Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
jfrog Bundle Jfrog Security XrayUse when working with JFrog Security/Xray -- scanning for vulnerabilities, managing policies/watches/violations, generating SBOMs, configuring advanced security (SAST, secrets detection, contextual analysis), or monitoring runtime. Triggers on mentions of xray, vulnerability, CVE, scan, policy, watch, violation, SBOM, SAST, secrets detection, contextual analysis, IaC scanning, or runtime security.
Audited -
jfrog Skill Jfrog Curation OnboardingSet up JFrog Curation with protection policies on an existing JFrog Platform instance. Checks if Curation is enabled, collects a notification email, then creates security, license, and operational risk policies on remote repositories. The "Block Malicious" policy blocks downloads; all others run in dry-run (audit) mode. Use when the user wants to set up curation, onboard curation, enable curation protection, or block malicious packages.
-
jmylchreest Skill ReviewCode review and security audit, including conformance against recorded decisions
-
rejot-dev Skill Slack SetupSet up or verify Slack in Backoffice for bot-token API calls, sending messages, Events API webhooks, app mentions, URL verification, signing-secret validation, or checking whether a Slack event arrived.
-
sipyourdrink-ltd Bundle SecuritySecurity review - OWASP, auth, secrets, input validation.
-
spree Skill Spree API V3Use when the user is integrating with Spree's v3 REST API — making requests as a customer, building an admin app, writing webhook consumers, debugging auth errors, parsing API responses. Distinguishes the Store API (customer-facing) from the Admin API (back-office). Common phrasings include "Spree API", "Store API", "Admin API", "publishable key", "secret key", "X-Spree-Api-Key", "API scopes", "prefixed IDs in API", "expand", "API pagination", "Spree 401", "Spree 403", "{data, meta} envelope", "v3 endpoint". For ADDING a new resource to the API, use the spree-resource skill instead.
-
oxsecurity Skill Review DescriptorAudit a linter descriptor YAML for completeness, correctness, and best practices. Checks all properties against the full schema.
-
oxsecurity Skill Fix Security IssueHandle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.). Tries to upgrade first; ignores only when safe and justified; disables an unmaintained linter (with user confirmation) when a dangerous CVE has no fix.
-
pfangueiro Skill Code Review ChecklistA ten-category human code-review rubric — correctness, design, readability, testing, security, performance, documentation, dependencies, error handling, and style — plus process guidance on feedback tone, review size, and a pre-submit self-review pass. Use when a review verdict is actually being produced on a concrete change, such as reviewing a pull request or diff, self-reviewing before opening one, or defining a team's code review standards. Triggers include code review, review this PR, pull request review, review checklist, review standards. It is a rubric rather than an analyzer, so it does not apply to merely reading or explaining code, answering how something works, debugging, refactoring, or running linters, formatters, and type checkers.
-
s-hiraoku Skill Security ReviewRun a multi-pass security review over the current diff using parallel specialist subagents focused on injection, authn/authz, secrets, supply-chain, and infrastructure-as-code risks.
-
thatjuan Bundle CommitpushSafe commit-and-push workflow with secrets detection, sensitive file screening, and submodule-aware prompting. Use when committing and pushing changes to git, especially in repos with submodules or when security-conscious commits are needed.
-
8ddiehu0314 Skill MaliciousA test fixture that intentionally triggers all security checks in skill-lab
-
8ddiehu0314 Skill Security WarnUse when you need to test a skill that produces a security warning (not block).
Audited -
8ddiehu0314 Skill Token BombUse when you need to lint and format source code.
Audited -
8ddiehu0314 Skill YAML SmugglingUse when you need to scaffold a new project from a template.
-
8ddiehu0314 Skill Homoglyph AttackUse when you need to search and replace text across files.
-
8ddiehu0314 Skill Jailbreak SoftcodedUse when you need to draft creative writing or stories.
-
8ddiehu0314 Skill Unicode ObfuscationUse when you need to rename files in a directory.
-
8ddiehu0314 Skill Evaluator ManipulationUse when you need to help format and clean up data files.
Audited -
djalmajr Skill Agile RefinementValidates planning artifacts and reviews code for quality, consistency, and completeness. Use to lint planning documents (cross-references, dependencies, format) or to review changed code (security, coherence, scope, quality).
-
grimaldost Skill Corpus ReviewAudit a large file corpus — dozens to hundreds of docs, configs, or mixed code-plus-docs-plus-tests — by fanning out blind reviewers over partitions, adversarially verifying every high-severity finding before acting on it, fixing in disjoint file partitions, and re-auditing with fresh eyes until the findings converge. Use when reviewing or auditing a whole repo's documentation, a release's doc set, an entire plugin or package, or any file set too large for one reader to hold at once; on asks like "review all the docs before we push", "audit the whole repo for X", "blind review across these N files", "do a pre-push review of everything", or "check the docs still match the code across the project". It orchestrates the audit on the harness's parallel subagent and workflow primitives and ships no engine of its own. Not for a fresh-eyes panel on a single design, spec, or artifact (that is review-panel), not for reviewing one change's diff for bugs and regressions (that is a diff review / code-review), and not for
-
tencentblueking Bundle Bk Security Redlines<!-- BKUI-KNOWLEDGE-MANAGED:2e279de905d0 -->
-
drmoisan Skill Commit Message ConventionsGenerate a single high-signal conventional commit message from staged Git changes or an explicit commit-context artifact. Use when Codex or a subagent must classify dominant change intent, choose a precise commit type and optional scope, and emit an audit-quality message that is immediately usable with `git commit`.
-
fanthus Bundle Openclaw SecurityPerform a thorough security audit before installing any skill, script, plugin, or code from an external source — including GitHub repositories, URLs, .skill files, shell scripts, npm packages, pip packages, and zip archives. Trigger this skill whenever the user mentions: installing a skill from outside, downloading scripts, "install from GitHub", "run this script", importing an external plugin, or any time untrusted code is about to be executed or installed. ALWAYS use this skill proactively — security checks should happen before installation, not after. Even if the user just pastes a URL or file and says "install this", run the security check first. This is the openclaw external source security verification skill.
-
fanthus Bundle Architecture ReviewCritically evaluate whether a code project's architecture is sound — module decomposition/cohesion, module and class responsibility clarity (SRP), whether business logic sits in the right modules, dependency direction and Dependency Inversion Principle (DIP) adherence, and whether the public API is intuitive and hard to misuse for its consumers (crucial for SDKs/libraries). Produces a structured Markdown report with severity-ranked findings and concrete refactoring suggestions (example code / interface redesigns). Use whenever the user asks to review, audit, or critique architecture, or asks things like "架构是否合理", "模块划分是否合理", "职责是否清晰", "是否符合依赖倒置/SOLID", "这样设计好不好", "这个类是不是太重了", "SDK 好不好用" / API 设计是否合理, or wants a second opinion on a design/refactor decision. This is a critique/audit skill (finds problems, proposes fixes), unlike a plain codebase-overview skill. For iOS/macOS (Swift/OC) projects, also read references/ios-specific-checks.md.
-
drugclaw Skill Medical Qms ToolsMedical quality-system and documentation workflow guide for ISO 13485, FDA QMSR, design controls, risk management, CAPA, document control, supplier qualification, complaint handling, and audit preparation. Use when the user asks to plan, review, or gap-assess medical-device or diagnostic quality documentation without asking for legal determinations or regulatory guarantees.
-
jd-opensource Bundle Pentest API DeepDeep OWASP API Security Top 10 testing for REST, GraphQL, gRPC, and WebSocket APIs — BFLA, mass assignment, rate limiting, and unsafe consumption.
-
jd-opensource Bundle Pentest Mobile AppOWASP Mobile Top 10 security testing for Android and iOS — local storage, certificate pinning bypass, IPC abuse, and binary protections.
-
jd-opensource Bundle Pentest Vuln Verify Test通过原始 HTTP 请求操作和严格验证自动验证 Web 漏洞(开放重定向、XSS)。
Audited -
jd-opensource Bundle Seclens Enterprise WebProfessional web application and API security testing workflows using OWASP Top 10 methodologies.
Audited -
jd-opensource Bundle Pentest Config HardeningSecurity header auditing, TLS configuration testing, HTTP method analysis, CSP bypass assessment, and deployment hardening verification.
-
jd-opensource Bundle Openclaw Security CheckerOpenClaw 安全检测工具,基于安全实践指南验证配置安全、权限隔离、网络策略、日志审计和运行时完整性
-
jd-opensource Bundle Pentest Exploit ValidationProof-driven exploitation with 4-level evidence system, bypass exhaustion protocol, mandatory evidence checklists, and strict EXPLOITED/POTENTIAL/FALSE_POSITIVE classification.
-
jd-opensource Bundle Pentest Whitebox Code ReviewSource code security audit using backward taint analysis, slot type classification, render context verification, and 3-phase parallel review producing an exploitation queue.
-
materialofair Bundle Merge ReviewMANUAL ONLY. Run a structured pre-MR review when the user explicitly requests merge-review via /merge-review, $merge-review, merge-review, or natural language such as 执行 merge-review. Produces impact analysis report, merge readiness checklist, regression self-check, code quality audit, and changelog for the current branch against origin/main.
Audited -
jiyangnan Bundle Skill VetterSecurity-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-review, JFrog Security (Xray), jfrog-curation-onboarding. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.