Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ryanmaclean Skill RedactUse when printing, logging, or verifying any credential, API key, token, or secret — pipe through redact to show only first/last 4 chars (e.g. fc1d...4439) instead of the full value
-
ryanmaclean Bundle Tiger TeamUse when facing a hard single problem that benefits from multiple expert perspectives simultaneously — debugging, architecture decisions, security review, incident response. Spawns 2-4 specialist agents (attacker/defender/architect/pragmatist) attacking the SAME problem from different angles.
-
zmice Skill Zc Context Budget Audit上下文审计
-
zmice Bundle Zc Security And Hardening安全加固
Audited -
zmice Skill Zc Developer Experience Audit开发者体验审计
-
lee-fuhr Skill Ww Plan AuditThe full gauntlet for plans. Runs automatically before exiting plan mode on any multi-phase plan, rather than waiting to be invoked by name. Combines interviewing, a principles deep read, multi-domain audit, steelman, pre-mortem, convergence, and prophylactic guardrails into one comprehensive quality process.
-
lee-fuhr Skill Qq Audit MasterMeta-orchestrator that selects and sequences the right combination of audit domains based on project context, conversation state, and user intent. Routes to 13 domain-specific audit skills containing 255 expert-persona frameworks.
-
lee-fuhr Skill Qq Audit TrackerCreates and maintains a live Notion tracking doc for audit runs. Standard format with overview table, live feed, per-domain sections, and findings summary. Used by qq-audit-master automatically.
-
lgtm-hq Skill ScorecardAudit the OpenSSF Scorecard rating for py-lintro. Use when asked to check the scorecard, understand the rating, or find what's missing. Specific to github.com/lgtm-hq/py-lintro.
Audited -
lgtm-hq Skill Sweep PrsRetrospective audit of recently merged/closed PRs for anomalies that slipped through - merges without green builds, merges onto red main, unresolved or post-merge review threads, hollow resolutions. Read-only sweep, then confirmed remediation (issues, disposition replies). Use when asked to sweep PRs, audit merged PRs, or check what slipped through.
-
lgtm-hq Skill Analyze CodeCode-level quality analysis. Use when asked to review code for smells, security issues, implementation quality, or test coverage.
-
murphytrueman Skill Token ComplianceCheck a codebase or implementation for token compliance — finding hardcoded values, wrong-tier token references, and inconsistent token application in consuming code. This checks how tokens are used in code, NOT how the tokens themselves are defined or structured. Trigger when someone says: are we using tokens correctly, find hardcoded values, token compliance check, find raw values, token misuse, are there any hex values in the code, checking token usage, or anything about whether tokens are being used consistently and correctly. Do NOT trigger for auditing the token definitions themselves — use token-audit for that.
-
henriquescastilho Skill Security Audit<!-- Source: claude-code-templates/security/security-audit.md -->
-
nolpak14 Skill Vies Vat ValidationValidate any EU VAT number for free via the official EU VIES service - confirm a counterparty's VAT registration, get the registered name and address (where the member state shares it), and obtain a consultation number as audit proof. Use as the first step of a KYB / KYC / AML check: validate the VAT, then pull the full registry record. Also validates EU EORI (customs/trade) numbers via the official EOS service. Trigger on: 'validate VAT number', 'check EU VAT', 'VIES', 'is this VAT valid', 'VAT number lookup', 'verify a VAT registration', 'EU VAT check', 'validate EORI number', 'EORI check'. VIES is keyless and free; for the full company record it routes to the free national skills and the paid regdata registry actors.
-
nolpak14 Skill Sanctions Pep ScreeningScreen a person or company against the official government sanctions lists for free - US OFAC (SDN + Consolidated), the EU Consolidated Financial Sanctions List, the UK Sanctions List, and the UN Security Council Consolidated List. Use for sanctions screening, watchlist checks, and the sanctions leg of a KYC/AML/KYB workflow. Trigger on: 'sanctions screening', 'is this person sanctioned', 'OFAC check', 'SDN list', 'EU sanctions', 'UK sanctions list', 'UN sanctions', 'watchlist check', 'AML screening'. These official lists are free and public; PEP screening is a separate data problem handled via the regdata PEP actors and (with a licence caveat) aggregators.
-
aks-builds Bundle Hitrust CsfWhen the user is preparing for, scoping, scoring, or maintaining a HITRUST CSF assessment or certification. Also use when the user mentions "HITRUST," "HITRUST CSF," "e1," "i1," "r2," "MyCSF," "PRISMA," "control maturity," "CAP," "corrective action plan," "validated assessment," "interim assessment," "readiness assessment," "inheritance," "CSP inheritance," "authoritative sources," or "HITRUST audit." For HIPAA itself, see hipaa-compliance. For cybersecurity program design, see healthcare-cybersecurity. For audit logs, see audit-logging.
-
aks-builds Bundle Phi HandlingWhen the user is designing or reviewing the operational controls around PHI — how to de-identify, anonymize, pseudonymize, encrypt, mask, minimize, or securely retain Protected Health Information across structured data, free text, images, audio, and biometrics. Also use when the user mentions "Safe Harbor de-identification," "Expert Determination," "limited data set," "DUA," "k-anonymity," "l-diversity," "t-closeness," "differential privacy," "encryption at rest," "TLS 1.2," "KMS," "HSM," "RBAC," "ABAC," "break the glass," "minimum necessary in practice," "DICOM PHI," "burned-in PHI," "audio PHI," "biometric PHI," "secure deletion," "retention schedule," or "cross-border PHI." For the regulatory backdrop, see hipaa-compliance. For audit-log design, see audit-logging. For EU rules, see gdpr-health-data.
-
aks-builds Bundle Audit LoggingWhen the user is designing, implementing, or reviewing audit logging for PHI access — including the HIPAA §164.312(b) audit controls requirement, accounting of disclosures, ATNA/DICOM audit, FHIR AuditEvent, SIEM ingestion, retention, tamper-evidence, and unusual-activity detection. Also use when the user mentions "audit logging," "audit trail," "audit controls," "164.312(b)," "164.308(a)(1)(ii)(D)," "accounting of disclosures," "164.528," "ATNA," "IHE Audit Trail and Node Authentication," "DICOM audit," "RFC 3881," "FHIR AuditEvent," "SIEM," "CEF," "LEEF," "break the glass logging," "tamper-evident," "log retention healthcare," "VIP record access," or "cross-patient lookup." For the regulatory basis, see hipaa-compliance. For the cybersecurity program, see healthcare-cybersecurity. For PHI controls, see phi-handling.
-
aks-builds Bundle Medical CodingWhen the user wants to design or build software that touches medical coding — computer-assisted coding (CAC), autocoders, NLP for clinical coding, code-set validation, audit support, HCC/risk-adjustment capture, or revenue-cycle pipelines. Use when the user mentions "ICD-10," "ICD-10-CM," "ICD-10-PCS," "CPT," "HCPCS," "HCPCS Level II," "J-codes," "CDT," "NDC," "DRG," "MS-DRG," "APC," "modifiers," "NCCI edits," "MUE," "PTP," "LCD," "NCD," "E/M coding," "MDM," "computer-assisted coding," "CAC," "autocoding," "coding audit," "RAC," "ZPIC," "UPIC," "OIG audit," "problem list," "HCC capture," or "RAF coding." For end-to-end claim submission/remittance, see billing-claims. For HCC risk score modeling and VBC programs, see value-based-care. For prior auth, see prior-authorization. This skill is for engineers building coding systems — it does not assign codes for real patient encounters.
-
aks-builds Bundle Gdpr Health DataWhen the user is processing health, genetic, or biometric data of people in the EU/EEA, UK, or other GDPR-aligned jurisdictions, or designing controls for special-category health data. Also use when the user mentions "GDPR," "Article 9," "special category data," "Article 6," "lawful basis," "explicit consent," "controller," "processor," "joint controller," "DPA," "data processing agreement," "DPIA," "DPO," "Article 30," "records of processing," "72 hour breach," "SCCs," "Standard Contractual Clauses," "Schrems II," "Transfer Impact Assessment," "TIA," "Recital 26," "UK GDPR," "EHDS," or "European Health Data Space." For US HIPAA, see hipaa-compliance. For operational PHI controls applicable globally, see phi-handling. For audit-log design, see audit-logging.
-
aks-builds Bundle Hipaa ComplianceWhen the user wants help applying the HIPAA Privacy, Security, or Breach Notification Rules to a healthcare product, workflow, vendor relationship, or incident. Also use when the user mentions "HIPAA," "PHI," "covered entity," "business associate," "BAA," "minimum necessary," "TPO," "treatment payment operations," "Notice of Privacy Practices," "NPP," "authorization," "Security Rule," "Privacy Rule," "Breach Notification Rule," "risk analysis," "SRA Tool," "OCR investigation," "tiered penalties," "HITECH," "HIPAA Omnibus," or "164." For operational PHI controls (de-identification, encryption choice, access design), see phi-handling. For cybersecurity program design, see healthcare-cybersecurity. For audit-trail design, see audit-logging. For EU data, see gdpr-health-data.
-
aks-builds Bundle Healthcare ContextWhen the user wants to create or update their healthcare context document, or whenever any other healthcare skill needs to understand the organization, patient population, regulatory jurisdiction, EHR/clinical systems, terminology in use, and security posture. Also use when the user mentions "healthcare context," "healthcare profile," "organization context," "covered entity," "business associate," "regulated jurisdiction," "EHR vendor," or "we are a [hospital/clinic/payer/digital health/etc]." Read this file first before any other healthcare skill — it controls assumptions every other skill makes (HIPAA vs. GDPR, FHIR vs. HL7 v2, Epic vs. Cerner, etc.).
-
aks-builds Bundle Healthcare CybersecurityWhen the user wants to design, assess, or harden a healthcare cybersecurity program — covering threat-aligned safeguards, medical device security, ransomware readiness, network segmentation, supply chain, and incident response. Also use when the user mentions "HHS 405(d)," "HICP," "Health Industry Cybersecurity Practices," "NIST CSF healthcare," "NIST SP 800-66," "medical device cybersecurity," "FDA premarket cybersecurity," "FDA postmarket cybersecurity," "SBOM," "SPDX," "CycloneDX," "MDS²," "IEC 80001," "IEC 62443," "zero trust healthcare," "network segmentation clinical," "ransomware playbook," "MFA healthcare," "PAM," or "phishing healthcare." For the regulatory basis, see hipaa-compliance. For operational PHI controls, see phi-handling. For audit-log design, see audit-logging.
-
davistroy Skill Spark AuditSSH into the DGX Spark and audit all running containers against known best practices and community optimizations. Reports gaps, misconfigurations, and optimization opportunities. Complements spark-recon (external landscape) with internal config validation.
-
davistroy Bundle Security AnalysisComprehensive security analysis with tech stack detection, vulnerability scanning, and remediation planning. Suggest when — security/vulnerabilities/CVEs/audit mentioned, new projects scaffolded, before releases/deployments/production, auth/input-handling code review, dependency updates, or new repos cloned.
-
espennilsen Skill NPMManage npm packages — install, publish, version bump, audit, and run scripts using the npm tool.
-
espennilsen Skill Npmjsnpm package maintenance and lifecycle management for monorepo extensions. Covers health audits, dependency sync, version bumping, changelog updates, pre-publish checks, coordinated publishing, and post-publish verification. **Triggers — use this skill when:** - User asks to "publish", "release", or "version bump" extensions/packages - User says "audit packages", "check package health", "dependency sync" - User asks to "update changelogs", "prepare release", "pre-publish check" - User mentions "npm publish", "version management", "package lifecycle" - User wants to "sync dependencies" or "align versions" across packages - User asks "what needs publishing" or "which packages changed" **Covers:** Monorepo with multiple npm packages under `extensions/`. Each package has its own package.json, CHANGELOG.md, README.md, and version. Packages are scoped (e.g. `@e9n/pi-*`) and published individually.
-
espennilsen Skill Code ReviewReview code for quality, security, performance, and maintainability. Use when reviewing PRs, auditing a codebase, or refactoring. Covers TypeScript, Node.js, infrastructure-as-code, and full-stack web apps.
-
espennilsen Skill Agents Md ManagerAudit, generate, update, and lint AGENTS.md files across all projects. Use when asked to check project context files, scaffold AGENTS.md for new projects, update stale ones, or run a cross-project audit.
-
espennilsen Bundle Dry Code ReviewPerform a comprehensive DRY (Don't Repeat Yourself) code review on a codebase. Identifies duplicated code, repeated logic, redundant patterns, and opportunities for abstraction. Use this skill whenever the user asks to review code for duplication, reduce repetition, apply DRY principles, refactor for reusability, find copy-pasted code, deduplicate logic, or audit code quality with a focus on redundancy. Also trigger when users say things like "clean up my code", "find repeated patterns", "too much boilerplate", "reduce code duplication", or "refactor for maintainability". Works on any language or framework.
-
ww-w-ai Skill AuditQuery audit trail logs, decision traces, and session history for AI transparency. Provides searchable access to all bkit audit records via MCP tools. Use proactively when user wants to review past decisions, trace actions, or inspect logs. Triggers: audit, log, decision trace, audit trail, history, 감사, 로그, 결정 추적, 이력, 監査, ログ, 決定追跡, 履歴, 审计, 日志, 决策追踪, 历史, auditoría, registro, rastreo de decisiones, audit, journal, traçage des décisions, Audit, Protokoll, Entscheidungsverfolgung, audit, registro, tracciamento delle decisioni Do NOT use for: creating new audit entries (hooks do that automatically), modifying logs
-
idanmann10 Bundle Audit Evidence RefreshKeep coding audits aligned with the latest committed evidence.
-
datex Bundle DB QueryUse when querying or mutating Datex Studio storage components via the `$db` predicate DSL — function-tier-only Mongo-backed access to `*-storage.json` configurations. Covers the fluent predicate operators (`.equals`, `.ne`, `.gt`/`.gte`, `.lt`/`.lte`, `.in`, `.isNull`/`.isNotNull`, regex via `.includes`, composed with `.and`/`.or` inside `.where`), result-row TypeScript-optionality semantics, the implicit `id` column, the `required: true` read-then-patch trap, and schema-change audit checklist. Flow datasources that back grids or selectors over `$db` are covered in the flow-db-datasources reference. Triggers: "query the storage", "add/update/remove rows in xxx_storage", "write a $db predicate", "filter by storage column", "$db predicate with AND/OR/null", "$db query returning wrong rows", "patch validation error", "TypeScript accepted my predicate but it doesn't work at runtime". For authoring the calling function itself, see function-creator.
-
datex Skill Impact AnalysisUse BEFORE any rename, removal, required-field change, or other contract-breaking edit to a config on a Datex Studio branch. Runs reverse-trace to find all callers, categorizes them (including write-side vs read-side for storage-shape changes), and presents a safety gate. Generic — works for any config type (functions, datasources, flows, storages, type definitions, reports, etc.). Also invoke when a calling skill asks you to "audit all callers" or "verify a contract change is safe" before proceeding.
-
datex Skill Branch Code ReviewerUse when reviewing the code/configuration changes on a Datex Studio feature branch. Traces dependencies, reads unified diffs across all changed configs, and produces a structured review with bugs / quality / security / performance / simplification / alignment findings plus a verdict. Trigger for: "review branch X", "code review this branch", "review the changes on <branch>", "audit branch before merge", "quality check this branch". For drafting a commit message on the same branch, use `commit-message-generator`.
-
matthull Skill ExploreAI-guided interactive code exploration for holistic comprehension. Pre-analyzes a codebase area with parallel subagents, then guides an interactive session with focused diagrams, code links, and narrative. Use when you want to deeply understand how a chunk of a system works — not audit it, not review it, but comprehend it. Triggers on "explore", "walk me through", "explain this codebase", "how does this work", or when the goal is understanding existing code.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include audit, redact, tiger-team. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.