Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
dkyazzentwatwa Skill Security AnalystThreat monitoring, security policy, incident response, and posture reporting
-
duhu2000 Bundle Logistics BriefActivate for: logistics, carrier, freight, shipping, route, delivery, on-time delivery, OTD carrier, logistics performance, carrier review, freight cost, cost per kg, lane analysis, route optimisation, logistics brief, carrier scorecard, logistics KPI, shipping performance, freight audit, expedited freight, premium freight, mode of transport, logistics network, carbon emissions, Scope 3 logistics. NOT for: supply network facility placement (use network-design), vendor assessment (use vendor-assessment), spend category analysis (use spend-analysis).
-
duhu2000 Bundle Vendor AssessmentClassifies, scores, and evaluates vendors. Activate for: vendor assessment, classify vendor, vendor classification, Kraljic matrix, vendor tier, bottleneck vendor, strategic vendor, vendor review, supplier assessment, vendor onboarding, new vendor approval, vendor audit, annual vendor review, vendor scorecard, supplier evaluation, vendor qualification, approve vendor, vendor due diligence, vendor health check, vendor performance review, bottleneck supplier, vendor exit, risk profile of a vendor. USE THIS when the task is to CLASSIFY a vendor into a category (Strategic / Tactical / Commodity / Bottleneck), SCORE them across dimensions, or EVALUATE a vendor for onboarding/approval/exit. NOT for: ongoing risk signal monitoring or risk alerts (use supplier-risk), invoice reconciliation (use invoice-reconciliation), carrier performance review (use logistics-brief), spend category analysis (use spend-analysis).
-
ec-cube Skill Eccube SecurityEC-CUBE 4.4 の認証・認可・CSRF などセキュリティを実装・改修・点検するときの規約。「認可を追加して」「アクセス制御を直して」「このルートに権限チェックを入れて」「CSRF対策を確認して」「Voterを作って」「セキュリティ監査して」などと言われたとき、または src/Eccube/Security 配下・app/config/eccube/packages/security.yaml を作成・編集するとき、認可漏れ/CSRF漏れ/IDOR を点検するときに使用する。
-
ec-cube Skill Eccube Twig TemplateEC-CUBE 4.4 の Twig 拡張(Extension/Filter/Function)とテンプレートを実装・改修・点検するときの規約。「Twig拡張を作って」「フィルタ/関数を追加して」「テンプレートを上書きして」「このテンプレートを直して」「XSS/エスケープを確認して」「rawの使い方を点検して」などと言われたとき、または src/Eccube/Twig/Extension・app/template・Resource/template 配下を作成・編集するときに使用する。
-
ec-cube Skill Eccube Review ResponsibilityEC-CUBE 4.4 で実装・改修したコードを実装直後に自己レビューする全層チェックリスト。「責務分離を確認して」「実装後のレビューをして」「Fatコントローラ/Fatサービスになってないか見て」「レイヤ違反がないか確認して」「認可/CSRF/XSSの抜けを確認して」「リファクタの観点を出して」などと言われたとき、またはコントローラ/サービス/フォーム/テンプレート等の実装・改修が一区切りついた直後に使用する。責務分離・セキュリティ・レイヤ違反を横断的に点検する。
-
elliottlawson Skill ReviewReviews a change by running the mission, architecture, implementation, craft, security, and performance passes, then weighing them into a verdict.
Audited -
elliottlawson Skill SecurityJudges whether the change can be abused — auth, injection, secrets, data exposure.
Audited -
ttttstc Bundle Ni Readme GuideCreate, rewrite, beautify, or audit GitHub repository READMEs as a synchronized Chinese-default and English pair, with reciprocal language links, verified functional badges, project-native visuals, real proof, concise quick starts, and maintainable Markdown. Use when a user asks to write, redesign, improve, localize, translate, visually upgrade, or review a README; create README heroes, badges, diagrams, screenshots, or optional GitHub-safe GIF assets; or turn a repository homepage into a clear bilingual project story.
Audited -
upex-galaxy Bundle Pr Review LeadActs as a QA Lead / QA Architect reviewing a pull request's test-automation work against this repo's KATA doctrine (or the target repo's own doctrine, if it has one) and general QA best practices — grounding every finding in a concrete doctrine citation or code location, never a guess. Use whenever the user wants to review, audit, or give feedback on a colleague's or a teammate's PR, whether it lives in THIS repo or an external repo the user points at (owner/repo#PR via gh). Triggers on: revisa este PR, review this PR, revisá este pull request, dame feedback de este PR, actúa de QA lead, haz de QA lead reviewer, audita este pull request, pr-review-lead, revisión de PR externo, review external repo PR, dale feedback a este trabajo de automatización, evalúa este PR contra KATA, is this PR any good, cómo quedó este PR de automatización. Always runs a strictness preflight first (Flexible / Standard / Strict) before analyzing anything, and never posts a comment to GitHub without the user's explicit final OK. Do NO
-
uwuclxdy Bundle Threat ModelingSTRIDE, attack trees, security-requirement extraction, mitigation and control selection, compliance mapping.
-
uwuclxdy Skill Skill Routing AuditAudits a skill for routing gaps: boundary and negative probes that land where the answer is absent.
-
vinceservidad Bundle Shopify Store AuditAudits a Shopify store across customer journey, merchandising, trust, performance, measurement, and operations. Use for whole-store reviews, not a single-page rewrite.
-
vinceservidad Bundle Shopify Product PageAudits and drafts Shopify product-page structure, copy, proof, offer, and mobile UX. Use for a specific PDP or product template, not a whole-store audit.
-
yacb2 Bundle Aidex SkillUse when the user wants an existing or in-progress skill checked or structured against THIS project's house skill conventions — "what are our skill conventions", "review this skill against our standards", "does this skill follow our patterns", "structure this skill the way we do", "audit this skill's front-matter/description for our rules". Not for: creating a skill from scratch, optimizing a skill's description for triggering, or running skill evals (all skill-creator); planning (aidex-plan); decisions (aidex-decision); requests (aidex-request); research (aidex-research); references (aidex-reference); ecosystem audits (aidex).
-
yacb2 Bundle Aidex ReviewUse when the user wants code reviewed as it stands — a module, a feature, a path, or the whole app — rather than a diff or a pull request. Covers correctness/bug hunting, simplification and dead code, exploitable security defects, and performance waste, and it first proposes which finder agents are worth launching and what they will cost. Fires on "review this module", "review the X feature", "find bugs in this module", "what dead code is in X", "can this module be simplified", "security review of this code", "review the whole app", "review the changes since Friday / this weekend" (the changes pick the modules, reviewed as they stand). Not for: reviewing a diff, branch, or PR (the built-in /code-review, /simplify and /security-review already do that); auditing a running system against Lighthouse/OWASP program methodology (aidex-audit); fixing a specific known bug (aidex-bugfix).
Audited -
patrick-fu Bundle DeslopReview or rewrite existing Chinese, English, or mixed-language prose to remove formulaic AI-slop patterns while preserving facts, intent, stance, register, and author voice. Use when the user explicitly asks to deslop, humanize, remove AI writing patterns or AI 味, 说人话, 别像模板/机器人, make text less AI-generated, or audit a draft for those problems. Do not trigger for generic polishing, proofreading, translation, summarization, fact-checking, or drafting from scratch unless deslop is explicitly requested as a step.
Audited -
patrick-fu Bundle Codex Session NamingApply the session title lifecycle to every user-visible top-level Codex App session. Write a stable sidebar headline at entry, rewrite it only when its mandate, gate, or owner makes it false, and audit closure claims. Excludes chats, subagents, and controller-role titles.
-
zszz3 Bundle Dsh Code ReviewReview a branch or pull request for correctness, lifecycle, security, compatibility, and missing behavior using the target repository's own instructions and live base/head rather than DeepSeek Harness-specific commands.
-
zszz3 Bundle Dsh Trim Cot LeakageAudit or rewrite repository prose that exposes authoring-session reasoning, review history, dead draft references, change narration, or unsupported planning residue while preserving every durable technical fact.
-
avinashp Bundle Security AuditAudits code for security vulnerabilities. Use when asked to check security, find vulnerabilities, or audit for OWASP issues.
Audited -
drafael Bundle Java CoderMandatory for every task in a Java codebase, including planning, implementation, debugging, refactoring, review, testing, Maven or Gradle build and dependency changes, performance or security analysis, and Java-related documentation. Detect Java projects from pom.xml, Gradle files, gradlew, or .java sources. Load before inspecting or changing the repository even when the user does not explicitly mention Java. Covers Java 21+, Spring Boot, Swing/EDT, code style, testing, security, and desktop UI.
-
drafael Bundle Code ReviewFind actionable defects and risks through a focused, evidence-based review of correctness, regressions, security, performance, architecture, and testing. Use for requests to review, audit, critique, or identify improvements. Use blast-radius, when explicitly invoked and available, for cross-boundary consequence tracing and executable safety proof of a concrete change. Use explain-code when the user only wants to understand current behavior or architecture.
-
maoyadongsh Skill Secure ReportWrite a source-linked security review report.
-
obra Bundle Maintaining DocumentationUse when documentation needs creating, checking, or maintaining — docs may have drifted from code, pre-release doc verification, updating docs after finishing code work, adding or enforcing project terminology, deciding where a new doc should live, or a routine re-audit of previously verified docs.
Audited 247k -
rimagination Skill Evidence ReviewUse when a ScanSci user wants to verify a claim, audit citations, inspect supporting passages, or assess whether evidence supports a conclusion.
148 -
jiahao-shao1 Skill Context AuditAudit project context management (CLAUDE.md, rules, knowledge) for progressive disclosure compliance. Checks that all knowledge files are reachable from rules, detects stale references, orphaned files, and CLAUDE.md index leakage. Triggers: 'audit context', 'check context', 'context hygiene', 'context audit', '检查 context', '审计上下文', 'knowledge 覆盖检查'. NOT for: code review, rule content correctness, or knowledge content quality.
-
jmagly Bundle Security Engineering QuickrefAUTO-INVOKE when user mentions cryptography, AEAD, KDF, chain of trust, signing key, auth factor, MFA, secret hygiene, supply chain trust, physical threat. Security-engineering quick reference — decision domains for crypto primitives, chain-of-trust, auth factors, degraded modes, supply-chain trust, physical-threat modeling.
-
jzills Skill Risk AuditView the shimmering-forest risk auditor's current configuration and recent audit log entries. Use when the user types "/risk-audit", asks to "show risk audit config", "check risk thresholds", "view audit log", "show blocked operations", or "what is shimmering-forest configured to block".
-
jzills Skill Auto Claude MdKeeps CLAUDE.md in sync with the codebase by diffing recent commits and patching stale or missing documentation. Triggers automatically after git commits via `[AUTO-CLAUDE-MD]` hook injection. Also invoke manually when the user asks to update, sync, refresh, or audit CLAUDE.md, or asks whether their project docs are up to date. Use this skill whenever there's a question about whether CLAUDE.md reflects the current state of the repo.
-
kodexa-ai Bundle Kdx CLIUse when running the Kodexa CLI (kdx) — logging in and managing profiles, listing/describing/deleting resources, validating and applying resource YAML, invoking declared API operations with run, pulling/pushing/deploying metadata with a sync manifest, inspecting local KDDB documents, and the project/store/task/secret/intake/document-family/knowledge command groups.
-
kucherenko Bundle Audit ReviewUse when completing tasks, implementing major features, or before merging — dispatches the-inspector to audit the books before the job is closed
-
kucherenko Skill The ConsigliereUse when needing impartial architectural advice, security audit, spec integrity review, or a second opinion — operates outside the chain of command with standing authority to invoke truth checks
-
latias94 Skill Fret UI ReviewThis skill should be used when the user asks to "review a Fret UI", "polish UX", "audit focus/overlays", or "check token drift and `test_id` stability". Provides a framework-aligned audit workflow (tokens, focus-visible, overlays, commands gating) with outcome-first findings, recommended regression gates, and evidence anchors.
-
latias94 Skill Fret Crate AuditsThis skill should be used when the user asks to "audit a crate", "review contract surfaces", "assess refactor hazards", or "produce a crate audit note". Provides a crate-by-crate audit workflow (purpose/exports/deps/hazards) plus a small gate set to turn findings into landable steps.
-
latias94 Bundle Fret Framework Consumer AuditThis skill should be used when the user asks to "find problems from a Fret user's perspective", "audit developer experience", "build real examples to expose framework friction", or "review onboarding/examples/scaffolds/API ergonomics". Provides a task-driven workflow that simulates framework consumers shipping a small app slice, records friction by owner layer, and turns the top issues into gates, docs/example fixes, or refactor lanes.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include maintaining-documentation, evidence-review, security-analyst. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.