Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
op0ai Skill Convex Helpers PatternsGuide for convex-helpers library patterns including Triggers, Row-Level Security (RLS), Relationship helpers, Custom Functions, Rate Limiting, and Workpool. Use when implementing automatic side effects, access control, relationship traversal, auth wrappers, or concurrency management. Activates for triggers setup, RLS implementation, custom function wrappers, or convex-helpers integration tasks.
-
0xranx Skill Security ReviewSystematic checklist and process for reviewing code for security vulnerabilities
Audited -
shekerkamma Bundle SecurityCreate security architecture diagrams using PlantUML syntax with identity, encryption, firewall, and compliance stencil icons. Best for IAM flows, zero-trust models, encryption pipelines, and threat detection architectures.
-
mark393295827 Skill Workflow AuditUse when manual work, prior sessions, or an operator interview must be audited for repeatable skill, automation, or bounded-loop candidates.
-
othmanadi Skill Gmira SlopUse when a built page needs the audit for the visual tells no detector catches, or when someone says a page looks generic, templated, bland, stock, or "AI-made" and cannot say why. Run it before showing any surface to the user, and again after a redesign pass. Detects uniform section rhythm, the three-column reflex, one crop ratio everywhere, accent-as-confetti, identical section entrances, the icon-plus-heading-plus-two-lines feature card, the ghost card, grids that truncate real content to stay even, decorative chrome standing in for data, a full-bleed effect turned down until it does nothing, and single-registry house style. Produces a findings table with severity that says what should happen, plus a specificity score per section.
-
recusive Skill Full AuditFull Spectrum Audit
-
recusive Skill Audit As Dx EngAudit an implementation plan through the eyes of a Developer Experience (DX) Engineer. Use this skill when the user says "audit as DX", "DX review this plan", "review the developer experience", or any plan that adds user-facing features to a developer tool — CLI commands, error messages, configuration, onboarding, keyboard shortcuts, tool output, or API surfaces. Orbit is a developer tool; its users are developers. This lens catches the usability issues specific to developer tools that generic UX audits miss because they don't think like a developer using a tool.
-
recusive Skill Audit As UX EngAudit an implementation plan through the eyes of a UX Engineer. Use this skill when the user says "audit as UX", "UX review this plan", "review the user experience", or any plan that changes how users interact with the product — new features, flow changes, navigation, onboarding, error states, modals, dialogs, or multi-step processes. This lens catches usability issues, broken mental models, missing feedback, and interaction patterns that look fine in code but confuse real users.
-
recusive Skill Audit As Prod ReadinessAudit an implementation plan for Production Readiness. Use this skill when the user says "audit for production", "production review this plan", "will this work in prod", "is this production ready", or any plan that's about to ship — especially features involving data persistence, process lifecycle, error recovery, environment configuration, or user-facing workflows. This lens catches the failures that only appear in production — environment differences, missing error recovery, deployment gaps, and the "works on my machine" syndrome.
-
recusive Skill Audit As Repo MaintainerAudit an implementation plan through the eyes of a Repo Maintainer. Use this skill when the user says "audit as repo maintainer", "review conventions", "check code hygiene", "review the file structure", or any plan where you want to verify it follows the project's established patterns — barrel exports, file placement, naming conventions, import ordering, style reuse, code deduplication, and lint compliance. This lens catches the slow erosion of codebase health that individual feature reviews miss because each violation seems minor in isolation.
-
sid-surange Skill Commit History AuditAudit a branch's full commit history for commit hygiene — WIP commits, squash candidates, merge commit policy violations, subject length, and optional convention compliance — before opening a PR. Triggered by "audit my commits", "check commit history before PR", "are my commits clean", "commit-history-audit".
-
sassy-dog Skill Send ItShip a PR end-to-end — worktree audit, freshness gates, pre-flight CI guardrails, template-compliant PR body, commit, push, watch checks, merge, clean up. Use when the user says "send it", "ship it", "open the PR", "create a PR", or asks to merge a branch. Reads the current repo's settings from `.claude/sassy-dog/send-it.md`; run `setup-config` if that file is missing.
-
sassy-dog Bundle Whats BehindThis skill should be used when the user asks "what's behind", "what needs a bump", "what's out of date across our repos", "which products are lagging", "who's on an old version", "portfolio dependency audit", "audit our dependencies across products", "are any products falling behind", "version drift", "which repos have stale actions", "keep the runners updated", or wants a cross-repo currency check spanning EVERY repo in a portfolio rather than one repository. Compares each repo's pinned GitHub Actions, toolchain versions, runner labels, and Dependabot coverage against its peers, then reports which repos are lagging and whether the cause is a missing automation config. Read-only — never edits pins, never opens PRs. For things that are broken or stalled rather than merely old, use whats-on-fire; for single-repo prioritization, use that repository's own survey-work skill.
Audited -
sassy-dog Bundle Whats On FireThis skill should be used when the user asks "what's on fire", "what's on fire today", "what's broken", "what's broken across our products", "what's stuck", "what's red", "anything burning", "portfolio status", "portfolio health", "how's the portfolio looking", "which product needs attention", "cross-product status", "any leaked secrets", "security exposure", or wants one cross-product sweep of production failures and stalled work spanning EVERY repo in a GitHub org rather than a single repository. Pulls Sentry issues and cron monitors, org-wide open issues and pull requests, failing workflows, Dependabot exposure, and structural blind spots (products with no error monitoring, no alerting, or no dependency scanning), then ranks them across products and routes each one to the owning repo. Read-only — never files issues, never mutates state. For deep single-repo prioritization, defer to that repository's own survey-work skill.
-
sassy-dog Bundle Github SecretsThis skill should be used when the user asks to "set a GitHub secret", "add a GitHub variable", "configure secrets for a workflow", "list GitHub secrets", "fix missing secrets in CI", "set up environment secrets", "add org secrets", "debug empty secret values in GitHub Actions", or any task involving GitHub Actions secrets, variables, or environment configuration. Also triggers when editing .github/workflows/ files that reference secrets.* or vars.* contexts.
-
adrigm06 Bundle Flutter SecurityGlobal critical override authority for Flutter security. Use whenever credentials, tokens, PII, secure storage, SSL pinning, obfuscation, root detection, or sensitive data handling is in scope. Can override convenience, performance, and UX.
-
adrigm06 Bundle Flutter Code ReviewLead authority for Flutter code review and tech debt assessment. Use when reviewing PRs, auditing codebases, prioritizing refactoring, or synthesizing findings across architecture, security, performance, and testing domains.
-
clearsmog Skill QAAdversarial quality audit loop. Critic finds issues, fixer applies fixes, loops until APPROVED (max 5 rounds). Works with any document format.
Audited -
cmdr-chara Bundle Review And Refactor CodeReview a defined diff or code area for actionable defects and integration risks, assess structural problems, and plan or execute behavior-preserving refactors through traceable evidence and incremental verification. Use when a user asks for code review, change-risk analysis, maintainability assessment, cleanup, decomposition, or refactoring. Do not use for general repository mapping, unknown runtime failures, version or schema migrations, security-only review, platform-wide production audits, or final release approval.
-
cmdr-chara Bundle Verification And ReleaseBuild a risk-based verification strategy and decide whether an integrated change is ready to release from traceable test, CI, coverage, operational, security, compatibility, and rollback evidence. Use when the question is what must be proven or whether a completed change can ship. Do not use to implement the feature, diagnose an unknown failure, or treat a green checkmark as sufficient evidence by itself.
Audited -
cmdr-chara Bundle Delegate With Mission CardsDelegate independent, bounded repository work to specialized reader and writer subagents using mission cards, exclusive write ownership, staged fan-out, and parent-side verification. Use for parallel exploration, reviews, research, isolated implementation, tests, migrations, or security-sensitive work. Do not use when work is small, tightly coupled, ambiguous, or cannot be independently verified.
-
cmdr-chara Bundle Typescript Quality EnforcerAudit and strengthen TypeScript/JavaScript type-evidence and lint discipline, stage adoption of deterministic anti-slop Oxlint rules, and remediate approved violations without laundering diagnostics. Use when a repository needs stronger TypeScript/JavaScript quality enforcement, unsafe type escape-hatch cleanup, anti-slop adoption, or systematic reduction of casts, unknown/any contracts, module mocking, and boundary-parsing debt. Do not use when the primary task is a concrete bug investigation, a known dependency/runtime migration, a measured performance bottleneck, an ordinary bounded refactor, a non-TypeScript platform audit, or final release approval.
Audited -
csfuwwc Bundle Skill VetterSecurity review protocol for Codex skills before installation, update, or execution. Use when the user asks to install, import, convert, trust, audit, review, or run a third-party skill from ClawHub/OpenClaw, GitHub, a zip/archive, pasted files, or any unknown source; also use when evaluating whether a skill is safe for Codex.
Audited -
dojocodinglabs Skill Course AuditAuditoría de curso contra framework completo. Use when user asks to "audit my course", "review my syllabus", "check course quality", "auditar curso", "revisar mi syllabus", "validar curso", "/course-audit".
-
dojocodinglabs Skill Session Plan AuditAuditoría de plan de sesión 1-on-1 contra framework Irby (2018) coach/mentor/tutor + agenda time-boxing + reflection quality. Use when user asks to "audit my session plan", "review session plan", "auditar sesión", "/session-plan-audit".
-
elastic Bundle Docs Frontmatter AuditAudit Elastic documentation files for frontmatter completeness and correctness. Checks products, description, and navigation_title fields across a directory. Use when auditing docs metadata, checking frontmatter quality before publishing, or validating a batch of files.
-
elastic Bundle Docs Kibana Release NotesConvert raw Kibana release notes tool output into Stack release notes (Elastic Observability or Elastic Security) using GitHub PR context and prior release notes. Use when drafting or editing Stack 9.x release notes from the Kibana release notes generator output.
-
eliasmalmsandberg Skill Google Ads KeywordsWhen the user wants help with Google Ads keyword research, keyword strategy, match types, search term analysis, keyword planning, keyword organization, or keyword audits. Triggers on 'keyword research', 'keyword strategy', 'match types', 'search terms', 'keyword planner', 'keyword audit', 'broad match', 'phrase match', 'exact match', 'keyword expansion', or 'keyword list'. For deep negative keyword optimization, wasted spend elimination, or cannibalization prevention see google-ads-negative-keywords. For building search campaigns see google-ads-search. For bid management on keywords see google-ads-bidding.
-
eliasmalmsandberg Skill Google Ads Audit EcommerceWhen the user wants to audit a Google Ads account for an ecommerce business — reviewing ROAS, Shopping campaigns, product feed health, PMax, cart abandonment retargeting, and revenue-focused optimization opportunities. Triggers on 'ecommerce audit', 'Google Ads audit ecommerce', 'shopping audit', 'audit my ecommerce account', 'ROAS audit', 'product feed audit', 'ecommerce account review', 'PMax ecommerce audit', or 'review ecommerce Google Ads'. For general account audits see google-ads-account-audit. For lead gen audits see google-ads-audit-leadgen.
-
eliasmalmsandberg Skill Google Ads Ad Extension AuditWhen the user wants to audit Google Ads ad extensions or assets across an account — finding coverage gaps, underperforming extensions, outdated copy, or missing extension types on specific campaigns. Triggers on 'extension audit', 'asset audit', 'missing extensions', 'extension coverage', 'sitelink audit', 'callout audit', 'review my extensions', 'extension performance review', 'which campaigns are missing extensions', or 'improve extensions'. For extension strategy, copy frameworks, and best practices see google-ads-ad-extensions.
-
entpnomad Skill Solution AnalysisProduct fitness and solution validation for bootstrapped founders. Assesses whether THIS specific solution is the right way to address a validated problem — value proposition clarity, solution-problem fit, minimum product achievability, differentiation reality, switching motivation, time-to-value, retention potential, and substitute vulnerability. Use when user runs `/solution-analysis`, asks about "is this the right solution", "product-market fit", "differentiation", "MVP scope", "time to value", "substitute threat", "should I build this", "solution validation", or needs to evaluate whether a specific product approach is worth building.
-
justnau1020 Skill IncidentGuide through security incident or outage response. Use when there is a security incident, the service is down, or there is a production emergency.
-
justnau1020 Skill Dep AuditRun a security audit and dependency check on project dependencies. Use when you want to check for vulnerabilities, audit packages, or update outdated dependencies.
-
justnau1020 Skill Hygiene AuditRun a comprehensive codebase hygiene audit. Spawns a team of recon and research agents to analyze structure, dependencies, inconsistencies, and industry best practices, then synthesizes findings into an actionable refactoring plan with phased implementation.
-
karozi Bundle Small BatchesAudit roadmaps, backlogs, and release plans for batch-size pathology — big-bang releases, quarter-long requirement queues, work that integrates at the end — and re-cut them into small shippable slices with learning checkpoints. Use when a release keeps slipping, when work sits done-but-unshipped, when integration happens in one painful merge, or when the user says small batches, why is this release taking so long, re-slice, batch size, big bang release, or WIP is piling up. Not for sprint mechanics, capacity planning, or personal productivity batching.
-
kw12121212 Bundle Spec Driven ReviewReview the code quality of a spec-driven change. Checks readability, security, performance, and best practices before archiving.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include convex-helpers-patterns, security-review, security. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.