Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
onekeyhq Bundle 1k Bundle ReleaseBundle release workflow — checkout, prepare, pr, diff-check, audit, publish, sync.
-
onekeyhq Bundle 1k Worktree CleanUse when the user wants to audit local git worktrees against origin/x, choose by number or A, and decide whether stale worktree directories, already-merged worktrees, or no-delta worktrees can be cleaned up. Triggers on "worktree clean", "worktree 合并到 x", "检测哪些 worktree 已进 x".
Audited -
cmdecker95 Skill Review SecurityReview code changes with Security Review subagent.
Audited -
cloudchef Bundle ResourceSmartCMP resource browsing, detail inspection, recycle-bin management, resource-first Security posture and violation analysis, comprehensive single-resource analysis coordination, and user-scoped operations. Use when the user asks whether a named or selected resource is secure or has Security violations, wants an overall resource review across alerts, health, Security, and cost, or wants to browse, inspect, operate, or permanently remove a recycled resource. CMP-wide policy posture and violation-object workflows belong to security-compliance.
Audited -
cristhianzl Bundle Developing FeaturesWrite production code with security-first thinking, SOLID design, pragmatic principles, observability, and strict file-structure limits. Use when implementing a new feature, designing a system, refactoring code, or whenever the task is "build production code" rather than fix a bug or write tests. This is the default for feature and production-code work — use it unless the user explicitly asks for TDD (tests-first / red-green-refactor), which is developing-features-tdd. Pairs with ensuring-cross-platform for portability and writing-tests for coverage.
-
rahmanef63 Bundle Sc DokployDokploy CRUD, audit, and debug. List/create/update/delete projects, applications, compose services, and domains via REST API. Find stale domains, duplicate hosts, and *.traefik.me leftovers. Inspect status and recent deployments.
Audited -
rahmanef63 Skill Sc ProviderSI-Coder provider + connection control plane for humans and agents. Manage user-scoped labeled provider connections, auth methods/scopes, custom provider metadata, secret-safe credential status/handoffs, injected execution, audits, and safe updates without putting provider secrets in chat/tool JSON.
-
wisdom-in-a-nutshell Bundle Fli ReviewIndependent reviewer for the frontier-lab-intelligence repo. Use when Adi asks to "get context and critique", review project state, audit progress against the submission endpoint, find blind spots, sanity-check a plan or architecture decision, or recommend what to do next. The role is critic and auditor, not implementer — load full project context cold, verify claims against live data, and judge everything by whether it pushes the case study toward earning the next interview by the deadline.
-
wisdom-in-a-nutshell Bundle Secret ManagementManage secrets correctly in this environment: use the machine-local canonical secret store, generate repo-local `.env`, machine-local `~/.secrets`, and native credential files, handle provider runtime delivery and GitHub Actions deliberately, choose naming, and validate materialization without exposing values.
-
jurislm Skill Spectra AuditAudit changed code for security sharp edges — dangerous defaults, type confusion, and silent failures
Audited -
jurislm Bundle Codebase SyncThis skill should be used when the user says "更新 README", "更新 CLAUDE.md", "同步文件", "移除過時內容", "codebase 文件已過時", "文件跟不上代碼", "CLAUDE.md 要更新", "重構完需要更新文件", "update README", "sync documentation", "docs are outdated", "documentation is stale", "docs don't match the code", "update my docs after refactor", or wants to audit and refresh README.md and CLAUDE.md to match the current codebase state.
Audited -
zhnnky329 Skill Completeness AuditorAudit whether the semantic evidence required by the active lean or submission profile exists and is current, without requiring one verbose artifact per skill or an arbitrary number of pass bullets.
-
zhnnky329 Skill Data Auditor CleanerMap contest attachments to subquestions, audit and clean raw data, and emit one reusable data profile with quality, coverage, imbalance, concentration, and method-readiness evidence for downstream risk screening.
-
zhnnky329 Skill Quality Assurance AuditorPerform the final submission-level audit of mathematical-modeling workflow integrity, evidence quality, anti-fabrication, paper coherence, figures, references, and contest readiness after consistency and completeness audits pass.
-
firstsun-dev Skill Permission CleanupAudit and clean up Claude Code permission rules (permissions.allow/deny in ~/.claude/settings.json, project .claude/settings.json, and .claude/settings.local.json). Finds leaked credentials embedded in rule strings, dead one-off rules tied to expired job IDs/PIDs/dates, and rules already made redundant by a broader wildcard. Use when asked to 'organize permissions', '清理權限', 'clean up settings.json', or when a permissions file looks cluttered after many sessions.
-
alsk1992 Bundle HardenVPS security auditing and hardening
Audited -
alsk1992 Bundle Token SecurityToken security audit via GoPlus API
Audited -
sarmkadan Skill Serialization ReviewReview .NET serialization - System.Text.Json configuration, contract evolution, polymorphism, streaming large payloads, and deserialization security. Use when reviewing JSON handling, serializer options, or API/message contracts.
-
sarmkadan Skill Configuration And SecretsReview .NET configuration handling - IOptions<T> vs raw IConfiguration access, secret material never in appsettings committed to git, user-secrets/env/KeyVault ordering, and redaction in logging.
-
sarmkadan Skill Nullable Reference DisciplineEnforce nullable reference type discipline in C# - annotation honesty, null-forgiveness audit, boundary validation, and EF Core interaction. Use when writing or reviewing C# code in nullable-enabled projects or migrating projects to nullable.
-
b4r7x Bundle Nuke DepsUse when dependencies need a planned audit or upgrade — "nuke deps", "update dependencies", "are our deps safe/outdated", "upgrade to v5" — vulnerable, outdated, unused, or duplicated packages, upgraded in gated waves with majors isolated one at a time, never a blind bulk bump.
-
b4r7x Bundle Nuke ExecUse when work should be executed by delegated subagents — a spec produced by nuke-audit, nuke-review, nuke-spec, or nuke-verify ("nuke exec", "execute the fix spec", "nuke fix" — its former name), or a clear task stated inline without a spec ("implement this with agents", "build this cheaply" — formerly nuke-implement). Spec in → phased execution; task in → contract first, then a single-phase execution. For the session's own hands, nuke-code applies; for judging finished work, nuke-verify.
-
frostney Bundle Code ReviewReviews a pull request, branch, or worktree against its claim, repository standards, reproducible behavior, and churn-backed architectural risks. It can delegate evidence gathering by review axis, limit findings to exact files, revalidate prior review or audit JSON, and optionally fix selected findings or all in-scope findings. Use when the user runs /code-review or asks for an evidence-backed review of a bounded change.
-
frostney Bundle Codebase AuditAudits the current repository for systemic correctness, architecture, churn, simplification, clarity, test value, and operational risks using current source and reproducible probes. It can delegate evidence gathering across bounded capability and perspective lanes. Use when the user runs /codebase-audit or asks for an evidence-backed repository or subsystem audit.
-
galleonlabs Bundle Galleon Defi SecurityReview DeFi transactions, typed signatures, token allowances and smart-account policies using official decoding, simulation and risk tools. Use when reviewing consequential wallet actions or inspecting a suspicious approval; distinguish verified effects, unresolved behavior and actual authorization.
-
galleonlabs Bundle Galleon Defi Security Token DiligenceInvestigate an exact EVM token's controls, launch allocations, liquidity custody, sellability and treasury flows, or compare it with a prior review. Use when assessing token risks or reviewing earlier diligence; transaction-payload review remains a separate workflow.
Audited -
gitkraken Skill ReviewCode review against GitLens standards with optional impact completeness audit
-
gitkraken Skill Live PairUse when you want to iterate on a feature interactively with the user watching a running instance — pair-programming rhythm for UI-heavy work, redesigns, copy tightening, layout exploration, or any "let me just show you what I want" session. Not for systematic audit (/live-exercise) or perf-tuning (/live-perf).
-
gitkraken Skill Audit CommitsAudit commits for issues and CHANGELOG entries
-
gitkraken Skill Live ExerciseUse whenever any UI-bearing work touches a running instance — building or fixing a feature, ship-gating, auditing, OR debugging visible bugs (flaky behavior, intermittent rendering, "sometimes does X" reports, hover/focus/animation glitches, layout overflow). Adaptive depth from tactical fix-loop to ship-gate audit. Not for pure-logic diff review.
-
gitkraken Skill Changelog StoryReorganize the CHANGELOG's [Unreleased] section into a release "story" — pillar features become umbrella entries with sub-bullets, wording gets tightened to expert release-notes quality, and intra-release-only fixes get pruned by verifying against the last stable tag. Use whenever the user asks to make the changelog tell a story, reorganize/consolidate/group the unreleased section, prep the CHANGELOG for a release, or complains the unreleased section is too long, too detailed, or disorganized — even if they just say "clean up the changelog". Not for adding individual entries (that's /audit-commits or /commit).
-
gnekt Skill DefragWeekly vault defragmentation. Runs a 5-phase structural audit: inbox hygiene, area completeness, project archival, MOC refresh, tag consistency, structure evolution, and generates a report. Triggers: EN: "defragment the vault", "reorganize the vault", "structural maintenance", "vault defrag", "weekly defrag". IT: "deframmenta il vault", "riorganizza il vault", "manutenzione strutturale", "defrag settimanale". FR: "defragmenter le vault", "reorganiser le vault". ES: "desfragmentar el vault", "reorganizar el vault". DE: "Vault defragmentieren", "Vault reorganisieren". PT: "desfragmentar o vault", "reorganizar o vault".
-
gnekt Skill Deep CleanExtended vault cleanup: full audit PLUS stale content scan, outdated references, content quality review, redundant tags, broken external links, and template compliance. Triggers: EN: "deep clean", "deep cleanup", "thorough cleanup", "the vault is a mess". IT: "pulizia profonda", "pulizia completa", "il vault è un disastro". FR: "nettoyage en profondeur", "le vault est un désordre". ES: "limpieza profunda", "el vault es un desastre". DE: "Tiefenreinigung", "das Vault ist ein Chaos". PT: "limpeza profunda", "o vault está uma bagunça".
-
gnekt Skill Tag GardenAnalyze all vault tags: find unused, orphan, near-duplicate, over-used, and under-used tags. Suggest merges and cleanup actions. Triggers: EN: "tag garden", "clean up tags", "tag cleanup", "tag audit". IT: "tag garden", "pulizia tag", "revisione tag". FR: "jardinage des tags", "nettoyer les tags". ES: "jardín de tags", "limpiar tags". DE: "Tag-Garten", "Tags aufräumen". PT: "jardim de tags", "limpar tags".
-
hani-q Bundle Qstack LiberoCatch the code that got built because it seemed useful rather than because the goal required it. Restate the goal, test each assumption against evidence, then remove, simplify, optimize, or automate in that order and never further than the goal needs. Does not cut validation, error handling that prevents data loss, security, or a repository invariant. Use as /qstack-libero after a task or feature is built, or when asked what can be deleted or simplified.
-
fanlw0816 Skill Code ReviewArchitecture and quality code review for specified files or directories. Checks standards, patterns, security, and maintainability.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include resource, spectra-audit, codebase-sync. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.