Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
alessioscarfone Bundle Code ReviewRun a multi-perspective code review that spawns parallel reviewer agents focused on different quality dimensions — simplicity/DRY, bugs/correctness, and project conventions — then consolidates findings into a single prioritized report. Use when the user asks to review code, check for bugs, audit recent changes, review a branch or PR, inspect code quality, or wants a second pair of eyes on their work. Also triggers on "review my changes", "anything wrong with this code", "check before I push", "sanity check", or "code audit". Do not use for implementing features, writing new code, or refactoring — those have their own workflows.
-
platonai Bundle Organize Task FilesLists, pairs, deduplicates, and moves task files across the Coworker task state machine (0draft → 6git-pushed). Use when asked to organize, clean up, or audit task files.
Audited -
receptron Skill Publish MulmoclaudePublish the `mulmoclaude` npm package — with dep audit, workspace drift check, tarball test, and cascade publish of stale @mulmobridge/* dependents
-
vincentkoc Bundle Semantic SlicingBuild local semantic review slices by combining clawpatch feature maps, deepsec threat candidates, visual review maps, and optional gitcrawl/discrawl evidence for repos such as openclaw/openclaw.
Audited -
vincentkoc Bundle Org Branch CleanupAudit and safely prune stale branches across a GitHub organization with immutable snapshots, conservative merged-PR classification, live SHA/protection/open-PR revalidation, resumable deletion ledgers, and post-delete verification. Use when a maintainer asks to clean up old, dead, merged, bot-created, or abandoned organization branches without risking default, protected, release, security-advisory, state, or active pull-request refs.
Audited -
vincentkoc Bundle Opik Integrations AuditorAudit, compare, and document Opik integrations across Python SDK, TypeScript SDK, and OTEL/API backend. Use when adding a new integration, reviewing an existing one, or generating first-pass integration docs and gap analysis.
-
hams-ollo Skill Doc SyncUse when code has moved and the documentation may not have, or when a documentation set needs auditing for stale claims. Detects documentation drift by checking prose claims against repository facts, classifies every document as current-state (correctable), contract (report-only, human-owned) or ledger (skipped), and reports each finding with a stable id, the fact that grounds it, and a grounded or suspected confidence. Dry run is the default and detection never changes a file; updating a current-state document requires explicit per-finding approval and leaves an audit trail, and a contract document is never edited because a disagreement there means the code is wrong. Distinct from doc-author (writes documents that do not exist), doc-revise (edits a document you have already decided to change, and which this composes for editing discipline), and spec-conformance (audits code against a spec). It finds what drifted; it does not silently fix it.
Audited -
hams-ollo Skill House ReviewReview a code change against an explicit house rubric and severities, and produce a structured, severity-ranked markdown review, without editing or committing anything. Determines the review range (the current branch against its merge-base with the default branch, with a working-tree fallback), applies the review-quality lens (correctness, security, error handling, tests, readability, performance, API design, docs), resolves every finding's quoted evidence against the real file and drops any finding that does not resolve, and writes findings ordered blocker to nit with file:line, the quote, a stable signature, why it matters, and a concrete fix. Use when the user says "review this", "review my changes", "code review", "review this PR/branch/diff", "what's wrong with this change", or wants a second pair of eyes before merging. Report-only: it never changes code.
Audited -
hams-ollo Skill Spec ConformanceUse when closing a spec-driven feature or issue, or auditing whether an implementation actually matches its spec. Given a spec path, emits a section-by-section conformance matrix mapping every scenario and proposed surface element to conformed (with file:line or test evidence), diverged (what, why, and both sides), or not-built, plus an audited/unreconciled coverage proof. This is the spec-vs-implementation audit, distinct from spec-quality (spec well-formedness) and doc-sync (doc-vs-code drift), and it is independent of test pass/fail.
Audited -
paulgrape Skill Website SecurityTransport and HTTP-header security for a website — HTTPS/TLS, HSTS, Content Security Policy, X-Content-Type-Options, clickjacking protection, cookie attributes, and security.txt. Use when configuring server headers, TLS, cookies, or a disclosure policy.
-
prime-radiant-inc Skill Container ExecutionInfrastructure skill for containerized target execution. Runtime detection, container lifecycle, security restrictions, interaction patterns.
-
prime-radiant-inc Skill Fidelity ValidationCross-validates sanitized output specs against raw source specs to detect lost behavioral detail, dropped constants, missing features, or diluted precision. Run AFTER sanitization and AFTER contamination audit passes.
-
pubnub Bundle Pubnub SecuritySecure PubNub applications with Access Manager v3, end-to-end AES-256 encryption, TLS 1.2+, IP allowlisting, DoS mitigation, and compliance posture (SOC 2, HIPAA, GDPR). Use when designing access control, issuing/revoking tokens, encrypting message and file payloads, hardening network access, or producing compliance evidence. Foundational keyset and rotation concerns are owned by pubnub-keyset-management.
-
fastrepl Bundle Product Update NewsletterDraft, update, or audit a crisp, changelog-grounded Anarlog product-update newsletter in Loops (app.loops.so) for a desktop release. Use after the changelog is merged, when asked to draft, revise, or pre-send check the release announcement email.
-
harshsinghmp Bundle UpdatedocsProject-wide documentation synchronization, drift detection, and governance engine. Traces code, schema, API, and configuration changes to all affected documentation (README, changelogs, architecture, APIs, contributing, client docs), enforces strict .memory/ no-touch boundary, .agents/artifacts/ working-state boundary, and .agents/ DOX permission gates, audits for semantic drift, mandates a verify-after-bulk-edit gate (diff audit + mechanical re-check) for sd/sed/scripted sweeps, and applies minimal, evidence-backed updates.
-
harshsinghmp Bundle Evidence LedgerPersistent per-project evidence tracking system and source-cited claim verification gate for multi-client agency workflows. Maintains an append-only evidence-ledger.md per project tracking decisions (with options considered and evidence trail), client commitments (with deadlines and delivery proof), verified claims (with confidence taxonomy and receipts), and status facts (with blocker tracking). Six commands: /evidence onboard, /evidence status, /evidence decide, /evidence commit, /evidence audit, /evidence brief. Enforces the doctrine: 'No source, no claim. No verification path, no release.' Uses a 4-tier confidence taxonomy ([RAW], [FETCH], [SEARCH], [INFER]), academic DOI receipts, empirical vs speculative classification, and automatic staleness detection.
-
igapyon Bundle Igapyon ReviewerUse only when the user explicitly asks igapyon-reviewer to review a separate target or explicitly asks to use igapyon's reviewer skill. Once invoked, participate as a review-only skill for code, repositories, articles, documentation, social posts, GitHub text, README text, UI text, CLI text, or short text. A bare mention, an existence question, or a request to explain, review, audit, or update igapyon-reviewer itself is meta work and must not activate the reviewer workflow. Do not use this skill for ordinary feedback, proofreading, rewriting, implementation, repository cleanup, or generic review requests unless the user explicitly invokes this reviewer skill.
-
krishnakanthb13 Skill Code ReviewComprehensive code review covering Functionality, Security (OWASP), Performance, and Maintainability. Includes good/bad examples.
-
krishnakanthb13 Skill Security AuditScans the codebase for OWASP Top 10 vulnerabilities (Secrets, Injection, Auth) and manages SECURITY.md.
-
lhohan Skill Extension Security ReviewUse when adding an extension, plugin, GitHub repo, npm package, or local plugin and you need a structured security review before installing or enabling it.
-
lhohan Skill Code ReviewUse when reviewing code changes (diffs, PRs, or commits) that need operational verification, project-rule checks, and actionable findings across bugs, security, quality, and compliance.
-
ankurjain1121 Bundle Fix HardZero-tolerance code quality enforcement. Fixes ALL errors, warnings, suppressions, and security issues. Includes mutation testing, intelligent suppression audit, and optional hook generation. No mercy, no shortcuts.
Audited -
ankurjain1121 Skill UI AuditUI Audit
-
diguike Skill AfterCode review with security, performance, and style checks. 代码审查:安全、性能、风格。
-
diguike Skill Review SecuritySecurity-focused code review. Fork subagent for parallel execution. 安全专项审查。
-
goiltpatpat Skill Patpat ArchitectDesign a repository-native change before implementation. Use for architecture, migrations, public contracts, security-sensitive boundaries, cross-cutting work, or decisions with meaningful compatibility risk.
-
iamzifei Bundle Zmm Review📐 詹明明·发布前审一遍 ——口播稿发布前审核技能。按观众的四次决定审:点不点进来 · 留不留下来 · 记不记得你 · 做不做点什么。逐句信息密度评分(60/80 分线)+ 十一问 + 红线五查(改法给稳妥版和保留力度版两版)+ 机器信号层(导流 / 广告形状 / 名单词,与内容违规分开报),默认只诊断不改。 触发方式:/zmm-review、/能不能发、/审核、/zmm-审核、「这稿子能不能发」「帮我审一下」「过一遍红线」「信息密度够不够」 Pre-publish review for talking-head scripts, organised around the viewer's four decisions: click, stay, remember, act. Per-sentence density scoring, eleven questions, red-line audit. Diagnose-only by default. Trigger: /zmm-review, "can I publish this", "review my script" —— 📐 詹明明 · 不给公式,给判据。每条规则都标了实测代价。
-
ievo-ai Skill ScheduleUse this skill when the user asks "schedule an iEvo audit", "set up weekly security scan", "automate iEvo", "run iEvo on a schedule", "periodic security check", or "create a routine for iEvo". Configures a Claude Code Routine for periodic iEvo operations — recurring security audits, skill-update checks, or custom iEvo commands on a schedule. Three-step wizard: pick operation (security audit / skill refresh / custom), pick frequency (daily / weekly / monthly / one-off / custom cron), confirm and create via the in-session /schedule command. Routines run on Anthropic-managed infrastructure (research preview). Falls back to the claude.ai/code/routines web UI, or to CI cron instructions when Routines are unavailable (API-key auth, Free plan).
Audited -
ievo-ai Skill Deep ReviewUse this skill before committing significant changes, after a refactor, or when you want a second opinion on a diff — not for auditing a third-party skill/plugin's safety before install (use /ievo:security-check for that). Structured 11-point gap-detection review of a diff before commit. Spawns a deep-reviewer subagent for independent eyes (fresh context, separate token budget). Catches issues that survive pre-commit hooks, linters, and test suites but surface in human PR review — completeness gaps, test/impl drift, dead code from partial refactors, naming/behaviour mismatch, doc-paraphrase drift, cross-file consistency, error-path coverage, API contract fidelity, security surface, concurrency/state, and leaked secrets. Supports scope modes — staged changes (default), working tree, or arbitrary git range.
-
ievo-ai Skill Overlay StatusUse this skill when the user asks "what evolutions have I captured", "show my iEvo overlays", "what rules are active in this project", "list installed overlays", "summarize .ievo/evolution" — not for previewing a remote repo's contents before install (use /ievo:inspect for that). Surfaces the current state of iEvo evolution overlays in this project. Lists every overlay under `.ievo/evolution/` grouped by scope (project, agents, skills), with a one-line summary + last-modified date per file. Read-only — never modifies, deletes, or rewrites overlay content. Closes the legibility gap iEvo's own `coverage-audit.md` flagged as "Standalone 'list installed iEvo overlays' command".
Audited -
thomasrohde Bundle Improve SkillThis skill should be used when the user asks to "improve a skill", "optimize a skill", "review a skill", "audit a skill", "apply SkillsBench findings", "make a skill more effective", "refactor a skill", "fix a skill", or mentions improving, optimizing, or auditing an existing Claude Code skill based on research-backed best practices.
-
thomasrohde Bundle Earos RubricCreate new architecture evaluation rubrics (profiles and overlays) based on the Enterprise Architecture Rubric Operational Standard (EAROS). Use this skill whenever the user wants to "create a rubric", "add a rubric profile", "write an architecture evaluation rubric", "define scoring criteria for architecture artifacts", "create an EAROS profile", "add an overlay", "create a security overlay", "create a data overlay", "evaluate architecture artifacts", "set up architecture review criteria", "build a rubric for solution architecture", "create an ADR rubric", "create a capability map rubric", "define architecture quality criteria", or mentions "EAROS", "rubric", "architecture evaluation", "scoring profile", or "architecture review criteria" in the context of creating or extending evaluation rubrics. Also triggers when the user says "help me evaluate architecture documents", "define review criteria for our artifacts", "standardize architecture review", "create a review checklist", or any request to systematicall
-
devantler-tech Skill Product EngineeringThe ADVANCE playbook for an autonomous AI engineer — how to move a product forward once it is healthy: product strategy and roadmap stewardship, issue triage and decomposition, oldest-actionable-first implementation, test coverage, benchmarking and performance, refactoring and code quality, documentation sync, and security posture — all shipped as evidence-backed draft PRs self-promoted on genuine readiness. Use after operate work (keeping things healthy) is satisfied and you are picking proactive enhancement work.
Audited -
garcon-drinks Bundle Home Bar RestockingCalculate review-only home-bar replenishment quantities from reconciled usable stock, approved demand, lead time, review period, buffer, inbound supply, package sizes, and user-supplied constraints. Use after an inventory audit when deciding how many packages of recurring staples to restock.
Audited -
garcon-drinks Bundle Accessible Drink ServiceAudit a pre-event drink-service journey from guest-stated preferences, supplied venue facts, communication formats, touchpoints, measurements, and current applicable official requirements. Use for approach, menu access, ordering, queues, payment, pickup, self-service water, seating, or restroom-route barriers. Exclude compliance certification, disability diagnosis, inferred needs, venue contact, physical verification, purchasing, modification, emergency-egress design, structural work, and electrical work.
-
garcon-drinks Bundle Cocktail Tool Kit PlanningPlan a minimum cocktail-tool capability set from approved recipes, verified owned equipment, measured substitutes, constraints, and supplied candidates. Use for a first kit or equipment-gap audit; exclude recipe, bottle, shaker-type, glassware-set, live-price, and checkout decisions.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include updatedocs, evidence-ledger, code-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.