Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
wwwroot Bundle Codex Solidity Web3Principal Smart Contract Security Researcher & EVM Systems Architect. Master of Solidity 0.8.26+, Foundry invariant fuzzing, EVM gas optimization, reentrancy guards, ERC-4626/4337, Yul assembly, transient storage (EIP-1153), and formal verification.
-
xiaolai Skill Ecp ProposeCreate a formal EOU Change Proposal from a diagnosed failure or refactor option, capturing simulation, regression case, audit, and approval requirements per rule 92. <example> Context: $eou-diagnose has produced a diagnosis recommending a change. Owner wants to convert it into an actionable ECP. user: "$ecp-propose foundry/audits/incidents/inc-0042.diagnosis.yml" assistant: "I'll read the diagnosis, target_eou, and proposed change; draft an ECP under foundry/self-evolution/ecp/proposed/ with simulation, regression case, audit, and approval blocks. Status starts at proposed." </example> <example> Context: User wants an ECP for a refactor option produced by $eou-refactor. user: "$ecp-propose ./refactor-options/ro-split-audit-eou.yml" assistant: "I'll draft the ECP. If the target requires a constitution change, I'll stop and direct you to the constitutional ECP process instead." </example>
-
xiaolai Skill Eou SpecifyConvert an approved candidate (from a candidate set) into a formal EOU spec at lifecycle_stage draft, populating all six classification facets, context manifest, execution steps, stop conditions, validation, failure modes, blast radius, and responsibility. <example> Context: A candidate has been accepted in audit-candidate-eou-set; owner wants to draft the formal spec. user: "$eou-specify foundry/self-evolution/candidate-sets/cs-generate-eou-candidates-20260520-1430.yml#audit-step-coverage" assistant: "I'll resolve the candidate id, draft a complete EOU spec at lifecycle_stage draft under foundry/eous/, and never set lifecycle_stage active (that requires approved ECP and human owner)." </example> <example> Context: User wants to REPAIR an existing partial spec. user: "$eou-specify foundry/eous/audit-step-coverage.yml --mode repair" assistant: "In REPAIR mode I leave fields that already satisfy schema constraints alone and only fill empty or placeholder-containing fields." </example>
-
xiaolai Skill Eou DiagnoseDiagnose an EOU failure using the F-code taxonomy and recommend the smallest-blast-radius repair, producing either a diagnosis (path to $ecp-propose) or a no-change record. <example> Context: An incident has been filed; owner wants a structured diagnosis before deciding whether to open an ECP. user: "$eou-diagnose foundry/incidents/inc-0042.yml" assistant: "I'll classify the failure under one or more F-codes, rank repair options by blast radius, and emit either a diagnosis YAML (decision: change) or a no-change record under foundry/audits/incidents/." </example> <example> Context: User wants to diagnose from an audit finding rather than a full incident. user: "$eou-diagnose foundry/audits/eou-audits/eou-promote.audit.yml" assistant: "I'll diagnose the audit's findings; if evidence is insufficient for a change, I'll write a no-change record explicitly rather than silently doing nothing." </example>
-
xiaolai Skill Eou RefactorGenerate candidate EOU refactor options (split, merge, scope-reduction, authority-downgrade, step-extraction, validator-addition, stop-condition-injection, responsibility-separation) from an audit finding or incident. Produces options only; applying any option requires an ECP through $ecp-propose. <example> Context: An audit flagged that one EOU conflates two distinct judgments. Owner wants refactor options before opening an ECP. user: "$eou-refactor foundry/audits/eou-audits/audit-foundry.audit.yml" assistant: "I'll generate refactor options from the canonical patterns in foundry/refactoring-patterns.yml, weighing blast radius and constitutional fit, then write options under foundry/self-evolution/refactor-options/." </example> <example> Context: User asks for a specific refactor of an EOU with too-broad authority. user: "$eou-refactor eou-promote" assistant: "I'll generate options including authority-downgrade variants. None are applied; downstream $ecp-propose converts a chosen option into a proper change
-
xiaolai Skill Foundry AuditAudit the EOU Foundry as a whole — not individual EOUs, but the system: schema drift across rule/validator/skill/docs layers, self-approval risk, generation overreach, weakened validators, missing trace, orphan EOUs, stale active EOUs without ECP history. <example> Context: Owner wants a portfolio-level health check before a quarterly release. user: "$foundry-audit" assistant: "I'll audit the whole Foundry. Checks include schema/validator/skill consistency, no-self-approval enforcement across active EOUs, vocabulary drift in canonical functions, and lifecycle/evidence triangle compliance (trace gate, activation evidence, maturity claim vs evidence)." </example> <example> Context: User wants to find which active EOUs have no run traces or no-trace justifications. user: "$foundry-audit" assistant: "Among other checks, I'll surface every EOU at lifecycle_stage active that fails the ECP-0014 trace gate. Report goes to foundry/audits/foundry-audits/." </example>
-
xiaolai Skill Audit JudgmentAudit value_invocations in run traces for EOUs with classification.judgment_authorized:true. Verifies invocations against the captured_workflow's declared priority (no F15), checks for drift over multiple runs (no F16), detects hallucinated value ids (no F17), catches silent decisions on contested cases (F14), and runs counterfactual-swap audit as the V1 anti-theater defense. <example> Context: An EOU with judgment_authorized:true has accumulated several run traces with value_invocations. The owner wants to verify the invocations are load-bearing, not citation theater. user: "$audit-judgment compose-dish" assistant: "I'll load compose-dish.yml, its app's captured_workflow, and the run traces under foundry/runs/compose-dish/. I'll check each value_invocation entry against F14-F17, then run counterfactual-swap audit on up to 5 sampled invocations. Verdict report goes to foundry/audits/judgment-audits/compose-dish.judgment-audit.yml." </example> <example> Context: An EOU with judgment_authorized:false is passed
-
xiaolai Skill Audit Candidate Eou SetAudit a generated candidate EOU set for boundary quality, minimality, overlap, authority, operational value, and governance risk before any candidate advances to specification. <example> Context: A generation run has just produced a candidate set; the owner wants to know which candidates survive audit before promotion. user: "$audit-candidate-eou-set foundry/self-evolution/candidate-sets/cs-generate-eou-candidates-20260520-1430.yml" assistant: "I'll run the eight tests (boundary, non-overlap, minimality, authority, operational value, counter-generation, set composition, high-stakes) and write the audit report under foundry/audits/candidate-set-audits/." </example> <example> Context: User wants to audit a candidate set that contains a generating EOU without a corresponding audit path. user: "$audit-candidate-eou-set ./my-candidates.yml" assistant: "I'll audit. Heads-up that if any candidate has authority_level approve/publish or proposes weakening validators, I'll escalate to FAIL regardless of other test outc
-
xiaolai Skill Generate Regression CasesConvert incident reports and audit failures into candidate regression cases that prevent re-occurrence — each case captures a concrete observable symptom, the target EOU, the failure class (F-code), and an expected-behavior predicate. Cases are written as candidates; activation requires human owner approval. <example> Context: A diagnosis was filed for a path-drift incident; owner wants regression coverage so the failure cannot return silently. user: "$generate-regression-cases foundry/incidents/inc-0042.yml" assistant: "I'll extract the observable symptom, classify it under the F-code taxonomy, and write a regression case under foundry/self-evolution/regression/cases/. activation_status defaults to candidate." </example> <example> Context: User wants regression cases for a batch of audit findings. user: "$generate-regression-cases foundry/audits/eou-audits/*.audit.yml" assistant: "I'll iterate each finding, generate at most one regression case per observable symptom, and refuse to generate cases for findings
-
zapgun-ai Bundle Verify ConfigConfig doctor for clawback — loads the merged config (DEFAULTS < global < ./CLAWBACK.md < CLI overrides) exactly as the proxy's loadConfig does, prints a secret-free summary of the resolved values plus the merge-order sources, and exits non-zero if the canonical CLAWBACK.md did NOT take effect (host not 0.0.0.0, tls off, or adminToken missing) so a bad parse fails loudly instead of silently falling back to loopback defaults. Read-only; never prints the adminToken value, only its length. Use to confirm a CLAWBACK.md edit actually parsed and merged before starting the proxy, or to debug which config layer won.
Audited -
zarif3624 Bundle Handle ObjectionsDiagnose and prepare responses to B2B sales objections about price, priority, trust, competition, security, implementation, timing, procurement, or change. Use before or after a sales conversation when the goal is to understand the concern, answer honestly, and decide the right next step.
-
zarif3624 Bundle Design Sales ProcessDesign, audit, or revise a B2B sales process and its CRM operating rules. Use for lifecycle and opportunity stages, entry and exit criteria, qualification gates, handoffs, recycling and disqualification paths, required fields, stage governance, service expectations, conversion measurement, or rollout plans without importing generic benchmarks as company truth.
-
zarif3624 Bundle Create Mutual Action PlanCreate or revise a mutual action plan for a B2B buying process. Use when buyer and seller need shared milestones, owners, decision criteria, validation, security, legal, procurement, implementation, or target-date coordination without turning the plan into a seller-only closing checklist.
-
znlgis Skill Security ReviewAudit code changes for security vulnerabilities before merging. Use when reviewing a diff/PR, hardening code, or the task mentions security, injection, XSS, SSRF, secrets, auth, deserialization, path traversal, or "is this safe?". Reports findings; never auto-fixes silently.
-
nob-git-dev Bundle Security脅威モデリング、アクセス制御、シークレット管理、依存関係、入力検証、攻撃者視点の検証を行う。認証、権限、支払い、個人情報、ファイル受付、DB変更、外部API、本番影響のある変更で使う。
-
nob-git-dev Bundle Write From EvidenceWrite Japanese articles, reports, proposals, explanations, and decision documents from supplied evidence while preserving provenance and separating facts, interpretations, hypotheses, and proposals. Use when the user needs evidence-grounded writing, claim-to-source traceability, citation-aware drafting, conflict handling between sources, or an audit of whether a conclusion is supported; do not use it to silently fill missing information with plausible guesses.
-
uniclipboard Bundle Design Audit定期审计代码库的工程设计问题(高心智复杂度、单一真相源被破坏、catch-all 胖接口、死代码、散落魔法字面量、泄漏抽象、资源生命周期靠环形缓冲)与可优化点,范围限定为自上次审计以来的 git churn,每条发现都落到 file:line 并对照本项目自己的 VISION.md / 各级 AGENTS.md / memory 规则,明确区分「意外复杂度」(要修)与「本质复杂度」(不动)。维护去重台账,重复运行只报新增。Use when 用户要做设计审计 / 每周设计复盘 / 技术债扫描,或运行 $design-audit;不用于行级 bug review(用 $review-strict)或写功能。
-
wukongnotnull Bundle Product DesignUse when Product Design is explicitly invoked, or when the user's main goal is to explore a design, research UX, audit or critique a flow, faithfully clone a visual source, check a built design, or share a prototype. Do not use Product Design for ordinary implementation unless the user explicitly asks for it.
-
wukongnotnull Bundle Product Design Design QAInternal prototype QA helper. Use only after a Product Design prototype, URL-to-code build, or image-to-code build has a source visual target and a rendered implementation to compare before handoff. Do not use for broad UX critique, design critique, product audits, or flow reviews; route those user-facing requests to audit.
-
stunspot Bundle It Work Reviewer🔍 Evidence audit for device repair claims.
Audited -
stunspot Bundle Officecraft Reviewer🧪 Docs, decks, and sheets readiness audit.
-
driangle Skill AuditPerform a comprehensive codebase audit covering security, privacy, data integrity, architecture, and code quality. Use when the user wants to audit the codebase, check for security issues, or review code quality.
-
driangle Skill Test AuditReview the project's test suite for legitimacy: detect tautologies, trivially-passing assertions, mocked-away logic, and other patterns that give false confidence in test coverage. Use when the user wants to verify their tests are meaningful.
-
driangle Skill Triage DependabotTriage Dependabot security alerts: group by package, find high-payoff upgrades and removal candidates, then plan a fix for the one the user chooses.
-
efeumutaslan Bundle Sap MobileSAP Mobile development skill. Use when building apps with MDK (Mobile Development Kit), SAP BTP SDK for iOS/Android, configuring offline OData store, push notifications, or mobile security. If the user mentions SAP mobile app, MDK, Mobile Services, offline sync, or BTP SDK iOS/Android, use this skill.
Audited -
honerlaw Bundle ReviewReviews a changeset against both the minerva spec/knowledge lenses and code quality. With a work unit in context it runs a spec/knowledge audit alongside the code quality review, presenting both result sets before unified triage; if a GitHub PR exists for the branch it delegates code quality to `code-review:code-review`, otherwise it performs a check via a fresh-context subagent in the same finding format. Triage state persists to the scratchpad so re-runs pre-fill prior dispositions. Use when implementation on a work unit has just finished and the diff is unreviewed, when the user asks to review or audit a changeset or to verify shipped code matches what was designed, or when they invoke `minerva:review`.
-
howarewoo Bundle Woostack QAUse to explore a running web app in a real browser, reproduce confirmed bugs, and create sanitized, severity-ranked, non-authoritative diagnostic reports; use woostack-review for code diffs and woostack-audit for standing code. Report-only runs never mutate Linear, Plane, GitHub, or application source.
-
howarewoo Bundle Woostack InitInitialize or repair a repository's .woostack workspace, diagnostic stores, non-secret policy, and safe Linear defaults. Guarded legacy migration is optional.
Audited -
howarewoo Bundle Woostack AuditUse to audit standing code — an explicit file, directory, module, or whole repo at rest (not a diff) — from multiple angles, with optional exact verified read-only Linear, Plane, or GitHub context, code simplification, and production readiness. Synthesizes an all-added diff and drives woostack-review's swarm plus one evidence adjudicator, then writes a sanitized, non-authoritative diagnostic report under .woostack/audits/. Never mutates Linear, Plane, GitHub, or source, gates, posts, remediates, or merges. Invoke via /woostack-audit <target>.
Audited -
m1nga Bundle Product 5wInterrogate a product's definition with five questions, at any stage — idea, mid-build, or shipped — asking past behavior, never future opinion. WHO (by behavior not demographics; who it's NOT for; user vs buyer; first 10 users), WHAT job it does (and deliberately doesn't; do-nothing as first competitor), WHEN as context and trigger (struggling moment, frequency, tense-matched), HOW it gets used AND found (distribution is half of HOW; ultimate test: an offer), WHY it matters / why now / why you. Answers tagged verified/inferred/assumed; each W splits desk reasoning vs field proof; output: DEFINED/NARROW/REDEFINE verdict + validation debt, cheapest-next-verification list, named contradictions. Use for "run a 5W on this", "who is my product actually for", "survey my product before launch", 给我的产品做个调研 / 这个产品的 who what why 帮我过一遍 / 上线前做个基本盘调研 / 产品定义审计. NOT persona simulation (idea-probe), NOT architecture mapping (map-product-system), NOT hands-on audit (product-experience-officer), NOT technical feasibility.
-
m1nga Bundle Product Experience OfficerExperience a product-in-development as a zero-context first-time user, then report to the person who built it with a verdict, prioritized findings, concrete fix recommendations, and follow-ups. Covers comprehension, onboarding, core loop, interaction, visual design, copy, and emotion — everything a cold stranger would feel. Two modes — analyze screenshots the user provides, or run the product live (web, CLI/TUI, or native). Trigger on requests like "walk through my app as a first-time user", "does this onboarding make sense?", "UX audit these screenshots", "pretend you've never seen this and try it", "would a new user understand this?", or Chinese phrasings 体验一下 / 用户视角 / 从0经验的角度 / 体验官 / 帮我试试这个产品 / 看看新用户会怎么想 / 这个流程顺不顺(产品体验语境). Any "experience my product and give me feedback" request counts, screenshots included or not. NOT for debugging a specific error shown in a screenshot, code review, or fixing bugs — this skill evaluates the experience, it does not repair the build.
-
matis-dev Bundle Security ArchitectLoad when planning a feature that takes untrusted input or changes authorization, when writing an auth check, query, upload handler, or error path, when an advisory arrives, or when a review finding needs a fix. Models trust boundaries, hardens the sink as it is written, remediates with a regression test, triages by reachability. OWASP Top 10:2025.
-
matis-dev Bundle Maintenance ArchitectUse for dependency upgrades, security advisories, deprecations, lockfile hygiene, and the rot sweep (suppressions, skipped tests, dead code, stale docs). Triages by reachability, batches upgrades so a break is attributable, records deliberate non-upgrades in the profile. Never bundles an upgrade with a refactor.
-
matis-dev Bundle Documentation ArchitectLoad when writing, auditing, or repairing any doc a project ships — README, quick start, how-to, architecture record, API or CLI reference, docstrings, migration guide, release notes — or when a reader got stuck. Picks reader and doc type first, traces every identifier to a file actually read, and returns a friction log in audit mode.
-
matis-dev Bundle Search Optimization ArchitectUse for GEO, AEO, and AI-search work — an AI-visibility audit, retrieval-shaped content, llms.txt or schema decisions, crawl and rendering diagnosis, a citation dashboard. Sorts every tactic by evidence tier (load-bearing, plausible, theater), verifies against fetched bytes, measures with repeated runs. Never promises a ranking, citation, or lift.
-
nextstage-brasil Bundle Ns Reviewer(NS) Senior Tech Lead review: SOLID, clean code, performance, security, testability. `Approved` only at score 10; score 9 = `Rejected`. Use after code changes, before PRs, at implementation closure, or code/PR/issue review gate — even without naming this skill. GitLab `ISSUE_URL`: Issue review mode. Do NOT write code-review-report.md. Do NOT use for root-cause debugging (ns-investigator).
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include codex-solidity-web3, ecp-propose, eou-specify. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.