Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
rene-kuhm Skill AuditAuditoría completa del proyecto: dependencias, seguridad, performance, código. Genera reporte actionable.
-
alenazaharovaux Bundle UX AuditRun a full UX audit on any website: Nielsen heuristics, conversion, content, technical quality, information architecture. Produces a prioritized report with evidence-based findings and actionable recommendations. Use when asked to review a site, check a landing page, find UX problems, evaluate usability, assess conversion, or anything like "what's wrong with this site", "review the website", "audit UX", "check the forms", "why isn't the site converting".
-
muzalee Skill Code ReviewTechnical code review for correctness, security, tests, error handling, and style. Distinct from design-review (which is visual/aesthetic). Use when user says "review this code", "check my PR", "code review", "check for issues", or after implementing a feature.
-
openai Bundle ValidationUse when Codex is already in the validation phase of a security scan or the user explicitly asks to determine whether one or more candidate security findings are valid. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
23.3k -
openai Bundle Verify FixUse only when the user explicitly requests verification that a security fix remediates a reported vulnerability. Do not invoke automatically while implementing fixes, reviewing ordinary code changes, or running tests. Do not use for non-security fixes, candidate finding validation, or full repository scans.
23.3k -
openai Bundle Fix FindingUse when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
23.3k -
openai Bundle Security ScanUse for a standard, single-pass security audit of an entire repository or a scoped path, package, folder, or submodule with no diff to review. This is the default repository scan. Do not use for PR, commit, branch, or working-tree diffs, or for deep, multi-pass scans.
23.3k -
openai Bundle Track FindingsTrack validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories. Use it for one finding or an explicitly selected batch of up to 25 findings tracked as Linear, Jira, or GitHub issues. Includes duplicate checks, exact previews, approval-gated writes, and readback. Do not use it for scans or fixes.
23.3k -
openai Bundle Assess Patch RiskAssess an immutable patch artifact's program impact, regression risk, and auto-merge eligibility. Use for generated patch files, provider pull-request diffs, or commit ranges when reviewers need evidence about affected runtime paths, contracts, tests, and recoverability. This skill is read-only and does not generate, edit, apply, push, or merge the patch.
Audited 23.3k -
openai Bundle Deep Security ScanUse when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated complete independent Standard scans with the Codex Security deep-scan tool, which aggregates their validated findings and prepares the canonical artifacts; then complete the same scan once. Do not use for PRs, commits, branch diffs, or working-tree diffs.
23.3k -
openai Bundle Security Diff ScanReview a pull request, commit, branch diff, or working-tree patch for security vulnerabilities.
23.3k -
openai Bundle Attack Path AnalysisUse when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
23.3k -
openai Bundle Propose Security HardeningDevelop evidence-backed structural and architectural security hardening proposals from vulnerability disclosures, supplied findings, incident or assessment documents, source code, or a completed Codex Security scan. Use when a user asks for systemic improvements, alternatives beyond per-finding patches, before-and-after security architecture views, engineering tradeoff analysis, or an implementation-ready plan for a selected hardening option. Also use automatically after a Codex Security scan with reportable findings when the top-level scan workflow requests final-report hardening guidance.
23.3k -
patolojiai Bundle Pathology Compliance CheckerValidates surgical pathology cancer reports against CAP (College of American Pathologists) and ICCR (International Collaboration on Cancer Reporting) guidelines with severity-based compliance scoring (0-100) and automatic pT/pN/margin cross-validation. Use whenever the user pastes or uploads a pathology report (.pdf, .docx, .txt) and asks to "check compliance", "validate against CAP", "score this report", "audit this synoptic", "find missing elements", or "verify pT/pN consistency". Supports breast, colorectal, pancreas, and gastric carcinoma in English and Turkish.
-
photostructure Bundle Project SetupSetup and hardening review for cross-platform modern-C++ (C++17) native projects, especially Node.js addons built with node-gyp / node-addon-api. Use when asked to "set up a native addon", "harden a C/C++ build", "review my binding.gyp", "add compiler hardening flags", "wire up AddressSanitizer/UBSan/TSan/clang-tidy", "set up cross-platform CI / prebuilds for a native module", or "make this native code maintainable". Produces an applicability-aware baseline gap analysis (Met / Gap / Not applicable / Needs verification) across build config, per-OS/per-arch compiler hardening, sanitizer & static-analysis wiring, CI/prebuilds/supply-chain, and modern-C++ conventions — not exploit findings.
-
photostructure Bundle Web Security HardeningSecurity best-practices and hardening review for JavaScript/TypeScript web and Electron desktop applications. Use when asked to harden an app, review security posture or secure defaults, assess OWASP ASVS or Electron security-checklist alignment, improve HTTP headers or CSP, review forms/input validation/sanitization/uploads, strengthen authentication/passwords/sessions/secrets, secure Electron windows/preloads/IPC/navigation/permissions/protocols/updates/packaging, or evaluate deployment/operations controls. Produces an applicability-aware baseline gap analysis (Met / Gap / Not applicable / Needs verification), not exploit severity findings.
-
phpinfo Bundle Pflow AgentsCreates or rewrites a minimal AGENTS.md for the current project and syncs it to CLAUDE.md. Audits the repo, asks the user only for facts that cannot be derived from code or docs, drafts a file of non-guessable commands, conventions, gotchas and boundaries (no project overview, no README duplication, no generic advice), then lint-checks it for size, filler and verbatim duplication before writing. Use when asked to create, update, trim or audit AGENTS.md or CLAUDE.md. Invoked manually only.
Audited -
pilastdigit Bundle Trip ReviewReview code following project standards (manual fallback/audit path)
-
skills-il Bundle Israeli Amuta ComplianceNot legal or accounting advice and not an audited financial statement. Prepares an Israeli amuta or public benefit company (chalatz) for its annual filing to the Registrar of Associations: builds the checklist for the four annual documents, works out which governance organs and which audit duty the turnover band triggers, fixes the correct annual fee tier and deadline, and produces a gap report naming what blocks the ishur nihul takin. Use when the user asks about amuta annual reports, ishur nihul takin, doch miluli, vaadat bikoret, the amuta annual fee, or Section 46 digital donation reporting to the Tax Authority. Do NOT use for incorporating a new amuta, drafting or amending a takanon, producing the audited financial statement itself, which is reserved to a licensed accountant, or for listed-company reporting to the TASE or MAYA, which israeli-annual-reports covers.
Audited -
socketdev Skill Socket FixFix dependency security issues - either scan and fix everything (requires /socket-scan), or target a single named package. Orchestrates /socket-dep-cleanup, /socket-dep-replace, /socket-dep-patch, and /socket-dep-upgrade as subskills.
-
socketdev Skill Socket Dep PatchApply Socket's binary-level security patches without changing dependency versions. Uses socket-patch apply to fix vulnerabilities in-place, then verifies automated patching is configured so patches persist across installs.
-
socketdev Skill Socket Dep UpgradeUse socket fix to find and update vulnerable dependencies, then fix any breaking changes in the codebase. Security-audited upgrades with automated code migration.
-
splunk Bundle Vulnerability Remediation And Compliance ReadinessAssess Splunk-related advisories, CVEs, scanner or package findings, remediation and exception evidence, and vulnerability or compliance readiness. Use when Splunk administrators, security operators, compliance owners, or reviewers need an evidence-backed environment exposure decision, remediation or exception plan, reviewer-ready pass/fail/unknown assessment, or cited guidance for documented Splunk vulnerability and compliance surfaces.
Audited -
stella Skill Security AuditRun a security-focused code audit with a generic checklist first, then layer on repo-specific risks.
-
tal7aouy Skill Recruit EmployerEmployer Brand Audit — Glassdoor/Indeed review analysis, LinkedIn company page assessment, career site evaluation, employee testimonials, competitiveness vs other employers
-
talkincode Bundle Release VersionReview merged PRs since the last Git tag and decide whether a ToughRADIUS release is warranted. Use when Codex is asked to prepare a version release, audit unreleased changes, decide whether to publish, create a new release tag, or tag origin/main after PR review.
Audited -
wjgoarxiv Bundle Csw ReviewRun a binding, all-or-nothing review for broad, risky, shared, security-sensitive, or release-facing work across compliance, code quality, real manual QA, evidence integrity, security, and scope fidelity.
-
youlaitech Bundle Spring BootThis skill should be used when developing Spring Boot projects, implementing REST APIs with MyBatis-Plus, configuring authentication with JWT/Redis tokens, implementing permission control with Spring Security, or adding new backend modules in the youlai-boot project.
-
ytrofr Skill Skill Maintenance SkillMonthly skill library maintenance with audit scripts and gap detection. Use when auditing skills for 'Use when' patterns, checking activation rates, or maintaining skill quality.
-
ztemerbekov Bundle A1 Consumer PsyAudit consumer psychology hypotheses or analyze test outcomes using peer-reviewed research to explain user behavior, identify flaws, and set evidence limits.
-
endika Skill Exploit HuntUse when hunting for actually-exploitable vulnerabilities — reachable, user-controlled paths into a real sink (SSRF, SQLi, command injection, RCE, deserialization, path traversal, XSS), discarding theoretical or local-only noise. Offensive triage, the counterpart to security-bar's defensive checklist.
-
gerardordz96 Bundle Aios AuditUse when someone asks for an AIOS audit, asks to score their setup against the Four Cs, or says "is my AIOS working" / "audit my setup" / "find gaps in my AIOS" / "/aios-audit". Produces a Four-Cs scoreboard with top-3 fixes ranked by leverage.
Audited -
imyourboyroy Bundle Brand DoctorRun Portable Web Toolkit brand-doctor for favicons, OG images, and brand/meta asset audits on toolkit-managed sites. Use when branding, social previews, or icon sets need audit or repair. Follow the client Brand Guide.
-
jasonlo Skill Ss Skill CraftCreate, improve, and design Claude Code skills. Routes between three modes: create (new skill from scratch), improve (fix quality issues in existing skills), and design (architect multi-step workflow skills). Use when users want to create a skill, turn a workflow into a skill, write a SKILL.md, improve skill quality, fix frontmatter, audit skills, design workflow architecture, or structure multi-step skills. Triggers on "create a skill", "make a skill", "turn this into a skill", "new skill", "fix my skill", "improve skill quality", "skill review", "audit skills", "design a workflow skill", "skill architecture", "multi-step skill".
-
jasonlo Bundle Ssm Skill ValidateValidate all skills in this repo for frontmatter correctness, naming conventions, and structural rules. Use when adding a new skill, before releases, or in CI. Triggers on "validate skills", "lint skills", "check skills", "audit frontmatter", "skill validation", "pre-release check".
Audited -
markphelps Skill Oss Repo ReadinessAudit and prepare a GitHub repo for open source release, with a focus on developer experience (DevEx) — the things that determine whether a stranger can go from "found this repo" to "opened a PR" without friction. Use this whenever the user wants to open-source a repo, make a private repo public, do a "pre-launch checklist" or "OSS readiness audit," improve their README/CONTRIBUTING/issue templates, or asks something like "is this repo ready for people to use/contribute to." Also trigger for narrower asks that are really pieces of this — "write a CONTRIBUTING.md," "set up issue templates," "add a CODEOWNERS file" — since those are almost always better done as part of the full readiness pass rather than in isolation.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include propose-security-hardening, validation, verify-fix. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.