Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
full-stack-skills Bundle Rust Java Migration TestingDesign, implement, audit, and report lossless Java-to-Rust migration tests without promoting green tests into false completion claims. Use when porting 100% of JUnit tests and concrete parameterized/dynamic cases, SHA-256-verifying source fixtures/resources/scripts/data, requiring complete per-case golden or live differential MATCH results, validating object/test ledgers, reviewing oversized Rust test files, organizing inline unit versus integration tests, adding Rust-specific obligations, comparing coverage, or building property, fuzz, mutation, concurrency, lifecycle, adapter, host, load, security, and rollback evidence. Enforces a 500-line cohesion-review threshold, an 800-line authored-file blocker, and idiomatic Rust test placement.
Audited -
hoetaek Bundle TheoSecurity review of code touching input, auth, crypto, privileges, or network — attack surface, default-deny, least privilege, cut corners. Not for general engineering (→ torvalds) or production-readiness (→ ramsay). Profane only on request.
-
hoetaek Bundle RamsayProduction-readiness review of work claimed done — unhandled errors, missing edge cases, absent tests/migrations/rollback, "works on my machine." Not for security (→ theo), code craft (→ torvalds), or whether it's excellent (→ ego/fletcher). Profane only on request.
-
hoetaek Bundle DijkstraCorrectness-rigor review of algorithms, state machines, and concurrency — is the code argued correct, or just observed to pass? Hunts missing invariants, unhandled states, accidental complexity. Not for general code quality (→ torvalds) or security (→ theo). Profane only on request.
-
hoetaek Bundle TorvaldsBlunt maintainer code review of a diff, PR, branch, or repo — correctness, contracts, data loss, tangled ownership, complexity, weak tests, and the one issue to fix first. Not for security (→ theo), correctness proofs (→ dijkstra), or readiness (→ ramsay). Profane only on request.
-
hoetaek Bundle AutopilotUse after a LEAF sprout's why / what / wireframe triple has been explicitly reviewed by the user and the user wants the remaining LEAF lifecycle to proceed automatically. Trigger on "$leaf:autopilot", "LEAF autopilot", "triple is approved, continue automatically", "run the rest of LEAF without asking", or "after this lock, handle the rest". Do not use for execution-ready direct work, unclear intent, destructive/external/credential/cost/security/privacy-sensitive work without explicit pre-authorization, or when the user wants normal per-gate approval.
-
huifer Skill Content AuditDeep dive into Content Integrity (CI) pillar. Verify originality, depth, volume, freshness, and proper structure of all content. Maps to ARB CI criteria: CI01-CI18.
-
huifer Skill Arb Full AuditUnified orchestrator for the complete ARB lifecycle. Accepts a URL + site type and automatically routes through all 4 Gates in sequence, halting at any veto condition. Produces a single consolidated report with score, grade, veto alerts, approval probability, and prioritized fix list.
-
huifer Skill Technical AuditTechnical Health (TH) comprehensive assessment. Verify SSL, performance, mobile-responsiveness, Core Web Vitals, structured data, and more. Maps to ARB TH criteria: TH01-TH20.
-
huifer Skill Trust Credibility StrategyMulti-phase strategy to build user trust and site credibility. Includes about page optimization, author verification, security signals, and user review integration.
-
huifer Skill Geo Localization ComplianceAudit regional compliance requirements for publisher monetization across privacy law, disclosure expectations, language coverage, and restricted verticals.
-
impertio-studio Bundle Axum Impl Auth JWTUse when adding stateless JWT authentication to an Axum service, when a login route must issue a bearer token, when handlers must require a valid token, or when migrating a JWT extractor from Axum 0.7 to 0.8. Prevents the hardcoded-secret security hole, the missing exp claim that makes every token fail to decode, implementing Claims as FromRequest instead of FromRequestParts, and leaking raw jsonwebtoken errors to the client. Covers the jsonwebtoken crate (v10, aws_lc_rs), the Claims struct, encode and decode, Validation::default, EncodingKey and DecodingKey from an env-var secret, the FromRequestParts extractor that makes any handler protected, the AuthError enum with IntoResponse, and the async_trait difference between 0.7 and 0.8. Keywords: axum jwt, jsonwebtoken, encode, decode, Claims, EncodingKey, DecodingKey, Validation, FromRequestParts, Authorization Bearer, JWT_SECRET, 401 unauthorized, InvalidToken, token expired, every token rejected, how do I protect a route, how do I add login to axum, what is a
-
sirkirby Skill Visitor AuditAudit visitor activity by correlating Access badge scans with Network client connections. Use when the user wants to know who visited, when, and what devices they brought.
-
sirkirby Bundle Unifi ProtectHow to manage UniFi Protect cameras and NVR — view cameras, smart detections, Find Anything detection search, recordings, snapshots, lights, sensors, Known Faces, license plates, and the Alarm Manager. Use this skill when the user mentions UniFi cameras, security cameras, NVR, recordings, motion detection, person detection, vehicle search, face recognition, Known Faces, license plates, snapshots, RTSP streams, floodlights, sensors, chimes, arming/disarming the alarm, or any UniFi Protect task.
-
sirkirby Skill Security PatrolShow everything that happened at a specific area across all UniFi products (Network, Protect, Access) in a given time window. Use when the user asks about activity at a door, entrance, room, or area.
-
sirkirby Bundle Security DigestGenerate a security digest summarizing events across UniFi Protect cameras, Access door events, and Network firewall activity. Use when asked about what happened overnight, security summary, event digest, recent activity, or reviewing camera and access events.
-
sirkirby Bundle Firewall AuditorAudit UniFi firewall policies for conflicts, redundancies, security gaps, and best practices. Use when asked to review firewall rules, check for security issues, audit network policies, or optimize firewall configuration.
-
skills-il Bundle Israeli Gov Form AutomatorAutomate Israeli government form filling via Playwright browser automation and PDF population. Prevents hours of manual form filling and data entry errors on government portals. Use when user asks about filling government forms, "tofes" (form), "milui tfasim" (form filling), "gov.il" portal submissions, online form submission, Rashut HaMisim (Tax Authority) filings, Bituach Leumi (National Insurance) claims, or Rasham HaChevarot (Companies Registrar) documents. Validates Teudat Zehut (ID numbers) with check digit, Israeli phone numbers (+972), and Hebrew address fields. Supports Doch Shnati (annual tax report), maternity grant claims, and company registration forms. Do NOT use for classified or security-clearance government systems.
Audited -
skills-il Bundle Israeli Municipal Audit ReportNot legal advice. For the internal auditor of an Israeli local authority writing the statutory annual report. Use when the user is a mevaker of a municipality, local council or regional council, or works in that office, and needs to structure the annual report, work out the statutory timeline, decide what belongs in the report, or understand who may see it and when. Covers the duties under section 170A of the Municipalities Ordinance, what an audited municipal body is, how the annual work plan is set and the two-topic cap on committee-requested subjects, the 1 April submission date, the full chain of deadlines through the mayor, the audit committee and the council including both fallback branches, the publication ban, and the rule that the report is not admissible as evidence. Do NOT use for state comptroller audits, for private-sector or company internal audit, for public complaints handled by the ombudsman role, or for financial-statement audits by an external accountant.
Audited -
vaquarkhan Skill Glba Ffiec Financial PrivacyImplements Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (16 CFR Part 314) and Privacy Rule (16 CFR Part 313) compliance aligned to FFIEC IT Examination Handbook modules for financial institutions—customer information protection, risk assessments, access controls, vendor oversight, and GLBA privacy notices (initial, annual, opt-out). Trigger when auditing banks, credit unions, fintech lenders, or insurance entities for GLBA Safeguards, preparing FFIEC cybersecurity examinations, reviewing customer information security programs, or harmonizing GLBA with state privacy laws. Do not use for California CPRA consumer rights alone (use ccpa-cpra-privacy-rights), PCI cardholder data controls (use pci-dss-encryption-key-management), or SOX 404 ITGC without GLBA customer information scope (use sox-itgc-audit).
-
microsoft Bundle CouncilifyBuild a NEW complete "council" for a domain — a panel of orthogonal review lenses that fan out cold, debate to consensus, and return a synthesized verdict with recorded dissent, exactly like /council and /design-council. Identifies the distinct lenses a domain needs (one load-bearing question each, mined from real archetypes — not invented), reuses existing lenses, and builds only the genuinely-missing ones (persona SKILLs via personafy, or agents when the role is an active builder). Use when creating a council, standing up a review panel for a domain (product, security, performance, data), or when someone says "councilify", "make a council", "build a <domain> council".
2.7k -
moonlarry Skill Proof CheckerRigorous mathematical proof verification and fixing workflow. Reads a LaTeX proof, identifies gaps via AGENTS.md paper architect/reviewer audit, fixes each gap with full derivations, re-reviews, and generates an audit report. Use when user says "检查证明", "verify proof", "proof check", "审证明", "check this proof", or wants rigorous mathematical verification of a theory paper.
-
moonlarry Skill Citation AuditZero-context verification that every bibliographic entry in the paper is real, correctly attributed, and used in a context the cited paper actually supports. Uses the AGENTS.md paper architect/reviewer role with web/DBLP/arXiv lookup to catch hallucinated authors, wrong years, fabricated venues, version mismatches, and wrong-context citations (cite present but the cited paper does not establish the claim). Use when user says "审查引用", "check citations", "citation audit", "verify references", "引用核对", or before submission to ensure bibliography integrity.
-
moonlarry Bundle Paper Grill With DocsRun a one-question-at-a-time claim-evidence reconciliation only after experiments are complete and a full or near-complete paper exists. Use to trace central Conclusion claims back through the Abstract, Introduction, Results, scientific-support verdicts, and raw-evidence audits, then write paper/CLAIM_EVIDENCE_RECONCILIATION.md. Route missing prerequisites to experiment-result-to-claim or experiment-claim-audit. Do not use before experiments, for experiment planning, broad paper review, manuscript rewriting, or replacing a zero-context evidence audit.
-
moonlarry Skill Experiment Claim AuditZero-context verification that every number, comparison, and scope claim in the paper matches raw result files. Uses a fresh paper architect/reviewer with no prior context to prevent confirmation bias. Use when user says "审查论文数据", "check paper claims", "verify numbers", "论文数字核对", or before submission to ensure paper-to-evidence fidelity.
-
nearform Skill Security Advisory ReviewAssess security advisories against a Git repository by creating an isolated worktree, building a PoC exploit, and validating whether the described vulnerability is real and exploitable. Use when given a CVE, GitHub Security Advisory, or vulnerability description to verify.
-
owl-listener Skill Process RetrospectiveAudit and improve an existing process.
1.7k -
renky1025 Bundle Skill Security Check专门用于skill安装前的安全检查。支持多种编程语言(JavaScript/TypeScript, Python, Rust, Java, Go, C/C++, Ruby, PHP等)。在用户安装任何skill之前自动执行安全检查,检查数据外泄、凭证访问、文件系统越界、敏感文件访问、动态代码执行、权限提升、持久化机制、运行时安装、代码混淆、进程侦察、浏览器会话访问等安全风险。必须在安装任何第三方或社区skill之前使用此skill进行全面安全审查。
Audited -
realjaymes Skill Product Onboarding ActivationDesigns complete onboarding, activation, retention, and expansion lifecycles for SaaS products. Use when the user mentions 'onboarding lifecycle,' 'activation strategy,' 'user onboarding,' 'time to value,' 'aha moment,' 'onboarding audit,' 'retention lifecycle,' or 'lifecycle design.'
-
rudrathegreat Skill Reproducibility AuditorAudit scientific analyses for deterministic environments, provenance, repeatability, and complete documentation.
-
sergio-bershadsky Skill Frappe APICreate secure REST API endpoints for Frappe Framework v15 with proper authentication, permissions, and validation. Triggers: "create api", "new endpoint", "frappe api", "rest api", "whitelist method", "/frappe-api". Generates v2 API compatible endpoints with type validation and security best practices.
-
sergio-bershadsky Skill Sequence DiagramUse when the user asks for a sequence diagram, ladder diagram, message-exchange diagram, or any temporal flow showing who talks to whom in order ("draw the OAuth flow", "show the request lifecycle", "diagram the protocol over time", "sequence diagram for X"). Produces dark-themed self-contained SVG with actor lifelines, sync/async/return messages, self-loops, halo text, and a geometry-audit gate that knows about lifelines.
-
serhiy-bzhezytskyy Skill Use The Tool For Its PurposeTo find real bugs in an unfamiliar project, don't audit its code hunting for smells — USE the tool for its actual purpose, on real data, at realistic N. The defects that survive green CI live in the step everyone skips: the gap between "it ran" and "you have a result" (aggregate, compare, report, export, the second run). Then reproduce each finding against the REAL method with a passing control, rule out your own setup, and check whether the thing you call missing is actually documented. Use when picking what to contribute in a repo you don't know. Trigger terms: find a bug, what should I fix, unfamiliar repo, where to contribute, audit the code, N=1, test-mode, demo path, real data.
-
yc-software Skill AdminAct for an org admin — the admin API (scope directory, per-scope config & SOUL, any scope's memory, transcripts & captured prompts, files, user roster & external users, audit/errors/metrics/egress) accepts your token when the user you're talking to is an org admin and started this turn themselves. Use when an admin asks you to inspect or change anything org-wide or in another scope, or anyone asks whether they're an admin.
Audited -
yc-software Skill Use Shared CredentialWhen you need to call a service the org has a SHARED credential for (a SERP/search key, a paid-API key, a data-vendor feed, a Git remote) — and the platform has told you that credential is available to this conversation — make the call BY PROXY through the credential broker. You never see the secret; the core stamps it onto the outbound request for you.
-
kali-decoder Skill CompactWrite, reason about, and debug Compact smart contracts for the Midnight blockchain. Use this skill whenever a user asks about Compact syntax, ledger state, witnesses, circuits, disclosure, ZK patterns, data types, standard library functions, security patterns, nullifier design, Merkle trees, or anything related to writing .compact files. Also trigger for questions about compiling contracts, debugging circuit errors, choosing between ledger ADTs, and implementing privacy-preserving patterns like commitments, hash-based auth, and anonymous membership proofs.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include process-retrospective, rust-java-migration-testing, theo. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.