Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
lx-wnk Bundle Oss ReadinessAudits a repository for public-release ("open source") readiness: README front-door quality (Why/How/Benefits, badges, quick example, section order), doc deduplication, community-health files (LICENSE, CONTRIBUTING, SECURITY, CODE_OF_CONDUCT, issue/PR templates), and repo signals (description, topics, CI badge, releases, .gitignore, secrets). Fans out 4 parallel dimension agents into outputs/OSS-Readiness.md, P0-P3 findings. --apply-fixes drafts missing community-health files tailored to the repo, adds a CI badge, reorders README, dedups docs — escalates subjective calls (tagline, license choice, prose voice) as TODOs, never guesses. Use for "oss readiness", "prep for public release", "audit my repo for open source", "make this repo public-ready", "readme tuning", "make it presentable", or German "fit für open source", "repo veröffentlichen", "readme aufhübschen", "public-ready machen", "oss-check". Does NOT review source-code quality/security — use /branch-review or /full-project-review.
-
lx-wnk Skill Review And FixReview MULTIPLE open pull requests in one pass — discovers the open PRs (or the ones you name), runs `/branch-review` per PR in an isolated git worktree, and archives every report to `outputs/reviews/YYYYMMDD-<branch>.md` with a fixed/not-fixed flag plus a roll-up index. Optional `--apply-fixes` is forwarded to each per-PR review; design decisions from all PRs are batched and escalated once at the end. Use for "review my PRs", "check the open PRs", "review all open pull requests", "fix PR issues", "PR fleet review", "audit the open PRs", or German "review meine PRs", "check die offenen PRs", "alle PRs prüfen", "PRs reviewen und fixen", "offene Pull Requests durchgehen". DO NOT trigger for a single diff on the branch you already have checked out — use /branch-review. DO NOT trigger for a whole-repo audit without PR context — use /full-project-review.
Audited -
aiyo28 Skill Memento Vault AuditVault health check. Validates structure, detects stale reasoning artifacts by priority level, processes inbox, and suggests cleanup. Triggers: "vault audit", "check vault", "clean up vault", "process inbox", "what's stale", "vault health".
Audited -
aiyo28 Bundle Memento DecayFind aged [D] artifacts whose invalidation triggers may have fired. Scans vault _context.md tables, parses the invalidates-if clause, scores decay from git log keyword search + vault contradiction + age. Emits ranked candidates with the triggering signal. User confirms → artifact marked superseded. Triggers: "decay check", "what's stale", "memento decay", "find stale decisions", "audit aged artifacts".
Audited -
aiyo28 Skill Vault AuditVault health check. Validates structure, detects stale reasoning artifacts by priority level, processes inbox, and suggests cleanup. Triggers: "vault audit", "check vault", "clean up vault", "process inbox", "what's stale", "vault health".
Audited -
aiyo28 Bundle DecayFind aged [D] artifacts whose invalidation triggers may have fired. Scans vault _context.md tables, parses the invalidates-if clause, scores decay from git log keyword search + vault contradiction + age. Emits ranked candidates with the triggering signal. User confirms → artifact marked superseded. Triggers: "decay check", "what's stale", "memento decay", "find stale decisions", "audit aged artifacts".
Audited -
autocss-com Bundle SecuritySecurity rules for projects following the air-gapped, declarative-first architecture. Covers Content Security Policy, recommended security headers, and the architectural decisions that enable a strict CSP without unsafe-inline or unsafe-eval. Use when configuring deployment, reviewing CSP, or auditing for inline-script or inline-style violations.
-
bongsuchoi Bundle Cx Acceptance QAVerify completed or claimed work against explicit acceptance criteria using scope-proportional mechanical and observed evidence. Use for QA, release or handoff approval, task-contract verification, or whenever a behavior-bearing artifact must be proven. Do not run a second audit after equivalent evidence already proves the same claim; route rendered UI judgment to cx-visual-qa and unresolved failure diagnosis to cx-debugging.
-
impertio-studio Bundle Pdfjs Agents ReviewUse when reviewing or validating generated PDF.js code for correctness, best practices, and common mistakes. Prevents shipping code with missing worker setup, uncancelled render tasks, incorrect DPI handling, or wrong layer stacking order. Covers worker setup verification, render task lifecycle, memory management, v5 API compliance, and anti-pattern detection checklist. Keywords: code review, validation, checklist, anti-pattern, PDF.js review, quality, check my PDF code, verify PDF.js setup, audit viewer.
-
kin9zeus Bundle API ContractsAPI design and contract engineering — REST resource modelling, error envelopes, pagination, filtering, idempotency, versioning and deprecation, rate limiting, webhooks, OpenAPI, GraphQL schema and N+1 defence, and contract testing. Use when designing, reviewing or documenting an endpoint or integration; when the user says "API design", "REST", "GraphQL", "endpoint", "OpenAPI", "Swagger", "versioning", "pagination", "rate limit", "webhook", "idempotency", "status code", "API contract", "breaking change" or "integrate with"; and as a pass in any project audit that finds a public or internal API. By Devleck.
-
kin9zeus Bundle Testing StrategyTest strategy and quality engineering — the test pyramid, what to test at each layer, meaningful coverage policy, integration and contract testing, E2E for critical journeys, test data and fixtures, flaky-test control, mutation testing, load and security testing, and CI gating. Use when the user says "tests", "testing", "unit test", "integration test", "E2E", "Playwright", "Cypress", "Jest", "pytest", "coverage", "TDD", "flaky", "mocking", "test data", "how do I test this", "we have no tests" or "the tests keep breaking"; when writing tests for new code; and as a pass in any project audit. By Devleck.
-
kin9zeus Bundle Observability SloObservability and reliability engineering — structured logging, metrics, distributed tracing, correlation ids, error tracking, dashboards, SLIs/SLOs and error budgets, alerting that pages on symptoms rather than causes, on-call practice, incident response and blameless postmortems. Use when the user says "logging", "monitoring", "observability", "metrics", "tracing", "Prometheus", "Grafana", "Datadog", "Sentry", "OpenTelemetry", "SLO", "SLA", "uptime", "alerting", "on-call", "incident", "postmortem", "how do we know if it breaks", "it broke and we didn't notice" or "debugging production"; and as a pass in any project audit. By Devleck.
Audited -
kin9zeus Bundle Engineering StandardsTeam engineering practice — code conventions and readability, git and branching workflow, commit and pull request hygiene, code review standards, architecture decision records, documentation and runbooks, onboarding, developer experience, and managing technical debt deliberately. Use when the user says "code review", "conventions", "code style", "git workflow", "branching", "commit messages", "pull request", "ADR", "documentation", "README", "onboarding", "developer experience", "technical debt", "refactor", "CLAUDE.md", "AGENTS.md" or "how should the team work"; and as a pass in any project audit covering documentation and DX. By Devleck.
Audited -
kin9zeus Bundle Performance EngineeringPerformance engineering across the stack — Core Web Vitals (LCP, INP, CLS), bundle size and rendering strategy, image and font optimisation, backend latency budgets, caching layers, database query cost, profiling, and load testing. Use when the user says "slow", "performance", "optimize", "Core Web Vitals", "LCP", "INP", "CLS", "Lighthouse", "PageSpeed", "bundle size", "page speed", "latency", "TTFB", "caching", "CDN", "it takes forever to load", "high response times" or "will this scale"; and as a pass in any project audit. By Devleck.
-
kromatic-innovation Skill Repo AuditOccam sub-skill — comprehensive single-repo audit producing (a) a decision sheet for a human and (b) an issue graph for implementers with no session memory. Diagnosis only, never fixes. Use when asked to audit, review, or assess the health of a repository.
-
manazoid4 Skill Wiki LintHealth check the Obsidian wiki vault. Finds orphan pages, dead wikilinks, stale claims, missing cross-references, frontmatter gaps, and empty sections. Creates or updates Dataview dashboards. Generates canvas maps. Triggers on: "lint", "health check", "clean up wiki", "check the wiki", "wiki maintenance", "find orphans", "wiki audit".
-
max-sixty Bundle Running In CIGeneric CI environment rules for GitHub Actions workflows. Use when operating in CI — covers security, CI monitoring, comment formatting, and investigating session logs from other runs.
-
mrhinkle Bundle Aie Web SecurityRead-only defensive self-audit of a website or web app for common security gaps — exposed secrets in client code and git history, dependency vulnerabilities, missing or weak HTTP security headers (CSP, HSTS, X-Content-Type-Options, X-Frame-Options), HTTPS/TLS and mixed-content issues, unsafe DOM sinks (innerHTML/XSS), CSRF/cookie and CORS misconfigurations, and privacy-compliance gaps. Produces findings ranked by severity with plain-language fixes. This skill NEVER attacks a live target — it only reviews code, config, and public response headers you own. Trigger on "security audit," "security review," "security check," "is my site secure," "check for exposed API keys," "audit my security headers," "am I leaking secrets," "check my CSP," "HTTPS/SSL check," "XSS review," or "privacy compliance check."
-
mystenlabs Bundle Walrus Data SecurityEncrypting data before storing on Walrus using Seal (threshold encryption with onchain access control). Use when the user needs to store private or sensitive data on Walrus, implement access control for blob content, encrypt blobs before uploading, use @mysten/seal for threshold encryption, or understand Walrus data security guarantees (availability, integrity, confidentiality). Also use when the user asks about Nautilus (TEE-based off-chain computation) in the context of Walrus data. All blobs on Walrus are public by default.
-
neotherapper Skill Site SecurityUse when the user asks to "scan my site for vulnerabilities", "what CVEs does X have", "security coverage for", "check my site's security", or runs /aegis:scan. Produces a prioritized passive vulnerability-coverage report from a site's fingerprint — known CVEs (OSV-first) ranked by CISA KEV + EPSS, plus TLS/header misconfig. Passive lookup only (no active probing).
Audited -
northseadl Bundle Coding Net IntegrationCoding.net DevOps automation: MR lifecycle, CI operations (trigger/logs/stop), artifact registry, cross-project queries, remote file audit.
Audited -
indrasvat Skill CoderabbitLocal AI code reviews via CodeRabbit CLI. ONLY use when (1) user explicitly requests "coderabbit"/"cr review", OR (2) code changes are high-risk (security, concurrency, complex logic). Rate-limited to 1 review/hour—be highly selective.
-
jlreyes Skill Audit Xcode Security SettingsApple's progressive hardening playbook for Xcode build settings: security-oriented compiler warnings, static analyzer checkers, and Enhanced Security features (pointer authentication, typed allocators, hardware memory tagging, read-only platform memory), with a build- settings catalog and a filter script. Use when asked to audit or harden an Xcode project's security posture, enable security warnings or static analysis, or catch more bugs at compile time in C/C++/ObjC/ Swift. Skip for network security, code signing, or privacy APIs. (Content extracted from your local Xcode on install.)
-
stuartshields Skill Debug RulesDiagnose which rules loaded, which didn't, and why. Reads the InstructionsLoaded audit log and compares against expected rules.
-
stuartshields Bundle Module Depth ReviewUse when reviewing whether module boundaries earn their keep — finding shallow modules that should be consolidated into deep ones. Triggers on phrases like "is this over-modularised?", "should these be one module?", "too many small files doing related work", "interface feels as complex as implementation", "review the architecture of X", or when a folder has many tiny files that mostly call each other. Read-only audit; pairs with audit-vs-fix-discipline. Not a substitute for `simplify` (which works inside functions) or `cleanup` (which removes dead code).
-
vindm Skill Journey MappingBuild the prior-surface inventory before designing OR auditing any screen — walk every surface the user touched before reaching this one, classify each by type, and apply the forbidden-pattern matrix so first-touch copy/voice/chrome never leaks onto a daily-driver surface. Load before any new design spec or any single-screen / flow audit.
-
vindm Skill Persona TestingRun three orthogonal outside-eyes tests on every user-visible string — day-30 (frequency-jaded), partner (voice-register), and stranger (already-knows-me) — to catch voice violations that pass a deny-list but still feel wrong. Load at design time on every proposed string and at audit time on every visible string on a captured surface.
-
waldencui Skill Docs SyncCheck if documentation is in sync with code. Use when the user wants to verify that documentation matches current code, find outdated docs, or audit documentation accuracy. Triggers on requests like "check docs", "sync documentation", "are the docs up to date", "/docs-sync".
-
waldencui Skill Code QualityRun code quality checks (ruff lint, ruff format, pyright, pytest) on a directory and report findings by severity. Use when the user wants to audit code quality, check for type errors, lint issues, or run automated checks on a path. Accepts a directory path as argument. Triggers on requests like "check code quality", "run quality checks", "/code-quality apps/".
-
kakarot-oncloud Bundle Code ReviewerPerforms senior-level code review on a diff, file, or snippet. Surfaces bugs, security issues, performance problems, and design smells with severity tags and concrete fix suggestions. Use this skill when the user asks to "review this code", "check this PR", "look for issues", or pastes code for feedback.
-
kakarot-oncloud Bundle Env Var AuditorAudits how a project handles environment variables and secrets — finds hardcoded values, missing .env.example entries, unsafe defaults, and inconsistent naming. Generates a clean .env.example. Use this skill when the user asks to "audit env vars", "generate .env.example", "find secrets in my code", or wants to clean up configuration handling before open-sourcing or onboarding.
-
kakarot-oncloud Bundle Changelog WriterWrites CHANGELOG.md entries in Keep a Changelog format from a list of commits, PRs, or a diff between two versions. Groups changes into Added, Changed, Deprecated, Removed, Fixed, Security. Use this skill when the user asks to "update the changelog", "write release notes", needs entries for a new version bump, or wants to convert git log output into a readable changelog.
-
kakarot-oncloud Bundle Error Message ImproverRewrites cryptic, unhelpful, or user-hostile error messages into clear, actionable ones that tell the user what went wrong, why, and what to do next. Use this skill when the user pastes an error message and asks to improve it, says "make this error better", needs user-facing error copy, or asks to audit error handling for clarity.
-
kazukinagata Bundle Monitoring TasksPerforms a health check on tasks. Analyzes task age (stagnation), field completeness by status, blocked tasks (including other assignees' blockers), and executor ratio (human vs AI delegation). Supports 3 modes: specific assignee (by name), all tasks (team-wide overview), or defaults to current user when no target is specified. Use this skill whenever the user wants to monitor task health, check stagnation, audit task quality, or review AI delegation metrics — even if they don't say "monitor" explicitly. Triggers on: "monitor tasks", "task health check", "task analysis", "stagnation report", "task monitoring", "task report"
Audited -
keybase Skill Prod BundlesUse when the user asks to build production bundles, check bundle sizes, audit tree-shaking, or verify mobile/desktop code separation. Covers both the desktop webpack prod build and the iOS/Android Metro bundle.
-
ok-helloworld Skill Csp Bypass AdvancedAdvanced Content Security Policy bypass techniques. Use when XSS or data exfiltration is blocked by CSP and you need to find policy weaknesses, trusted endpoint abuse, nonce leakage, or exfiltration channels that CSP cannot block.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include running-in-ci, oss-readiness, review-and-fix. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.