Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
dills122 Bundle Repository Doc DriftAudit canonical repository documentation against current code, configuration, tests, generated contracts, and recent Git history, then make minimal evidence-backed corrections. Use after feature merges or releases, when plans and status may be stale, when README or architecture claims are questioned, or when multiple docs disagree about the current source of truth.
-
first-fluke Skill Symphony ConformanceAudits the current implementation for Symphony SPEC compliance and architecture rule adherence. Use when user asks to "check conformance", "audit symphony", or "verify spec compliance".
-
multiplex-ai Skill Wf Geo Client ServiceGEO agency client service workflow — manage the full client lifecycle from prospect intake through audit, reporting, proposal, and monthly tracking. Use when user says "GEO client workflow", "new GEO client", "GEO agency workflow", "client audit workflow", "GEO service delivery", "onboard a GEO client", or "monthly GEO reporting". Chains 10 GEO skills for agency service delivery.
-
0x-shashi Bundle SkillsRoot skill definition for the Web3 Audit Plugin providing AI-powered smart contract security auditing across EVM, Solana, Move, Cairo, CosmWasm, and TON platforms. Use as the top-level entry point for understanding plugin capabilities, supported chains, and skill routing.
-
0x-shashi Bundle ScoringQuantitative scoring framework for measuring audit quality with objective metrics to evaluate performance, track improvement over time, and identify areas needing attention. Use when benchmarking audit thoroughness, comparing engagement quality, or building quality gates into CI pipelines.
-
0x-shashi Bundle CommandsStructured command patterns for invoking audit capabilities through slash commands. Use when triggering /audit, /scan, /checklist, /report, /severity, /patterns, or other slash commands that map to underlying skills and load the correct context for each workflow.
-
0x-shashi Bundle SeverityData-driven severity classification for smart contract audit findings with statistical breakdowns and 30 representative examples per level from top audit firms. Use when assigning severity to findings, justifying classifications with historical data, or calibrating severity judgment against Code4rena, Sherlock, and Cyfrin benchmarks.
-
0x-shashi Skill Fix ReviewVerify that bug fixes correctly address reported vulnerabilities without introducing new issues. Use when reviewing protocol team fix submissions, during re-audit engagements, or in contest mitigation review phases on Sherlock and Code4rena.
-
0x-shashi Bundle MethodologyComprehensive audit methodology guides covering the full security auditor workflow -- from preparation and AI-assisted analysis through formal verification, economic modeling, report writing, and skill quality scoring. Use when learning audit workflows, selecting testing strategies, or authoring new skills with TDD methodology.
-
0x-shashi Bundle Aztec ScannerUse when the user wants to audit Aztec Network smart contracts written in Noir, scan for privacy-specific vulnerabilities including state leakage, note handling, or nullifier collisions, review private DeFi protocols for information disclosure, or analyze encrypted computation and zero-knowledge proof circuits.
-
0x-shashi Bundle Report WriterGenerate professional audit reports with structured findings, severity classifications, proof-of-concept code, and actionable recommendations. Use when writing individual findings, composing full audit reports, or formatting results for Code4rena, Sherlock, or client engagements.
-
0x-shashi Bundle Cosmos ScannerUse when the user wants to audit Cosmos SDK modules or CosmWasm smart contracts, scan IBC protocol interactions for relay, channel, or packet vulnerabilities, review Cosmos Go modules for state machine exploits, or analyze cross-chain message handling in the Cosmos ecosystem.
-
0x-shashi Bundle Solana ScannerUse when auditing Solana programs for security vulnerabilities, reviewing Anchor or Pinocchio/native Rust smart contracts, checking CPI safety, PDA validation, account ownership, signer verification, or Token-2022 security.
-
0x-shashi Bundle Cyfrin FindingsQuery the Cyfrin/Solodit findings database (50,530+ findings from 30+ audit firms) for vulnerability research, pattern extraction, and audit enhancement. Use when searching for historical findings by vulnerability type, protocol category, or severity, or when looking for similar bugs found in comparable protocols.
-
0x-shashi Bundle Static AnalysisIntegrate automated static analysis tools (Slither, Mythril, Aderyn, Semgrep) into the audit workflow to catch known vulnerability patterns before manual review. Use when starting an audit to establish a coverage baseline, or when configuring static analysis tooling for a project.
-
0x-shashi Bundle Solidity ScannerUse when the user wants to audit Solidity smart contracts for security vulnerabilities, scan EVM-compatible contracts for reentrancy, oracle manipulation, access-control, or flash-loan issues, review DeFi protocols on Ethereum, Arbitrum, Optimism, Base, Polygon, or BSC, or generate security audit reports for smart contract deployments.
-
0x-shashi Bundle Differential ReviewCompare two versions of a codebase to identify security implications of changes. Use when reviewing protocol upgrades, verifying bug fixes, auditing dependency updates, or when only a subset of code has changed since the last audit.
-
0x-shashi Bundle Skill ChainsOrdered sequences of individual audit skills to execute for different audit depth levels ensuring comprehensive, systematic coverage. Use when selecting between quick scan, standard audit, deep audit, or full engagement workflows to match coverage to time and scope constraints.
-
0x-shashi Bundle Attack ChainsDetect multi-step exploit sequences where individual steps may appear benign but combine into critical vulnerabilities. Use when analyzing protocols for flash-loan-to-governance chains, oracle manipulation sequences, or cross-contract re-entrancy paths inspired by real-world exploits like Ronin, Wormhole, and Beanstalk.
-
0x-shashi Bundle Audit Context BuildingSystematically build comprehensive understanding of a protocol before code-level analysis. Use when starting a new audit engagement, mapping trust boundaries and external dependencies, or when needing to identify all privileged roles and protocol invariants before manual review.
-
0x-shashi Bundle Context DetectionAutomatically identify the type of protocol being audited to load appropriate checklists, templates, and vulnerability patterns without manual configuration. Use when starting any new audit to classify the protocol (DeFi lending, AMM, bridge, governance, etc.) and surface the most relevant checks.
-
0x-shashi Bundle Protocol TemplatesStructured, protocol-type-specific audit templates enumerating the exact checks, invariants, and attack vectors relevant to each protocol category. Use when auditing AMM/DEX, lending, bridge, governance, or vault protocols to load targeted checklists based on context detection results.
-
10xequity Skill Security Static AnalysisDetect vulnerabilities before commit using CodeQL, Semgrep, and SARIF processing, backed by manual review of the changed surface. Use this skill before merging changes that touch authentication, authorization, user input, file handling, secrets, deserialization, subprocess execution, or dependencies.
-
elzawarudo Bundle Krt Docs ChroniclerMaintain durable project knowledge without creating documentation sprawl. Use when a user asks to update docs after a feature, incident, release, review, or architecture decision; reconcile stale README/runbook/ADR/changelog content; capture lessons learned; write lightweight ADRs; audit documentation drift; or decide where a new piece of project knowledge belongs. Runtime aliases may expose this as krt:docs-chronicler.
-
elzawarudo Bundle Krt Bicentennial WriterWriting and editing guidance for natural, specific, contextual prose that avoids generic patterns associated with AI-generated writing. Use when the user asks to draft, rewrite, humanize, naturalize, polish, localize, or audit text so it sounds less formulaic; when working on theses, academic articles, research documents, academic reasoning, critical argument, or AI-assisted authorship; or when they mention "sounds like AI," "AI detector," "humanize text," "natural writing," "human tone," "AI writing tells," "Bicentennial Writer," "suena a IA," "detector de IA," "humanizar texto," "redacción natural," or "tono humano," or want to avoid typical AI-writing patterns in Spanish or English. Runtime aliases may expose this as krt:bicentennial-writer.
-
elzawarudo Bundle Krt Cognitive Load CourtDiagnose avoidable cognitive workload in software task flows through six independent lenses covering memory, search, integration, decision, uncertainty, and recovery. Use when asked to audit cognitive load or mental effort, compare workflow variants, investigate an interface that feels mentally taxing, or verify that a redesign reduced workload. Do not use for broad product-polish audits or clinical cognitive assessment.
-
fastrevmd-lab Bundle Srx NatDesign, configure, audit, and troubleshoot Juniper SRX NAT. Use when handling source, destination, static, NAT64, DNS64, CGN, PBA, persistent or address-persistent NAT, hairpinning, proxy ARP, rule order, pool exhaustion, security nat configuration, show security nat output, sessions, or RT_NAT logs.
-
fastrevmd-lab Bundle Srx MnhaDesign, configure, audit, and troubleshoot Juniper SRX Multi-Node High Availability. Use when handling routed, default-gateway, or hybrid modes, chassis-cluster migration, SRGs, ICL or ICD, session sync, BGP or BFD failover, VIPs, IPsec, NAT, proxy ARP, routing instances, or DHCP. Use focused SRX skills for non-MNHA behavior.
-
fastrevmd-lab Bundle Srx AdvpnDesign, configure, audit, and troubleshoot Juniper SRX ADVPN spoke-to-spoke IPsec shortcuts. Use when handling suggester or partner roles, multipoint st0, OSPF p2mp, certificates, PKI, shortcut lifecycle, or “No public key found” IKE_AUTH failures. Use AutoVPN for hub backhaul and static IPsec for small fixed estates.
-
fastrevmd-lab Bundle Srx PolicyDesign, migrate, configure, audit, and troubleshoot Juniper SRX security policy on Junos 23.x+ non-Branch platforms. Use when handling global or zone policy, address and application objects, AppID, AppFW, NGWF, EWF, SecIntel, ATP, logging, rule order, hit counts, default deny, or cross-VLAN mDNS and SSDP boundaries.
-
fastrevmd-lab Bundle Srx Mpls In FlowDesign, configure, audit, and troubleshoot Juniper SRX MPLS L3VPN in flow mode. Use when handling Junos 24.2R1+ family mpls with inet or inet6 flow, secure PE or CPE, VRFs, LDP, MP-BGP, l3vpn vrf-group policy, VRF-to-zone mapping, VRF-aware NAT or AppID, PowerMode or RFP, MTU, labels, or policy matching.
-
fastrevmd-lab Bundle Parsing Srx ConfigsParse Juniper SRX and Junos display-set or hierarchical configurations into the shared firewall schema. Use when input contains set security, zones, policies, address-book, from-zone, to-zone, NAT rule-set, chassis cluster, logical-systems, or routing-instances, including audit, conversion, diff, summary, and explanation tasks.
-
fastrevmd-lab Bundle Srx Dynamic Ip FeedConfigure, audit, and troubleshoot Juniper SRX dynamic IP objects from HTTPS feeds. Use when handling feed archives, dynamic-address mapping, certificate validation, basic auth, mTLS, session scanning, routing-instance reachability, Recovery Mode after reboot, show security dynamic-address, ipfd logs, or feed and TLS failures. Use srx-policy for SecIntel feeds.
-
fastrevmd-lab Bundle Srx Ipsec Hub SpokeDesign, configure, audit, and troubleshoot Juniper SRX static route-based IPsec hub-and-spoke. Use when handling per-spoke IKE gateways, one st0 per spoke, static routes, anti-recursion, centralized source NAT, VPN-to-untrust policy, or hub hairpinning. Use AutoVPN for changing spokes and ADVPN for direct shortcuts.
-
fastrevmd-lab Bundle Parsing Palo ConfigsParse PAN-OS and Panorama XML or set-format exports into the shared firewall schema. Use when input contains vsys, device-group, security rulebase, address-group, application-default, security-profile-group, set deviceconfig, or XML entry/member elements, including audit, conversion, diff, summary, and explanation tasks.
-
fastrevmd-lab Bundle Hipaa Ngfw ComplianceMap firewall controls, evidence, and gaps to HIPAA Security Rule safeguards for ePHI. Use when assessing segmentation, access and audit controls, transmission security, risk management, BAA or vendor access, OCR evidence, 45 CFR 164.312, or “HIPPA.” Parse raw configs first.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include context-detection, srx-mnha, repository-doc-drift. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.