Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
hashgraph-online Skill MaliciousFixture that tries to exfiltrate SSH keys and environment secrets.
-
hazat Bundle Pi Extension DevelopmentDefines the local standard for standalone Pi extension repositories. Use when manually invoked to create, audit, test, publish, or release an extension with Git-backed installation, local loading, and Vite+ linting and formatting.
-
jasonm4130 Skill Docs ConsolidateAudit a repo's documentation for internal contradictions, stale claims, orphans and bloat after it has accumulated commits, then report findings for the user to disposition. Use when the consolidation nudge fires, or when the user asks to consolidate, audit, or spring-clean the docs. Triggers: "/docs-consolidate", "consolidate the docs", "docs audit", "have the docs drifted", "check the docs against each other". Do NOT use for updating one doc alongside a code change — that is the commit gate's job, and a single doc edit needs no audit.
-
kyleamathews Bundle Evaluate ReviewEvaluate an external pull-request review for technical accuracy, analytical depth, signal-to-noise ratio, and reviewer quality while preserving every finding in a lossless ledger and final audit. Use when the user supplies review findings and wants them checked against the code, red/green verified, reconciled after fixes, or audited for omitted items.
-
lpalbou Bundle CoredocCreate, audit, normalize, and maintain a professional external-facing repository documentation system for users, contributors, and tools, including the core doc set, cross-linked topic deep dives, and faithful AI-readable `llms.txt` and `llms-full.txt` files. Use when Codex needs to bootstrap docs for a new repo, repair stale or missing project docs, add or revise `docs/*.md` pages, keep root and `docs/` documents coherent, or regenerate AI-actionable documentation indexes for LLMs and tooling.
-
muhammad-anas35 Bundle Send EmailSend emails via Gmail API with approval workflow and audit logging. Smart approval logic determines if emails need human review based on recipient, content, and attachments. Use when you need to send emails programmatically, automate email responses, or integrate email sending into workflows. Supports attachments and templates.
-
muhammad-anas35 Bundle Business AuditGenerate automated weekly business audit reports with metrics, insights, and recommendations
Audited -
iabstergo1 Skill Kb QARun QA / audit / coverage checks on the published knowledge base or pre-save candidates, producing a report and Review-Queue proposals. Use when the user says "run a KB QA / audit coverage / spot-check evidence / run the Q-chain / check for concept pollution". Semantic-health words (L4, contradiction, Q2 added value) belong to wiki-lint-semantic and must not be hijacked here.
-
heathwang Skill Code Review With FilesUse when reviewing source files, diffs, commits, pull requests, or bugfixes for correctness issues, regressions, security problems, performance risks, edge cases, or missing tests across any language or framework.
-
shakacode Skill Assess Abtest QualityAudit existing .abtest.ts files plus the latest `shaka-perf audit` results for anti-patterns, false-positive PASSes (blank/high-whitespace screenshots), and coverage gaps. Use whenever the user wants to review, audit, improve, or "assess quality" of AB tests — phrasings like "are my visreg tests any good?", "check the ab tests", "why is this test passing?", or "make these tests more reliable".
-
jeninh Bundle Resolving SecretsWraps shell commands to resolve secret references in environment variables to their actual values. Always use when invoking synu, crush, gh, hut, etc. Ask whether to use if an invocation fails due to missing credentials.
-
canxiangcc Bundle Aminer PDF Citation Verifier[Activation] Use this skill when the user provides a paper PDF (file path or upload) and asks to verify, audit, or fact-check its references / citations / bibliography — e.g. "check whether the references in this PDF are hallucinated", "find fake citations", "verify the bibliography". [Capability] Uploads the PDF to the AMiner pdf-citation-verifier service, polls the asynchronous job, and returns a per-reference classification (REAL / LIKELY_REAL / NEEDS_REVIEW / LIKELY_FAKE / FAKE) plus an overall hallucination summary. [Routing] Do NOT use for general paper search, scholar lookup, citation-intent analysis, or building a citation graph — use aminer-academic-search, aminer-free-academic, or paper-source-trace instead. This skill only verifies whether references actually exist.
-
canxiangcc Bundle Structured Reference AuditBuild an auditable reference ledger from a paper PDF with GROBID, then resolve structurally parsed entries through AMiner. Use when a user needs conservative reference-existence checking rather than a direct PDF-level FAKE verdict.
-
cdeistopened Skill Sleep OptimizerAudit and fix sleep problems using Huberman Lab protocols. Use when someone has trouble sleeping, wants to optimize sleep quality, asks about sleep supplements, sleep temperature, or says 'help me sleep better.' This is a decision skill — it diagnoses the user's specific sleep issues and prescribes targeted protocols with exact dosages and timings.
Audited -
cloverink Skill Audit FullBranch-aware audit orchestrator. On main — scans whole project, opens tracker issue. On feature branch — scopes to diff, auto-fixes, stages changes.
Audited -
cmj-hub Skill Cold Email Audit30-point audit of a B2B outbound program across four dimensions — infrastructure (8 points), targeting (8 points), messaging (8 points), and operations (6 points). Produces a 0-100 score, the top 3 levers, and a 90-day remediation order. Loaded by the main cold-email skill when the user asks to audit or grade their outbound. Based on the JMC 30-Point Outbound Audit framework.
Audited -
cmj-hub Skill Pricing Audit30-point audit of a B2B pricing program across four dimensions — diagnostic data (8 points), reference frames + copy (8 points), tier architecture (8 points), and operating practice (6 points). Produces a 0-100 score, the top 3 levers, and a 90-day remediation order. Loaded by the main pricing skill when the operator asks to audit or grade their pricing. Based on the JMC 30-Point Pricing Audit framework.
Audited -
cmj-hub Skill Pricing TribunalThe capstone workflow for high-stakes pricing decisions. Four stages — Hypothesize, Test, Adjudicate, Audit — that make material pricing changes safe to ship at speed. Loaded by the main pricing skill when the operator faces a decision material to ARR (new tiers, value-metric switch, raise-the-base, outcome guarantee, kill a tier, change discount policy). Outputs a tribunal-defensible pricing plan + verdict matrix + 30/60/90 audit cadence.
Audited -
csepulv Bundle Michi DebriefStructured post-session review — assess what was delivered, review decisions, capture learnings, audit what got invalidated, refresh the root docs, and calibrate trust for the next session.
-
aligundogdu Bundle Symfony Security VotersSymfony security voters — role hierarchy, voter pattern, access control, authorization, permissions, IsGranted attribute. Triggers on: security, voter, role, authorization, access control, permission, IsGranted, role hierarchy, RBAC
-
pluginagentmarketplace Bundle SpecializedLinux specialized topics - kernel, security hardening, performance
Audited -
holon-run Bundle PDFInspect, extract, assemble, generate, render, OCR, and validate PDF files with local tools while treating active content and external services as explicit security boundaries.
-
tao12345666333 Skill Security Best PracticesSecurity best practices and vulnerability prevention guidelines
-
techfleetworks Bundle Compliance Data LifecycleUse whenever a feature handles personal data, regulated data, or must satisfy audit/compliance requirements, AND whenever building or changing how data is stored, migrated, retained, backed up, or recovered. Covers SOC 2 / ISO 27001 control mapping, GDPR/CCPA privacy engineering (data-subject rights, consent, minimization, DPIA), tamper-evident audit logging, data classification + retention/deletion, and data lifecycle at scale: safe schema/data migrations, backups, and disaster recovery (RTO/RPO). Trigger proactively on "PII," "personal data," "GDPR," "CCPA," "HIPAA," "SOC 2," "ISO 27001," "audit," "compliance," "consent," "data retention," "right to be forgotten," "data deletion," "backup," "disaster recovery," "RTO," "RPO," "migration," or handling user/customer data — even without those words. Pairs with owasp-secure-coding-bdd (security controls) and release-deployment-safety (migration mechanics).
-
teklabsdigital Skill KernelUse to change the claims catalog (add, amend, retire a claim, cut a catalog pass), to manage editions (add, retire, recompose), to measure an edition's conformance honestly (plant, prove, audit, lower a row), to clear accumulated decisions with the owner, or to check that the whole kernel is still coherent. Also use when a claim or edition change may have left counts, scope or statements in the documentation stale. Do not use it to seed a project from an edition; that is seed's job.
-
thibautbaissac Bundle Scaffold SeedAuthor idempotent Drizzle seed data in scripts/seed.ts that supports demos, security proofs, and empty/edge states, with inputs parsed through feature zod schemas.
-
thoreinstein Skill Link AuditUse when the user wants to audit vault link health, find broken wikilinks, orphaned notes, or semantic clusters. Triggers on "link audit", "broken links", "orphaned notes", "link health", "graph cleanup", or "find orphans".
-
thoreinstein Skill Vault LintUse when the user wants a health audit of the vault — stale content, provenance drift, frontmatter compliance, or MOC coverage gaps. Triggers on "lint vault", "vault health", "check vault", "stale notes", "vault audit", "vault quality", or "check conventions".
-
tjcages Bundle Behavior ContractsKeep multi-platform products behaviorally one product: write platform-neutral behavior contracts per form/primitive, let each kit satisfy them natively, audit contract drift (not screenshots). Use when adding a second surface (web/iOS/macOS), when parity tickets pile up, when lightboxes/composers fork, or the user asks for behavior contracts / platform parity / kit drift. NOT for single-platform apps or pure visual QA.
-
tjcages Bundle Linear MethodologyProven methodology for building and tracking features, projects, and issues in Linear. Use when the user wants to set up Linear tracking, sync or audit a board, run a Linear health check, finish install after skills add, or keep session discipline honest. Routes to linear-setup / linear-sync / linear-monitor / linear-finish-install as needed; linear-discipline is always-on.
-
tjcages Bundle Lossless MigrationInventory-before-rewrite: map every table/endpoint/engine/UI to a destination tag, prove zero regressions, retire only when replacement is live. Use when migrating/reframing an existing product, consolidating AI engines, or the user asks for an inventory audit / lossless migration / “don’t lose anything.” NOT for green-field apps with nothing to preserve.
-
afu-it Bundle Setup BillplzSet up, build, debug, review, and explain Billplz payment integrations using Billplz API docs, help center, GitHub plugins, status pages, payment collections, payment forms, Payment Order payouts, X Signature callbacks/redirects, V5 checksums, sandbox/live setup, API Secret Key, Collection ID, and X Signature Key.
-
afu-it Bundle Setup SenangpaySet up, build, debug, review, and explain senangPay payment integrations using official senangPay guide pages, Manual Integration API, Direct API, callbacks, return URLs, query status APIs, refund API, sandbox/live setup, Merchant ID, Secret Key, Hash Type, shopping cart plugins, e-commerce integrations, recurring payments, payout API, tokenisation, split settlements, and DOKU migration references. Use when working with senangPay hosted checkout, payment forms, callbacks, SHA256/MD5 hash verification, Direct API client sessions, JavaScript Web SDK, FPX bank lists, refunds, package capabilities, sandbox testing, or senangPay dashboard setup.
-
afu-it Bundle Setup ToyyibpaySet up, build, debug, review, and explain toyyibPay payment integrations using official toyyibPay API references, onboarding manuals, DuitNow QR notes, pricing/support pages, WooCommerce plugin notes, and WorkDo setup docs. Use when working with toyyibPay categories, bills, payment links, FPX, cards, DuitNow QR, callbacks, return URLs, MD5 callback verification, transaction lookups, inactive bills, sandbox/live setup, secret keys, category codes, WooCommerce setup, or ToyyibPay settlement checks.
-
agoradynamics Skill Wick Consolidate MemoryReflective pass over memory/ files — flag duplicates, stale facts, conflicts, and consolidation candidates. Proposes edits, never applies without confirmation. Use monthly or when /audit flags drift.
Audited -
apache Skill Pr ReviewReview of a PR, branch, or your own uncommitted work across eight dimensions — security, correctness, test coverage, API/compatibility, usability, documentation, code quality, performance. Sizes the diff, reviews inline or fans out reviewers off a shared brief, verifies findings against code, reports a grouped list with a shape verdict, fixes on approval. Use for "review this PR", "/pr-review 3011", or a pre-flight self-review before submitting; add "thorough" for adversarial verification.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include specialized, malicious, pi-extension-development. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.