Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
hopeoverture Skill Expand FactionBuild out an organization with member hierarchy, internal politics, resources, secret plots, rivals, and operational details. Use when user wants to "flesh out a guild", "expand an organization", or "detail a faction".
-
johnoconnor0 Bundle Audit ResolverRead a plan-completion-audit report, plan the fixes, and execute them with safety gates per finding. Verifies between batches; optionally re-runs the audit to confirm closure.
-
johnoconnor0 Bundle Plan Completion AuditAudit a plan against what was actually built - deriving the checks from the plan and the detected stack, never from a fixed list.
-
johnoconnor0 Bundle Review ChangeUse to review a branch, pull request, diff, or uncommitted change for correctness, architecture, security, tests, migrations, and maintainability.
-
johnoconnor0 Bundle Create System MapUse to map actors, workflows, components, data flow, external systems, responsibility boundaries, failure points, security, and deployment shape.
-
johnoconnor0 Bundle Run Engineering CouncilConvene an independent multi-perspective engineering council before high-stakes or hard-to-reverse work — major architecture, a new plugin or subsystem, external integrations, risky migrations, security-sensitive or AI-system design, or build-vs-buy. Invoke proactively when a change is large, cross-cutting, or costly to undo, not only when explicitly asked; skip it for routine bug fixes and simple docs.
-
joshukraine Skill Ruby GcAudit asdf-installed Ruby versions against project pins and remove unreferenced ones. Dry-run by default.
-
ratacat Bundle ClarifyChained clarity review of a repo, plan, or work items — combines code review, plan refinement, deep-module architecture, DRY/cruft, and naming analysis. Use for clarify/defuzz/audit/harden/fresh-eyes requests.
-
ratacat Bundle Conjecture CascadeProbe a bounded target from many angles at once — audit for hidden bugs/stale state, stress-test a claim or plan, or brainstorm wide. Falsifiable or generative probes through explicit lenses, each closed with evidence.
-
researai Bundle ReviewUse when a draft, paper, or paper-like report is substantial enough for an independent skeptical audit before finalization, rebuttal, or revision routing.
-
rikocr8orh8 Skill Aeo Site AuditYou can be found by an AI assistant and still be unusable to it.
-
rikocr8orh8 Skill Gpsr Readiness AuditA safe product with no EU Responsible Person still can't be sold, and Amazon suppresses the listing today.
-
rikocr8orh8 Skill AI Content Fact Audit'The AI wrote it with citations, so it's sourced' is how a fabricated stat ships.
-
rikocr8orh8 Skill Hipaa Readiness AuditYour BAA is a contract, not a risk analysis — and the risk analysis is what OCR cites.
-
rikocr8orh8 Skill Pci Dss Payment Audit'We use a Stripe iframe, so this doesn't apply to us' is the belief that gets merchants skimmed.
-
rikocr8orh8 Skill Dora Ict Register AuditYour DORA register isn't a list, it's 15 inter-linked templates, and supervisors cross-check them.
-
rikocr8orh8 Skill Gdpr Consent Dsar AuditEveryone's redesigning cookie banners around a law that hasn't passed.
-
rikocr8orh8 Skill Vibe Code Security GateAI-assisted commits leak secrets at roughly double the baseline rate.
-
rikocr8orh8 Skill Hts Classification AuditYour supplier's HS code cannot tell you what you owe.
-
rikocr8orh8 Skill Eu AI Act Article50 Audit'The AI Act got delayed' is true of the high-risk rules and false of the part that hits you in 2026.
-
rikocr8orh8 Skill Email Deliverability AuditYou think you're under the 0.30% spam ceiling.
-
sap-samples Bundle Authentication XsuaaInvoke this skill to set up XSUAA authentication and Application Router. Detects <auth-method>FORM</auth-method> in web.xml, security-constraint definitions, or UserProvider usage in Java code. Replaces Neo built-in auth with CF XSUAA.
-
scalably-io Skill Weekly Memory CleanupRuns the memory-system skill's Sunday deep pass: the nightly routine first, then archiving the finished week, deduping and topic-merging learned-corrections, reviewing the tree for staleness, cross-file deduping, and rebuilding the index from scratch. Use for weekly memory cleanup, a Sunday memory cleanup, a weekly deep pass, archiving the week, or a memory audit. Not for the nightly pass alone: that's the dream skill; this skill runs it first and then goes further.
Audited -
luongnv89 Bundle Skill Auto ImproverImprove an external, legacy, or drifted SKILL.md to the skill-creator standard — hard validation gates plus an advisory predictability audit. Don't use for authoring from scratch (skill-creator output is already standard), bulk eval, or prose edits.
-
luongnv89 Bundle Skill Index UpdaterAdd GitHub skill repos to the ASM index: clone, audit, eval, regenerate index, rebuild catalog, open PR. Use when given GitHub URLs to onboard. Don't use for authoring (skill-creator), improving (skill-auto-improver), or install (asm install).
Audited -
makgunay Bundle Skill MaintainerMeta-skill for ingesting Apple developer documentation (WWDC transcripts, API docs, migration guides, release notes) and using it to create, update, or improve Swift/macOS development skills. Trigger when user uploads new Apple documentation, asks to update skills with new API information, requests skill creation from documentation, says "ingest this", "update skills with this", or provides markdown/text files containing Apple framework documentation. Also trigger when user asks to audit existing skills for staleness, merge overlapping skills, or check skills against new OS releases.
-
marco-souza Skill Pr ReviewReview GitHub pull requests for code quality, security, and best practices. Use when the user asks to review a PR, check a pull request, evaluate code changes, or provide feedback on GitHub code. Requires `gh` CLI authenticated with appropriate permissions. Do NOT use when the user wants to create a PR, merge a PR, or perform other PR operations.
-
marco-souza Skill Code ReviewReview your own local code changes before pushing or creating a PR. Use when: the user wants to self-review staged or unstaged changes, check code quality before committing, or get feedback on work-in-progress. Covers readability, patterns, error handling, performance, and security. Do NOT use when: reviewing an existing pull request (use pr-review), reviewing code you didn't write, or when changes are already pushed to remote.
-
marco-souza Skill Security AuditPerform standalone security audits covering OWASP Top 10, dependency scanning, secret detection, input validation, and authentication review. Use when: the user asks for a security review, vulnerability assessment, audit, or wants to check for security issues in code or dependencies. Do NOT use when: the user wants a general code review (use pr-review), is asking about deploying to production, or wants penetration testing guidance.
-
mtgvim Bundle Tk Audit[user] 저장소를 읽기 전용으로 감사하고, 다른 실행자나 `tk-prep`이 재사용할 수 있는 우선순위가 있는 근거 기반 `AUD-*` `finding`을 작성합니다.
-
openinterpreter Bundle Roll ForwardBuild a roll-forward schedule for a balance-sheet account or account group, tying beginning balance, activity, reversals, payments, adjustments, and ending balance to GL support. Use for month-end close packages and audit support.
-
sharex Skill Audit RefactoringAudit XerahS refactoring candidates when explicitly requested. Do not trigger on ordinary bug fixes.
-
cristiano-pacheco Bundle AI Codebase ReviewAudit a whole codebase for bottlenecks.
-
yha9806 Bundle AuditCheck thesis chapters for consistency before submission — contradictory numbers, terminology drift, and broken cross-references.
Audited -
yha9806 Bundle Self ReviewReview the user's own manuscript, paper, thesis chapter, rebuttal, or release packet with clean-room anti-contamination controls and, when needed, an unfamiliar-reader comprehension gate. Use for internal review, readiness checks, reviewer simulation, or claim-evidence self-audit where prior chat memory and unstated context must not become evidence.
Audited -
yha9806 Bundle Argument GovernanceBuild and audit the manuscript or research-project argument system across intended use, gaps, claims, data, results, experiment roles, contributions, innovation evidence, limitations, and contribution focus. Use when a paper, thesis chapter, review article, or research project needs an explicit argument map, evidence-fit or over/under-balance checks, analysis admission, contribution prioritisation, innovation-evidence checks, or a decision about whether the current emphasis should change; also use for Chinese requests such as 梳理研究项目、研究主线、贡献侧重、创新证据、结果是否支撑论点、主实验与辅助分析、内容或证据是否过多或过少.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include plan-completion-audit, skill-auto-improver, expand-faction. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.