Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
getlost01 Skill Thesis AuditRe-test every position thesis in PORTFOLIO-PLAN.md against current data — is the stated reason for owning it still true, and has any invalidator tripped. Use when the user asks why they own something, whether a thesis still holds, or wants a conviction/thesis check across holdings. Read-only.
-
getpipher Skill Quality RoastBrutal pre-production code audit that roasts lazy shortcuts, security red flags, scalability issues, and "fix it later" implementations
-
getpipher Skill Git Tools Pr AuditPR auditor — reviews open PRs, merges sequentially with rebase, handles conflicts (auto org-aware)
-
getpipher Skill Quality Production ChecklistAnalyze any codebase for production readiness with comprehensive security, performance, and deployment checklist
-
heyramzi Bundle Clickup Data ManagerManages ClickUp data programmatically: stale task and view cleanup, demo workspace enrichment, bulk task creation and updates, and doc page name standardisation to 'Company - Type - Date'. Use when running bulk updates, deleting views, or when doc pages have messy names. For interactive CLI work see clickup-cli, for a read-only audit clickup-audit.
-
innei Bundle Codebase Value AuditUse when asked whether a codebase's size is justified — "is 800k lines reasonable?", "audit our LOC", "are we bloated?", "值不值" — or when a LOC number is being used in an argument and nobody agrees what it measures. Produces a defensible per-sub-product accounting: strict line counts, a product-surface inventory, every line attributed to exactly one sub-product, and a worth verdict per block.
Audited -
jdinkla Skill Story QAIdentify comprehensive test coverage for a user story — 8–15 test cases across unit/integration/E2E levels and happy/edge/error/security/performance types. Use when the user asks for a QA plan, test coverage analysis, "what should we test?", or wants a test-pyramid-balanced list of test cases.
-
datus-ai Skill Memory OrganizationAudit and reorganize every persistent store — semantic_models, metrics, reference_sql, knowledge, memory, AGENTS.md, skills — verifying each item sits in the correct store per storage-classify, and surfacing duplicates, misclassifications, conflicts, and stale/erroneous entries. Produce a Remediation Plan, STOP for confirmation, then execute. Use ask_user only for genuine decisions during analysis. If nothing needs fixing, report it and stop.
-
dvasyliev Skill Code Review ChecklistComprehensive checklist for conducting thorough code reviews covering functionality, security, performance, and maintainability
-
federicoimparatta Bundle Data ReconciliationUse this skill when the user asks to reconcile two or more sources that report different numbers for what should be the same metric, resolve a disagreement between a dashboard and a database query, or debug why two reports do not tie. Trigger phrases include "why do these numbers disagree", "reconcile these reports", "the dashboard does not match the database", "tie out these totals", "reconciliar los números", "por qué no coinciden", "audit these metrics". Produces a reconciliation report that names the root cause and the fix, not just the variance.
-
scaleto Skill Comunicador SeguridadEnlace A2A del Grupo Seguridad.
-
scaleto Skill Orquestador SeguridadLíder del Grupo Seguridad. Planifica y delega tareas de ciberseguridad, auditorías, compliance y pentesting a los especialistas del grupo.
-
blueprintos Skill QA AuditQA 审计 — 跑全量文档质量检查,按 P0/P1/P2 严重度分级输出审计报告。设计完成、代码交接前调用本 skill,作为进入实施的最后一道硬门控,确保 P0=0 才放行。
-
dyai2025 Skill Defense In DepthUse when designing verification strategy so independent gates cover requirements, implementation, security, validation, and judgment without claiming perfect certainty.
-
gustavogutierrez Skill ReviewerRigorous technical and quality reviewer that audits artifacts (PRDs, specs, architectures, user stories, APIs) for consistency, completeness, clarity, gaps, and standards compliance. Trigger: when the user asks for a review, quality audit, QA gate, technical validation, or to check an artifact before implementation.
Audited -
gustavogutierrez Skill Risk AssessorAssess technical, operational, scalability, security, delivery, and AI/spec ambiguity risks across specs, architectures, workflows, and initiatives. Use when asking to review risk, identify blockers, assess feasibility, audit technical decisions, or evaluate initiative health.
Audited -
gustavogutierrez Bundle API Spec WriterDesign complete API contracts in OpenAPI 3.0/3.1 YAML with endpoints, schemas, security, pagination, error handling, and RFC 7807 problem details. Use when asking to design an API, create an OpenAPI spec, define API endpoints, write API contracts, or generate a Swagger specification.
-
impertio-studio Bundle Tauri Core ConfigUse when editing tauri.conf.json, configuring build options, or setting up platform-specific bundle configuration. Prevents invalid configuration keys and v1 config patterns that silently fail in Tauri 2. Covers build settings, app settings, window configuration, bundle options, plugin configuration, and security settings. Keywords: tauri.conf.json, configuration, build settings, bundle options, window config, security settings, tauri.conf.json, change settings, window size, app title, bundle config, icon..
-
impertio-studio Bundle Tauri Impl SecurityUse when hardening Tauri 2 app security, configuring CSP, reviewing permissions, or implementing isolation patterns. Prevents overly permissive CSP, disabled prototype freeze, and unscoped file/shell/http permissions in production. Covers CSP configuration, Tauri protocols, freezePrototype, isolation pattern, scope-based access control, and dangerous permissions. Keywords: tauri security, CSP, Content Security Policy, freezePrototype, isolation pattern, scope, permissions audit, harden app, CSP policy, secure permissions, production security, lock down access..
-
impertio-studio Bundle Tauri Agents ReviewUse when reviewing Tauri 2 code, auditing permissions, or validating a Tauri project before deployment. Prevents shipping apps with missing permissions, unhandled IPC errors, insecure CSP, and unregistered commands. Covers command signature review, permission coverage, state management, error handling, security audit, and anti-pattern detection. Keywords: tauri code review, validation checklist, security audit, permissions audit, anti-pattern scan, deployment readiness, check my Tauri code, security review, permission audit, before release..
-
impertio-studio Bundle Tauri Syntax PermissionsUse when configuring permissions, creating capability files, setting up plugin access control, or debugging permission denied errors. Prevents using v1 allowlist patterns and overly permissive wildcard capabilities that compromise security. Covers capability file structure, permission definitions in TOML, scope configuration, plugin and custom command permissions. Keywords: tauri permissions, capabilities, allow, deny, scope, TOML, plugin permissions, access control, ACL, capability file, allow plugin, restrict access, permission TOML, scope config..
-
b4r7x Bundle Nuke ReviewUse when the user wants a thorough review of a diff, branch, PR, or staged changes — "nuke review", "review this branch/PR", "review my changes" — heavier than a glance, cheaper than a full audit.
-
bjesuiter Bundle Jb Dev EnvUse when setting up or reviewing a development environment, especially Varlock env schemas, gitignored env files, macOS Keychain/local secret storage, SOPS/age optional GitOps secrets, CI secret access, dotenv bootstrapping, or secure local dev onboarding.
-
bjesuiter Skill Jb Clawpatch ReviewUse when the user mentions Clawpatch/clawpatch.ai, semantic feature review, repo-wide AI audit, persistent findings, or clawpatch init/map/review/report/fix/revalidate.
-
decocms Bundle Incident ReportCreate incident reports and post-mortems for platform issues. Supports both internal technical reports and client-facing communications. Use when documenting outages, security vulnerabilities, data leaks, performance degradation, or any production incident.
-
decocms Skill Deco Apps Vtex ReviewAudit and fix the VTEX integration in @decocms/apps-start (TanStack Start). Covers cookie propagation (vtexFetchWithCookies, buildAuthCookieHeader), expectedOrderFormSections, salesChannel injection, HttpOnly cookie handling, Intelligent Search cookie generation, useCart/useUser/useWishlist hooks, and TypeScript validation. Use when reviewing vtex/ code quality, fixing authentication issues, debugging missing cart sections, or ensuring full parity with deco-cx/apps.
-
decocms Bundle Deco Performance AuditPerform a deep dive analysis of CDN metrics, cache performance, error rates, and traffic patterns for a Deco site. Use this skill to identify performance bottlenecks, optimize cache hit rates, and reduce error rates.
-
happier-dev Skill Verify ClaimsAudit a report, plan, or handoff by re-deriving every load-bearing claim from primary sources. Use before trusting subagent/lane reports, before building decisions on unverified claims, or when reviewing a conclusion written earlier (including your own). Distinct from running the app to verify behavior or reviewing a diff — this audits claims.
-
happier-dev Bundle Happier ReviewConduct evidence-backed Happier code, plan-completeness, session, worktree, feature, commit, branch, PR, codebase, and release-readiness reviews with affected-corridor analysis, high-confidence finding triage, meaningful parallel lanes, proportionate but comprehensive QA, optional root-cause fixes, and independent closeout. Use for deep review, audit, QA, pre-merge assessment, plan-vs-implementation verification, review-and-fix loops, or when asked to inspect all related code rather than only changed lines.
Audited -
happier-dev Bundle Happier CompatibilityAudit, design, implement, and verify Happier compatibility across UI, CLI, daemon, server, installers, and persisted state. Use when changes affect wire or semantic contracts, serialization, sessions/settings/queues, schemas or migrations, capability negotiation, mixed-version operation, upgrades, rollback, or the `remote-dev` predecessor frontier for `dev`.
-
huang-sir1 Bundle Radiology ResponseDraft, audit, and revise point-by-point reviewer response letters for Radiology (RSNA) and imaging-journal revisions. Use when the user has reviewer comments / a major or minor revision / 审稿意见 to answer for an imaging-AI/radiomics/radiogenomics manuscript. Assigns each comment a stable ID, classifies it, maps it to a concrete manuscript action, and ties every claimed change to a specific location — without fabricating experiments, analyses, citations, line numbers, or results. Bilingual-aware (中文作者备注 → English response + Chinese confirmation items).
-
huang-sir1 Bundle Radiology PrereviewRun a rigorous pre-submission mock peer review of an imaging-AI / radiomics / radiogenomics manuscript — simulate the methods, statistics, reporting-guideline, figure, citation/claim-verification, and data-sharing reviewer a top journal would assign, and surface the issues that cause desk-reject or major revision before submission. Use when the user wants a mock review, pre-submission audit, "投稿前预审/模拟审稿", "find the holes before a reviewer does", a two-pass abstract/figure/table claim audit, or a readiness check. Returns a reviewer-style report with Blocker / Major / Minor issues, each tied to the manuscript location and the reporting-guideline or methodological risk, plus an editor-style recommendation and a prioritised fix order. Never fabricates compliance or papers over a real weakness.
-
huang-sir1 Bundle Radiology Federated LearningUse when multiple imaging centers cannot pool raw data and need a federated-learning research design. Chooses horizontal, vertical, split, or personalized federation; plans aggregation, non-IID handling, site weighting, secure aggregation, differential privacy, threat modeling, governance, communication, reproducibility, fairness, calibration, and centralized/local/external baselines. Never presents federated learning alone as proof of privacy or external validity.
-
iflytek Bundle Time Blocking SchedulerDraft flexible daily or weekly schedules around a user's priorities, availability, energy patterns, and fixed commitments. Use for day planning, deadline reverse-planning, focus protection, or a time audit.
-
itsjavi Bundle App Security ReviewReview repositories, features, or diffs for exploitable application security weaknesses, including injection, authentication and authorization failures, exposed APIs, and broken trust boundaries. Applies to web applications, APIs, CLIs, workers, and libraries. Produce findings and remediation recommendations. Route content abuse and moderation concerns to trust-and-safety-review when available.
-
itsjavi Skill Trust And Safety ReviewReview product designs and implementation for abuse through user-generated content and interactions, including phishing, scams, harassment, spam, and moderation failures. Use for content safety, reporting, blocking, consent, and policy enforcement reviews. Produce findings and recommendations. Route technical vulnerabilities to app-security-review when available.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include incident-report, deco-apps-vtex-review, deco-performance-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.