Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
seroneyemmanuel4-afk Skill Forge PaymentsAudit money movement, pricing, entitlements, provider events, reconciliation, idempotency, and sensitive data boundaries. Use for payments, billing, subscriptions, refunds, credits, invoices, or financial ledgers.
-
seroneyemmanuel4-afk Skill Forge SecurityPerform a threat-informed audit of trust boundaries, injection, secrets, browser controls, dependencies, and abuse cases. Use for every production-bound application.
-
seroneyemmanuel4-afk Skill Forge ReliabilityAudit timeouts, retries, overload, dependencies, degradation, consistency, and operational objectives. Use for services and critical workflows with availability or durability expectations.
-
seroneyemmanuel4-afk Skill Forge IntegrationsAudit outbound and inbound integrations for authentication, validation, failure isolation, drift, and replay safety. Use for third-party apis, webhooks, sdks, and service-to-service calls.
-
seroneyemmanuel4-afk Skill Forge Supply ChainInspect dependencies, build integrity, provenance, releases, licenses, actions, and secret exposure across the delivery chain. Use for any project consuming or publishing software artifacts.
-
uniswap Skill Review CodeReview code changes for quality, security, and performance. Use when user says "review my changes", "do a code review", "check this for issues", "analyze code quality", "security review", "performance review", "is this PR ready", or needs architecture, security, performance, and style analysis.
-
uniswap Bundle Analyze CodeComprehensive code explanation and analysis. Use when user says "explain this file to me", "what does this code do", "analyze the security of this module", "review the performance of this function", or "help me understand this architecture".
-
uniswap Skill Analyze BundleAnalyze web application bundle size to find what's making it large and how to shrink it. Always use this skill whenever the user says "analyze the bundle", "what's making my bundle large", "bundle size analysis", "check my webpack output", "why is my app so big", "find heavy dependencies", "optimize the bundle", "check my Vite build size", "bundle is too large", "reduce my JS bundle", "find large modules", "tree-shaking opportunities", "what dependencies are bloating the bundle", "bundle report", "check build output size", "source map analysis", or asks to audit build artifacts for size. Also trigger when the user sees slow initial page load and suspects large JavaScript as the cause.
-
uniswap Skill Strengthen TypesAudit and harden TypeScript type safety by finding and fixing weak typing patterns. Always use this skill whenever the user says "strengthen types", "improve TypeScript types", "fix any types", "type safety audit", "remove any from the codebase", "tighten TypeScript", "find unsafe casts", "harden types", "type hardening", "clean up TypeScript types", "get rid of type assertions", "fix non-null assertions", "improve type coverage", "find implicit any", "type-safe refactor", "add missing return types", "reduce ts-ignore", "eliminate type suppression", "TypeScript strict mode cleanup", "fix weak types", "find type holes", "our types are too loose", or any request to make the codebase more type-safe. Also trigger when the user is migrating to strict mode, preparing to enable `noImplicitAny` or `strictNullChecks`, or doing a type-quality pass before a major release.
-
uniswap Skill Audit DependenciesAudit project dependencies for security vulnerabilities and outdated packages, then apply safe updates. Use when user says "audit my dependencies", "check for vulnerable packages", "run npm audit", "find security issues in my packages", "what packages are outdated", "update my dependencies", "dependency health check", or "fix security vulnerabilities in dependencies".
-
uniswap Skill Analyze Dead CodeFind and remove dead code — unused exports, unreachable modules, and stale files. Always use this skill whenever the user says "find dead code", "remove unused code", "clean up unused exports", "what code can we delete", "detect unreachable code", "what files are no longer used", "prune dead code", "unused exports cleanup", "find unused variables or functions", "what's safe to delete", "trim the codebase", "find unused imports", "identify unused dependencies", "dead code audit", or asks which symbols, files, or packages can be safely removed. Also trigger when the user is preparing a major refactor or cleanup sprint and wants to reduce surface area first.
-
shaishavmaisuria Bundle Verify ClaimsAudit load-bearing paper claims against evidence in results, tables, figures, experiments, or citations. Use for claim audits, overclaiming checks, first or state-of-the-art claims, significant-result wording, prose-table number mismatches, and camera-ready or rebuttal evidence checks.
-
shaishavmaisuria Bundle Plan SubmissionBuilds a backwards submission timeline from a conference deadline - days remaining (AoE-aware), abstract-registration offsets, author-list freeze, OpenReview/CMT/EasyChair/HotCRP/PCS account lead times and per-system steps, supplementary-material and code size limits, reciprocal-reviewing duties, and a dual-submission audit. Use when the user wants to plan a submission, asks how long until a deadline, mentions abstract registration, submission checklist, deadline countdown, "what do I need before the NeurIPS/ICML/CHI deadline", or asks what happens after submitting (rebuttal window, notification, camera-ready). Phase-aware - produces pre-submission, under-review, and camera-ready plans from venues/ profiles and flags overdue steps.
-
shaishavmaisuria Bundle Work With OverleafBridges an Overleaf project to the local skills so a paper kept on Overleaf can be checked, polished, and reviewed, then synced back. Use when a researcher says "my paper is on Overleaf", "sync my Overleaf project", "pull my paper from Overleaf", "run preflight on my Overleaf paper", "edit my Overleaf project locally", or "push my changes back to Overleaf". Walks the three real paths — Overleaf Git integration (clone as a local repo), GitHub synchronization, or download-as-ZIP for free accounts — gets the .tex into a local working copy the other skills operate on, and guides syncing changes back. Treats the Overleaf access token as a secret, never auto-pushes without confirmation, and re-verifies the current Overleaf method live since premium availability and steps change. Trigger words - overleaf, my paper is on overleaf, sync overleaf, pull from overleaf, push to overleaf, edit overleaf locally.
-
skills-il Bundle Israeli Smart SaverNot legal advice. Save money in Israel through smart shopping, cashback optimization, subscription auditing, and deal hunting. Covers Zap.co.il price comparison, BuyMe gift card strategies, Cashback.co.il and Cashdo rebate programs, credit card perks maximization (Visa Cal, Max, Isracard), loyalty program stacking, seasonal sale timing, and recurring expense optimization. Use when user asks about "lachsoch kesef", saving money in Israel, Israeli coupons, cashback, "hashvaat mechirim", subscription audit, "kamah ani meshalem", credit card benefits, "hotza'ot", reducing expenses, or smart shopping tips. Helps Israelis reduce monthly spending by identifying unnecessary subscriptions, switching to cheaper alternatives, and maximizing cashback on everyday purchases. Do NOT use for investment advice (use israeli-pension-advisor), mortgage comparison (use israeli-mortgage-comparator), or grocery price comparison (use israeli-grocery-price-intelligence).
-
10cg Bundle Aria DoctorAria 环境健康诊断器。检测 aria-plugin 默认 hook 安装状态、配置一致性, 辅助 owner 决策本地 copy 与 plugin SOT 的清理时机。 使用场景:"诊断 aria 安装状态"、"check secret-guard install"、 "dual install 状态"、"何时清理 local copy"、"plugin hook 没加载"
-
bkywksj Skill Security PermissionsTauri 安全与权限管理技能,指导 Capabilities 配置和安全最佳实践。 触发场景: - 需要配置 Capabilities 权限 - 需要理解 Tauri 安全模型 - 需要处理 CSP(内容安全策略) - 功能不可用可能是权限问题 触发词: 权限、Capabilities、安全、CSP、permission、安全策略、sandbox
-
lidessen Bundle Document WritingWrite, rewrite, or audit truthful prose for a real document, reader, and purpose without reducing quality to an anti-AI phrase list. Use for READMEs, design and decision documents, reports, explainers, guides, essays, internal notes, public project copy, or requests such as "write this document", "rewrite this README", "make this sound less AI-generated", "好好表达", "去 AI 味", "改写文档", and "这段话写得不像人". Do not use for choosing a shared name, visual layout, literal transcription, or mechanical formatting.
-
lidessen Bundle Design DrivenDesign-driven development methodology — the design/ directory is the single source of architectural truth; read it before coding, stay within its boundaries, and update it first when the system's shape changes. Use whenever starting development on this project, or when the user asks to create/update architecture docs, add a feature that may cross existing boundaries, refactor system structure, or understand the codebase architecture. Triggers on "design first", "update the design", "does this change the architecture", "write a design for", "what's the current design", or onboarding to a codebase's shape. Args — `/design-driven init` to configure a project, `bootstrap` to generate design from existing code, `audit` to reconcile design/ against current code.
-
lidessen Bundle Setup Lidessen SkillsOperational deployer for the lidessen skills collection — wires harness config (CLAUDE.md / AGENTS.md / .cursor/) in a target project, injects an L1 expression of selected sequence principles, and reconciles when lidessen evolves. Triggers on "/setup-lidessen-skills", "set up lidessen skills", "wire lidessen into this project", "sync lidessen principles", "install lidessen skills". Use after cloning or symlinking lidessen skills into a project, when adopting the collection, or when lidessen has new content the project hasn't picked up. Args — `init` to scaffold, `sync` to re-align with current lidessen, `audit` to check drift without writing. Pairs with harness (portable methodology); this is the lidessen-specific application layer.
-
agentsorg Bundle Motion AuditUse when auditing motion across an existing codebase and a prioritized fix plan is required, not a per-diff verdict.
-
cosmicstack-labs Skill Secure CodingComprehensive secure coding practices covering input validation, authentication, authorization, cryptography, secrets management, and error handling. Provides actionable code examples and checklists for building security into every stage of development.
Audited -
cosmicstack-labs Skill Security AuditComprehensive security audit methodology covering OWASP Top 10, dependency scanning, threat modeling, and vulnerability assessment. Provides actionable guidance for conducting systematic security audits from scope definition to final reporting.
-
deanpeters Bundle Aipom Data Readiness AuditAssess whether data is fit for a specific AI product decision across provenance, quality, access, representativeness, consent, privacy, freshness, and operations.
5.6k -
celestialdust Skill Code SimplificationReduce code complexity without changing behavior — the Review-stage QUALITY axis. Use the moment a slice's code is green but reads heavier than it should: deep nesting, nested ternaries, dead code, generic names, copy-paste duplication, speculative abstractions. Apply Chesterton's Fence (understand before you cut) and stay scoped to what changed. Quality only — it does NOT hunt for bugs (that is `code-review`/`security-and-hardening`). It REPORTS findings and edits nothing — not the code, not the tests; a simplification that cannot be had without moving behavior, a frozen test, or the repo's decided look is a HALT, not a finding.
-
celestialdust Skill Doubt Driven DevelopmentIn-flight adversarial review — subjects every non-trivial decision to a fresh-context reviewer biased to disprove, not approve, BEFORE it stands. Use during Plan and Implement (not at the merge gate) when correctness outweighs speed, when working in unfamiliar code, when stakes are high (production, security-sensitive logic, irreversible operations), or any time a confident output would be cheaper to disprove now than to debug later. If you feel certain, that is exactly when to reach for it.
-
codejunkie99 Skill API DesignerUse when the user wants to design a REST API with endpoints, schemas, error formats, pagination, versioning, and security. Triggers include "design an API", "REST API design", "API spec".
Audited -
codejunkie99 Skill Code ReviewerUse when the user wants a thorough code review covering security, logic, performance, readability, and best practices with severity-rated findings. Triggers include "review this code", "code review", "audit this code".
Audited -
codejunkie99 Skill Test Case GeneratorUse when the user wants comprehensive test coverage across happy path, edge cases, errors, security, and performance. Triggers include "generate tests", "test cases for", "write unit tests".
Audited -
dbc-oduffy Skill Architecture AuditRotational arch audit — score systems, audit the top, package spinoffs. Never edits code.
Audited -
dbc-oduffy Skill Plan Delivery AuditTriangulate plan claims against code and reviews for delivery status.
-
dennydkt Bundle Xb Audit调用受用户配置约束:高自动、中先确认、低须明确开启;用户指定其他技能时禁止接管。只读审查 xbskill 技能族的结构完整性、路由覆盖、契约一致性、安全边界、静默降级和更新漂移;结论必须引用文件与行号。触发:$xb-audit、审查 xbskill、检查技能系统、发布前验收。
-
deuxksy Skill Code Audit정적 코드 보안 분석. SAST scan → CWE 분류 → OWASP Top 10 매핑 → 수정 제안. 기본값은 현재 프로젝트 디렉토리. 다른 대상 스캔 시 경로 지정. 패키지 수준 CVE 점검은 /security:system-audit 사용.
-
deuxksy Bundle Docs Md ManagementUse when repository README.md, document hubs (docs/README.md, docs/okf/README.md), Diátaxis indexes, architecture documentation (arc42 structure, C4 diagrams, ADR decision records), or overall project docs under docs/ need audit, structuring, or updating.
-
deuxksy Skill Backdoor RemediationLinux 서버 백도어 제거·복구·예방 대응. 백도어 파일 삭제 rm, 프로세스 종료 kill, 역외 차단 iptables, 암호 변경 passwd, 크론/init.d 정리, SSH 강화, Fail2Ban/OSSEC 설치. Use when backdoor-investigation 스킬이 백도어 침해를 확인한 후. 전 명령 서버 파괴적 변경이므로 사용자 승인 후 실행.
-
deuxksy Bundle Backdoor InvestigationLinux 서버 백도어/맬웨어 침해 포렌식 진단. read-only 명령(ps/ss/find/strings/lsof/stat/journalctl)으로 프로세스·네트워크·파일·로그 조사 후 증거 수집·로컬 다운로드·보고서 자동 생성. Use when 백도어 의심 증상 - CPU 급증, 역외 연결, 모르는 계정, /etc 변경, 로그인 실패 급증, libudev.so/gcc.sh 흔적, Mirai. 서버 변경(rm/kill/iptables)은 backdoor-remediation 스킬.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include aipom-data-readiness-audit, analyze-code, forge-payments. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.