Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
flux-point-studios Skill Aiken Dex Security Audit OperatorOperator skill: run local Aiken build/test commands and capture evidence for the audit. Manual invoke only.
-
big-emotion Skill Project Standard AuditProduction-readiness audit for Big Emotion Project Standard (this repo). Read-only multi-domain scored assessment that answers four questions — is the plugin ready to install on real repos, is the template surface healthy, what is the security posture, and is the score close to 8–9/10. Use when the user asks "is it ready", "audit the project", "production-readiness check", or invokes /project-standard-audit.
-
kshyam Skill Delete AI WordsAudit and rewrite any text so it stops sounding like AI. Use this skill whenever the user invokes /delete-ai-words, or asks to "delete the AI words", "humanise this", "make this sound less like AI", "de-AI this", "audit this against the writing rules", "fix the AI writing", or pastes a draft and asks you to clean up the robotic patterns. Also trigger right after you produce any longer piece of writing (LinkedIn post, email, article, blog post) and the user wants it to read like a person wrote it. Apply the rules below to the user's supplied text, or to your own most recent draft if they say "audit your text".
-
avivsinai Skill Security GateClassifies inbound Telegram messages for telclaude as ALLOW/WARN/BLOCK with brief rationale.
-
rldyourmnd Bundle Version PatrolAudit dependency/runtime/tooling freshness against current stable releases and provide risk-ranked upgrade guidance.
-
rldyourmnd Bundle Better Code ReviewRisk-first semantic code review focused on correctness, security, regressions, and missing tests with severity-ordered findings.
-
j03fr0st Bundle Code ReviewReview code changes read-only at quick, standard, or deep depth, with a bounded single-reviewer default and evidence-backed findings. Use when the user asks to review a branch, pull request, commit, working-tree changes, staged changes, a diff, or code before merge; asks for a quick or deep review; or wants to know whether a change matches its specification and repository rules. Route whole-codebase audits, product acceptance, dedicated security audits, and implementation-only requests to their own workflows.
-
mark393295827 Skill Wiki LintUse when an Obsidian wiki needs a reproducible health audit for structure, provenance, links, understanding, lifecycle, and promotion readiness.
-
aman-bhandari Skill Weekly ReflectingFriday depth test from memory. Triggers on /reflect, weekly reflection, or friday reflection. The student writes answers from memory with NO code lookup allowed. Gaps in writing equal gaps in understanding. Connects to spaced review deck, trend scout, and system check for a complete weekly audit.
Audited -
asimons81 Bundle Hermes Skill AuditUse when installed Hermes skills must be audited for overlap, staleness, broken references, usage-integrity problems, and dead weight without changing the installation.
Audited -
asimons81 Bundle Hermes Token AuditUse when Hermes token usage, cost attribution, runaway sessions, cron consumption, or billing discrepancies must be investigated using privacy-preserving, schema-aware evidence.
Audited -
asimons81 Bundle Hermes Stack DoctorUse when a top-level, read-only Hermes health audit is needed across installation, updates, gateways, cron, profiles, skills, repositories, credential posture, persistence, and cost signals.
Audited -
asimons81 Bundle Hermes Profile AuditUse when a Hermes profile must be audited for role clarity, authority boundaries, configuration fit, skills, memory posture, credential scope, handoffs, and recurring operational failures.
Audited -
asimons81 Bundle Repo Readiness AuditUse when a user asks whether an identified repository is ready for further development, release work, a new feature, handoff, or a new contributor, requiring a disciplined read-only audit before an evidence-backed verdict.
Audited -
asimons81 Bundle Pre Build Feature AuditUse when a proposed open-source feature must be checked across source, history, branches, issues, pull requests, roadmaps, and contributor guidance before implementation begins.
Audited -
asimons81 Bundle Hermes Environment MigrationUse when a Hermes environment must be safely migrated between machines with staged exports, integrity manifests, secret separation, selective imports, verification, and rollback.
Audited -
aws-samples Bundle Bedrock Adoption ReadinessAmazon Bedrock production readiness assessment covering IAM governance, data retention (ZDR), quota and capacity headroom, and operational observability across Standard Bedrock and Mantle surfaces. Use this skill when a user asks to review Bedrock readiness, assess Bedrock security posture, evaluate quota headroom, check ZDR configuration, validate Bedrock operational setup, or prepare for Bedrock production deployment. Triggers on "Bedrock readiness review", "am I ready for Bedrock production", "Bedrock security assessment", "check my Bedrock quotas", "Bedrock adoption audit", "Bedrock operational review", or "assess my Bedrock environment".
-
buyoung Bundle Code Security AuditPerforms OWASP-based code security audits on any codebase. Analyzes source code against ASVS 5.0.0 verification requirements, API Security Top 10 2023 risk patterns, OWASP CheatSheet secure coding practices, and WSTG testing methodologies. Input is a codebase to review; output is a detailed Markdown security audit report. Use when the user requests a security audit, security review, vulnerability assessment, or code security analysis.
-
joemccann Bundle Testing WeekendWeekend testing loop - daily delta-audit of test-suite health for everything merged since the last audited SHA (new findings appended to TEST_AUDIT.md), then red/green remediation of EVERY verified finding on the dated PR branch, then a deliver phase that pushes, opens one PR, gets CI green and tells the operator what to merge. Runs unattended on the always-on runner via scripts/testing_weekend.sh, one daily cycle at 00:10 local that runs audit, remediate, then deliver; invoke as /testing-weekend audit, /testing-weekend remediate or /testing-weekend deliver.
-
joemccann Skill Security NightlyNightly security auditor and authorized local penetration tester - daily audit that scans the source delta since the last audited SHA with pinned deterministic tools plus harvest of whatever Vercel DeepSec sibling export is already ready and the official Claude Security plugin, independently verifies every candidate against current code, then remediates every independently verified source-actionable finding with a durable regression, then a deliver phase that pushes P2/P3 (and operator-released P0/P1) fixes as one sanitized PR, gets CI green and tells the operator what to merge. DeepSec is a sibling worker (scripts/security_deepsec_worker.sh, own launchd/cap/dead-man), not a second remediate/deliver loop. Runs unattended and CREDENTIAL-FREE in ~/radon-weekend/radon-security via scripts/security_nightly.sh, one daily cycle at 00:40 local (audit, remediate, then deliver); invoke as /security-nightly audit, /security-nightly remediate or /security-nightly deliver. Fails closed and never touches production, live
-
joemccann Bundle Reliability WeekendWeekend reliability loop - daily delta-audit of everything merged since the last audited SHA (new findings appended to RELIABILITY_AUDIT.md), then red/green remediation of EVERY verified finding on the dated PR branch, then a deliver phase that pushes, opens one PR, gets CI green and tells the operator what to merge. Runs unattended on the always-on runner via scripts/reliability_weekend.sh, one daily cycle at 00:00 local that runs audit, remediate, then deliver; invoke as /reliability-weekend audit, /reliability-weekend remediate or /reliability-weekend deliver.
Audited -
joemccann Bundle Documentation NightlyNightly documentation maintainer - daily audit that classifies the documentation impact of everything merged since the last audited SHA (rolling issue labeled documentation-nightly), then smallest source-backed remediation of EVERY verified P0/P1/P2 finding on the dated PR branch documentation/<date> without inventing prose, duplicating machine truth, or touching live systems, then a deliver phase that pushes, opens one PR, gets CI green and tells the operator what to merge. Runs unattended on the always-on runner via scripts/documentation_nightly.sh, one daily cycle at 00:30 local that runs audit, remediate, then deliver; invoke as /documentation-nightly audit, /documentation-nightly remediate or /documentation-nightly deliver.
-
kennykankush Skill BedrockFoundation audit mode. Walk a codebase as an adversarial building inspector - stress-test load-bearing logic to bank-grade, limit-test feature flows by actually running them, and file a fragility report backed by runnable repros. Maintains an AUDIT.md ledger at repo root across runs. Use when the user asks to audit the foundations, check whether things are foundationally strong or flaky, run a bank-logic check, limit-test or stress-test features after a heavy build sprint, question the codebase from first principles, or harden what the audit found ("report and fix"). Two modes - report (default) and report-then-fix.
-
kennykankush Skill PotentialSee what a codebase wants to become. The generative counterpart to a foundation audit - read the existing structure and surface the features it already implies, the capacity it isn't using, and the doors it hasn't opened. Two modes - open ("what does this want to become?") and wish (the user brings "I wish it could X" and the structure answers whether and how it can grant it). Use when the user asks what could this become, squeeze the potential of this feature, what features want to be born, what's latent here, run potential, or starts a sentence with "I wish it could". A conversational thinking mode like isomorph - it never implements and never writes files.
-
ivklgn Bundle Update Node DepsAudit and update Node.js/JavaScript project dependencies using native package-manager commands (npm, pnpm, yarn, bun). Auto-applies patch updates silently, asks before minor, and confirms each major individually. Cross-checks changelogs via Context7 and security advisories before each batch. Use when the user asks to update dependencies, bump packages, check outdated packages, or audit security in a JS/TS project.
-
ivklgn Bundle Update Golang DepsAudit and update Go module dependencies using native go toolchain commands (go list, go get, go mod tidy) plus govulncheck for security. Auto-applies patch updates silently, asks before minor, and confirms each major individually. Cross-checks release notes via gh/Context7 and vulnerabilities before each batch. Handles v2+ module path changes (gopkg.in/, github.com/.../v2). Use when the user asks to update dependencies, bump modules, check outdated modules, or audit security in a Go project.
-
az9713 Bundle Windows Diagnostics360-degree Windows system health diagnostics — covers CPU, memory, disk, network, security, startup programs, services, system info, hardware, and installed software. Use this skill whenever the user mentions system diagnostics, PC health check, performance issues, 'why is my computer slow', disk space, memory usage, startup optimization, security audit, bloatware removal, system cleanup, laptop health, or wants to keep their PC in prime condition. Also use when the user asks about high CPU, RAM usage, what's eating their disk, or wants a full system report.
Audited -
az9713 Bundle Plugin Skill AuditorAudit all personal Claude Code skills and plugins, back them up, and generate exhaustive removal and restoration instructions. Covers personal skills (~/.claude/skills/) and plugin marketplaces only — does NOT audit project-level (.claude/skills/) or enterprise skills. Use when you want to inventory, backup, or prepare to clean up your Claude Code extensions. This skill is READ-ONLY and will NEVER remove anything.
Audited -
az9713 Bundle Skill Best PracticesAudit installed Claude Code skills against best practices and output ranked suggestions. Use when you want to check skill quality, review a skill for issues, audit all personal skills, lint skills, or improve skill structure. Accepts an optional skill name or "all" (default).
-
shishiv Skill Maintain Verification SkillPeriodic pass that keeps a project's verification skill and feature map honest: parallel source readers per feature, one live session driving every feature, at most one PR of proven corrections. Use for /skill:maintain-verification-skill or "audit the verify skill".
-
theoklitosbam7 Bundle Maintain Verification SkillPeriodic pass that keeps a project's verification skill and feature map honest: parallel source readers per feature, one live session driving every feature, at most one PR of proven corrections. Use for /maintain-verification-skill or "audit the verify skill".
-
summersec Skill Ponytail AuditWhole-repo audit for over-engineering. Scans the codebase and ranks what to delete, simplify, or replace with stdlib/native equivalents. Use when the user asks to audit a repo for bloat, unnecessary abstractions, redundant dependencies, or "what can I delete from this codebase".
Audited -
arthjean Bundle Rust DoctorDeep analysis of Rust projects — scan with rust-doctor CLI, triage by priority, read source context for each finding, apply senior Rust reviewer expertise, produce before/after fixes, verify score improvement. Triggers on "scan", "health check", "rust-doctor", "code quality", "audit this Rust project".
-
arthjean Bundle Security ReviewComprehensive security audit of code changes. Analyzes changed files for OWASP Top 10 vulnerabilities, injection flaws, authentication issues, secrets exposure, and insecure patterns. Produces a structured report with severity ratings, confidence scores, and actionable remediations. Use when the user says 'security review', 'security audit', 'check for vulnerabilities', 'OWASP check', 'is this safe', 'check my code', 'vulnerability check', '/security-review', or asks to review code for security issues. Do NOT trigger for general code quality reviews, refactoring, or non-security concerns.
-
profpowell Skill SecurityWrite secure web pages and applications. Use when handling user input, forms, external resources, authentication, or implementing security headers and CSP.
-
novuhq Skill Env SetupCreate or update Novu environment variables in the user's project safely (never expose the secret key to the client). Complements the official Novu skills by covering project-level env configuration.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include aiken-dex-security-audit-operator, project-standard-audit, delete-ai-words. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.