Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
b-open-io Bundle Soc2 Policy DraftingThis skill should be used when the user asks to "draft a SOC 2 policy", "write an access control policy", "write an incident response policy", "create security policies for audit", "prepare policy documents for SOC 2", "draft our control narratives", or mentions policy drafting, approval cadence, review frequency, governance language, or auditor-facing policy documentation for SOC 2.
-
b-open-io Bundle Soc2 Evidence CollectionThis skill should be used when the user asks to "collect SOC 2 evidence", "build an evidence register", "prepare evidence for the auditor", "what artifacts do we need", "organize our control evidence", "respond to an auditor request list", or mentions evidence gathering, control artifacts, audit requests, screenshots, exports, or testing records for SOC 2.
-
bambooxlotus Skill Rick RecapEnd-of-day audit across today's /rick-save files — diffs the structured sections within each feature folder to grade real progress vs rabbit holes, yak shaving, and avoidance. Use when the user wants an honest accounting of the day's work.
-
blueclover22 Skill Doc AuditUse after a slice/phase completes, at a phase transition, or before handing off unfinished work. Not for single-design implementation review (mak:review-report), verification (mak:verify-checklist), code-vs-doc behavior analysis (mak:analyzer), or choosing the next task (mak:dev-resume).
Audited -
blueclover22 Skill Dev ResumeUse only on explicit request to resume or take over work when the next task is undecided. Use mak:dev-kickoff for a decided task, mak:reverse-engineering when project docs are absent, and mak:doc-audit for document-consistency audits.
Audited -
brightops-ai Bundle 1passwordThis skill should be used when the user asks to read, inject, or manage secrets using the 1Password CLI (op). Covers authenticating with op, reading secrets from 1Password vaults, injecting credentials into config files, storing new secrets, troubleshooting op CLI issues, secret rotation, or credential management — even if the user does not explicitly say "1password".
-
brightops-ai Bundle Improve MemoryAudit and consolidate this project's auto memory, proposing what needs a decision.
-
buzzer-re Skill Vulnerability AuditSecurity audit — buffer overflows, format strings, integer issues, memory safety
Audited -
buzzer-re Skill Driver AnalysisWindows kernel driver analysis — DriverEntry, dispatch table, IOCTL handlers, vulnerability audit
-
bwkw Skill Da Skills AuditAudit the whole set of installed skills for bloat and breakage. Use before adding a skill, when skills stop firing automatically, or for periodic clean-up. Not a security scan.
Audited -
canonical Bundle Sl AuditorAudits an existing Squeeze Loop (SL) for soundness — checking whether a target loop is truly compliant (pairwise-disjoint authority pairs, physically barriered contexts, gate-defined "done", a genuine executable lower bound, and demonstrated catching of coherent-and-wrong) or is quietly collapsing into a rubber stamp. It applies the squeeze's own discipline to the loop under audit: it maps the actual (upper, lower) authority pairs and hunts for an actor certifying its own work; probes whether each context barrier is physical or merely honorary; confirms an executable oracle disjoint from the actor it judges; checks Gate A / Gate B / Gate C are present and load-bearing; seeds coherent-and-wrong artifacts to calibrate the monitors (flag rate not zero, not saturated); audits the loop's accumulated learned skills VIA the sl-monitoring-sl pattern; checks each known collapse mode is blocked by a stabilizer; and routes whatever an internal audit cannot self-certify to a disjoint base (external / cross-provider / hum
-
serendipityoneinc Bundle Amazon Listing Audit ProComprehensive listing health check and optimization engine for Amazon sellers. Scores listings across 8 dimensions, benchmarks against category leaders, identifies keyword gaps, and generates data-backed improvement recommendations. Supports single ASIN or bulk audit (10-100+ ASINs for agencies). Uses all 11 ZooData API endpoints with cross-validation. Use when user asks about: listing audit, listing optimization, listing score, listing quality, improve my listing, listing review, listing diagnosis, title optimization, bullet point optimization, keyword gaps, listing benchmark, A+ content, listing health check, listing comparison. Requires ZOODATA_API_KEY.
Audited -
songhonglei Bundle Glic CheckSystematic quality check for code, skills, configs, and documents. Two modes — GLIC for internal quality (4 dimensions: Grammar / Logic / Integrity / Containment) and UGLIC adding User Experience (5 dimensions: U + G + L + I + C). Each finding cites file:line; severity is tagged as ERR / WARN / INFO with explicit escalation rules (silent-failure = ERR, 3× repeated WARN → ERR, missing public-param doc = ERR). Use when the user says "GLIC check", "UGLIC check", "do a glic", "systematically review this", "audit my skill", "quality check this code", or any phrasing that asks for a multi-dimension review of code / skills / configs / docs.
Audited -
themis-legal-framework Skill Pleading Qc And Risk AuditAudit a pleading like opposing counsel will—find the weaknesses before they do.
-
aby-studio-works Bundle Garelier SmithGarelier-only: fire in a `__garelier/<pm_id>/` project or on explicit Garelier/smith invocation, not on generic hardening/integration-test/anvil wording. Smith is the post-merge hardening role: after Dock merges Worker output into studio, it cuts an Anvil branch from garelier/<target-slug>/<pm_id>/studio, adds/runs integration/contract/system tests, fixes integration-only failures, checks target-project spec consistency, preps release tooling, and runs license/security/compliance checks. Activate in a `__garelier/<pm_id>/_crew/smiths/<id>/` worktree, when assignment.md appears for a Smith, review.md signals Anvil rework, or merged.md arrives after Dock merges the Anvil branch. Requires garelier-core.
-
addyosmani Skill Factory MonitorInspect factory health, stale work, CI, security advisories, and recent run evidence without implementing fixes.
Audited 69.5k -
adrojis Bundle Tracecat Case ManagementActivate when users manage security cases, track incidents, or configure case lifecycle workflows in Tracecat
-
45ck Skill Threat Surface Mapperthreat-surface-mapper
-
45ck Skill Session Security Reviewersession-security-reviewer
-
45ck Skill Security Requirements Writersecurity-requirements-writer
-
45ck Skill Security Misconfiguration Checkersecurity-misconfiguration-checker
-
ai-riksarkivet Bundle Typescript SecurityValidate input, secure auth tokens, and prevent injection attacks in TypeScript. Use when validating input, handling auth tokens, sanitizing data, or managing secrets and sensitive configuration.
-
zircote-plugins Bundle ReleaseThis skill should be used when the user asks to "release a project", "create a release", "bump version", "publish to GitHub", "prepare a release", "run release validation", or needs to perform SDLC-compliant releases for Claude Code plugins, Python, Node.js, Go, or Rust projects. Provides comprehensive pre-release validation including tests, lint, coverage, and security checks.
Audited -
neuroaihub Bundle Audit EvidenceAudit numeric, artifact, log, citation, and cross-report claims against inspectable evidence. Use for reports, syntheses, benchmark claims, external citations, or conflicting Expert outputs.
-
nicanac Bundle Skill Code ReviewPerform thorough, constructive code reviews focusing on correctness, security, maintainability, and best practices
-
guillevc Skill AuditAudit code against the living spec (ADRs and the glossary) and let the human resolve each contradiction. Use proactively whenever you write or change code that touches a documented decision, rule, or term, and after a build or before a commit/PR, even if the user doesn't ask. Also on "check for drift", "do the docs still match", "audit code vs spec", /audit, or when develop freezes. Reports; never auto-fixes. It stops and the human picks.
-
guillevc Skill RecordWrite a resolved fact into the living spec (a glossary term or an ADR) and keep it coherent. Use proactively the moment a durable fact settles, even if the user never says "record" or "ADR": a decision made, a library/tool/protocol/schema chosen, a rule or constraint set, a term's meaning pinned, or a past decision reversed. Also on "record this", "write an ADR", "add to the glossary", "supersede that decision", /record, or when develop or audit needs to write the spec. Drafts for human ratification; durable writes are gated.
-
microboxlabs Skill Dependabot ReviewReview Dependabot security alerts, plan resolution, and propose fixes. Use when the user asks to check security vulnerabilities, review a Dependabot alert, fix a CVE, audit dependencies, or provides a Dependabot alert URL. Also use when the user says "check security", "fix vulnerability", "dependabot", "CVE", or "security alert".
-
wso2 Bundle Security ReviewReview code for security vulnerabilities using OWASP guidelines
-
thanasimos Bundle Flare Builders ToolkitMaster skill for building, testing, auditing, and deploying smart contracts on the Flare-family EVM chains (Flare, Songbird, Coston2). Use this skill as the entry point for any Flare-related development task. It bundles 16 specialized sub-skills covering: chain registry and addresses (Permit2, Multicall3, DEXes, routers, tokens), Flare protocols (FTSO, FDC, FAssets, Smart Accounts), Enosys contracts and rewards, security-first Solidity standards, Flare-specific audit checklists (Permit2 chain availability, fee-on-transfer detection, blacklistable token surface, basefee floors, FTSO redistributor proxy upgradeability), the cross-project lessons-learned from real Flare builds, and the audit/gas/test workflow (`audit`, `audit-contract`, `gas-optimize`, `test-foundry`, `test-hardhat`). Trigger on: any Flare/Songbird/Coston2 development question, "how do I X on Flare", security review request, audit kickoff, contract verification on flare-explorer or flarescan, address lookup, RPC selection, FTSO reward claim, FAs
-
thanasimos Skill AuditPerform a systematic security audit of a Solidity contract using industry-standard checklists, vulnerability classifications (SWC), and known edge cases including weird ERC20 behaviors.
-
devenkhatri Skill UI UX AuditorPerform a thorough, structured UI/UX audit of an application. Use when given a video recording, YouTube URL, live web URL, or a zip/set of screenshots of an application and asked to audit, review, or evaluate its design, usability, or launch-readiness.
-
davideast Skill Rtdb Security RulesAuthor or audit Realtime Database security rules — cascading read/write access, .validate shape checks, auth expressions, data vs newData semantics. Use when the user works on database.rules.json, asks why an RTDB read/write is allowed or denied, or needs RTDB paths locked down.
-
davideast Skill Firestore Rules AuditAudit Firestore security rules for public access, semantic errors, unsafe match-block composition, and missing validation. Use when the user asks to review firestore.rules, check rules for vulnerabilities, or explain why a rule allows/denies an operation.
-
editor-code-assistant Skill WeedWeed the Allium garden. Find where Allium specifications and implementation code have diverged, and help resolve the divergences. Use when the user wants to check spec-code alignment, compare specs against implementation, audit for spec drift or violations, sync specs with code or code with specs, or verify whether the implementation matches what the spec says.
-
editor-code-assistant Skill Context ModeUse context-mode tools (context-mode__ctx_execute, context-mode__ctx_execute_file) instead of eca__shell_command/eca__read_file when processing large outputs. Triggers: "analyze logs", "summarize output", "process data", "parse JSON", "filter results", "extract errors", "check build output", "analyze dependencies", "process API response", "large file analysis", "run tests", "test output", "coverage report", "git log", "recent commits", "diff between branches", "fetch docs", "API reference", "index documentation", "call API", "check response", "query results", "find TODOs", "count lines", "codebase statistics", "security audit", "outdated packages", "dependency tree". Also triggers on ANY tool output that may exceed 20 lines.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include factory-monitor, improve-memory, record. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.