Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
iamakbarsha1 Skill Audit Before You BuildUse as the FIRST step of any implementation task handed to you from a checklist, ticket, milestone, or spec — the first step is an existence check, not a design. Trackers record conversations, not deliverables, so grep for the item's key nouns and cross-check spec status before writing code, then pivot "build X" to "verify X and close the gaps" when it already exists. Triggers on "implement this ticket", "build feature X", "next milestone item", "from the checklist", "start this task", "add X".
-
iamakbarsha1 Skill Findings List Is Not A Todo ListUse when re-engaged to "act on" or "fix the rest of" a review, audit, or recommendation list — the list is not a to-do list. Re-read each item's own disposition first and bucket them; some are explicitly marked no-fix, some need a human decision, some are scale-gated. Triggers on "fix the findings", "address the review", "do the rest of the recommendations", "apply the audit", "action these items", and acting on any list you or someone else produced earlier.
-
iamzifei Skill Money QualityCode and product quality gates for shipping with confidence. Runs code review, QA testing, performance checks, and security audits. Use when the user says 'review my code', 'is this ready to ship', 'check quality', 'run QA', 'test this', 'security check', 'pre-launch review', or wants a quality assessment before deploying.
-
jposluns Skill AdoptRun-once onboarding for a fork of a project that ships this governance pack. A maintainer's clone carries accumulated operational working-state (audit-trail registers, session handoff, a queue of next actions, per-document review anchors) that is meaningless to a fresh adopter; this skill either resets present machinery-core working-state to clean adopter baselines or, when the configured working-state location is absent, treats it as already clean and creates only the adopter-local state a public versioned consumer requires, settles how the adopter will handle the project's optional external dependencies (their own, or self-contained with in-repo stubs `/adopt` creates or functional in-repo substitutes), strips maintainer-only operational residue, and records the adopter's choices in the project's committed adoption marker so the resume mechanism proceeds in adopter mode without re-asking. It runs ONLY on a confirmed adopter fork (a fork origin), never on the upstream maintainer repository or an upstream mai
-
jposluns Skill Claim FitClaim Fit (citation-precision audit of normative-attribution claims)
-
jposluns Skill Matrix FitMatrix Fit (semantic-fit audit of control-code citations)
-
jposluns Skill Reference AuditReference Audit (reference-breadth audit of project content against configured source material)
-
jposluns Skill Pr RetrospectivePer-PR process retrospective, run as a PR's finalizing step before merge. Surfaces what went well, what caused friction, recurring patterns, and proposed improvements. Output is one entry per PR in the improvement-log register; recurring patterns become candidates for pack-rule updates, worker-brief template additions, or new audit gates. Invoke after the PR-scoped validation sweep (`validation-sweep-pr-scoped`; the parent library's `/validate-pr`) returns and before the next-PR planning step.
-
jposluns Skill Validation SweepProject-wide regression sweep run as a follow-up after any issue is identified and corrected, to confirm no sibling issue remains anywhere in the repository. Invoke after fixes that touch multi-surface artefacts, gate inventories, prose claims about repository state, AI-inferred citations, or generated artefacts. Combines the mechanical audit suite with a structured semantic fan-out, and loops until clean.
-
jposluns Skill Library Fitness ReviewTrigger a comprehensive whole-collection library-fitness review with a project-defined catalogue of persona reviewers when a documentation collection (the parent case is a governance/security documentation library) undergoes a major change or reaches its minimum review cadence, quarterly by default unless the adopting project records a different interval. The parent GRC library's major-change triggers are a new domain directory, a new document type, multiple governance rule additions, and a major restructure. Each invocation dispatches a fan-out of independent persona subagents (for example an executive reader, a security practitioner, an auditor, a newcomer) who review every page from a fresh-reader perspective without inheriting maintainer mental models. Catches comprehensibility, usability, logical-structure, standardization, domain quality, auditability, maintainability, and reader-experience gaps that per-change validation sweeps and mechanical audit gates do not detect. Surfaces prioritized recommendati
-
jposluns Skill Gate Discipline DiagnoseDiagnoses a failing CI gate, lint, or audit and fixes the artefact rather than weakening the gate. Use when a gate fails. Use when tempted to bypass a check with --no-verify, blanket suppression, severity-threshold lowering, or exemption-list addition. Use when a pre-commit hook blocks a commit. Use when a required status check on a PR shows red.
-
jposluns Skill Change Tracking Write EntryComposes a CHANGELOG entry (substantive or terse form) for a PR. Use when about to commit, open a PR, or finalize a change. Every PR carries an entry, even if terse; there is no skip path. The entry's required parts (date-and-version header, structured Keep a Changelog sections for substantive entries, file references as markdown links, the "why" not just the "what", verification evidence, phase context) are walked step by step so an entry that would fail the link-coverage gate, the version-monotonicity audit, or the PR-time delta gate is caught at the draft stage rather than at CI.
-
jwiegley Bundle WiggumMethodology for the user-triggered /wiggum command (do not self-invoke). An autonomous-continuation loop for long-running work -- run, checkpoint, and verify until a defined Definition of Done holds or a stop-and-escalate condition fires. Covers durable handoff state, baseline re-verification after context compaction, per-commit self-audit, work-unit commit and restack cadence, subagent fan-out limits, and escalation.
-
jwiegley Bundle Comment AuditExhaustively verify code comments against the current state of a project. Use when asked to audit, fact-check, or validate comments/docstrings -- to confirm that every claim a comment makes is true, that any code shown in a comment actually works, and that everything a comment references still exists. Supports auditing an entire project or only the changes in a PR or stack of PRs. Triggers: "check the comments", "are these comments still accurate", "audit comments in this PR", "verify the docstrings".
Audited -
koinod Skill Workflow AuditorAudit your business workflows and find automation opportunities
Audited -
jmylchreest Skill SemgrepRun Semgrep security and code quality analysis
-
kdeldycke Skill Pr TriageAudit open PRs across multiple repos for duplicates, stale drafts, Renovate noise, and conflicts. Produces a unified priority report.
-
kdeldycke Skill Repomatic DepsGenerate dependency graphs. Audit pyproject.toml declarations against the version policy. Explore unused dependency APIs that could simplify code. Modernize code against the changelogs of upgraded dependencies.
Audited -
kdeldycke Skill Upstream AuditCreate or update the upstream contributions page (docs/upstream.md), which records what this project sends back to its dependencies. Find merged PRs, reported issues, workarounds and declined features.
-
kdeldycke Skill Repomatic AuditAudit how far a downstream repo has drifted from the upstream repomatic reference. Cover workflows, configs and conventions.
-
kdeldycke Skill Audit Repo IssuesAnalyze a GitHub repository's issues and PRs to find unaddressed feature requests, dismissed ideas, maintenance signals, and opportunities relevant to the current project. Use when you want to scout a related or competing repo for gaps your project could fill.
-
khuynh22 Skill Code Review PassReviews a diff, branch, or pull request across correctness, security, architecture, readability, and performance, returning ranked findings with file and line references and a concrete fix for each. Use before merging, when checking code written by someone or something else, or when a change needs a quality gate.
Audited -
khuynh22 Skill Security HardeningAudits a change or a system for reachable vulnerabilities by tracing untrusted input to its sinks and checking authorization at every new path. Use when code touches authentication, secrets, cryptography, file paths, shell execution, deserialization, or any input crossing a trust boundary, and before exposing anything to the internet.
Audited -
ksachdeva Bundle Zephyr WifiExpert guidance for WiFi development in Zephyr OS. Covers Station (STA) and Access Point (AP) modes, scanning, connection management, security types (WPA2-PSK, WPA3-SAE, EAP-TLS), power save modes, and Target Wake Time (TWT). Use when implementing WiFi connectivity, configuring network parameters, handling scan results, managing connections, or troubleshooting WiFi issues.
-
ksachdeva Bundle Zephyr Net SocketExpert guidance for BSD sockets, TLS/DTLS secure sockets, and DNS resolution in Zephyr OS. Covers TCP/UDP socket programming, secure socket creation with mbedTLS, TLS credential management, hostname resolution with getaddrinfo/dns_resolve, mDNS/LLMNR support, and socket offloading. Use when implementing network clients/servers, adding TLS security to connections, resolving hostnames, or configuring socket-based networking.
-
lilac-labs Bundle Knowledge BaseBuild and maintain a company knowledge base as a wiki of interlinked markdown notes in the workspace — a private, compounding Wikipedia. Use when the user wants to start or organize a knowledge base / wiki, ingest sources (URLs, documents, pasted notes) into it, ask questions answered from it, or audit (lint) it. Defines the wiki layout (SCHEMA / index / log / raw / pages), the frontmatter contract, [[wikilink]] conventions, and a deterministic lint script that catches broken links, orphan pages, index drift, and frontmatter problems.
Audited -
mblauberg Bundle RetrospectUse after delivery, release, incident, evaluation, or a long run to derive evidence-backed process improvements and regression gates. Not for session cleanup, one skill audit, or an active defect; use session, skill-craft, or implement.
-
meganz Skill Android Code ReviewAndroid PR Code Review skill. Performs a comprehensive code review on the current Git repository's PR or specified code changes. Covers all review dimensions including architecture, Kotlin code quality, Android platform best practices, performance, security, and testability — along with a standardized output format. Can also be used as a standalone reference for Android review standards.
-
momentmaker Bundle Security And HardeningOWASP-Top-10-aware security review of a diff or target file set. Use when the user says "security review", "OWASP check", "audit for vulns", "harden this", "security audit", or invokes /security. Composes blunder-hunt's hostile-input lens. Surfaces injection, auth gaps, broken access control, sensitive data exposure, and supply-chain risks.
-
mysteryon88 Bundle Mina O1js Learning CoachUse when teaching or learning Mina, o1js, zkApps, proof constraints, AccountUpdates, permissions, Merkle state, ZkPrograms, custom tokens, or Mina security fundamentals.
-
mysteryon88 Bundle Ton Zk Integration ReviewUse when reviewing the TON integration boundary after proof-system artifacts exist, including canonical scalars, VK handling, public-input semantics, replay, messages, state, gas, or generated verifier edits. Do not use as the sole audit for circuit constraints, prover correctness, proof-system soundness, or ceremony execution.
Audited -
mysteryon88 Bundle Mina Token Standard SecurityUse when building or reviewing Mina custom tokens, fungible tokens, stablecoins, wrapped assets, token managers, mint or burn authorization, tokenId handling, or token accounting flows.
-
mysteryon88 Bundle Mina Ecosystem Research ScoutUse when finding or evaluating current Mina and o1js resources, examples, grants, audit reports, repositories, issues, tooling, standards, or ecosystem projects.
-
mysteryon88 Bundle Mina Deployment Upgrade SecurityUse when preparing, reviewing, or hardening Mina zkApp deployments, upgrade policies, verification keys, permission matrices, key management, network configuration, or release procedures.
Audited -
mysteryon88 Bundle Mina Privacy Credentials SecurityUse when designing, implementing, testing, or reviewing Mina privacy flows, credentials, zkKYC, selective disclosure, nullifiers, unlinkability, issuer signatures, or private-data leakage.
-
open-coder-ai Skill Block Curl Pipe ShBest-effort guard against piping a network download straight into a shell or script interpreter: curl|wget|iwr ... | sh/bash/zsh/python/perl/ruby/node (bare or path-qualified, including subshell groups and sudo/exec/command/env wrappers), bash -c "$(curl ...)", bash <(curl ...), and the PowerShell iwr ... | iex form. Downloading to a file, or piping a fetch into a non-interpreter tool (jq, tar, grep), stays allowed. Known bypass classes include aliases, variable indirection, base64/obfuscated payloads, env-var-prefixed interpreters, and non-standard fetch clients. This is friction, not a security boundary.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include audit-before-you-build, findings-list-is-not-a-todo-list, money-quality. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.