Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
netvar1337 Skill Solidity Lending Liquidation Bad DebtAudit money markets (Compound/Aave models) for collateral valuation desync, faulty health factor calculations, self-liquidation arbitrage loops, bad debt socialization failures, and liquidation frontrunning.
-
netvar1337 Skill Solidity Proxy Upgradeability StorageAudit UUPS, Transparent, and Beacon upgradeable smart contracts for uninitialized implementation contracts, storage slot layout collisions, clashing function selectors, constructor vs initializer pitfalls, and unauthorized selfdestruct calls.
-
netvar1337 Skill Solidity Precision Rounding AccountingAudit mathematical routines for precision truncation, division before multiplication, rounding direction bias (favoring attacker over protocol), decimal normalization discrepancies, and phantom token creation.
-
netvar1337 Skill Solidity Signature Replay MalleabilityAudit ECDSA signature verifications, EIP-712 typed data hashing, and permit operations for cross-chain/cross-contract replay, missing nonces, ecrecover address(0) return on invalid signatures, and s-value malleability.
-
netvar1337 Skill Solidity Governance Voting ManipulationAudit governance architectures (GovernorBravo, OpenZeppelin Governor, Compound governance) for flash-loan voting power borrowing, proposal griefing, quorum manipulation, cancellation race conditions, and timelock bypasses.
-
nicknisi Bundle Squad ReviewReview the current branch with six specialist lenses (security, correctness, conventions, tests, architecture, duplication), then put every finding through an adversarial verifier that tries to refute it — so what reaches you has already survived a skeptic. Use when the user asks for a thorough, deep, or paranoid review, a review before merging or shipping, a "real" review, or wants to know what a review would catch that a quick pass misses. Costs 12 agents; for a fast single-pass read, use the built-in code-review skill instead.
Audited -
patforna Skill Review CodeUse to review a diff for correctness, design, security, and convention conformance. High-signal, read-only, severity-gated, with an autofix lane for mechanically-certain trivia. Default review step in /at:auto-task.
-
pdugan20 Bundle Feature DeliveryTake a substantial production feature from an idea or selected behavior through specification, coordinated implementation, integration, and staged user availability. Use when delivery spans meaningful product or architecture decisions, multiple repositories or subsystems, important data or security boundaries, client and backend compatibility, or controlled rollout. Do not use for UI direction exploration, bounded feature spikes, hardening-only work, deployment of an already completed build, small fixes, or ordinary isolated changes.
-
rauleburro Bundle Feature Flow AuditorAnalyze a software feature or module end-to-end using parallel subagents, source-code introspection, Mermaid/UML diagrams, and an independent critical audit. Use when asked to understand how a feature works, map flows across models/views/controllers/APIs/jobs/integrations, explain architecture, identify functions involved, produce diagrams, or prioritize improvements for any codebase feature.
-
reopt-ai Bundle Reopt CLIBaseline guidance for the reopt CLI — authentication, login, global flags, security rules, and exit codes. Use before other reopt CLI skills or whenever a task involves `reopt login`, `reopt status`, brandapp credentials, or CI automation.
-
fivetran Skill Evaluate ConnectorEvaluate a Fivetran connector for correctness, SDK compliance, security, and reliability. Use when the user wants a code review or quality report before deploying.
-
jal-co Bundle UX SoundDecide whether an interface element should make a sound, which kind, how loud, and where the audio comes from (synthesis, recording, or ElevenLabs generation). Use when adding sound to a UI, choosing between synthesizing and sampling, levelling sounds against each other, syncing audio to animation, or auditing an existing sound layer. Triggers on: ui sound, ux sound, sonic ux, audio feedback, micro feedback, earcon, auditory icon, notification sound, alert sound, hover sound, click sound, sound effect, sfx, should this have sound, too loud, sounds cheap, sound doesn't fire, elevenlabs, sound generation.
Audited -
githubmofo Skill Torusguard VerifyVerify finding evidence sufficiency, audit live code line matches, and calibrate 0–100 confidence scores.
-
githubmofo Skill Torusguard Web ValidateExecute authorized HTTP probing against local/staging web applications — session capture, transparent audit headers, and secret redaction.
-
githubmofo Skill Torusguard Exploit CheckSafe, non-destructive confirmation of exploitability using inert canary tokens and sentinels.
Audited -
wkentaro Bundle Writing CodeWrite or audit code against the house coding conventions. Use while writing code to settle a style call, or when auditing a change against the conventions.
-
xgent-ai Bundle Portal App Exchange跨应用调用(OAuth Token Exchange)的布线与排错。凡任务涉及让 App A 读 App B 的数据(如 组卷读题库、文件调多模态解析、任务中心读 LMS)、声明 exchangeTargets/交换白名单/consent 共授,或出现 EXCHANGE_NOT_ALLOWED / EXCHANGE_CONSENT_REQUIRED / CONSENT_REQUIRED / SECRET_INVALID / GRANT_NOT_ALLOWED / 跨应用下拉列表莫名为空 等症状时,务必先用本 skill 再动手改代码。Use for wiring or debugging cross-app token exchange: grants, whitelists, consent co-grant, scope intersection, and the classic failure modes (secret drift, missing user consent rows, consent narrowing).
-
y3owk1n Skill ResearchAnswer a question from primary sources when getting it wrong would be expensive — APIs, versions, protocol details, security claims.
-
yaklang Skill Xss Testing跨站脚本(XSS)漏洞测试技能。覆盖反射型、存储型、DOM型 XSS 的识别与验证方法, 提供分层 Payload 集合、WAF 绕过策略、编码变换技巧和系统化测试流程, 适用于 Web 应用安全评估中的 XSS 漏洞发现与确认。
-
yaklang Skill Recon Planning渗透测试侦查与任务规划技能。定义渗透测试的完整工作流程:从信息收集(Recon)到 范围确定、任务规划和漏洞测试执行。覆盖端口扫描、子域名枚举、Web 搜索、 服务识别等侦查手段,提供 OWASP Top 10 检查矩阵和任务编排策略。
-
yaklang Skill Authorization BypassWeb 应用越权漏洞测试技能。覆盖水平越权(IDOR)、垂直越权(权限提升)、业务逻辑绕过 三大类测试场景。提供基于 HTTP 请求篡改的系统化测试方法论,包括参数替换、Cookie/Token 交换、角色 ID 篡改、隐藏字段操控、HTTP 方法变换、路径遍历、请求头伪造等具体技术。 每种技术都映射到可直接调用的工具(do_http_request, send_http_request_packet, use_browser), 确保 AI 可以自动化执行越权测试。参考 OWASP WSTG-ATHZ-02/03/04 和 OWASP Top 10 A01。
-
yaklang Skill Security Engineering面向通用安全工程任务的工作框架。用于安全知识问答、风险分析、安全方案设计、 配置检查、事件研判和跨领域安全任务,强调授权边界、证据质量、风险优先级与可执行结论; 当任务明确属于代码审计或渗透测试时,再切换到相应的专项技能。
-
yakoub-ai Skill Flutter SecurityAudit and harden security in Flutter apps. Use when the user wants a security review, secrets detection, token storage audit, permissions review, or OWASP Mobile Top 10 check. Trigger phrases: "security review Flutter", "check secrets Flutter", "Flutter security audit", "secure token storage", "app permissions Flutter", "harden Flutter app", "sensitive data Flutter", "OWASP Flutter", "API key Flutter", "secure storage Flutter", "certificate pinning Flutter", "obfuscate Flutter", "Flutter HTTPS".
-
yeshelloab Skill Red Team ModeRuns an adversarial stress-test on any analysis, thesis, plan, or conclusion: exposing weak assumptions, constructing counter-arguments, and determining whether conviction is genuinely earned. Use whenever the user says "red-team this", "challenge this", "tear this apart", "steelman the other side", "play devil's advocate", "what could go wrong", "stress-test this", "audit this analysis", "is this thesis defensible", or any variant of wanting adversarial scrutiny applied to a conclusion, plan, or recommendation. Works across domains: equity analysis, market research, business cases, strategic plans, financial models, and product decisions.
-
daniellublinsky Skill Skill AtlasGraph, categorize and visualize the installed Claude Code skill collection. Use when the user wants to map, audit or categorize their skills, move skills into the searchable tier, or asks which skills are broken, dangling, dead, disabled or duplicated — and for any mention of the skill atlas, skill graph or skill catalog.
Audited -
danielimad Skill Rls AuditAuthorized defensive security audit of a Supabase project you own — anon-key exposure, RLS gaps, service-role logging. Use for "what's exposed with the anon key", "rls audit", "security audit the backend".
-
danielimad Skill Rls EnforceHarden a Supabase/Postgres database by enforcing Row-Level Security — enable RLS, apply battle-tested policy patterns, and close every gap, as revert-safe migrations. Runs in parity after an RLS audit. Use for "enforce RLS", "harden the database", "lock down the tables", "apply RLS policies".
-
polakinio Bundle Project EngineerTurn a design, idea, sketch, brief, or product concept into the simplest feasible project plan spanning design, deployment, security, operations, finance, tool reuse, and verification.
-
polakinio Bundle Security EngineerPlan or review project security, tool reuse, dependencies, services, integrations, permissions, secrets, supply-chain risk, and security scan requirements.
-
polakinio Bundle Scope Safety GuardReview or plan changes that affect permissions, security boundaries, sensitive operations, external effects, or safety constraints.
Audited -
axisrobo Skill Arch SecurityDeep-dive security audit of a technical architecture diagram. Focused exclusively on authentication, authorization, credential protection, network boundaries, and data classification. Does NOT score overall quality — produces a prioritized security finding list. Use after arch-validate when you want a security specialist's deep cut.
-
starforall Bundle Workflow AuditUse when auditing whether the repo-local workflow rooted at `docs/workflows/新项目开发工作流/` has same-version maintenance issues in workflow assets, install/embed flows, CLI-native adaptation, or post-install verification boundaries, including a user-approved patch-only stable version mismatch in the current run; do not use for ordinary business code, application features, or generic implementation review, and use `workflow-capability-audit` instead for broader Trellis version-drift or upgrade-compatibility audits.
-
starforall Bundle Workflow Capability AuditUse when auditing whether `docs/workflows/新项目开发工作流/` remains compatible under newer-version drift or an explicitly requested same-version full audit.
-
agentic-engineering-agency Skill Convex Security CheckQuick Convex security pass for auth, validation, exposure, and access-control mistakes.
Audited -
blockmatic Bundle F SecurityApply Security First with a security lens who inspects this repo as a data analyst. Use when the user types /f-security or /f security.
-
rustfs Skill Plugin Contract GuardGuard changes to target-plugin manifests, extension schemas, admin catalog/instance contracts, secret redaction, and external-plugin install policy. Use when a diff changes those contracts in crates/targets, crates/extension-schema, or admin plugin/extension handlers; path membership alone, comments, and unrelated runtime internals do not trigger it.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include project-engineer, scope-safety-guard, torusguard-exploit-check. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.