Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
rustfs Bundle Security Advisory LessonsPerform a dedicated RustFS security/advisory review for authn/authz, IAM, RPC trust, paths, secrets, browser isolation, encryption, Object Lock, or other security boundaries. Use only when the user requests a security/advisory review or an adversarial review explicitly escalates to the full advisory map; do not auto-load solely because code touches a sensitive path.
-
saleh-alhaddad Skill InspectSenior code review across correctness, complexity, architecture, security, performance, and cross-service impact. Read-only — it reports and routes fixes to construct.
-
sendx Bundle Email DeliverabilityDiagnose, audit, and fix email deliverability problems using a proven, systematic methodology. Use this skill whenever someone asks for a deliverability audit, says "audit my email", "check my deliverability", "why are we hitting spam", or "why are my emails going to spam" — or mentions inbox placement problems, emails going to spam, low open rates, IP/domain reputation damage, blocklisting, warming up IPs or domains, shared pool contamination, bounce rate spikes, mailbox provider blocks, sender reputation, or email authentication failures. Also trigger when someone is setting up email sending for the first time and wants to get it right, wants a review of their email setup, or asks about ESP infrastructure health, sender compliance, list hygiene, traffic shaping, or reputation recovery planning. Even if they just say "our emails aren't working" or "open rates dropped" — this is the skill to use.
-
serial-studio Skill Ss AI AuditAudit Serial Studio's AI-facing material (CLAUDE.md, doc/claude/**, .claude/skills/**, and optionally the in-app assistant corpus under app/rcc/) against code ground truth. Use when asked to "audit the skills/docs", "check the docs for drift", "verify CLAUDE.md is still true", or after a refactor that moved/renamed things (TU splits, workflow consolidation, symbol renames). Finds stale claims and fixes them with targeted edits; docs-only, never touches code.
-
singh-gur Skill Setup CIGathers CI requirements through a four-area intake and scaffolds Concourse or Forgejo CI pipelines for the current repository, wiring build, test, and security gates to real project commands. Use when asked to set up, scaffold, or improve CI for a repo, or to choose between Concourse and Forgejo CI.
-
jaan-mustafa Skill 10x TeamYou MUST use this when building projects end-to-end. Orchestrates all 12 team roles — automatically switches between CTO, architect, PM, engineers, SRE, security, DBA, QA, and EM based on the current phase of work. Starts with brainstorming before any implementation.
-
jaan-mustafa Skill Security EngineerYou MUST use this for security decisions - threat modeling, vulnerability assessment, auth/authz design, security review, compliance requirements, and hardening recommendations.
-
kelvinyou Skill Identity AuditQuarterly identity audit: infer "the top 3 things that mattered most last quarter" from behavioral data, and compare against the claims in data/user_profile.md. Trigger when the user says "quarterly audit", "identity audit", "what did my quarter actually look like", "quarterly review", or "behavior vs. claims". Requires ≥ 12 weeks of log data.
-
davideast Skill Firebase AuditAudit a Firebase project's security and data posture — who can access what, what rules/data/auth exist, and where they disagree. Use when the user asks for a Firebase audit, a security review of rules and data, or "find the gaps" across Firestore/RTDB/Auth.
-
olafgeibig Skill Lightrag Deep ResearchDeep research workflow over an internal LightRAG knowledge base (no web search). Use when you need an in-depth investigation with a structured plan, iterative sub-questions, evidence gathering via LightRAG queries (local/global/hybrid/mix/naive), synthesis, and KB-citations. Best for: architecture/security research, incident retrospectives, design decisions, policy interpretation, and any question that should be answered primarily from your organization’s knowledge base.
-
onlyterp Skill Weekly Dep AuditAudit dependencies across configured repos for security advisories, open triage issues
-
onlyterp Skill Rotate SecretsRotate webhook HMACs, API keys, OAuth tokens, and update gateway configs atomically
-
onlyterp Skill Audit Approval BypassAudit every path that bypasses dangerous-command approval — YOLO, approvals off, command_allowlist entries, cron approve mode, container backends
-
thechandanbhagat Skill Code ReviewPerform automated code reviews with best practices, security checks, and refactoring suggestions. Use when reviewing code, checking for vulnerabilities, or analyzing code quality.
-
xiaolai Bundle AuditAsk Claude Code to audit a file or set of files and return structured findings. Claude reads the code with fresh eyes and independent judgment — Codex does not self-review. Supports mini (5-dimension) and full (9-dimension) depth.
-
xiaolai Bundle VerifyAsk Claude Code to verify that a list of reported issues has been fixed. Continues the same Claude session from a prior audit if session_id is available, so Claude has full context of what it flagged. Returns FIXED / NOT FIXED / PARTIAL / REGRESSED per issue.
-
xiaolai Bundle Audit FixFull audit→fix→verify cycle: Claude audits, Codex fixes, Claude verifies. Repeats up to 3 rounds until all issues are resolved or the user stops. Claude does all code reading and judgment; Codex does all file editing.
-
xiaolai Skill Claude Code ConventionsCanonical reference for Claude Code plugin artifact schemas, hook events, frontmatter fields, and naming conventions. Used to inject domain knowledge into Codex audit prompts. Run /cc-suite:refresh-knowledge to update from latest docs.
-
howells Skill AuditComprehensive codebase audit with verification and specialized reviewers. Generates actionable reports. Use when asked to "audit the codebase", "review code quality", "check for issues", "security review", or "performance audit". By default, run the complete audit: mechanical checks first, then specialist reviewers, then a scored report.
Audited -
wenyuchiou Bundle Paper Memory BuilderConvert a paper draft + figures + Zotero metadata into reusable .paper/claims.yml and .paper/figures.yml files so the academic-writing-skills skill can do writing, revision, and audit passes without re-reading the manuscript every time. Use when the user asks to "build paper memory", "extract claims from this manuscript", "extract claims, supporting evidence, and figure key numbers", or "prepare this paper for AI-assisted writing". NOT for summarizing cited papers in a literature cluster — that's `paper-summarize`. This skill is for the user's own manuscript draft only.
-
wenyuchiou Bundle Zotero Library CuratorAudit and curate a Zotero library — find duplicate DOIs, orphan items missing required tags, propose collection rebinds, identify bloated or under-used collections, generate tag hygiene reports, emit preview-only cleanup plans. Use when the user asks to "audit Zotero", "find duplicates", "tag hygiene report", "which collections are bloated or under-used", or "propose a Zotero cleanup plan". Defers all CRUD operations to the standalone `zotero-skills` skill or `research-hub zotero` CLI. Includes a backup-first reminder before any apply/CRUD handoff suggestion.
-
just-silver Skill Security And HardeningUse when handling user input, secrets, tokens, or file paths, when building auth or external integrations, when auditing dependencies for vulnerabilities, or when reviewing a change for injection, traversal, or secret leaks.
-
just-silver Skill Doubt Driven DevelopmentUse when stakes are high (production, security, irreversible), when working in unfamiliar code, when correctness matters more than speed, or when a confident output is cheaper to verify now than debug later.
-
evolvingagentslabs Skill AdminAct for an org admin — the admin API (scope directory, per-scope config & SOUL, any scope's memory, transcripts & captured prompts, files, user roster, audit/errors/metrics/egress) accepts your token when the user you're talking to is an org admin and started this turn themselves. Use when an admin asks you to inspect or change anything org-wide or in another scope, or anyone asks whether they're an admin.
Audited -
ferueda Bundle Code Quality ReviewReview substantial structural or abstraction changes read-only for consequential maintainability risks. Not routine polish, a second correctness pass, or surrounding-code cleanup.
-
firatcand Skill Chief Of StaffWorkspace maintenance for Roster workspaces. Uses deterministic roster scaffold/validate commands in v2 and quarantined legacy scripts only in v1. Triggers when the user asks to scaffold or audit a roster workspace, or invokes the /chief-of-staff slash command.
-
skillmedev Skill Fundraise Readiness AuditRuns the audit an investor will run before a founder starts pitching - scoring metrics, story, team, and legal/financial hygiene red/yellow/green and returning a go, fix-first, or wait verdict with the milestones that turn each red gate green. Use when a founder asks "audit my fundraise readiness before I pitch", "run the audit an investor would run on my startup", "score my metrics, story, and team before I raise", "am I ready to start fundraising", or wants a fundraise checklist before any outreach at any stage. Do NOT use for Series A-specific metric benchmarks (ARR bar, NRR, payback) and building the Series A data room - use series-a-readiness. Do NOT use for choosing the stage, amount, and instrument of the raise - use fundraising-stage-selector. Do NOT use for writing the pitch story itself - use fundraising-narrative.
-
pipixia-labs Bundle Self ObserveObserve OpenTeamwork Node health with usage, automation status, audit facts, logs, and quick diagnostics.
Audited -
creceradigital Bundle Hc RankLook up a domain's Harmonic Centrality (HC Rank / CC Rank) from Common Crawl's Web Graph — single or bulk — and use it to prioritize link building toward the web's link core. Reads Common Crawl's published domain-ranks file directly, so it does not depend on the (currently erroring) webgraph.metehan.ai tool. Triggers on "harmonic centrality", "HC rank", "CC rank", "crawl priority", "web core", "distance to core", "metehan webgraph", "AI visibility audit centrality check", or wanting to score/prioritize domains by proximity to the web core for link building.
Audited -
danielonpurpose Skill Local Business AuditLocal-business prospecting fan-out — audit a city's small businesses (Google Business Profile score, website check) and produce a verified call list / audit sheet with checkpointing so session limits never lose work. Use when the user says "audit <city>", "build a call list for <city>", "find businesses without websites", "GBP audit", or "prospect list".
-
humblytics Skill Heatmap AnalystClick-engagement analyst that pulls element-level click data, a page-level scroll proxy, and bounce/exit signals from Humblytics to surface UX friction and ignored CTAs. Generates prioritized, data-backed optimization recommendations. NOTE: Humblytics does NOT provide pixel-level click heatmaps, scroll-depth distributions, or rage-click detection — those need a dedicated heatmap tool. Use when auditing element-level click patterns, finding ignored CTAs, gauging scroll engagement, or diagnosing on-page friction. Triggers: click analysis, element clicks, ignored CTA, click engagement, scroll engagement, UX friction, interaction audit.
-
astro-han Skill Wrap UpClose a session cleanly by resolving session-owned loose ends and reporting the final state. Use when the session is ending or the user asks to wrap up or audit its end.
Audited -
astro-han Skill Simplify AuditAudit an existing repository or scoped architecture area for simplification opportunities, separating proven removals from those still blocked on a fact or a decision. Use when asked to find what can be removed or consolidated, reduce codebase-wide maintenance complexity, or identify obsolete or duplicated authorities, states, paths, contracts, or representations. Do not use to implement an already chosen change, fix a bug, optimize performance, or perform general code review without a simplification goal.
Audited -
b-open-io Bundle Legal ComplianceThis skill should be used when the user asks to draft a privacy policy, terms of service, cookie policy, or data processing agreement; when they ask about GDPR, CCPA, HIPAA, or other privacy regulations; when they need a compliance audit, legal gap analysis, or regulatory guidance; when they ask about employment law, IP rights, open source licensing, or contract review; when they mention 'legal', 'compliance', 'regulation', 'liability', 'terms', 'privacy', or 'lawsuit'. This skill also applies to crypto and digital asset questions: token classification (Howey test), security token offerings, stablecoins, GENIUS Act, DeFi compliance, CFTC jurisdiction, DAO liability, IRS crypto tax, AML/FinCEN MSB registration, tokenization of real-world assets, UCC Article 8, and smart contract legal review.
-
b-open-io Bundle Saas Launch AuditThis skill should be used when the user asks to "audit my SaaS", "check if I'm ready to launch", "review my launch checklist", "verify my pricing", "audit my payment setup", "check my AI visibility", "prepare for Product Hunt", "validate my SaaS for launch", or mentions launching a SaaS product. Provides a comprehensive, repeatable checklist with PASS/FAIL verification and actionable next steps.
Audited -
b-open-io Bundle Soc2 Gap AnalysisThis skill should be used when the user asks to "prepare for SOC 2", "run a SOC 2 gap analysis", "check our audit readiness", "map our controls", "what controls are missing", "review us for SOC 2 Type I", "review us for SOC 2 Type II", or mentions SOC 2, trust service criteria, control gaps, auditor prep, trust center readiness, or remediation planning.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include code-review, security-advisory-lessons, inspect. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.