Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
auditmos Bundle Audit Liquidation CalculationAudits Solidity liquidation mechanisms for calculation vulnerabilities including incorrect liquidator reward decimals making rewards too small/large, unprioritized liquidator rewards paid after other fees removing incentive, excessive protocol fees making liquidation unprofitable, minimum collateral requirements not accounting for liquidation costs, unaccounted yield/PNL not included in collateral valuation, missing swap fees during liquidation, and oracle sandwich self-liquidation manipulation
-
autodevx Skill Contagem De Prazo ProcessualCalcula prazos processuais em dias úteis considerando feriados nacionais, estaduais e municipais, suspensões de recesso forense e regras do CPC, entregando data-limite com memória de cálculo completa e auditável.
Audited -
autodevx Skill Classifica O De Risco E Provis O Cpc 25Classifica o risco de cada processo judicial como Provável, Possível ou Remoto conforme CPC 25 e calcula o valor de provisão contábil recomendado, com memória de cálculo auditável para reporte ao financeiro e auditoria externa.
Audited -
autodevx Bundle Contingencia ReportGera relatórios estruturados de contingência jurídica para uso em balanços, auditoria e compliance. Use quando o usuário precisar classificar processos por probabilidade de perda (provável/possível/remota) conforme CPC art. 95-96 e IAS 37 / CPC 25, calcular impacto financeiro no passivo contingente, ou preparar memórias de cálculo auditáveis para controllers e auditores externos. Aplicável a portfólios de processos cíveis, trabalhistas e tributários.
-
aymericzip Bundle Intlayer CLIManages Intlayer dictionaries and configuration via the Command Line Interface. Use when the user asks to "audit translations", "build dictionaries", "sync content", or run "intlayer" commands.
-
bottelet Skill Security Review ChecklistStatic review rules for authorization, validation, and privilege escalation risks
Audited -
authenticfake Skill Secure Config SecretsEnforce safe configuration, secret handling, auth boundaries, restricted egress, and security evidence for promotable software.
-
authenticfake Skill Enterprise Solution ArchitectureKeep enterprise solutions coherent across requirements, runtime profiles, integration boundaries, observability, audit, and release readiness.
Audited -
geoly-ai Bundle Geo Sentiment OptimizerAudit and optimize brand messaging to improve how AI platforms portray your brand. Fix negative AI sentiment signals and strengthen positive brand associations through content optimization. Use whenever the user mentions AI saying negative things about their brand, improving AI brand portrayal, auditing content for sentiment signals, fixing brand perception in AI search, or strengthening brand voice for GEO.
Audited -
fastled Skill Address ReviewsFetch CodeRabbit review comments on the current PR, classify each finding, apply fixes for valid issues, and reply to each thread. Use before attempting gh pr merge when CodeRabbit has posted a review. Blocks merge on unresolved threads. Routes security-critical findings to a human.
-
legions-developer Skill Two Factor Authentication Best PracticesConfigure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin. Use when users need MFA, multi-factor authentication, authenticator setup, or login security with Better Auth.
-
legions-developer Skill Email And Password Best PracticesConfigure email verification, implement password reset flows, set password policies, and customise hashing algorithms for Better Auth email/password authentication. Use when users need to set up login, sign-in, sign-up, credential authentication, or password security with Better Auth.
-
legions-developer Skill Nodejs Best PracticesNode.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.
-
secondorderai Bundle ElectronBuild cross-platform desktop applications with Electron, covering main/renderer process architecture, IPC communication, BrowserWindow management, menus, tray icons, packaging, and security best practices. Use when the user asks about Electron, needs to create desktop applications, implement Electron features, or build cross-platform desktop apps.
-
secondorderai Bundle Ou Full Code ReviewPerform a comprehensive full-codebase code review using specialized parallel agents. Use this skill whenever the user asks for a "full code review", "codebase review", "review everything", "audit the code", "code health check", or any request to review the entire project (not just a PR or single file). Also trigger when the user says things like "what's wrong with this codebase", "find all the issues", "review all my code", or "comprehensive review". This is specifically for whole-codebase analysis, not single-file or PR-scoped reviews.
-
rediumvex Skill Market ReportCompile previously-generated audit artifacts into a client-ready report in Markdown or PDF format. Invoke whenever the user says "report", "final report", "deliverable", "client report", "PDF report", or runs `/market report <url>` or `/market report --format pdf <url>`. Reads existing audit files in the project root and produces one consolidated deliverable.
-
reticlehq Skill Audit My AppSweep a whole running web app for what is broken, without writing a script or knowing the codebase. Clicks every reachable control and reports dead buttons, console errors, failed requests, and places where the API and the screen disagree. Use on an unfamiliar codebase, before a release, after a big merge or dependency bump, when the user asks for a smoke test or a health check, or when someone says "just check everything still works".
Audited -
samgalanakis Skill ProspectBenchmark your project against reputable peer projects and mine them for concrete improvements: survey your repo, clone references locally, extract enforceable mechanisms, audit your own code through each reference's written doctrine, verify every finding independently, and output a verified improvement batch. Use when the user wants to benchmark against comparable projects, mine external repos for practices, or run an outward-looking quality round.
-
samgalanakis Bundle ComplexitysmashAudit a codebase for systemic complexity and simplification opportunities: duplicated business logic, unnecessary abstractions, mixed responsibilities, poor boundaries, pattern drift, indirection without payoff, and modules that should be merged, split, or deleted. Use when the user wants a full-project design pass or says the codebase feels over-engineered, inconsistent, hard to change, or harder than the problem requires. Prefer this over spring-cleaning when the issue is architectural or cross-cutting rather than a smaller cleanup pass.
-
samgalanakis Bundle PerformancesmashAudit a codebase or system for real performance bottlenecks and optimization opportunities across CPU, memory, allocation behavior, data access, caching, databases, network hops, payload size, batching, connection management, concurrency, queueing, and compression. Use when the user wants a serious performance pass, suspects the system is slow or wasteful, or wants guidance on where latency, throughput, or resource efficiency are being lost. Prefer this over ad-hoc micro-optimizing or style-level cleanup.
-
sap Skill Best PracticesAudit existing code against project conventions and Angular 22+ best practices
-
schub-tech Skill Wiki LintRun semantic wiki lint beyond structural link checks. Use when the user asks to audit, lint, health-check, find stale claims, find unsupported claims, check provenance, or identify contradictions in the wiki.
-
semantius Bundle Semantius OptimizerReverse-engineers a `*-semantic-spec.md` file (the analyst artifact, version "5.4") from a live Semantius module: reads the module's entities, fields, enum values, permissions, roles, and permission hierarchy via `semantius`, pulls in referenced built-ins (e.g. `users`) so the output is self-contained, and writes a spec byte-compatible with the template `semantius-analyst` produces and `semantius-modeler` deploys. Deterministic: the mapping runs through `references/spec-extract-lib.ts`. After saving, optionally runs an audit pass. Trigger when the user wants to extract / export / optimize / snapshot / reverse-engineer / pull / regenerate a spec from a live Semantius module, build a spec for a module created without one, or bring a customized live module back in sync with a markdown spec. Example phrases: "generate a spec from the `{slug}` module", "reverse-engineer the `{slug}` module into a spec", "someone built a module in the UI, get me a spec", "pull `{slug}` down to a semantic spec".
Audited -
tomkraaij Skill Tenant Security ReviewOrganization baseline checklist for SaaS tenant isolation.
-
tomkraaij Skill Tenant Isolation ChecklistChecklist for validating tenant isolation in multi-tenant systems.
-
tomregan-revenueleaks Skill Speed To LeadUse when the buyer asks to build, fix, or audit a sub-5-minute B2B lead response system. Triggers on phrases like "speed to lead", "lead response time", "5 minute response", "instant routing", "Warmly + Amplemarket setup".
-
unopim Bundle Unopim StandardsUse when writing or changing any UnoPim code — the canonical rules for Laravel 13 and PHP 8.4 idiom, security, performance, scale, extensibility, localization and comments. Trigger phrases include "best practice", "standards", "laravel 13", "security", "performance", "scalable", "localization", "comments".
-
vamdawn Bundle Req Code Review发起基于实现方案和当前代码的系统性代码审查,并输出可执行的 Markdown 审查报告。Use when asked to request code review, review an implementation against plans/designs, audit code before release, review before merge, or generate a structured findings document. 适用于需要根据项目情况定义审查角色、用 SubAgent 并行审查,并将输入抽象为实现方案、输出目录和其他材料的场景。
-
vamseeachanta Bundle Audit Feedback LoopMaintains an anchored-text feedback inbox for a knowledge store where every item attaches to an exact text anchor, carries an explicit resolution state, and is never silently deleted. Use when collecting, triaging, or resolving review feedback on extracted or generated pages.
-
zebbern Bundle Code ReviewerUse when reviewing pull requests, conducting code quality audits, or identifying security vulnerabilities. Invoke for PR reviews, code quality checks, refactoring suggestions.
-
zebbern Bundle Secure Code GuardianUse when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities. Invoke for authentication, authorization, input validation, encryption, OWASP Top 10 prevention.
-
smixs Skill Blog AuditFull-site blog health assessment scanning all blog files for quality scores, orphan pages, topic cannibalization, stale content, and AI citation readiness. Spawns parallel subagents for comprehensive analysis. Produces per-post scores and a prioritized action queue. Use when user says "audit blog", "blog audit", "site audit", "blog health", "audit all posts", "check all blogs".
-
softwareone-platform Bundle Update Unit TestAudit and update unit tests for changed source signatures or a user-specified target. Two-phase: audit first, then execute automatically (no confirmation gate — actions derive from audit status; git is the rollback). Trigger phrases: "update unit tests for X", "the test for X is stale", "refresh unit tests". Do NOT trigger for: questions about how to write a unit test, refactoring discussions, or general test maintenance topics.
-
softwareone-platform Bundle Review Code RiskAdversarially review an IMPLEMENTED FIX — a committed diff on a branch — against the issue it claims to resolve and the plan it was built from, BEFORE the PR is opened. Its question is intent alignment: does THIS change resolve THAT issue, per THAT plan, without regressing callers or hiding a band-aid. Use whenever someone has an implemented fix and wants it challenged before opening a PR. Trigger phrases: "challenge this fix / diff", "will this change regress anything", "red-team this implementation", "pre-mortem this diff", "review my fix before the PR", "/review-code-risk". Do NOT trigger for: reviewing a plan / spec / RFC before implementation (review-plan-risk); generic line-level bug-hunting or style / simplification cleanup (code-review / coderabbit); security-vulnerability scanning (security-review); debugging a failing test; addressing PR reviewer comments; refactoring; or confirmatory "is this correct?" checks that want validation, not adversarial enumeration.
-
softwareone-platform Bundle Review Issue FactFact-check an ISSUE — a bug report, story, or incident description, as text or a Jira / GitHub issue link — against the codebase that is its ground truth, BEFORE any fix is planned. The issue is not a source of truth, so the question is diagnosis alignment: do its claims hold in THIS code, or is the bug misdiagnosed. Use whenever someone wants an issue or repro fact-checked before planning a fix. Trigger phrases: "fact-check this issue", "does this issue reproduce", "is the root cause right", "is this issue real / misdiagnosed", "/review-issue-fact". Do NOT trigger for: reviewing a plan / spec / RFC before implementation (review-plan-risk); reviewing an implemented fix / diff (review-code-risk); creating, editing, or transitioning a tracker issue; generic line-level bug-hunting (code-review / coderabbit) or security scanning (security-review); debugging a failing test; or confirmatory "is my understanding correct?" checks that want validation, not adversarial fact-checking.
-
softwareone-platform Bundle Update Integration TestAudit and update integration tests for changed handlers/endpoints. Two-phase: audit first, then execute automatically (no confirmation gate — actions derive from audit status; git is the rollback). Trigger phrases: "update integration tests for X", "refresh endpoint test for /foo". Do NOT trigger for: integration test infrastructure questions, container/fixture refactoring, or test strategy discussions.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include Classificação de Risco e Provisão (CPC 25), security-review-checklist, wiki-lint. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.