Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
lautreintelligence Bundle Clean Code AuditRéalise des audits Clean Code selon les 6 principes de Robert C. Martin (nommage, fonctions, commentaires, formatage, gestion d'erreur, DRY). Utilise ce skill quand l'utilisateur demande d'auditer du code, de relire la qualité d'un code, de vérifier les violations de clean code, d'évaluer la dette technique, ou d'améliorer la lisibilité du code. Retourne des rapports structurés avec notation de sévérité (🔴 Critique / 🟠 Majeur / 🟡 Mineur), des exemples concrets de refactoring et des recommandations priorisées.
-
le-19-stvn Skill Security ReviewEnd-of-development defensive hardening audit for a web project — scored, with fixes. Runs a defensive configuration checklist (security headers, CORS, TLS, file exposure, form protection, cache/SRI/security.txt), scores the result out of 100 by severity, and proposes config diffs to apply after human review. Use when hardening before launch, or when the user asks "is this secure to ship", "security audit", "hardening review", "check the headers/CORS/TLS". This is a NON-INTRUSIVE configuration review, not a penetration test.
-
gebruder Bundle LyrikSecurity assessment of a codebase — minimal mode for runner validation
-
gordon1210 Bundle Deep Code ReviewPerforms deep, evidence-driven reviews of pull requests, commits, diffs, patches, working-tree changes, and explicit current-state audits. Use for code review, security review, regression hunting, or merge-risk assessment when the goal is to find real bugs with minimal false positives. Traces behavior through callers, state, data flows, trust boundaries, tests, configuration, and deployment contracts while loading only relevant reference modules.
-
grandcamel Skill Gitlab VulnerabilityGitLab vulnerability operations via API. ALWAYS use this skill when user wants to: (1) list security vulnerabilities, (2) view vulnerability details, (3) confirm/dismiss/resolve vulnerabilities, (4) view vulnerability findings.
Audited -
greenpau Bundle Threat Huntinggo-authcrunch threat-hunting workflow for security audits, vulnerability triage, and deep review of authentication and authorization boundaries. Use when auditing the package for security issues, validating external vulnerability reports, reviewing authn/authz bypasses, ACL/path matching, redirects, token/cookie/session handling, OAuth/SAML/LDAP/KMS flows, input parsing, concurrency, secret logging, dependency vulnerabilities, or producing security findings and remediation plans.
-
adityahegde712 Skill Production Readiness ReviewAutonomous, iterative, rubber-ducked production-readiness and system-hardening review. Audits codebases metric-by-metric across reliability, availability, performance, scalability, data integrity, security, observability, operability, and cost. Produces a fact-checked, bucketed report with concrete file:line citations and production-grade remediations.
-
jzkk720 Skill Anti SlopAnti-AI-slop design and copy rules for any UI work (website, web app, or interface). Use whenever building, refining, or auditing user-facing UI. Holds every visual decision to a purpose test and the result to a liveliness bar so the output feels crafted by a designer, not generated by AI. Two modes: DURING (apply rules while building) or AFTER (audit finished work with a numbered findings list). Pairs with a DESIGN.md / brand direction for identity. Complements hallmark, taste-skill, baseline-ui, and improve-ui.
Audited -
jzkk720 Skill Open Code ReviewPerforms AI-powered code review on Git changes using the `ocr` CLI from alibaba/open-code-review. Use when the user asks to review code, review a pull request, review staged/unstaged changes, review a commit, or compare branches for code quality issues. Produces line-level review comments and can automatically apply fixes when requested. With appropriate review rules, can detect various types of issues including bugs, security vulnerabilities, performance problems, and code quality concerns.
Audited -
cdxgen Bundle CdxgenSkill: OWASP cdxgen (CycloneDX BOM Generator)
Audited -
cdxgen Skill Bom AuditRuns supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk, dependency source integrity, license policy violations, and SARIF or JSON reporting for code scanning. Use when asked to audit an SBOM, assess supply-chain or dependency risk, check for compromised or malicious packages, triage which dependencies to review first, or produce SARIF from a BOM.
-
cdxgen Skill Bom ExploreExplores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences and callstacks, unpackaged container binaries, HBOM and OBOM categories, and Golem or Cargo hotspots. Use when asked to inspect, query, summarize, or triage an existing BOM, find what is inside an SBOM, or answer ad hoc questions about BOM contents without writing scripts.
-
cdxgen Skill Bom Convert ValidateConverts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber Resilience Act compliance benchmarks with cdx-validate, emitting SARIF for code scanning. Use when asked to convert an SBOM to SPDX, downgrade or upgrade a BOM spec version, validate or lint a BOM, check SCVS or CRA compliance, or score SBOM quality.
Audited -
cdxgen Skill Os Hardware InventoryCollects live operating-system inventory (OBOM) and host hardware inventory (HBOM) as CycloneDX documents using the cdxgen obom and hbom commands, including osquery-backed runtime artifacts, Linux hardening snapshots, GTFOBins enrichment, firmware and bus topology, and macOS permission troubleshooting. Use when asked to inventory a live machine, audit a running host's packages or services, produce a hardware BOM, or check host trust posture.
-
mohitkhandelwal242 Skill Play Console InsightsPlay Store ASO audit — pulls installs, store-listing CVR, search-term acquisition, vitals, and live store-listing experiments. Combines Play Console reports bucket + Play Developer Reporting API + Product DB install funnel. Diff vs prior run, flag anomalies (CVR drop, install >20% delta, keyword shifts, experiment moves), publish to Confluence. Use when asked about ASO, Play Store performance, store listing experiments, Play Store CVR, search terms, or '/audit-aso'.
Audited -
mohitkhandelwal242 Bundle Deep Competitor TrackerWeekly competitor audit — scrapes app stores, scans news, tracks feature changes, ratings, reviews, hiring + ads/social signals for your competitors (loaded from business.json). Each run also DISCOVERS new entrants in your space and self-updates the tracked set. Produces a delta-first report with a per-competitor strategic card (Product / Ads / Social / Insight for your product). Invoke weekly Monday morning.
Audited -
morphet81 Skill CleanupReview uncommitted changes, verify tests, fix lint and audit issues, ensure 100% coverage, then propose fixes for approval before committing.
-
mralaminahamed Bundle Wp Coding StandardsUse when setting up PHPCS with WordPress Coding Standards (WPCS), configuring phpcs.xml.dist, running phpcs/phpcbf, fixing sniff violations, adding PHPCS to CI (GitHub Actions), configuring IDE integration, or verifying a plugin meets WP.org code style requirements. Covers squizlabs/php_codesniffer, wp-coding-standards/wpcs, dealerdirect/phpcodesniffer-composer-installer, WordPress-Extra, WordPress-Docs, WooCommerce-Core rulesets. Triggers: "phpcs error", "WPCS violation", "fix my code style", "set up PHPCS", "configure phpcs.xml.dist", "my code fails PHPCS", "add linting to CI", "WordPress.Security.EscapeOutput sniff", "WordPress.WP.I18n error", "WordPress.NamingConventions sniff", "how do I ignore a phpcs rule", "phpcbf auto-fix", "phpcs in GitHub Actions", "add PHPCS to pre-commit hook", "vendor/bin/phpcs -i", "WordPress-Extra ruleset", "WordPress-Docs ruleset", "WooCommerce sniff", "phpcs.xml.dist example", "phpcs says my spacing is wrong", "fix indentation for WP standards", "PHPCS not finding WPCS", "de
-
nateslabach Skill Vibe AuditRuns a comprehensive 20-point code quality audit on a "vibe-coded" codebase that was shipped fast and now needs hardening. Use this skill whenever the user mentions vibe coding, vibe audit, code audit, code review, code cleanup, hardening a prototype, productionizing a codebase, technical debt cleanup, or asks Claude to "audit my code", "review my codebase", "clean up my project", or check a freshly-shipped project for common quality issues. Also use when a user shares a repo and asks what's wrong with it or how to make it production-ready.
-
nateslabach Skill Code ReviewConducts a structured 3-phase code review — understanding intent, cataloguing issues by severity, and stress-testing with adversarial questions. Use when reviewing a code diff, pull request, or snippet for correctness, edge cases, security issues, and merge readiness.
-
nirholas Skill Atomic AuditUse when the user wants to determine whether a Solana wallet was seeded (funded) by pump.fun — a provenance / forensics check. Triggers on "did pump.fun seed this wallet", "check-pump-funding", "detectSeededByPump", "wallet provenance", "funding source check", or any audit of pump.fun funding lineage.
-
nirholas Skill Atomic Funding SourceUse when the user wants to determine whether a Solana wallet was "seeded by pump.fun" — i.e. its first inbound SOL transfer came from a known pump.fun fee recipient or migration authority. Useful for wallet provenance audits, distinguishing genuine pump.fun-originated activity from cosplay, or detecting if a creator wallet was bootstrapped by the protocol itself. Triggers on "was this wallet funded by pump", "check-pump-funding", "wallet provenance", "detect pump-seeded wallet", "is this a pump.fun wallet", or any wallet-origin audit task.
-
notque Skill Sapcc SecretsSecret management operations via Barbican. Triggers: secret, key, certificate, barbican, key manager, encryption, tls cert. NOT for: application credentials (use sapcc-identity/Keystone).
-
notque Bundle Sapcc NetworkingNeutron networking operations: network topology, port inspection, security group debugging, connectivity troubleshooting. Triggers: network, subnet, port, security group, firewall, connectivity, "can't reach", interface, IP address, CIDR.
-
notque Skill Sapcc LoadbalancerLoad balancer operations via Octavia. Triggers: load balancer, lb, listener, pool, vip, octavia, l7. NOT for: network ports or security groups (use sapcc-networking).
-
premdevai Skill Brutal Readme ReviewerA merciless reviewer for README files, project documentation, API docs, and developer-facing technical writing. Destroys missing install steps, broken examples, "TODO" sections shipped to production, badge soup, and READMEs that explain everything except what the project actually does. Use this skill whenever the user shares a README, docs page, contributing guide, or API reference and asks for a review, critique, or harsh feedback, OR says things like "review my readme", "is my readme bad", "rip my docs", "why does no one star my repo". Trigger on phrases like "review my project docs", "critique my readme", "audit my docs". Different from brutal-code-reviewer (which reviews code) and brutal-writing-editor (which reviews prose) — this skill reviews technical documentation specifically.
-
premdevai Skill Brutal Commit Message ReviewerA merciless reviewer for git commit messages, PR titles, and PR descriptions. Destroys "fix stuff", "wip", "asdf", "final", "final final", subject lines that don't say what changed, descriptions that summarize the diff instead of explaining the why, and 50-line subject lines. Use this skill whenever the user shares commit messages, a git log, PR titles, or PR descriptions and asks for a review or critique, OR says things like "are my commit messages bad", "review my git log", "rip my PR titles", "is my commit history embarrassing". Trigger on phrases like "audit my commits", "are these commit messages bad", "review this PR description". Different from brutal-code-reviewer (reviews code) and brutal-readme-reviewer (reviews docs) — this skill is specifically for git history and PR metadata.
-
anyproto Bundle Swiftui Performance DeveloperAudit and improve SwiftUI runtime performance through code review and Instruments guidance. Use for diagnosing slow rendering, janky scrolling, excessive view updates, or layout thrash in SwiftUI apps.
-
cartridge-gg Skill Dojo ReviewReview Dojo code for best practices, common mistakes, security issues, and optimization opportunities. Use when auditing models, systems, tests, or preparing for deployment.
Audited -
cartridge-gg Bundle Cairo AuditorSystematic Cairo/Starknet security audit workflow with deterministic preflight, parallel vector specialists, adversarial reasoning, and strict false-positive gating.
-
macro-inc Skill Sqlx Query ValidatorInspect Rust changes for SQLx queries. Use after modifying Rust code that adds or changes SQLx queries to ensure compile-time SQLx macros are used, run `just prepare_db` for offline query cache, and review queries for performance and security issues.
-
aospbooks Skill Aosp SecurityAOSP Part IX — Security. Use when reasoning about SELinux on Android, Keystore/Keymint, Trusty TEE, gatekeeper/weaver, Android Verified Boot, dm-verity, hardware-backed attestation, Credential Manager (CredentialManagerService, credential providers, passkeys/FIDO2, password and autofill integration, digital credentials), or DRM (MediaDrm framework, Widevine L1/L2/L3, OEMCrypto, license acquisition, secure decoder/display path), or the LFI in-process sandbox (Lightweight Fault Isolation for untrusted code such as software codecs). Chapters 40–42, 68.
-
az9713 Skill Test AllRun the complete UI testing suite — all 16 test skills across functional testing and UX design quality. Use when user wants a comprehensive site audit, full test suite, or complete quality assessment.
-
az9713 Skill Test LinksTest link integrity, navigation, and semantics. Use when user wants to check for broken links, test navigation, verify external links, or audit link behavior.
-
az9713 Skill Test ConversionAnalyze conversion optimization, cognitive load, and trust signals. Use when user wants to audit conversion funnels, reduce friction, analyze cognitive load, check trust signals, or optimize CTAs.
-
az9713 Skill Test UX WritingAnalyze micro-copy, CTA text, error messages, and content quality. Use when user wants to audit UX writing, button labels, error messages, form labels, or content clarity.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include swiftui-performance-developer, clean-code-audit, security-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.