Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
yaojingang Bundle Yao Websecurity SkillUse when auditing an authorized website, SaaS, API, AI app, local code path, GitHub repo, staging URL, or owned runtime for security risks, vulnerability checklist scoring, static review, dynamic review, active validation, or Chinese security reports.
Audited -
krutikjain Bundle Android Security Best PracticesApply Android app security guidance around secrets, storage, network trust, exported components, and least privilege.
Audited -
karlorz Skill Wiki AuditVerify per-page that every ^[raw/...] resolves and sources frontmatter matches the body.
-
karlorz Bundle Vault Fuse FreshnessAudit Linux rclone FUSE wiki freshness. Use when dir-cache-time drifts or a bounded vfs/refresh is needed.
Audited -
axect Bundle Adversarial ReviewRun an adversarial peer-review swarm on a paper draft, report, or manuscript by spawning parallel persona subagents (hostile theorist, experimentalist, statistician, journal editor, citation auditor, figure critic) and synthesizing their critiques into a ranked fix list with suggested defense experiments. Use when the user asks for a paper review, referee simulation, desk-reject check, pre-submission audit, citation audit, figure audit, novelty attack, or wants feedback on a draft report before submission or internal circulation.
-
axect Bundle Journal Club ReviewProduce a journal-club-style paper presentation (9 sections: TL;DR, Problem, Key Idea, How It Works, Key Results, Why It Matters, Strengths/Limitations/Open Questions, Discussion Questions, Takeaways) from an arXiv ID/URL, a PDF, raw text/markdown, or a local LaTeX source (.tex / project dir). Helps a reading group UNDERSTAND and DISCUSS the paper — not score or accept/reject it. Grounds every claim in the source, renders math as LaTeX, auto-matches the source language (Korean source -> Korean review). When LaTeX source is available (arXiv e-print or local .tex), embeds the paper's real figures with captions; optionally generates two friendly-whiteboard infographic figures via the bundled codex image_generation tool. Use when the user wants a journal-club review, paper walkthrough/presentation, or paper explainer, to "review this PDF/paper like a journal club", or 논문 저널클럽 리뷰/발표자료/논문 설명. For an OpenReview referee report use workshop-paper-review; for an adversarial pre-submission audit use adversarial-review.
Audited -
marcel-bich Skill DiagRead-only root-cause diagnosis for a symptom, bug, failure, or unexpected behavior. Establishes the mechanism at file:line and reads up the facts instead of guessing, before any fix is attempted. Produces a diagnosis report; the fix is always a separate step gated by an explicit GO. Use when something is broken, failing, throwing, or behaving unexpectedly and the cause is not yet proven, or when asked to investigate or find the root cause. Not for judging whether finished work meets its requirement (use audit) and not for confirming rendered UI behavior (use verify).
-
marcel-bich Skill AuditRead-only quality gate that audits already-built work against its stated requirement and Definition of Done before it is allowed to move to 2_done/. Produces a severity-ranked decision proposal (BLOCKER/MAJOR/MINOR/NIT) with evidence, never a fix. Use when an item is claimed complete, before moving anything to 2_done/, when asked to audit or review finished work for completeness against requirements, or when acting as the dedicated post-completion review subagent. This gate is mandatory in every session mode. Not for diagnosing why something is broken (use diag) and not for verifying rendered UI behavior (use verify).
-
arjuncrevathi Skill YamaSupabase standards — auth, Row Level Security, schema migrations, typed clients, and the boundary between Supabase app data and the FastAPI/Render Postgres side. Use when writing Supabase queries, auth flows, RLS policies, Supabase migrations, storage rules, or deciding where data should live.
-
arjuncrevathi Skill ChitraguptaStructured logging, audit trails, and request tracing standards. Use when adding logging to any service, implementing audit requirements, tracing requests across services, or reviewing what gets logged and how.
-
automagik-dev Bundle DocsDispatch docs subagent to audit, generate, and validate documentation against the codebase.
-
automagik-dev Bundle Supply ChainUse when auditing security and supply chain in any codebase — trust boundaries, credential handling, injection surfaces, update/release integrity, CI permissions, dependency pinning. Assess by default, harden on request; provenance or it didn't happen.
-
getstoreconnect Bundle Storeconnect Debug PerformanceInstrument and speed up StoreConnect Liquid — the web Console, the debug and timer tags, drop and record introspection, cache key design and invalidation, collection and pagination cost, per-item hot paths, asset weight, and client-side batching. Use when you need to instrument a template that renders blank or wrong, cache a fragment, or cut queries on a slow page, when cached output is stale or reaches the wrong visitor, and before adding any debug, timer, or cache tag. For an audit that changes nothing use storeconnect-theme-review.
-
aizech Bundle Image Quality AuditAssesses medical image quality against clinical standards and identifies optimization opportunities. Use when user mentions "image quality audit", "artifact review", "dose analysis", "protocol deviation", "quality metrics", "diagnostic adequacy", or "technique optimization".
-
aizech Bundle Report Quality ReviewMonitors and improves radiology report quality through systematic audit and feedback. Use when user mentions "report quality review", "discrepancy audit", "report completeness", "addendum analysis", or needs quality assurance.
-
cody-sims Bundle Code ReviewReviews a diff, pull request, or set of staged changes for correctness, tests, error and edge cases, security, performance, readability, and architectural fit, then reports severity-ranked, actionable findings with file and line references. Use when reviewing a PR, examining staged or unstaged changes, giving feedback on a patch, or deciding whether a change is safe to merge.
-
cody-sims Bundle Requirements And Spec WritingTurns an ambiguous or large request into an agreed written specification before implementation, covering objective, users and use cases, requirements, non-goals, interfaces and data contracts, security and privacy, error and edge cases, acceptance criteria, open questions, alternatives considered, and rollout and rollback. Use when a request is vague, scope or acceptance criteria are unclear, or the user asks for a spec, requirements, or a design before coding begins.
-
conmuyan Bundle Kim Ccf Research IntegrityAudit CCF paper integrity: claim-support alignment, result-to-claim consistency, numeric consistency, terminology consistency, figure/table-to-text consistency, existing citation existence, BibTeX metadata, and citation-context support. Use for evidence audit, citation audit, consistency check, 引用核验, claim审计, 数字一致性. Do not perform full scientific review or broad literature search.
-
dolphinllc Skill Django Security ScanDefensive security scan for Django and Django REST Framework projects. Detects DEBUG=True in production, wildcard ALLOWED_HOSTS, SECRET_KEY in source, missing CSRF, raw ORM queries with string formatting, mark_safe on user input, AllowAny on mutating DRF views, and ModelSerializer fields="__all__" leaking sensitive fields. Invoke when the user asks to "review", "audit", or "scan" a Django project.
-
dolphinllc Skill Nestjs Security ScanDefensive security scan for NestJS applications. Detects missing global ValidationPipe with whitelist, controllers without @UseGuards, DTOs without class-validator decorators, permissive CORS, missing helmet, exception filters leaking stack traces, TypeORM raw queries with template literals, and WebSocket gateways without auth. Invoke when the user asks to "review", "audit", or "scan" a NestJS project.
-
dolphinllc Skill Fastapi Attack ProbeAuthorized self-pentest probe targeting FastAPI-specific weaknesses. Tests /docs and /redoc auth, OpenAPI schema enumeration, Pydantic boundary bypass via extra fields, missing Depends/Security on routes, JWT alg confusion, and unsafe file responses. Use when the user asks to "pentest" their own FastAPI app.
-
dolphinllc Skill Express Security ScanDefensive security scan for Express.js applications. Detects missing helmet, unsafe body-parser limits, broken trust-proxy config, weak cookie/session options, missing CSRF, middleware-ordering bugs (auth registered after route), unvalidated res.sendFile, and unsafe eval of request data. Invoke when the user asks to "review", "audit", or "scan" an Express project.
-
dolphinllc Skill Spring Boot Attack ProbeAuthorized self-pentest probe targeting Spring Boot-specific weaknesses. Tests Actuator endpoint exposure (/env, /heapdump, /loggers), Whitelabel error page info disclosure, h2-console exposure, Spring Security permitAll gaps, and SpEL/parameter-binding pitfalls. Use when the user asks to "pentest" their own Spring Boot app.
-
dolphinllc Skill Webapp Pentest ChecklistAuthorized self-pentest checklist for web applications you own. Walks the OWASP Web/API Top 10 against a locally-running target, discovering the base URL via env or entrypoint files (never hardcoded). Use when the user asks to "pentest", "attack", "probe", or "test the security of" their own running web app and the framework is unknown or mixed. For framework-specific deeper checks, use express/django/spring-boot/nextjs/nestjs/fastapi attack-probe skills.
-
dolphinllc Skill Langchain Security ScanDefensive security scan for LangChain / LangGraph applications. Detects unsafe agents (PythonREPLTool, ShellTool), retriever trust-boundary violations, output parser injection, callback handlers leaking secrets to logs, and missing tool input validation. Invoke when the user asks to "review", "audit", or "scan" code using langchain, langgraph, or related extensions.
-
dolphinllc Skill Spring Boot Security ScanDefensive security scan for Spring Boot applications using Spring Security. Detects permitAll on sensitive routes, disabled CSRF on stateful endpoints, wildcard CORS with credentials, missing @PreAuthorize, JdbcTemplate string concatenation, Jackson default typing, exposed actuators, and weak BCrypt strength. Invoke when the user asks to "review", "audit", or "scan" a Spring Boot project.
-
dolphinllc Skill Openapi Spec Security ScanDefensive security scan for OpenAPI 3.x specifications (openapi.yaml / openapi.json). Detects missing global security, unprotected mutating operations, HTTP-only servers, loose schemas (additionalProperties true, missing required), wildcard CORS, missing 401/403 responses, PII in examples, and weakly-typed parameters. Invoke when the user asks to "review", "audit", or "scan" an OpenAPI / Swagger spec, or when editing files named openapi.{yaml,json}, swagger.{yaml,json}, or under api/ directories.
-
dolphinllc Skill Vercel AI Sdk Attack ProbeAuthorized red-team probe for applications built on the Vercel AI SDK (`ai` package). Tests tool execute exploitation via crafted user messages, useChat endpoint authentication, attachment limits, and streamText/dangerouslySetInnerHTML XSS via injected markdown. Use when the user asks to "red-team" or "attack-test" their AI SDK app.
-
impertio-studio Bundle Speckle Syntax WebhooksUse when setting up Speckle webhooks, handling webhook payloads, or automating reactions to Speckle events. Prevents incorrect event trigger strings, missing webhook security validation, and exceeded webhook limits. Covers webhook lifecycle (create/update/delete), all 14 event types with trigger strings, payload structure, configuration limits, security, and retry behavior. Keywords: speckle webhook, event, trigger, payload, webhookCreate, commit_create, stream_update, branch_create, automation, notify, trigger on change, real-time update.
-
api-evangelist Bundle Transfer Validator ProtocolTransfer Validator V5 background knowledge -- modular rulesets, list management, validation logic, security configurations. Use this skill whenever the user asks about transfer validation, operator whitelists, blacklists, soulbound tokens, OTC transfer rules, account freezing, or any code referencing the Transfer Validator at 0x721C008fdff27BF06E7E123956E2Fe03B63342e3.
-
ascend Bundle Gitcode Pr AuditQuality audit for merged GitCode PRs: sample by time range or repo list, check compliance (labels, comments, tests, size, etc.), output table. Use when user asks to 抽检/质量检查 已合入的 PR 规范性、多仓库 PR、或 将结果整理成表格. Multi-repo (owner/repo). Python 3.7+ stdlib only.
-
ascend Bundle Sdk Security AuditC/C++ 和 Python SDK 代码安全审计。当用户请求安全审计、代码审计、漏洞扫描、安全检查时使用。支持本地仓库和远程 GitHub/GitLab/GitCode 仓库。从对外 SDK 函数入口出发,依据安全编码规范进行符号级分析,输出具备完整证据链的问题报告。
-
ascend Bundle Gitcode Pr Security ReviewGitCode PR安全审查技能。用于自动审查GitCode仓库的Pull Request中的代码安全问题,使用sdk-security-audit技能进行代码安全分析,并将审查结果作为评论发布到对应的PR上。当用户需要对GitCode仓库的PR进行安全代码审查时使用此技能。
Audited -
cyberuni Skill Audit SkillUse this skill when auditing a SKILL.md for structure, quality, and security before installing or committing.
-
cyberuni Skill Fix Security PrUse this skill when a PR fails security or vulnerability checks (audit, CVE, Dependabot, Snyk, or advisory blocks).
-
dandacompany Skill Iris Security AuditMAGMA 4기둥 보안 감사 — 키·권한·스킬·격리를 점검해 위험 삼각·Rule of Two로 판정하고 잘하는 것/조치 필요/신규 위험 3부 보고서를 낸다. 대화형 세션에서는 보고 후 발견 이슈를 한 개씩 순차로 제시해 처리 방식(자동·승인후·안내)을 확인받아 Iris가 안전하게 처리하고, cron·훅 등 무인 실행에서는 보고서만 전송한다(이상 없으면 [SILENT]). 헤르메스 강의 4.3 보안 감사 자동화 실습 준비물.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include yao-websecurity-skill, android-security-best-practices, wiki-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.