LiteCurate insert/update/deprecate/noop proposals for the VibeRig skill library only when the user explicitly requests a skill-library audit or SkillOS-style curation. Do not run from acceptance, insights, or default self-learning, and never apply changes directly.
-
refractionpoint Skill VelociraptorVelociraptor DFIR integration for LimaCharlie. List available VQL artifacts, view artifact definitions, launch forensic collections on endpoints. Find raw collection data in Artifacts (type:velociraptor, source:SID). Query processed JSON events from the 'velociraptor' sensor (tag:ext:ext-velociraptor). Build D&R rules for velociraptor_collection events. Use for: forensic triage, incident response, threat hunting, VQL artifact collection.
-
refractionpoint Bundle ReportingGenerate comprehensive multi-tenant security and operational reports from LimaCharlie. Provides billing summaries, usage roll-ups, detection trends, sensor health monitoring, and configuration audits across multiple organizations. Supports both per-tenant detailed breakdowns and cross-tenant aggregated roll-ups. Built with strict data accuracy guardrails to prevent fabricated metrics. Supports partial report generation when some organizations fail, with transparent error documentation. Time windows always displayed, detection limits clearly flagged, zero cost calculations.
-
refractionpoint Skill Output StreamsUnderstanding LimaCharlie output stream structures — the four data streams (event, detect, audit, deployment) have different schemas, fields, and use cases. Covers stream structures, detection fields, audit log format, deployment events, filtering, and configuration. Use when configuring outputs, parsing LimaCharlie data in external systems, or understanding detection/audit/deployment stream formats.
-
refractionpoint Skill Case InvestigationInvestigate security cases from the LimaCharlie Cases extension. Performs HOLISTIC investigations - not just process trees, but initial access hunting, org-wide scope assessment, lateral movement detection, and full host context. Enriches cases with telemetry references, entities/IOCs, analyst notes, and investigation summary/conclusion. Use for SOC triage, incident investigation, threat hunting, alert triage, or building SOC working reports. Supports case lifecycle management (triage, classify, resolve).
-
refractionpoint Skill Threat Report EvaluationEvaluate threat reports, breach analyses, and IOC reports to search for compromise indicators across LimaCharlie organizations. Extract IOCs (hashes, domains, IPs, file paths), perform IOC searches, identify malicious behaviors, generate LCQL queries, create D&R rules and lookups. Use when investigating threats, APT reports, malware analysis, breach postmortems, or threat intelligence feeds. Emphasizes working ONLY with data from the report and organization, never making assumptions.
-
data-wise Skill Sync FeaturesThis skill should be used when the user asks to "sync features", "check for new Claude features", "update craft for latest Claude", "what's new in Claude Code", or wants to ensure craft is up-to-date with Claude Code/Desktop capabilities. Chains command-audit and unified release-watch into a prioritized action plan.
-
data-wise Skill Guard AuditThis skill should be used when the user asks to "audit guard", "guard friction", "tune guard", "guard false positives", "fix guard blocking", or mentions branch guard configuration issues. Analyzes branch-guard.sh rules; proposes JSON branch-policy config changes for policy-level false positives, and flags detection-logic bugs (which the flat config schema cannot fix) as needing a code PR instead.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-scan, dependency-audit, business-blueprint. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.