Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
sriptcollector Bundle Honest Metrics AuditCheck that every number your UI shows actually means what its label claims, by tracing each displayed figure back to the query that produced it. Catches counts of the wrong entity, stale denominators, placeholder traction, and labels that quietly overstate. Use before a launch, a pricing page, or any screen that shows social proof.
-
sriptcollector Bundle Dependency Outage AuditFind which pages die when a dependency dies — database, cache, or upstream API — and which ones lie about it by returning HTTP 200 with an empty body. Use before a launch, after an incident, when adding a page that fetches data, or when the user asks how their app behaves if the database goes down.
Audited -
studioxvii Bundle Apply ReviewApply a batch of explicit Modbus map decisions while preserving evidence, exclusions, holds, and audit history. Use when the user confirms layout, exclusion, or field decisions and wants them applied to a new reviewed map.
Audited -
syncfusion Bundle Syncfusion Aspnetmvc Security**CONTENT SECURITY POLICY (CSP) GUIDE** — Assist with configuring Syncfusion ASP.NET MVC EJ2 components to work with strict Content Security Policy (CSP) headers. Use when: implementing CSP headers, applying nonces to inline scripts/styles, configuring external font allowlists, or troubleshooting CSP violations and XSS protections.
-
tavily-ai Skill Threat Intelligence EnrichmentEnrich threat intelligence from CVEs, IOCs, malware names, threat actors, vendor advisories, security incidents, exploit reports, vulnerability disclosures, breach news, and mitigation guidance. Use when the user asks to investigate a CVE, enrich indicators, summarize vendor advisories, assess exploit status, collect mitigations, or produce a source-grounded security brief.
Audited -
bolivian-peru Skill Self HealingDetect service failures and system anomalies. Diagnose root causes. Auto-remediate using NixOS rollback, service restart, or config repair. Every action logged to the hash-chained audit ledger.
Audited -
bolivian-peru Skill Morning BriefingGenerate a concise daily infrastructure briefing. Covers: service health, resource usage, security events, overnight incidents, and cost tracking. Designed for Telegram/chat delivery.
-
bolivian-peru Skill Security HardeningContinuous security posture assessment. Scores the system, auto-fixes safe issues, proposes fixes for risky ones. Every change audited.
-
jiahongc Skill Card WalletAudit a multi-card wallet — earning map, credit stack, overlaps, gaps, and total annual cost. Evaluates a user's full card lineup. Covers 11 major US issuers including co-branded hotel and airline cards.
-
lassejlv Bundle Backend Security AuditDefensive backend security review for source code, API servers, auth flows, database access, dependency configuration, secrets handling, file uploads, webhooks, background jobs, and deployment settings. Use when Codex is asked to audit, review, deep research, harden, or find vulnerabilities in a user's own backend or authorized codebase, and to report findings before making fixes.
-
mnox Bundle DebutAudit a personal open-source repo for public-readiness before going public or pushing to its public git history — secrets/PII in history, licensing, README & community-health files, code quality, tests/CI, deps & releases. Produces a scored report (SHIP IT / NEEDS POLISH / NOT READY) with exact fix commands. Use when: '/debut', 'is this repo ready to go public', 'oss readiness audit', 'public-ready check', 'audit my repo before open-sourcing', 'is this presentable', 'pre-publish audit'. Adaptive: full-repo readiness sweep or lighter pre-push diff mode. Draft-only, flag-only — never commits, never auto-fixes, never rewrites history.
Audited -
mnox Bundle Gdpr ReviewUse when auditing a codebase, design doc, IaC, or data-flow map for GDPR compliance - lawful basis, consent validity, data subject rights (access/erasure/portability), retention and deletion, cross-border transfers, processor/DPA posture, privacy by design, breach readiness - OR when assessing organizational GDPR readiness (RoPA, DPIA, DPO, accountability). Triggers - /gdpr-review, GDPR audit, GDPR review, are we GDPR compliant, privacy review, data protection review, right to be forgotten, data deletion audit, erasure audit, consent flow review, PII handling review, DSAR, DPIA, RoPA, EU user data, cross-border transfer check, Schrems, SCCs. Auto-detects input mode, builds a personal-data inventory first, fans out parallel domain agents, and produces structured findings with GDPR article IDs, severity, evidence, remediation, confidence, plus an out-of-scope section for legal-attestation items. Analysis aid, not legal advice.
-
mozilla Skill Fxa ReviewThorough FXA-specific commit review using parallel specialist agents. Covers security, TypeScript, logic/bugs, test quality, and architecture. Agents explore call sites, git history, and monorepo conventions.
-
alexanderop Skill Maintain Verification SkillPeriodic pass that keeps a project's verification skill and feature map honest: parallel source readers per feature, one live session driving every feature, at most one PR of proven corrections. Use for /maintain-verification-skill or "audit the verify skill".
Audited -
heapy Bundle Clean Claude MemoryAudit, prune, rewrite, or relocate Claude Code project memory. Use when the user asks to review, clean, update, or remove Claude memory files, eliminate stale project memories, or rebuild MEMORY.md.
-
phucbm Skill Revise BlockFast structural audit of all blocks or specific blocks — checks required files, wrapper attributes, fields.json timestamp, previewImage, viewScript. No AI, runs instantly via script.
-
phucbm Skill Revise Block DeepDeep AI audit of all blocks or specific blocks — runs structural checks first, then uses AI to review content quality, descriptions, grammar, admin render justification, wrapper usage, and empty-state messages.
-
aircury Skill Spec Kit ChecklistAudit requirement quality across spec.md, plan.md, and tasks.md. Validates that requirements are complete, clear, measurable, and consistent — not that code works.
Audited -
alainator Bundle Auditing CanonVerifies canon status, naming compliance, frontmatter completeness, writing standards, and cross-reference validity across worldbuilding files. Use when checking naming consistency, verifying frontmatter, auditing prose standards, or when user says "canon audit", "check names", "verify frontmatter", "writing standards check", or "naming audit". Does NOT check physics equations — use /auditing-physics for that.
-
alainator Skill Cross CheckingCross-references a specific topic, concept, or rule across all files to verify it is used consistently. Use when checking if a term or claim matches its authoritative definition everywhere, or when user says "cross-check", "is this consistent", "verify this term", or "does this match everywhere". Does NOT audit entire directories — use /auditing-physics or /auditing-canon for that.
Audited -
alainator Bundle Auditing PhysicsChecks science files for cross-layer contradictions, inconsistent equations, broken derivation chains, and violations of the universe's foundational axiom. Use when promoting drafts to canon, after writing new science content, after restructuring, or when user says "audit the science", "physics audit", "check for contradictions", "does this break anything", "verify the science", or "cross-layer check". Does NOT check frontmatter or writing standards — use /auditing-canon for that.
-
alainator Skill Auditing Human AssumptionsScans worldbuilding files for unexamined assumptions — descriptions, vocabulary, and social structures that were imported rather than derived from the civilization's biology, cognition, and environment. Applies to ALL civilizations: alien species get checked for anthropomorphism; human civilizations in novel contexts get checked for assumptions imported from familiar Earth cultures. Use after writing civilization content, during civilization builds, or when user says "check for assumptions", "anthropomorphism audit", "assumption check", "is this too human", "derivation check", "cultural assumption audit", or "did I import this". Reports only — does NOT fix content.
Audited -
anmolnagpal Bundle AppsecApplication-level security review: dependency manifests for known-vulnerable packages, missing HTTP security headers, permissive CORS configuration. Use when user says 'review my dependencies', 'check for vulnerable packages', 'run a dependency audit', 'audit security headers', 'review CORS config', or when working in package.json/package-lock.json, go.mod/go.sum, requirements.txt/poetry.lock, Gemfile.lock, Cargo.toml/Cargo.lock, pom.xml, or server/app config with CORS or header middleware.
Audited -
anmolnagpal Bundle GithubGitHub repository operations: PRs, issues, releases, branch protection, CODEOWNERS, Dependabot, and repo settings audits. Use when user says 'review my PR', 'create a release', 'cut a release', 'tag a release', 'set up branch protection', 'add CODEOWNERS', 'audit repo settings', 'is Dependabot configured', or asks about GitHub repo configuration. Repo settings and metadata, not workflow files; /clouddrove:github-actions owns .github/workflows.
Audited -
ansible Bundle Docs QA AuditAudit documentation coverage against common user questions. Generates a Q&A matrix, searches docs/code for answers, flags gaps, and creates DRs for missing content. Use when asked to "audit docs", "check documentation coverage", "what questions can users answer", or before releases/demos.
-
ansible Bundle Security ScanScan project dependencies and CI workflows for known vulnerable packages. Use when checking for security issues, "scan for vulnerabilities", "check for compromised packages", or after a security advisory is published. Extensible via references/vulnerable-packages.md.
-
archibate Bundle Fable AdvisorConsult an independent read-only Claude Fable advisor when a decision can affect security, privacy, money, data loss, deployment, or public API compatibility; when investigation leaves two plausible directions with materially different consequences; when a consequential completion claim depends on an unverified assumption or critical behavior that normal tests cannot cover; or before claiming completion of a substantial goal, for final code or artifact review and a sanity check, even when local validation passes. Also use when the user requests an independent or Fable review. Skip routine work and cheaply resolvable uncertainty when none of these triggers applies. Fable challenges Codex's reasoning and evidence; Codex retains responsibility for edits and the final judgment.
-
aspectrr Skill Kibana AuditEnable and configure Kibana audit logging for saved object access, logins, and space operations. Use when setting up Kibana audit, filtering events, or correlating Kibana and ES audit logs.
-
aspectrr Skill Elasticsearch AuditEnable, configure, and query Elasticsearch security audit logs. Use when the task involves audit logging setup, event filtering, or investigating security incidents like failed logins.
-
aspectrr Skill Elasticsearch AuthzManage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security. Use when creating users or roles, assigning privileges, or mapping external realms like LDAP/SAML.
-
aspectrr Skill Security Alert TriageTriage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge. Use when triaging alerts, performing SOC analysis, or investigating detections.
-
aspectrr Skill Security Case ManagementCreate, search, update, and manage SOC cases via the Kibana Cases API. Use when tracking incidents, linking alerts to cases, adding investigation notes, or managing triage output.
-
aspectrr Skill Security Detection Rule ManagementCreate, tune, and manage Elastic Security detection rules (SIEM and Endpoint). Use for false positives, exceptions, new coverage, noisy rules, or rule management via Kibana API.
-
aspectrr Skill Elasticsearch Security TroubleshootingDiagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues. Use when the user reports a security error.
Audited -
batur Bundle Build MvpPlan, implement, verify, and prepare the smallest releasable product or bounded first release that delivers one primary end-to-end outcome to a defined early audience and creates measurable feedback. Use when the user says MVP, minimum viable product, first usable release, early release, core product flow, private beta, or asks to turn a validated PoC or prototype into a usable product. Keep non-core features out of scope while retaining essential security, data integrity, validation, error handling, testing, observability, deployment, rollback, and support requirements. Do not use merely to test feasibility; use validate-poc when critical assumptions remain unresolved.
-
batur Skill TS TestingDefines the TypeScript testing standard for AI coding and review. Use when adding, changing, or reviewing tests, test structure, Vitest, Playwright e2e, validation/error/PATCH/auth/security/tenant tests, fixtures, mocks/fakes, coverage, CI test commands, or any behavior that needs test protection.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include backend-security-audit, auditing-human-assumptions, honest-metrics-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.