Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
grant-ge Bundle Policy Compliance Audit规章制度合规审查:用于逐条审查员工手册、考勤、薪酬、奖惩、休假等公司制度,识别无效条款、程序瑕疵和修订建议。
-
caglarbaranbora Skill PrivacyRoute Privacy Manifest (PrivacyInfo.xcprivacy) implementation tasks to the correct Knowledge Contracts -- file structure/bundling, required-reason API declarations, collected data type declarations, and tracking domains/third-party SDK signatures. Use when writing or editing PrivacyInfo.xcprivacy, NSPrivacyCollectedDataTypes, NSPrivacyAccessedAPITypes, NSPrivacyAccessedAPITypeReasons, NSPrivacyTracking, NSPrivacyTrackingDomains, NSPrivacyCollectedDataType, NSPrivacyCollectedDataTypePurposes, or handling "required reason API" / "privacy manifest" / "third-party SDK signature" tasks. v1 is manifest file implementation/schema only -- no App Store Connect nutrition-label questionnaire, no permission-request UI design, no Info.plist usage strings, no Keychain/security. Triggers on PrivacyInfo.xcprivacy, privacy manifest, NSPrivacyTracking, NSPrivacyTrackingDomains, NSPrivacyCollectedDataTypes, NSPrivacyAccessedAPITypes, NSPrivacyAccessedAPITypeReasons, required reason API, App Privacy Configuration, third-party SD
-
caglarbaranbora Skill NetworkingRoute URLSession networking implementation tasks to the correct Knowledge Contracts — request construction, async/await and completion-handler data fetching, Codable decoding, HTTP error handling, task cancellation, session configuration, App Transport Security, authenticated requests, session delegates and their invalidation, background transfers, progress reporting, authentication challenges, server trust and certificate pinning, and Combine's dataTaskPublisher. Use when writing or reviewing code that makes an HTTP request, decodes a JSON response, handles a network error, downloads a file in the background, reports transfer progress, or answers a TLS or credential challenge in Swift. Sign-in UX/terminology is out of scope here — see the authenticationservices skill. Triggers on URLSession, URLRequest, URLComponents, async await network call, data(for:), bytes(for:), dataTask, completionHandler, resume(), withCheckedThrowingContinuation, JSONDecoder, Codable decoding, DecodingError, HTTPURLResponse, URLErro
-
caglarbaranbora Skill App Store Review GuidelinesRoute App Store submission-compliance tasks to the correct Knowledge Contracts — app completeness, demo accounts, screenshot/description accuracy, in-app purchase requirements, external payment link restrictions, restore purchases, minimum functionality, spam/duplicate-app avoidance, permission usage strings, privacy manifest, privacy nutrition label accuracy, user-generated content moderation, developer contact information, data security, copycats and impersonation, the login-services equivalent option, third-party content licensing, Apple trademarks, and the ratings API. Use when preparing an app for App Store submission, implementing in-app purchase, writing Info.plist usage descriptions, building a PrivacyInfo.xcprivacy manifest, adding user-generated content or a social login, asking users for a rating, shipping third-party assets, or reviewing App Store metadata before submitting. Triggers on App Store review, App Review guidelines, app rejected, in-app purchase, IAP, restore purchases, demo account, sc
-
grimoire-rs Bundle Hex InitInitialize or reconfigure a project for the hex swarm - audits project context (CLAUDE.md/AGENTS.md) for the knowledge the orchestrators need (how to verify, spec/plan conventions), provisions what is missing into project context, optionally seeds default templates, and bootstraps the AI-maintained swarm memory at .agents/memory/hex.md (cached pointers, orchestration preferences, perspectives of interest). Re-entrant - run again anytime to re-audit pointers or change the setup.
-
grimoire-rs Bundle Hex ArchitectTiered architecture-decision orchestrator — evaluates trade-offs and produces ADRs or system designs through discover, research, design, and adversarial-review phases. Use for architecture decisions, ADRs, system design, trade-off analysis between approaches, one-way-door decisions, C4-level design, or NFR evaluation (scalability, availability, latency, security, cost, operability). Tier (low|medium|high|xhigh|max, auto by default) scales research-axis count and selection, whether the design is delegated to an architect worker, and review breadth.
-
grimoire-rs Skill Security AuditorSecurity Auditor
-
grimoire-rs Bundle Support DeskRoute a question to the team that owns an artifact. Use when a published skill misbehaves and you need the maintainer, the issue tracker, or the security contact rather than a code change.
-
grimoire-rs Bundle Code ReviewerReview a diff for SOLID/DRY violations, missing tests, and risky changes. Use when asked to review a pull request, audit a patch, or check code quality before merge.
Audited -
b-open-io Skill SigningThis skill should be used when signing messages, authenticating HTTP requests, or doing counterparty cryptography with a BRC-100 wallet. Covers BSM (Bitcoin Signed Message) signing, BRC-77 auth tokens for signed HTTP requests, deriving a counterparty's Type-42 public key (ECDH friend key), and encrypting/decrypting data for a counterparty. Triggers on 'sign message', 'BSM', 'Bitcoin Signed Message', 'auth token', 'BRC-77', 'signed request', 'friend public key', 'Type-42', 'ECDH', 'encrypt for counterparty', 'decrypt from counterparty', or 'shared secret'. Uses @1sat/actions signing module.
-
fcsouza Bundle Nuvemshop SdkPrepare, audit, implement, homologate, and publish Nuvemshop/Tiendanube apps. Use when the user needs help with Nuvemshop Partner Portal app creation, public App Store publication, private client distribution, OAuth, scopes, webhooks, API usage, NubeSDK migration or development, Nexo embedded admin apps, Nimbus/design requirements, homologation artifacts, demo videos, FAQ/support docs, billing/publication data, app descriptions, or approval checklists.
-
widnyana Skill Solana Security MainnetGuide users on security best practices, mainnet considerations, and risk management for blockchain operations. Activate when discussing mainnet operations, security concerns, or risk acceptance.
-
mangowhoiscloud Skill Wiki LintAudit and maintain the health of the Obsidian wiki. Use this skill when the user wants to check their wiki for issues, find orphaned pages, detect contradictions, identify stale content, fix broken wikilinks, or perform general maintenance on their knowledge base. Also triggers on "clean up the wiki", "what needs fixing", "audit my notes", or "wiki health check".
-
mangowhoiscloud Skill Tag TaxonomyEnforce consistent tagging across the Obsidian wiki using a controlled vocabulary. Use this skill when the user says "fix my tags", "normalize tags", "clean up tags", "tag audit", "what tags should I use", "tag taxonomy", or whenever you're creating or updating wiki pages and need to choose the right tags. Also trigger when the user asks about tag conventions, wants to add a new tag to the taxonomy, or says "my tags are a mess". Always consult this skill's taxonomy file before assigning tags to any wiki page.
-
mangowhoiscloud Skill Crumb SuggestRecommend the user's next action in an active Crumb session — /approve, /veto, /redo, /pause, wait, or open summary. Branches on last event + verdict + audit + stuck_count. Trigger on "이제 뭐 하지?", "다음에 뭐 할까?", "what next", "next action", "다음 단계", "이거 끝난 거야?", "이거 어떻게 마무리?", or any "I'm not sure what to do" hesitation. Read-only. Output: primary recommendation + 1-3 alternatives. Do NOT trigger for status snapshots (use `crumb-status`) or fault diagnosis (use `crumb-debug`).
-
allanbian1017 Bundle Evolution LogGenerate, update, or audit an Evolution Log — a narrative document that tells the development history of a project through iterative problem-solving cycles (Problem → Options → Decision → Result → New Problem). Use this skill whenever the user says 'update my evolution log', 'generate evolution log', 'audit my evolution log', 'verify evolution log', 'check evolution log for missing files or commits', 'clean up evolution log', 'write the project history', 'document the development journey', 'update EvolutionLog', 'add recent changes to evolution log', 'chronicle the project evolution', or any request to create, maintain, or verify a narrative development history from git commits, RFCs, RCAs, ADRs, or other decision documents.
-
allanbian1017 Bundle Decision SparringStress-test decisions, break analysis paralysis, and overcome procrastination using 9 structured mental models (Bottleneck Analysis, Inverting the Question, New Information Test, Time-Value, Regret Minimization, Hell Yeah or No, Optionality, Documentary vs Horror, Future-Me). Trigger whenever the user says 'help me decide', 'stress-test my decision', 'I'm procrastinating on', 'I can't decide between X and Y', 'break my analysis paralysis', 'decision sparring', '9 mental models', '幫我決策', '猶豫不決', or asks for a structured decision audit.
-
allanbian1017 Bundle Review Newsletter SubscriptionsAudit and evaluate newsletter subscriptions based on past 30 days of ingestion reports and suggestion review history. Analyzes newsletter frequency, suggestion conversion rates (accepted vs. rejected), and rubric blocklist vetoes to propose evidence-backed recommendations: Keep, Unsubscribe, or Adjust/Filter. Use whenever the user asks to 'review my newsletter subscriptions', 'audit newsletters', 'which newsletters should I unsubscribe', 'analyze newsletter subscriptions', 'evaluate newsletter value', '檢查電子報訂閱', '該取消訂閱哪些電子報', '分析電子報', or asks for advice on newsletter subscriptions.
Audited -
qwwiwi Skill LearningsLearnings System v2 — self-improvement через scoring ошибок. 3 слоя: Episodes (сырой лог) → Learnings (scored) → Rules (promoted). Используй когда: (1) пользователь поправил действие, (2) обнаружена ошибка, (3) нужен отчёт по learnings, (4) lint/audit накопленных уроков.
-
qwwiwi Skill Memory AuditСамоаудит памяти и состояния агента. Используй когда: (1) user пишет «аудит памяти», «проверь память», «memory-audit», (2) после крупных изменений. Проверяет: memory backend, личную память, скиллы, cron, heartbeat.
-
mikker Skill Solidify CodebaseDeep investigation and solidification pass on an existing codebase. Use when asked to audit, simplify, or future-proof a system; perform a deep cleanup/refactor pass; identify high-impact improvement opportunities; or present a vetted change list before implementing selected items.
-
mikker Bundle Stripe Best PracticesGuides Stripe integration decisions across API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, tax and registrations (Stripe Tax, automatic_tax, product tax codes), Treasury financial accounts, integration options (Checkout, Payment Element), migrating from deprecated Stripe APIs, and security best practices (API key management, restricted keys, webhooks, OAuth). Use when building, modifying, or reviewing any Stripe integration, including accepting payments, building marketplaces, integrating Stripe, processing payments, setting up subscriptions, collecting sales tax, VAT, or GST, creating connected accounts, or implementing secure key handling.
-
mikker Bundle Audit Xcode Security SettingsAudit and enable security-oriented Xcode build settings. Progressively enables compiler warnings, static analyzer checkers, and Enhanced Security features. Use when: user wants to secure their Xcode project, audit security settings, enable hardening, review security posture of build configuration, set up security-focused static analysis, enable static analysis, improve warning coverage, harden diagnostics, or catch more bugs at compile time in C/C++/Objective-C/Swift. SKIP: network security (TLS/ATS), code signing, privacy APIs.
Audited -
qdhenry Skill Convex Security AuditDeep security review patterns for authorization logic, data access boundaries, action isolation, rate limiting, and protecting sensitive operations
-
qdhenry Skill Convex Security CheckQuick security audit checklist covering authentication, function exposure, argument validation, row-level access control, and environment variable handling
-
talgacapri Skill Test BackendWrite, review, and audit backend tests for a Java codebase. Applies ISTQB CTFL v4.0 standards (black-box/white-box techniques, test pyramid, risk-based prioritization, defect taxonomy) with JUnit 5, Mockito, Spring Boot Test, and REST Assured. Triggers on "write tests for this service", "test this endpoint", "unit test", "integration test", "mock this repository", "test coverage Java", or any request to test Java backend code.
-
talgacapri Skill UX HeuristicsRun a usability audit using Nielsen's 10 heuristics and Krug's "don't make me think" principles, then return severity-scored UX issues and fixes. Use for heuristic reviews, usability audits, and pre-ship UX quality checks.
-
ligphidonk Bundle Inno Reference AuditThis skill provides reference guidance for citation verification in academic writing.
Audited -
augments-labs Bundle Post MortemUse after a production escape, late defect, data loss, outage, security incident, or badly failed work cycle, once the technical cause and containment are known and the open question is why the safeguards missed it or why the impact grew. Fires on how did this reach production, why didn't we catch this, and what do we change so it doesn't happen again, even if nobody says post-mortem. Skip while the technical cause is still unknown, and skip ordinary bugs.
-
augments-labs Bundle Feasibility CheckUse before an accountable owner commits to a project or initiative, when whether it can be done under real technical, delivery, operational, security, data, or dependency constraints is still uncertain. Fires on can we actually build this, is this realistic by the deadline, and what would it take, even if nobody says feasibility. Skip proven or trivially reversible approaches.
-
augments-labs Bundle Complexity AuditUse when existing code should be examined for accidental complexity — abstraction nothing needs, ownership it should not hold, flexibility nobody uses, or custom machinery a library already provides. Fires on is this over-engineered, why is this so complicated, and do we still need all of this, even if nobody says complexity or audit. Skip implementation choices, review of an exact candidate, and structural work already approved.
-
q00 Bundle Ce Compound RefreshRefresh stale learning and pattern docs under docs/solutions/ by reviewing them against the current codebase, then updating, consolidating, or deleting drifted ones. Use when the user asks to "refresh my learnings", "audit docs/solutions/", "clean up stale learnings", or "consolidate overlapping docs", or when ce-compound flags an older doc as superseded. Do not trigger for general refactor, debugging, or code-review work unless the user has explicitly pointed at docs/solutions/.
Audited -
foxl-ai Skill HealthcheckHost security hardening and risk-tolerance configuration
-
full-stack-skills Bundle Sa Token API SecuritySa-Token API 安全防御技能。覆盖 API 参数签名(sa-token-sign)防篡改防重放(timestamp+nonce+sign四步演进)、API Key(sa-token-apikey)部分授权与Scope控制(可吊销/可限权)、临时Token(SaTempUtil内嵌核心包)短效链接邀请。 API签名支持多应用(多secret-key)模式和多种摘要算法(md5/sha256/sha512)。API Key支持多账号体系、数据库持久化模式。临时Token支持前缀裁剪、反向查询、JWT集成。 基础登录认证请先使用 sa-token 技能。
-
goldziher Skill PHP ConventionsPHP code conventions covering PHP 8.2+ strict types, PSR-12 formatting, PHPStan/Psalm static analysis, PHPUnit, Composer dependency management, PSR-4 autoloading, and security. Load when writing or reviewing PHP code.
-
goldziher Skill Java ConventionsJava code conventions covering Java 17+ records and sealed classes, formatting/static analysis, Maven/Gradle, JUnit 5, exception handling, constructor injection, streams, and security. Load when writing or reviewing Java code.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-auditor, support-desk, code-reviewer. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.