Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
fieldlu Bundle Ml Leakage Defense数据泄漏专项防御。当用户怀疑线下虚高线上暴跌、某特征重要性异常高、验证集好得可疑, 或搭管道想事前防漏——归一化/填充/目标编码在切分前还是切分后做、时序能否 shuffle、 特征选择是否偷看测试集——时激活。 trigger: data leakage 数据泄漏、target leakage、train-test contamination、offline-online gap 线上线下不一致、too good to be true。 动作: 三大类型定位(特征-目标/训练-测试污染/过程泄漏)→信号核对→上线前检查清单。 不适用于: 六问总审(ml-pitfall-audit)、偏差方差归因(ml-diagnosis)、特征构造 (ml-feature-engineering)。
-
garrettjsmith Skill Semrush ToolWhen the user wants keyword research with search volume, competitive keyword analysis, site audit data, position tracking, or competitor organic analysis. Trigger on "keyword research," "search volume," "keyword difficulty," "what keywords do they rank for," "site audit," "Semrush," or "competitive analysis." Use Semrush for keyword data and competitive intelligence — use Ahrefs for backlink-focused analysis.
-
garrettjsmith Skill Local Competitor AnalysisWhen the user wants to analyze local search competitors, benchmark against map pack rivals, or understand why competitors outrank them. Also use when the user mentions "competitor analysis," "who's outranking me," "competitor GBP," "local competition," or "competitive audit." For geogrid-specific ranking data, see geogrid-analysis. For general map pack strategy, see map-pack-optimization.
-
guiziweb Skill Add SecuritySecure the admin panel with a User entity, firewall and access control
-
lukaskellerstein Skill Update DocsCreate or update project documentation. If no docs/ folder exists, creates comprehensive documentation from scratch using multiple parallel agents covering architecture, infrastructure, security, tech stack, and features. If docs/ already exists, re-analyzes the codebase and updates all sections EXCEPT docs/features/ (use update-feature-docs for feature documentation). <example> Context: User wants to create documentation for a project user: "create documentation for this project" </example> <example> Context: User wants to update existing docs user: "/update-docs" </example> <example> Context: Project has no docs user: "this project has no docs, can you write them?" </example> <example> Context: User wants to refresh docs after changes user: "update the project documentation" </example> <example> Context: User wants comprehensive documentation user: "document this entire codebase" </example>
-
christopheralphonse Skill Plan Review ArchitectureReviews architecture, data flow, dependencies, security boundaries, rollout, and failure scenarios.
Audited -
prowlrbot Bundle Code ReviewUse this skill when the user wants to review code, audit a pull request, check code quality, find bugs, or get feedback on implementation.
Audited -
prowlrbot Bundle Secret ScannerUse this skill when the user wants to scan code for secrets, find leaked credentials, check for hardcoded API keys, audit git history for sensitive data, or set up secret detection.
Audited -
alihusains Skill Hr Training Needs AnalysisConsolidates a team-level training needs analysis from evidenced capability gaps, separating genuine skill gaps from process, tooling and motivation problems that training cannot fix, and refusing to infer any individual's development need from job title, tenure or team average. Use when planning a learning budget, responding to an audit or regulator finding about competence, building a team capability plan, deciding whether to buy training, or consolidating individual development plans into one view. Trigger on 'training needs analysis', 'TNA', 'skills gap', 'capability assessment', 'learning plan', 'what training does the team need', 'development plan for the team'. Not for writing or grading a role profile (use hr-job-description-authoring) or for coaching a single person's objectives and review (use hr-performance-review-coaching).
Audited -
alihusains Skill Engineering Code ReviewA prioritised code review procedure: read the change for intent first, then correctness, security, and operability, and write findings with a severity that says whether they block the merge. Use when reviewing a pull request or diff, when a review has stalled in nitpicks, or when a change needs a risk-appropriate depth of review. Trigger on 'review this PR', 'review my diff', 'is this safe to merge', 'what should I look for in this change', 'the review is going in circles'. Not for reviewing a live incident fix under time pressure — take the hotfix path in engineering-incident-command and review after; not for architectural direction on a change that has not been written yet, which is engineering-decision-record.
Audited -
alihusains Skill Operations Vendor EvaluationRuns a defensible vendor or tool selection: requirements weighted and agreed before any demo, a scoring rubric with written anchors, mandatory pass/fail gates for security, data protection and viability, evidence recorded per score, and total cost of ownership including exit. Use when choosing between suppliers, software, or outsourcing options; trigger on 'evaluate these vendors', 'which tool should we buy', 'build a comparison matrix', 'vendor scoring', 'we're renewing this contract, should we switch'. Not for responding to someone else's RFP as the seller (use sales-proposal-assembly), not for documenting the resulting operational process (use operations-sop-authoring), and not for an internal build-versus-buy technical design (use engineering-decision-record).
Audited -
alihusains Skill Executive Board Pack PreparationPrepares board, executive-committee or steering material to a governance standard: the decision being asked for stated on the first page, options with real trade-offs, the management recommendation and the reasoning behind it, risks that are actually risks, and a disciplined split between the main body and the appendix. Use when material is going to a board, an exec committee, a risk or audit committee, or any forum that takes minuted decisions. Trigger on 'board pack', 'paper for the board', 'exec committee paper', 'steerco decision paper', 'prepare for the risk committee', 'we need approval from the board for X'. Not for a recurring delivery status (use operations-project-status-report), not for building slides from a finished analysis (use cross-functional-deck-assembly), and not for drafting the policy or standard a board is being asked to approve (use legal-compliance-policy-drafting).
Audited -
alihusains Skill Procurement Intake And Risk TieringHandles a vendor or purchase request at the front door: capture the underlying need rather than the named product, classify data exposure and business criticality into a risk tier using a fixed table, and list the reviews each tier requires before any evaluation or commercial conversation begins. Use when someone asks to buy, trial, renew or expand a third-party product or service, and when a request has already reached legal or security without being triaged. Trigger on 'we want to buy X', 'can we get a licence for X', 'vendor request', 'someone started a trial of X', 'does this need a security review', 'what checks does this supplier need', 'renewal is coming up'. Not for comparing shortlisted suppliers against weighted criteria (use operations-vendor-evaluation), not for reviewing the contract terms once a supplier is chosen (use legal-compliance-contract-review), and not for granting access to a system already procured (use it-access-review).
Audited -
alihusains Skill Legal Compliance Policy DraftingDrafts or revises an internal policy or standard with testable control statements, named accountable roles, a real exception route, and a mandatory self-audit that lists every change made to the source text — including changes nobody asked for — so a reviewer approves the actual diff rather than a summary of it. Use when writing a new policy or standard, implementing a regulatory change into internal rules, revising a policy after an audit finding or incident, harmonising conflicting policies, or preparing a policy for approval and publication. Trigger on 'draft a policy', 'update the standard', 'write the procedure', 'revise this policy', 'policy review', 'turn this into a standard', 'implement this rule internally'. Not for reviewing a counterparty contract (use legal-compliance-contract-review) or for assessing what a new regulation requires in the first place (use legal-compliance-regulatory-change-impact).
Audited -
alihusains Skill Legal Compliance Questionnaire ResponseAnswers an inbound security questionnaire, vendor assessment, due diligence questionnaire or RFP compliance section from a maintained evidence library: every question mapped to a named source document, every answer marked SOURCED, NEEDS-SME or UNANSWERABLE, and anything amounting to a legal, security or regulatory attestation routed to the named human who is entitled to give it. Never composes a control the organisation does not demonstrably operate. Use when a prospect, client, counterparty, auditor or insurer sends a questionnaire, when an RFP contains a security or compliance annex, when a vendor assessment must be returned by a deadline, or when the answer library itself needs building or refreshing. Trigger on 'security questionnaire', 'DDQ', 'due diligence questionnaire', 'vendor assessment', 'RFP security section', 'SIG', 'client wants our controls', 'fill in this assessment'. Not for evaluating a vendor we are assessing (use operations-vendor-evaluation) and not for the commercial and pricing body of
-
bxmaximum Bundle Bitrix SecurityCSRF, XSS, SQLi, SSRF, JWT/JWK, access rights, encryption. Use when handling input or auditing security.
-
dragoon0x Skill Absence AuditNotice what's deliberately missing from a design. Restraint is a taste signal. Use when studying minimalist products, evaluating design maturity, or understanding the power of removal.
-
dragoon0x Skill Visual AuditThe 10-second design audit. Look at any design and name what's working and what's not within seconds. Trains rapid pattern recognition for hierarchy, spacing, type, and color. Use when evaluating designs quickly, giving first-impression feedback, or building perception speed.
-
orientpine Bundle Deep Interview한국어 심층 인터뷰로 모호한 요구사항을 실행 가능한 명세로 변환합니다. 다음과 같은 경우 사용 — '인터뷰해줘', '심층 인터뷰', '전부 다 물어봐줘', '가정하지 마' 같은 요청, 막연하거나 수용 기준이 불명확한 작업, ralph/team/plan/autopilot 워크플로우 전 명확화 필요 시. 5개 불리언 게이트(non-goals/decision-boundaries/pressure-pass/closure-audit/contradiction-audit) + 가중치 기반 모호성 게이팅 + 7단계 상태 머신 + 4개 한국어 도메인 렌즈(기술/UI-UX/위험/트레이드오프) 적용. omo와 표준 Claude Code 양 환경 호환. 결과는 .claude/plans/interview-{slug}-{ts}.md 명세로 결정화.
-
srobinson Bundle WarroomOrchestrate a helioy-bus warroom: tmux agents doing parallel work under one orchestrator. Use for warroom, mixture of experts, MoE review, peer consensus, sign-off, brainstorm, spec-writing, scout, reuse audit, code-review, engineering, slice-build-loop, or any request that dispatches work to parallel agents.
-
srobinson Skill Maintain Verification SkillPeriodic pass that keeps a project's verification skill and feature map honest: parallel source readers per feature, one live session driving every feature, at most one PR of proven corrections. Use for /maintain-verification-skill or "audit the verify skill".
-
harshanandak Bundle DevForge DEV stage — implement an already-planned /plan task list into committed, test-backed code. Reads tasks.md + plan.md, then drives each task through a subagent TDD loop (implementer → spec-compliance reviewer → code-quality reviewer) with RED-GREEN-REFACTOR, HARD-GATE evidence checks, and a spec-gap decision score. Use when a plan and task list already exist and it is time to implement — triggers: "/dev", "start the dev stage", "build the tasks", "implement tasks.md test-first", "run the implementer/reviewer TDD loop", "write the code for the planned tasks one by one", "work through the task list with subagents". Per-task coding ONLY. Do NOT use for creating the design doc or task list (that is plan), for the post-build type-check/lint/security/test gate (validate), for pushing the branch or opening the PR (ship), for addressing PR review feedback (review), or for orchestrating several stages / taking an issue end-to-end to a merged PR (smith).
-
harshanandak Bundle PlanForge PLAN stage — first stop when starting a NEW or unscoped feature. Sets up an isolated worktree up front, then runs one-question-at-a-time brainstorming for design intent, commits a design doc, does technical/OWASP/DRY + codebase research, and produces a TDD task list for /dev. Trigger on "let's plan X", "scope a new feature", "brainstorm before we build", "write a design doc", "break this into tasks", or "set up a worktree and task list before coding". Reach for this even when the ask sounds like only design or only scoping — plan owns intent → research → task-list setup as one stage. NOT for driving a feature to a merged PR (that is smith), NOT for implementing tasks that already exist (dev), NOT for a standalone deep-research pass into an approved design doc (research), NOT for reporting where work stands or what is stale (status), and NOT for everyday issue create/list/close or picking the next ready issue (issue-basics / triage-ready).
-
harshanandak Bundle ValidateForge VALIDATE stage — the pre-pull-request quality gate. Rebases the branch onto the current base branch, then runs type-checking, linting, code review, an OWASP Top 10 security review plus dependency scan, and the full test suite, demanding fresh passing output in THIS session before anything ships. Reach for this whenever a branch is code-complete and someone says: validate my changes, run the quality gates, run the pre-PR checks, type-check and lint before the PR, run the security scan, or run the full test suite before opening a PR — and for the literal `/validate` command or `bun run check`. This is the gate that runs AFTER code is written but BEFORE a PR exists, so discriminate carefully: it does not implement features or write tests (that is `/dev`), it does not push the branch or open the PR (that is `/ship`), it does not answer PR review feedback from Greptile / SonarCloud / CodeRabbit (that is `/review`), and it is not the post-merge CI health check (that is `/verify`).
-
harshanandak Bundle Sonarcloud AnalysisSonarCloud deep-dive via its REST API: pull open issues (bugs, vulnerabilities, code smells), coverage/duplication metrics, quality-gate pass/fail with failed thresholds, security hotspots, and measure/analysis history for a whole project, branch, or PR, then return a ranked summary. Use whenever the user names SonarCloud or asks about code-quality metrics, technical debt, a red/failing quality gate, or static-analysis vulnerabilities/hotspots — e.g. 'why is the SonarCloud gate failing on this PR' or 'pull every BLOCKER vulnerability with file and line'. NOT for: the thin `/sonarcloud <query> <project>` slash command for a quick lookup (sibling 'sonarcloud'); replying to/resolving PR review threads across Greptile, CodeRabbit, or GitHub Actions ('review'); running local lint/type-check/test/security scans pre-ship ('validate'); implementing or patching a flagged issue ('dev'); or an external market/competitor report on SonarSource or DevSecOps vendors ('parallel-deep-research').
-
gtrabanco Bundle Audit PrAudit a whole PR against the delivery contract and return MERGE-READY or evidenced blockers with the full URL. Consumes the current review-change REVIEW-PASS receipt instead of re-running review axes; posts a SHA-bound ready comment; never edits or merges. Triggers: "audit-pr", "is this PR ready", "merge gate".
-
gtrabanco Skill Review CodeInternal correctness + simplification review pass of the agentic-workflow review pack — composed in-turn by review-change and product-audit; not a menu entry. Checks correctness, error handling, duplication, dead code, and simplification opportunities against the project's own conventions. Findings only; never edits code.
Audited -
gtrabanco Skill Review DebtInternal tech-debt transform pass of the agentic-workflow review pack — composed in-turn by review-change and product-audit; not a menu entry. Transforms the synthesized findings table into explicit debt items, each with a re-trigger condition; it does not rescan the diff. Findings only; never edits code.
Audited -
gtrabanco Skill Review PerfInternal performance review pass of the agentic-workflow review pack — composed in-turn by review-change and product-audit; not a menu entry. Checks the changed paths for algorithmic and resource regressions: N+1s, hot-path allocations, asset weight, and leaks. Findings only; never edits code.
Audited -
bogheorghiu Skill Pii GateInstalls a PII/secret gate into a git repo — pre-commit + pre-push hooks and a CI workflow that block personal names and secrets from reaching a remote. Fires BEFORE a repo can leak: on `git init`, "new repo", "set up a repo", "add a remote", "push this to GitHub", "publish this", "make this repo public", "first push", or "is it safe to push this?". Also fires on the retrofit case — an existing repo that already has a remote and needs the gate plus a full-history scan. Use when a repo will hold real names, client identifiers, addresses, or any personal context that must never enter git history. Covers denylist setup, the write-only `PII_DENYLIST` Actions secret, gitleaks secret scanning, and the armed-run proof that the gate actually blocks. Not for scanning a repo you are not about to push, and not a substitute for gitleaks alone.
-
bogheorghiu Skill Pr Merge GuardExplains and toggles the security-toolkit PR-merge guard — whether Claude is blocked from running `gh pr merge`. Fires in BOTH directions: when the user asks about it ("can you merge PRs?", "is there a setting that stops you merging?", "what's EXCOG_BLOCK_PR_MERGE?", "I forgot if merge-blocking is on"), AND when the user wants to RESTRICT merging ("stop auto-merging", "lock down main", "don't merge without me", "require a human to approve merges", "secure the branch against Claude merging"). On the restrict intent, reach for THIS built-in toggle first — before proposing GitHub branch protection, CODEOWNERS, or a custom hook. The guard is OFF by default. Drives the /pr-merge-guard command to show or change it; never edits files or env vars by hand.
Audited -
bogheorghiu Bundle Dev Job Defense TiesEvaluating a dev job, studio, or employer? Before taking it, screen who the work actually serves — is it military/defense behind civilian language, and is the buyer one your red line rules out? Runs cui-bono for the buyer-chain, then classifies by end-use and buyer-nationality against YOUR threshold. Ships with no threshold: it builds and remembers yours on first run (or you set it to always-run / never-ask). Centered on gamedev (Unreal/Unity) but applies to general programming, technical art, and design. Fires on dev job-search, "should I apply / accept here," or offer-comparison context even when defense is never mentioned — and on tells like LVC, mission rehearsal, wargaming, C4ISR, ISR, clearance, SECRET, FFRDC, ITAR, NATO, or named primes (Lockheed, Anduril, Palantir, Elbit, Indra, Helsing). Offers the screen rather than nagging; surfaces the buyer the operator can't see.
-
bogheorghiu Bundle Windows Wsl Security VerificationAm I compromised? After supply-chain news — a poisoned npm/PyPI package, a malicious VS Code extension, a backdoored dep that ran as you — this runs a guided IOC triage of a Windows + WSL2 dev box, then trims the attack surface the next compromise would use. WSL side: known-bad package versions, ld.so.preload, persistence (systemd/cron/autostart), planted SSH keys, shell-rc injection, executable .pth. Windows side: full AV scan (a third-party AV makes Defender passive — one scan, not two), second-opinion scan, Sysinternals Autoruns with VirusTotal, code --list-extensions, scheduled tasks, BYOVD-class drivers. Carries the discriminators that stop false alarms: filename IOCs via find not grep, VT named-family verdicts over aggregate labels, web-filter blocks vs infections. Fires on "am I hacked", "did I get owned", a named bad package or CVE in your dependency chain, or an AV detection you're unsure how to read. Windows/WSL-specific; verifies — does not harden. A clean result raises confidence, never proves.
-
buildgreatproducts Skill Studio Develop Code ReviewUse when the user has uncommitted changes and wants them reviewed before committing — the deliberate whole-diff correctness pass. Triggers on phrases like "review my changes", "code review", "check my work before I commit", "am I ready to commit", "review what we just built", "anything wrong with this diff", or any request to review uncommitted work. Runs in the app repo — the repository that contains `productos/`. Reads the working tree, staged changes, and new untracked files, states what the change is trying to do, reviews across five lenses (correctness, regressions, edge cases, a thin security pass, consistency), verifies every finding against the actual source before reporting, and delivers an in-conversation report — must-fix items, considerations, pre-existing issues — ending in an explicit verdict: ready to commit or not. Works standalone in any repo.
Audited -
buildgreatproducts Skill Studio Define Leverage FinderUse when the user runs a business or has deep expertise but no software idea yet and wants one MVP worth building. Triggers on phrases like "find my idea", "what should I build", "I have a business but no product idea", "find the leverage in my business", "turn my expertise into software", "audit my business for software ideas", "I don't know what to build", "productize my service", "software idea for my business", or any request to go from a running business to a single software idea. Audits where the money and time actually go, inventories leverage points, generates a 3-5 idea shortlist, scores it, routes between an internal tool (removing your own bottleneck) and a customer-facing product (productizing the value you already deliver), converges on ONE idea, and writes the Leverage Audit before handing off to studio-define-offer-builder. Not for picking features in an existing codebase — that's studio-develop-feature-finder. The Define entry point for members arriving with a business instead of an idea.
Audited -
chienchuanw Bundle Gh IssueCreate structured GitHub issues via gh CLI using type-specific templates (bug, feat, refactor, doc, perf, security). Use when filing bugs, requesting features, tracking work, opening tickets, or any intent to create a GitHub issue — even implicit phrases like "track this" or "file this".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include ml-leakage-defense, semrush-tool, local-competitor-analysis. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.