Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
nwiizo Skill Zap TriageTurn OWASP ZAP JSON reports into code-level remediation work for any authorized web application without launching unscoped scans.
-
nwiizo Skill Owasp AssessmentOWASP Assessment — 詳細仕様
-
agentera Skill Security Audit ReporterTriage raw security-scan findings (hardcoded secrets, injection patterns, vulnerable dependencies) into a prioritized, actionable security audit report. Use for security audit, code audit, vulnerability triage, and risk review.
-
agentera Skill Document Compliance AuditAudit a vendor agreement or contract: extract key clauses, check that required clause categories are present, flag compliance gaps and risks, and emit a structured audit summary. Use for compliance, contract review, audit, and vendor agreement requests.
Audited -
robinebers Bundle ValidationUse when Codex is already in the validation phase of a security scan or the user explicitly asks to determine whether one or more candidate security findings are valid. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
-
robinebers Bundle Attack Path AnalysisUse when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
-
aleksandr-litvinenko Skill Security And HardeningУкрепляет код против уязвимостей. Используй при работе с пользовательским вводом, аутентификацией, хранением данных или внешними интеграциями. Используй при создании любой функциональности, которая принимает недоверенные данные, управляет пользовательскими сессиями или взаимодействует со сторонними сервисами.
Audited -
anacatavc Skill Ami Audit QualityPerforms a deep code quality, security, and structure audit on modified files.
-
anacatavc Skill Ami Analyze DependenciesAnalyzes the project's libraries and dependencies. It checks for unused dependencies, outdated versions, security vulnerabilities, and generates a structured report of the project's dependency health.
-
chrike Skill Context EngineeringUse when the user explicitly asks to audit, pack, or configure the context for a task or project, or asks to investigate an observed context-specific quality problem such as invented APIs or ignored conventions. Do not use for ordinary source reading, new sessions, task switching, long conversations, generic uncertainty, reliability reassessment, handoff or compaction, planning, or ordinary implementation.
-
chrike Skill Shipping And LaunchUse when the user explicitly asks to assess readiness for a concrete production release, launch, rollout, or rollback plan, or when an active owner identifies a release-specific production evidence gap. Do not use for ordinary implementation, generic review or done claims, repository CI definition, telemetry design, performance or security analysis, UI or test work, deployment execution, or authority pressure without a defined release question.
-
chrike Skill Performance OptimizationRuns a narrow, framework-neutral performance experiment. Use only when the request states a concrete performance goal or metric, provides a measured baseline or regression, identifies a bottleneck, or explicitly requests a performance audit or experiment. Do not use for vague speed requests, unknown slow paths or regressions, test design, architecture trade-offs, live browser evidence, generic review, existing tools alone, or automatic profiling and tool setup.
Audited -
chrike Skill Observability And InstrumentationUse when the user explicitly asks to design, add, or audit persistent operational telemetry such as logs, metrics, traces, or alerts, or when an active owner identifies a concrete observability gap needed to answer an on-call question. Do not use for every production feature, ordinary logging, unknown active failures, measured performance work, generic review, launch readiness, or existing monitoring/tool availability alone.
-
goodsmileduck Bundle Onepassword SecretsInjects and audits 1Password secrets via the op CLI using op:// references, prefers op run/op inject over op read so values stay out of context, gates every op call behind an always-ask permission rule, and ships an opt-in deny-capable audit hook. Use when handling API keys, tokens, passwords, credentials, .env secrets, OP_SERVICE_ACCOUNT_TOKEN, or when the user mentions 1Password or the op CLI.
Audited -
thesmokedev Skill Geo ReportGenerate a professional, client-facing GEO report combining all audit results into a single deliverable with scores, findings, and prioritized actions
-
thesmokedev Skill Geo SchemaSchema.org structured data audit and generation for rich results and entity clarity — detect, validate, and generate JSON-LD markup. Schema is NOT an AI-citation lever (Ahrefs controlled study, May 2026); it earns rich results and keeps entity data unambiguous.
-
thesmokedev Skill Geo Report PDFGenerate a professional PDF report from GEO audit data using ReportLab. Creates a polished, client-ready PDF with score gauges, bar charts, platform readiness visualizations, color-coded tables, and prioritized action plans.
-
thesmokedev Skill Geo AI Index AccessIndex and access layer audit for AI search -- the hard prerequisites. Verifies Bing indexation (the ChatGPT entry ticket), audits robots.txt and CDN-level AI-crawler access, removes legacy nosnippet/max-snippet preview restrictions, and confirms key content is server-rendered. Use before any content-level GEO work, or when a site is invisible to ChatGPT despite good content.
-
thesmokedev Skill Geo Platform OptimizerPlatform-specific AI search optimization — audit and optimize for Google AI Overviews, ChatGPT, Perplexity, Gemini, and Bing Copilot individually
-
makisuo Bundle Maple AuditAudit an already-instrumented project against Maple's OpenTelemetry conventions, report gaps per service, and fix them. Triggers on requests like 'audit my instrumentation', 'check my telemetry', 'review my OTel setup', 'why is my service map missing edges', 'is my Maple instrumentation correct'.
-
makisuo Skill Maple Otel Spec ReviewReview a diff, PR, or specific file in this repo for OpenTelemetry *specification* compliance, grounded in the source-linked spec corpus at docs/otel-spec/ (snapshot v1.58.0). Triggers on requests like 'is this spec compliant', 'review this PR against the OTel spec', 'spec-review this diff', 'check my partial-success handling', 'are these retryable status codes right', 'does apps/ingest honor the OTLP spec', and on reviews of changes touching the OTLP server surface in apps/ingest (partial success, retryable set {429, 502, 503, 504}, protobuf Status bodies, gzip, OTLP/JSON encoding), self-instrumentation (apps/api tracer setup, apps/ingest/src/otel.rs, packages/effect-sdk), or consumers of span status / SeverityNumber / db.query.text (WarehouseQueryService, query-engine). Spec MUSTs and SHOULDs only — for Maple house conventions use maple-telemetry-conventions; for whole-project instrumentation audits use maple-audit; for general diff correctness use /code-review.
-
jal-co Bundle Security ViteReview Vite security audit patterns for SPA and dev server security. Use for auditing VITE_* exposure, build-time secrets, and proxy configs. Use proactively when reviewing Vite apps (vite.config.ts present). Examples: - user: "Audit Vite env vars" → check for secrets with VITE_ prefix - user: "Check Vite build config" → verify define block and source maps - user: "Review Vite dev server" → check host binding and proxy security - user: "Scan Vite bundles" → search dist/ for leaked API keys or secrets - user: "Audit Vite SPA auth" → verify server-side auth vs client route guards
-
jal-co Bundle Security ConvexReview Convex security audit patterns for authentication and authorization. Use for auditing query/mutation auth, row-level security, and validators. Use proactively when reviewing Convex apps (convex/ directory present). Examples: - user: "Audit these Convex mutations" → check for missing ctx.auth and input validators - user: "Check for IDOR in Convex queries" → verify ownership checks on document access - user: "Review Convex HTTP actions" → check for signature verification on webhooks - user: "Secure these Convex queries" → implement custom functions for enforced auth - user: "Check for data leaks in subscriptions" → verify filtered result sets
Audited -
jal-co Bundle Security ExpressReview Express.js security audit patterns for middleware and routes. Use for auditing Helmet.js, CORS, body-parser limits, and auth middleware. Use proactively when reviewing Express.js apps. Examples: - user: "Secure my Express app" → add Helmet.js and disable x-powered-by - user: "Check Express CORS config" → verify origin allowlists and credentials - user: "Review Express auth middleware" → check route order and coverage - user: "Scan for Express path traversal" → verify path normalization and validation - user: "Audit Express session config" → check secure, httpOnly, and sameSite flags
-
jal-co Bundle Security FastapiReview FastAPI security audit patterns for dependencies and middleware. Use for auditing auth dependencies, CORS configuration, and TrustedHost middleware. Use proactively when reviewing FastAPI apps. Examples: - user: "Audit FastAPI route security" → check for Depends() and Security() usage - user: "Check FastAPI CORS setup" → verify origins when allow_credentials=True - user: "Review FastAPI middleware" → check TrustedHost and HTTPSRedirect config - user: "Secure FastAPI API keys" → move from query params to header schemes - user: "Scan for FastAPI footguns" → check starlette integration and dependency order
-
m0rtalphe0nix Skill Claude Md ImproverAudit and improve CLAUDE.md project instructions. Use when the user asks to check, audit, update, improve, or maintain CLAUDE.md files or project memory.
-
theveller Skill Ship OssGeneral OSS-readiness pass for a repo before it goes public: sweep the full tree (not just README) for secrets and internal/personal references, verify LICENSE and .gitignore, run a fail-closed secret scan, delegate README polish to readme-commit, then flip GitHub visibility to public and push. Use when the user says "prepara este repo para open source", "hazlo público", "ship this as OSS", "publica este repo", "make this repo public", "ready this for GitHub", or "/ship-oss".
-
theveller Bundle Repo AuditAutonomous repo-wide audit (MANIFEST queue). Loops all pending units in one invocation without human checkpoints between units; generates HANDOFF when done. Coherence, broken symlinks, secrets, vault PARA, scripts, doc condensation. Writes to 06_Metadata/Reference/Repo-Audit/. Readonly except audit artifacts. Use with /repo-audit or repo-auditor subagent.
Audited -
blink-new Skill Linear DesignBuild and audit Linear/Vercel/Notion-quality UI. Covers color systems, motion, progressive disclosure, keyboard-first design, layout architecture, surface elevation, information density, micro-interactions, and state handling. Use when building UI components, reviewing design quality, creating pages, or when the user asks for a design review.
Audited -
cwijayasundara Bundle ReviewRun evaluator and security reviewer concurrently for comprehensive quality gate.
-
george-rd Bundle Deep ReviewHeavy review mode normally invoked by request-code-review for risky checkpoints, pre-submit stacks, OpenSpec/cflx acceptance, security-sensitive work, or explicit deep review, audit, or red-team requests.
Audited -
george-rd Bundle Swarm ImprovePlanner-led repo improvement loops with subagents, review gates, Mermaid DAGs, and workflow-aware commits. Use for improve, refactor, audit, or continue-loop requests.
Audited -
george-rd Skill RalphUse for spec-driven development loops, porting code between languages, migrating codebases, retrospective analysis, or autonomous build loops. Trigger phrases: "ralph loop", "spec-driven", "build feature", "port", "clone to", "migrate to", "translate to", "rewrite in", "convert from X to Y", "autonomous loop", "implementation plan", "JTBD", "retrospective", "retro", "post-mortem", "what went wrong", "audit the project", "improvement todo".
-
jimweller Skill Review DeepWhole-codebase deep audit launching parallel code reviews across OpenAI, Gemini, and Claude via opencode run.
Audited -
joshukraine Skill Update DepsDependabot-aware dependency updates with security audit, real-CI validation, and a unified PR. Framework-agnostic.
-
joshukraine Skill Readme RefreshAudit and update a project README, or bootstrap a new one. Detects tech stack, versions, and services.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include review, zap-triage, owasp-assessment. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.