Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
l4ci Skill Hv QAQA the built product — not the diff. Use on "/hv-qa", "run QA", "test the feature", "validate the build", before ship as a gate, or on first cycle to scaffold a per-repo strategy. Detects testing surfaces per repo (web, API, CLI, mobile, lib), picks runners (Playwright, smoke, contract, lighthouse, ZAP, axe), and produces a scored report with executable pass/fail results plus audit-style usability findings. Strategy is per-repo in .hv/qa/<repo>.md so the skill never hardcodes "browser". Modes — first-run (probe + propose strategy), run (execute strategy, emit verdict), restructure (audit strategy files). Opt-in gate via ship.qa.
-
latchagent Skill Enclave MerkleBinary Merkle tree utility with domain-separated hashing for the Latch Enclave attestation system. Provides O(log n) inclusion proofs and consistency proofs for tamper-evident audit logging. Use when working on Merkle roots, audit event proofs, log consistency verification, or attestation store Merkle integration.
-
latchagent Skill Enclave AttestationAudit logging and session attestation for the Latch Enclave. Covers hash-chained proxy audit events, Merkle tree proofs, session receipts, PR annotations, and tamper-evident logging. Use when working on audit trails, session receipts, compliance proofs, inclusion proofs, PR annotation, or the attestation engine.
-
latchagent Skill Enclave Latch ProxyPer-session HTTP proxy for the Latch Enclave. Gates outbound requests by domain/service, injects credentials, enforces path/method scoping, scans for credential leaks, logs all traffic for audit. Use when working on proxy lifecycle, network gating, leak prevention, or enclave session setup.
-
nono911 Bundle ReviewUse for a general objective code, diff, PR, or fix review without edits; use architecture-review or security-review when either is the primary assessment objective.
-
nono911 Bundle Fix FindingsUse when validated review, audit, QA, or security findings are the primary work queue and must be corrected and verified; use implement for a general requirement or feature.
-
nono911 Bundle Security ReviewUse when security is the primary assessment objective for code, configuration, architecture, identities, data handling, or a change set; use review for a general defect review.
-
nvidia-omniverse Skill Ovstorage Operator Monitor BrokerUse when wiring observability for a running ovstorage-broker - covers the Prometheus /metrics surface, the 11 metric families, the tracing span fields, and the audit-safe diagnostic shape.
Audited -
nvidia Bundle Audit CIRun and analyze Elements cold CI performance profiles and propose evidence-backed build, test, lint, and dependency-graph improvements. Use whenever asked to profile or benchmark pnpm run ci, rerun ci:profile, create a CI performance audit, compare CI timings, find bottlenecks or the completion path, investigate a CI performance regression, or recommend measured CI/build optimizations.
2.2k -
nvidia Skill Audit CodeComprehensive code review process for Elements monorepo changes. Provides structured feedback on type safety, testing, documentation, and adherence to project guidelines. Use this skill whenever the user asks you to review code, check staged changes, look at a diff, give feedback before committing, review a PR or merge request, or assess code quality. Trigger on phrases like "review these changes," "check this code," "give feedback," "look at the staged files," "review this PR," or "before committing."
2.2k -
nvidia Skill Authoring BenchmarksDesign, implement, run, debug, and interpret browser performance benchmarks for Elements components and utilities. Use whenever the user asks to benchmark or performance-test runtime code, create or update a .test.bench.ts file, compare benchmark results, investigate a browser performance regression, understand Vitest bench metrics such as throughput, mean, p99, RME, or samples, or add a test:bench task. Do not use this workflow for whole-CI profiling; use the audit-ci skill instead.
2.2k -
outthislife Skill Audit OnlyRead-only investigation mode: answer and report findings first, change no code until told to go. Use when the user says audit, investigate, "don't touch code", or asks a plain question.
-
shhac Bundle Seam AuditMap a codebase's module boundaries: enumerate modules, chart the import edges between them, and produce a layered topology diagram plus a review list of accidental hubs, cycles, and layer violations. Read-only. Use when assessing whether abstractions sit at the right boundaries, verifying a refactor improved them, or mapping an unfamiliar codebase. Not for intra-module refactoring, bug hunting, or feature work.
-
shhac Skill Dep Multi ReviewReview code changes from multiple specialist perspectives in parallel. Use when you want a thorough review of a PR, branch, or set of changes covering security, performance, correctness, edge cases, and ripple effects. Spawns parallel reviewer agents that each focus on a different lens, then synthesizes into a unified review.
-
skillist-io Skill Security AuditAudit code changes for common vulnerabilities — injection, XSS, auth gaps, and secret exposure.
Audited -
skillist-io Bundle Web Perf AuditAudit web application performance using Core Web Vitals, Lighthouse-style checks, and actionable remediation steps. Includes scripts and reference thresholds for LCP, INP, and CLS.
Audited -
whamp Bundle Repo CleanupAudit and safely remove obsolete Git worktrees, repository-owned temporary artifacts, and inactive development databases.
-
whamp Bundle Omarchy Free Disk SpaceSafely audit and reclaim disk space on Omarchy and Arch Linux systems. Use when asked to free up disk space, clean an Omarchy computer, find what is using storage, audit disk usage, clean Arch package caches, or check Snapper disk usage.
Audited -
berabuddies Skill SecuritySecurity
-
kellymears Skill GistManage GitHub gists — create, list, view, edit, and delete. Use this skill when the user wants to create a gist, share a snippet, save code to a gist, list their gists, view or read a gist, edit/update a gist, or delete one. Also triggers when the user pastes code and asks to "gist this", "share this snippet", or "save this somewhere". Gists are created as **private** (secret) by default — only made public when the user explicitly asks.
-
legioncodeinc Bundle Aeo Audit Stinger100-page AEO audit: llms.txt presence, per-engine AI-crawler robots.txt access (GPTBot, PerplexityBot, ClaudeBot, etc.), citation-relevant structured data, subjective topical alignment. Wave W5.
-
legioncodeinc Bundle Audit Intake StingerRuns the four-question intake, scaffolds the shared audit workspace, hydrates every template with the answers. First Bee in every engagement, no authorization-capture step by design.
Audited -
legioncodeinc Bundle Blog Content StingerBonus, conditional blog audit: 10 recent posts, word count, subjective quality read, AI-authorship reported only as a probability band with method and error rate, never a verdict. Wave W6a.
Audited -
legioncodeinc Bundle Master Website AuditorFallback orchestrator for harnesses without native command dispatch. Activates the same 20 Bee/Stinger pairs as /perform-website-audit, same order, same shared workspace.
-
legioncodeinc Bundle Performance Cwv StingerCDN/caching-header audit plus Core Web Vitals scoring for an external site, from an outside unauthenticated posture. Cross-linked with lighthouse-pagespeed-stinger, not duplicated. Wave W5.
Audited -
legioncodeinc Bundle Social Presence StingerFacebook/LinkedIn/Instagram presence audit via the harness's own browser tooling, opt-in auth per platform; decline or unavailable auth is a silent no-op, never a score penalty.
-
legioncodeinc Bundle Ecommerce Catalog StingerBonus, conditional ecommerce audit: up to 25 products, schema.org Product metadata completeness (quantified) plus subjective copy/conversion quality, kept separate. Wave W6b.
Audited -
legioncodeinc Bundle Web Security Posture StingerExternal, passive security-posture audit: headers, TLS coarse-check, cookies, CSP, injection surface, payment-path integrity. Highest-weighted category (20%); a critical leaf caps the grade at C.
-
liarmttt Bundle Code Quality WorkflowEnd-to-end code quality workflow for evidence-backed code review, full repository reviews, architecture reviews of software and character-card systems, refactor decisions, authorized minimal changes, and verification. Use for 全量审查、架构审查、全量架构审查, code or diff audits, cleanup triage, or a scoped quality fix. Preserve coverage gaps and keep audit-only requests read-only.
Audited -
mikeng-io Bundle Bridge GeminiReference adapter for Gemini CLI. Read by any orchestrating skill via the Read tool. Defines how to invoke Gemini CLI in non-interactive mode, timeout estimation, and fallback behavior. Usable by deep-council, deep-review, deep-audit, or any future skill that needs Gemini-based review.
-
mikeng-io Bundle Debate ProtocolGeneric structured adversarial protocol for review, audit, research synthesis, and brainstorm/design councils. Supports finding validation plus proposal brainstorming lifecycles, packetized exchanges, and auditable manifests for nested councils.
-
mikeng-io Bundle Domain RegistryReference library of domain definitions used by deep-* skills to select appropriate expert agents. Not invocable standalone — read via the Read tool by context, deep-audit, deep-verify, deep-review, deep-research, deep-explorer, and deep-council.
-
netboxlabs Skill Netbox Review IntegrationReview and audit NetBox integration code for correctness, performance, and reliability. Use when reviewing scripts or applications that interact with NetBox APIs, checking for pagination bugs, authentication issues, performance anti-patterns, error handling gaps, and SDK misuse.
Audited -
szotasz Bundle Kanban Audit4 óránkénti kanban-tábla audit. Tisztítás (7+ napos done archiválás) + beakadt task-ok számon kérése (előző audit óta nem mozdult in_progress -> ping az assignee-nek).
Audited -
taubyte Skill Enforcing Taubyte ConstraintsNumbered catalog of the non-negotiable Taubyte rules — naming, push ordering, domain CLI-management, matcher consistency, function layout, build/runtime env placement, and Dream vs remote build triggers — with one-line statements and cross-links to the skill that owns each rule's deep coverage. Use as a final pre-push checklist, when reviewing a teammate's change, or when you need a single audit point that touches every "must / never" rule across the collection.
-
truefoundry Bundle Truefoundry SecretsManages TrueFoundry secret groups and secrets. Handles listing, creating, updating, and deleting secret groups and individual key-value secrets.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include enclave-merkle, web-perf-audit, security-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.