Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
marcoantolini Bundle FallowCodebase intelligence for TypeScript and JavaScript. Static analysis of code and styles reports changed-code risk, cleanup opportunities, duplication, circular dependencies, complexity hotspots, architecture boundaries, design-system drift, feature flags, and opt-in security candidates. Runtime coverage can merge production execution data for hot-path review, cold-path deletion confidence, and stale-flag evidence. 123 framework plugins, zero configuration, sub-second static analysis. Use when asked to audit PR risk, find unused code or dependencies, detect duplicates, check styling consistency, inspect architecture boundaries, merge runtime coverage, auto-fix supported issues, or run fallow.
Audited -
jgtolentino Bundle Audit SkillComprehensive audit capabilities for security, code quality, module structure, compliance, and performance analysis. Use this skill when performing security audits, code reviews, vulnerability assessments, module structure validation, or generating audit reports.
-
eugenepyvovarov Bundle VulnhunterVulnHunter - Security Vulnerability Detection & Analysis
Audited -
fabioc-aloha Bundle Security Review SkillDefend before attackers find the gaps - OWASP, STRIDE, and Microsoft SFI
-
involvex Skill Code ReviewPerforms thorough code reviews for Flutter/Dart pull requests and merge requests. Use when asked to review a PR, MR, branch, or a set of changed files. Follows a structured checklist covering correctness, security, style, testing, and documentation.
-
aksoftcode Bundle Aicrew Harness AuditAudit the aicrew harness health and completeness in Codex.
-
fnord123 Bundle Stock Investment AnalysisEquity research on ONE publicly traded security, named by ticker or company name. Produces a full investment memo: valuation, bull and bear case, and a clearly labeled final verdict (one of five fixed labels). PREFER THIS SKILL whenever the subject is a single listed security — including muni ETFs and closed-end funds such as MUB, VTEB, and NVG, which are evaluated as equities. Use `investment-hypothesis-investigation` instead when the subject is a theme, sector, or macro claim spanning several companies. Use `pre-ipo-investment-analysis` instead when the company is private and not yet listed. Use `municipal-bond-analysis` instead for an individual bond identified by CUSIP. Activate on any of: "analyze NVDA", "is TSLA a buy", "what do you think of <ticker>", "should I buy <ticker>", "what's <ticker> worth", "is <company> overvalued", "bull case and bear case", "DCF", "reverse-DCF", "peer comparison", "equity research", "stock pitch", "investment memo", "stock thesis".
-
fnord123 Bundle Investment Hypothesis InvestigationStress-test ONE directional investment THESIS spanning multiple companies, a sector, or a macro variable — no single security is the subject. Quantifies what the market already prices in, gathers evidence for and against, and reports a probability estimate against market-implied with an explicit edge number. PREFER THIS SKILL whenever the user states a claim or view they want validated, rather than naming one security to analyze. Use `stock-investment-analysis` instead the moment a single ticker or listed company is the subject. Use `municipal-bond-analysis` instead for one bond by CUSIP. Use `pre-ipo-investment-analysis` instead for one private round. Activate on any of: "test this thesis", "research this hypothesis", "is this priced in", "what's the edge here", "build a case for", "build a case against", "stress-test this view", "are <sector> stocks cheap", "will <event> happen by <date>", "is <theme> overvalued", "should I bet on <trend>".
-
freema Bundle Publish Report ArtifactPublish analysis results as a polished, shareable web page (Claude Artifact) instead of pasting a markdown table into the terminal. Use when the deliverable is a report, audit, data table, comparison, incident timeline, or migration inventory that the user will share with colleagues (management, product, non-developers). Triggers on: "make a report", "share this with the team", "prepare something I can send", or whenever an analysis produces a table or findings worth reading outside the terminal. Covers page structure, PII rules for aggregated data, a token-based house style with light/dark themes, and the publish/update workflow.
-
garagon Bundle SecurityUse before shipping to production. Performs OWASP Top 10 audit and STRIDE threat modeling against the codebase. Supports --quick, --standard, --thorough modes. Also use when the user asks to check security, audit code, or review for vulnerabilities. Triggers on /security.
Audited -
garagon Bundle Audit LicensesUse to list the open-source licenses of every dependency in this project, grouped by license family. Flags GPL or AGPL dependencies that may force the project itself to be open-source. Triggers on /audit-licenses.
Audited -
garagon Bundle License AuditUse to audit the open-source licenses of every direct dependency in this project before shipping. Flags GPL/AGPL as BLOCKED, unknown as WARN. Triggers on /license-audit.
Audited -
garagon Bundle Release ReadinessUse after review/qa/security/license-audit/privacy-check to compose a release decision before /ship. Returns OK only when all required upstream evidence is present and clean. Triggers on /release-readiness.
Audited -
go-sphere Bundle Go Test EngineeringAudit, repair, or write Go tests so they enforce real API and behavior contracts. Use for reviewing unreliable or AI-generated tests, removing duplicate or low-value tests, strengthening weak assertions, designing reusable interface contract suites, deciding when golden tests are justified, fixing implementation bugs exposed by valid tests, or adding focused unit and integration tests. Do not use for ordinary Go implementation work that does not involve tests.
-
gvago Skill Kernel Security AuditUse when a Linux kernel PR diff handles untrusted input (copy_from_user, get_user, ioctl args, netlink attrs, network or firmware data), security lens (Sashiko stage 6): OOB access, integer overflow, TOCTOU, info leaks to userspace, privilege escalation in the CHANGED code only. Part of the linux-kernel-review suite.
Audited -
gvago Bundle Appsec Compliance ReviewUse when a PR diff touches application code, or any committed configuration that can carry credentials, governed by an organization's written security policy. Enforces five AppSec rules on the CHANGED code only - authentication/authorization on sensitive endpoints, injection, SSRF, debug/test code reachable in production, and hardcoded secrets - reporting per-rule per-file coverage so an unevaluated rule is never a silent skip. Skip only for docs-only diffs.
Audited -
gvago Bundle Kernel Locking ConcurrencyUse when a Linux kernel PR diff touches locks, atomics, RCU, IRQs, or deferred work, concurrency audit (Sashiko stage 5): races, deadlocks, lock-context violations, missing barriers, RCU misuse. Every finding must name the two racing contexts. Part of the linux-kernel-review suite.
Audited -
gvago Bundle Toml Portal Migration AuditUse when a repo still has a .pr_agent.toml and Qodo settings are managed in the portal, or when a portal setting change has no effect. Audits every toml key against the portal-managed key map and proposes the exact minimal removal diff so the portal becomes the single source of truth. Run it before touching any Qodo config.
Audited -
haochengw372-hash Bundle Communication TheoryAudit whether a communication theory explains a proposed mechanism, select defensible theoretical anchors, and surface rival explanations. Use for theory selection, mechanism claims, theory-driven RQ development, 理论选择/机制解释/传播理论审计. Do not use for generic statistical or writing work without a theoretical-claims question.
-
haochengw372-hash Bundle Communication ReviewerRun structured seven-gate review and audit of communication research manuscripts, proposals, and analyses, and diagnose journal fit and writing maturity. Use for peer review, internal manuscript audit, proposal review, revision planning, 论文评审/审稿/研究审计/七道门/投稿前检查. Review mode is read-only unless the user separately asks for edits.
-
kunitoki Skill Au ReviewReviews AudioUnit v2/v3 plugin implementations for spec compliance, thread safety, and correctness. Use when the user asks to review an AudioUnit plugin, check an AUv3 app extension, audit property or parameter handling, or asks "is my AUComponent thread-safe?" or "why does my AU crash in Logic?". Trigger on phrases like "review my AudioUnit", "check my AUv3", "is my render block safe?", or when you see AURenderCallback, internalRenderBlock, kAudioUnitProperty_*, or AUAudioUnit in the code.
-
kunitoki Bundle Yup ReviewReviews YUP audio plugin code for YUP-specific correctness issues: AudioProcessor lifecycle, AudioParameterBuilder and AudioParameterHandle usage, editor gestures, AudioBusLayout handling, CLAP/VST3 wrapper contracts, state recall, and MIDI safety. Use when the user asks to review a YUP plugin, check a processBlock, audit parameter smoothing, or asks "is this YUP code safe?". Trigger when you see yup::AudioProcessor, yup_audio_plugin, AudioParameterBuilder, AudioParameterHandle, AudioProcessorEditor, or createPluginProcessor in the code.
-
kunitoki Bundle Juce ReviewReviews JUCE audio plugin code for JUCE-specific correctness issues: thread safety, APVTS parameter patterns, MessageManager usage, ValueTree, and MIDI handling. Use when the user asks to review a JUCE plugin, check a processBlock, audit parameter handling, or asks "is this JUCE code safe?". Trigger on phrases like "review my JUCE plugin", "check my AudioProcessor", "is this APVTS usage correct?", or when you see AudioProcessor, AudioProcessorEditor, or AudioProcessorValueTreeState in the code.
-
kunitoki Bundle Vst3 ReviewReviews VST3 plugin implementations for spec compliance, host compatibility, and correctness. Use when the user asks to review a VST3 plugin, check bus arrangements, audit parameter handling, or verify their process() callback is safe. Trigger on phrases like "review my VST3 plugin", "check VST3 bus arrangement", "is my VST3 process safe", "audit my IAudioProcessor", or when you see IComponent, IAudioProcessor, IEditController, ProcessData, or Vst:: namespaced types in the code.
-
kunitoki Bundle Webaudio ReviewReviews Web Audio API JavaScript/TypeScript code for correctness, thread safety, and deprecated patterns. Use when the user asks to review AudioWorklet code, check an AudioWorkletProcessor, audit Web Audio graph construction, or diagnose crackling/dropouts in a web audio app. Trigger on phrases like "review my Web Audio code", "check my AudioWorklet", "is my AudioWorkletProcessor safe", or "why does my web audio crackle".
-
kunitoki Bundle Audio Dsp ReviewReviews audio DSP and audio processing code for realtime safety violations. Use whenever the user asks to review, audit, or check audio processing code — including plugin process callbacks, audio engine render functions, DSP implementations, or any code that runs on the audio thread. Trigger on phrases like "review my processBlock", "check this DSP code", "is this safe for the audio thread?", "review my JUCE plugin", or when you see an audio callback and spot potential realtime violations. Flag issues proactively even when the user hasn't explicitly asked for a review.
-
kunitoki Bundle Game Audio ReviewReviews game audio code for Wwise/FMOD integration safety, custom DSP plugin correctness, and audio middleware usage. Use when the user asks to review a Wwise plugin, check an FMOD DSP effect, audit game audio middleware integration, or asks "is my game audio code safe?". Trigger on phrases like "review my Wwise plugin", "check FMOD DSP effect", "is my game audio code safe", "review my audio middleware integration", or when you see AkPluginInfo, FMOD_DSP_DESCRIPTION, IMetaSoundSource, or Execute/process callbacks in game audio code.
-
kunitoki Bundle Audio Numerics ReviewReviews audio DSP code for numerical correctness. Use when the user asks to review, audit, or check DSP code for correctness issues — filters, feedback loops, fixed-point arithmetic, accumulation loops, or any numeric computation in audio code. Trigger on "check this filter for NaN", "why does my reverb blow up?", "is this numerically stable?", "why do I hear DC in my output?". Pairs with audio-dsp-review (realtime safety); this skill covers numeric correctness. Flag issues proactively.
-
lcrvl2 Bundle Content RefreshProactively identifies declining content and orchestrates refreshes. Use when detecting content decay, generating refresh briefs, tracking refresh effectiveness, or auditing content health. Triggers on "content refresh", "content decay", "declining content", "refresh audit", "content health check", or when user asks about underperforming/stale content.
-
matematicsolutions Skill Clause Checklist EnA clause checklist for a single contract - walks the contract against 41 clause categories (the CUAD taxonomy), assesses which of them this deal needs, and marks each applicable one present / absent / risky, so the clause that should be there but is missing does not slip through. Extractive (quotes the contract, does not paraphrase). Common-law native, jurisdiction-neutral framing. Different from a bulk audit - this goes deep on one contract and asks "what is missing and what bites here". Pairs with adversarial-legal-review-en and reviewer-en. Use when: "check the clauses in this contract", "what is missing from this agreement", "clause spotting", "contract checklist", "review a single contract", "which clauses are risky" - before signing, in negotiation, or in DD of one contract.
Audited -
mattjmdesign Bundle SystemAudit or maintain existing tokens, components, and shared layouts; resolve drift with evidence and a migration path. Use when auditing drift, deduplicating components, fixing theme or focus gaps, or updating DESIGN.md before new UI.
-
open-edge-platform Bundle Fastapi REST API DesignDesigns and reviews REST APIs for FastAPI services using consistent resource naming, HTTP semantics, validation, security, and error handling patterns. Use for backend API tasks, endpoint design/refactors, or API review requests in FastAPI/Python projects.
-
oscal-compass-lab Bundle Trestle AssessmentUse this skill for OSCAL assessment plans and assessment results models in Compliance Trestle. Use it for assessment plans, assessment results, security assessments, SAP, SAR, assessment activities, findings, observations, or assessment-related OSCAL models.
-
pale-knight Bundle TunnelNetwork reachability and pivoting after an operator already has a foothold. Use to make previously unreachable hosts, subnets, services or listener directions reachable via Ligolo-ng, Chisel, GOST v3, SSH/native forwarding, socat/netsh, Microsoft Dev Tunnels, DNS/HTTP/QUIC fallback transports, and multi-hop routing. This module does not exploit services, obtain credentials, or own C2/persistence. Its success condition is changed reachability: the operator can route/connect to the intended internal network/service through the selected foothold.
-
pale-knight Bundle Ad ReconActive Directory reconnaissance with or without credentials: user/group/computer enumeration, ACL/delegation, ADCS, modern Windows LAPS, BloodHound, Server 2025/dMSA/Ghost SPN candidates, and trust mapping. Recon only — do not exploit Kerberoast-to-DA, DCSync, or change passwords. Operator may select /ad-attack after cards are ready.
-
pavelsimo Bundle ReviewPerforms deep, evidence-first code review on local diffs, staged changes, branch comparisons, or GitHub PRs and issues, with severity-annotated findings. Use when the user wants to review code changes, audit a pull request, or investigate a GitHub issue.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include fallow, audit-skill, code-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.