Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
kdoronin Skill Spec CheckAudit GWT acceptance test specs for implementation leakage. Optionally provide a specific file path.
-
kdoronin Skill Consistency CheckUse to validate DAE artifacts for schema correctness and cross-artifact consistency. Triggers — "engineer plugin -> consistency-check skill", "check consistency", "validate the artifacts", "are the specs and ACs in sync", "audit this feature".
-
markuplint Skill Bench XrefSync benchmark cross-reference blocks onto GitHub Issue bodies via `yarn bench:xref`, manage `tests/external/bench/issue-xref.config.ts` mappings, and run the pre-release checklist. Use when adding / removing / updating a primary or secondary mapping, when an issue closes upstream, when the xref CLI's output disagrees with what's on the issue body, or before cutting a release that touches a rule the benchmark covers. Trigger keywords: bench-xref, issue-xref, xref CLI, GitHub issue body, primary mapping, secondary mapping, umbrella block, pre-release checklist, bench-xref-audit workflow, marker version.
-
mirage-project Skill Dpskv3 Logistic ReviewAudit the DeepSeek V3 MPK demo + builder chain end-to-end and confirm logical equivalence with vLLM's reference implementation. Use after structural changes to `python/mirage/mpk/models/deepseek_v3/builder.py`, `demo/deepseek_v3/demo.py`, or any MLA / MoE / MTP task in `python/mirage/mpk/persistent_kernel.py`, `src/kernel/task_register.cc`, and `include/mirage/persistent_kernel/tasks/blackwell/mla_*.cuh` / `moe_*.cuh`. Produces a structured drift report so the change reviewer can confirm the math/topology is still equivalent.
-
somnio-software Bundle Security AuditExecute a comprehensive, framework-agnostic Security Audit. Detects project type at runtime and adapts security checks accordingly. Analyzes sensitive files, source code secrets, dependency vulnerabilities, and optionally uses Gemini AI for advanced analysis. Produces a severity-classified report. Use when the user asks to audit security, scan for vulnerabilities, check for secrets, or assess dependency risks. Triggers on: 'security audit', 'vulnerability scan', 'secret scan', 'dependency audit', 'security check', 'pentest', 'owasp'.
-
somnio-software Bundle Nestjs Best PracticesExecute a micro-level NestJS code quality audit. Validates code against live GitHub standards for testing, architecture, DTO validation, error handling, and code implementation. Produces a detailed violations report with prioritized action plan. Use when the user asks to check NestJS code quality, validate best practices, or review backend code standards. Triggers on: 'nestjs best practices', 'backend code quality', 'code review', 'nestjs standards', 'dto validation', 'error handling review'.
-
somnio-software Bundle Python Best PracticesExecute a micro-level Python code quality audit. Validates code against live GitHub standards for typing, code style, function design, data validation, error handling, module structure, and testing. Produces a detailed violations report with prioritized action plan. Use when the user asks to check Python code quality, validate best practices, or review Python code standards. Triggers on: 'python best practices', 'python code quality', 'code review', 'python standards', 'type hints review', 'pytest review', 'pydantic validation'.
-
somnio-software Bundle Flutter Best PracticesExecute a micro-level Flutter code quality audit. Validates code against live GitHub standards for testing, architecture, and code implementation. Produces a detailed violations report with prioritized action plan. Use when the user asks to check Flutter code quality, validate best practices, or review code standards compliance. Triggers on: 'flutter best practices', 'code quality', 'code review', 'flutter standards', 'architecture compliance', 'testing quality'.
-
thinkfleetai Skill PinProtect a critical MemMesh memory from consolidation/pruning by raising its importance and marking it high-impact — or unpin to release it. Use for architecture decisions, security constraints, or immutable team conventions that must never be retired by a `dream` pass.
-
tradeinsight-info Skill Competitive PositionThis skill should be used when the user asks about competitive advantages, market position, Porter's Five Forces, competitive landscape, market share, industry competition, barriers to entry, threat of substitutes, competitive analysis, or industry structure for a publicly traded company.
-
tumf Bundle Oss PublishOpen source publication and release hygiene for repositories and CLIs (language-agnostic): choose and add LICENSE, prepare README/CONTRIBUTING/SECURITY/CODE_OF_CONDUCT, standardize versioning/tags/releases and release notes, set up CI matrices, quality gates (pre-commit/pre-push), and safe-by-default automation/bootstrapping. Use when preparing a project to be published publicly (GitHub/GitLab), cutting a release, or standardizing repo tooling across languages.
-
tumf Bundle Unit Test HygieneAudit and reorganize an existing test suite to remove outdated tests, reduce duplication, and isolate external dependencies from unit tests. Use this skill whenever the user wants to clean up tests, find obsolete or redundant tests, detect unit tests that directly hit APIs/URLs/timers/commands/databases/filesystems/env state, improve mock boundaries, reduce flakiness, or clarify the boundary between unit and integration tests. Use it even if the user only says things like "整理したい", "モック化したい", "テストが遅い", or "古いテストを掃除したい".
-
turntuptechnologies-ai Skill Repo Publish SecurityGitHub リポジトリを公開するとき(public で新規作成 / private から切替)や、公開リポジトリのセキュリティ設定を点検するとき。「リポジトリを公開して」「public にして」「公開前にセキュリティ設定を確認して」等で使う。secret scanning・Dependabot・ブランチ保護 ruleset・Actions 権限を gh CLI で点検し、不足分をユーザー確認の上で適用する。private → public 切替時は公開前に履歴の秘密情報チェックも行う。
-
velt-js Bundle Velt Proxy Server Best PracticesVelt proxy server setup and configuration best practices for routing Velt SDK traffic through your own reverse proxy (nginx or Cloudflare Workers). Use when configuring proxyConfig on VeltProvider or initVelt, setting up nginx or Cloudflare Workers as a reverse proxy for Velt CDN/API/database/storage/auth endpoints, whitelisting Content Security Policy (CSP) domains for Velt, enabling Subresource Integrity (SRI), or debugging proxy-related connectivity issues. Triggers on any task involving Velt proxy, reverse proxy, proxyConfig, cdnHost, apiHost, v1DbHost, v2DbHost, storageHost, authHost, forceLongPolling, CSP whitelisting for Velt, nginx or Cloudflare Workers configuration for Velt, or network policy compliance with Velt — even if the user doesn't explicitly say 'proxy'.
-
vesely Bundle Supply Chain ProtectionOne-time setup of supply-chain protections for a project. Detects the package manager (npm, pnpm, Yarn, Bun), installs Socket Firewall (sfw), configures a 48-hour minimum package release age, and writes persistent dependency rules to CLAUDE.md. Use when the user mentions supply chain protection, dependency security, securing packages, malicious dependencies, typosquatting defense, "setup sfw", Socket Firewall, package release age, or wants to harden their project against compromised npm/pnpm/yarn/bun packages — even if they don't use these exact terms.
-
radustefandumitru Bundle Security ReviewUse for security reviews, vulnerability audits, hardening passes, auth/authz checks, injection/XSS/RCE/data exposure analysis, supply-chain risk, secrets handling, or "audit this for security issues" requests on agents without Claude Code's bundled /security-review. Prefer Claude Code's official /security-review when available. Report only concrete, high-confidence security findings; avoid generic best-practice noise.
-
rshade Bundle Security AuditComprehensive security audit covering OWASP Top 10, secrets detection, supply chain security, threat modeling, and language-specific vulnerability patterns. Investigates actual code paths rather than grep-matching keywords. Generates a scored SECURITY_AUDIT.md with prioritized remediation. Use when assessing application security, preparing for a security review, or onboarding to a codebase with security concerns.
-
rshade Bundle Go Nolint AuditAudit Go nolint directives for staleness and lazy justifications. Mechanically verifies each suppression with golangci-lint, then runs adversarial Red/Blue/White debates on the top candidates for removal. Use when inheriting a Go codebase, during periodic cleanup, or when nolint count is growing unchecked.
-
rshade Bundle Design PrinciplesAudit a codebase against well-known software design principles: SOLID, DRY, YAGNI, KISS, Law of Demeter, Separation of Concerns, Composition over Inheritance, and the code-relevant 12-Factor subset. Scores findings by impact and effort, runs adversarial debate on contested violations, and generates a prioritized DESIGN_AUDIT.md. Use when reviewing code quality beyond what linters catch, assessing design health before a refactor, or onboarding to an unfamiliar codebase. Can be invoked standalone or delegated from tech-debt.
-
saschb2b Bundle Comment StinkyDetect code-comment smells in any language, explain the cost of each, and propose the rewrite. Built against the failure mode where a comment narrates the edit that produced it (now, no longer, previously, instead of the old X) rather than the standing reason the code has its shape, because the reader only ever has the file, never the diff. Six pillars and 37 categories cover change narration and diff residue, redundancy (restating the code, signature echo, banner ceremony), missing intent (magic constants, workarounds, swallowed errors, unstated invariants), truth and decay (stale and lying comments, dead anchors), placement and form (a comment that wants to be a name, a test, or a doc comment, unowned TODOs), and voice. Ships a four-question write gate and a taxonomy of the nine comments worth writing. Apply implicitly whenever you write or edit a comment or docstring, and when asked to comment, document, audit, or clean up comments in a codebase, diff, file, or snippet. Defers prose register to no-slop.
-
shalintripathi Skill Onsite ProposeUse to turn audit findings or signals into concrete gated change proposals - "propose fixes for /pricing", /organic-os:propose.
-
shalintripathi Skill Hoo Monthly AuditUse for the monthly deep audit - "run the monthly audit", /organic-os:monthly-audit, or the scheduled monthly routine.
-
somnio-software Bundle Soc2 AuditExecute a comprehensive, framework-agnostic SOC 2 readiness audit of an entire repository or application. Detects project type and stack at runtime and adapts evidence gathering accordingly. Inspects the whole project for observable evidence of AICPA Trust Services Criteria controls (Common Criteria CC1-CC9 plus the optional Availability, Confidentiality, Processing Integrity, and Privacy categories), organized around eleven control families (A-K). For every control it records a Status (met / partial / gap / organizational) with concrete evidence and an ownership lane (platform-auditable / organizational / client-CUEC), scores readiness per control family, lists gaps mapped to criteria references, and produces a prioritized remediation plan with an overall readiness score /100 and a readiness band. Read-only and evidence-based: never invents controls; absent evidence is a Gap; secret values are always redacted. Use when the user asks for a SOC 2 audit, SOC 2 readiness assessment, Trust Services Criteria revie
-
somnio-software Bundle Harness AuditExecute a comprehensive, framework-agnostic AI Harness Audit. Scores how complete a project's AI coding harness is — CLAUDE.md, .claude/rules, settings.json permissions and hooks, commands/skills, custom agents, and the autotest-to-green-PR lifecycle — then returns a /100 score, a maturity band, and a prioritized action plan. Read-only: never modifies the audited repo. Use when the user asks to audit the AI harness, score their Claude setup, assess AI adoption maturity, or check how paved the quality path is. Triggers on: 'harness audit', 'ai harness', 'claude harness score', 'ai adoption audit', 'harness health'.
-
somnio-software Bundle Iso27001 AuditExecute a comprehensive, framework-agnostic ISO/IEC 27001:2022 readiness audit of an entire repository or application. Detects the stack at runtime and adapts evidence gathering accordingly. Inspects the whole project for evidence of an Information Security Management System (ISMS clauses 4-10) and Annex A controls (93 controls across 4 themes), organized into 11 auditable control categories. Records a Status and Owner/lane for every control, scores readiness per category, lists gaps mapped to Annex A references, and produces a prioritized remediation plan, a Statement of Applicability starter, and an ISMS clause coverage check - with an overall readiness score /100 and a readiness band. Read-only and evidence-based: never invents controls; absent evidence is marked a Gap. Use when the user asks to run an ISO 27001 readiness audit, an ISMS audit, an Annex A gap analysis, or an ISO compliance audit. Triggers on: 'iso 27001 audit', 'iso27001 readiness', 'isms audit', 'annex a gap analysis', 'iso compliance audi
-
dcouple Bundle Codex Security ScanRun or diagnose an authorized repository scan with the official Codex Security plugin, applying repository-specific scope and reporting policy when present. Use for explicit security scans, scheduled scan runs, or Codex Security preflight failures; not for ordinary code review.
-
educlopez Bundle Gitlab Project BootstrapSet up or audit GitLab project metadata hygiene (avatar, description, topics, badges, README) for Cinetic Digital's private client repos on gitlab.com. Use this whenever the user is starting a brand-new client project, asks to "configure" or "bootstrap" a GitLab project, wants project descriptions/tags/topics/badges set, mentions a project's README is missing/stock/hidden/needs improving, or asks what's missing / what should be set up on a GitLab repo. Also trigger when the user mentions a specific client project by name (e.g. a PrestaShop or Laravel repo) and asks about its GitLab page, its description, or wants it to "look proper." Works both for brand-new projects (apply everything from minute 1) and for auditing/fixing an existing one.
-
emaballarin Skill RoundDesign the next round of experiments — scope one goal, classify every hyperparameter as scientific, nuisance or fixed, build the studies, choose search spaces and a sampler, and allocate the trial budget. Use for `/tml:round`, "what experiment should I run next", "how do I test whether X helps", "design a sweep for this", "is this comparison fair", "set up a hyperparameter search", or after `/tml:plan`. Emits a self-contained study bundle under ./.tml/rounds/NNN/ — config matrix, launch stub and a return manifest — so trials can run on another machine and be analysed here. Read-first: never runs training and never edits project code. Do NOT use to interpret finished results (that is /tml:analyze) or to find opportunities (that is /tml:audit).
Audited -
first-fluke Skill Security AuditThis skill should be used when performing security audits on Cratos - command injection analysis, REST API authorization review, WebSocket authentication, tool security, and generating actionable fix plans.
-
wakqasahmed Bundle Open Code Review SetupSet up Alibaba Open Code Review (OCR) on a repository that lacks it, or audit and update an existing setup. Use when creating a new repository, onboarding an existing repo to automated AI code review, configuring `.opencodereview/rule.json` or the OCR GitHub Actions workflows, or when OCR reviews are not running on PRs.
-
counterpointconsulting Skill Security And HardeningApply baseline data security and integrity checks for schema and migration work.
Audited -
counterpointconsulting Skill Code Review And QualityPerform structured multi-axis code review before merge. Use for correctness, quality, security, performance, and test adequacy assessment.
Audited -
creanlab Bundle Repo AuditorAudit repo structure, memory health, compatibility, and security
-
creanlab Bundle Secret Leak RemediationStandard operating procedure for handling accidentally committed secrets.
-
creanlab Bundle Dependency Audit ResolutionResolving npm audit or Dependabot high/critical alerts.
-
hedera-dev Bundle Review Harness SpecAudit an existing hedera-harness recipe for wiring and evaluate-checklist problems before a run. Use when the user wants a harness recipe reviewed before running it.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include spec-check, consistency-check, bench-xref. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.