Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
1yihui Bundle Oc Full Ops Audit RecipeEnd-to-end OpenClaw audit and remediation recipe for gateway, channels, nodes, security, and memory sync.
-
archsightlabs Bundle Aios Scheme专项施工方案通用入口。用于在未区分写作或审核时,按任务意图路由到 aios-scheme-write 或 aios-scheme-audit。
-
archsightlabs Bundle Aios Tender工程招投标通用入口。用于在未区分写作或审核时,按任务意图路由到 aios-tender-write 或 aios-tender-audit。
-
archsightlabs Bundle Aios Scheme AuditAios Scheme Audit
-
archsightlabs Bundle Aios Tender Audit工程招投标审核与响应性复核工作流。用于从招标文件、评分办法、资格条件和技术标要求中抽取废标风险、评分点、响应矩阵、资料清单和人工复核事项。
-
archsightlabs Bundle Aios Contract Audit工程合同审核与履约证据链复核工作流。用于从工程合同、补充协议、采购分包协议和履约资料中抽取节点、付款条件、责任边界、空白字段、资料缺口和人工复核事项。
-
jignesh-ponamwar Bundle Code ReviewReview code for correctness, bugs, security vulnerabilities, performance issues, and best practices. Produces structured findings with severity ratings and concrete fixes. Use when the user asks to review code, check for bugs, find security issues, audit code quality, or get a second opinion on an implementation.
Audited -
jignesh-ponamwar Skill Stripe IntegrationBuild Stripe payment integrations - one-time payments, subscriptions, marketplaces, and Connect platforms. Covers API selection (Checkout Sessions vs PaymentIntents vs Setup Intents), webhooks, restricted API keys, Stripe Connect (Accounts v2), billing, and security best practices. Use when accepting payments, integrating Stripe, building subscription billing, creating connected accounts, or reviewing Stripe integration code.
Audited -
jignesh-ponamwar Skill Supabase IntegrationIntegrate Supabase into applications - PostgreSQL database queries, Row Level Security (RLS) policies, authentication (email/password, OAuth, magic link), real-time subscriptions, storage (file uploads), and Edge Functions. Covers the Supabase JavaScript/TypeScript SDK, Python client, type-safe queries with generated types, and local development with the Supabase CLI. Use when building with Supabase, setting up auth, writing RLS policies, querying a Supabase database, or managing file storage.
-
the-artificer-of-ciphers-llc Skill Linuss LawApply Linus's Law when discussing code review practices, open source contributions, bug finding strategies, security auditing, or the value of having more people look at code. Trigger on phrases like "should we do code reviews?", "we don't have time for reviews", "how do we find bugs faster?", "open source is more secure", "how many reviewers do we need?", or any discussion about the relationship between the number of people examining code and the quality of that code.
-
mgifford Bundle CLI AuditAudit live URLs using Playwright and Axe combined with WCAG skills
-
microsoft Skill Cve RemediationScan dependency manifests against known CVEs and remediate by upgrading vulnerable dependencies to patched versions, then rebuild and re-scan to confirm. Self-contained scan→fix→verify loop for any project with a dependency manifest. Use when: a cve-remediation task is dispatched; dependency set changed (version bump, new framework); assessment flagged vulnerable or EOL dependencies; or user asked to "fix CVEs", "patch vulnerabilities", or "dependency security". Triggers: "cve", "remediate cve", "fix cves", "patch vulnerable dependencies", "vulnerability scanning", "dependency security", "vulnerable dependencies", "security advisories", "npm audit", "pnpm audit", "maven audit", "gradle audit", "dependency scan", "vulnerability remediation". NOT for: security audit of auth/input/secrets/OWASP code paths (use security-review).
2.7k -
monarchjuno Bundle Tcx PolicyReview workspace policy readiness before approval, including restricted lists, adapter eligibility, notional limits, approval readiness, information barriers, and audit gaps.
-
handoffacademy Skill Inbox Assistant OrganizeAudit, preview, or safely apply an inbox organization plan in ChatGPT or Codex. Use when the user types /inbox-assistant:organize or asks to clean up, label, archive, move, mark read, or delete inbox mail.
-
higgsfield-ai Skill Blender PbrGenerate a seamless albedo through a connected provider, derive aligned PBR maps locally, apply an editable Blender material and audit its scale, shading and repetition.
518 -
higgsfield-ai Skill Blender AnimationDynamic-by-default motion — the motion plan, semantic rigs, deliberate interpolation, constraints and drivers, surface contact, rotational aliasing, visibility keying, dynamic defaults per subject type, and the motion audit.
518 -
higgsfield-ai Skill Blender Audit FinalizeAudit a local Blender scene against its specification, measure structural, motion and visual failures, repair them, and save requested deliverables under the local recovery policy.
518 -
higgsfield-ai Skill Blender Lighting CameraCamera gate first, then motivated one-role-at-a-time lighting — direction/falloff/softness, world/HDRI, product and night setups, shaping with gobos/flags/negative fill, and the lighting audit.
518 -
huguryildiz Skill Layer SyncUse when checking whether the project's knowledge layers agree — the decision log, the spec/docs, the code, and the notebooks/reports — after a decision lands, after a refactor, before a phase closes, or when the user asks "is there drift", "did that decision propagate", "are docs and code in sync". Also use to register an explicit doc-to-source anchor link for point-precise checking. Trigger phrases: "sync check", "drift audit", "is the spec up to date with the code", "did D-numbers propagate", "link this doc to this source file".
-
karim-bhalwani Bundle GuardianSpecialized in quality assurance, security auditing, and performance optimization. Use when conducting code reviews, hunting bugs, scanning for vulnerabilities, profiling performance, ensuring security standards, or validating implementation quality.
Audited -
karim-bhalwani Bundle Top Web VulnerabilitiesComprehensive reference for the OWASP Top 100 web vulnerabilities. Identifies vulnerable patterns, explains impacts, and provides remediation guidance across injection attacks, authentication flaws, data exposure, and advanced attack vectors.
-
kimsanguine Bundle Decision LogAppend-only build/interview/pivot/hold/CONDITIONAL_GO decision log with 3-6 month self-eval audit. Records every gate decision with score + reasons; later backfilled with outcome (shipped, killed, alive_no_revenue, pivoted, external_success) to compute hit_rate, false_holds, and missed_builds. The only PM gate skill that measures its own accuracy over time.
-
konradcinkusz Bundle Security ReviewUse when performing a security review or triaging findings before launch. The repeatable method with justified N/A, the finding format, prioritization and the readiness ledger, plus the recurring rule sets: tokens in browsers, cryptographically secure random values, user-supplied paths and names, output/errors/rendering, and authorization structure. An audit whose output format changes each time cannot show whether the system is getting safer.
-
konradcinkusz Bundle Open Source ReleaseUse when moving a repository from private to public. The one-time gate that ongoing hygiene rules do not cover, ordered around the history-aware secret audit that cannot be fixed after the fact, plus licensing, the stranger-facing surface, and repo description and topics.
-
ldm2060 Bundle Paper Logic CheckUse when the user asks for a red-line consistency / logic check on near-final English LaTeX. High tolerance — only fatal issues are reported. Triggers on: "逻辑检查", "logic check", "校对", "proofread", "consistency check". Do NOT use for style polishing (paper-polish) or pre-submission audit (paper-sanity-check).
-
ldm2060 Bundle Paper Sanity CheckUse when the user is preparing to submit a paper or has completed a major revision and needs a pre-submission factual / structural / logical audit. Triggers on: "sanity check", "查错", "基础检查", "check paper", "verify paper", "论文检查", "pre-submission check". Six-pass audit. Do NOT use for writing style (paper-polish) or substantive review (paper-review).
-
ldm2060 Skill Sanity CheckFinal 6-dimension sanity check (logic/citation/reproducibility/novelty/venue/de-AI). Use before submission for comprehensive audit.
-
mikechongcan Skill Cfo AuditComprehensive ledger validation and integrity check. Verifies every transaction, checks for common errors, validates completeness, and produces an audit report. Use before filing taxes or at year-end. CLEAR step: Meta
-
mikechongcan Skill Cfo SnapshotGit commit your ledger with a meaningful message. Tag month-end, quarter-end, and year-end closes. Maintains the audit trail. Use after any meaningful ledger change. CLEAR step: Meta
-
hoangsonww Skill Audit RepoAnalyzes a GitHub repository for health, security, and maintenance metrics.
-
cai-aa Bundle Cylinder O GridPlan, create, adapt, and quality-audit coin-style five-block O-grid hexahedral meshes for cylindrical CAE models. Use for software-independent O-grid planning or implementation in a selected preprocessor, including requests mentioning 钱币原理、圆柱网格、中心正方形、顶点切到圆周、结构化六面体网格, mapped square-to-circle partitions, or HEX8 meshes. Includes a generic planner and an Abaqus/CAE execution adapter; do not claim automated support in another CAE application without a matching adapter or proved live native-tool path.
Audited -
phrazzld Bundle DiagnoseInvestigate, audit, triage, and fix. Systematic debugging, incident lifecycle, domain auditing, and issue logging. Feedback-loop-first protocol: reproduce or replay before root cause, pattern analysis, hypothesis test, and fix. Use for: any bug, test failure, production incident, error spikes, audit, triage, postmortem, "diagnose", "why is this broken", "debug this", "production down", "is production ok", "audit stripe", "log issues". Trigger: /diagnose.
-
phrazzld Bundle Human WritingEdit, audit, or rewrite prose so it sounds like a specific human wrote it, not a generic AI draft. Removes AI tells, filler, formulaic structure, fake polish, vague claims, and detector-bait phrasing while preserving truth, voice, and audience fit. Use when: "humanize this", "make this sound less AI", "remove AI slop", "de-slop this", "edit this prose", "make this sound natural", "fix the writing voice", "rewrite this copy". Trigger: /human-writing, /deslop.
-
spec-kitty Bundle Spec Kitty Mission ReviewReview a fully merged Spec Kitty mission post-merge (all WPs done/approved) to verify spec→code fidelity, FR coverage, drift, risks, and security. Triggers: "review the merged mission", "post-merge mission review", "verify the completed mission", "audit the mission implementation", "mission-level acceptance review", "is this mission releasable", "final review before tagging", "cross-WP coverage audit". Does NOT handle: per-WP review during implementation (use spec-kitty-runtime-review), implement-review loop orchestration (use spec-kitty-implement-review), setup or repair (use spec-kitty-setup-doctor), or glossary maintenance (use spec-kitty-glossary-context).
-
allura-ecosystem Bundle Bmad Testarch NfrAudit NFR evidence for performance, security, reliability, and scalability. Use when implementation evidence exists and the user says "audit NFR evidence", "audit NFRs", or "evaluate non-functional requirements"
-
allura-ecosystem Bundle Audit Packet DraftDrafts a human-review audit packet when a user asks "prepare an audit packet", "summarize the review", or "create a reviewer handoff".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include paper-sanity-check, bmad-testarch-nfr, blender-pbr. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.