Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
austintgriffith Bundle Evm Audit Chain SpecificChain-specific EVM quirks for Arbitrum, Optimism, Base, zkSync, Blast, BNB, Berachain and other L2s. Covers block.number behavior, sequencer downtime, address aliasing, retryable tickets, opcode differences, gas fee variations, and PUSH0 support. Load when deploying to any non-mainnet EVM chain.
-
austintgriffith Bundle Evm Audit Precision MathPrecision loss, rounding errors, division ordering, fixed-point math, and mathematical edge cases in Solidity. Load this for EVERY audit — math bugs are the
-
baserproject Bundle Basercms Security AdvisorybaserCMS のリポジトリセキュリティアドバイザリ(GHSA・triage含む)対応を、一覧取得→指摘検証→課題別の修正→プライベートフォーク/ブランチ/PR作成→ローカル検証まで一気通貫で扱う手順とスクリプト。「セキュリティアドバイザリを確認」「triageの脆弱性を検証」「アドバイザリごとにフォークとPRを作って」「脆弱性修正をプルリクにまとめて」等のときに使う。Copilot/GHAはアドバイザリforkで使えないためローカル検証(/code-review・basercms-unittest)を正とする点、push反映待ちリトライ、共有ファイルのhunk分割、base追従の定番競合解決を収録。
Audited -
baserproject Skill Basercms5 Claude Workflow SetupbaserCMS5(CakePHP5)の開発・移行を Claude Code で進めるときに、着手前に一度参照する「推奨ワークフロー環境セットアップ」スキル(提案ベース・実行は opt-in)。「5系プラグインの開発や移行をこれから始める」「どう進めるのがベストか」「設計→計画→実装の進め方/環境を整えたい」「パーミッションを整理して Auto mode で進めたい」等のときに最初に参照する。superpowers brainstorming での設計、permissions-audit でのパーミッション整理、その上での Auto mode 利用、spec/plan の Markdown プレビュー、brainstorming→plan プレビュー→spec 書き出しの順序を、強制せず"提案"する(やるかはユーザー判断、既に整っていればスキップ)。技術的な実装パターンは basercms5-plugin-development / basercms5-theme-development(共通ルールは basercms5-development)、移行の書き換えは basercms-plugin-4-to-5-upgrade / basercms-plugin-5x-update、テスト実行は basercms-unittest を参照。
Audited -
zxr-roro Bundle Pwn Chain从逆向走到可用利用 (Working Exploit) 的全链路工程化方法。 适用场景:拿到了二进制 + 漏洞点 + 目标环境,需要写出一个能稳定打通的 exploit(不是只能本地复现一下、远程一打就崩的脚本)。 覆盖三大方向:栈溢出 / 堆利用 / 内核 pwn。强调"CTF 本地通 → 真实远程稳定打通"的工程差距:libc 版本错配、堆喷射时序、SMEP/SMAP/KASLR、栈对齐、远程缓冲。 核心工具链:pwntools + GEF/pwndbg + ROPgadget/Ropper + one_gadget + libc-database + qemu-system 内核调试。 触发关键词:pwn、栈溢出、堆溢出、ROP、ret2libc、ret2csu、one_gadget、libc-database、堆利用、tcache、fastbin、unsorted bin、kernel pwn、kROP、SMEP、SMAP、KASLR、modprobe_path、pwntools、GEF、pwndbg。
-
zxr-roro Bundle API SecurityAPI 安全测试
-
zxr-roro Bundle Firmware Pentest固件 / IoT 渗透链。从拿到一坨 .bin / .img 开始,闭环走完逆向 → 提取 → 模拟 → 利用。 方法论遵循 OWASP FSTM 九阶段;工具链以 binwalk v3、unblob、EMBA、Firmadyne、AFL++ 为主。 适用场景:路由器/摄像头/智能家居固件审计、固件升级包逆向、IoT CVE 复现、嵌入式 0day 挖掘。 触发关键词:固件、firmware、IoT、binwalk、unblob、UART、JTAG、squashfs、UBI、JFFS2、Firmadyne、QEMU 全系统仿真、EMBA、固件渗透、路由器固件、嵌入式漏洞利用、bootloader、NVRAM、FAT、firmware analysis toolkit。
Audited -
zxr-roro Bundle Patch Diff ExploitN-day 补丁差分到利用。从厂商发布的补丁里反推漏洞点、写 PoC、做成可用的攻击模块。 适用场景:已知 CVE 编号但只有补丁没有 PoC、SRC/红队需要打击未及时更新的资产、N-day 武器化、Patch Tuesday 跟进。 核心方法:拿 before/after 二进制 → 对齐符号 → 二进制 diff → 看新增的安全检查反推 bug class → 写 PoC 触发漏洞。 触发关键词:N-day、Nday、补丁差分、patch diff、patch tuesday、1day、binary diff 漏洞、bindiff 利用、ghidriff、Diaphora、补丁分析、CVE 复现、漏洞还原、补丁反推、N-day 武器化。
-
zxr-roro Bundle Supply Chain Security# Supply Chain Security Testing
-
fellipeutaka Bundle NginxNginx web server and reverse proxy expert: configuration, reverse proxying, load balancing, SSL/TLS termination, rate limiting, caching, gzip compression, WebSocket proxying, and security hardening. Use for nginx.conf creation/review, performance tuning, HTTPS setup, upstream configuration, and troubleshooting.
-
azborgonovo Skill ParetoProcesses the user's request through the Pareto Principle. It ranks the causes that generate most of the outcome, spends roughly a fifth of the effort on the interventions that address them, and reports what that effort bought. This skill is user-only: it runs only when the user invokes /pareto [request]. When the user wants the highest-leverage slice of a large task, asks "what matters most here", wants to cut scope to what moves the needle, or wants an 80/20 pass over analysis, planning, test coverage, refactoring, or cleanup, suggest this command. Do not use it for work whose value depends on being complete, such as a security fix, a compliance change, a migration, or a specific reported bug.
Audited -
azborgonovo Skill Review Feature SuiteReviews a whole suite of `.feature` files against each other and reconciles them. This is cross-file consistency auditing for Gherkin and BDD. Makes sure that the suite holds one shared language across files, reuses step phrasing instead of duplicating it, carries no contradictory or redundant scenarios, and stays consistent in tags, naming, and data. Use whenever the user has several `.feature` files, in a Cucumber, SpecFlow, Behave, or plain Gherkin suite, and wants to audit, align, reconcile, or de-duplicate them as a set. Use it also when the user says "our features use different words for the same thing", "do these scenarios contradict each other", "find duplicate steps across our features", or "make our feature files consistent". To author or refine one feature on its own, use a single-feature skill such as define-behavior where one is available.
Audited -
yesterday-ai Skill Plan Eng ReviewReview execution approach for feasibility, architecture, data flow, edge cases, test coverage, performance, and security risks. Auto-detects mode: concept-mode reviews a pitch (OFFICE-HOURS.md) for technical feasibility before any scaffolding; milestone-mode reviews slice-plans (M###-S##-PLAN.md) before plan-task. Use concept-mode optionally after plan-ceo-review to sanity-check the pitched approach; use milestone-mode after slice-milestone to lock architecture before implementation. Thin ytstack wrapper around the vendored gstack plan-eng-review procedure.
-
yesterday-ai Skill Check ConsistencyAudit ytstack internal consistency. Compares README (source of truth) against docs/concept.md, .ytstack/DECISIONS.md, and actual plugin content (skills/, hooks/, agents/, artifacts). Reports drift: missing or extra skills, workflow mentions that do not resolve to real skills, trigger-map gaps, hook-list mismatches, skill-count drift, banned-words hits. Run before approving doc changes or after a vendor subtree pull. Does not fix anything -- humans decide how to reconcile.
-
hermeticormus Skill Site Perf AuditSite Performance Audit & Fix
Audited -
hermeticormus Skill Claude Md OverhaulAudit and improve a Claude Code memory layer end-to-end. Measures CLAUDE.md and MEMORY.md against Anthropic's documented caps (200 lines per CLAUDE.md, 200 lines OR 25 KB for MEMORY.md auto-load), surveys project portfolio on disk vs memory coverage, finds sync conflicts in ~/.claude/, identifies gaps tier-by-tier, and executes improvements under bias-to-action with cap-fitting verification at each step. Use when CLAUDE.md/MEMORY.md "feel bloated", when memory feels invisible in fresh sessions, or as periodic hygiene (~monthly).
Audited -
mrmaxie Bundle Audit Skill PortfolioInventory an installed skill portfolio, distinguish aliases from identity conflicts, and recommend evidence-backed routing or consolidation actions. Use only when explicitly requested and remain read-only.
Audited -
danmossa Bundle Spacetimedb AuthUse when implementing SpacetimeDB authentication or authorization, including SpacetimeAuth, Auth0, Clerk, OIDC, auth claims, subject/issuer checks, custom claims, roles, row-level security, and rejecting client connections. Triggers on: auth, authentication, authorization, SpacetimeAuth, Auth0, Clerk, OIDC, claims, RLS, row-level security.
-
discountry Skill DebugApply this skill whenever the user asks to debug, review, audit, or find problems in code — regardless of language or framework. Triggers include: "find bugs in this", "review my recent changes", "something is wrong but I don't know where", "check for security issues", "audit my commits", "why is this slow", "what am I missing in my tests", or any request to investigate correctness, safety, or performance. Prioritize recently modified files, staged changes, and the latest commits — the bug is almost always in what just changed.
Audited -
discountry Skill IgnoreGenerate or update a .gitignore file based on the current project stack and tools. Use when the user invokes /ignore or asks to create, fix, or audit a .gitignore for the current repository.
-
duthaho Skill FactcheckAdversarial citation and claim audit for any document — "do these sources actually say what the text claims?" Takes a markdown file, URL, or pasted draft (including this repo's own pulse/verdict briefs), extracts every checkable claim, then fans out verifier sub-agents instructed to refute, not confirm: does the cited link resolve AND assert the claim as stated, is the source primary or a laundered secondary write-up, has the claim gone stale. Emits a graded audit table — VERIFIED / MISATTRIBUTED / UNSUPPORTED / STALE / UNCHECKABLE — with a quoted passage as evidence for every grade, saved to out/factcheck/. Advisory: it grades, the human edits. Use when the user wants to check citations, verify sources, or audit a report, post, or brief — e.g. "/factcheck <doc>", "verify the sources in this", "are these citations real?", "is this actually true?". For researching a fresh topic use pulse; for judging code changes use done.
-
dylanpulver Bundle Audit SkillEvaluate any skill against a quality rubric. Checks trigger crispness, scope discipline, conflict detection, and description quality. Use when reviewing skills, evaluating external skills before adoption, or improving existing skills.
-
dylanpulver Skill Skill GovernanceManage your Claude Code skills ecosystem. Use when asked to index skills, audit skill quality, list installed skills, check for skill conflicts, or manage the skills system.
-
dylanpulver Bundle Continuous ImprovementAudit a codebase for improvements, implement the best ones as PRs with auto-review and merge safety analysis. Loops in user for approval at key moments.
-
ericluo04 Skill BibcheckAudit an existing .bib entry by entry against Crossref, OpenAlex, arXiv, and Zotero for wrong years, mis-cited authors, wrong venue or volume, dead DOIs, and hallucinated entries. TRIGGER on "/bibcheck", "audit my .bib", "verify my references", "check my bibliography", "are any of these citations fake", "did Claude hallucinate a citation", or a pre-submission bib audit.
-
shiosos Skill Maintain Verification SkillPeriodic pass that keeps a project's verification skill and feature map honest: parallel source readers per feature, one live session driving every feature, at most one PR of proven corrections. Use for /maintain-verification-skill or "audit the verify skill".
-
uzysjung Bundle Audit Harness FitAudits the resident steering layer — CLAUDE.md/AGENTS.md and its `@import` chain, `.claude/rules/`, hooks, permission rules, and the skill descriptors preloaded every session — against the published authoring checklist. INVENTORY measures what loads; EVIDENCE gathers block logs and correction history; VERDICT maps each section to the documented include categories and exclude list, then rules keep / rewrite / relocate / delete; RELOCATE moves procedures to skills, must-hold guarantees to hooks and permission rules, derivable facts back to code; APPLY proposes and waits for approval. Use when the user says any of "하네스 정리", "룰·훅이 밥값을 하는지", "CLAUDE.md 다이어트", "상주 컨텍스트 정리", "룰이 너무 많아", "훅이 실제로 뭘 막고 있는지" — or "harness audit", "trim my CLAUDE.md", "are my rules earning their keep", "prune the steering layer", "why does Claude ignore my rules". Do NOT use it after a specific defect recurred (that is recurrence-prevention), or for drift between the product's docs and its code (that is audit-service-gaps DRIFT).
-
uzysjung Bundle Audit Service GapsAudits the observable gaps between a service as it is today and an explicit target state, then researches how reference services actually solved each high-ranked gap before proposing a fix. DETECT scans through three independent lenses — north-star alignment, correctness (bugs), and user-perspective (UX) — and enumerates concrete, severity-ranked gaps; BENCHMARK verifies how a reference service closes each one and PROPOSES a differentiated close. VERIFY, CHANGE-IMPACT, DRIFT and FULL extend the same loop to post-fix closure, baseline changes, doc-vs-code drift, and the whole-service sweep. Use when the user says any of: "북극성 기준으로 부족한 점", "갭분석", "다른 벤치마크 서비스는 이 부분을 어떻게 해결했는지", "레퍼런스 서비스랑 비교해서 부족한 점 찾아줘" — or the English "gap analysis", "benchmark against reference services", "audit this service". Do NOT use it to *define* product direction (that is north-star), to review ONE standalone artifact's prose (that is multi-persona-review), or to turn an unverified benchmark claim into a fact.
-
uzysjung Bundle Multi Persona ReviewA panel-review skill that critiques ONE artifact (launch post, README, doc, markdown, plan, design) via 3-5 disjoint user-perspective personas running in parallel, then synthesizes deduped, severity-ranked improvement points (P0/P1/P2). Use when the user says "작성글을 사용자 관점의 페르소나를 여러명 만들어서 (손넷 모델정도로) 피드백 받아바", "다면 리뷰 해볼까", "페르소나로 리뷰", "여러 관점으로 피드백", or in English "multi-persona review", "review this from different user perspectives", "get persona feedback on this post/README/doc", "panel review this artifact". Lighter than a full service audit — point it at ONE artifact, not a whole codebase. Do NOT use it for a whole-service or whole-codebase audit, nor for a gap-vs-benchmark loop (both are audit-service-gaps), and do NOT simulate diversity by renaming reviewers that inspect the same evidence.
-
uzysjung Bundle Recurrence PreventionWhen the same defect, mistake, or incident happens AGAIN — a recurrence, not a one-off — verify it against prior evidence (memory, rule case tables, git/CHANGELOG history), classify it as a simple slip vs a complex harness problem, then escalate the countermeasure one level up the ladder: record (1st) → forced rule with a case table (2nd) → structural gate — test, hook, or derive — once prose has failed (3rd+). Complex problems get countermeasure candidates designed by a multi-persona panel instead of a quick patch. Use for "재발했어", "같은 실수 또 했네", "이거 저번에도 그랬잖아", "재발방지 대책 등록해줘", "재발방지 룰 만들어", "this happened again", "same bug as last time", "add a recurrence countermeasure", "postmortem this failure". Do NOT use it for a first-time defect (fix it, record it, stop), do NOT create a standing rule from an unverified first occurrence, and do NOT use it as a general audit of the steering layer at rest.
-
nahisaho Bundle Security Auditorsecurity-auditor skill Trigger terms: security audit, vulnerability scan, OWASP, security analysis, penetration testing, security review, threat modeling, security best practices, CVE Use when: User requests involve security auditor tasks.
-
nahisaho Bundle Constitution EnforcerValidates compliance with 9 Constitutional Articles and Phase -1 Gates before implementation. Trigger terms: constitution, governance, compliance, validation, constitutional compliance, Phase -1 Gates, simplicity gate, anti-abstraction gate, test-first, library-first, EARS compliance, governance validation, constitutional audit, compliance check, gate validation. Enforces all 9 Constitutional Articles with automated validation: - Article I: Library-First Principle - Article II: CLI Interface Mandate - Article III: Test-First Imperative - Article IV: EARS Requirements Format - Article V: Traceability Mandate - Article VI: Project Memory - Article VII: Simplicity Gate - Article VIII: Anti-Abstraction Gate - Article IX: Integration-First Testing Runs Phase -1 Gates before any implementation begins. Use when: validating project governance, checking constitutional compliance, or enforcing quality gates before implementation.
Audited -
0x0w1 Bundle Conformance AuditUse to check whether a repository's history actually followed the jig procedure: conventional squash subjects, Release-Grade trailers on unreleased work, version tag format and placement, the main/develop fast-forward invariant, and a committed rubric. Read-only, exits non-zero on violations, and runs in CI.
Audited -
pdbjork Skill Stripe Best PracticesGuides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial accounts, integration surfaces (Checkout, Payment Element), migrating from deprecated Stripe APIs, and security best practices (API key management, restricted keys, webhooks, OAuth). Use when building, modifying, or reviewing any Stripe integration — including accepting payments, building marketplaces, integrating Stripe, processing payments, setting up subscriptions, creating connected accounts, or implementing secure key handling.
-
arogyareddy Bundle Audit Agents SkillsAudit Claude Code agents, skills, and commands for quality and production readiness. Use when evaluating skill quality, checking production readiness scores, or comparing agents against best-practice templates.
-
witooh Skill Attack TestFires abuse/hack paths over HTTP against a running stack (local/SIT) after the happy path works. Hunts money-moves, authz bypass, proof forge, and idempotency leaks; reports each finding with reproduce steps plus a fix that names the file/check to enforce. Use when the user says try hack, attack-test, probe the flow, security probe HTTP, or asks whether skipping step X still transfers or completes a protected action. Not for static latent hunts (`bug-hunter`), gate audits (`falsifying`), diff review (`code-review`), or AC-driven e2e (`e2e-playwright`).
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include evm-audit-chain-specific, evm-audit-precision-math, basercms-security-advisory. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.