Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
pranav8494 Skill Kotlin ReviewerUse when reviewing a Kotlin/Spring Boot pull request, systematic checklist covering architecture, idioms, testing, security, and observability
-
promovaweb Bundle Companify AuditAudita a consistência e a prontidão do plano de negócio. Use para revisar company/ antes de considerar o pacote pronto para uso.
-
irfad7 Skill ThinkbackWhen the user wants to review past decisions, understand why something was built a certain way, audit decision quality, or learn from past reasoning. Use when the user says "why did we," "look back," "thinkback," "decision review," "was that the right call," "what were we thinking," "review our decisions," "decision audit," "trace back," "replay thinking," or when revisiting old code and needing to understand the reasoning behind it.
-
irfad7 Skill Code ReviewWhen the user wants a thorough code review of changes, a PR, a file, or a feature branch. Use when the user says "review this," "code review," "check my code," "what's wrong with this," "review my PR," "look over this," "critique this," "review before merge," or when submitting code for quality assessment. Performs multi-pass review covering correctness, security, performance, maintainability, and edge cases.
-
irfad7 Skill Security ReviewWhen the user wants a security audit, vulnerability assessment, or security hardening of their codebase. Use when the user says "security review," "security audit," "check for vulnerabilities," "is this secure," "pen test," "OWASP," "find security issues," "harden this," "check for leaks," "secrets scan," or before deploying any user-facing application. Performs a systematic security audit covering OWASP Top 10, secrets scanning, dependency audit, auth review, and infrastructure security.
-
wandb Bundle Senpai Tool TelemetryAudit recent tool use across local Senpai OpenHands root and recursively delegated conversations without exposing tool arguments. Use for provider comparisons, tool-loop diagnosis, status-poll analysis, error rates, and latency reports.
-
devenkhatri Skill Ads AuditFull multi-platform paid advertising audit with parallel subagent delegation. Analyzes Google Ads, Meta Ads, LinkedIn Ads, TikTok Ads, and Microsoft Ads accounts. Generates health score per platform and aggregate score. Use when user says "audit", "full ad check", "analyze my ads", "account health check", or "PPC audit".
-
devenkhatri Skill Ads LandingLanding page quality assessment for paid advertising campaigns. Evaluates message match, page speed, mobile experience, trust signals, form optimization, and conversion rate potential. Use when user says "landing page", "post-click experience", "landing page audit", "conversion rate", or "landing page optimization".
-
devenkhatri Skill Ads CreativeCross-platform creative quality audit covering ad copy, video, image, and format diversity across all platforms. Detects creative fatigue, evaluates platform-native compliance, and provides production priorities. Use when user says "creative audit", "ad creative", "creative fatigue", "ad copy", "ad design", or "creative review".
-
devolutions Skill Protocol ReviewerAnalyze IronRDP changes for RDP protocol conformance against Microsoft Open Specifications. Use when reviewing protocol behavior, wire formats, PDUs, virtual channels, codecs, security, capability negotiation, or protocol-visible errors.
-
eidoselegia Skill Noah ProtocolDelivery protocol for answers too large for one response — declare a round plan, deliver every round at full density with clean handoffs, and close the final round with an honest self-audit of quality and filler. Use for multi-part deliverables, long analyses, reports, and any task where the AI might silently truncate, pad the tail, or drop threads between messages. Trigger whenever a complete answer will not fit in one response at full quality.
-
exerias21 Bundle Code TourTurn an existing codebase into teaching material: audit docstring coverage, write why-focused docstrings that explain the reasoning behind each design decision, and generate a guided reading path (TOUR.md) with a pattern index and graded exercises. Use this whenever someone wants to document a codebase for humans rather than for an API reference — onboarding a new hire, handing a repo to another team, preparing a repo as a training or teaching module, "explain this codebase", "add docstrings", "write documentation for all the code", or after /repo-onboarding when the architecture is mapped but the code itself is undocumented. Distinct from its neighbours: /repo-onboarding generates the toolkit's contract files and /repo-health is a read-only sweep — this one writes documentation into the source, "help someone learn this repo", or when /code-tour, /docstrings, /codetour, or /onboarding-docs is invoked. Also use it when documentation exists but only says WHAT the code does and the user wants the WHY captured be
Audited -
whtsky Skill Skill ReviewAudit and format SKILL.md files in this repository. You MUST invoke this skill proactively when: (1) adding a new skill, (2) editing an existing SKILL.md, (3) migrating a skill from another source. Also use when explicitly asked to review skill quality or run a batch audit.
-
paretofilm Bundle Spec DriftStandalone plan-vs-code audit on any branch: runs /ship Step 8's plan-completion section from disk (hash-pinned) against an explicit plan and base. Report, JSON, exit code. Never edits code.
-
cardano-foundation Bundle Review ContractSecurity review for Cardano smart contracts written in Aiken, Plutus, or OpShin. Trigger: "review contract", "audit validator", "check security", "find vulnerabilities", "security review", "smart contract audit", "check for exploits".
-
cardano-foundation Bundle Write ValidatorGuide writing a Cardano validator from a specification. Covers datum/redeemer design, validator logic, security checks, and test planning. Default language is Aiken. Trigger: "write validator", "create contract", "build smart contract", "new validator", "implement spending validator", "write minting policy".
-
harshitsinghbhandari Bundle Pr ReviewComprehensive PR review focusing on code quality, test coverage, security, backward compatibility, and what CI cannot check. Use when reviewing PRs, when asked to review code changes, or when the user mentions "review PR", "code review", or "check this PR".
-
harshitsinghbhandari Bundle Boundary Bug HunterAggressive user-flow and boundary-bug analysis on a diff or branch. Auto-detects entry points, traces flows through changed code, finds every seam (cross-module calls, serialization, file I/O, shared state, schema versioning, network/IPC), and refuses to mark the work complete until each unverified boundary has a real round-trip test or an explicit written out-of-scope record persisted in an audit file. Use whenever the user says "boundary check", "seam check", "round-trip check", "flow boundaries", "user-flow check", "before merge", "is this safe to ship", "pre-merge gate", "boundary bugs", "verify the joins", or asks to validate cross-module joins, producer/consumer contracts, or end-to-end coverage of a change. Also use as a final gate from pr-review on any diff that touches more than one file, module, or process. Be pushy. Most surviving production bugs live at seams, not inside units — if the diff crosses any boundary, this skill almost certainly applies.
-
av Bundle Turso DBInstall, configure, and work with Turso DB — an in-process SQLite-compatible relational database engine written in Rust. Use when the user needs to (1) install Turso DB, (2) create or query databases with the tursodb CLI shell, (3) use Turso from JavaScript/Node.js via @tursodatabase/database, (4) work with vector search or embeddings in Turso, (5) set up full-text search with FTS indexes, (6) configure transactions including MVCC concurrent transactions, (7) enable encryption at rest, or (8) use Change Data Capture (CDC) for audit logging.
-
waynesutton Skill Sec CheckSecurity review checklist for Convex functions, auth logic, public queries, admin routes, webhooks, uploads, and AI-generated code. Use when reviewing code that touches user data, PII, or access control.
-
waynesutton Skill Convex DoctorRun convex-doctor static analysis, interpret findings, and fix issues across security, performance, correctness, schema, and architecture categories. Use when running convex-doctor, fixing convex-doctor warnings or errors, improving the convex-doctor score, or when asked about Convex code quality, static analysis, or linting Convex functions.
-
waynesutton Bundle Convex Return ValidatorsGuide for when to use and when not to use return validators in Convex functions. Use this skill whenever the user is writing Convex queries, mutations, or actions and needs guidance on return value validation. Also trigger when the user asks about Convex type safety, runtime validation, AI-generated Convex code, Convex AI rules, Convex security best practices, or when they're debugging return type issues in Convex functions. Trigger this skill when users mention "validators", "returns", "return type", or "exact types" in the context of Convex development. Also trigger when writing or reviewing Convex AI rules or prompts that instruct LLMs how to write Convex code.
-
vtmocanu Skill Upgrade AdvisorEvaluates whether and how to upgrade a tool, framework, library, or dependency. Discovers the pinned version(s), finds the latest released and latest installable version, reads the changelog across the whole version delta, and grep-classifies each breaking change and deprecation against real codebase usage, so the report covers only what applies here plus features worth adopting. Handles security/CVE- and end-of-life-driven upgrades; emits a safe / stay-put / blocked / needs-work verdict, investigate-only by default. Also verifies an already-done upgrade by auditing the runtime's error surface, catching latent breakage the changelog delta cannot reveal. Use when the user asks to upgrade, bump, or update a tool or dependency, mentions its new release or latest version, asks whether an upgrade is safe or worth it, or just upgraded and wants to know what broke. Triggers include "upgrade", "bump", "update dependency", "breaking changes", "is it safe to upgrade", "just upgraded", "what broke after the upgrade".
-
jasonkneen Bundle Env VarsLoad, list, verify, and store API keys. Canonical source is macOS Keychain (service=lazar). Use when you need a credential, to check which providers work, or after rotating keys. Never print secret values.
Audited -
fairy123456789 Bundle Csdn Technical WritingDraft, rewrite, or audit Chinese CSDN-style technical articles using a specific long-form teaching structure: a plain-text overall title, Markdown headings for section levels, dense natural paragraphs, beginner-first progression, commented code examples, and splitting when an article becomes too long. Use for technical tutorials, AI and backend articles, engineering practice notes, and beginner-friendly series.
Audited -
paulieb89 Bundle Workflow AuditorAnalyse a business workflow to find where time is actually lost and recommend specific improvements. Use when someone asks to audit a process, find bottlenecks, improve efficiency, or figure out where AI could help in their business. Based on Theory of Constraints thinking.
Audited -
ww-w-ai Bundle Scan SecurityDetects security vulnerabilities via static pattern matching based on OWASP Top 10
-
hetcreep Bundle Scale CanaryPerformance complexity and resource allocation canary — checks for O(N^2) loops, database N+1 query patterns, memory leaks (unbounded collections), and blocking calls in main event loop. Triggers on keywords: "/scale-canary", "scale-canary", "performance audit", "scale audit". Use when writing loops over growing data, DB queries, caches, or async/event-loop code.
-
hetcreep Bundle Gold StandardWorld-class completeness audit — score a project's rules/standards/features against best-in-class exemplars, name the gaps, fill missing rules, adopt as binding, then offer to conform existing code. Triggers on keywords: "/gold-standard", "gold-standard", "audit rules", "are we world-class", "fill gaps", "complete our rules", "conform old code".
-
hetcreep Bundle Resilience AuditFailure-mode audit (FMEA for software) — for each way the system can fail (network, storage, partial completion, crash, concurrency, bad input), check whether code DETECTS, HANDLES, RECOVERS, and COMMUNICATES it. Triggers on: "/resilience-audit", "resilience-audit", "FMEA audit". Use when touching network, storage, async, retry, or rollback paths. Flags data loss, silent-success-on-failure, missing rollback/retry/idempotency. Reports; does not fix unless asked.
-
hetcreep Bundle Telemetry CanaryObservability and structured logging canary — checks for structured logs (JSON), OpenTelemetry metrics/traces, proper error stack traces, and flags empty catches or silent log swallowing. Triggers on keywords: "/telemetry-canary", "telemetry-canary", "observability audit", "structured logging". Use when adding or changing logging, metrics, tracing, or error-handling code.
-
hetcreep Bundle Supply Chain AuditSoftware supply chain audit — dependencies (CVEs, maintenance, licenses, transitive risk), build/CI integrity (SHA-pinned actions, lockfile, CI-only release), artifact integrity (checksums, signing, SBOM). Triggers on: "/supply-chain-audit", "supply-chain-audit", "dependency audit". Run before adding a dep, before a release, or for periodic review. Reports; does not change deps unless asked.
-
hetcreep Bundle Testability CanaryTestability and design decoupling canary — checks for tight coupling, lack of Dependency Injection (DI), hardcoded constructors, Single Responsibility Principle (SRP) violations, and mockability gaps. Triggers on keywords: "/testability-canary", "testability-canary", "testability audit", "decoupling". Use when refactoring coupling, introducing DI, or making code unit-testable.
-
maybemonad Bundle Orchestrate Codex WorkflowRobust Codex orchestration workflow for complex implementation, planning, debugging, or audit tasks that need v1 planning, adversarial loophole checks, frozen execution specs, task ledgers, optional executor delegation, browser or command-line quality gates, fix loops, and final evidence-backed reports. Use when the user asks Codex to be autonomous, plan then execute, coordinate other executors such as DeepSeek or Kimi, harden a strategy until confident, run deep quality checks, continue through context loss, or avoid quitting in the middle of a multi-step task.
Audited -
rubenglez Bundle Address CvesFind and fix high and critical application dependency CVEs across all non-archived GitHub repositories available to the authenticated gh CLI user. Use when the user asks to address, remediate, audit, patch, or report severe CVEs/security advisories across many repos, including cloning missing repos, scanning dependencies and GitHub Actions, making dependency changes, testing, committing, pushing, merging to main after validation, cleaning branches, and producing a Markdown stdout report.
-
stoica-mihai Skill Fact CheckEnforces evidence-based reasoning for any task that involves making factual claims about a codebase — debugging, bug fixing, code investigation, code modification, AND explaining what code does, answering "where is X" / "what does Y do" / "is this safe", or summarizing behavior. Use this skill whenever the user asks to fix a bug, investigate an issue, modify existing code, trace a problem, debug behavior, refactor, change, update code, or explain/locate/audit any part of the codebase. This skill ensures Claude gathers real evidence from source code, docs, git history, and runtime behavior before making any claim — never guessing, never paraphrasing comments as fact, never relying on training memory. Even if the task seems straightforward, use this skill to guarantee that every claim and recommendation is grounded in verified facts.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include companify-audit, scan-security, kotlin-reviewer. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.