Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
managedcode Bundle Meziantou AnalyzerUse the open-source free `Meziantou.Analyzer` package for design, usage, security, performance, and style rules in .NET. Use when a repo wants broader analyzer coverage with a single NuGet package. USE FOR: the repo uses or wants Meziantou.Analyzer; the team wants one analyzer pack that covers design, usage, security, performance, and style. DO NOT USE FOR: repos that already enforce an overlapping analyzer baseline and do not want extra diagnostics; formatting-only work. INVOKES: inspect the repository context, edit targeted files, and run relevant build, test, lint, or validation commands when changes are made.
-
c0nant Bundle Review MrReview someone else's merge request for bugs, security, performance and design, check it against the task's acceptance criteria, and write a verdict plus the findings to a local markdown file.
-
c0nant Bundle Tech Debt MapAudit a codebase that grew organically and produce a ranked map of its worst technical debt, plus a phased, incremental cleanup plan. Diagnosis only, it changes no code.
-
marcel-bich Skill Compact PlusSecure everything the user approved before a context compaction so a later /compact can never lose or alter it. Writes verbatim intent and handoff state to disk and commits plus pushes the tracked work product in the correct repository, then reports whether it is safe to compact. It does NOT run /compact itself - it makes a later compact safe. Run this only when the limit plugin's injected ACTION line names it (session-context fill crossed a configured threshold) or when the user invokes it manually. Never self-trigger it proactively - that only wastes tokens. Accepts extra trailing instructions to perform in addition to the securing checklist. A minimal mode (invoke as /compact-plus min) secures only intent plus handoff to disk - no audit, no commit or push - for a quick token-cheap save.
-
marcel-bich Skill Skill CaptureTurn a recurring in-session workflow into a reusable Claude Code skill. Load this the moment you notice you have run the SAME multi-step sequence (same ordered steps or commands, small variation allowed) about three times in the current session, or when open candidates are waiting in .credo/skill-candidates.md at session start or resume. It is heuristic and in-session only - no persistent counter, no tracking backend. Mode-gated like the audit nit-disposition policy: autonomous mode NEVER builds a skill (it only appends a candidate note and keeps working), active / passive / default propose the capture via the Ask tool and build only on an explicit GO. Applies inside subagents too, where the safest branch (autonomous: candidate note only, never ask, never build) is the default whenever the mode cannot be determined.
-
neetx Bundle Eso Character ManagerCreates, updates, and uses ESO CHARACTER.md files for single-character planning. Use when the user wants to create, grow, audit, optimize, save, or track an ESO character or character concept.
-
onewave-ai Skill Polish PassThe de-AI pass -- audit a vibe-coded app for template smell in design and copy, then fix it with editorial layout, purposeful motion, and human-sounding words. Use after any build session, before anyone else sees it.
-
pranavnagrecha Skill Developer Code QualityAnswers Salesforce developer code-quality questions: "audit my Apex for quality issues", "find governor-limit risks", "where do we have hardcoded IDs / emails / usernames", "check CRUD / FLS enforcement", "what tests are missing / fake-covered", "find dead code", "review this Apex class", "what methods does this class have". Drives the v2.1 quality-recognizer cascade (`code_quality_audit`, `governor_limit_risks`, `find_hardcoded_values`, `crud_fls_audit`, `test_coverage_gaps`), the v2.4 hygiene tool `find_dead_code`, and `apex_structure` for a question about ONE named class or trigger (parsed on demand; adds AST-only checks at `confidence: 'parsed'`). Every recognizer finding is `confidence: 'heuristic'` — pattern recognition is recognition, not declaration; only `apex_structure`'s eight AST-only checks rise above that. Discloses the v2.1 boundary verbatim: the recognizer pattern-matches on tokenized Apex source (not a compiler AST), so cross-class blindness, custom security utility helpers invisible, dynamic
15 -
pranavnagrecha Skill Architect Integration TopologyAnswers Salesforce architect integration questions: "draw me our integration map", "what subscribes to this platform event", "who calls this REST API", "which classes are queueable / batchable", "what runs async in this org", "where does this external data source connect", "what is our external API surface", "which external services use this named credential", "audit our auth providers". Call `sfi.run_analysis` with `{ "name": "sfi.integration_map", "args": { … } }` (organized map of auth + endpoints + APIs + access lists) and `sfi.event_subscribers` (given a platform event, return all Apex/Flow subscribers). Plus `sfi.list_components` with the new v1.5 property filters (isQueueable, isSchedulable, isBatchable, hasFutureMethod, hasInvocableMethod, isRestResource, hasAuraEnabledMethod) for async/job and API surface questions. Discloses v1.5 honesty axis: some patterns are heuristic (dispatchesAsync via reflection, LWC fetch URL correlation, CDC subscription detection) and require manual verification.
15 -
timbogp Bundle UX AuditThis skill should be used when the user wants a structured usability review of an interface and asks to "audit this UX", "run a usability review", "do a heuristic evaluation", "review this flow/screen", "what's wrong with this UI", or "is this usable". It produces a scored, severity-ranked usability report from screenshots, a live URL, a description, or source code.
-
vdustr Bundle Vp Env SecretsSafely inspect, select, stage, persist, or load sensitive environment variables from dotenv files using dotenvx. Use for API keys, tokens, credentials, local secret files, or commands that need those values.
-
vdustr Bundle Vp Deps UpgradeUpgrade dependencies with breaking-change and compatibility analysis. Use for version bumps, outdated packages, security updates, and dependency-bot PRs. Boundary: use vp-deps-migrate when replacing a library or API family.
-
ssurmic Skill Analyze StockTop-down deep dive analysis on a US-listed stock with macro context, valuation audit, insider check, catalysts, and 3-tier entry plan with LEAPS option. Pulls live data via yfmcp. Triggers in English ("analyze X", "is X a buy", "deep dive on X", "should I buy X", "what about X stock", "research X") or Chinese ("分析 X", "X 怎么样", "X 能买吗", "深度看一下 X", "调研 X", "X 这只股票").
-
ssurmic Skill Portfolio AuditComprehensive portfolio risk audit. Computes single-name concentration, factor cluster exposure, leverage ETF decay risk, options Greeks aggregation, stress test scenarios (-10% SPX, yen carry, single-name miss), hedge effectiveness. Outputs explicit trim list with $ amounts and reasons + cash target. Triggers in English ("review my portfolio", "audit my book", "am I too concentrated", "what should I trim", "portfolio risk check") or Chinese ("审一下我的组合", "我组合风险大吗", "该减什么仓", "组合审计", "我哪里太集中").
-
ssurmic Skill Jackal Tech ScanSTOCK TRADING ONLY — Multi-indicator technical deep-scan combining MA alignment, RS Line divergence, MACD convergence, volume signature, and 200-MA deviation extremity check to infer institutional money flow direction. Outputs "smart money is doing X" conclusion with transparent reasoning. Use when user asks English: "tech scan $TICKER", "technical analysis NVDA", "institutional flow MRVL", "is smart money buying $TICKER", "Jackal tech scan", or Chinese: "$TICKER 技术面深度扫描", "看一下 $TICKER 机构资金流", "$TICKER 的 RS line / MA / MACD 综合判断", "Jackal 技术分析 $TICKER". DO NOT trigger for: code "tech debt scan", "tech stack analysis", security scans, vulnerability scans, dependency scans, or any non-equity technical analysis. If "tech scan" appears without a stock ticker, do NOT invoke.
-
suifei Skill Architecture ReviewReview code for architecture compliance against GopherPaw's layered architecture rules. Use when the user asks to review, audit, or check code for architecture violations, dependency issues, or design pattern compliance.
-
suifei Skill Dingtalk Channel Connect使用可视浏览器自动完成 CoPaw 的钉钉频道接入。适用于用户提到钉钉、DingTalk、开发者后台、Client ID、Client Secret、机器人、Stream 模式、绑定或配置 channel 的场景;支持遇到登录页时暂停,等待用户登录后继续。
-
swannysec Bundle Phased ReviewMulti-stage implementation review with parallel sub-agents, severity-based autonomous fixes, and gated test verification. Runs code quality, architecture, simplicity, documentation, and security reviews in sequence with test gates between each fix stage. Security review is blocked until all other fixes are complete. Use after completing a feature, implementation phase, or release candidate. Supports scope modes: full, code-only, security, simplicity, docs.
-
swannysec Bundle Impact FlowCodebase flow analysis for dependency visualization, impact assessment, and health scoring. Use PROACTIVELY when users need: (1) Dependency/import analysis ("what imports this?", "dependency graph", "module relationships") (2) Blast radius/impact analysis ("if I change X", "what's affected", "impact of modifying") (3) Code health scoring ("codebase health", "health grade", "technical debt score") (4) Execution flow tracing ("trace through", "call path", "how does data flow") (5) Dead code detection ("unused exports", "safe to delete", "orphan code") (6) Comprehensive analysis ("full analysis", "analyze this codebase") NOTE: For security scanning, defer to security-sentinel. For design patterns, defer to pattern-recognition-specialist. For architecture compliance, defer to architecture-strategist.
-
swannysec Bundle Secret Scanning InvestigatorInvestigate GitHub secret scanning alerts to trace provenance, gather context, assess risk, and produce a structured report for security professionals. Handles one or more alerts in a single investigation using only open-source tools.
-
wpultimatesecurity Bundle Ajax SecurityUse when registering or handling WordPress AJAX over admin-ajax.php - wp_ajax_{action} / wp_ajax_nopriv_{action} hooks, JavaScript that posts to admin_url('admin-ajax.php'), or wp.apiFetch / fetch calls to custom actions. Verifies the nonce with check_ajax_referer, gates the action with current_user_can, unslashes and sanitizes every field, and replies with wp_send_json_success / wp_send_json_error. Prevents CSRF, broken access control, and injection on the AJAX surface.
-
wpultimatesecurity Bundle Wp CLI SecurityUse when registering a WP-CLI command with WP_CLI::add_command or writing command logic. Validates and sanitizes positional and associative arguments, does not assume a logged-in user or capability context, avoids printing secrets, and confirms destructive operations. Prevents injection and unsafe automation through the CLI surface.
-
wpultimatesecurity Bundle Multisite SecurityUse when writing code that runs on a WordPress multisite network - switch_to_blog, network admin pages, get_sites, or capabilities that differ between site and network scope. Uses manage_network / manage_network_options and is_super_admin correctly, restores context with restore_current_blog, isolates per-site data, and never trusts a blog id from input. Prevents cross-site data leakage and network privilege escalation.
-
wpultimatesecurity Bundle Filesystem SecurityUse when reading, writing, including, or deleting files from paths that include user input - include / require, readfile, unlink, file_get_contents, or the WP_Filesystem API. Validates paths with validate_file, normalizes with wp_normalize_path, confines operations to an allowed base directory, and uses wp_delete_file / WP_Filesystem. Prevents path traversal, local file inclusion, and arbitrary file deletion.
-
wpultimatesecurity Bundle File Upload SecurityUse when a WordPress plugin or theme accepts file uploads, processes $_FILES, saves user-provided files, or generates file paths from input. Uses wp_handle_upload and wp_check_filetype_and_ext with a MIME/extension allowlist, blocks executable types, and prevents path traversal. Prevents arbitrary file upload and RCE. Apply proactively to any upload or file-writing code path.
-
wpultimatesecurity Bundle Security Headers CspUse when adding HTTP response headers to a WordPress site or plugin: Content-Security-Policy (or Report-Only), X-Content-Type-Options, frame protection (X-Frame-Options or frame-ancestors), Referrer-Policy, Permissions-Policy, HSTS, Secure/HttpOnly/SameSite cookie flags, or CORS on REST responses. Covers the wp_headers filter, the send_headers, login_init and admin_init surfaces, per-request CSP nonces via script_loader_tag, and REST origin restriction through core's allowlist. Headers are the second XSS layer after output escaping, and they also stop clickjacking and MIME sniffing.
-
wpultimatesecurity Bundle Woocommerce SecurityUse when a plugin extends WooCommerce - reading or writing orders, customer data, or hooking checkout, REST, or the Store API. Sanitizes input with wc_clean, gates shop actions with WooCommerce capabilities like edit_shop_orders, minimizes stored payment data, and escapes customer PII on output. Prevents broken access control and PII / order data exposure.
-
wpultimatesecurity Bundle Shortcode Block SecurityUse when registering a shortcode with add_shortcode or a dynamic block with a render_callback, or processing shortcode / block attributes. Normalizes attributes with shortcode_atts, validates against allowlists, and escapes all rendered output for its context with esc_html, esc_attr, esc_url, or wp_kses_post. Prevents stored and reflected XSS in rendered content.
Audited -
wpultimatesecurity Bundle Secure Plugin DevelopmentUse when starting a new WordPress plugin or theme, scaffolding a plugin file, wiring hooks, or adding any feature that handles requests, options, or output. Establishes the secure-by-default baseline — ABSPATH guard, the capability + nonce + sanitize + escape flow, prepared queries, and safe defaults — and routes to the focused security skills for each concern. Apply proactively at the start of any WordPress build.
-
wpultimatesecurity Bundle Settings Options SecurityUse when building an options or settings page with the WordPress Settings API - register_setting, add_settings_field, settings_fields, an options.php form, or update_option / get_option on plugin data. Attaches a sanitize_callback to every setting, gates the page with manage_options, relies on Settings API nonce handling, and escapes options on output. Prevents stored XSS and unauthorized option writes.
-
wpultimatesecurity Bundle Wp Hardening Best PracticesUse when configuring or hardening a WordPress site, editing wp-config.php, writing .htaccess or nginx rules, setting file permissions, or advising on deployment security. Covers security keys, DISALLOW_FILE_EDIT, FORCE_SSL_ADMIN, disabling debug output, blocking PHP execution in uploads, protecting sensitive files, and least-privilege file permissions. Apply proactively when setting up or reviewing a site's configuration.
Audited -
wpultimatesecurity Bundle Cron Background Job SecurityUse when scheduling WordPress cron events with wp_schedule_event / wp_schedule_single_event or writing the callback that runs on a cron hook. Treats cron callbacks as running without a logged-in user, re-checks authorization against stored context rather than current_user_can, keeps secrets out of cron URLs, and validates any stored input the job consumes. Prevents unauthenticated privileged actions via the cron surface.
-
stephschofield Skill Security Analysis````skill
-
stolinski Bundle UI Design CritiqueDesign critique for user interfaces that produces a prioritized, strict report of design issues. Use when asked to "critique this design", "review the UI", "design review", "roast my UI", "is this AI slop", "does this look AI-generated", "audit the visual design", or evaluate a screen, page, or screenshot against brand guidelines or a DESIGN.md spec. Classifies every finding as a gap, inconsistency, suggestion, or strength and ranks it by impact. Runs deterministic DOM detectors to catch broken layout (overflow, overlap, clipping) and evaluates visually via browser/devtools capture and against design tokens.
-
stolinski Bundle FallowCodebase analyzer for JavaScript/TypeScript projects. Finds unused code (files, exports, types, dependencies), code duplication, circular dependencies, complexity hotspots, architecture boundary violations, and feature flag patterns. 90 framework plugins, zero configuration, sub-second performance. Use when asked to analyze code health, find unused code, detect duplicates, check circular dependencies, audit complexity, check architecture boundaries, detect feature flags, clean up the codebase, auto-fix issues, or run fallow.
-
stolinski Bundle Repo Quality OrchestratorOrchestrates sub-agents to audit and safely clean up messy TypeScript codebases. Use when asked to "clean up AI-generated code", "reduce duplication", "improve folder organization", "enforce modularity", or "grade code quality".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include developer-code-quality, architect-integration-topology, meziantou-analyzer. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.