Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
theonize Skill CriticAudit the reasoning of a compiled exegetical analysis — cross-section coherence, evidentiary proportion, exegetical fallacies, unstated counter-readings, and application groundedness. Use when a draft study needs its arguments tested before publication, or when checking whether conclusions are proportional to the evidence offered.
-
trk Skill Pw Module FilevalidatorUse when deploying discrete file validation architectures inside ProcessWire assessing security and normalization workflows via FileValidator.
-
vinvcn Skill Security And Hardening加固代码以防漏洞。用于处理用户输入、认证、数据存储或外部集成时;用于构建任何接受不可信数据、管理用户会话或与第三方服务交互的功能时。
-
syntropic137 Skill LoggingUse when reviewing logging concerns: structured-vs-unstructured logs, log-level policy, secret and PII redaction, correlation IDs in distributed systems, log/trace linkage, print statements in production code paths
-
syntropic137 Bundle DependenciesUse when reviewing dependency concerns: lockfile health, version pinning, immutable references, maintenance signals, transitive audit gates, monorepo version skew, reviewable lockfiles, license posture
Audited -
syntropic137 Skill EnvironmentsUse when reviewing environment concerns: dev/staging/prod parity, declarative environment manifests, build vs runtime separation, environment promotion path, secret-loader parity across environments, reproducible local setup, ephemeral / preview environments per PR with auto-teardown, data parity (shape-realistic seed and anonymized prod copies), mechanically enforced parity rules
-
syntropic137 Bundle ConfigurationUse when reviewing configuration concerns: env-var layering, typed config objects, startup validation, secret/non-secret separation, schema discoverability, environment-dependent defaults, twelve-factor compliance, magic numbers
Audited -
mono Bundle API DocsWrite AND review XML API documentation for SkiaSharp (ECMA/mdoc XML in the docs submodule). Two modes: (1) ADD docs for new APIs with "To be added." placeholders; (2) REVIEW existing docs by scope for accuracy, freshness, examples, and hygiene. Triggers: "document class", "add XML docs", "write XML documentation", "fill in missing docs", "remove To be added placeholders", "review documentation", "check docs for errors", "fix doc issues", "audit the docs", "review the font docs", "are the examples correct", "update out-of-date docs", any request to add, validate, correct, or expand SkiaSharp API documentation.
-
mono Bundle Review Skia UpdateReview a Skia upstream merge PR in mono/skia. Produces a security-auditable report by diffing against the upstream branch, verifying generated P/Invoke bindings, checking source integrity, and auditing DEPS changes. Triggers: "review skia update PR #NNN", "review skia PR", "review skia bump", "check skia update integrity".
Audited -
mono Bundle Native Dependency UpdateUpdate native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork. Handles security CVE fixes, bug fixes, and version bumps. Use when user asks to: - Bump/update a native dependency (libpng, zlib, expat, webp, etc.) - Fix a CVE or security vulnerability in a native library - Update Skia's DEPS file - Check what version of a dependency is currently used - Analyze breaking changes between dependency versions Triggers: "bump libpng", "update zlib", "fix CVE in expat", "update native deps", "what version of libpng", "check for breaking changes". For security audits (finding CVEs, checking PR coverage), use the `security-audit` skill instead.
Audited -
aipentest Skill Web Attack MethodsWeb全栈攻击:SQLi/命令注入/SSTI/XSS/SSRF/NoSQL,认证JWT/OAuth/SAML,LFI/上传,Tomcat/WS/STOMP/XFF/PATH_INFO/CDN502/网宿JS挑战绕过。Use when testing Web injection, auth bypass, server-side, WAF/CDN bypass.
-
aipentest Skill Binary Mobile ReversingAPK/EXE/二进制:UniApp/DCloud/Flutter逆向,证书固定绕过,导出组件,内存破坏exploit链,IoT固件。Use when reversing APK/EXE, UniApp/Flutter, native .so, or memory-corruption exploits.
-
akarachen Bundle Eric Python Quality Control ChecklistApply before committing Python changes. Check formatting, lint, types, relevant tests, and dependency or security risks when affected.
-
eho Bundle Feature DeliveryDeliver every user story in a revised design document through GitHub issue synchronization, single-story implementation and independent review, merge, and an overall feature audit. Use when asked to deliver, ship, resume, finish, or fully implement a complete design doc or multi-story feature.
Audited -
eho Skill Post Implementation ReviewerRun an independent, report-only overall audit of a delivered design document or multi-story feature. Verify story completion, assembled behavior, design alignment, documentation, and relevant tests, then report whether blocking findings remain.
-
kimasplund Skill Security Analysis SkillsComprehensive security analysis framework teaching STRIDE threat modeling, OWASP Top 10 vulnerabilities, CVSS risk scoring, and secure coding patterns. Use when conducting security assessments, code reviews, threat modeling, or implementing security controls. Applicable to all development work requiring security consideration.
Audited -
laurigates Skill Project HealthAudit project completeness against the monorepo standard checklist (docs, config, registration)
-
laurigates Skill Wifi Sta SetupApply or audit the canonical ESP-IDF WiFi STA configuration for a monorepo project
-
laurigates Skill Sdkconfig AuditAudit sdkconfig.defaults by inferring needed settings from source code analysis
-
majiayu000 Skill Sage Sandbox SecuritySage 沙箱安全开发指南,涵盖命令验证、路径策略、OS 级隔离、违规追踪
567 -
gabriel-f-santos Bundle Review PhaseReview a just-implemented phase/feature across functionality, security, and quality by fanning out three reviewers as subagents, scoped to the phase contract. Use after building something — "revisa a fase", "review phase X", "code review da feature", "revisa o que foi implementado", "revisão da phase-NN". Reads docs/phases/phase-NN-<slug>.md (acceptance criteria, deliverables) + the diff, runs review-functionality, review-security and review-quality (parallel subagents when available), de-dupes and prioritizes findings P0/P1/P2, prints a summary to screen and writes the full report to a gitignored artifacts path. Do not use for live UI/runtime smoke (use e2e-test-review) or to apply fixes (use simplify/refactor).
-
gabriel-f-santos Bundle Review QualityReview changed code for "crap" reduction — reuse, simplification, efficiency, dead code, duplication, naming, and altitude. Use to clean up what was just built — "reduz a gambiarra", "revisa qualidade do código", "tem duplicação/dead code?", "dá pra simplificar essa feature?". Reports findings only (does not apply fixes — use simplify/refactor for that), confidence-based, never security or correctness (those are review-security / review-functionality). Runs standalone or as a subagent of review-phase.
-
gabriel-f-santos Bundle Review SecuritySecurity review of changed code, scoped to a phase/feature diff. Use to find exploitable vulnerabilities in what was just built — "revisa segurança da fase", "tem vuln nessa feature?", "security review do diff", "checa injection/authz/IDOR". Reports HIGH-confidence, attacker-reachable issues only (injection, broken authZ / cross-tenant / IDOR, secret exposure, missing validation, SSRF, deserialization, crypto misuse) AND supply-chain gaps (unpinned deps / uncommitted lockfile / no cooldown). Read-only — reports, does not fix. Runs standalone or as a subagent of review-phase. Do not use for functional conformance (review-functionality) or style/cleanup (review-quality).
-
gabriel-f-santos Bundle Review FunctionalityReview implemented code for conformance to a phase/feature contract and for correctness bugs. Use to check that what was built actually meets its acceptance criteria — "revisa se a feature faz o que devia", "conformance review", "review against the spec", "achou bug na fase?". Reads the phase contract (acceptance criteria, deliverables) + the diff and reports, confidence-based, whether each criterion is met and any correctness defects (logic, edge cases, error paths, concurrency). Read-only — reports findings, does not fix. Designed to run standalone or as a subagent of review-phase. Do not use for security (review-security) or style/cleanup (review-quality).
-
sordi-ai Skill Code QualityApply when writing or refactoring code. Generic rules to prevent the most common review comments — function length, naming, error handling, security, and tooling.
Audited -
sordi-ai Skill Security ReviewApply when performing a security review, checking for vulnerabilities, or implementing authentication and authorization logic.
Audited -
tkoenig Skill Macos Software ManagementManage persistent macOS software installations with Homebrew Bundle, mise, Mac App Store, and fnox. Use whenever installing, removing, or provisioning a Mac app, CLI, runtime, developer tool, or secret-backed tool.
-
studio-moser Skill House RulesUse when a code change needs Studio Moser conventions for change classes, branches, file naming, commits, pull requests, testing, or pre-commit security checks.
-
studio-moser Skill AuditAudit existing screenshot captures for quality issues. Checks every PNG file in a directory for wrong-company content, blank sections, cookie banners, error pages, and other problems. Reports what needs recapturing. Use when screenshots look wrong or after a batch capture to verify quality. Invoke with /site-capture:audit.
-
wonderslife Skill QA ExpertThis skill should be used when establishing comprehensive QA testing processes for any software project. Use when creating test strategies, writing test cases following Google Testing Standards, executing test plans, tracking bugs with P0-P4 classification, calculating quality metrics, or generating progress reports. Includes autonomous execution capability via master prompts and complete documentation templates for third-party QA team handoffs. Implements OWASP security testing and achieves 90% coverage targets.
-
agentjido Skill Sync Docs To CodeAudit and reconcile repository docs with current code, examples, module docs, configuration, Mix aliases, telemetry, workflows, and public APIs. Use when docs may be stale after code changes or before release.
Audited -
eigent-ai Skill ReviewPerform a direct five-axis code review across correctness, security, performance, readability, and maintainability. Use when the user asks for `/review`, PR review, security review, pre-merge review, production readiness review, or blocking issue assessment.
-
ramp-public Bundle Ramp Spend AuditReview Ramp spend for possible duplicate software, fragmented vendor payments, unused funds, oversized limits, and recurring-spend controls. Use when a customer asks for a spend audit, savings opportunities, or safer recurring spending. This skill identifies opportunities; it does not cancel subscriptions or change vendor-side payment settings.
-
wangyendt Skill Pywayne Lark Custom BotFeishu/Lark Custom Bot API wrapper for sending messages via webhook. Use when users need to send text messages, images, rich text posts, interactive cards, or share chat content to Feishu/Lark channels. Supports image upload from files or OpenCV/numpy images, signature verification for security, and @mention functionality. Ideal for one-way notifications, alerts, scheduled tasks, and simple push scenarios without message listening or two-way interaction requirements.
-
elsa-workflows Skill Elsa Source Of Truth AuditAudit Elsa-brain source-of-truth placement. Use when docs, constitution text, glossary terms, reports, maps, skills, specs, or code may duplicate responsibilities; when thinning constitution material; or when deciding where new knowledge/workflow/rules should live.
-
bruno-cunha-souza Bundle CavemanTerse posture — drop articles/filler/pleasantries/hedging. Keep technical substance, code blocks, errors exact. Mirrors user's language; never announces itself. Not for onboarding, pedagogy, security warnings. Triggers: 'caveman mode', 'modo caveman', 'be terse', '/caveman lite|full|ultra'.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include wifi-sta-setup, sdkconfig-audit, project-health. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.