Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
kali-decoder Skill Midnight SecurityPrivacy audit checklist, data leak patterns, and defensive Compact contract patterns for Midnight Network. Use when a user asks about what data is publicly visible on-chain, how to prevent accidental disclosure, how to audit a contract for privacy issues, how to implement commitment/nullifier patterns, domain separation, replay protection, witness trust, or front-running resistance. Also covers transaction semantics (guaranteed vs fallible phase), partial success implications, and what an observer can infer from the public transcript even when witness data is hidden.
-
yushui2022 Bundle Paper Formal WriterPlan, draft, audit, globally revise, format, and verify a formal mathematical-modeling paper after the Standard evidence gate passes. Use for the sole S7/S8 formal manuscript path, not for legacy micro-unit scaffolds.
Audited -
rcarmo Skill Graph DesignDesign, audit, and redraw inline SVG architecture and flow diagrams using source verification and a consistent orthogonal-routing visual language.
-
stevesolun Skill Ctx VerifySelect proportional validation for changes or reviews in the ctx repository. Use before handing off material code, workflow, migration, documentation, security, packaging, or release changes; before a PR; or when asked whether a change is adequately tested. Do not use for pure questions with no changed artifact.
-
stevesolun Skill Lat Md Knowledge GraphDesign or audit a repo-local markdown knowledge graph with wiki links, source-code backlinks, drift checks, and searchable sections. Use when AGENTS.md/CLAUDE.md is too flat for a large codebase or when a custom harness needs durable structured project memory.
-
viewway Bundle Code ReviewMiniHES 代码审查。当用户请求审查代码、review PR、检查变更时激活。 支持本地变更审查和指定文件审查,输出结构化审查报告。 引用 backend-checklist.md 和 frontend-checklist.md 作为审查依据。
-
viewway Bundle Security AssuranceEnsures system security through audits and automated scans
-
koinod Bundle MoltguardMoltGuard — runtime security plugin for OpenClaw agents by OpenGuardrails. Helps users install, register, activate, and check the status of MoltGuard. Use when the user asks to: install MoltGuard, check MoltGuard status, register or activate MoltGuard, configure the AI Security Gateway, or understand what MoltGuard detects. Provides local-first protection against data exfiltration, credential theft, command injection, and sensitive data leakage. Source: https://github.com/openguardrails/openguardrails/tree/main/moltguard
Audited -
koinod Bundle API GatewayConnect to 100+ APIs (Google Workspace, Microsoft 365, GitHub, Notion, Slack, Airtable, HubSpot, etc.) with managed OAuth. Use this skill when users want to interact with external services. Security: The MATON_API_KEY authenticates with Maton.ai but grants NO access to third-party services by itself. Each service requires explicit OAuth authorization by the user through Maton's connect flow. Access is strictly scoped to connections the user has authorized. Provided by Maton (https://maton.ai).
Audited -
managedcode Bundle CodeqlUse the open-source CodeQL ecosystem for .NET security analysis. Use when a repo needs CodeQL query packs, CLI-based analysis on open source codebases, or GitHub Action setup with explicit licensing caveats. USE FOR: the repo uses or wants CodeQL for .NET security analysis; GitHub code scanning is part of the CI plan. DO NOT USE FOR: teams that need a tool with no private-repo licensing caveat. INVOKES: inspect the repository context, edit targeted files, and run relevant build, test, lint, or validation commands when changes are made.
-
flyfission Skill Checking Legal And Safety WordingReviews public text for license, warranty, compliance, safety, security, certification, and fitness claims that go too far, then rewrites them to stay inside the real limits. Use when shipping or editing public docs, READMEs, or rollout copy. Do not use for internal code comments, or for deciding actual legal fitness, which needs a qualified lawyer.
-
guillemroca Skill Security And HardeningUse when handling sensitive data, authentication, network communication, or before shipping to the Play Store. Three-tier framework (Always Do, Ask First, Never Do) with Android-specific security patterns.
-
guillemroca Skill Code Review And QualityUse when reviewing Android code (own or others'). Five-axis review framework: Correctness, Readability, Architecture, Security, Performance. Categorized findings with Kotlin/Compose-specific checks.
-
horizonbrute Skill MonitorStart or explain the Horizon AIOS filesystem integrity monitor — watches the AIOS system directories for create/modify/delete/move events and appends them as JSON lines to the audit log. Use when the user types /monitor, asks to "start the monitor", "watch the AIOS for changes", "enable filesystem audit logging", or check what the monitor watches.
-
nick2bad4u Bundle Snyk ManagementInspect and manage Snyk organizations, groups, projects, targets, issues, policies, ignores, tests, monitored snapshots, SBOMs, audit logs, settings, and safe REST API operations. Use whenever the user mentions Snyk posture, findings, scans, projects, imports, configuration, or remediation.
Audited -
nick2bad4u Bundle NPM 12 MigrationMigrates npm-managed repositories from npm 11 or older to npm 12 with lifecycle-script allowlisting, Node and CI alignment, config and lockfile review, breaking-output fixes, and full validation. Use when explicitly invoked for an npm 12 upgrade, migration audit, or allowScripts rollout.
-
nick2bad4u Bundle Code Review MaintenanceMaintains code-review quality across repos, files, configs, and low-confidence claims. Use when reviewing codebases/files, brittle implementations, consistency drift, comment triage, correctness, maintainability, security, release, or test risks.
-
barcelosvinicius Skill Proc AdrUse when making any significant technical decision that affects structure, security, performance, or is difficult to reverse. Process for recording Architectural Decision Records (ADRs) — when to create them, the mandatory format, naming, and status lifecycle.
-
barcelosvinicius Bundle Be JWT Auth PatternsUse when implementing token-based authentication (JWT), deciding how to revoke tokens on logout, or choosing where to store tokens on the client. Stack-agnostic flow, secret handling, blocklist revocation, and client storage rules, with Java/Spring examples as a resource.
-
barcelosvinicius Skill QA Verification LoopUse when finishing a change, before declaring work "done", or before opening a PR — a stack-agnostic verification loop (build, type-check, lint, tests, security scan, diff review) that produces a READY / NOT READY verdict so quality is checked in the generation loop, not just in CI.
Audited -
barcelosvinicius Skill Engineering PrinciplesUse when making a design decision and needing the project-independent ground rules — UX, security, coupling, testing, observability, resilience, and the AI-assisted documentation protocol. One-page digest with pointers into the full engineering-principles.md document.
Audited -
kangwang42 Bundle Epi Project Audit六层审查流行病学与生物统计项目的数据链、代码、结果、表图、正文和交付一致性,并以证据判定是否可正式交付。用于项目质控、结果复核、审稿前自查或全面一致性检查;只审查时不修改文件。开工先遵循 biostat-principles,含咨询包时同时核对 consulting-delivery。单个 Word、表格、图片、PDF 或一段文字的局部修改与文件检查使用对应内容和文件操作 skill,不触发本技能。
Audited -
kangwang42 Bundle Consulting Delivery把已完成并验证的 R 或 Python 分析打包为客户可独立复现、可直接阅读且保留真实溯源的咨询交付物。用于“给客户交付”“打包结果”或在 05_reports/ 建正式结果包;不用于未完成分析或内部探索。开工先遵循 biostat-principles,文本终审配合 academic-humanizer,最终检查配合 epi-project-audit。
-
kimtth Bundle Databricks MigrationPort Databricks notebooks and jobs to Microsoft Fabric. Provides an exhaustive dbutils to notebookutils substitution table: fs operations (mount removal via OneLake Shortcuts), secret scope to Key Vault URL conversion, notebook run and exit, widget replacement with parameter-tagged cells, and library install replacement with Fabric Environments. Covers Unity Catalog three-level namespace reduction to Lakehouse two-level schemas, DBFS path conversion to OneLake, Databricks Jobs to Spark Job Definitions, MLflow tracking URI removal, and Photon to Native Execution Engine substitution. Use when the user wants to: (1) replace dbutils with notebookutils, (2) collapse Unity Catalog namespaces to Lakehouse schemas, (3) convert Databricks Jobs or Delta Live Tables. Triggers: "migrate from databricks", "databricks to fabric", "dbutils to notebookutils", "dbutils fabric", "unity catalog migration", "dbfs to onelake", "databricks notebook migration", "delta live tables fabric", "photon native execution".
-
libreyolo Skill Libreyolo License AuditAudit and maintain LibreYOLO's licensing and provenance surfaces, and handle contamination correctly. Use when adding ported code or weights (which notice files must change), when reviewing a PR for license risk, when someone asks "can we use/host/ship X?", when a family's provenance is questioned, or when GPL/AGPL/NC-licensed material may have touched the work. Covers the four notice surfaces and when each changes, the code-vs-weights license distinction, the decision table for common licenses, the contamination protocol, and the hard rules: no clean-room laundering, surface decisions to the maintainer instead of quietly "fixing" them.
-
mattmireles Skill AuditTriggered when the user’s message includes the word **audit** (primary routing hook). Findings-first review of the kokoro-coreml repo or a scoped slice (paths, diff, commits)—runs pytest (and optional lint when configured) as mechanical signals, optionally delegates readonly subagents by charter when scope or risk warrants it (**when in doubt, parallelize**), merges and dedupes findings, and assigns A–F grades for architecture, correctness risk, and complexity debt. Do not use when the user wants implementation fixes unless they explicitly ask to fix issues after the audit—for plan-phase checklists against an active plan, prefer phase-audit.
-
mattmireles Bundle Phase AuditAudit a completed plan phase in this repo. Use when a phase has just been implemented and needs a findings-first review against the active plan, changed files, linked guides, and the canonical audit rubric before commit or before moving to the next phase. Do not use for implementing fixes, broad product critique, or replacing tests and CI execution.
-
mattmireles Bundle Write NotesWrite or update repo notes under README/Notes. Use when the user wants debugging notes, investigation notes, audit notes, or institutional memory captured in the repo. Prefer updating the right high-level notes document over creating a fresh file for every session. Do not use for plans, README guides, or inline code comments.
-
mattmireles Bundle Ilya SutskeverAdopts the Ilya Sutskever persona and judgment for on-device ML work in kokoro-coreml: PyTorch tracing, Core ML conversion, MIL/op compatibility, ANE/GPU/CPU scheduling, precision and parity validation, and bakeoffs vs reference PyTorch. Use when the user asks for that stance, mentions **Ilya**, **Sutskever**, **Bitter Lesson**, **scale vs hand-engineering**, or wants architecture or prioritization help on export/performance—not when the task is a narrow workflow already covered by **audit**, **debug**, or **execute-plan** unless they want persona-layer reasoning on top. Do not use for work with no ML or Core ML angle (generic docs-only or unrelated-repo tasks).
-
mattmireles Skill Execute Plan HardcoreExecute a checked-in implementation plan like execute-plan (phase-by-phase, commits, push, CI), then run the full audit skill on the execution scope and require Architecture, Correctness risk, and Complexity debt grades all A—fix findings and repeat until all three are A. Use when the user explicitly invokes this skill or wants the hardcore post-audit gate after plan execution. Do not use for planning-only, read-only review, or when the user wants standard execute-plan without the audit-to-A loop.
-
cuga-project Skill Code ReviewerReview a code snippet (or whole file) and return structured, actionable feedback covering bugs, security flaws, performance, style, and architectural insights. Use when the user pastes code and asks for a review, audit, critique, or "look this over".
Audited -
dafang Bundle Cs Audit系统审计。触发:审查系统、扫描 bug/安全/性能/架构债,产出发现清单。
-
prof-ramos Bundle Ethical RedteamConducts authorized ethical security tests (Red Team / Bug Bounty) covering OSINT reconnaissance, subdomain enumeration, social media username investigation (Sherlock, Blackbird), port/service scanning, vulnerability analysis, and professional OWASP/NIST report generation. Use when the user asks for "penetration testing", "pentest", "vulnerability scan", "OSINT", "bug bounty", "security report", "port scan", "network analysis", "red team", "recon on target", "subdomain enumeration", "username search", or "social media OSINT". Requires written authorization before any active test. Outputs executive and technical reports in Markdown and PDF.
Audited -
prof-ramos Bundle Lgpd ChecklistCreate LGPD-ready operational checklists, audit checklists, release reviews, privacy-by-design reviews, or third-party evidence requests with explicit legal basis. Use when the user asks for LGPD compliance, privacy checklist, ROPA/inventory, cookies/consent, data minimization, data subject rights, retention, security, incident response, vendors, international transfers, or wants columns such as Item, Evidence, Legal basis, Status, and Risk.
-
prof-ramos Bundle Temp Mail PentestCreates and manages temporary email addresses via the Guerrilla Mail API for pentesting and bugbounty workflows. Use when you need to register on a site requiring email confirmation, receive password reset links, test for data leakage in outgoing emails, validate that an email-sending endpoint actually triggers, or test rate limits/spam handling by receiving multiple emails. Saves inbox state to a per-target JSON file for evidence and session reuse. Supports uv runtime.
Audited -
rynhardt-potgieter Skill Security ComplianceSecurity and compliance standards — Auth0 JWT integration, OWASP Top 10 mitigations, PCI DSS 4.0, PII/POPIA data protection, encryption at rest and in transit, secrets management, and audit trails. Use this skill when implementing authentication, handling sensitive data, storing PII, processing payments, reviewing security posture, or ensuring regulatory compliance. MUST use for any code touching user data, financial data, or authentication flows.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include midnight-security, paper-formal-writer, graph-design. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.