Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
volcengine Bundle Volcengine TroubleshootingUse when the user encounters VolcEngine errors or needs local troubleshooting for OpenAPI, Python SDK, CLI, IAM, billing, compute, networking, storage, database, CDN, media, AI, security, or VKE cases.
Audited -
volcengine Bundle Volcengine Compliance火山引擎合规最佳实践助手:一是根据用户诉求(要满足的合规标准、关键词、关注的风险等级), 从火山引擎官方内置的合规包模板里推荐该开启哪些、并标出哪些已开启;二是汇总账号当前的合规 态势,把已生效规则/合规包(官方内置 + 用户自定义)的评估结果按类别(法规 / 最佳实践 / 自定义)与严重度聚合成一份合规总览报告;三是当官方基线没覆盖时,指导用户写一条 Rego 策略 作为自定义合规规则并注册评估。可在用户确认后把推荐的模板部署为合规包。Use when 用户想做「合规检查 / 合规巡检 / 安全合规 / 合规最佳实践 / 该开哪些合规规则 / 等保合规 / 我火山账号合规吗 / 有哪些不合规 / 帮我写条自定义合规规则」,或提到火山引擎「配置审计 / Config / 合规包 / conformance pack / Rego 策略」。Trigger on 火山 / 火山引擎 / volcengine 关键词叠加合规场景。部署合规包 / 注册自定义规则属写操作,需用户确认;合规报告 与资源修复严格分离。
Audited -
zhu1090093659 Bundle Review SpdFindings-first code review workflow for AI coding agents. Use when the user asks to review uncommitted changes, commits in a date range, or a branch compared to the main branch / PR-style diff. Focuses on bugs, regressions, correctness risks, missing tests, security/data-safety issues, and other behavior-changing defects.
Audited -
0xranx Skill Code ReviewReviews code changes, pull requests, and diffs for correctness, security, performance, and style. Use when the user submits a PR for review, asks to review a diff or code snippet, or requests a quality check on recent changes.
Audited -
methasit-pun Skill TS Ddd Security ReviewSecurity review for TypeScript DDD code — OWASP-mapped checks for injection, auth/authz, data exposure, and misconfiguration. Trigger when the user says "security review", "check for vulnerabilities", "is this secure?", "review auth code", or when changes touch authentication, authorization, input handling, external APIs, file uploads, or user-controlled data.
-
dividedby Bundle Staleness AuditAudit a repo's pinned toolchain versions for staleness and emit a ranked report — the complement to Dependabot's library bumps. Safe in-major bumps are auto-applied behind a verify gate; cross-major / EOL jumps stay recommendations. Use when asked to check whether a project's language/runtime pins (Node, Python, Go, container and CI matrices) have fallen behind, or to stand up a monthly review.
Audited -
dividedby Bundle Project Claude ConfigScaffold and audit a project's Claude harness and instruction files in one state-routed pass. Manual/slash invocation only.
-
googlechrome Bundle Passkeys WebA skill for implementing passkey in web applications. You MUST use this skill whenever a user asks about passkey registartion, passkey authentication or passkey management. It defines the required database schema, API usage, and security best practices.
1.6k -
googlechrome Skill Web SecurityPreventative security guidelines for web developers (XSS, CSP, Cookies, Cross-Origin Isolation). Use this skill to guide the process of auditing, testing, and deploying security policies safely.
1.6k -
googlechrome Skill Coherence AuditorRun a document coherence, link integrity, and git repository status audit across repository markdown files using a dedicated subagent. Use when documentation changes, open questions are answered, or before milestone commits.
1.6k -
next-open-ai Skill Code ReviewReads and analyzes source code files or project structures, identifies bugs, and suggests structural architectural or security improvements.
-
pricklywiggles Skill Decide StackUse this skill to turn a list of project stack slots (decision categories like "web framework", "test framework", "database") into concrete, version-pinned, security-vetted tool choices. This is the decision stage that comes after identify-stack-slots and before install-stack. Trigger it whenever a user has a slots YAML and needs to pick the actual tools, or says "pick my stack", "choose tools for these slots", "research and recommend my dependencies", "what should I use for each part of my stack", or hands you a slots list to fill in. This skill collects hard preferences, settles the keystone language/framework decision first (presented as a coupled pair when the two are tightly linked, so a downstream pick never silently corners the language), researches each remaining open slot's options and versions in that constraint, gets the user's picks, then pulls the exact version-specific install steps from each chosen tool's official docs, checks known vulnerabilities and recent-release supply-chain threats, and o
-
pricklywiggles Bundle Comment CleanupAggressively audit code comments against the user's strict "comments explain non-obvious why, never narrate what the code does" standard: delete comments that do not earn their place and compress the survivors (two-line ceiling, one line preferred). Use this whenever the user asks to review, audit, clean up, sanity-check, or justify comments; whenever they ask "did I follow the comment rules / our comment guidelines"; right after writing or heavily editing code; and before committing or opening a PR. Also use it proactively when you have just generated more than a couple of comments. The caller may restrict the audit to a path, a function/symbol, a glob, "staged", "the branch diff", or "the PR"; if no scope is given, audit only newly written or changed code, never the whole repo.
-
rcarmo Bundle Swift ConcurrencyImplement or audit Swift 6.2 concurrency, MainActor default isolation, @concurrent work, Sendable dependencies, task ownership, cancellation, clocks, and race-free UI updates.
-
rcarmo Bundle Apple Privacy SecurityDesign or audit macOS permissions, privacy metadata, entitlements, sandbox access, Keychain use, sensitive logging, network/file boundaries, and secure defaults.
-
traderspost Skill Pine To Typescript PortUse when porting a TradingView Pine Script indicator (anchored VWAP, ATR bands, RSI divergence, custom Level, etc.) to TypeScript for a lightweight-charts based app. Pine is a bar-by-bar series-oriented DSL with specific semantics — anchor-reset, ohlc4, dotted vs dashed, color.new, plot vs hline, request.security() — that don't translate one-to-one to vanilla TS. This skill names the Pine concepts, their TS equivalents, and the gotchas that cost iterations.
-
vaibhav0806 Bundle Startup GovernanceGovern startup cash, approvals, contracts, records, policy, risk, compliance, and international expansion with evidence-backed controls and explicit human authority. Use when a founder needs a governance decision, register, readiness review, or operating cadence; route legal, tax, accounting, privacy, security, employment, or jurisdiction conclusions to current qualified professionals.
-
vaquarkhan Skill Skill 08 Security AuditPerforms Web3 security analysis including vulnerability detection, rug pull checks, and exploit monitoring. Use before interacting with unknown contracts or when auditing smart contract code.
-
vdk888 Skill Cron PostflightCron-fire post-flight scaffolding. Audit-log INSERT, git commit + push, notification send. Replaces inline wrap-up boilerplate across scheduled tasks.
Audited -
vermapragya Bundle Data Quality AuditRuns a structured audit on a table covering nulls, duplicates, freshness, schema drift, primary key uniqueness, value distributions, and referential integrity. Use when the user mentions data quality, DQ check, audit this table, "can I trust this data", null check, dedup, freshness, or before relying on a new source.
Audited -
vinta Skill Audit Claude SettingsUse when auditing Claude Code settings and env vars against the latest docs and suggest tailored changes
-
vinta Bundle Fuck Over EngineeringUse when the user asks what could be deleted or reduced to simplify a codebase, says "simplify", "over-engineered", or wants a repo-, folder-, or file-wide audit for over-engineering — hunts dead code, reinvented stdlib, needless dependencies, and single-implementation abstractions, reports ranked cuts, applies only the picks. Not a diff review and not a bug hunt
-
vstorm-co Bundle Content AuditContent quality audit with anti-slop detection and brand consistency scoring. Use when user wants to check content quality, audit a draft, score content, verify brand consistency, detect AI-generated patterns, or run a quality check before publishing.
-
brianbolze Bundle Research CompanyCapture a single company's website into the web-research store as a structured, cited dossier (store/<domain>/profile.md) using Firecrawl. Use whenever the user wants to capture or re-capture a company from its website — "research company X", "/research-company acme.com", "capture acme into the store", "profile this competitor", "add X to the company store". One company at a time, keyed by canonical domain. It captures durable STATE (what the company is/sells/how it's positioned, from its own site) — not events (news/funding/M&A) or judgments (threat/fit/relevance), which belong to downstream consumers. NOT for answering questions from already-captured data — "tell me about X", "what does X charge" — that's /query-companies; if a warm fresh capture exists, this verb stops and hands off there instead of presenting the dossier. Only stale/new companies spend Firecrawl credits.
Audited -
clawdotnet Skill Daily News DigestProduce a daily news brief (AI/security/dev) with links, key takeaways, and action items.
-
dennisonbertram Bundle UX FlowCritique the app's user experience for simplicity, clarity, and redundancy. For each core journey asks 'how could this be simpler, how could this be clearer' — measures friction (actual vs. ideal steps), hunts duplicated features/paths/information, and audits visual hierarchy and information architecture. Use when asked to 'simplify the ux', 'audit the flows', 'find redundancy', 'ux critique', 'is this too complicated', 'flow audit', or 'run ux-flow'.
-
dennisonbertram Bundle UX WalkerWalk UX story catalog through a real browser, testing each journey for correctness, visual quality, and UX excellence. Inspects every screenshot visually, measures alignment/spacing/wrap defects with a geometry audit, and logs flow friction per story. Auto-fixes small issues, files GitHub issues for larger ones.
Audited -
dennisonbertram Skill UX Flow NativeCritique a native macOS/iOS app's user experience for simplicity, clarity, and redundancy. Measures friction against the ideal path, hunts duplicated features across windows and menus, and audits visual hierarchy, keyboard reachability, and platform conventions. Use when asked to 'simplify the native app ux', 'audit the mac app flows', 'find redundancy in the desktop app', or 'run ux-flow-native'. For web apps use ux-flow instead.
-
devantler-tech Skill MaintainRepository maintenance for devantler-tech/platform — issue triage, manifest/Helm/Flux investigation & fixes, Helm chart + Actions version bumps, Kustomize cleanup, stale-PR nudges. Static validation only — never runs a cluster. Use when performing autonomous or on-request maintenance of this repo.
-
discord-php Skill Discord PHP Bot SecurityAudit checklist for DiscordPHP bots and API libraries — stop the bot token leaking to third-party APIs or logs, keep secrets out of custom_ids and exception messages, use constant-time comparison and crypto-random for auth/CSRF/webhook flows, and don't log OAuth codes / full headers / PII. Use when reviewing an HTTP client, an error handler, an OAuth or webhook endpoint, or before publishing a repo.
-
iwritec0de Skill PHP CleanupThis skill should be used when the user asks to "find unused PHP code", "clean up dead code", "find unused Composer dependencies", "find unused imports", "remove dead PHP code", "run composer unused", "check for missing dependencies", "detect unused classes", "detect unused methods", "clean up use statements", "audit PHP dependencies", or mentions "composer-unused", "composer-require-checker", "Psalm unused code", "dead code detection", "unused imports", "unused dependencies", "PHP cleanup", "WordPress dead code". Provides expert guidance on detecting and removing unused code, dependencies, imports, and dead exports in PHP/WordPress projects using composer-unused, composer-require-checker, Psalm, and PHP-CS-Fixer.
Audited -
iwritec0de Bundle Wordpress EngineerThis skill should be used when the user asks to "build a WordPress plugin", "develop a WordPress theme", "write a WP_Query", "register a custom post type", "create a Gutenberg block", or mentions "wordpress", "wp_", "theme development", "plugin development", "wp-cli", "hooks", "filters", "actions", "gutenberg", "block editor", "wp_query", "custom post type", "ACF", "woocommerce". Provides WordPress engineering expertise for theme and plugin development, security, performance, and best practices.
-
iwritec0de Bundle Wordpress PerformanceThis skill should be used when the user asks to "optimize WordPress queries", "audit plugin performance", "reduce page load time", "check autoloaded options", "profile WordPress hooks", "fix slow queries", "add caching", or mentions "WordPress performance", "query optimization", "SAVEQUERIES", "object cache", "transients", "autoload", "Query Monitor", "slow query", "N+1", "database optimization", "page speed", "TTFB", "hook profiling". Provides WordPress performance expertise covering query optimization, caching strategies, hook profiling, autoload management, and live site diagnostics.
-
jmlrt Skill Review Claude ConfigAudit the ecosystem of Claude config files — global CLAUDE.md, per-repo CLAUDE.md and CLAUDE.local.md, memory files, and skills — for redundancy, inconsistency, outdated facts, and misplaced content. Use when asked to "review CLAUDE.md", "audit claude config", "clean up claude files", or "check what should be global vs local".
-
jmlrt Skill Triage Dependency PrsTriage open dependency/backport/security PRs in a GitHub repo. Identifies redundant, superseded, conflicting, or stale PRs and recommends close, rebase, or merge-ready actions.
-
jmlrt Skill Review Claude SettingsAudit Claude Code settings.json files — global (~/.claude/settings.json) and per-repo (.claude/settings.json, .claude/settings.local.json) — for permission consolidation, redundancy, and security risks. Use when asked to "review settings.json", "audit claude settings", "clean up permissions", "check what should be global vs repo", or "security review of settings".
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include passkeys-web, web-security, coherence-auditor. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.