Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
light0305 Bundle Light Memory PmLight 项目运行时记忆与项目管理常驻技能:把"项目做到哪/定了啥/出到哪版/术语怎么统一/上次断哪" 落到每个项目自己的 .light/ 目录(项目卡 + 决策日志 + 版本史 + 受控术语表 + 跨会话交接卡), 复用 passport.py 引擎管 DAG 台账(不重造)。它是 consistency 事实源的归属方,定义一改即变更广播 回扫所有材料;是总控"会话开头自动汇报上次断哪"的记忆底座。何时用:长期/跨会话项目、需记住背景/进展/ 版本/决策、会话开头续跑或接手、重要进展后立即落账、上下文将尽要交接、改术语/指标/创新点定义后。 触发词:记忆 / 项目管理 / 项目卡 / 决策日志 / 版本史 / 版本记录 / 续跑 / 接手 / 上次断哪 / 下一步 / 交接 / handoff / 启动提示词 / 术语表 / 变更广播 / 归档 / 台账 / .light / passport / 跨会话。 核心纪律:记忆落 .light/ 显式文件(非向量检索);相对日期转绝对;外部可变事实带 [snapshot]; 自洽用 pm.py audit 出 exit code(不口头说"记过了");不可逆决策(归档/教训回写)停下问用户。
Audited -
light0305 Bundle Light TypesettingBuild and preflight submission-ready LaTeX/PDF artifacts for Light stage 11. Use when receiving a paper-writing manuscript, figure delivery, citation delivery.json/references.bib/citekey-audit.json, or a venue/template profile; when selecting pdfLaTeX/XeLaTeX/LuaLaTeX and BibTeX/Biber; when diagnosing LaTeX errors or unresolved references; when checking page limits, double-blind identity, PDF metadata, template, page box, embedded fonts, TODOs, figures, tables, labels and citations; or when producing a reproducible compile manifest, PDF, compliance report, failure bundle and venue-matching handoff. Distinguishes PASS, manuscript ERROR, toolchain UNAVAILABLE and convergence UNRESOLVED without redoing citation authenticity or figure scientific QA.
Audited -
light0305 Bundle Light Project StructureAudit, plan, scaffold, and safely migrate research project structures across greenfield, existing Git/non-Git repositories, and monorepo subroots. Use for project folders, repository cleanup, source inventory, move maps, naming and storage policy, Python/R/mixed/LaTeX profiles, template provenance, conflict review, applied-move evidence, or rollback. Existing projects are read-only until the user authorizes exact action IDs bound to a plan digest. Preserve uncommitted and untracked work, symlinks, submodules, and memory-pm's .light content. This is an off-DAG local tool: do not emit findings or invent a STAGE_GATES/ROUTES connection.
Audited -
looker-open-source Skill Lookml Access GrantsUse this skill to create Access Grants for row-level or object-level security.
Audited -
ippollo Bundle Security AuditSystematic vulnerability hunting using multi-pass methodology with per-class reasoning chains and data flow tracing. Use when performing offensive security reviews, hunting for specific vulnerability classes, or auditing code for exploitable flaws. Covers web, API, mobile, and native application attack surfaces.
-
ippollo Bundle Security HardeningUse when performing security audits, implementing authentication/authorization, hardening an app for production, or reviewing code for OWASP Top 10 vulnerabilities. Covers CSP headers, auth strategy decision trees, and pre-deployment security checklists.
Audited -
ippollo Bundle API Design PatternsUse when designing or reviewing REST/GraphQL APIs, choosing versioning strategies, implementing rate limiting, or defining API security. Covers naming conventions, error envelopes, status codes, and OpenAPI specs.
Audited -
policyengine Bundle Review ProgramALWAYS LOAD THIS SKILL for PolicyEngine PR reviews, including when the user invokes $review-program or Codex /review on a PolicyEngine PR. Performs read-only code validation, source-reference checks, regulatory review, optional PDF audit, summary reporting, and optional GitHub comment posting.
Audited -
tbusos Bundle Gated Dual Clone AuditIndependent evaluator for gated-dual-clone topologies. Re-verifies the three safety gates on demand — structural (filesystem / hook / hardlink), configuration (git config inspection), behavioural (safe --dry-run tests). Ships with a human-readable summary + JSON verdict, run it as a git hook, a cron, or manually before a risky push. gated-dual-clone 拓扑的独立评估 器,按需重验三道安全检查。 TRIGGER: "audit dual clone", "verify gated dual clone", "check safety gates", "dual clone drift", "审计双仓库", "验证安全检查", "检查 gated dual clone". DO NOT TRIGGER: single-repo setups, pure git worktree layouts, general git-config auditing unrelated to gated-dual-clone.
Audited -
indykite Bundle Indykite Authzen Search SubjectList the subjects allowed to perform a given action on a resource via the IndyKite AuthZEN REST API (`POST /access/v1/search/subject`) - given a resource and an action, returns the matching subject instances of a type. Use to enumerate who has access - "who can provision gpu-node-7?", "list the people allowed to approve this document" (audit / reviewer views). Not for a specific-subject yes/no ("can grace provision gpu-node-7?" -> indykite-authzen-evaluation); to enumerate the other axes use indykite-authzen-search-action (which actions) or indykite-authzen-search-resource (which resources); to author the policy use indykite-authzen-kbac-policies.
Audited -
jelbirt Skill AuditSkill: audit
-
jelbirt Skill Audit FixImplement fixes for findings from the preceding /audit report, parallelizing via subagents grouped by non-overlapping file scope. Accepts optional severity/category filter.
-
jelbirt Skill Deps AuditProduce a unified, prioritized report on project dependencies across three dimensions - security vulnerabilities, version freshness, and unused or missing packages - by orchestrating npm/yarn/pnpm audit, outdated, and depcheck into one triaged action list. Use when the user wants a dependency audit, asks if packages are outdated, wants to check for vulnerabilities, wants to find unused dependencies, or wants a dependency health report - this goes beyond automated security-only alerts like GitHub Dependabot by also covering freshness and utilization.
-
kalyvask Skill Pm Progress AuditorAudit a status update, exec review, board email, all-hands talking point, or dashboard callout for credibility leaks before sending. Flags claims that overstate ("shipped" when 5 users are in beta), cherry-picked windows ("+15% w/w" off a holiday), vanity metrics used as validation, attribution claims with obvious uncontrolled counterfactuals, and "on track" forecasts without a threshold. Use when a PM is about to communicate progress upward and wants every claim pressure-tested. Built on the principle that goodwill is a finite budget — every overclaim debits the account, and once drained the real wins stop being believed.
-
roboflow Skill Review Topic Auth And Tenant SecurityLoad when a PR touches `http_api.py` auth middleware (`check_authorization_serverless` / `check_authorization`), `get_serverless_usage_check_async`, api-key→workspace resolution (`get_roboflow_workspace`), assume-identity (`_add_assume_identity_headers`, `x-assume-identity-*`), the unauthenticated-route allowlist, api-key redaction (`api_key_safe_raise_for_status`, `deduct_api_key`), usage api-key hashing, or new `*_SECRET`/`*_TOKEN`/`API_KEY` env vars in `env.py`.
-
steedos Skill Steedos Object FieldsSteedos field types and .field.yml configuration. TRIGGER: .field.yml files in objects/{name}/fields/; field types (text, number, currency, select, lookup, master_detail, formula, summary, file, image, location); field properties (required, default, index, searchable, filterable, visible_on, amis, group); lookup/relationship config, formulas, field UI with Amis schema. SKIP: object definition → steedos-objects; list columns → steedos-objects; field-level security → steedos-object-permissions.
-
subinium Skill ResearchParallel research, comparative audit, or capability transfer analysis on multiple topics, tools, repos, codebases, or frameworks with structured comparison, parity, or feature-harvesting output. Use when asked to research, compare, analyze, audit, extract capabilities, or transfer the best parts of one project into another
-
subinium Skill Memory CurateAudit and curate the per-project memory system at ~/.claude/projects/<encoded-cwd>/memory/ — finds duplicates, stale entries, missing-pointer files, oversized MEMORY.md, and entries that violate the user/feedback/project/reference taxonomy. Use when memory feels noisy, before /clear of a long-running project, or when memories stop influencing behavior.
-
subinium Bundle Security AuditRun a comprehensive security audit — OWASP Top 10, secrets detection, dependency vulnerabilities, injection vectors, auth checks
Audited -
cartodb Bundle Carto Manage PlatformAdminister the CARTO org — users, roles, quotas, activity audit, and bulk resource operations.
-
chenwei791129 Skill Spectra AuditAudit changed code for security sharp edges — dangerous defaults, type confusion, and silent failures
Audited -
chromedevtools Skill Devtools Unicode EscapingGuidelines for escaping strings and handling user-controlled data in DevTools to prevent layout bleed-through, XSS, and security issues.
Audited -
crtvrffnrt Bundle Pentest XssXSS assessment skill for reflected XSS, stored XSS, DOM XSS, blind XSS, CSP bypass, WAF bypass, source-to-sink analysis, browser context validation, safe payload design, and evidence collection.
-
crtvrffnrt Skill Pentest Business Logic AbuseBusiness logic and workflow abuse assessment for state-machine manipulation, race conditions, replay, quota abuse, order-of-operations flaws, delegated execution abuse, and unauthorized state transitions. Hands off to recon, input/protocol, exploit, or reporting workflows when those become the owner phase.
Audited -
crtvrffnrt Bundle Incident Response FileanalyserStatic malware reverse-engineering and threat-intelligence triage for unknown files, Windows EXE/PE binaries, scripts, archives, ISOs, JavaScript, PowerShell, documents, and unpacked payloads. Use when a user provides a sample path, hash, filename, or file and asks whether it is malicious, benign, suspicious, contains IoCs, or should be reverse engineered with Ghidra, strings, capa, YARA, public TI, and structured phase artifacts.
Audited -
crtvrffnrt Skill Pentest Input Protocol ManipulationInput validation and protocol manipulation assessment for injection, parser differential testing, request smuggling, method tampering, header confusion, serialization abuse, and payload mutation. Hands off to authz, business-logic, exploit, or reporting workflows when those become the owner phase.
Audited -
crtvrffnrt Skill Pentest Cve Vulnerability Research HelperCVE and vulnerability research skill for exact CVE lookup, product/version applicability, exploit maturity, KEV/PoC status, source ranking, contradiction handling, and non-destructive validation guidance.
-
crtvrffnrt Skill Pentest Exploit Execution Payload ControlDeterministic exploit execution and payload control from validated primitives. Use for exploit implementation, payload hardening, chaining confirmed weaknesses, post-exploitation proof, controlled impact demonstration, reliability notes, and rollback or containment planning.
Audited -
crtvrffnrt Skill Pentest Outbound Interaction Oob DetectionOutbound interaction and OOB validation for SSRF callbacks, blind XSS beacons, webhook abuse, XXE/OOB behavior, DNS/HTTP/HTTPS callback correlation, asynchronous server-side interaction proof, and egress validation.
-
crtvrffnrt Skill Pentest Authentication Authorization ReviewAuthentication and authorization security assessment for sessions, tokens, MFA, account takeover, IDOR, BOLA, BFLA, privilege escalation, tenant isolation, and identity boundary validation. Hands off to recon, input/protocol, access-control deep dive, exploit, or reporting workflows when those become the owner phase.
-
mickzijdel Skill Rails AuditUse when auditing, reviewing, or doing a health-check of an existing/inherited Rails app — onboarding to a legacy codebase, assessing technical debt, or a pre-engagement code review. Orchestrates the deep-dive rails-* skills and produces a severity-ranked report. Triggers on: code audit, app review, legacy/inherited Rails app, technical debt assessment, 'review my Rails app'.
-
mickzijdel Skill Rails SecurityUse when implementing authentication, authorization, or security features in Rails
-
mickzijdel Skill Rails Database PerformanceUse when reviewing or auditing a Rails app's database schema for missing indexes, slow query patterns, or database performance issues. Triggers on: schema review, slow queries, EXPLAIN ANALYZE output, missing index warnings, or any request to audit db/schema.rb.
-
mohganji Skill Find Critical BugsDeep bug hunt for high-severity correctness bugs — data loss, crashes, security holes, races, silent corruption. Use when asked to find critical bugs, audit an open PR/MR or the repo's current changes for severe regressions, or when running as a scheduled bug-hunt automation.
-
perminder-klair Bundle Subwave Log AnalysisAnalyse the SUB/WAVE radio station's unified event log (state/logs/events-*.jsonl) and give the operator a diagnostic report on how the station is behaving — Navidrome/ Subsonic API call patterns, the DJ picker's behaviour and music-library coverage, and runtime health anomalies. Use this skill whenever the user wants to understand or get feedback on what the radio is doing under the hood: how Navidrome calls are being made and how often, why the picker keeps choosing certain tracks or artists, whether the library pool is too narrow, whether traces are failing or running slow, or asks things like "analyse the subwave logs", "check the radio's behaviour", "what is the picker doing", "why does it keep playing the same artists", "is the station healthy", "how are the navidrome calls looking", "give me feedback on the event log". Trigger this skill even if the user does not name the log file or the script — any request to diagnose, audit, review, or get feedback on SUB/WAVE's runtime behaviour from its logs belon
-
qbs784 Skill Metabolizing KnowledgeUse when asked whether something delivered earlier still holds, when closing a milestone or running a periodic sweep over what was already marked verified, or when the set of live claims has grown too large to read and dead entries need retiring. DO NOT invoke to add, audit, or retire a decision record — route that to ledger:curating-decision-records. DO NOT invoke to propose removing code — route that to ledger:proving-code-is-dead.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include gated-dual-clone-audit, light-memory-pm, light-typesetting. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.