Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
bruno-cunha-souza Bundle Only PlanRead-only planning: analyze and design without changing project files. Writes one step-by-step plan at project root (default IMPLEMENTATION_PLAN.md). Composable with other skills (e.g. /code-security-review /only-plan). Triggers: /only-plan, 'only plan', 'apenas planejar', 'não altere os arquivos'.
-
bruno-cunha-souza Bundle Code ReviewLifecycle code review Go/Rust/TS/Python. Auto-detects toolchain, runs static analysis, emits severity-ranked findings + file:line evidence, diffs, risk tags (SAFE/REVIEW/BREAKING). Covers OWASP Top 10, perf anti-patterns, test quality. Read-only — every finding cites file:line. Triggers: 'review code', 'revisar código', 'auditar código', '/code-review'.
-
bruno-cunha-souza Skill Ponytail ReviewOver-engineering review — finds what to DELETE, not what to fix. One line per finding with tags delete/stdlib/native/yagni/shrink and a net-lines score. Three scopes: current diff (default), whole repo ('repo'/'audit'), or 'debt' to harvest ponytail: comments into a ledger. Complements correctness review (@code-review, @github-pr-review) — this lens only hunts complexity. Use when the user says 'review for over-engineering', 'what can we delete', 'is this over-engineered', 'find bloat', 'audit for bloat', 'ponytail debt', 'list the shortcuts', '/ponytail-review'. One-shot report; applies nothing.
-
bruno-cunha-souza Bundle Github Pr ReviewStructured GitHub PR review — correctness, security, performance, maintainability. Severity-ranked findings + verdict (Approve/Request Changes/Comment). Non-PR: @code-review. Triggers: 'review PR', 'revisar PR', 'analisar pull request', '/github-pr-review'.
-
bruno-cunha-souza Bundle Code OptimizationLifecycle perf audit Go/Rust/TS/Python. N+1/leak/duplication sweeps, tri-axis Impact×Risk×Effort, writes OPTIMIZATION_REPORT.md. Read-only — file:line evidence. Triggers: 'optimize code', 'otimizar código', 'auditar performance', 'find bottlenecks', '/code-optimization'.
Audited -
gridlock-nyc Bundle Code EdgesAudit a project for edge cases, error-prone code paths, and unhandled failure modes. Researches the codebase, identifies the highest-risk areas, enumerates specific edge cases from a comprehensive catalog, writes and runs tests to prove them, then produces a prioritized risk report. Use when user says 'edge audit', 'find edge cases', 'what could break', 'edge case review', 'audit for edge cases', 'stress test this code', 'what am I missing', 'failure modes', 'where will this break', 'robustness check', or 'error path audit'. Do NOT use for security scanning or dead code detection (use code-security for that). Do NOT use for code quality review of specific PRs (use code-review for that). Do NOT use for running existing test suites (use code-preflight for that).
-
gridlock-nyc Skill PostmortemStructured incident and bug analysis — timeline reconstruction, root cause identification, contributing factors, and prevention. Use when user says 'postmortem', 'what went wrong', 'why did this break', 'incident review', 'root cause analysis', 'RCA', 'failure analysis', 'what happened'. Do NOT use for session-level audits (use session-audit). Do NOT use for code quality review (use simplify).
-
gridlock-nyc Bundle Skill EvalBenchmark how closely a skill followed its own instructions. Reads the skill's SKILL.md, extracts verifiable requirements, scores the skill's output from the current session. Returns compliance % with per-requirement pass/fail and cited evidence for every miss. Use when user says 'skill eval', 'did that skill work', 'how well did it follow instructions', 'benchmark skill', 'skill compliance', 'grade that skill', 'skill score', 'evaluate skill', 'skill audit', 'test skill'. Do NOT use for session-level audits (use session-audit for that). Do NOT use for building skills (use skill-builder for that). Do NOT use for behavioral evals of project code (use eval for that).
Audited -
gridlock-nyc Skill Code ReviewStaged code review — runs tests, extracts intent, dispatches 3 specialist agents (state-enumeration bug detection, project rule compliance, history + regression detection), then verifies findings with type-stratified confidence thresholds. Works on git diff (pre-commit) or PR diff. Use when user says 'code review', 'review this code', 'review changed code', 'review for regressions', 'check for bugs', 'is this good code', 'review what I just wrote'. Do NOT use for plan review (use /plan-review). Do NOT use for security/dead code scanning (use /code-security). Do NOT use for edge case auditing (use /code-edges). Do NOT use for pre-refactor impact analysis (use /code-blast-radius). Do NOT use for style cleanup or simplification (use /code-review).
-
gridlock-nyc Bundle Plan ReviewReviews plans from plan mode for real problems, then fixes them. Catches breaking bugs, security holes, over-engineering, and missing steps — but only when grounded in specific evidence. Returns CLEAN when a plan has no issues. Use when user says 'review this plan', 'check my plan', 'plan review', 'is this plan good', 'critique this plan', 'sanity check', 'poke holes in this', 'review my approach', or 'is this a bad idea'. Do NOT use for code review of written code (use simplify). Do NOT use for incident investigation (use postmortem). Do NOT use for generating alternative approaches (use directions).
-
gridlock-nyc Skill Code SecurityScan the current project for security issues, dead code, deprecated patterns, forgotten debug code, secrets in config, and hidden oddities. Use when user says 'scan for issues', 'find security problems', 'codebase audit', 'treasures', 'what's wrong with this codebase', 'find dead code', or 'security scan'. Do NOT use for code review of specific PRs (use review for that). Do NOT use for refactoring suggestions (use code-review for that).
-
gridlock-nyc Skill Session AuditFix the system after a session — edit CLAUDE.md rules, rewrite confusing docs, propose hooks, delete misleading instructions, save memories. The output is changes, not a report. Use when user says 'audit', 'session audit', 'what went wrong', 'debrief', 'fix the system', 'why does this keep happening', 'session review'. Do NOT use for code review (use code-review) or production incidents (use postmortem).
Audited -
gridlock-nyc Skill Session DriftDetect scope drift in the current session. Compares all changes made against the original stated goal, flags tangential work, and identifies unfinished parts of the original task. Use when user says 'drift', 'am I on track', 'scope check', 'what was I doing', 'did I drift', 'focus check', or 'are we still on target'. Do NOT use for session auditing (use session-audit for that). Do NOT use for code review (use code-review for that).
-
gridlock-nyc Skill Code Blast RadiusMaps all callers, importers, and dependents of a target function, class, module, or file before a refactor begins. Scores blast radius as low/medium/high and flags high-risk downstream effects so nothing breaks silently. Trigger phrases: "blast radius", "who calls this", "what depends on", "safe to rename", "safe to move", "what imports this", "refactor radar", "dependency map", "what breaks if I change", "callers of", "dependents of", "impact analysis before refactor", "check before refactoring". Do NOT use for: general code search, finding bugs, reviewing pull requests, auditing security, checking for dead code (use /code-security), detecting scope creep (use /session-drift), evaluating architecture options (use /plan-directions), or any task that is not specifically about pre-refactor impact analysis.
-
impertio-studio Bundle Vite Agents ReviewUse when reviewing Vite configuration, validating a Vite project, checking for common mistakes, or auditing Vite code before deployment. Prevents shipping insecure envPrefix settings, wrong bundler options for the target version, and known anti-patterns. Covers config correctness, plugin hook signatures, HMR patterns, version-specific API usage, build optimization, environment variable security, SSR configuration, and anti-pattern detection. Keywords: review, validation, checklist, audit, anti-pattern, envPrefix, plugin hooks, security, SSR, build optimization, check my Vite config, is my setup correct, verify Vite project.
-
masriyan Bundle Purple Team Adversary EmulationCollaborative purple-team operations — threat-informed adversary emulation planning (ATT&CK, CTID, Atomic Red Team, CALDERA), the detect-tune-validate loop, detection coverage measurement (DeTT&CT/Navigator), safe execution and deconfliction, and MTTD/coverage reporting
Audited -
ryanthedev Bundle Aposd Verifying CorrectnessVerifies implementation completeness across functional correctness, error handling, concurrency, and security dimensions using APOSD's post-implementation checklist. Run after a coding task is nominally complete, not during active bug investigation (use cc-debugging).
-
agentscope-ai Skill Dingtalk Channel Connect使用可视浏览器自动完成 QwenPaw 的钉钉频道接入。适用于用户提到钉钉、DingTalk、开发者后台、Client ID、Client Secret、机器人、Stream 模式、绑定或配置 channel 的场景;支持遇到登录页时暂停,等待用户登录后继续。
-
scoobydont-666 Bundle Code QualityDeep code quality analysis: performance (Big-O, hot paths, resource management), security (injection, secrets, auth, input validation), testability (coverage gaps, untestable design, DI), architecture (SOLID, coupling, abstraction leaks, layering). Language-agnostic with language-specific patterns from references. Trigger on: "code quality", "performance audit", "security review", "OWASP", "SOLID", "coupling", "testability", "technical debt", "code smell", "architecture review", "Big-O", "complexity analysis", "hot path", "memory leak", "injection", "vulnerability", "dependency injection", "clean architecture", "is this code good", or "can this be better". Also triggers on escalation from code-consistency quality triage.
-
scoobydont-666 Skill Skill UpdaterSelf-assessment and auto-update for Claude Code's installed skills, CLAUDE.md files, and reference data. Audits for staleness, gaps, overlaps, and freshness. Triggers on: "update your skills", "skill audit", "skill assessment", "refresh skills", "are your skills up to date", "check your skills", "review your context", "tune yourself up", "make yourself better".
-
scoobydont-666 Skill Config AuditorCross-reference all CLAUDE.md files, memory files, skill descriptions, and project registries for contradictions, stale data, and inconsistencies. Trigger on "check for contradictions", "audit configs", "config consistency", "are my configs consistent", or any request to verify configuration coherence across Project Swarm.
Audited -
memorysaver Bundle Aep CalibrateTurns a human's subjective judgment into criteria agents can apply. Use for a works-vs-right gap, a .5 layer, or "calibrate" — not a usability audit.
-
r3bl-org Bundle Check Test CoverageAudit and verify test coverage for a specific file or module, ensuring all custom logic branches, state transitions, and boundary conditions are covered while strictly eliminating dependency test bloat (never testing std, third-party crates, or macro-derived boilerplate). Use via /check-test-coverage <filename>.
-
phoenixrr2113 Skill ReviewerReviews a diff or change set for bugs, security issues, test gaps, and style. Use when evaluating a code change, reviewing a pull request, or running a structured review pass before merge.
-
suraj787 Skill Security AssuranceUse when a dependency, snippet, or external source enters the project and needs licence, supply-chain, and untrusted-code review before it is adopted.
-
vibeengineering-llc Bundle CensorРОЛЬ «Цензор» (постоянная): проектирование доктрины и новых контуров, глобальный аудит, аудит по заданию оператора, «интеллектуальная скорая помощь» контурам; адъюдикация необратимого по вызову; actor≠verifier. НЕ часть рабочего процесса контуров, работу агентов не контролирует (оператор, 2026-08-30). Триггеры: «можно ли пушить», «одобряю?», «спроектируй контур/правило». НЕ для разработки фичи. Голое «проверь» — по объекту: один артефакт → six-corner-audit; кодовая база → fact-audit; внешний код → code-audit-core; внешний факт → sci-search.
-
vibeengineering-llc Skill Fact AuditRead-only комплексный аудит качества чужой кодовой базы/системы с приоритизированной критикой, провенанс file:line. Триггеры: «проведи аудит», «покритикуй», «что не так в коде», «найди баги/слабые места». Голое «проверь» на кодовую базу целиком → сюда; один финализированный артефакт на гейте → six-corner-audit; код внешнего заказчика → code-audit-core. Строго read-only, НЕ для написания фичи.
-
vibeengineering-llc Bundle Incident LogФиксация инцидентов и мер: два РАЗДЕЛЬНЫХ журнала — РАБОЧИЕ (процессные провалы агента) и ПРОЕКТНЫЕ (баги продукта). Триггеры: «запиши инцидент», «прими меры, чтобы не повторилось», а также МОЛЧА — сразу после того, как что-то сломалось и починено. Не хендофф (session-handoff), не аудит (six-corner-audit).
-
vibeengineering-llc Bundle Deep ResearchМногоисточниковый разбор большого ВОПРОСА субагентами: декомпозиция на направления, параллельный обход, сборка с разведением конфликтов, адверсариальная верификация, отчёт с уровнем проверки каждого утверждения. Триггеры: «разберись подробно», «обзор по теме/аналогов», «что вообще есть по», «не изобретаем ли велосипед». Голое «разберись» — по объекту: один факт/число/ссылка → sci-search (вызывается, не заменяется); один артефакт на гейте → six-corner-audit; свой проект вширь → fact-audit.
-
vibeengineering-llc Bundle Six Corner AuditНезависимый аудит ОДНОГО финализированного артефакта ПО ФАКТУ перед пушем/мерджем: 6 углов + отдельный скептик, actor≠verifier, находки с file:line/SHA, GATED-вердикт — необратимое за оператором. Триггеры: «6-corner», «шесть углов», «скептик», «audit this PR/diff», «проверь/sanity-check чужую работу».
-
vibeengineering-llc Bundle Firmware StabilityПрошивка → продукт: зависания, фризы, лаги, потери данных, утечки, гонки, деградация за сутки; наблюдаемость, soak/endurance, фаззинг, приёмка. «Плату наизнанку», «не воспроизводится», «готова ли к релизу». Чтение кода на дефекты → `code-audit-core`.
Audited -
vibeengineering-llc Bundle Measure MethodologyМетодика ЛЮБОГО измерительного прогона (бенчмарк, профилирование, замер прибора): не «что мерить», а «как не обмануться» — поверка стенда ДО прогона, три исхода (объект/среда/стенд), обязательный блок «требует толкования». Триггеры: «сравни модели/варианты», «замерь», «бенчмарк», «почему у всех одинаково». НЕ аудит кода (code-audit-core), не инцидент (incident-log).
-
bitwise-media-group Bundle Actions SecuritySecurity hardening for GitHub Actions workflows with a least-privilege posture — default-deny permissions ({} then minimal per-job scopes), SHA-pinning every third-party action, avoiding pull_request_target (and the safe trusted-event allowlist pattern when an elevated trigger is unavoidable), preventing expression/script injection via env indirection, explicit secrets (no inherit), and OIDC over long-lived keys. Use when writing or reviewing GitHub Actions workflows for security, locking down permissions or GITHUB_TOKEN, deciding whether pull_request_target is safe, handling untrusted PR input or secrets, or pinning actions.
-
bitwise-media-group Bundle Actions ValidateValidate GitHub Actions workflow files locally with the actionlint then zizmor loop — actionlint for syntax, expression typing, and shellcheck of run steps; zizmor for security audits (expression injection, pull_request_target risks, unpinned actions, over-broad permissions). Use after editing any .github/workflows/*.yaml or action.yml, before committing workflow changes, when asked to lint, validate, or security-audit GitHub Actions workflows, when a workflow fails in CI, or when setting up actionlint/zizmor for a repository.
-
bitwise-media-group Bundle Actions Reusable WorkflowsWire a repository to the bitwise-media-group/github-workflows reusable workflows — thin, SHA-pinned caller workflows for CI, security (CodeQL) scanning, release (release-please/GoReleaser/Zensical docs), the signature-preserving fast-forward /merge + merge-review-ack + merge-notice flows, and add-to-project — plus the bitwise-media-group/toolchain mise-task consumer contract and the FF Merge / Project Sync org app setup. Use when setting up CI, security scanning, releases, auto-merge, dependency updates, or project-board sync for a repo; adding a caller that uses the shared/reusable workflows; wiring the mise toolchain library; scaffolding a repo's .github/ with the org's standard automation; or asked which reusable workflow to call and what to grant it.
-
carapace-sh Bundle GhUse when working with the GitHub CLI (`gh`) — authentication, repositories, pull requests, issues, releases, GitHub Actions (workflows, runs, caches), the gh API command, extensions, secrets and variables, search, gists, SSH/GPG keys, labels, rulesets, codespaces, browsing, configuration, aliases, JSON output formatting, and environment variables. Triggers on: "gh", "gh auth", "gh repo", "gh pr", "gh issue", "gh release", "gh run", "gh workflow", "gh api", "gh extension", "gh secret", "gh variable", "gh search", "gh gist", "gh label", "gh codespace", "gh browse", "gh status", "gh config", "gh alias", "gh completion", "gh ssh-key", "gh gpg-key", "gh ruleset", "gh cache", "gh org", "GH_TOKEN", "GH_REPO", "GH_HOST", "gh pr create", "gh pr checkout", "gh pr merge", "gh repo clone", "gh repo create", "gh issue create", "gh release create", "gh workflow run", "gh run list", "gh api graphql", "gh extension install", "gh secret set", "gh search repos".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include only-plan, code-review, ponytail-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.