Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
teddy563 Bundle Audit ConfigAudits a Minecraft server's configuration tree for performance, security and footgun issues and reports a prioritised fix list. Use whenever the user asks to "audit my config", "check my server config", "review paper-global.yml", "why is my server set up wrong", "is this config safe", "lint my server", or points at a folder containing server.properties, paper-global.yml, paper-world-defaults.yml, paper-world.yml, spigot.yml, bukkit.yml, purpur.yml or velocity.toml. Also use proactively after the user shares any of those files or pastes their contents. Flags online-mode/forwarding mismatches, exposed RCON, YAML tab characters, view-distance/simulation-distance mismatches, missing entity limits, and unsafe unsupported-settings. Reports findings as critical, high, medium and low.
Audited -
teddy563 Bundle Proxy NetworkSets up and troubleshoots Minecraft proxy networks with Velocity (recommended), BungeeCord or Waterfall. Use whenever the user mentions a proxy, Velocity, BungeeCord, Waterfall, "the network", "lobby server", "hub", multiple servers, "connect servers", server switching, velocity.toml, forwarding.secret, modern forwarding, "player info forwarding", "offline mode behind proxy", broken skins or UUIDs behind a proxy, "Unable to connect you... invalid forwarding", forced hosts, or moving players between backend servers. Covers velocity.toml structure, modern vs legacy forwarding, the forwarding.secret handshake, backend online-mode, and the BungeeCord-vs-Velocity "won't start" conflict. Prefer this skill over guessing.
-
teddy563 Bundle Gamemode StacksRecommends and configures the canonical plugin stack for any Minecraft server gamemode/archetype. Use whenever the user mentions an SMP, survival server, skyblock, prison, factions, towny, minigames, a network or BedWars, RPG, MMO, MMORPG, anarchy, creative or build server, KitPvP, lifesteal, OneBlock, GenPvP, BoxPvP, SkyPvP, the Pit, OP prison/skyblock/factions, HCF, practice or duels, SkyWars, survival games, earth or geopolitical, or asks "what plugins do I need for a [gamemode] server", "how do I set up a [gamemode]", "what's a good stack for", "best plugins for my SMP/skyblock/prison/etc", or "I'm starting a [gamemode] server". Knows the core + supporting plugins, the config touchpoints, and the common pitfalls for each archetype, and defers exact config keys to the learn-plugin-docs skill. Pair with new-server-bootstrap for greenfield setups and audit-config to review the result.
-
teddy563 Bundle New Server BootstrapBootstraps a brand-new Minecraft server from scratch (Paper, optionally with a Velocity proxy). Use whenever the user says "set up a new server", "start a Minecraft server from scratch", "how do I make a server", "fresh install", "download Paper", "what Java do I need", "first time server setup", "create a network", "eula.txt", "startup script", "set up Velocity", or is greenfielding any server. Knows the current Paper Fill v3 download API, the Java 25 requirement, the EULA + first-run flow, a Java-25 + Aikar's-flags startup script, sane server.properties starter values, and Velocity modern-forwarding setup. Hand off the gamemode plugin stack to gamemode-stacks and the final review to audit-config.
Audited -
agent-rig Skill Rig TidyRun post-merge code cleanup: audit recent changes for dead code, duplicates, and stale comments, then safely remove them. Triggers on: 'cleanup', 'simplify', 'clean up code', 'remove dead code', 'post-merge cleanup'.
-
younesbenallal Bundle Geo Audit ReportAudit GEO and AI-search visibility. Use when the user wants to measure brand mentions, citations, search traces, maps, competitors, or fan-out queries in AI answers and receive a reusable report.
Audited -
younesbenallal Bundle Internal LinkingAudit and improve contextual internal linking across a website. Use when the user wants to map links, find orphan or underlinked pages, strengthen a confirmed commercial target or topical cluster, recommend source-to-target links, or apply explicitly approved edits.
-
zekainie Skill Exam Audit只读检查一个已生成的备考工作区是否健康并报告问题,默认不做任何修改。核对 .ingest 原材料版本、 内容单元、接管队列与派生产物完整性,以及 wiki、题库、视觉证据、计划和进度的一致性。当用户怀疑 工作区有问题、建库 readiness 被阻断、或想在开始复习前体检时使用。
Audited -
catwillgh Skill Mainframe Test AuditAudit an existing test system for meaningful regression coverage, reliability, and execution cost. Use when a test audit is requested or when observed flakiness, false confidence, hidden cost, or a material coverage gap makes test-system quality the actual problem. Do not use for routine implementation, writing or fixing tests, final product acceptance, or general code review.
Audited -
closetheloops Skill Moradin AuditLint memory — find stale files, missing frontmatter, bad topic tags, orphans. Propose fixes.
Audited -
closetheloops Skill Moradin CloseStage 6 of the Forge — the loose-ends stage. Evidence-derived security core, closed-loop audit, converge, and the four-question retro whose lessons flow back into Moradin memory. Core/Extended keys to release significance, never to operator profile.
-
jagoda11 Skill AuditDeep architecture audit for any feature or change. Runs failure mode analysis, boundary audit, test gap mapping, contract compliance, data flow tracing, and risk prioritization. Use for major features, critical refactors, or when things feel architecturally wrong.
-
jagoda11 Skill ReviewSmart router that detects branch changes and recommends which audit skill(s) to run. Use this when starting a review or when unsure which audit to run.
-
jagoda11 Skill Review AuthProduction-readiness audit for authentication. Use when auth code changes or when auth feels fragile, unclear, or unsafe. Covers OIDC, sessions, tokens, route protection, and secret management.
-
jagoda11 Bundle Review MonorepoMonorepo boundary audit. Use when shared packages change, new workspaces are added, or import patterns feel tangled. Checks workspace boundaries, dependency direction, domain ownership, and shared package bloat.
Audited -
leanos-technologies Skill Gap Running DestructionAdversarially attacks the current register state through pre-mortem, red-team response, constraint inversion, evidence concentration analysis, and kill signal audit. Use when a gap pass requires adversarial validation of hypotheses and proposals.
Audited -
lx050 Bundle Research Integrity AuditAudit the ResearchCase v1 publication gate for missing evidence, HYP or rejected support, unresolved conflicts, unadjudicated machine output, unaccountable adjudication records, broken hash bindings, sticky blockers, evidence-layer confusion, and vacuous completion attempts. Use before packaging or publishing claims, after claim-evidence links change, or when a workflow needs a machine-readable pass/warn/block decision.
Audited -
michaelleehobbs Bundle Deep Code ReviewRun an exhaustive, file-by-file review of a whole service, package or directory by splitting it across parallel reviewers that each read every assigned file in full, then merging into one severity-tagged report grouped per file. Use for "deep review", "extremely thorough review", "file-by-file review", "audit this service", "review everything under <path>", or any review too large for one pass, especially when the user says not to bias them about what to look for. NOT for a quick diff or pull-request review, and not for a single file.
-
michaelleehobbs Bundle Optimize CommentsAudit and tighten comments in a file, diff or package. Use for "clean up these comments", "the comments are out of date", "too many comments", or "this file is over-commented". Delete information readily recoverable from nearby code, preserve the shortest useful explanation of constraints and intent, and add missing reasons only when supported by evidence. NOT a general code review, and not for generated or vendored files.
-
nexpace-limited Bundle Determinism AuditAudits nondeterministic game behavior and flaky execution. Use when the same initial state and inputs produce different outcomes, a test fails intermittently or only under load, behavior differs by frame rate or machine, a replay diverges, or lockstep peers desynchronize. Establishes the required determinism boundary, reproduces and measures variance, isolates randomness, timing, async or thread ordering, state leakage, unordered iteration, and numeric drift, then reports verified causes and implements and stress-tests fixes only when requested.
-
necturalabs Bundle Docs ManagerCreate or maintain a project's docs/ folder with ADRs, design documents, guides, and reference material. Use to set up documentation, write an ADR or design doc, or audit documentation freshness.
-
necturalabs Bundle Iterative Security AuditMUST invoke when code changes touch authentication, authorization, cryptography, input validation, data handling, API endpoints, session management, secrets/config, dependencies, or comments that could carry secrets or internal infrastructure detail. Also use when the user asks for security review or audit. Requires superpowers plugin. Iterates until clean, then triggers code review.
-
sjdjdiejdrirhdkjej Skill Audit Claude Mdaudit-claude-md Skill
-
agulli Skill Code ReviewPerform a structured security and quality audit on source code. Use when asked to review code, audit a pull request, check for vulnerabilities, or assess code quality.
Audited -
agulli Skill Dependency AuditAudit project dependencies for vulnerabilities, license issues, and bloat. Use when asked to check dependencies, audit packages, find vulnerable libraries, or reduce bundle size.
Audited -
agulli Skill Security HardeningHarden an application or service against common attack vectors. Use when asked to improve security posture, secure an API, harden a server, or prepare for a security review.
Audited -
angad-kandhari Skill SecureSecurity discipline. Load when a change touches authentication, authorization, user input, secrets, data access, file handling, or a network boundary. Covers treating security as part of working, never routing around a security control, distrusting everything that crosses a boundary, keeping secrets out of the repo, defaulting to least privilege, vetting dependencies before adding them, and escalating security decisions instead of defaulting them.
-
arcblock Skill Intent PlanTransform approved Intent into executable phased plan with strict TDD. Each step requires tests first (happy/bad/edge/security cases), then implementation. Use after /intent-review when ready to start development.
-
bjg4 Bundle Code ReviewProvides comprehensive code review assistance for developers analyzing pull requests and code changes. Use when performing code reviews, examining diffs, or evaluating code quality before merge. Covers bugs, security vulnerabilities, performance concerns, and maintainability with structured feedback and severity levels.
-
dkadts Skill RefsParses references from references/ across all 9 design aspects. Finds conflicts (e.g. quiet-luxury mood vs bombastic motion). Produces a coherent proposal for DESIGN-LOCK.md AND an approved-manifest.md that /build and /audit enforce as required elements.
-
exiao Bundle Design ReviewRun a product design review on a feature or site. Answers 13 design questions, runs Nielsen Norman heuristic evaluation, builds before/after visual fixes, and deploys a shareable report to Surge. Use when asked to review a design, audit UX, do a design review, or analyze a product's user experience.
-
geoffsdesk Skill Post Migration OpsRun the day-2 work after every workload is on GKE — FinOps tuning (right-sizing, autoscaling, CUDs, Spot adoption), security hardening (Workload Identity audit, NetworkPolicy enforcement, Binary Authorization mode flip), observability completeness (golden-signal dashboards, SLO-tied alerts), and EKS decommissioning. Produces a final summary, FinOps report, hardening checklist, and decommission plan. Use as Phase 5 of a Portage migration, when "what do we do post-migration", or "tune GKE cost / harden the new environment".
-
ianalloway Skill Security ScannerScan code and dependencies for security vulnerabilities. Check npm audit, pip safety, and common security issues.
-
jord0-cmd Bundle RefraxINVOKE THIS SKILL when: reviewing AI-generated code, understanding unfamiliar codebases, visualizing code logic as flow diagrams, explaining code to non-technical stakeholders, identifying security risks in code, reviewing diffs visually, or when users need to understand code they didn't write. Generates interactive visual code comprehension pages.
-
lteawoo Bundle Code ReviewPerform a general code review. Use it to inspect PRs, commits, diffs, or local changes for functional bugs, regressions, security issues, performance degradation, missing tests, and maintainability risks. Apply it when the user asks for a code review, PR review, risk check, or merge-readiness assessment.
-
lteawoo Bundle Auth Security ReviewerReview security risks around login, sessions, tokens, authorization checks, admin boundaries, and secret exposure. Use it for changes involving auth or sensitive data handling.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include post-migration-ops, mainframe-test-audit, moradin-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.