Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
kobogithub Skill Security TrivyContainer and dependency vulnerability scanning with Trivy
Audited -
kobogithub Skill Security GitleaksSecret detection and prevention with Gitleaks
Audited -
kobogithub Skill Security Owasp ZapAPI security testing with OWASP ZAP for FastAPI endpoints
Audited -
hylarucoder Bundle Readme BeautifierReformats and restructures a README or similar Markdown project document without changing its factual content, voice, or scope, then summarizes formatting-only edits. Use when the user asks to beautify, tidy, organize, or professionally format a README(README 美化、排版、格式化、太乱了). Use document-audit skills to judge correctness or consistency, and hai-rewrite-doc when meaning or claims must change.
-
igorwarzocha Bundle Pi Stuff Tool Error AuditRead when auditing tool and Notebook failures across stored Pi sessions or checking recovery since this repo's previous audit.
-
injectivelabs Bundle Injective Docs StyleAudit and report adherence to Injective's documentation standards
-
iulspop Skill Code ReviewReviews code changes for correctness, maintainability, security, and adherence to project conventions. Use when reviewing PRs, auditing recent changes, or getting a second opinion on implementation quality.
-
iulspop Skill Security CheckSecurity audit for web applications based on OWASP Top 10 and common vulnerabilities. Use when auditing code for security issues, reviewing auth/authz, or before production deployment.
-
jamillazarev Skill JoinTake over a repo that already exists — guest or successor read from the ground, the audit before any touch, findings as one classified list, fixes in batches the owner approves.
-
irwebtools Bundle Security ReviewReview secrets, unsafe commands, dependency risk, and permission scope.
-
iskron-ai Skill VahtaВахта — собственный цикл агента в выровненном репо: инбокс роли и живой канал. Триггеры: «вахта», «заступай на вахту», «работай сам», on duty, stand watch, автономный старт с ролью агента в AGENTS.md. Два такта: дешёвый дежурный и дорогой рабочий (постичь→разметить→отгрузить→эстафета→интеграция→сведение→проткать→закрыть). Режим, фокус и канал объявлены; вахта начата, когда может говорить; работа кончается интеграцией. Композирует entry, standing, inquiry, reality-audit, writing, weaving. Нужны iskron_* и AGENTS.md.
-
iskron-ai Skill IntegrityИспользуй для задач интеграции и целостности превращения. Триггеры: «интеграция», «интегрировать X с Y», «спецификация интеграции», integrate, integration spec — режим 0: сначала граф; «область интеграции изменения», integration scope, cold review — режим 1: холон + steward + узлы изменения; «проверь бяньхуа на целостность», «что затронет превращение», «кого заденет», integrity check — волновой фронт; «подкреплено ли графом», «не театр ли», claim audit — обратный аудит прозы. Distinct from assembly и design. Нужны iskron_*.
-
iskron-ai Skill ReconcileДвусторонняя сверка кода и графа — уборочный такт: всюду ли код соответствует графу, а граф — коду; конец каждой сущностной задачи. Триггеры: reconcile, «сверь код с графом», «приведи граф в порядок», «протки свою область», «отдай долги графа», does the graph match the code, tidy the graph. Также: задача, записанная крией; феномен-ярлык состояния; комментарий-портянка, пересказывающая граф. Distinct from weaving (ремонт графа изнутри), integrity (claim-аудит), reality-audit (поведенческие заявки). Композирует entry, writing, weaving. Нужны тулы iskron_*.
-
iskron-ai Skill Reality AuditТерминальная приёмка поведенческой работы — свидетельствование реальностью. Используй после последней содержательной правки, до слов verified/done/green; после поправок владельца или упавших фальсификаторов; когда тест вернул ненулевой код или смешанный вывод. Триггеры: reality audit, «проверка реальностью», «проверь канонический артефакт», tests passed. Заморозь утверждения → канонический носитель и фальсификатор → фейл-клоузд лестница → один вердикт на утверждение. Скретч и печатный вывод — provisional.
-
oprogramadorreal Bundle Code ReviewReviews local changes, an open PR/MR, or a branch diff against the project's own coding guidelines through the review lenses — bugs, security, guidelines, architecture, simplification, plus test coverage and API contracts when relevant — inline on a small diff, in parallel agents on a larger one. Excludes style and linter-catchable issues. Read-only: applies fixes or posts PR/MR comments only on explicit approval. For an iterative auto-fix loop, use /optimus:deep review.
-
u9401066 Skill Security Reviewer安全性審查技能
-
anton-abyzov Skill Sw HandoffWrite a portable, secret-scrubbed handoff doc plus a diff of your uncommitted edits so another tool or machine resumes where you stopped. Use for "handoff", "out of tokens", "switch to Codex".
-
cntwdev Skill Code ReviewThorough code review covering bugs, security, style, and performance
Audited -
codebeltnet Bundle Dotnet Docfx DigestUse when the user wants to create, repair, audit, or complete DocFX docs for .NET public APIs, or has changed public API that needs namespace pages, XML comments, overwrite files, extension-member tables, examples, or build verification. Exclude private/internal APIs.
Audited -
codebeltnet Bundle Dotnet Strong Name SigningUse when the user wants to generate a `.snk` strong-name key, configure `SignAssembly` or `AssemblyOriginatorKeyFile`, or sign a .NET assembly, library, or NuGet package. Do not use for Authenticode, code-signing certificates, or secret-management tasks.
-
contextosai Bundle Review ChangeReview a code change for concrete correctness, security, data-integrity, compatibility, concurrency, and operability regressions by reconstructing intent and checking affected invariants and boundary paths. Use for local diffs, commits, branches, patches, or pull requests when the user wants actionable review findings. Report only defects introduced or exposed by the change with precise evidence; do not modify code unless asked to address findings.
-
contextosai Bundle Triage IncidentTriage an active or recent software production incident by establishing impact, stabilizing the system, preserving evidence, building a timestamped timeline, coordinating hypotheses, and choosing reversible mitigations. Use when users report an outage, severe degradation, security or data-integrity event, broken deployment, elevated errors, or ask for incident command, status assessment, mitigation, or investigation support. Prioritize user harm reduction over root-cause completeness and require explicit authority for production mutations.
-
contextosai Bundle Contextos Run AuditAudit a ContextOS proof-carrying run using RunContext, CompiledContext, ToolEnvelope, DecisionRecord, trace, scorecard, and ReplayPacket artifacts. Use for incident review, launch evidence, or record completeness; do not use for a whole-repository harness maturity audit.
-
crowi Skill Crowi DepsCrowi の security 依存(GitHub Dependabot alerts)を本質的に対応する skill。 「最近 dependency 見てないな」というとき単発 (`/crowi-deps`) で手起動する。 alert 取得 → direct/transitive 分類 → 根本対応(direct は version bump、 transitive は親 bump、親が上げられないときだけ per-major override、major upgrade 待ちは報告のみ)→ pnpm install + lint/type-check/test で検証 → commit (push しない)。crowi-orchestrate の D 系統(watcher)も fix の本体としてここを使う。 キーワード: dependency, dependabot, security, vulnerability, CVE, GHSA, bump, override, undici, nodemailer, npm audit, 脆弱性, 依存更新, セキュリティ
-
crowi Skill Crowi Orchestratemain セッションで /loop から 1 tick ごとに呼ぶ前提のオーケストレーション skill。 (A) ready for merge になった worktree を裏取りして integrate-worktree で取り込む、 (B) specs/ を groom して着手 ready / 不足要素 / 削除候補を報告する、 (C) main に直接積まれた作業が意味のある塊になったら code-review をかける、 (D) GitHub Dependabot security alerts を確認して新規 advisory のみ報告する、 (E) 統合 signal の立っていない停滞 worktree を検知して報告する、 (F) flake-report が起票した flaky-test issue の新規/更新を検知して報告する、 の 6 系統を実行する。push しない・spec を自動削除しない・dirty な main に勝手に commit しない・dep を自動 bump しない・詰まったら ping して待つ。 キーワード: orchestrate, loop, watcher, integrate, groom, spec 整理, code-review, dependabot, security, 停滞, stalled, 統合漏れ, flaky, flake-report, flaky-test
-
mozilla Skill Fxa Review QuickFast single-pass FXA-specific commit review covering security, conventions, logic/bugs, tests, and migrations. No subagents — runs directly in the main context.
-
omarfarahatoglu-tur Bundle API Security ReviewerApi Security Reviewer
Audited -
omarfarahatoglu-tur Bundle Nodejs Security ReviewerNodejs Security Reviewer
Audited -
omarfarahatoglu-tur Bundle Application Security AuditorApplication Security Auditor
Audited -
owasp Skill AI Security VerificationComprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework. Provides structured checklist to verify security and ethical considerations across 13 categories of AI-driven applications, from training data governance to human oversight.
-
owasp Skill Sca AuditScan project dependencies for known vulnerabilities (CVEs). Use when reviewing dependency files (package.json, requirements.txt, go.mod, pom.xml, Gemfile, Cargo.toml, etc.), triaging Dependabot/Renovate alerts, or performing pre-deployment security checks.
Audited -
owasp Skill Secrets ScanDetect hardcoded credentials, API keys, tokens, and secrets in source code and configuration files. Use when reviewing code for leaked secrets before commit/merge, auditing a repository for credential exposure, or setting up secret detection.
-
owasp Bundle Security GuidanceSecurity-first development guidance based on OWASP ASVS (Application Security Verification Standard). Use this skill automatically when planning or implementing any code that touches user input, authentication, data persistence, network communication, file I/O, cryptography, or access control. This skill ensures all generated code adheres to industry-standard security practices with explicit references to applied guidance.
-
owasp Skill Mobile Code ReviewSecurity-focused review of native Android and iOS mobile app source code against OWASP MASVS v2.1.0. Use when reviewing mobile codebases, mobile PR diffs, or auditing a mobile module.
Audited -
owasp Skill API Security ReviewComprehensive API security review against OWASP API Security Top 10 (2023). Use when reviewing OpenAPI/Swagger specs, auditing REST/GraphQL/gRPC implementations, testing authentication mechanisms, or checking API gateway configurations. Covers BOLA/IDOR, broken auth, mass assignment, rate limiting, SSRF, and more with real-world attack scenarios.
Audited -
owasp Skill Web Security ReviewReview web applications against the OWASP Top 10 for Web Applications (2021). Use when auditing web apps, reviewing server-side code, or assessing web frameworks for the classic OWASP Top 10 risks including injection, broken auth, and XSS.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-trivy, security-gitleaks, security-owasp-zap. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.