Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
waishnav Bundle Cleanup WorkAudit, harden, and simplify an existing implementation after an AI-generated or broad first pass. Use when Codex is asked to clean up work, perform a reliability pass, prepare code for merge, address review findings, reduce GPT-style TypeScript such as repeated unknown/isRecord guards or condition-heavy orchestration, or investigate races, duplicated truth, lifecycle gaps, weak adapter boundaries, performance regressions, and feature-overhaul fallout.
-
databricks-solutions Bundle Databricks Unity CatalogUnity Catalog system tables and volumes. Use when querying system tables (audit, lineage, billing) or working with volume file operations (upload, download, list files in /Volumes/).
-
bagelhole Bundle Threat ModelingConduct threat modeling using STRIDE methodology. Identify threats, assess risks, and design security controls. Use when designing secure systems or assessing application security.
-
bagelhole Bundle Incident ResponseHandle security incidents with IR playbooks and procedures. Implement detection, containment, eradication, and recovery processes. Use when responding to security events or building incident response capabilities.
Audited -
bagelhole Skill Hipaa ComplianceImplement HIPAA security and privacy rules. Configure PHI protections and BAA requirements. Use when handling healthcare data.
Audited -
ai-driven-school Skill APIGenerate OpenAPI 3.0 specification documents with endpoints, schemas, and security definitions. Use when designing REST APIs, creating API docs, or running /api.
-
ai-driven-school Skill ReviewRun code review against design documents, checking acceptance criteria, security, performance, and test coverage. Use when reviewing implementation quality or running /review.
Audited -
ai-driven-school Skill AnalyzeAnalyze entire codebases using Gemini CLI's 1M token context. Generates architecture reports covering structure, security, performance, and improvement roadmaps. Use when auditing code quality or running /analyze.
Audited -
lallapallooza Bundle Vs Core AuditAdversarial review with parallel specialized agents. Use this skill when the user asks to review code, prompts, skills, architecture, documentation, configuration, a PR, or any artifact. Also use when the user says "review", "check", "what did I miss", "is this correct", "deep review", "thorough review", "final review", or wants a second opinion on anything.
Audited -
metalnib Bundle Dotnet Techne Code ReviewUse when reviewing PRs/diffs/branches/documents for .NET quality, correctness, performance, security, data access, messaging, and observability. Includes adversarial critical-thinking mode for skeptical/cynical review requests. Keywords: code review, review PR, review diff, critical review, cynical review, adversarial review, production readiness, low GC, AOT, security review.
Audited -
pratiyush Skill Skill With ExtendedDemonstrates extended spec features. Use when learning about security, testing, composition.
-
svgreg Bundle Sg MaintainRun one surfaceguard self-maintenance cycle — pick a single activity (rule polishing, threat research, rule implementation, code review, corpus sweeping, or GitHub issue triage/implementation), run it, and log the result. This is the entry point for the scheduled maintenance loop. Use when asked to run a maintenance cycle, tend the project, or when invoked on a schedule via /loop.
-
svgreg Bundle Sg Code ReviewPerform a cold code review of one rotating area of the surfaceguard codebase — hunt for correctness bugs, security issues, and performance/efficiency problems, then fix what fits in one PR. Use when asked to review the code, audit for bugs, do a security or performance pass, or when the maintenance loop selects code review.
-
svgreg Bundle Sg Rule PolishPolish one existing surfaceguard detection rule — pick the least-recently-tuned rule, audit its real false positives against the evaluation corpus, generate realistic real-world attack test cases for its threat class, then widen the match tree where it misses and narrow it where it over-matches. Opens a PR. Use when asked to polish, harden, tune, improve coverage of, or reduce false positives on an existing rule, or when the maintenance loop selects rule polishing.
-
zubair-trabzada Skill Finance RetirementRetirement projection with Monte Carlo simulation logic. Calculates required nest egg via 4% rule and 25x expenses, projected vs needed gap, contribution recommendations, asset allocation by age, Social Security claim optimization, healthcare cost projections, and withdrawal sequence planning. Use when the user says "/finance retirement", "am I on track for retirement", "how much do I need to retire", "Social Security timing", or any retirement question.
-
zubair-trabzada Skill Recruit EmployerEmployer Brand Audit — Glassdoor/Indeed review analysis, LinkedIn company page assessment, career site evaluation, employee testimonials, competitiveness vs other employers
-
zubair-trabzada Skill Reputation AuditFull Reputation Audit
-
zubair-trabzada Skill Full Restaurant Audit OrchestratorLaunches 5 parallel AI agents to produce a comprehensive restaurant audit with composite Restaurant Health Score (0-100), grade, and prioritized action plan
-
zubair-trabzada Skill Restaurant Quick60-Second Restaurant Snapshot — quick assessment without subagents with grade, top 3 fixes, and CTA to full audit
-
zubair-trabzada Skill Restaurant OnlineOnline presence audit — Google Business Profile completeness, Yelp listing quality, website assessment, online ordering setup, third-party platform presence
-
zubair-trabzada Skill Restaurant PhotosFood photography audit — reviews existing photos, identifies missing item photos, provides specific shot list with angles, lighting, and styling direction
-
surfrrosa Skill PerfAudit performance — bundle size, image weight, render-blocking resources, and Core Web Vitals via PageSpeed
-
surfrrosa Skill PrivacyAudit data collection, consent flows, exposed secrets, and privacy policy accuracy
-
surfrrosa Skill CouplingOrthogonality / module-coupling audit. Asks the Pragmatic Programmer's central orthogonality question — "if I change feature X, how many modules light up?" — and surfaces the answer with mechanical evidence. Finds circular imports, cross-layer architecture violations, centralization magnets (large file × high fan-in), hidden coupling via git file-co-change patterns, and wildcard / dead imports. Use as a periodic full-codebase sweep (monthly, or before launches that grow surface area), or after a wholesale architectural refactor.
-
texarkanine Bundle Slobac AuditUse this skill to audit a test suite or set of test files for for test quality and design smells. Produces a portable findings report without modifying code.
-
whatifwedigdeeper Skill Audit And FixSecurity audit with automatic fixes for vulnerabilities
-
abdurshd Skill I18N SweepSweeps a codebase for internationalization gaps, including hardcoded user-facing strings, missing translation keys, and locales that drifted out of sync, then fills the gaps with proper translations and verifies the result. Use when UI is untranslated, screenshots show mixed languages, the user asks to add a language, or an i18n audit is requested for a page, directory, or whole project.
Audited -
abdurshd Bundle Claude ReviewUse Claude Opus 5 through the authenticated Claude Code CLI as a detached critical reviewer for either (1) implementation-plan review before coding or (2) uncommitted-code review before commit. Trigger this skill when Codex already has a concrete task and either needs an independent Claude review to stress-test the plan against the codebase, security, and correctness concerns, or needs Claude to review local workspace changes for correctness, regressions, security, and alignment with the target task. Best for medium/large tasks, security-sensitive changes, refactors, and any work where Codex should iterate with Claude until the plan or implementation is defensible.
Audited -
aboudjem Skill Flow AuditUser flow and navigation audit covering information architecture, onboarding, and error states. Use when the user asks for a flow audit, a navigation audit, an onboarding review, or help with a UX flow.
Audited -
aboudjem Skill Design AuditFull project design audit that orchestrates all agents, scores across 12 dimensions, and generates a prioritized action plan. Use when the user asks to audit their design, run a design review or UX audit, review their UI, or asks how their design looks.
Audited -
aboudjem Skill Design ScoreQuick design score card covering 12 dimensions with the top 5 improvements, in under 2 minutes. Use when the user asks for a design score, to score their design, to rate their UI, or for a quick audit.
Audited -
aboudjem Skill Layout AuditLayout and spacing audit covering grid, spacing consistency, density, and responsive behavior. Use when the user asks to audit the layout, run a layout audit or grid audit, review spacing, or fix their spacing.
Audited -
amanahmed2222 Bundle SecurityUse when auditing security, checking for vulnerabilities, scanning for secrets, or reviewing dependencies. OWASP Top 10 audit with GitLeaks and dependency checks.
-
anilcancakir Bundle Review ChangesReview uncommitted code changes for bugs, security vulnerabilities, and quality issues. Use before commits or when asked to review code.
-
eunomia-bpf Skill Iter Refine WritingIteratively refine the WRITING of a systems paper through 12 serial review-fix rounds. Covers macro structure, micro structure, section conventions, explicit RQ-organized evaluation, logic flow, abstract/intro rebuild, consistency, language (3 passes), terminology/claim tone, citation verification, and a final meaning-preservation audit against the entry baseline. Does not handle claims, RQ meaning, research framing, or scope. Use when the user asks to iterate, polish, or improve paper writing, or when an orchestrated WRITE gate requires full writing refinement. Never invoke iter-refine-ideas; report scientific-contract defects to the caller. Works with LaTeX papers targeting any systems venue.
-
eunomia-bpf Bundle Iter Review CritiqueIteratively review and attack a complete research paper across systems, AI/ML, or cross-domain venues. Use for an orchestrated REVIEW gate, whole-paper accept/reject simulation, source-grounded novelty and evidence attack, external closest-work/baseline/protocol/contradictory-evidence search, cycle-change audit, or choosing the next decisive experiment. Reads all of docs/paper/, selects venue/domain-specific references, searches and opens primary external sources, rereads the full paper, and returns detailed auditable reports. Read-only for the paper.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include dotnet-techne-code-review, cleanup-work, databricks-unity-catalog. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.