Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
owasp Skill Code Review SecuritySecurity-focused code review mapped to OWASP Top 10 and ASVS. Use when reviewing pull requests, auditing files or modules for vulnerabilities, or performing pre-merge security gate checks. Covers injection, auth, authorization, cryptography, data exposure, misconfiguration, and deserialization.
Audited -
excelle Skill Trust Signal AuditorNEXUS trust gate: audit domain authority and citation-worthiness across 36 trust signals. 域名信任/权威审计
Audited -
gleanwork Skill Verify RfcVerify an RFC or design doc against the actual implementation — find drift, missing pieces, and undocumented changes. Trigger phrases include "verify the RFC", "compare design doc to implementation", "is the spec implemented", "does the code match the design", "what's drifted from the RFC", "audit the doc against", "spec compliance check", "is what we built what we designed".
-
hainrixz Bundle AdsFree-first paid advertising audit and optimization skill, focused on the 3 platforms where 95% of advertiser spend lives: Meta, Google, TikTok. Guided onboarding (/ads start) saves context once and step-by-step OAuth walkthroughs; continuous coach (/ads next) ranks Quick Wins after each audit. ~158 weighted checks with scoring, parallel agents, industry templates, and AI creative generation.
Audited -
hainrixz Skill Ads NextContinuous coach. Reads the most recent <platform>-audit-results.json files (cwd + ~/.claude-ads/history/), ranks Quick Wins and Critical Issues by impact × ease using the user's saved spend mix, surfaces the top 3 next actions, and optionally walks the user through fixing the #1 right now. Detects regressions vs the previous audit (score drops, new failures) and flags them as Priority 0. Use when user says next, what should I do, recommend, fix, suggest, what's next, qué sigue, recomienda, próximo paso.
-
hainrixz Skill Ads AuditFull multi-platform paid advertising audit with parallel subagent delegation. Analyzes Google Ads, Meta Ads, LinkedIn Ads, TikTok Ads, and Microsoft Ads accounts. Generates health score per platform and aggregate score. Use when user says audit, full ad check, analyze my ads, account health check, or PPC audit.
-
hainrixz Skill Ads LandingLanding page quality assessment for paid advertising campaigns. Evaluates message match, page speed, mobile experience, trust signals, form optimization, and conversion rate potential. Use when user says landing page, post-click experience, landing page audit, conversion rate, or landing page optimization.
-
hainrixz Skill Ads CreativeCross-platform creative quality audit covering ad copy, video, image, and format diversity across all platforms. Detects creative fatigue, evaluates platform-native compliance, and provides production priorities. Use when user says creative audit, ad creative, creative fatigue, ad copy, ad design, or creative review.
-
im-shashanks Bundle Shaktra AnalyzeCodebase Analyzer workflow for brownfield codebases — deep structural analysis producing structured YAML artifacts for downstream agents. Use this skill whenever the user wants to analyze, assess, or understand an existing codebase — including requests like "analyze my codebase", "what's the health of this project", "check for tech debt", "audit dependencies", "understand this codebase before we start", or any brownfield due diligence task.
-
im-shashanks Skill Shaktra Memory StatsMemory system inspector. View learned principles, anti-patterns, procedures, per-story briefings, and seed new entries. Complements status-dash with detailed memory audit capabilities.
-
thienty1207 Bundle Code ReviewRigorous code review methodology — technical review protocols, evidence-based claims, verification gates, security review, performance review, architecture review. Use when reviewing code, requesting reviews, or establishing review processes.
-
m-sec-org Bundle JWT Tool SkillHelp with authorized JWT assessment using ticarpi/jwt_tool. Use this skill whenever the user mentions `jwt_tool`, wants commands for JWT decoding, verification, secret cracking, claim tampering, playbook scans, `alg:none`, key confusion, JWKS spoofing or inline JWK injection, raw-request mode with `-r`, or needs to test bearer-token trust with a real HTTP request. Make sure to use it when the user asks how to audit or exploit JWT handling with `jwt_tool`, even if they only describe the token, headers, cookies, or a captured request and do not explicitly ask for a skill.
-
m-sec-org Skill Known Product Exploit通用已知产品/框架漏洞利用专项技能。适用于 fscan/Nuclei/Wappalyzer 识别出目标运行已知产品(OA系统、CMS、中间件、框架)后的标准利用流程。 核心原则:已知产品必须 Nuclei 先行,不走盲测渗透。覆盖 Nuclei 精准扫描、模板分析、手工验证、环境诊断、命令执行方式选择、NPS 收口。 触发场景:fscan 或手工识别出目标为已知产品(通达OA/致远OA/用友NC/泛微OA/WordPress/Drupal/Tomcat/WebLogic/Shiro/Spring/ThinkPHP/Laravel/ phpMyAdmin/Confluence/GitLab/Jenkins 等)时必须优先使用本技能。
-
marcelinero Bundle Auditoria AmbientalAuditar sistemas de gestión ambiental conforme a ISO 14001, verificación de inventarios de gases de efecto invernadero conforme a ISO 14064 y GHG Protocol, y cumplimiento ambiental aplicable. Activar siempre que se hable de auditoría ambiental, environmental audit, ISO 14001, ISO 14064, GHG Protocol, sistema de gestión ambiental, SGA, aspectos ambientales, impactos ambientales, residuos peligrosos, vertimientos, emisiones, permisos ambientales, licencia ambiental, EIA, evaluación de impacto, ciclo de vida, LCA, biodiversidad, agua, energía.
-
marcelinero Bundle Auditoria OperativaEvaluar la eficiencia, eficacia y economía de procesos operativos, identificar oportunidades de mejora y verificar el logro de objetivos del proceso. Activar siempre que se hable de auditoría operativa, auditoría de procesos, eficiencia operacional, productividad, eficacia, value for money, mejora de procesos, mapeo de procesos, KPIs operativos, BPM, lean, six sigma en auditoría, indicadores de gestión, performance audit, optimización, throughput, ciclo de proceso.
-
marcelinero Bundle Auditoria CumplimientoEvaluar la adherencia de la organización a leyes, regulaciones, normativas internas y compromisos contractuales aplicables, así como la efectividad del programa de cumplimiento. Activar siempre que se hable de auditoría de cumplimiento, compliance audit, regulatory audit, programa de cumplimiento, ISO 37301, ISO 37001, antisoborno, anticorrupción, FCPA, UK Bribery Act, SAGRILAFT, SARLAFT, AML/CFT, lavado de activos, política de cumplimiento, código de ética, conflicto de interés, regaliación, sanciones, due diligence de terceros, oficial de cumplimiento.
-
marcelinero Bundle Auditoria CiberseguridadEvaluar la postura de ciberseguridad de la organización aplicando NIST CSF 2.0, ISO 27001/27002 y CIS Controls — gobernanza de seguridad, identificación, protección, detección, respuesta y recuperación. Activar siempre que se hable de ciberseguridad, cybersecurity audit, NIST CSF, ISO 27001, ISO 27002, CIS Controls, MITRE ATT&CK, SIEM, SOC, EDR, DLP, IAM, MFA, gestión de vulnerabilidades, pentest, red team, ransomware, phishing, NIS 2, zero trust, gestión de identidades, respuesta a incidentes, IR, threat hunting, breach.
-
marcelinero Bundle Auditoria Esg SostenibilidadAuditar reportes y desempeño ambiental, social y de gobernanza (ESG), incluyendo aseguramiento de divulgaciones de sostenibilidad bajo ISSB (IFRS S1/S2), GRI, TCFD y SASB, y la efectividad del sistema de gestión de sostenibilidad. Activar siempre que se hable de auditoría ESG, sustainability audit, reporte de sostenibilidad, ISSB, IFRS S1, IFRS S2, GRI, SASB, TCFD, CSRD, ESRS, doble materialidad, alcance 1, alcance 2, alcance 3, GHG Protocol, huella de carbono, net zero, cambio climático, derechos humanos, debida diligencia ESG, taxonomía verde.
-
marcelinero Bundle Auditoria Tecnologia InformacionAuditar el gobierno de TI, los controles generales de TI (ITGCs) y los controles automatizados de aplicación, evaluar la gestión de cambios, accesos lógicos, operaciones, continuidad y seguridad tecnológica conforme a COBIT, ITAF, GTAGs e ISO 27001. Activar siempre que se hable de auditoría de TI, IT audit, controles generales de TI, ITGC, COBIT, gobierno de TI, gestión de accesos, gestión de cambios, gestión de operaciones, computación en la nube, SaaS auditoría, BCP, DRP, continuidad de negocio, virtualización, ERP, SAP, Oracle, integraciones, interfaces, batch jobs, base de datos auditoría.
-
open-agreements Bundle Soc2 ReadinessAssess SOC 2 Type II readiness. Map Trust Services Criteria to controls, identify gaps, and build a remediation plan. Uses NIST SP 800-53 (public domain) as canonical reference with SOC 2 criterion cross-mapping. Use when user says "SOC 2 readiness," "SOC 2 preparation," "SOC 2 gap analysis," or "prepare for SOC 2 audit."
-
open-agreements Bundle Iso 27001 Internal AuditRun an ISO 27001 internal audit. Walk through controls by domain, identify gaps, collect evidence, and generate findings with corrective action recommendations. Uses NIST SP 800-53 (public domain) as canonical reference. Use when user says "run internal audit," "ISO 27001 audit," "control assessment," "audit findings," or "ISMS assessment."
-
open-agreements Skill Field Selector Quality AuditAudit NVCA field-selector quality: check file inventory, metadata schema, field-to-replacement coverage, ambiguous keys, smart quotes, test fixtures, and fill quality. Produces a structured scorecard per field-selector with maturity tier classification. Use when user says "audit field-selector quality," "check field-selector coverage," "field-selector scorecard," or "NVCA field-selector quality."
Audited -
prostdev Skill How To Generate SecretTell the user the command to generate a random 32-byte hex string for a secret, token, API key, or signing key. Use when the user needs to create a strong random secret.
-
hamr0 Skill SecuritySecurity audit — recurring six, injection, auth, trust boundaries
-
hamr0 Skill Branch ReviewPre-merge review gate. Two stages — **general review** then a **full security
-
sidiangongyuan Bundle Paper Review PanelUse when independently reviewing a research-paper draft before submission, running a mock top-conference panel, assessing readiness or accept/reject risk, or predicting reviewer concerns for venues such as CVPR, ICCV, ECCV, ICLR, NeurIPS, and AAAI. Does not draft or audit author responses after official reviews arrive.
-
sipengxie2024 Bundle Scientific VisualizationPublication-ready data plots for CS papers (systems, ML, networking, security). Use when creating figures with multi-panel layouts, error bars, colorblind-safe palettes, log-scale axes, latency CDFs, throughput curves, training curves, ablation bars, or speedup comparisons for IEEE / ACM / USENIX / NeurIPS / ICML / ICLR submissions. Orchestrates matplotlib, seaborn, and plotly with venue-specific styling and PDF output that drops cleanly into LaTeX. For one-off exploration use seaborn or plotly directly; for system architecture diagrams use tikz-figures or scientific-schematics instead.
Audited -
sipengxie2024 Bundle Game Based Security ProofUse when proving security of encryption schemes, MACs, signatures, PRFs, hash constructions, or other cryptographic primitives, constructing reduction proofs from standard assumptions (DDH, CDH, RSA, LWE), or writing formal game-based security proofs and advantage bounds in academic papers. Covers game sequences and hopping, negligible-advantage arguments, tightness accounting, and turning an informal security claim into a displayed definition, theorem, and proof a reviewer can verify.
-
sipengxie2024 Bundle Simulation Security ProofsUse when proving security of MPC protocols, zero-knowledge proofs, oblivious transfer, commitment schemes, garbled circuits, or any protocol whose security is argued by comparing a real execution against an ideal functionality, in standalone simulation-based or UC frameworks. Covers simulator construction, hybrid arguments, corruption models, composition theorems, and writing the proof section of a cryptographic paper so the ideal-versus-real argument is complete and checkable.
-
soia-team Bundle Soia Dev Audit UI只读验收界面,将布局、键盘等技术证据与 UX、视觉判断分开报告。触发:验收这个界面、检查键盘和布局、评审视觉与体验
-
srfinch17 Skill Paladin ReviewUse when the author is about to ship, merge, push, publish, send, or delete something and wants a reviewer on their side — one who checks whether they are about to hurt themselves (delete the wrong thing, leak a secret, expose something irreversibly), whether they are underselling a real win, and how the work will land with whoever decides their outcome. Also use when asked to "watch my back", "am I about to shoot myself in the foot", "am I underselling this", "protect me from myself", "defuse this before I blow up", or to run a "paladin" review. Runs INDEPENDENTLY of its sibling nemesis-review — reach for the paladin when the risk is to YOUR outcome (a footgun, an under-sell, an irreversible or public step); there is no mandatory pairing, pick by the risk.
-
srfinch17 Skill Guarding Silent FailuresUse when an operation can fail while still returning valid-looking output - CAD/geometry booleans, image and mesh pipelines, renderers, cleanup and migration scripts, bulk edits, data transforms - or when writing the check that is supposed to catch such a failure. Also use when a test, grep, audit or probe comes back clean and that clean result is about to be trusted, when a fix "worked" but nothing visibly changed, and whenever choosing between fixing a magic number and installing an assertion.
-
sriptcollector Bundle Pr ReviewerStructured three-pass review of the working diff (staged + unstaged) — correctness bugs, security, then simplification — with severity-tagged findings and a ship/no-ship verdict. Use when the user asks to review their changes, review the diff, check a PR before pushing, or says "is this safe to ship".
-
sriptcollector Bundle Route Auth SweepEnumerate every API route and prove each one gates before it touches data — authentication, ownership checks, role checks, rate limiting — so no endpoint is accidentally public or leaks another user's records. Use before a launch, after adding routes, during a security review, or when the user asks whether their API is safe.
-
sriptcollector Bundle Empty State AuditFind every screen that looks broken, dead, or dishonest when there is no data yet — rows of zeros, "no results" with no way forward, fake placeholder content, and stats that expose emptiness. Use before a launch, when building a new product, or when the first users are not converting.
-
sriptcollector Bundle Crawlability AuditFind pages search engines cannot reach or will not trust — robots.txt rules that block real content, sitemaps contradicting robots, error pages served as HTTP 200, missing canonicals, and duplicate metadata. Use before a launch, when organic traffic is flat, after changing robots or routing, or when the user asks why a page is not indexed.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include code-review-security, trust-signal-auditor, verify-rfc. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.