Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
ozrwayne Bundle Rw Claim Audit逐条核验论文、报告或研究笔记中的事实性主张是否被指定来源原文支持,保存主张位置、来源指针、原文定位、判断和阻断状态。Use when the user asks for“检查引用是否支持这句话”“做 claim-to-source audit”“核验数字、趋势或因果说法”“投稿前查主张”,or requests the rw-claim-audit workflow.
Audited -
ozrwayne Bundle Rw Citation Audit核对文内引用、参考文献、作者身份、年份消歧、DOI 和指定格式规则,不判断来源是否支持主张。 Use when the user asks for “检查引用格式”、“核对文内引用和参考文献”、“检查同姓作者”、“做 citation audit”, or requests the rw-citation-audit workflow. Runs without a private local workspace or preset research-lab; use user-provided material and bundled public-source methods.
Audited -
ozrwayne Bundle Rw Statistics Audit审查研究中的分析单位、重复层级、统计方法和结果报告是否对得上,不把报告审查当成重新分析。 Use when the user asks for “检查统计报告”、“核对 n 和重复实验”、“审查统计方法和结果”, or requests the rw-statistics-audit workflow. Runs without a private local workspace or preset research-lab; use user-provided material and bundled public-source methods.
Audited -
pipecat-ai Skill MaintenanceToggle the server-side login killswitch on a Supabase environment. Usage `/maintenance <env> <on|off>` (e.g. `/maintenance prod on`). Sets or unsets the `MAINTENANCE_MODE` secret on the login edge function, which short-circuits new logins with HTTP 503 when enabled. Existing sessions keep working.
-
qiao-925 Skill Skill Audit对指定 SKILL.md 进行静态审查。在修改任何 SKILL.md 后自动触发,或手动调用审计某个 skill。检查 frontmatter 规范、description 质量、正文结构与类型一致性、冗余内容。关键词:skill审查、skill-audit、审计、静态检查、frontmatter、description、类型一致性。
-
rhyssullivan Skill Warden Security ReviewRun Warden security scans in this repo using Sentry's warden-skills. Use when asked to audit security, scan with Warden, investigate authz/data-exfil/code-execution/GitHub Actions risks, or triage Warden findings.
-
rlajous Bundle ReviewPerform a comprehensive code review on a GitHub pull request. Use when the user asks to review a PR, review code changes, check a pull request for quality, security, bugs, or best practices, or provides a PR number or GitHub PR URL to review.
Audited -
rubicon Bundle Codebase MemoryUse the codebase knowledge graph for structural code queries. Triggers on: explore the codebase, understand the architecture, what functions exist, show me the structure, who calls this function, what does X call, trace the call chain, find callers of, show dependencies, impact analysis, dead code, unused functions, high fan-out, refactor candidates, code quality audit, graph query syntax, Cypher query examples, edge types, how to use search_graph.
-
rubicon Bundle Secret Santa GeneratorGenerate Secret Santa assignment lists from participant names and optional exclusion pairs. Use when the user asks to organize a Secret Santa, assign recipients, resolve duplicate names, or validate exclusion constraints.
-
securityskills Skill Soc2 ReadinessPrepare an organization for a SOC 2 Type I or II audit — trust services criteria mapping, evidence collection, control implementation, and remediation planning. Use when starting a SOC 2 journey or preparing for an audit window.
-
securityskills Skill JWT Security ReviewAudit JSON Web Token implementations for algorithm confusion, weak secrets, missing validation, and token lifecycle flaws. Use when a codebase or API uses JWTs for auth.
-
securityskills Skill Secure Code ReviewPerform a security-focused code review — map trust boundaries, audit input paths and auth flows, and use vulnerability-class-driven checklists instead of line-by-line skimming. Use on any PR or codebase with security implications.
-
securityskills Skill Owasp Top10 AnalysisSystematically review a web application against the OWASP Top 10 vulnerability classes with concrete test cases per category. Use for web app assessments and security gate reviews.
-
securityskills Skill AI Change EvidenceTurn changes authored by AI coding agents into evidence an auditor accepts — provenance, authorization, and mapping to change-management controls. Use when agents contribute to code that falls under SOC 2, ISO 27001, PCI DSS or similar.
-
securityskills Skill Pentest Engagement MethodologyExecute an authorized penetration test end-to-end, from scoping and rules of engagement through reconnaissance, exploitation, post-exploitation, and reporting. Use when planning or running an offensive security engagement.
-
securityskills Skill Active Directory Attack PathsEnumerate and exploit common Active Directory misconfigurations such as Kerberoasting, AS-REP roasting, delegation abuse, and ACL attacks. Use during authorized internal network assessments.
-
wilbeibi Bundle Code ReviewReview a diff, package, or API through one of five lenses (necessity and layering, honest invariants and costs, product-versus-library fit, a complexity gate before a design change, or newcomer clarity). Use when asked to review, audit, or polish code, vet a dependency, judge whether a change is too complex, or find what a new hire would not understand.
-
wilbeibi Bundle Skill CuratorAudit a skill library for duplicated guidance, contradictions, bloat, dead references, and defects. Use when cleaning, consolidating, or de-duplicating a skills tree.
-
winhok Bundle Testspec Audit只读审计 TestSpec TestLib 的结构健康、重复用例、模块错放、provenance 缺失和未验证历史导入。用户说「审计 TestLib」「检查知识库质量」「清理重复用例前先盘点」「TestLib 被污染了」「历史用例是否可信」「找出该废弃或合并的用例」或执行 testspec-audit 时使用。只输出证据和 lifecycle proposal,不修改 TestLib。
Audited -
yaojingang Bundle Yao Geo Page AuditDiagnose a website page or small page set for GEO readiness with authoritative public evidence, systematic page analysis, code/content/schema fixes, and four-format Chinese report delivery.
Audited -
yaojingang Bundle Yao Geo Panorama Audit当用户需要基于品牌官网抓取、公开事实交叉验证、内容资产诊断、站内站外 GEO 机会地图、项目启动诊断、季度复盘或投放前评估时使用;不用于问答平台采样监测、单页诊断、文章写作、标题生成、后端归因或执行路线图拆解。
Audited -
brianv1981 Bundle Aim AuditEvolving product-truth audit: one living artifacts/AUDIT_<SLUG>.md, update in place (aim-handoff rules), never dated _REAUDIT/_AUDIT3 novels. Modes baseline|delta|closeout|event. Use for audit, re-audit, /aim-audit, or when the Operator asks how a target is doing vs its README.
-
isnoobgrammer Bundle Skill CreatorCreates new skills, improves/refactors/audits existing ones, and ensures SIP compliance across the ecosystem. Use whenever the user wants to create a skill from scratch, turn a workflow into a skill, edit or audit a skill, add SIP composability, or discuss skill architecture — including when they describe a repeatable workflow and say 'I wish this was automatic'. Triggers on: '/create-skill', 'make a skill', 'turn this into a skill', 'new skill', 'improve this skill', 'audit this skill'.
-
antgroup Bundle Code ReviewSystematic code review patterns covering security, performance, maintainability, correctness, and testing — with severity levels, structured feedback guidance, review process, and anti-patterns to avoid. Use when reviewing PRs, establishing review standards, or improving review quality.
-
antgroup Bundle Pr ReviewerAutomated GitHub PR code review with diff analysis, lint integration, and structured reports. Use when reviewing pull requests, checking for security issues, error handling gaps, test coverage, or code style problems. Supports Go, Python, and JavaScript/TypeScript. Requires `gh` CLI authenticated with repo access.
-
eugenezhangco-spec Skill Memory AuditMemory Audit — Self-Cleaning Memory Lint
-
eugenezhangco-spec Skill Weekly ReviewRuns a structured weekly review session where the assistant asks the user about their week, updates all context files, audits backlogs, and sets priorities for next week. Use this skill whenever the user says 'let's do the weekly review', 'weekly review', 'weekly check-in', 'let's review the week', 'end of week review', or 'how did this week go'. Also activates when the user wants to audit and clean up context files, update stale metrics, or align on priorities. Do NOT use for daily planning (use day-planner). This is the assistant and user sitting down once a week to get everything current.
-
enuno Skill Source Command SecurityRun security scans and vulnerability checks
1 -
acquia Skill Meo Cdn SecurityUse when managing MEO CDN domains, security rulesets, IP rules, custom security rules, rate limiting rules, failover groups, or purging CDN cache for a subscription or environment.
Audited -
acquia Skill Security UpdatesUse when user asks about fixing security vulnerabilities, composer audit failures, vulnerable Drupal packages, or CVE advisories in a Drupal codebase.
Audited -
arogyareddy Skill Eval SkillsAudit all skills in the current project for frontmatter completeness, effort level appropriateness, allowed-tools scoping, and content quality. Produces a scored report with effort-level recommendations for each skill. Use when onboarding to a new project, reviewing skill quality before shipping, or adding effort fields to an existing skill library.
Audited -
arogyareddy Bundle Token AuditAudit Claude Code configuration to measure fixed-context token overhead and produce a prioritized action plan
-
elastic Skill Review And Enable Migrated AlertsUse when obs-migrate created Kibana alerting rules and the user asks whether they can enable them, verify them, review connectors/actions, audit migrated rules, or safely roll alert rules into production.
-
s-hiraoku Skill Vscode Extension ExpertThis skill provides expert-level guidance for VS Code extension development. Use when implementing new extension features, debugging extension code, designing WebView UIs, implementing Language Server Protocol features, or optimizing extension performance. Covers activation events, contribution points, VS Code API patterns, security best practices, testing strategies, and publishing workflows.
-
aws-samples Skill Generate V3Generate all security control artifacts and compliant IaC templates from mapping-results.json and validated.json. Split into 3 focused sub-skills for better accuracy; this skill orchestrates them.
-
aws-samples Skill Generate DetectiveGenerate detective and responsive security control artifacts — Config rules with Lambda handlers, EventBridge rules, CloudWatch alarms, SSM runbooks, Step Functions workflows, CloudTrail configuration. Reads from mapping-results.json and validated.json.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include source-command-security, yao-geo-page-audit, yao-geo-panorama-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.