Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
hedera-dev Bundle Hedera Consensus ServiceHow to create topics, submit messages, and subscribe to real-time message streams on Hedera using the Hiero JavaScript SDK (@hiero-ledger/sdk). Use this skill whenever the user wants to work with Hedera Consensus Service (HCS), including topic creation, message submission, pub/sub messaging, mirror node subscriptions, chunked large messages, topic fees, or any consensus-related operation in JavaScript or TypeScript. Also trigger when users mention @hashgraph/sdk topic operations, event logging on Hedera, decentralized messaging, audit trails, or ordered message streams.
Audited -
wpultimatesecurity Bundle Security Auditing Code ReviewUse when auditing or code-reviewing an existing WordPress plugin or theme for security issues, triaging a vulnerability report, or hardening inherited code. Provides a systematic methodology — locate trust boundaries, inventory sensitive sinks, trace their controls and data flows, then triage confirmed issues and report with fixes. Apply proactively before shipping or when reviewing third-party code.
Audited -
wpultimatesecurity Bundle Authentication Session SecurityUse when code logs users in or out, sets or clears auth cookies, manages session tokens, throttles failed logins, or builds a custom login form in WordPress. Enforces wp_signon() and core session primitives over hand-rolled credential checks, adds brute-force throttling via the wp_authenticate_user filter keyed on username + IP, destroys sessions after password or role changes, makes login error messages uniform to stop user enumeration, and validates redirect_to with wp_safe_redirect() to close open redirects.
-
wpultimatesecurity Bundle Gutenberg Block Editor SecurityUse when building dynamic blocks or block-editor features - a render_callback, server-side rendered blocks via ServerSideRender, REST-backed block data, or register_rest_field for the editor. Sanitizes block attributes per type, escapes server render output, sets a real permission_callback on editor REST surfaces, and handles RichText content with wp_kses. Prevents stored XSS and broken access control in the editor.
-
wpultimatesecurity Bundle Dependency Supply Chain SecurityUse when a plugin or theme bundles a third-party PHP or JavaScript library, enqueues an asset from a CDN, fetches or executes code at runtime, manages dependencies with Composer, or prepares the distributable zip. Covers core-handle-first enqueuing, dependency vetting with composer audit, lockfile pinning, export-ignore artifact hygiene, Subresource Integrity for CDN assets via script_loader_tag, and refusal of eval() and remote include patterns. Prevents supply-chain compromise through stale, unvetted, or remotely loaded third-party code.
Audited -
yakoub-ai Bundle Phaser AnalyzeThis skill should be used when the user asks to "analyze my game", "review my Phaser project", "audit project health", "find bottlenecks", "refactor my game", "improve my code", "optimize my project", "what's wrong with my game", "code review Phaser", or "assess architecture".
Audited -
zakelfassi Skill Breaking Change AuditAudit shipctl's public interface before a release — compare flags, exit codes, and output formats against the previous tag to catch accidental breaking changes. Use when preparing a release, when asked to "check for breaking changes", or as a gate before tagging a new version.
-
zhuqingxun Skill Rpiv Loop Code Audit对指定目录/模块/skill 进行全量代码审计(不依赖 git diff)。支持逻辑、安全、性能、架构、集成与环境、可迁移性、必要性 7 个维度的审查,特别适合审计 skills 是否绑定 Claude Code、Codex、CodeAgent 或特定机器环境。
-
lftpadilla Skill SemgrepRun static analysis (SAST) over the codebase with semgrep to find real bug and security patterns — injection, auth gaps, secret handling, dangerous APIs. Use before a security-sensitive PR, on auth/payment/data-handling code, or when the user asks for a deterministic security scan.
-
razshy Bundle Cancel UnsubscribeCancel a subscription or unsubscribe from a service. Works from a description, a pasted charge line, a URL, or a photo/screenshot. Can also audit a full statement for recurring charges and cancel several at once. Finds the right contact method and handles the cancellation — including phone calls.
-
peterblazejewicz Skill Security And HardeningHardens .NET/C# code against vulnerabilities — input validation (FluentValidation), EF Core parameterization, ASP.NET Core Identity / JWT bearer / policy-based authz, Data Protection, antiforgery, user-secrets + Key Vault, `dotnet list package --vulnerable`. Use when handling user input, authentication, data storage, or external integrations in ASP.NET Core, Blazor, or Avalonia/MAUI apps that talk to an API.
Audited -
peterblazejewicz Skill Doubt Driven DevelopmentSubjects every non-trivial decision to a fresh-context adversarial review before it stands. Use when correctness matters more than speed, when working in unfamiliar code, when stakes are high (production, security-sensitive logic, irreversible operations like EF Core migrations or deploys), or any time a confident output would be cheaper to verify now than to debug later.
-
wrm3 Bundle Fstrent Code ReviewerComprehensive code review following company standards with focus on security, performance, maintainability, and best practices
-
impertio-studio Bundle Nextcloud Core SecurityUse when securing Nextcloud apps, configuring CSP, understanding the middleware chain, or implementing security patterns. Prevents missing security attributes on controllers, overly permissive CSP policies, and bypassing middleware chain. Covers controller security defaults, middleware chain architecture, Content Security Policy configuration, security attributes overview, and encryption interfaces. Keywords: CSRF, CSP, middleware, #[NoCSRFRequired], #[NoAdminRequired], #[PublicPage], ContentSecurityPolicy, CSRF error, security headers, middleware, access control, public page, admin only..
-
impertio-studio Bundle Nextcloud Syntax ControllersUse when creating controllers, defining routes, handling requests, or implementing API endpoints. Prevents missing security attributes, incorrect route definitions, and wrong response type usage. Covers Controller and OCSController types, routes.php definition, attribute-based routing, parameter extraction, security attributes, response types, and format negotiation. Keywords: Controller, OCSController, routes.php, #[ApiRoute], JSONResponse, DataResponse, parameter extraction, create endpoint, route setup, API response, handle request, JSON response, URL routing..
-
italink Skill Unreal Large Blueprint AnalysisSystematically analyze and translate large UE Blueprints (10+ functions) into C++ or other targets. Use when the user asks to convert a Blueprint to C++, audit a complex Blueprint, or understand a large Blueprint's full logic.
-
junerdd Bundle Hack ReviewPerform a scoped, coverage-led review of a working tree, staged diff, commit range, branch diff, PR, or suspicious implementation to find hack-like implementation risks. Use when Codex must audit brittle shortcuts such as impossible-state fallbacks, masked root causes, duplicate abstractions, hardcoded special cases, boundary bypasses, hidden temporal coupling, write-then-fix-up flows, or other ownership problems, and must write a Markdown report that enumerates all distinct hack-risk findings discovered within the reviewed scope plus coverage gaps and intentional exceptions.
-
junerdd Bundle Thermo ReviewPerform an extremely strict, report-writing code quality review focused on structural simplification, responsibility concentration, abstraction quality, file-size pressure, spaghetti branching, canonical ownership, type boundaries, and exhaustive recursive candidate sweeps. Use for thermo-nuclear code quality review, thermonuclear review, harsh maintainability review, deep code quality audit, structural quality gate, or when asked whether a change is too complex or should be restructured. Writes a Markdown report and does not make code changes unless explicitly asked for fixes.
-
junerdd Bundle Regression ReviewPerform a scoped, coverage-led review of working tree, staged, commit-range, branch, or PR changes to find user-visible behavioral regressions. Use when Codex must audit code changes for broken or degraded user journeys, changed defaults, loading/error/permission/session behavior, stale data, ordering, retries, duplicate/destructive actions, exported output, emails, CLI output, or other visible behavior, and must write a Markdown report that enumerates all distinct findings discovered within the reviewed scope plus coverage gaps, intentional visible changes, and scoped behavior-graph deltas when they clarify the affected path.
-
junerdd Bundle Reduce ReinventionIdentify, prevent, and remediate 重复造轮子 across code, libraries, services, templates, docs, platform workflows, and architecture decisions. Use when asked to audit duplicated implementations, search for existing reusable assets before building, decide build-vs-reuse/buy, consolidate similar components/tools/APIs, create reuse catalogs, write ADR/RFC/migration plans, establish golden paths/paved roads, or improve discoverability, ownership, and governance for reusable assets.
Audited -
mariusgithub13 Skill Citation CheckerAudit any summary or brief claim-by-claim against its source document, what's supported, what's overstated, what can't be found at all, and any number that differs. Use after any brief is produced (including from these agents), or when asked to 'check the citations', 'verify this summary against the source', or 'did the AI make this up'.
-
masashifukuzawa Skill AdrArchitecture Decision Record を起票・更新し、設計判断と既存記録の整合性を保つ。複数案から技術選定した時に使う。軽微な変更やコードベース全体の監査には使わない。「ADRにして」「この決定を記録して」を正のトリガーとし、コードベース全体の設計課題探索には codebase-audit を使う。
-
masashifukuzawa Bundle Codebase Auditコードベース全体を横断監査し、重大度・根拠ファイル・改善案を構造化する。技術負債や設計課題の包括的な洗い出しに使う。単一ファイルや PR のレビューには使わない。「技術負債を洗い出して」「横断的にレビュー」を正のトリガーとし、特定差分のセカンドオピニオンには codex-review / claude-review を使う。
-
masashifukuzawa Bundle AI Native Engineering設計・実装計画・スコープ・技術選択・工数見積もりを、AIが主実装者として継続・並列稼働する前提で判断する。「実装計画を作って」「MVPのスコープを決めたい」「まず簡易版で始めてよいか」「どれくらいで実装できる」「この構成はoverengineeringか」「将来の拡張をどこまで考慮する」を正のトリガーとし、非自明なarchitecture・security・コアUX設計と基盤選定では原則として使う。人間の工数感による妥協と、需要や脅威を確認しない機構追加を両方補正する。仕様と手段が確定した単純修正には使わない。
-
beclab Skill Ha SystemInspect Home Assistant system health, repair issues, error logs, logbook, and state history with hass-cli. Use to diagnose problems, check integration health, find open repairs, read recent errors, or gather the raw native data that audits (dead entities, broken automations) are derived from. Complexity scoring/audit are NOT native HA features; compute them here from native data.
-
beclab Skill Ha RegistryManage Home Assistant areas, devices, entities, floors, and labels with hass-cli. Use to list/create/rename/delete areas, assign devices or entities to areas, organize with floors and labels, rename entity_ids, or audit the registry. These are WebSocket-only operations (config/*_registry/*).
-
beclab Skill Ha StatisticsQuery Home Assistant's recorder long-term statistics with hass-cli: list which statistic ids exist, read their metadata (unit, source, has_sum/has_mean), and pull aggregated values (sum/mean/min/max) over a time period and bucket. Use for 'how much energy/water/gas over time', 'trend of this sensor', 'monthly totals', or as the data source for consumption/audit analyses. Distinct from instantaneous state history.
-
beclab Skill Ha Workflow AuditPlaybook for auditing a Home Assistant instance for tech debt with hass-cli: dead/unavailable entities, duplicate entities, broken automations referencing missing entities, and unused automations. Use when the user asks to 'clean up', 'find broken/unused automations', 'find dead entities', or 'audit my setup'. These are derived analyses (not native HA features) computed from native data.
-
benoror Skill Vault HealthAudit the vault for structural issues: unresolved wikilinks, orphan notes, dead-end notes, and Obsidian sync conflicts. Optional --fix flags create stubs or surface fixable issues.
Audited -
carinyadigital Bundle Docs ReviewUse when the user wants a set of documents reviewed — a docs folder, a wiki, a handbook, a repo's markdown, or any collection of written material. Checks that each document is well written and well structured, that boundaries between documents are clear with no duplication, and that the set is consistent and cohesive. Triggers on "review the docs", "are these docs any good", "is our documentation consistent", "do these docs overlap", "audit the documentation". Works on any doc set in any format or tool. Read-only: produces a report and changes nothing. Do NOT use to write or amend a document, to review code (code-review), or to review rendered UI (ux-design-review).
-
cnife Bundle Arch Wsl CleanupFree up disk space on Arch Linux WSL through layered cleanup: cache purge, orphan removal, package audit, and large file scanning. Use whenever the user mentions disk space, cleanup, storage, package review, or wants to shrink their WSL footprint — even if they just say "空间不够", "磁盘满了", "WSL 太大了", or "clean up my system". Prefer this skill over ad-hoc cleanup commands on Arch WSL.
Audited -
daehounan Skill Compliance Audit RoutingTwo niche audit specialists not covered by existing operations/finance/ecc skills — smart contract security audit (Solidity / EVM / DeFi) and business automation governance (n8n workflow auditing). Use when the user asks about smart contract audit, reentrancy / oracle manipulation / gas optimization in DeFi, or evaluating and governing n8n / Zapier / business automation workflows at scale. For SOC 2 / ISO 27001 / HIPAA / PCI-DSS / SOX, prefer existing skills. Triggers on smart contract audit, blockchain audit, gas optimization audit, DeFi audit, reentrancy, oracle manipulation, n8n governance, workflow audit, automation governance.
-
agent-kit-startup Skill Security ReviewSecurity Review skill.
-
agent-kit-startup Skill Cursor Skills PHPCURSOR-SKILLS rules for PHP (Laravel, Symfony, WordPress). PSR, Composer, security.
-
matrixfounder Bundle Skill ValidatorUse when auditing a new or existing skill for security vulnerabilities, malware (bash scripts), and structural compliance.
Audited -
eugenezhangco-spec Skill Security ReviewUse this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include hedera-consensus-service, security-auditing-code-review, authentication-session-security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.