Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
sprngr Bundle Duck AdaptAdapts external skills to rubber-duck philosophy; audits skills for compliance and overlap. Use when: "adapt this skill", "make this duck-compatible", "audit skill", "should we add this skill".
-
sunilgentyala Skill XssCross-Site Scripting expert methodology covering reflected, stored, DOM-based, and mutation XSS. Includes CSP bypass, filter evasion, and post-exploitation (session hijacking, keyloggers, BeEF integration).
Audited -
sunilgentyala Skill JWTJWT (JSON Web Token) attack methodology. Covers algorithm confusion (RS256→HS256), none algorithm, weak secret cracking, kid injection, JKU header forgery, and claims manipulation.
Audited -
sunilgentyala Skill GRAPHQLGraphQL security testing methodology covering introspection abuse, IDOR via query manipulation, batching attacks, injection via arguments, and subscription abuse.
Audited -
tushaarmehtaa Skill ReadmeAudit, write, and verify README files for adoption, operation, contribution, or internal orientation. Use when repository documentation is missing, inaccurate, or hard to follow.
Audited -
tushaarmehtaa Bundle UI CopyAudit, write, and implement interface language across actions, forms, states, errors, progress, and notifications. Use when product copy must match system behavior and voice.
-
tushaarmehtaa Bundle HumanizeEdit or audit prose for generic AI patterns while preserving voice, meaning, uncertainty, and format. Use when writing sounds synthetic, repetitive, over-polished, or unlike its author.
-
tushaarmehtaa Skill SupabaseSet up, extend, or audit Supabase schema, grants, RLS, migrations, typed clients, storage, and external auth. Use when integrating Supabase or repairing data access and tenant isolation.
Audited -
tushaarmehtaa Skill Decision DocFacilitate, research, write, or audit decision records with options, evidence, tradeoffs, ownership, and review triggers. Use when a person or team must choose or document an approach.
Audited -
tushaarmehtaa Bundle Mobile FirstAudit and repair responsive interfaces from measured narrow-screen evidence without changing product intent. Use when a page clips, overflows, stacks poorly, or fails on touch.
-
tushaarmehtaa Bundle Product SpecCreate or audit product briefs and buildable specs covering scope, flows, data, permissions, rollout, and acceptance. Use when planning a new product or a change before implementation.
-
tushaarmehtaa Bundle Cold OutreachResearch, write, audit, and improve cold messages, introductions, replies, and sequences. Use when contacting prospects, investors, partners, candidates, or other professional recipients.
-
tushaarmehtaa Skill Remove AI SlopAudit and remove AI-like design and copy defaults using rendered evidence and confidence scoring. Use when reviewing an interface for generic or repetitive patterns.
Audited -
tushaarmehtaa Skill Social SharingAudit, implement, and verify canonical URLs, social metadata, preview images, and share links. Use when shared routes are missing, stale, generic, private, or incorrect.
Audited -
tushaarmehtaa Bundle Credit MeteringImplement or audit usage credits with atomic reservations, spending, grants, purchases, expiration, refunds, limits, UI state, and an immutable ledger. Use when an app meters consumable usage.
-
tushaarmehtaa Bundle Email With ResendImplement or audit Resend email with templates, queues, preferences, audiences, campaigns, webhooks, and delivery safety. Use when an app needs consent-aware email or Resend repair.
-
v0lka Bundle Code ReviewComprehensive code review methodology for evaluating code changes. Identifies bugs, logic errors, security issues, structural problems, performance concerns, and unintended behavior changes. Use when reviewing uncommitted changes, specific commits, branch comparisons, or pull requests.
-
spacezephyr Skill Space Xhs Account Audit小红书账号整体诊断与竞品对标。对一个或多个小红书账号做量化体检——定位清晰度、内容垂直度、封面统一性、标题钩子率、更新节奏、互动率、爆款率、粉丝转化效率八个维度打分,定位卡点并给出可执行改动。当用户说"账号诊断""帮我看看我的号""我的号没起色/不涨粉/流量下滑""主页体检""账号定位有问题吗""竞品账号分析""对标账号拆解""这个博主为什么能起来""帮我和竞品比一比",或直接贴出小红书主页链接/主页截图要求分析时触发。支持有数据源(GUAIKEI_API_TOKEN / SOCIALDATAX_API_KEY)的量化分析和无数据源的截图定性诊断两条路径。只做分析参谋,不做发布、不刷互动、不批量起号。
-
tikalk Bundle WorkspaceMulti-repo workspace coordinator for shared team context. Initialize .adlc/ structure, configure .gitignore, discover child repos, link them as Git submodules, and audit workspace health. Use --init for first-time setup, default mode for ongoing auditing.
-
tikalk Bundle Evals InitInitialize evals/{system}/ directory structure for evaluation system following EDD principles (Standalone). Choose PromptFoo or DeepEval based on tech stack, generate security baseline.
Audited -
tkersey Bundle SynesthesiaReversible cross-modal diagnostic lens for software. Use when the user asks what code, architecture, behavior, logs, APIs, or alternatives feel, sound, look, or move like; for compare-by-feel analysis; when literal analysis leaves multiple plausible structural, temporal, interaction, or boundary interpretations that cross-modal recoding could distinguish; or after an owning technical workflow documents such an ambiguity. Start from literal evidence and translate every sensory statement into a technical hypothesis, uncertainty, falsifier, and next move. Not for ordinary architecture, performance, readability, or UX audits; exact syntax; legal/compliance or security sign-off; or code mutation by itself.
-
tkersey Bundle Codebase DoctrineRecover a repository's latent constitution: the scoped authorities, governing laws, permitted variations, historical wounds, proof obligations, and governed aporia that explain how it remains correct and how future agents should act. Use for deep codebase learning plus durable doctrine, correctness atlases, authority/law/failure/proof analysis, doctrine refresh, audit, task-context projection, or evidence-based repository-skill candidacy. Research before asserting and preserve rival models until evidence discriminates them. Not for quick onboarding, one isolated invariant, implementation, generic review, or direct skill creation.
-
tomimor Bundle Miguel ReviewOpinionated code review that prioritizes minimal diffs, deletions over additions, and zero tolerance for dead code or premature abstractions. Reviews the current branch diff against a base branch. Use when the user mentions miguel review, PR review, diff review, code review, or audit.
-
tomimor Skill Loop Cve AuditIterative dependency-CVE remediation loop: scan with ecosystem-native advisory tooling, assess whether each high/critical finding is actually reachable (with call-path evidence, not vibes), fix the highest-risk reachable one with the smallest credible change, re-verify, and repeat. Terminates when no exploitable high/critical CVE remains or every remaining finding has an evidence-backed reachability assessment and an approved risk decision. Use when the user mentions CVEs, vulnerability scanning, dependency security, npm/pip/cargo audit, security patching, or wants a recurring dependency-security loop.
-
tuana-vn Skill Adversarial Baseline AuditChallenge promoted reverse-engineering baseline claims by trying to disprove them, detect over-generalization, stale evidence, test-as-runtime mistakes, and persistent hallucination before high-impact migration or design work.
-
tuana-vn Skill Current State Tdd SynthesisSynthesize verified reverse-engineering evidence and architecture models into a consumer-facing CURRENT_STATE_TDD.md that explains current responsibilities, dependencies, runtime flows, boundaries, state, variants, failure behavior, and evidence without turning the audit report into the baseline.
-
tuana-vn Skill Post Readiness Adversarial AuditIndependently challenge an IMPLEMENTATION_READY package after design-to-implementation. Resolve actual artifact paths from workflow state, verify workflow/gate integrity, audit requirement-to-WBS traceability, architecture consistency, negative requirements, boundary exposure, source anchors, and missing work before downstream implementation handoff.
Audited -
tuana-vn Skill Reverse Engineering Coverage AuditAudit reverse-engineering completeness by finding important architectural domains, entry points, implementations, configuration paths, boundaries, persistence areas, or lifecycle behaviors that were never investigated deeply enough.
-
tuana-vn Skill Observability Traceability AnalysisAnalyze whether a system has enough evidence to trace an operation across internal layers and external boundaries, identify troubleshooting blind spots, and design or review audit/log traceability without confusing logs with source-of-truth architecture.
-
withkynam Skill Vc Predict5 expert personas debate proposed changes before implementation. Catches architectural, security, performance, and UX issues early. Use before major features or risky changes.
-
withkynam Bundle Vc SecuritySTRIDE + OWASP-based security audit with optional auto-fix. Scans code for vulnerabilities, categorizes by severity, and can iteratively fix findings using vc-autoresearch pattern.
-
withkynam Bundle Vc Audit PlansAudit active project plan files for staleness, completion, and routing truth. Use when cleaning up plans, reconciling active work, or archiving completed artifacts.
-
withkynam Bundle Vc Audit ContextAudit project context routing, shared-skill discoverability, and Claude/Codex wiring. Use when context docs or skill surfaces move, split, or drift.
-
fullrefit Bundle ClearpathFile and folder naming and organization system (ClearPath v3.0). Renames and reorganizes files to one legible convention: lowercase-hyphens for words, UPPERCASE format/platform prefixes (LF, SF, LIC, LI...) on subfolders and files, underscore as a segment separator that joins co-equal topics and precedes the date, MMDDYY dates (month-first, never ISO or YYMMDD), topic-based folders, 4-level soft depth, never an empty folder. Reorganizes WITHIN a topic's own home, never into a global type-based master folder. Workflow: scan, show a BEFORE/AFTER tree, get approval, execute with copy-first safety and before/after tree snapshots archived to _archive/. Use when creating, renaming, organizing, or auditing files and folders. MANDATORY TRIGGERS: clearpath, organize files, rename files, naming convention, file naming, folder structure, audit directory, naming compliance, file organization, clean up folder, restructure folder, tidy directory.
Audited -
midudev Bundle Rails GuidesOfficial Rails documentation. Use when asked about any Rails-specific topic including ActiveRecord, routing, controllers, views, mailers, jobs, Action Cable, Action Text, Active Storage, migrations, validations, callbacks, associations, caching, security, or internals.
-
midudev Bundle Stripe Best PracticesGuides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial accounts, integration surfaces (Checkout, Payment Element), migrating from deprecated Stripe APIs, and security best practices (API key management, restricted keys, webhooks, OAuth). Use when building, modifying, or reviewing any Stripe integration — including accepting payments, building marketplaces, integrating Stripe, processing payments, setting up subscriptions, creating connected accounts, or implementing secure key handling.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include rails-guides, stripe-best-practices, duck-adapt. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.