Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
carapace-sh Bundle BrewUse when working with Homebrew (`brew`) — the package manager for macOS and Linux. Covers the command structure, formula and cask DSLs, taps, bottles, the Cellar, services, bundle/Brewfile, environment variables, installation internals, and developer commands. Triggers on: "brew", "homebrew", "brew install", "brew uninstall", "brew update", "brew upgrade", "brew search", "brew tap", "brew cask", "brew bottle", "brew services", "brew bundle", "brew cleanup", "brew doctor", "brew audit", "brew livecheck", "brew test-bot", "brew bump-formula-pr", "Brewfile", "HOMEBREW_PREFIX", "HOMEBREW_CELLAR", "HOMEBREW_NO_INSTALL_FROM_API", "HOMEBREW_CASK_OPTS", "HOMEBREW_BOTTLE_DOMAIN", "Formula", "Cask", "Cellar", "Caskroom", "keg", "rack", "tap", "bottle", "superenv", "Formulary", "FormulaInstaller", "shellenv", "restart_service", "keg-only", "brew deps", "brew uses", "brew leaves", "brew outdated", "brew pin", "brew fetch", "brew create", "brew edit", "livecheck", "auto_updates", "depends_on".
-
coroboros Bundle Humanize EnRemove AI writing tells from English prose while preserving meaning, structure, code, links and quotations. Use for humanize this, remove AI slop and polish the English on inline text or prose files. Optional -f BRAND-VOICE.md applies brand rules with explicit mechanical and semantic coverage. Inherit authorized rewrite scope; audit/propose remains read-only. Structural README work belongs to write-clear-readme.
Audited -
coroboros Bundle Write Clear ReadmeAuthor, restructure, audit or polish a project README for clarity and scannability. Reads repository truth, preserves anchors and code, and verifies rendering. Explicit author/polish requests apply local changes; audit/propose stays read-only. Use for README creation, wording, structure and navigation, including skill collections and CLI/SDK docs.
Audited -
danielkinneyspears Bundle Auditing CommitmentsAudits a US Federal proposal draft for the obligations it creates, and flags promises stronger than the solicitation requires. Use when the user needs a commitment audit, a promise review, an obligation review, a check for overcommitting, a review of "we will" and "shall" language, a check that the draft does not guarantee more than the RFP asked for, or a review of AI-generated proposal content before it goes out. Produces a commitment register mapping every promise to the requirement behind it, with the delta priced and the unsupported promises listed.
Audited -
danielrosehill Bundle Nsc Travel ThreatUse when the user wants the current Israel National Security Council (NSC) travel threat level / advisory for a specific country. Pulls the official rating, recommendation, area under threat, and background details from gov.il. Trigger phrases include "NSC threat level for X", "is it safe for Israelis to travel to X", "travel warning for X", "Israeli travel advisory for X", "what's the threat rating for X", "NSC recommendation on X".
Audited -
dzhng Skill ReviewCloseout pass on a finished substantive change — sequence refactor-clean (shape), code-review (diff), and write-docs (docs) so all three run, in the order where each feeds the next. Use after implementing a slice or feature and before calling it done or committing; when the user asks for a final review, a cleanup-and-document pass, or to "review everything." For a diff-only audit, reach code-review directly.
-
dzhng Skill Code ReviewReview changed code for naming, stale references, unnecessary complexity, and comment quality. Use after completing implementation work, before committing, or when the user asks to review or audit code.
-
ekkolearnai Bundle 1passwordSet up and use 1Password CLI for authentication, secret references, command injection, and safe configuration templating.
-
fattain-naime Bundle Admin Access Control SpecificationSpecify admin roles, permissions, and every admin-facing control in a system - a full role-permission matrix (RBAC), the principle of least privilege applied concretely, admin action audit logging, and emergency/break-glass access procedures. Use whenever a system has more than one privilege level, before building the admin panel or access-control logic.
-
goldenprofile Bundle Django AuditРазбор Django-проекта по одной выбранной линзе: ORM и N+1, безопасность (OWASP), Celery, шаблоны, settings, миграции, техдолг, тесты — находки по уровням риска и план. Используй когда пользователь просит «экспресс-анализ кодовой базы на N+1 и анти-паттерны», «собери весь техдолг», «проверь Django проект», «django security review», или сам называет линзу. Балльная оценка готовности всего бэкенда — python-project-audit; понять устройство без приговора — codebase-recon; глубокий разбор тестов — test-coverage-auditor.
-
goldenprofile Bundle Change ReviewГлубокий разбор ОДНОГО изменения — диффа, файла или пары связанных правок — с вердиктом APPROVE / APPROVE WITH COMMENTS / REQUEST CHANGES и шкалой критичности. Два режима: self — силами Claude (корректность, безопасность, надёжность на проде, производительность, границы слоёв); second-opinion — тот же код смотрит ДРУГАЯ модель через внешний CLI (галлюцинации API, edge cases, over-engineering). Вызывается ЯВНО. Используй когда пользователь говорит «код ревью, если не было», «сделай ревью», «посмотри мой код», «есть ли тут баги», «безопасен ли код», «второе мнение», «оцени два подхода и выбери лучший». Быстрый построчный гейт по диффу — /code-review; весь бэкенд с оценкой — python-project-audit.
-
goldenprofile Bundle Codebase ReconРазведка кодовой базы, только чтение, два режима: whole — незнакомый проект целиком (стек, архитектурный стиль, точки входа, поток данных, бизнес-цель, карта-отчёт); subject — одна область, модуль или фича адресно, с gap-анализом текущего против желаемого (OK/PARTIAL/GAP/RISK и план закрытия). Используй когда пользователь говорит «нужна экспресс-диагностика кодовой базы», «изучи кодовую базу и составь план улучшения», «что это за проект», «как он устроен», «с чего начать изучение», «разбери модуль X», «что сейчас есть по теме Y». Оценка качества и поиск дефектов — python-project-audit / django-audit; ревью одного диффа — change-review.
-
goldenprofile Bundle Dependency AuditorЗависимости Python-проекта: уязвимые пакеты (CVE через pip-audit/safety), слабый пиннинг и отсутствие lockfile, неразделённые prod/dev, заброшенные пакеты, typosquatting, а также безопасные апгрейды по semver (батчи, breaking changes, откат). Менеджеры uv, pip, poetry. Используй когда пользователь спрашивает «нужна ли ещё библиотека X в проекте», «есть ли уязвимости», «что обновить», правит requirements или pyproject, видит алерт Dependabot, настраивает lockfile, упоминает pip-audit, safety, uv.lock, supply chain.
-
goldenprofile Bundle Harness EngineeringВнедрение harness engineering (обвязки для AI-агентов) в Python-проект: Django, FastAPI, aiogram. Создаёт Makefile, CI (GitHub Actions), ARCHITECTURE.md, обновляет CLAUDE.md/AGENTS.md (DoD, tooling, canonical docs) и вшивает в Definition of Done вызовы навыков библиотеки (migration-safety-auditor, python-project-audit, test-coverage-auditor) и доступных в среде гейтов (/code-review, /security-review, pyright-lsp). Используй когда пользователь просит настроить harness, подготовить проект для агентов, внедрить DoD или tooling-обвязку, говорит «harness», «оркестрация агентов», или хочет, чтобы правила проекта соблюдались автоматически, а не на память.
Audited -
goldenprofile Skill Postgres PerformanceЗапрос или ручка тормозит — найти причину в БД и устранить: чтение EXPLAIN ANALYZE, подбор индекса (btree, GIN, partial, covering), поиск медленных запросов (pg_stat_statements), пул соединений (pgbouncer против пула драйвера), autovacuum и bloat, память под типовой VPS. Django и SQLAlchemy. Используй когда пользователь говорит «посмотри, можно ли оптимизировать бекенд <url>», «запрос тормозит», «база медленная», просит подобрать индекс или прочитать план, упоминает EXPLAIN, pg_stat_statements, slow query. Безопасность создания индекса на живой таблице — migration-safety-auditor; N+1 на уровне ORM — django-audit.
-
goldenprofile Bundle Python Project AuditПроект выглядит законченным — проверить, так ли это, и выставить оценку: незавершённый код и заглушки, критические проблемы, мёртвые куски, слабые места перед выкаткой. Статанализ (pylint, bandit, mypy, radon, vulture) плюс ручной обход чек-листа; на выходе отчёт с баллами по разделам и вердиктом. FastAPI, Django, Flask. Используй когда пользователь просит «проверить готовность проекта к деплою», «отчёт о готовности к запуску в режиме MVP», «найти незавершённый код и критические проблемы», оценить законченность и целостность кодовой базы, или готовится к релизу. Уровень проекта, не диффа: одно изменение — change-review; Django-специфика по линзам — django-audit; понять устройство без оценки — codebase-recon.
-
goldenprofile Bundle Test Coverage AuditorТесты есть, но не ловят регрессии: тесты без assertions, моки без проверки вызовов, skip без причины, зелёный coverage при непокрытом критическом пути. Python и Django. Используй когда пользователь спрашивает «хорошие ли у меня тесты», «что не так с тестами», «почему баг прошёл через тесты», просит проверить качество тестирования или разобрать coverage. Обзорная линза tests в рамках Django-разбора — django-audit.
-
greenpau Bundle Configurationcaddy-security Caddyfile configuration generation for the security app and authenticate or authorize HTTP directives. Use when creating, reviewing, or modifying Caddyfile configs for authentication portals, authorization policies, identity stores, OAuth or SAML identity providers, SSO app providers, users, registration flows, messaging, credentials, secrets, or runtime replacement in this repository.
-
greenpau Bundle Testing And CIcaddy-security repository testing and CI workflow guidance, including Go test command selection, Makefile report targets, Caddyfile parser/adapt fixture tests, runtime resolution fixtures, coverage artifacts, and GitHub Actions build/release/CLA behavior. Use when choosing or running tests, adding or updating test coverage, interpreting CI failures, reproducing GitHub Actions locally, or documenting validation for this Go/Caddy module.
-
greenpau Bundle Configuration Userscaddy-security local user account Caddyfile configuration. Use when creating, reviewing, or modifying local identity store user entries, usernames, display names, email addresses, plaintext or bcrypt passwords, overwrite behavior, roles, static API key prefixes and payloads, and secret-backed user attributes.
-
greenpau Bundle Configuration Cryptocaddy-security crypto directive configuration for authentication portals and authorization policies. Use when creating, reviewing, or debugging crypto Caddyfile lines, JWT signing or verification keys, token names and lifetimes, key IDs, HMAC/RSA/ECDSA key loading, auto-generated keys, env or secrets-backed crypto values, System API crypto keys for remote Basic/API-key authentication, and authenticate/authorize key compatibility.
-
greenpau Bundle Scripts And Automationcaddy-security repository automation, Makefile target selection, local build/test/report/coverage commands, local go-authcrunch go.mod replacement shim workflow, asset and documentation update scripts, release/version workflows, generated artifact handling, and guardrails for dependency, devbuild, cleanup, and release actions. Use when choosing, running, documenting, or updating repository scripts and Make targets; troubleshooting CI/build/test automation; coordinating caddy-security development with local go-authcrunch changes; refreshing Caddyfile/config fixtures; deciding whether generated outputs belong in a change; or preparing releases for this Go/Caddy module.
-
greenpau Bundle Configuration Messagingcaddy-security messaging provider Caddyfile configuration. Use when creating, reviewing, or modifying messaging email provider or messaging file provider blocks, SMTP settings, passwordless email, senders, BCC addresses, message templates, root directories, and registration email wiring.
-
greenpau Bundle Authentication Portal APIcaddy-security authentication portal JSON API and admin/server API guidance. Use when building, reviewing, or debugging programmatic login clients, Portal API calls, Accept: application/json behavior, sandbox challenge sequences, /beacon, /whoami JSON/probe/id_token responses, refresh token API behavior, enable admin api, /api/server metadata/realms/info endpoints, and API-oriented authentication troubleshooting.
-
greenpau Bundle Break Fix Troubleshootingcaddy-security break-fix triage and support-report workflow. Use when diagnosing reported configuration, deployment, or runtime failures; analyzing Caddyfiles, Caddy logs, redirect loops, login failures, authorization denials, OAuth/OIDC/SAML/LDAP/local-user issues, module-version mismatches, or secret/runtime placeholder problems; preparing GitHub issue Markdown files for .github/ISSUE_TEMPLATE/break-fix.md under tmp/breakfix/; or identifying gaps in repository skills after troubleshooting.
-
greenpau Bundle Configuration Credentialscaddy-security reusable generic credentials Caddyfile configuration. Use when creating, reviewing, or modifying security credentials blocks for reusable username/password credentials, optional domains, SMTP or email messaging authentication, registration email provider credentials, environment placeholders, or secret-backed credential values.
-
greenpau Bundle Configuration Authorizationcaddy-security authorization policy Caddyfile configuration. Use when creating, reviewing, or modifying security authorization policy blocks, route-level authorize directives, ACL rules, allow or deny shortcuts, bypass rules, crypto verification keys, auth redirects, bearer token validation, basic or API key auth proxy settings, user identity fields, and injected claim headers.
-
greenpau Bundle Configuration Registrationscaddy-security user registration Caddyfile configuration. Use when creating, reviewing, or modifying user registration blocks, registration titles and codes, dropbox files, terms and privacy links, accepted email domains, MX checks, email provider wiring, admin notification addresses, and identity store targets.
-
greenpau Bundle Configuration Authenticationcaddy-security authentication portal Caddyfile configuration. Use when creating, reviewing, or modifying security authentication portal blocks, route-level authenticate directives, portal crypto, enabled identity stores, OAuth or SAML identity providers, SSO app providers, trusted redirects, source address validation, or portal wiring. For cookies, UI, and user transforms use the focused authentication subskills.
-
greenpau Bundle Configuration Identity Storescaddy-security local and LDAP identity store Caddyfile configuration. Use when creating, reviewing, or modifying local identity store blocks, LDAP identity store blocks, local user records, store shortcuts, realms, user files, LDAP bind settings, servers, search filters, attributes, groups, recovery settings, support links, fallback roles, and login icons.
-
greenpau Bundle Configuration HTTP Integrationscaddy-security HTTP integration Caddyfile configuration. Use when creating, reviewing, or modifying route-level authenticate and authorize directives, portal and protected route separation, matcher forms, same-host or split-host auth wiring, auth URL routing and alignment, auth-path collisions such as upstream /auth routes, dedicated auth hosts with root-mounted portals, portal-owned path prefixes to avoid, or unnecessary global Caddy directive-order overrides.
-
greenpau Bundle Configuration Runtime Resolutioncaddy-security runtime replacement guidance for Caddyfile configuration. Use when creating, reviewing, or modifying configs that rely on Caddy replacer placeholders, env placeholders, secrets manager lookups, resolved Caddyfile fixtures, runtime credential resolution, unresolved token checks, or caddyfile_resolve behavior.
-
greenpau Bundle Configuration Authentication Cookiescaddy-security authentication portal cookie Caddyfile configuration. Use when creating, reviewing, or modifying authentication portal cookie directives, cookie domains, paths, lifetimes, SameSite, insecure cookies, guessed or stripped domains, token cookie names, cookie name prefixes, access token cookie validation, or authcrunch cookie defaults.
-
greenpau Bundle Configuration Authentication User Transformscaddy-security authentication portal user transform Caddyfile configuration. Use when creating, reviewing, or modifying authentication portal transform user blocks, transform matchers, ACL condition syntax, add or overwrite role actions, drop matched role actions, MFA requirements, block or deny transforms, transform UI links, or authcrunch claim replacement placeholders.
-
hashload Skill Horse Security AuthGuide for securing routes, configuring JWT and Basic-Auth middlewares, and handling route authentication groups.
-
hopeoverture Skill Audit WorldAudit a world for consistency, D&D 5e 2024 rule compliance, broken links, orphaned entities, and connection gaps. Provides detailed reports and can auto-fix issues.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include brew, humanize-en, write-clear-readme. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.