Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
learnprompt Bundle Frontmatter RepairRepair synthetic MDX frontmatter when title, description, or sidebar.order drift from the frontmatter contract. Use for files that follow the same observable patterns proven in the receipts; do not use on private transcripts, secret-bearing material, or arbitrary YAML.
Audited -
rocketchat Skill I18N AuditAudit translation completeness across all language files
-
techdufus Bundle Omp Release Config AuditAudit recent OMP releases against project configuration, effective runtime behavior, optional features, extensions, and maintenance drift using source-backed evidence.
-
tencentblueking Bundle Tech Debt AuditThorough, user-invoked tech debt and architecture audit of the current codebase. Produces TECH_DEBT_AUDIT.md with file-cited findings, severity, effort estimates, and a required "looks bad but is actually fine" section. Use only when the user explicitly asks for a debt audit, codebase health check, architecture review, or whole-repo code quality assessment.
-
tencentblueking Bundle Bklite Ops Product DesignUse when proposing or reviewing BK-Lite operations-product modules, MVP scope, product specifications, competitor-derived designs, workflow/state models, extensibility decisions, permissions, audit, execution safety, or acceptance criteria.
-
tencentblueking Bundle Improve Codebase ArchitectureUse only when the user explicitly asks for an architecture-deepening audit, visual report, and follow-up grilling of a selected opportunity.
-
tile-ai Skill Audit FamilyCompare each op's code signature against its manifest spec, classify gaps, produce a structured report.
-
fancyboi999 Bundle Skill Safety Reviewer在不执行的前提下,依据显式沙箱策略审查 skill 请求的文件系统、命令、网络、secret 或破坏性操作。
Audited -
qualcomm Skill Wos Woa DashboardWindows on Arm Ecosystem Dashboard lookup — resolves each project dependency to a native-ARM64 / building / unsupported / unknown status per Arm AppReady, with citation links. Load during wos-analyzer Phase 2 (dependency audit) and when writing the Phase 8 Arm AppReady Status section. Also emits the ARM64-native vs emulated-x64 vs blocking three-way classification Arm's guidance recommends.
-
qualcomm Skill Wos Forbidden Skip ReasonsCanonical list of forbidden vs valid skip reasons for ARM64 SIMD porting, plus the PowerShell regex audit block used by wos-porter Phase 8 gate G7c and wos-optimizer Hard Constraints. Load when auditing an optimizer report, when the optimizer decides whether to skip a Tier-S file, or when writing the Limitations section of ARM64-PORT.md.
-
barissozen Skill Pitfalls SecuritySecurity Pitfalls
-
exceptionless Bundle Dependency UpgradesAudit and implement dependency upgrades safely. Use when updating, bumping, replacing, or removing NuGet, npm, container, or other third-party dependencies, including security-driven updates. Covers release-note review, compatibility and migration analysis, security advisories, full validation, and PR evidence.
-
exceptionless Bundle Serialization AuditUse this skill when verifying serialization behavior across branches, testing for backwards compatibility in JSON serialization changes, or comparing API request/response/storage formats between implementations. Apply when migrating serializers (e.g., Newtonsoft to System.Text.Json), adding new JSON converters, or changing naming policies.
Audited -
exceptionless Skill Backend ArchitectureUse this skill when working on the ASP.NET Core backend — adding controllers, services, repositories, validators, authorization, WebSocket endpoints, jobs, Foundatio infrastructure, configuration, or Aspire orchestration. Prefer this as the backend entrypoint for project layering, C# conventions, logging, ProblemDetails, security-sensitive config, and OpenAPI baseline updates.
-
arenukvern Bundle Your Skill NameReplace with what this skill does and when to use it. Include trigger phrases users say, e.g. "audit my API", "scaffold a skill"; activation-critical routing belongs here.
-
rldyourmnd Skill Security ReviewПроверь безопасность Antigravity CLI adapter: hooks, MCP, secrets, auth. EN: security review.
-
basecamp Bundle Truffle HuntUse when sweeping a whole dependency corpus or codebase for every instance of one known bug class — "audit our gems/modules/packages for X", "we fixed this here, where else does it occur?", "find every place this pattern appears". Truffle hunting. Covers defining the class and its discriminator, scoping the corpus, the cheap-sweep-then-discriminate pass, the proof protocol that makes a negative trustworthy, fanning out to agents, and routing what you find.
-
basecamp Bundle Harden Github ActionsUse when resolving zizmor warnings in GitHub Actions workflows, hardening CI pipelines, or pinning actions to SHA hashes. Covers artipacked, template-injection, excessive-permissions, secrets-outside-env, dependabot-execution, and when to suppress vs fix. Also covers scheduling vulnerability scanners (govulncheck, bundler-audit, npm audit, Trivy) and maintaining pinned toolchain versions.
-
blockscout Bundle Openapi SpecCreate, adjust, or inspect OpenAPI declarations for Blockscout API v2 endpoints. Use this skill whenever the user asks to: add an OpenAPI spec to an endpoint that lacks one, update a spec after controller/view changes, audit or fix an existing OpenAPI declaration, or work with open_api_spex annotations in the Blockscout codebase. Also trigger when the user mentions 'swagger', 'openapi', 'open_api_spex', 'API spec', 'API schema', or 'operation macro', or when debugging failures like 'response schema mismatch', 'CastAndValidate rejection', 'json_response validation error', 'Unexpected field', or extra/missing keys in API responses.
Audited -
bobmatnyc Skill Mutation TestingAudit whether a test suite actually detects regressions (not just whether it runs) by introducing small code mutations and measuring how many your tests catch. Advisory and on-demand — not a blocking CI gate.
Audited 71 -
jvalin17 Bundle AssessEvaluate existing architecture fitness. Identify gaps, suggest improvements only when scale justifies them. Safe refactoring if user wants changes. Keywords: assess, audit, evaluate architecture, tech debt, refactor, modernize, fitness, anti-patterns, scale
-
jvalin17 Bundle UpdaterAudit toolkit health, freshness, security, standards. Keywords: updater, audit, outdated, stale, security, OWASP, refresh, check links, standards, compliance
Audited -
jwilger Skill Security ReviewAudit code for security vulnerabilities, unsafe practices, and data exposure risks
Audited -
kambleakash0 Skill Code ReviewPerforms a thorough code review of the current changes or a specified file / pull request. Covers correctness, security, performance, readability, and adherence to project conventions. Outputs prioritised, actionable feedback. TRIGGER when the user writes /code-review or asks for a code review, PR review, or feedback on their code.
-
kambleakash0 Bundle Deep Codebase AuditFind deepening opportunities in a codebase, surfacing architectural friction and proposing refactors that turn shallow modules into deep ones. Use when the user wants to improve architecture, make a codebase more testable, consolidate tightly-coupled modules, or make it safer for AI agents to navigate and change.
-
leongibhub Skill TestingDesign and execute independent requirement-driven testing covering functional, boundary, negative, integration, E2E, regression, performance, reliability, compatibility, and security-oriented validation as applicable.
-
leongibhub Skill Code ReviewPerform independent risk-oriented code and architecture review, prioritizing correctness, security, regressions, edge cases, test gaps, and requirement/design conformance.
-
leoyeai Bundle Security For OpenclawApply practical application-security discipline to coding work in an OpenClaw workspace. Use when the request sounds like "is this secure", "review auth", "we are touching tokens or secrets", "this code handles user input", "this calls an external API", or any task that expands trust boundaries.
-
lkshrk Bundle Linear ReviewRun parallel reviewer subagents across a target repo or diff to surface findings across correctness, security, maintainability, performance, tests, dead code, and dependency health, dedup them against a persistent ledger and Linear, then triage survivors into Linear tickets. Use when the user wants a code review, repo health audit, or to turn review findings into tickets.
-
mturac Skill Security SentinelPerforms security audits, vulnerability assessments, SSL/TLS hardening, DNSSEC configuration, and compliance checks. Covers OWASP Top 10, CIS Benchmarks, email security (SPF/DKIM/DMARC), and network reconnaissance. Use this skill when the user asks for a security audit, vulnerability scan, penetration test, SSL hardening, DNSSEC setup, compliance check, or security posture assessment. Also triggers on "is my site secure," "check for vulnerabilities," "harden my server," "audit my domain," "set up DNSSEC," or any request involving security assessment — even vague ones like "I'm worried about my site's security."
-
nangongwentian-fe Bundle Post Implementation Review GateUse after completing a non-trivial implementation and before final handoff, especially for public API/schema compatibility, database or migration work, authentication/security, deployment/configuration, concurrency or data integrity, algorithmic or control-flow complexity, cross-module refactors, runtime lifecycle, and rendered UI behavior. Make sure to invoke this skill even when the user asks only to implement or fix something and does not explicitly request review. Risk-classify the completed change, use a new isolated read-only subagent for review-triggering changes when delegation is allowed, otherwise perform and disclose a local fallback, verify findings, fix authorized in-scope defects, rerun relevant checks, and report residual risks. Do not use for planning, answer-only or diagnosis-only tasks, trivial text edits, mechanical formatting, or tasks with no implementation-artifact change.
Audited -
nealcaren Skill Review StataRead-only code review for Stata .do files. Checks reproducibility, correctness, Stata's notorious numerical/missing-value traps, idioms, and whether reported numbers match what the code produces — then writes a report WITHOUT editing your files. Use when the user says "review this do-file", "check my Stata code", "audit the analysis", or after stata-analyst writes a script.
-
netvar1337 Skill Immunefi Vulnerability PatternsAudit Web3 smart contracts against top Immunefi bug bounty disclosure patterns, post-mortems, and critical severity vulnerability categories across DeFi, lending, bridges, and yield protocols.
-
netvar1337 Skill Solidity Mev Slippage FrontrunningAudit decentralized exchange integrations and automated trading logic for missing slippage parameters (amountOutMin = 0), deadline = block.timestamp antipatterns, public mempool sandwich susceptibility, and router validation bugs.
-
netvar1337 Skill Solidity Yield Staking Reward DrainAudit staking pools, MasterChef forks, Synthetics StakingRewards implementations, and reward distributors for reward debt miscalculations, reward frontrunning, flash-deposit harvesting, and reward rate dilution.
-
netvar1337 Skill Solidity Crosschain Bridge MessagingAudit cross-chain interoperability protocols and L1/L2 messaging bridges (LayerZero, Axelar, Wormhole, Chainlink CCIP, Arbitrum/Optimism messaging) for message replay, gas exhaustion DoS, untrusted adapter callbacks, and bridge fee underpayment.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include mutation-testing, frontmatter-repair, i18n-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.