Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
qball-inc Bundle Test AuditTest Audit
-
anymouschina Skill Aesthetic Audit商业级视觉资产与网页(详情页/落地页)的审美与UX视觉审查:输出P0/P1/P2问题清单、可落地的样式tokens与改稿建议;可结合截图、URL与源码进行定位与修改。
-
bsamiee Bundle DocgenGenerates and validates project documentation: READMEs, ADRs, changelogs, ARCHITECTURE.md, and code documentation. Use when creating, updating, or reviewing any non-code markdown artifact, README file, architecture decision record, ARCHITECTURE document, CHANGELOG entry, or code documentation (docstrings, XML docs, TSDoc). Activates for: (1) scaffolding README, CHANGELOG, ADR, CONTRIBUTING, ARCHITECTURE, or SECURITY files; (2) writing or reviewing doc comments on exported APIs; (3) auditing documentation coverage or staleness; (4) generating release notes from commit history.
Audited -
bsamiee Bundle DockerfileGenerates and validates production-ready multi-stage Dockerfiles and .dockerignore files with BuildKit features, pnpm monorepo support, OCI labels, and security hardening. Use when creating, editing, reviewing, or validating Dockerfiles for Node.js, Python, Go, Java, or Rust.
-
bsamiee Bundle Sonarcloud ToolsExecutes SonarCloud API operations for quality gates, issues, metrics, analysis history, and security hotspots. Use when checking code quality, inspecting bugs/vulnerabilities, retrieving coverage/complexity metrics, or viewing project security status.
-
laststance Bundle CI HardeningPort the skills-desktop GitHub Actions hardening setup to another repo. Use when asked to harden CI, secure GitHub Actions, add CodeQL, Dependency Review, Scorecard, Dependabot, CODEOWNERS, pinned actions, least-privilege permissions, or branch/security settings.
Audited -
laststance Bundle UX Gap DetectorSaaS UX gap audit
-
laststance Bundle Codebase Litter AuditFind unfinished code litter
Audited -
kerberosclaw Bundle Repo ScanUse when the user wants to evaluate a GitHub repository before installing, running, forking, or depending on it. Takes a GitHub repo URL, cleans tracking params, shallow-clones to /tmp, inspects dependency/supply-chain risk, static vulnerability patterns, issue-reported security problems, maintainer health, and produces a risk summary. NOT for reviewing the user's own PR diff or for running untrusted code.
-
sahirvhora Skill Sf Rbp Permission AuditorUse when you need to detect over-permissioned roles, hidden access paths, and sod risks before audit season.
Audited -
sahirvhora Skill Sf Picklist RationalisationUse when audit picklist bloat -- find unused, duplicated, and overlapping picklist values across SF, then produce a safe consolidation plan.
Audited -
sahirvhora Skill Sf Time Tracking Rule AuditUse when you need to audit time valuation, holiday calendars, overtime logic, and payroll handoff risks.
Audited -
sahirvhora Skill Sf Compensation Eligibility AuditUse when you need to catch worksheet eligibility, proration, budget, and guideline logic before compensation planning opens.
Audited -
sahirvhora Skill Sf Recruiting Offer Approval AuditUse when you need to check rcm requisition templates, offer approvals, and handoff logic before hiring stalls.
Audited -
sahirvhora Skill Sf Position Jobinfo Alignment AuditUse when you need to find where position attributes and employee jobinfo have drifted apart.
Audited -
addxai Bundle Trufflehog CLIPerform local secret scanning, remote repository scanning, pre-commit integration, and single-credential verification using TruffleHog CLI. Triggers when the user mentions trufflehog, secret scan, leaked credential investigation, Git history scan, remote repo scan, pre-commit, or post-rotation credential verification.
Audited -
addxai Bundle Security Compliance ReviewPerform a structured security and compliance review using evidence from code/config/docs. Use for MR/PR review, architecture review, and periodic full scans. Detects secrets exposure, PII leakage, access control gaps, and compliance violations.
Audited -
lensetek Skill Startup Workflow OrchestratorThe Startup Workflow Orchestrator selects the right specialist agents, sequences handoffs, enforces security gates, and keeps startup delivery workflows aligned from strategy through launch.
-
lucastamoios Skill Docs AuditAudit a project's documentation (requirements, design specs, plans, index, glossary) for inconsistencies and produce a report with suggested fixes. For each finding, cross-checks Linear (source of truth), then the code (how the behavior is actually handled), then sibling docs that touch the same concept, to surface tensions you would otherwise only find at integration time. Never edits docs except `docs/glossary.md` when terminology is resolved. Trigger on explicit audit intent only ("audit the docs", "find contradictions", "are the docs consistent"); do **not** trigger on generic verbs like "check the docs" or "read the docs", which usually mean a lookup, not a consistency sweep.
-
lucastamoios Skill Docs PruneReduce a project's documentation to the minimum tokens needed for future agents to do their work. Finds duplicated content across files, obsolete files, dead cross-references, and verbose prose; proposes a numbered change plan (delete / merge / move / trim per file); applies it after the user approves. Operates on every file under docs/ including docs/map/. Trigger on explicit pruning intent ("simplify the docs", "shrink the docs", "dedupe the docs", "the docs are bloated"); do not trigger on lookups or on the existing docs-audit skill which only inspects.
-
lucastamoios Skill Code ReviewReview a PR or diff for bugs, logic errors, security issues, edge cases, test quality, and requirements alignment. It uses an agentic approach (dynamically investigate suspicious patterns) backed by a checklist for completeness. It loads project-specific learnings from codebase-learnings.json filtered by area tags.
-
matellez Skill Hubspot AuditAUTO-TRIGGER: Apply this skill when the user asks about auditing, cleaning up, reviewing, or improving their HubSpot instance. Trigger phrases include: "audit our HubSpot," "clean up HubSpot," "HubSpot is a mess," "inherited a HubSpot instance," "our workflows are broken," "deal stages don't make sense," "leads aren't routing correctly," "HubSpot hygiene," or any request to assess the health or structure of a HubSpot CRM. Also trigger when the user is starting a new role and mentions evaluating the existing HubSpot setup they inherited. Do NOT trigger for general HubSpot how-to questions or feature requests that are not about auditing an existing instance.
-
sharpdeveye Skill GuardUse when deploying to production, handling sensitive data, or the workflow needs safety constraints, input validation, and security boundaries.
-
sharpdeveye Skill DiagnoseUse when the user wants to find problems, audit workflow quality, or get a comprehensive health check on their AI workflow.
-
sharpdeveye Skill EvaluateUse when the user wants a quality review, interaction audit, or to test the workflow against realistic scenarios.
-
sharpdeveye Skill Zero DefectUse when you need maximum precision on a critical task — production deployments, security-sensitive code, financial calculations, or any work where mistakes are unacceptable.
-
sorawit-w Bundle Startup GrillAdversarially grill a startup IDEA or PITCH with a 5-seat panel of domain-aware probers (plus up to 3 domain specialists from team-composer), and ship a structured kill report ranked on two axes: severity (lethal vs material) and fixability (fixable vs unfixable). Use when the user says "grill my startup", "stress-test my pitch", "kill my idea", "pre-mortem my startup", "is this fundable", or uploads a one-pager / canvas / RAT plan / pitch deck for adversarial review. Use THIS, not `team-composer`, whenever the user wants an adversarial review with a verdict on a belief artifact, even if they say "review". CARVE-OUT: if the input is a BUILT product (a CODEBASE or live URL) that is `startup-audit`, even though they say "grill" or "kill". This skill reads BELIEF artifacts only (Lean Canvas, pitch deck, one-pager), never a codebase. Do NOT use for collaborative brainstorming, canvas construction, assumption-test design, or pitch-deck building (those route to the named constructive skills).
-
sorawit-w Bundle Skill EvaluatorAudit an existing SKILL.md for rule adherence — does the text actually land when Claude runs it? Use when the user wants a behavioral review of a shipped skill. Outputs: failure classification by fix layer (skill text / rubric / brief / fixture) and targeted rule-text diffs. Trigger ON: "audit this skill", "stress-test my skill", "does this skill actually work", "find gaps in this skill", "what's broken in this skill", "validate rule adherence", "review this skill end-to-end", or uploading a SKILL.md for behavior review. Do NOT trigger on: "build a skill", "create a skill from scratch", "benchmark this skill", "evaluate skill quality", "compare versions", "optimize trigger phrases", or "measure variance" — those are all `skill-creator`. If the request mixes both, start with `skill-creator` and chain here. Hard boundary: `skill-creator` builds, benchmarks, measures variance, and optimizes triggering; this skill does NONE of those — it asks "does the text land?".
Audited -
stanshy Skill Harness AuditPeriodic Harness health audit based on 7 design principles
-
thedecipherist Bundle Code ReviewReview changed code for correctness, security, and maintainability with cited, severity-ranked findings. Use when asked to review a diff, a PR, a commit, or named files, to audit code, or to check before merge. Runs isolated and read-only, reports findings, does not edit.
-
toverux Bundle Compound RefreshGarbage-collect the knowledge stores — audit AGENTS.md, and docs/solutions/ where that store is enabled, against the current code.
-
tryboy869 Skill Sbom ProvenanceProduire un SBOM et signer les artefacts de release. Use this skill whenever the user asks about sbom provenance in an open-source maintenance context — including phrasing like "générer un sbom", "signer une release", "prouver la provenance du build" — even if they don't name the skill directly.
-
tryboy869 Skill Scorecard BaselineUtiliser OpenSSF Scorecard comme check-list de sécurité objective. Use this skill whenever the user asks about scorecard baseline in an open-source maintenance context — including phrasing like "évaluer la sécurité du projet", "openssf scorecard", "auditer mes dépendances" — even if they don't name the skill directly.
-
tryboy869 Skill Security DependabotGérer les secrets et les dépendances avec Dependabot. Use this skill whenever the user asks about security dependabot in an open-source maintenance context — including phrasing like "auditer les dépendances", "configurer dependabot", "scanner les secrets" — even if they don't name the skill directly.
-
tryboy869 Skill Lone Maintainer RiskDétecter et réduire le risque structurel d'un projet critique porté par une seule personne. Use this skill whenever the user asks about lone maintainer risk in an open-source maintenance context — including phrasing like "risque mainteneur unique", "prévenir une attaque type xz", "bus factor du projet" — even if they don't name the skill directly.
-
wwwroot Skill Codex ReviewConducts senior-level peer code reviews, security vulnerability audits, concurrency and memory safety inspections, and architectural compliance checks. Generates timestamped code review walkthroughs in codex-drive/walkthroughs/.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include test-audit, aesthetic-audit, docgen. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.