Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
dynamods Bundle Dynamo Dotnet ExpertWrite and review C#/.NET code in Dynamo following Dynamo coding standards, modern C# patterns, and repo conventions. Use this skill whenever writing C# code, reviewing a PR diff, designing types, managing PublicAPI surface files, choosing patterns, making performance decisions, or refactoring in the Dynamo codebase. Also use when asking about NUnit testing, async patterns, error handling, immutability, or security in Dynamo.
-
emtcmca Skill Security ReviewReview a change for how it gets attacked, abused, or leaked, ranked by real-world impact rather than checklist severity. Use when code touches authentication, authorization, untrusted input, secrets, payments, file uploads, or personal data.
-
felipecabargas Skill Verify Acceptance CriteriaVerify acceptance criteria quality and identify gaps. Use this skill whenever you need to evaluate acceptance criteria (ACs) to ensure they meet quality standards. Trigger on: "review these ACs", "check if these acceptance criteria are good", "validate my user story criteria", "improve our acceptance criteria", "audit these requirements", "do these ACs pass review", or similar requests. Also use proactively when someone shares acceptance criteria that look hastily written or vague. The skill analyzes criteria against five key dimensions (clarity, testability, outcome-focus, measurability, independence), scores issues by severity (critical/major/minor), and generates a structured report. It can also rewrite poor criteria into better ones or convert them to user story format.
-
flaviocopes Skill Fstack SimplifyAudit for unnecessary complexity and propose deletions — from a single file to the whole codebase. Use when something feels bloated, over-engineered, or sloppy.
-
flutter Skill Audit DependenciesOptimize plugin size and security by removing unused dependencies and updating outdated libraries.
-
flutter Skill Audit UI Thread SafetyPrevent UI freezes and ensure a responsive user experience by validating threading rules and migrating blocking calls off the Event Dispatch Thread (EDT).
-
hunvreus Bundle AuditAudit a new or unfamiliar project to understand its structure, health, risks, documentation gaps, and next actions. Use when initially entering a repo, assessing project quality, preparing onboarding, or asking what should be improved first.
-
hunvreus Bundle ReviewReview code changes or a selected code scope for correctness, regressions, missing tests, security risks, dependency risks, product mismatch, and mismatch with the requested behavior. Use when the user asks for a code review, PR review, branch review, diff review, security review, or review since a commit.
-
hussainweb Bundle Drupal ReviewReview Drupal code against team standards for Drupal 11, PHP 8.4/8.5, and modern best practices. Use this skill whenever someone asks to review a Drupal module, check a PR, audit Drupal architecture, or validate that code follows standards.
-
i9wa4 Bundle Plan DesignUSE FOR: Implementation plans and durable task tracking: reduce ambiguity, compare options, parallel investigation, multi-source synthesis, review gates, planning evidence, handoff/resume, DONE/BLOCKED verification, and Secret-Gist handoff semantics. DO NOT USE FOR: artifact storage mechanics, machine-only outputs, internal logs, code/config artifacts, unrelated tasks, broad rewrites outside the request, or generated runtime outputs.
-
isanthoshgandhi Skill Founder CheckPsychological state audit for founders. Surfaces fear-based avoidance, decision clarity, conviction level, and co-founder alignment — then flags where psychology is driving business decisions. Not therapy. A diagnostic with an output. Invoke when the user says "founder check", "how am I doing", "am I being rational", "I'm avoiding something", "something feels off", or /founder-check.
-
isanthoshgandhi Skill Security AuditAudit code for security vulnerabilities. Use when the user says "security-audit", "security check", "is this secure", "audit for vulnerabilities", or before any public deployment. Covers OWASP Top 10 and common API/backend attack surfaces.
-
isanthoshgandhi Skill Frugal Token UsageActivate when the user wants to reduce token usage, manage context efficiently, or says "be frugal", "save tokens", "token usage", "frugal mode", "reduce context", "don't waste tokens", "context limit", or "token efficient". Reviews current behaviour and enforces minimal-token rules for the rest of the session. Always active via CLAUDE.md — this skill is a mid-session audit and reminder.
-
joacod Bundle Dx FirstAudit, improve, or guard developer experience (DX/DevEx) across any software repository or project type. Use this whenever a user asks about repository onboarding, development setup, local development, developer tooling, build/test feedback, task ergonomics, confusing commands, CI/local workflow friction, codebase discoverability, reproducible environments, development workflows, repository usability, or reviewing plans and changes that affect developer workflows, even when they do not use the term DX.
-
joacod Bundle Test HealthAudit a repository's automated testing health and recommend a bounded, high-value next improvement slice. Use when assessing an existing test suite, introducing tests into an untested or legacy project, deciding what to test next, evaluating testing strategy or coverage, choosing between unit, integration, and end-to-end tests, investigating brittle or flaky tests, or determining whether a small architecture change is needed for testability. Detect and prefer the repository's existing stack and conventions. Improve testing incrementally rather than pursuing arbitrary coverage targets.
Audited -
joacod Bundle Secure Node TypescriptWrite secure-by-default Node.js and TypeScript applications following security best practices. Use when: (1) Writing new Node.js/TypeScript code, (2) Creating API endpoints or middleware, (3) Handling user input or form data, (4) Implementing authentication or authorization, (5) Working with secrets or environment variables, (6) Setting up project configurations (tsconfig, eslint), (7) User mentions security concerns, (8) Reviewing code for vulnerabilities, (9) Working with file paths or child processes, (10) Setting up HTTP headers or CORS.
Audited -
johnkozaris Bundle Esp32 ExpertThis skill should be used for ESP32-specific hardware and runtime work in ESP-IDF, Arduino-ESP32, or PlatformIO projects: target/build detection, FreeRTOS tasks and ISRs, memory/DMA, peripherals, power, networking/security, OTA, crash diagnosis, and unattended reliability. Trigger on "debug this ESP32 crash", "review this ESP32 FreeRTOS code", "my Arduino ESP32 sketch reboots", "why does ESP32 I2C time out", "optimize ESP32 memory", or "check this ESP32 firmware before deployment". Not for generic C++, ESP8266, or non-ESP32 targets.
-
johnkozaris Bundle Validate APIRun the project's Hurl scenarios with an OIDC access token passed as a secret variable
-
jorgemuza Bundle AttestationVerify, download, and inspect build provenance attestations using the orbit CLI. Use this skill whenever the user asks about verifying attestations, checking provenance, inspecting Sigstore bundles, SLSA provenance, build provenance, verifying binaries, downloading attestation bundles, signer identity, in-toto attestations, or supply chain security. Trigger on phrases like 'verify attestation', 'check provenance', 'inspect bundle', 'build provenance', 'sigstore', 'SLSA', 'verify binary', 'attestation download', 'download bundle', 'check signer', 'inspect attestation', 'provenance verification', 'verify artifact', 'supply chain verification', 'check build origin', or any attestation-related task — even casual references like 'is this binary legit', 'who built this', 'where did this artifact come from', 'check the bundle', or 'show provenance'. The orbit CLI alias for attestation is `attest`.
-
makieali Bundle ReviewerValidates work completed by /executor agents. Reviews contract compliance, test quality, edge cases, security, performance, and integration correctness in a fresh context, refutes its own findings before reporting them, and gates the verdict on recorded exit codes. Runs after a phase or the full plan is implemented. Trigger: "review phase", "validate the work", "check what was implemented", "run review", "quality check".
-
makieali Bundle InvestigateDeep multi-perspective codebase investigation. Use when: analyzing feasibility of a new feature, auditing code for issues, investigating bugs, evaluating technical debt, or assessing any change before planning. Dispatches investigations across the dimensions that matter for the question asked, refutes every finding before reporting it, and synthesizes into one actionable report. Trigger: "investigate this", "is this feasible", "analyze my codebase", "audit this", "what would it take to", "assess this", "can we do this", "deep dive", "research this before we start".
-
mgoericke Skill ReviewPerforms systematic code reviews focusing on BCE architecture, Quarkus conventions, security, and test coverage. Use this skill for code quality checks and before merge requests.
-
minasaad1 Skill Power Bi SecurityConfigure row-level security (RLS) roles, object-level security, and perspectives for Power BI semantic models using pbi-cli. Invoke this skill whenever the user mentions "security", "RLS", "row-level security", "access control", "data restrictions", "who can see", "filter by user", "perspectives", "limit visibility", or wants to restrict data access by role.
-
mongodb Skill Quickstart ConfigExample configuration for connecting to a development cluster.
-
full-stack-skills Bundle Ascii Motd Profile BannerGenerate ASCII-only MOTD / SSH login banner / shell profile welcome messages (short/long variants, quiet mode guidance, security notices).
-
future-architect Skill Diet Assess RiskDeep-dive security risk analysis for a dependency flagged by uzomuzo diet
-
gnurio Bundle Audit Strategy ConsistencyAudit a competitive strategy for internal consistency using Porter's tests. Use when evaluating whether a strategy hangs together, after formulating strategy, or when diagnosing strategic drift.
-
gul-labs Bundle Craft FixThe Craftsman standard for driving fixes against an existing `craft-audit` workspace — "fix the findings", "fix SEC-003", "work through the audit", "start the climb". An ACTION skill, not a domain: it picks findings off the master tracker's climb sequence, re-verifies each is still real, gets the user's approval, and executes a batched fix with a regression test — it never re-audits or re-ranks. Fires with no finding ID named ("start the climb" means the top 5 open items) and on handoffs like "regression test for finding X" or "work on TEST-004". REQUIRES an existing `.craftsman/` workspace at the project root. Without one, a scoped fix request goes to the relevant domain craft skill and a whole-project assessment goes to `craft-audit` first.
-
gul-labs Bundle Craft SecurityThe Craftsman standard for defensive security hardening — authorization policy (per-resource authZ, IDOR/tenant scoping), input validation & injection prevention, secrets, security headers, CORS, dependency vulnerabilities, XSS/CSRF, and data exposure. Use WHENEVER work touches security: harden an endpoint, review auth, handle secrets, lock down headers, audit dependencies, or production-harden a service. Trigger on "is this secure", "harden this", "review for vulnerabilities", or "handle secrets properly". Owns authZ, abuse-defense policy, and security review of auth flows — see "Scope boundaries" in the body for handoffs.
-
hellotern Skill Review CodeYou MUST use this skill before evaluating, commenting on, or giving feedback on any code. Use when the primary request is to assess existing code — quality, correctness, style, or readiness to merge. Stronger signals: "review", "PR", "pull request", "code review", "check this code", "is this correct", "review this file", "give me feedback on", "look at this diff". Takes highest priority when the primary request is to evaluate code rather than write or fix it. Use sextant:security instead when the review focus is specifically on security vulnerabilities.
-
hmans Skill Technical WritingInvoke this skill whenever you need to create, update, review, restructure, or audit technical documentation such as README files, user manuals, API documentation, architecture notes, setup guides, troubleshooting guides, or developer docs. Use it to align docs with source code, existing project conventions, and the intended audience.
-
hoangsonww Bundle Devverse Supabase AuthSupabase auth, favorites, and security boundaries for DevVerse. Use when changing files under supabase/, auth or favorites UI, or the verify-email and reset-password API routes.
-
hoangsonww Bundle Estatewise ReviewReview EstateWise changes for correctness, regressions, security issues, contract mismatches, operational risk, and missing tests. Use for PR review, diff review, bug hunts, and branch-vs-main analysis. Do not use for implementation tasks unless the user asks for fixes after findings are reported.
-
huangruiteng Bundle Loopx MaterialOperate an explicitly activated LoopX Material Lifecycle for a connected project. Use for material-store inventory, lossless migration, candidate/archive transitions, exact-read-backed ranking, ranked-entry rebuilds, bounded Explore intake, owner-gated apply, rollback, and audit. Do not use for ordinary one-off reading or research when the project has not activated Material Lifecycle.
-
classmethod Bundle Ipa Security Guideipa-security-check をはじめとするセキュリティ診断ツールが出力したレポートを読み込み、各検出項目を優先順位付きの dev-debug 依頼リストに変換する。対象プロジェクトの言語・FWを問わず汎用的に使える。コードベースを直接読んでアーキテクチャ判断を行う。
-
justincordova Skill Code ReviewUse when reviewing code for quality, bugs, security, and correctness. Load before any code review, whether reviewing your own work or someone else's.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include security-review, secure-node-typescript, dynamo-dotnet-expert. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.