Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
marine-softdrink524 Skill Security AuditorApplication security expert that performs thorough security audits including OWASP Top 10 analysis, dependency scanning, authentication review, and vulnerability assessment. Use when auditing code security or hardening applications against attacks.
Audited -
rhythmmittal19 Skill ReviewReview current branch changes for bugs, security, and quality before merging.
-
victoraurelius Skill Quality AuditDùng khi user nói 'audit', 'quality check', 'kiểm tra chất lượng', 'điểm chất lượng', 'ready to merge?', 'persona coverage', hoặc trước khi merge một wave/feature lớn vào main. Chấm điểm 11 categories /110 điểm (10 tech + 1 persona coverage).
-
victoraurelius Bundle Repo StatusUse when the user says 'status', 'repo status', 'tình trạng repo', 'health check', 'is the repo OK?', 'security', 'CVE', 'vuln', or when starting a conversation that needs a quick remote-repo assessment. Checks: CI, PRs/branches, audit gaps, GitHub Security (Dependabot + code-scanning + secret-scanning) → output level GREEN/YELLOW/ORANGE/RED/BLACK.
-
victoraurelius Bundle API Contract AuditDùng khi user nói 'api audit', 'contract check', 'kiểm tra API', 'endpoint match docs?', 'breaking change?', hoặc trước release. Verify API endpoints match api-contract.md /100.
-
victoraurelius Bundle Business Logic AuditDùng khi user nói 'business audit', 'logic check', 'kiểm tra business logic', 'code đúng rules chưa', hoặc trước GA release. Verify code implement đúng rules.md + use-cases.md. 5 categories /100.
-
victoraurelius Bundle Design Pattern AuditDùng khi user nói 'design pattern audit', 'pattern check', 'kiểm tra design patterns', 'God service đâu', 'anti-pattern hotspot', hoặc trước một refactor planning cycle. Score code against `.claude/rules/design-patterns.md` §3 BANNED list. Output: hotspot list (file path + LOC + violated pattern) + score /100.
-
victoraurelius Bundle Thesis Citation ExtractDùng khi user nói 'extract citations', 'trích dẫn luận văn', 'audit thesis cite', 'verify bibliography', 'orphan citation check', 'kiểm tra cite luận văn', hoặc khi review thesis chapter trước defense. Parse `[N]` cite keys từ thesis chapters + verify chéo với `documents/<thesis-dir>/references/bibliography.md` → báo 3 bucket: matched / orphan-body (cite không có entry) / orphan-bib (entry không cite).
Audited -
zhonghao1995 Bundle Swmm Modeling MemoryRead historical Agentic SWMM experiment audit artifacts and summarize repeated assumptions, QA issues, failures, missing evidence, run-to-run differences, lessons learned, and controlled skill update proposals. Use downstream of swmm-experiment-audit when multiple audited runs exist or when a user asks for modeling memory, failure-pattern extraction, lessons learned, or human-reviewed skill refinement proposals.
Audited -
aidevgtm Skill The HomepageStructure a dev-tool homepage that converts developers into champions. Use when the landing page is written for the buyer instead of the developer, reads as salesy, buries what the product does, or makes it hard to start. Pairs with the ShipReady homepage audit.
-
pietz Bundle Code AuditStructural health assessment for codebases. Use when the user asks to audit code quality, assess code health, review a codebase, find technical debt, clean up code structure, or identify refactoring opportunities. Also use when asked to do a "code audit", "codebase review", "quality assessment", or "tech debt analysis". Provides parallel multi-lens analysis via sub-agents with specialized checklists for code health, cross-module coherence, refactoring detection, and security.
-
redis Skill Dead DependenciesFind and safely remove unused ("dead") npm dependencies in RedisInsight using a grep + leaf-check + build-gate recipe. Use when cleaning up dependencies, investigating whether a package is still used, removing a suspected leftover, or when the user mentions dead deps, unused dependencies, dependency cleanup, leftover packages, or "is this safe to remove". Complements the weekly vulnerability audit (`scripts/dependency-audit-report.mjs`), which only reports vulnerabilities.
-
remix-run Skill Write GuidesWrite, rewrite, or audit Remix guide chapters in the voice of docs/guides/app/actions/docs/chapters/01-start-here.md. Use when drafting app guides, revising generated-sounding prose, tightening guide examples, preserving doc anchors, or reviewing Markdown chapters under docs/guides/app/actions/docs/chapters/.
-
remix-run Skill Write API DocsWrite or audit public API docs for Remix packages. Use when adding or tightening JSDoc on exported functions, classes, interfaces, type aliases, or option objects.
-
romiluz13 Skill Deal StrategistDiagnoses stuck deals and builds a 3-move recovery strategy using MEDDPICC scoring and targeted frameworks. Use when: deal is stalled, competitive threat identified, single-threaded, or process has stopped. Triggers: deal strategy, deal review, stuck deal, advance this deal, competitive play, challenger approach, deal health, how do I win this, competitive strategy, how to advance, deal blocked, reframe strategy.
-
skills-il Bundle Israeli Employment Contract ReviewerNot legal advice. Pre-signing red-flag audit of an Israeli employment contract (chozeh avoda) from the employee's defensive perspective. Scans a pasted contract for illegal clauses, missing mandatory protections, and unfair terms, then produces an annotated review with citations to Israeli labor law. Flags Section 14 (Saif 14) waiver traps, unenforceable non-competes, hoda'at mukdemet below statutory minimum, missing pension, missing keren hishtalmut, at-will language, and gross vs net ambiguity. Produces a negotiating points memo for the employer. Use when about to sign an Israeli employment contract and wanting an independent review before committing. Do NOT use for generating new contracts (use israeli-employment-contracts), post-hire workplace rights (use israeli-workplace-rights-navigator), payroll calculations (use israeli-payroll-calculator), or unemployment benefits (use israeli-unemployment-benefits-navigator).
Audited -
linuxfoundation Skill Lfx General Code ReviewThe general code-review method for LFX local reviews — correctness, security, data privacy, error handling, simplicity, naming, DRY, testing, performance and style, over one explicit pinned range, normally the single commit at the branch's tip. Carries no repo-specific rulebook. Loaded by the lfx-local-review host in either harness, headless Pi or a generic Claude subagent. Returns an ordinary Markdown review.
-
linuxfoundation Skill Copilot Code ReviewerSenior review method for lfx-skills pull requests. Use whenever the task is to review a pull request on this repo, whatever it changes.
-
marconae Bundle Speq AuditAudit a speq project's health — spec-library structure, feature/decision-log/plan validation, mission-to-spec sync, unrecorded plans, and gitignore hygiene — then guide fixes. Use when the user asks to audit, health-check, doctor, lint, or sanity-check the specs or repo, or after cloning or inheriting a speq project.
-
marconae Bundle Speq MissionCreate or update specs/mission.md through a Socratic interview; detects brownfield vs greenfield. Use when the user asks to bootstrap or initialize a speq project, write or revise the project mission, or when /speq-audit reports mission drift and seeds this skill with its findings.
-
mekras Bundle AI Setup ApmНастройка, проверка и диагностика APM: публикуемый пакет (`apm.yml`, `.apm/*`, выпуск) или зависимости потребителя (`apm.lock.yaml`, `apm audit`), включая восстановление установки.
Audited -
mekras Bundle AI Audit ProjectИспользуй, когда нужен глубокий аудит правил проекта для агента: `AGENTS.md`, другие инструкции, локальные и глобальные навыки и APM-коллекции.
-
mekras Bundle AI Audit Agents MdИспользуй, когда нужно проверить один или несколько `AGENTS.md` на машинную пригодность, конфликты, лишний контекст и соседние инструкции.
-
mekras Bundle Policy ExportСоздаёт машинное состояние политики проекта.
Audited -
mekras Bundle Event SummaryСохраняет сводку событий проекта.
Audited -
mekras Bundle Project ReviewПроверяет проект и сохраняет состояние проверки.
Audited -
spotify Bundle Account AdminAdminister Spotify Ads API businesses and ad accounts: discover businesses and accounts, inspect or update supported profile and billing fields, create businesses or ad accounts, list members and roles, invite users, assign ad-account access, update roles, cancel invitations, and remove access. Use when a user asks to find an ad account by ID, audit access, onboard an agency or teammate, manage business/ad-account membership, or update supported account identity details.
-
tejovanthn Skill Security PracticesSecurity Practices Skill
-
thalysjuvenal Bundle Changelog PatternsUse when the user asks to generate a changelog, release notes, or delivery notes from ADVPL/TLPP code changes on TOTVS Protheus -- analyzing diffs or a list of changed files, classifying each change (NEW/FIX/CHANGE/REMOVE/REFACTOR), assessing business impact (ALTO/MEDIO/BAIXO), and detecting affected tables. Also triggers on Portuguese phrasing like "gerar changelog", "notas de versao", "documentar entrega", "o que mudou nessa versao", or requests to audit code changes for compliance.
-
triliumnext Bundle Ckeditor5 ReviewingReview or audit CKEditor 5 plugin code in the Trilium (TriliumNext Notes) monorepo, or a PR/diff touching packages/ckeditor5 (including its in-tree plugins under src/plugins/). Use when checking a Trilium CKEditor 5 plugin for correctness and idiom: schema / conversion / command / UI / widget code, CKEditor-specific defects (asymmetric upcast/downcast, unconsumed upcast elements, missing inline-widget position mapping, command refresh/isEnabled bugs, memory leaks, t() gaps, editing/UI split violations), and Trilium integration defects (plugin not registered in plugins.ts, button missing from toolbar.ts, import/file-extension lint failures, wrong augmentation module, wrong DOM assumptions in tests). Pairs with the ckeditor5-plugin-development and ckeditor5-testing skills and delegates their checklists.
-
darbin Bundle Rem SkillBuild, evaluate, improve, and analyze Claude Code skills. Encodes skill-design expertise — description optimization, progressive disclosure via `_references/`, knowledge-delta scoring, archetype selection, anti-pattern detection. ANALYZE mode reads `~/.claude/skill-feedback.jsonl` (populated by `/rem-feedback`), aggregates by skill + mistake_type, and proposes targeted edits — description triggers for misrouted flags, new anti-patterns for missed, severity calibration for over-flagged, Step-0-context for context-ignored, freshness stamps for stale. IMPROVE mode consumes that analysis and applies edits, marking entries `addressed`. Use when the user says "create skill", "new skill", "evaluate skill", "audit skill", "improve skill", "refactor skill", "skill builder", "meta-skill", "analyze skill", "aggregate feedback", "why is rem-X misfiring", "skill report card", "skill health", "skill won't load", "skill not triggering", "skill not firing", "diagnose skill", "skill doctor", "why isn't my skill loading".
-
darbin Bundle Rem TestTest strategy, generation, and quality audit. Analyzes untested code paths, generates tests matching project patterns, reviews existing test quality, and identifies coverage gaps. Use when the user says "write tests", "add tests", "test this", "check coverage", "review tests", or "what's untested".
-
darbin Bundle Rem RefactorSystematic safe refactoring with verification at each step. Resolves DRY violations, splits large files, extracts patterns, removes dead code, and aligns conventions — all while preserving behavior. Use when the user says "refactor", "clean up", "extract", "simplify", "DRY this up", or after rem-audit/rem-review-code identifies issues to fix.
-
darbin Bundle Rem Review CodeCode review for bugs, security, performance, DRY, and maintainability - file-scoped or diff-scoped, not repo-wide. Parallel independent reviewers + a separate verification pass. Auto-detects mode - Plan Verification cross-checks the plan contract against what actually shipped; Diff Review covers recent changes + scope drift; File Review walks listed files. Distinct from rem-audit (repo-wide health) and rem-review-plan (validates the plan BEFORE code). Use for "review code", "review this diff", "review the implementation", "check for bugs", "verify plan was implemented", "review after rem-execute", "code review", or "review these files".
-
dkeken Skill Product DesignOrchestrator for the Product Design skill set — turn early ideas into reviewable prototypes. Routes to the right sub-skill (get-context, research, audit, ideate, image-to-code, url-to-code, prototype, qa, share) based on where you are in the design process. Use when the user gives a high-level design goal like "design a UI for X", "prototype this idea", "rebuild this screen", "review our flow", or isn't sure which design step they need. Delegates to design-* skills.
-
dkolba Skill Verify LayersAudit import dependencies in packages/game to verify they comply with the layered architecture rules
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-auditor, review, quality-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.