Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
captainflasmr Skill Code ReviewerExpert code review with actionable feedback on bugs, security, performance, and maintainability. Trigger on phrases like "code review", "review this code", "audit this code", "review my PR", "code quality check".
Audited -
captainflasmr Skill System AdministratorManage and troubleshoot computer systems with security-first practices. Trigger on phrases like "system administration", "system admin", "linux admin", "server management", "troubleshoot system".
Audited -
celestialdust Skill Git WorkflowTrunk-based git discipline — atomic save-point commits (~100 lines, one logical change), short-lived branches, descriptive why-not-what messages, and a hard secret scan before every commit. Use this BEFORE every commit, branch, merge, or revert. Git is always on: if you are about to write code or type `git commit`, you are already in this skill's scope. Skipping it means giant unreviewable commits, secrets baked into history, and lost save-points.
-
rachitkumarrastogi Skill Unity Animation Controller AuditUse for Animator Controllers: states, transitions, clips, avatar masks, override controllers, and Timeline playables.
-
sarojkjha Bundle Brand Voice GovernanceUse when the user wants to check whether content actually sounds like their brand — enforcing a defined voice across AI-generated or team-written copy at scale. Also use when the user mentions brand voice guardrails, tone consistency, on-brand/off-brand, banned words, content governance, style compliance, AI-content review, "does this sound like us", or keeping a large volume of content on-message. Checks content block by block against the brand's own do/don't rules and emits a pass/revise verdict with an audit trail.
-
stencila Bundle Figure ReviewCritically review an existing or proposed Stencila figure artifact for structural correctness, caption quality, layout, overlay annotation safety, cross-references, measurement validity, and approval readiness. Use when asked to review, critique, assess, audit, validate, or improve a figure block, multi-panel figure, subfigure grid, executable chart figure, caption, SVG overlay, ROI annotation, scale bar, panel labeling, or figure plan.
-
stencila Bundle Site Config ReviewReview a Stencila site configuration (stencila.toml) for correctness, completeness, best practices, and rendered appearance. Use when asked to review, audit, validate, check, or assess a site config, stencila.toml, site routes, redirects, site layout, layout presets, site nav, navigation, site access, access control, or site deployment readiness.
-
stencila Skill Software Code ReviewEvaluate source code for correctness, quality, security, style conformance, and maintainability, producing a structured review report with findings and recommendations. Use when the user wants to review, critique, audit, evaluate, or inspect source code — checking for bugs, logic errors, unhandled error paths, security vulnerabilities, naming and readability issues, complexity, duplication, coupling, testability, and API design. Discovers codebase conventions independently and produces an actionable report with severity-graded findings grouped by category, prioritized recommendations, and open questions.
-
stencila Skill Software Design ReviewCritically review a software design specification and suggest concrete improvements. Use when the user wants to review, critique, audit, evaluate, or strengthen a design spec, technical specification, feature design, architecture proposal, or implementation plan. Focus on clarity, completeness, correctness, feasibility, tradeoffs, risks, assumptions, and actionable recommendations that improve the design without turning the task into code generation or workflow design.
-
tianque6916 Skill Trailofbits Security安全审计 — CodeQL/Semgrep 静态分析、漏洞检测、智能合约审计
-
nero1688 Skill Citation Verifier無網環境的引用『內部一致性稽核+幻覺風險評估』。做三件事:(1) 內文↔參考文獻清單雙向對帳(孤兒引用、冗餘文獻);(2) APA 7 格式診斷;(3) 幻覺風險訊號標記(頁碼範圍異常、DOI 格式錯、作者-年份-期刊組合可疑)——只標『疑似、需工具驗證』,不宣稱已查證文獻真實存在。適用中英文論文的引用稽核。觸發詞:引用檢查、參考文獻對帳、孤兒引用、幻覺文獻、假文獻、chimeric、拼接文獻、APA 7 檢查、DOI 檢查、文獻一致性、citation check。與 check-citations 劃界:本 skill 是無網、做內部一致性與風險評估,無法確認文獻真偽;要對接 CrossRef/Semantic Scholar/OpenAlex 做真實性查驗,改用 check-citations(Claude Code 環境須加 anthropic-skills: 前綴)。與 thesis-consistency-audit 劃界:那個做全論文六維度數字對帳,本 skill 專攻引用與參考文獻。
-
nero1688 Skill Q1 Journal Reviewer模擬 FT50/UTD24/ABS 3*-4* 頂尖商管期刊(AMJ、SMJ、JOM、JFE、JCF、CGIR)匿名審查委員,對完整論文草稿或投稿版本產出正式審稿報告(Summary of contribution/Major concerns/Minor issues/Questions to authors/總判定)。審查維度含理論貢獻定位、識別策略與內生性、穩健性、機制、經濟顯著性 vs 統計顯著性。附屬功能:AI 使用揭露聲明建議稿。適用於家族企業、公司治理、ESG/TESG、TEJ panel regression 研究。觸發詞:審稿、模擬審查、reviewer 2、審查意見、頂刊審查、reject or revise、內生性檢查、識別策略、理論貢獻、投稿診斷、期刊審查報告。與 q1-journal-polisher 劃界:本 skill 做完整審查判定(要不要退稿、理論夠不夠),polisher 做投稿前英文潤飾管線;需要改英文措辭找 polisher。與 thesis-consistency-audit 劃界:後者做論文內部數字對帳(樣本數、表格、引用一致性),本 skill 做學術貢獻與方法論的實質評斷。
-
nero1688 Bundle Thesis Consistency Audit對管理/財務/策略的量化碩博論文做系統化『內部一致性稽核』,在投稿或口試前抓出會被審查委員打點的自相矛盾。附 scripts/audit_docx.py 做 .docx 機械對帳(表格加總、跨表樣本數、不可能值、離群、敘述↔迴歸 N 落差),另附 scripts/anonymize_office.py 做**雙盲投稿前的身分資訊稽核與清除**(core.xml 作者、app.xml 機構、custom.xml 計畫編號、註解作者、追蹤修訂作者——Word「檢查文件」不一定清得掉這些,是 desk reject 常見原因)。機械層外依 references/audit_checklist.md 人工核對。六維度:假設↔迴歸表對齊、樣本數一致性(篩選→敘述→迴歸)、篩選聲明↔敘述統計、資料品質界限(不可能值/離群/縮尾/相關逾0.9/同值重複)、文字↔表格數字、APA 引用與表註一致。觸發詞:一致性稽核、論文對帳、審稿、proofreading、雙盲、雙盲審查、匿名投稿、去識別、作者資訊、檔案屬性、中繼資料、metadata、desk reject、符號一致性、迴歸表檢查、樣本數對不上、假設對齊、表格檢查、引用一致、投稿前檢查、口試前檢查。與 q1-journal-reviewer 劃界:本 skill 做論文內部數字/表格/引用的機械對帳,reviewer 做學術貢獻與方法論的實質評斷。與 citation-verifier 劃界:引用只做內文↔清單雙向對帳,深度幻覺/真實性查驗轉 citation-verifier 或 check-citations。
-
nero1688 Skill Academic Journal Polisher台灣商管領域中文論文審查與潤飾。以資深學者觀點優化中文文句、去除 AI 慣用語(值得注意的是、在當今數位時代、綜上所述等)、對齊台灣學術文風(控制股東、盈餘分配權與控制權偏離、TESG 等術語),並嚴格區分『審查意見』與『潤飾後文本』分區塊輸出。適用領域:家族企業、公司治理、ESG/TESG、TEJ panel 研究的中文稿。觸發詞:中文潤飾、論文潤飾、去 AI 腔、學術中文、台灣學術文風、審查意見、文句優化、中文母語化、口試稿潤飾、期刊中文修改。與 q1-journal-polisher 劃界:本 skill 專做中文,那個做英文學術潤飾。與 q1-journal-reviewer/thesis-consistency-audit 劃界:那兩者做實質審查與數字對帳,本 skill 做中文文句層面的潤飾與台灣文風校準。
-
theophiluschinomona Skill Self ReviewCode-quality checklist run on Claude's own output before reporting done: unused imports, missing error handling, naming consistency, security issues. Use after completing any code changes.
-
theophiluschinomona Skill Coding StandardsSecurity-focused code review standards. Use when reviewing code for security issues, or when writing code that handles user input, authentication, secrets, file uploads, or database queries.
-
abpai Bundle Hexagon AuditAudit Ports & Adapters / hexagonal architecture boundaries in packages/ + adapters/ monorepos. Use for hexagon compliance, port/adapter separation, inward dependency flow, peer-adapter imports, and vendor SDK leaks.
-
andr-ca Skill Code ReviewUse when reviewing a diff, pull request, or code change — systematic checklist for correctness, clarity, security, testability, and adherence to the project's conventions. Covers what to look for, how to give actionable feedback, and when to approve vs. request changes.
-
andr-ca Skill Security ReviewUse when reviewing code for security vulnerabilities, performing a security audit, or checking for OWASP Top 10 issues — covers injection flaws, broken access control, cryptographic failures, secrets exposure, dependency vulnerabilities, and language-specific pitfalls for Python, TypeScript/JavaScript, and Go.
Audited -
andr-ca Skill Dependency AuditUse when adding dependencies, reviewing a project's dependency tree, or checking for known vulnerabilities and ownership risk — covers pip-audit, npm audit, govulncheck, lock file hygiene, update policy, and trust assessment.
-
andr-ca Skill Audit Review FollowupUse when asked to check whether review/audit recommendations were actually implemented, whether gaps were closed, or to re-score the repo — verifies claims against repo state instead of trusting status reports.
Audited -
aws-samples Skill Aidlc ReplayPrint a structured session narrative for stakeholders who weren't in the room. Numbers (stage counts, phase rollup, duration) come from `aidlc-runtime.ts summary`; prose comes from the audit trail and artefacts. Renders to the terminal only — writes no file, never mutates workflow state, never emits audit events.
-
aws-samples Skill Aidlc Session CostRead-only session cost view. Prints deterministic aggregates for the current workflow — duration, stage outcomes, memory entries, sensor firings, learnings captured — sourced entirely from `aidlc-runtime.ts summary`. Never mutates workflow state, never emits audit events, never writes files.
-
aws-samples Skill Aidlc Outcomes PackGenerate a comprehensive handover document at workflow close so the team can own, operate, and continue the system without re-running the workflow. Stage/phase/learning counts come from `aidlc-runtime.ts summary`; prose comes from the artefacts. Writes OUTCOMES.md but never mutates workflow state or emits audit events.
-
aws-samples Skill Aidlc Security PatchRun the AI-DLC workflow with the security-patch scope baked in — no scope detection. CVE response. Packaging over `/aidlc --scope security-patch`, which works without this skill.
Audited -
purpleailab Bundle PocGenerates and validates Foundry PoC tests from attack scenario documents. Use when: (1) Audit Phase 3 invokes Skill(vigilo:poc) for each High/Medium finding, (2) A finding at .vigilo/findings/ needs PoC validation, (3) Converting attack scenarios into executable Foundry tests. Outputs: test/poc/{finding-id}.t.sol, .vigilo/poc/ validation logs.
-
purpleailab Bundle AuditSmart contract security audit orchestrator. Use when user says "audit", "security review", "find vulnerabilities", "Code4rena audit", or starts an audit workflow. Automatically executes all phases: scope → recon → analysis → PoC → report.
-
purpleailab Bundle ReportGenerates submission-ready audit reports from validated findings. Use when: (1) Audit Phase 4 invokes Skill(vigilo:report) after PoC validation completes, (2) Findings need to be formatted for Code4rena, Cantina, Sherlock, or Immunefi submission, (3) Generating executive summary or individual submission reports. Default format: Code4rena. Reads from .vigilo/findings/ and poc/.
-
amit-t Bundle E2e AuditRun a Playwright end-to-end audit of a web app using its PRDs as the test spec. Produces a diagnostic report showing what's working and what's not from a user's perspective.
-
vinhnxv Bundle File TodosStructured file-based todo tracking for Rune workflows. Each todo is a markdown file with YAML frontmatter and lifecycle status. Source-aware templates adapt for review findings, work tasks, PR comments, tech debt, and audit findings. Session-scoped: todos live in tmp/{workflow}/{timestamp}/todos/, cleaned by /rune:rest. Use when creating, triaging, resolving, or querying todos from any Rune workflow.
-
vinhnxv Skill Using RuneUse when the user asks to review code, plan features, brainstorm ideas, audit a codebase, implement a plan, fix review findings, debug failed builds, analyze code impact, or run end-to-end workflows. Also use when the user seems unsure which Rune command to use, when the user says "review", "plan", "brainstorm", "explore idea", "audit", "implement", "fix findings", "ship it", "check my code", "what changed", or "help me think through this". Routes user intent to the correct /rune:* command. Keywords: which command, what to use, rune help, workflow routing, review, audit, plan, brainstorm, explore, implement.
-
vinhnxv Bundle ElicitationUse when comparing multiple approaches, when a decision has security or architecture implications, when root cause analysis is needed, or when thinking needs structure. Provides 24 reasoning methods (Tree of Thoughts, Pre-mortem, Red Team, 5 Whys, ADR). Auto-loaded by plan, forge, and review commands for eligible sections. Keywords: structured reasoning, trade-off, decision, compare approaches, risk analysis.
-
vinhnxv Bundle Roundtable CircleUse when running /rune:appraise or /rune:audit, when spawning multiple review agents, when TOME aggregation fails or produces malformed output, or when a TeammateIdle hook fires before expected output is written. Handles 7-phase lifecycle (pre-flight, Rune Gaze, inscription, spawn, monitor, aggregate, cleanup) for up to 8 parallel reviewers. Use when team cleanup fails after a review, when on-teammate-idle.sh blocks review completion, or when roundtable phases need to be re-entered after session resume. Keywords: roundtable, appraise, audit, TOME aggregation, inscription, Ash, team lifecycle, TeammateIdle, 7-phase, 8 reviewers, SEAL marker.
-
vinhnxv Skill Supply Chain AuditAnalyze project dependencies for supply chain risks. Checks maintainer count, commit frequency, CVE history, abandonment signals, bus factor, and security policy presence for each direct dependency. Supports npm, pip, cargo, go mod, and composer. Use when: "supply chain audit", "dependency risk", "check dependencies", "maintainer risk", "abandoned packages", "dependency health", "package security", "supply chain risk".
-
fieldlu Bundle Ml Hpo Strategy超参搜索 (HPO) 算法选型手册。当用户要调超参、纠结网格/随机/贝叶斯优化(TPE)/Hyperband 选哪种、问搜索空间怎么设计(对数尺度?哪些参数值得搜)、预算只够 N 次 trial 怎么分配、 或搜索跑一半没起色想止损时激活。 trigger: hyperparameter search/tuning 超参搜索、grid search 网格搜索、random search 随机搜索、Bayesian optimization 贝叶斯优化、Optuna、Hyperband、调参预算止损。 不适用于: 未做归因就开搜(先 ml-diagnosis,偏差主导时白搜)、实验记账 (ml-experiment-tracking)、六问总审(ml-pitfall-audit)。
-
fieldlu Bundle Ml Pitfall Audit新项目/新模型上线前的六问前提审查清单。报告"指标虚高""线下好线上崩""加数据反而 变差""结果不可复现",或上线/投稿前需健全性检查时调用。六问:训练数据无偏采样吗/ 测试错误率独立采样吗/分布形式假设对吗/集成个体误差独立吗/未标记样本同分布且相似→ 相似吗/完美表现是不是信息泄露。每问配诊断信号+修正方案。不适用于已定位的单一技术 问题、纯工程bug。trigger: data leakage, 数据穿越, assumption check, 线下线上 不一致, offline online gap, too good to be true, sanity check, 审稿被质疑。
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include code-reviewer, system-administrator, git-workflow. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.