Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
beskars-code Bundle TastePack coding taste: keep it simple, keep jobs apart, honest names, fail fast, trust the server, types tell the truth, don’t repeat yourself, and related rules. Use to audit or apply taste to a lane; parents load it before planning or writing code.
-
biggora Bundle Ecommerce CommonThis skill should be used when the user asks about "payment gateway integration", "shipping provider plugin", "e-commerce security", "PCI-DSS compliance", "product data normalization", "multi-currency support", "webhook handling", "e-commerce testing", or needs common patterns shared across multiple e-commerce platforms. Provides cross-platform e-commerce plugin development patterns.
-
chainsafe Skill Chainsafe Solidity ArchitectArchitectural guidance for designing Solidity contracts and EVM systems at ChainSafe (Sygma bridge and broader crypto work). Use whenever the user starts a new contract, designs a contract system, picks an upgrade strategy (immutable / UUPS / Transparent / Diamond), chooses access control (Ownable vs AccessControl, multi-sig, timelocks), designs reentrancy posture, plans a deployment, or writes an ADR for Solidity work. EVEN IF the user does not say "architecture" — triggers on "design a contract", "Sygma bridge architecture", "upgrade strategy", "UUPS or Transparent", "multi-sig setup", "access control design", "reentrancy strategy", "audit plan", "deployment plan", "bridge invariants", "cross-chain replay", "storage layout upgradeable". Every Solidity decision is a security decision. Do NOT use for line-level Solidity (use chainsafe-solidity-developer) or PR review (use chainsafe-solidity-reviewer).
Audited -
nwiizo Skill Check Production ReadyProduction readiness audit - checks unwrap elimination, error handling, clippy, docs, channel usage, and test count.
-
freekmurze Bundle Audit ArchitectureRun an application-wide, read-only architecture audit that finds materially useful simplifications in a codebase's data structures, state representation, control flow, algorithms, and ownership boundaries. Fans out bounded read-only agents per subsystem, verifies every finding against the repo, and ranks results P0 to P3. Use when asked to audit architecture, review how state or data is modelled, find structural simplifications, or invoke /audit-architecture. Not a style or line-level quality pass (use /simplify for that) and not a bug hunt (use /code-review).
-
florianbruniaux Skill PerformanceOptimize web performance for faster loading and better user experience. Use when asked to "speed up my site", "optimize performance", "reduce load time", "fix slow loading", "improve page speed", or "performance audit".
Audited -
florianbruniaux Skill Best PracticesApply modern web development best practices for security, compatibility, and code quality. Use when asked to "apply best practices", "security audit", "modernize code", "code quality review", or "check for vulnerabilities".
Audited -
florianbruniaux Skill Security GuardianExpert en sécurité applicative pour détecter les vulnérabilités, auditer le code, et guider les bonnes pratiques de sécurité. OWASP Top 10, authentification, autorisation, cryptographie, gestion de secrets. Utiliser pour audits sécurité, reviews de code sensible, conception de features sécurisées, ou résolution de failles.
-
florianbruniaux Skill Source Command Tech Audit Codebase7-category codebase health audit for StarMapper with weighted scoring and tier system. Run before major releases or architectural changes.
-
suibianqugenichenghaole Skill State AuditAudit whether a demo, page plan, flow draft, or prototype sufficiently covers the states that matter, and identify likely missing, weak, or misleading states before downstream freeze or delivery. Use when Codex needs to check happy-path bias, missing outcomes, missing exceptional states, or weak state expression in product demo work.
-
suibianqugenichenghaole Skill Pm Devil Advocate触发:需反向挑战价值/假设/风险,含口语挑刺(有没有问题/有没有坑/盲点在哪);不触发:高风险交易/履约/状态/角色需求系统反证→用pm-requirement-reverse-audit;只查状态缺口→用state-audit;冻结裁决→用freeze-readiness-check;输出:最强反对意见+行动
-
suibianqugenichenghaole Skill Pm Requirement Reverse Audit触发:交易/履约/状态/角色等高风险需求需反证;不触发:普通澄清→用pm-requirement-intake;泛风险挑战→用pm-devil-advocate;输出:反例+补规则建议
-
tamdogood Bundle Lead ResearchProvider-neutral deep-research orchestration for brainstorming, technology choices, comparisons, and state-of-the-art surveys. The Research Lead makes scope and decision calls while native subagents scout, search, verify, synthesize, audit, write, and commit every research artifact.
-
tamdogood Bundle Code StandardsApply a disciplined engineering workflow to any code change. Use whenever implementing a feature, fixing a bug, or refactoring — before writing code, not after. Walks orient → baseline → smallest change → test → verify → self-review, and enforces language-agnostic hard gates (don't mass-reformat, keep the linter and type-checker clean, keep the build and tests green, make interface changes additive, protect security invariants).
-
tamdogood Bundle Validate MarketRun an honest market-fit and viability audit of any project or idea and produce a decision doc, not code. Use when someone asks "is this viable as a business", "audit the market fit", "make the case and compare to competitors", "should I apply to YC or bootstrap", or wants to validate a project, product, or market before investing more time. Gathers verifiable traction data first, researches the competitive field, gets an independent cold read, writes a doc with pre-committed pass/middle/kill criteria and a concrete week-1 assignment, then hardens it with an adversarial review loop.
-
tamdogood Bundle Paper Opportunity RadarRun a cumulative daily or retrospective sweep of research papers on a chosen topic, audit their claims, methods, integrity signals, and independent support, then identify overlooked but feasible project or business opportunities in a detailed source-grounded report. Use when asked to monitor papers every day, mine buried research, evaluate whether a paper is credible or reproducible, find unimplemented research ideas, or separate promising work from hype, weak evidence, and retracted or contradicted results.
-
the-open-agent Bundle Repo BootstrapScaffold a new open-source repository or bring an existing one up to community standard. Use when starting a project from scratch, open-sourcing internal code, or when a repo is missing baseline files (LICENSE, README, CONTRIBUTING, CODE_OF_CONDUCT, SECURITY, issue templates, CI, editorconfig, gitignore). Also use for "make this repo look professional", "what am I missing before I make this public", or GitHub community-standards checklists. Includes a pre-publication scrub for secrets and internal references.
-
the-open-agent Skill Supply Chain SecuritySecure an open-source project against supply-chain attacks and handle vulnerability reports. Use when writing a SECURITY.md, setting up private vulnerability reporting, responding to a reported CVE, hardening GitHub Actions permissions, pinning dependencies, adding SBOM or build provenance, signing releases, or improving an OpenSSF Scorecard. Also use when evaluating whether a dependency or a maintainer handoff is trustworthy, and when reviewing a PR that touches CI, build scripts, or install hooks.
-
tronghieu Bundle Strategy BoardA C-level strategy advisory board, run as a team of named specialist agents, that takes an executive from a raw strategic question to a defended, board-ready recommendation. Use this skill whenever the user faces a significant business decision or wants strategic analysis — market entry, build-vs-buy, M&A, digital transformation, annual planning, portfolio prioritization, pricing, a big investment, a competitive threat, a turnaround. Trigger on requests like "should we invest in / build / buy / enter…", "develop a strategy for…", "evaluate this opportunity", "make the business case", "stress-test this plan", "run a pre-mortem", or "prepare a board presentation" — in any language, even when the user doesn't say the word "strategy". Also trigger when the user names a board member (Drucker, Porter, Christensen, Graham, Grove, Wack, Taleb, Minto) or asks to convene the board / open a boardroom session.
Audited -
tronghieu Bundle Critical ThinkingAudit the reasoning of a document or argument (memo, proposal, investment analysis, board paper, article, the user's own draft): claims, evidence, unstated assumptions, logical gaps, fallacies, and what would falsify it, each anchored to quoted text. Use whenever the user wants reasoning examined, in any language ("audit this argument", "is this analysis sound", "poke holes in this proposal", "review the logic of my draft"; Vietnamese "phản biện giúp tôi", "soi lập luận này", "tài liệu này có lỗ hổng gì", "góp ý bản nháp của tôi"), even when they never say "critical thinking". Also use when the user drops a document and asks whether to trust or act on it, or asks to see their reasoning profile. Not for company-level strategic bets (strategy-board) or learning a topic through dialogue (socratic-questor).
Audited -
ukgovernmentbeis Skill Security Audit EvalAudit a third-party Inspect AI evaluation for security risks before running it locally. Decide whether the eval is safe by checking for malicious host-side code, externally-fetched files that aren't quality-controlled, sandbox-breakout instructions, weak sandbox configuration, supply-chain hazards, credential exposure, resource exhaustion, and provenance signals. Use when the user asks to audit / vet / security-review an eval repo (GitHub URL or local path), or asks "is it safe to run X". Do NOT use for assessing whether an eval *measures what it claims* (use eval-validity-review) or for general code-quality review (use eval-quality-workflow / code-quality-review-all).
-
ukgovernmentbeis Bundle Code Quality Review AllReview all evaluations in the repository against a single code quality standard. Checks ALL evals against ONE standard for periodic quality reviews. Use when user asks to review/audit/check all evaluations for a specific topic or standard. Do NOT use for reviewing a single eval (use eval-quality-workflow instead) or for test coverage (use ensure-test-coverage instead).
-
ulpi-io Bundle Auto ReviewReview a change across every dimension at once, then keep only the findings that survive an adversarial check — autonomously. It fans out independent reviewers over the diff (correctness, security, performance, maintainability/readability, test adequacy, API/contract & compatibility), dedups their findings, and puts each through a majority-refute verification so false positives never reach you or drive a fix. Survivors come back severity-labeled and actionable (file:line, why, suggested fix), and — if you ask — a bounded fix loop resolves the confirmed blockers. It fails closed: a dimension that didn't actually run is reported as a gap, never as "clean". This is the REVIEW phase. Composes fan-out-work (dimensions), adversarial-verify (confirm findings), converge-loop (optional fix), and checkpoint-resume.
Audited -
ulpi-io Bundle Fan Out WorkCover a large work-list in parallel without losing correctness or honesty — scout the items inline, then run each through its stages concurrently (map, optionally reduce) via the Workflow tool, with concurrency caps, per-item isolation where items mutate files, and an explicit account of anything dropped. Use when the task is "do the same thing to N independent things" — audit every module, migrate every call site, write tests for every gap, review every changed file — and N is big enough that serial is wasteful. It keeps the coordinator in control of the decision to continue while the per-item work runs in agents; it never silently truncates (a top-N/sampling cap is logged), and it aggregates results faithfully (a failed item becomes a reported null, not a hidden success). Composes with converge-loop (per-item loops) and adversarial-verify (gate each item's result).
-
ulpi-io Bundle Adversarial VerifyProve a claim before acting on it: spawn N independent skeptics prompted to REFUTE it (optionally through distinct lenses — correctness, reproduction, security, regression, measurement) and keep it only if a majority fails. Fails closed on ties. Use to gate findings before fixing, fixes before committing, and any "clean/safe" verdict before trusting it.
-
undefined-ui Skill Second Brain LintAudit a second-brain vault for structural problems and repair them: broken wikilinks, orphan pages, empty stubs, frontmatter that violates the schema, near-duplicate pages, and stale index entries. Use this skill whenever the user asks to lint, clean, audit or check the health of their vault, says pages feel messy or links are broken, after a large bulk import, or when a scheduled maintenance run fires. Do NOT use for ingesting new sources, for answering questions from the vault, or for rewriting page content that is structurally fine but reads badly.
-
undefined-ui Skill Second Brain PrivacyAudit the vault for material that should not be in it: credentials, other people's private information, confidential work, and anything the user would not want synced or backed up. Use this skill when the user asks about privacy, is about to share or sync the vault, has just imported chat history or meeting notes, or asks what is sensitive in their notes. Do NOT use to delete anything on your own, or as a substitute for the publishing check.
-
validkeys Bundle QA Test PlanGenerates a structured QA test plan from business-requirements.yaml and technical-requirements.yaml. Produces test suites keyed to functional requirements and user personas, covering positive, negative, edge, security, and performance cases. Outputs qa-test-plan.yaml ready for use in delivery timeline QA phases.
-
vladmandic Skill Check UIAudit Python-to-JavaScript UI bindings for Gradio _js calls, global window exposure, and ui/globals.d.ts registration.
-
vladmandic Skill Check APIAudit SD.Next API route definitions and verify endpoint parameters plus request/response signatures against declared FastAPI contracts.
-
vladmandic Skill Check ScriptsRun a phased scripts audit in scripts/*.py: validate Script overrides (init/title/show) first, then verify ui() output compatibility with run() or process() parameters.
-
vladmandic Skill Check ProcessingRun a phased processing-workflow audit from UI submit bindings to backend execution: map workflow paths first, then validate parameter, type, and initialization correctness.
-
vladmandic Skill Check SchedulersRun a phased scheduler audit from modules/sd_samplers_diffusers.py and scheduler UI definitions: verify class loadability first, then config validity against scheduler capabilities, then SamplerData correctness and UI option alignment.
-
warpdotdev Skill Security Review PrAudit a pull request diff for common security concerns (input validation, sanitization, authentication and authorization, secrets management, unsafe dependencies, and related risks) and fold findings into the same review.json produced by the base PR review. Use as a supplement to `review-pr` whenever a code PR is being reviewed.
-
wdm0006 Skill Evergreen Stale Data AuditAudits Evergreen CRM for stale or incomplete contact data — outdated titles, missing fields, potential duplicates, and contacts that may have changed jobs. Use for periodic database hygiene, before a big outreach push, or when data quality feels off.
-
wei63w Skill Pm CheckupOn-demand five-dimension project checkup (security, function, completeness, quality, docs) with P0/P1/P2. No cron.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include performance, best-practices, security-guardian. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.