Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
batur Bundle Documentation AdrUse this skill when creating, updating, or reviewing repository documentation, ADRs, engineering standards, architecture docs, Mermaid diagrams, README onboarding, Copilot instructions, or documentation changes required by architecture/API/security/database/auth/deployment decisions in TypeScript software projects.
-
batur Skill Security BaselineEnforce the project's secure-by-default TypeScript/Node.js security baseline. Use when creating or reviewing authentication, authorization, API endpoints, input handling, CORS, rate limits, secrets, logging, webhooks, file uploads, SSRF-sensitive URL fetching, dependency/security checks, or AI-generated code.
Audited -
chatbotxio Skill Chatbotx BasecodeUnderstand and audit the ChatbotX base code before making changes. Use when asked to scan the project, check architecture, locate ownership boundaries, onboard to the repository, or decide which project-specific skill should handle a task.
-
comfy-org Skill Layer AuditDetect violations of the layered architecture import rules (base -> platform -> workbench -> renderer). Runs ESLint with the import-x/no-restricted-paths rule and generates a grouped report.
-
neversight Bundle Qt UI DesignDesign or audit UI for Qt/QML, Qt projects, web, or embedded MPU or MCU targets. Use when creating screens, layouts, navigation, or auditing UX.
-
neversight Skill Llvm SecurityApply or develop LLVM sanitizers, compiler hardening, and exploit mitigations. Use when secure compilation is central, not for general vulnerability analysis unrelated to the toolchain.
-
neversight Skill Mobile SecurityAnalyze Android or iOS game security and platform protections. Use for APK/IPA, mobile IL2CPP, Frida, root or jailbreak, emulator, mobile kernel, or mobile anti-cheat research.
-
neversight Bundle Dma Attack TechniquesAnalyze PCIe DMA threats, FPGA device behavior, and IOMMU defenses. Use for DMA-specific threat modeling or detection; use windows-kernel-security for kernel mechanisms without a DMA boundary.
-
neversight Skill Game Engine ResourcesResearch game-engine internals, source trees, SDK extraction, plugins, and engine-specific security surfaces. Use for Unreal, Unity, Source, Godot, or custom-engine structure rather than generic cheat techniques.
-
neversight Bundle Game Hacking TechniquesClassify game-cheat implementation surfaces and their defensive implications. Use for authorized threat modeling of memory access, injection, overlays, input, or engine attack surfaces.
-
neversight Bundle Windows Kernel SecurityAnalyze Windows kernel security mechanisms used by drivers and game protection. Use for callbacks, IRQL, kernel memory, PatchGuard, DSE, HVCI, or driver trust; use dma-attack-techniques for PCIe DMA.
-
neversight Skill Awesome Game Security OverviewMaintain the awesome-game-security resource index. Use when adding or reclassifying links, organizing categories, or checking README format; use topic skills for security research itself.
-
kiloloop Bundle Org Memory SynthesisSynthesize org-memory — fold new events into recent.md, promote cross-repo patterns to decisions.md and rules.md, and audit for staleness, cross-file conflicts, and drift. Invoke whenever the user asks "synthesize org-memory", "fold events", "is recent.md stale", "audit org-memory", or any phrasing like "did we synthesize org-memory" — even if they don't explicitly type the slash command.
-
nearai Skill Code ReviewParanoid architect review of code changes for bugs, security, missing tests, and undocumented assumptions. Works on local git diffs OR a GitHub pull request (e.g. `owner/repo N`). For PRs, can post findings as line-level review comments.
-
nearai Skill Parallel Pr ReviewReview a batch or stack of pull requests, or run a recurring PR-review pass on a repo. Best with many PRs, stacked branches, conflicts, or security-sensitive changes. Covers grouping, fan-out to review subagents, verdict synthesis, and posting.
-
tyecode Skill SecurityPassive guardrail that enforces a security checklist for full-stack development. Install globally — automatically runs before any feature touching user input, auth, data storage, or API endpoints is marked complete.
Audited -
tyecode Bundle Secure CommitPre-commit safety check and passive guardrail against sensitive files. Invoke with /secure-commit to scan staged files or audit git history. Install globally to block leaks automatically before every commit.
Audited -
utsabpanta Skill Harden SetupThis skill should be used when the user asks to "audit my Claude Code setup", "check my hooks", "is my .claude config safe", "harden Claude Code for my team", or mentions that a hook does not seem to be firing or blocking. It finds configuration that looks correct but silently does nothing.
Audited -
terrylica Skill Security HardeningRBAC configuration, row policies, quotas, network security, audit logging, and access control best practices.
-
open-mercato Bundle Code ReviewReview code changes for architecture, security, conventions, and quality compliance. Use when reviewing pull requests, code changes, or auditing code quality.
-
skrun-dev Bundle Code ReviewReview code for quality, bugs, security issues, and suggest improvements. Use when asked to review, audit, or improve code.
-
skrun-dev Bundle Semgrep Rule CreatorGenerate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example. Picks an appropriate severity, infers the right CWE/OWASP mapping, and produces a ready-to-commit rule with documentation. Use when asked to draft a Semgrep rule, encode a security pattern, or productize a security finding for the codebase.
Audited -
skrun-dev Bundle Audit Fixture Tool ErrorE2E test fixture — calls a tool that always fails, used to verify tool_call_error events.
Audited -
tarangdeep-goel-by Skill Vault AuditAudit the workflow and vault health. Use when the user says /vault audit to check if skills are being invoked and pushes are happening.
-
thienty1207 Bundle SecuritySecurity
-
hackerfish Skill Dsh Dependency Audit升级或审查项目依赖时使用:审计安全告警、控制安装脚本风险、制定升级回滚预案。
-
hongmaple0820 Skill Security AuditOWASP Top 10 security checklist
-
iamantoniodinuzzo Bundle RetroEnd-of-task retrospective. Gathers verifiable evidence from the session transcript, answers six hard self-audit questions (least confident, what user is missing, most likely 3-month failure, unstated assumptions, smoother session, what worked well — backed by that evidence), auto-persists reusable learnings to memory, flags unintegrated work, and proposes concrete fixes. Use when the user says "/retro", "retrospettiva", "cosa mi sfugge", "self-audit", after completing a significant deliverable (plan, milestone, feature, migration), at the end of `issue-dev` after merge, or before the session's context is about to be compacted.
Audited -
iamantoniodinuzzo Skill Tune SetupOn-demand config & workflow audit. Reads the target project's CLAUDE.md, .claude/settings.json (+.local.json), hooks, and agents/, cross-referenced against transcript evidence (repeated hook injections, hook_cancelled, toolDenialKind breakdown, skill-trigger-miss), and proposes concrete config fixes. Never runs automatically — invoke explicitly with "/tune-setup", "ottimizza il setup", "audit config", or similar. Sibling to `retro` (which audits the session, not the config) — see that skill for end-of-task self-audit instead.
-
iamantoniodinuzzo Skill Audit FeatureOrchestrate a full static audit of a Flutter feature folder across all present clean-architecture layers — domain, data, application, and presentation. Delegates each layer to its dedicated per-layer audit skill (running them in parallel via Explore subagents), then aggregates violations into one grouped report and offers targeted fixes. Falls back to audit-presentation-layer alone when only presentation/ is present (sub-feature or UI-only feature). Use proactively when the user says "audit feature", "audit this feature", "review feature", "audit this feature folder", "check all layers", or "full feature audit".
-
iamantoniodinuzzo Bundle Flutter FlavorsInitialize flavors (dev/stg/prod) in a Flutter project, or audit and fix an existing partial/broken flavor setup — Android (build.gradle.kts, AndroidManifest), iOS (xcconfig, xcscheme, Info.plist), Web (--dart-define WEB_FLAVOR workaround), multiple entry points (main_*.dart), IDE config (VSCode launch.json, Android Studio .idea/runConfigurations), and optional multi-project Firebase (flutterfire configure per flavor). Detects project state first and branches into an INIT flow (flutter_flavorizr with targeted processors, or manual fallback) or an AUDIT+FIX flow against a bundled rule catalog. Use proactively when the user says "aggiungi flavor a questa app", "inizializza flavors", "setup dev/stg/prod", "flutter_flavorizr", "audit flavors", "i miei flavor sono rotti", "add flavors to this Flutter app", "set up flavors", "fix my flavor setup", "flavor configuration is broken", or asks to distinguish flavors from dart-defines.
-
iamantoniodinuzzo Bundle Audit Application LayerAudit a Flutter application-layer file or folder against the project's documented Riverpod v3 notifier rules, async-mutation patterns, and cohesion/coupling rules — Flutter framework imports in application code, datasource bypass (skipping the repository facade), presentation imports, hard-wired repository construction instead of provider injection, god notifiers, redundant manual try/catch in notifiers, mutation methods returning values instead of Future<void>, and unconstrained provider state types. Emits a violations table with file:line and rule ID, then offers to apply fixes. Use proactively when the user says "audit application layer", "audit notifier", "review application layer", "check notifier rules", "find application violations", "audit this notifier", or asks to verify application-layer code against project architecture rules before code review.
-
iamantoniodinuzzo Bundle Audit Presentation LayerAudit a Flutter presentation-layer file or folder (screens, widgets, pages, related widget tests) against the project's documented UI guidelines — Riverpod v3 widget rules, rebuild isolation (const subtrees, scoped MediaQuery, builder child caching, setState blast radius), widget extraction and cohesion/coupling (oversized builds, function widgets, Law of Demeter params, layer/cross-feature imports), Robot Testing pattern, GoRouter conventions, layout antipatterns, side-effect handling, responsive layout (named breakpoints, flex rows, adaptive grids), and web interaction affordances. Platform-aware: auto-detects target platforms from pubspec.yaml and gates rules accordingly; override with --platform=web|android|ios|mobile|all. Emits a violations table with file:line and rule ID, then offers to apply fixes. Use proactively when the user says "audit presentation layer", "audit this widget", "review this widget", "check UI guidelines", "find UI violations", "presentation audit", "lint widgets", or asks to verify
-
imgompanda Bundle Fireauto Secure Guide"보안 점검", "security check", "security audit", "취약점 분석", "vulnerability scan", "보안 감사", "시크릿 노출", "API 보안", "인증 점검", "rate limit" 등 보안 관련 코드 리뷰나 취약점 감사 시 사용하세요.
-
jablonkai Skill Code AnalyzerAudit an entire project for bugs, security vulnerabilities, code quality problems, performance issues, missing tests, documentation gaps, and concrete improvement or feature ideas — then produce a prioritized, actionable report with file:line references. Read-only by default; only edits or commits when the user explicitly asks for a fix afterwards. Use when someone says 'review my project', 'audit the codebase', 'find bugs', 'check for security issues', 'what could be improved', 'suggest improvements', 'are there any vulnerabilities', 'do a code quality review', or the Hungarian equivalents 'nézd át a projektet', 'auditáld a kódot', 'találj hibákat', 'milyen biztonsági problémák vannak', 'javasolj fejlesztéseket', 'mit lehetne javítani'. Trigger this skill whenever the user wants a holistic assessment of a project rather than a fix to one specific thing — even if they don't say the word 'audit'.
-
marine-softdrink524 Skill Code ReviewerThorough code review assistant that checks for bugs, security vulnerabilities, performance issues, and adherence to best practices. Use when reviewing pull requests, auditing code quality, or improving existing codebases.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-hardening, security-audit, documentation-adr. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.