Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
jairotorregrosa Skill Constatar VerifyRun and interpret verification through the constatar engine — the 6-rung ladder, grounded evidence, and conformance auditing. Use when the user asks to verify work with constatar, run a constatar plan, or audit a constatar run.
-
jasoncodemaker Bundle ReflectionUse when the user invokes $reflection or asks for an independent, concise post-task audit of whether Codex overthought a completed request, used too many tools, or should persist a project-scoped workflow lesson.
-
kirkruglov Bundle Arch HealthPeriodic audit of the recorded architecture of the current project - cross-document consistency, docs vs actual code dependencies, version freshness, ADR journal integrity. Read-only - reports findings and recommended actions, changes nothing. Run manually via /arch-health or from a per-project scheduled task.
-
myaifreedomsystems Bundle GoalIncredAgents /goal command — structured planning + launch infrastructure (Swarm Heartbeat, Telegram) + stateful execution + workspace governance. Fuses plan-for-goal (planning discipline) with persistent state management plus quad-logging, approval gates, completion audit, and Pacific Time.
Audited -
nordic-ai Skill Test CoverageEnforces a 90% line and branch coverage threshold and audits for meaningful integration, end-to-end, stress, and property-based tests beyond unit tests. Identifies critical paths that lack coverage, flags tests that pass without asserting, and in edit mode generates missing test scaffolds. Use when the user asks to "check test coverage", "audit tests", "are we tested enough", "add tests", invokes /test-coverage, or when the orchestrator delegates. Stack-agnostic, mode-aware, scope-tier-aware.
Audited -
nordic-ai Skill Security AuditComprehensive application security audit covering OWASP Top 10, authentication, authorization, secret handling, input validation, cryptography, session management, CORS, CSP, security headers, and common injection vectors. Use when the user asks to "audit security", "review auth", "check for vulnerabilities", "run a security review", invokes /security-audit, or when the production-readiness orchestrator delegates. Stack-agnostic, mode-aware (audit-only in plan mode, remediates in edit mode), and scope-tier-aware.
Audited -
nordic-ai Skill Reliability AuditReviews an application's reliability posture — error handling, retries with backoff and jitter, timeouts, idempotency, circuit breakers, graceful degradation, transaction boundaries, and failure isolation. Use when the user asks about "reliability", "error handling", "resilience", "retries", "timeouts", "graceful degradation", invokes /reliability-audit, or when the orchestrator delegates. Stack-agnostic, mode-aware, scope-tier-aware.
Audited -
nordic-ai Skill Observability AuditReviews logging, metrics, distributed tracing, error reporting, alerting, and operational runbooks. Checks that the system emits the right telemetry at the right granularity, that signals are actionable, and that on-call has what it needs. Use when the user asks about "observability", "logging", "metrics", "tracing", "monitoring", "alerting", invokes /observability-audit, or when the orchestrator delegates. Stack-agnostic, mode-aware, scope-tier-aware.
Audited -
nordic-ai Skill Production ReadinessOrchestrates a full production-readiness review of an application. Use when the user asks "is this production-ready", "audit my app", "what's missing before we ship", "prepare this for launch", or when they invoke /production-readiness. Triages scope, jurisdiction, and stack, then delegates to the 8 specialist audit skills (security, compliance, test-coverage, reliability, observability, supply-chain, data-protection, scalability) and aggregates their findings into a single go / no-go report.
Audited -
nordic-ai Skill Data Protection AuditReviews how data is classified, stored, transmitted, retained, and destroyed. Covers encryption at rest and in transit, PII classification and inventory, retention and deletion policies, data residency, key management, backup integrity, and anonymization / pseudonymization. Use when the user asks about "data protection", "encryption", "PII", "data retention", "key management", "backups", invokes /data-protection-audit, or when the orchestrator delegates. Stack-agnostic, mode-aware, scope-tier-aware.
Audited -
trendmicro Skill Email SecurityEmail Security
-
trendmicro Skill Endpoint SecurityEndpoint Security
-
trendmicro Skill Container SecurityContainer Security
-
trendmicro Skill Threat IntelligenceThreat Intelligence
-
wecode-ai Bundle Weibo Skill微博技能集合。包含热搜榜、智搜、用户微博、超话互动、图片/视频上传、定时任务、创作者数据分析等功能。 首次使用请先完成配置(向用户询问 App ID 和 App Secret,运行 login 命令完成登录)。
Audited -
wecode-ai Bundle Weibo Skill API微博技能集合。包含热搜榜、智搜、用户微博、超话互动、图片/视频上传、定时任务、创作者数据分析等功能。 首次使用请先完成配置(向用户询问 App ID 和 App Secret,写入本地配置文件并获取 Token)。
-
wemwi Bundle Global Make ConventionsProjektübergreifender Konventionsstandard und Audit-Maßstab für Make-Szenarien — Architektur-Grundprinzipien, Architektur-Muster (Dispatcher/Worker, native Subscenarios, Router-Fan-out u.a.) und eine MUST/SHOULD-Regelliste (Naming, Settings, Modul-Wahl, Trigger, Schleifenfreiheit, Webhook-Lebenszyklus, Idempotenz, Fehlerbehandlung, Datenlayer, Variablen/State, Blueprint-Hygiene). IMMER laden, sobald ein Make-Szenario entworfen, gebaut, geprüft oder auditiert wird — auch ohne das Wort Skill. Ergänzt make-scenario-building/make-module-configuring (die WIE decken) um das WELCHE und dient als Prüfmaßstab für den Gesamt-Audit. Trigger u.a.: Szenario-Architektur, Dispatcher-Pattern, Trigger-Wahl, Webhook vs. Polling, Schleifenprävention, Watch-Feld, changeTypes, Idempotenz-Gate, dedupkey, Error-Handler-Konvention, Blueprint-Hygiene, Szenario-/Modul- Naming, native Modul vs. HTTP, Legacy-Modul, Set/Get Variables, Set Multiple Variables, Variablen-Scope, Scenario- vs. Custom-Variable, Data Store, Make-Audit.
-
xiaotianfotos Skill Homerail Pr ReviewRun HomeRail's built-in read-only pull request review DAG. Use when the user asks to review a GitHub PR, requests an evidence-backed PR audit, or wants a reusable independent Qwen, Kimi, and GLM review with retained findings.
-
ace-step Skill Quality AuditQuality Audit Skill
-
croftspan Skill SnapRun The Snap — audit rules for bloat, staleness, and derivability, then capture session learnings. Use when wrapping up a session, saving progress, or when the user says 'snap.' Requires an existing .claude/rules/snap.md in the project.
Audited -
croftspan Bundle SweepDeep code sweep — dispatches 3 parallel focused auditors for security, stubs, and code quality. Works standalone or offered after gigo:execute completes. Use gigo:sweep.
-
croftspan Bundle MaintainOngoing maintenance for your assembled expert team. Add expertise, audit for bloat, restructure messy setups, or upgrade older projects. Auto-detects severity — targeted addition, health check, or full restructure. Use gigo:maintain, /maintain, or when gigo:blueprint or gigo:snap detect gaps.
-
glideapps Bundle App AuditAudit Glide apps for performance issues and optimization opportunities. Use when analyzing app performance, identifying bottlenecks in data structure or layout, or providing recommendations for improving app speed and user experience. Automatically triggered when user provides a Glide app URL for audit, including read-only support-mode URLs of the form https://go.glideapps.com/support/{uuid}. Can also produce an optional plain-language, customer-facing version of the report on request, for sharing directly with the customer who reported the issue.
-
glideapps Skill App SharingManage Glide app access, privacy, authentication, and publishing. Use when configuring who can access an app, setting up sign-in methods, publishing apps, inviting users, or configuring Row Owners for data security.
-
learn-with-santosh Skill Code ReviewerPerforms deep, professional code reviews. Use this skill whenever a user wants to "review this code", "check for bugs", "improve quality", or needs a second pair of eyes on a Pull Request. This skill focuses on performance, security, maintainability, and clean code principles.
-
saurabhshuklagrowisto Bundle Lead Nurture SequencerStages leads by real engagement signal (opens, clicks, replies, meetings booked, unsubscribes, days since last touch) and decides the next nurture action for each -- what to send, and how many days until it's due. Enforces the suppression/cooling rules that keep automated nurture from talking over a real reply or a booked meeting, or re-touching someone who unsubscribed. Use to run or audit an email/lifecycle nurture cadence, decide who's due for a touch today, or check that automation isn't stepping on human-handled leads.
Audited -
saurabhshuklagrowisto Bundle Website Conversion AuditAudits a B2B website page for conversion leaks from a buyer's lens and returns findings ranked by revenue impact. Takes a URL plus a set of observed page elements (hero message, CTAs, form fields, trust signals, mobile behaviour) and returns P0/P1/P2 findings, each with what was found, why it costs conversions, a concrete fix, and how to measure the fix. Use before a redesign, when diagnosing why demo requests are low, or to turn a landing page review into a prioritised action list.
Audited -
saurabhshuklagrowisto Bundle Ecommerce Conversion AuditAudits a D2C / eCommerce store for conversion leaks along the path to purchase and returns findings ranked by revenue impact. Takes a URL plus observed elements across the product page, cart, and checkout (imagery, price clarity, add-to-cart, guest checkout, steps, payment options, shipping surprises, reviews, returns, urgency, mobile) and returns P0/P1/P2 findings, each with what was found, why it costs revenue, a concrete fix, and how to measure it. Use before a store redesign, when the add-to-cart or checkout conversion rate is low, or to turn a store review into a prioritised action list. This is the D2C counterpart to the B2B website-conversion-audit skill.
Audited -
daochild Skill Senior Bitcoin AuditorProvides senior-level security auditing guidance for Bitcoin smart contracts including Taproot/Script, PSBT, UTXO management, Lightning Network, DLCs, and Bitcoin L2 protocols. Use when auditing Bitcoin contract code, PSBT builders, settlement engines, Lightning integrations, or ordinal/BRC-20 logic.
-
daochild Skill Senior Solidity AuditorProvides senior-level smart contract security auditing guidance for Solidity/EVM including vulnerability patterns, formal verification, gas optimization, and audit methodology.
-
homingo Skill Code ReviewReviews source code for bugs, security vulnerabilities, and style issues. Provides suggestions for improvement following language-specific best practices.
-
homingo Skill Security AuditAudits applications and infrastructure for security vulnerabilities, misconfigurations, and compliance with security standards. Performs penetration testing analysis and recommends remediation steps.
-
horizon-foundry Skill FoundryUse when a project is approaching a release decision and you want one pass over its pre-ship gates instead of remembering each one. Resolves the project's release policy, then runs `check` (read-only preview) or `prepare` (invokes the gate skills to close the gaps). Not an inspector; production-audit issues the authoritative verdict afterward.
-
horizon-foundry Skill DocumentUse to keep a project's documentation true to the code and current across every surface, or to turn the repo's own docs into a product surface (the public hub, the overview deck, showcase copy). Modes, public, internal, reconcile; idempotent and safe to re-run. Not for creating a doc set from nothing (that is scaffold) or judging release readiness (that is production-audit).
-
horizon-foundry Skill Feature DesignUse when a substantial feature is being designed inside an existing codebase, before any implementation plan is written. The builder declares the feature; the skill audits the declaration against the repository and reports what the code contradicts or already provides. Never an interview, never the implementation plan (phase-plan), never a verdict (production-audit).
-
inclusionai Skill Choruz DocCreate, restructure, review, audit, or migrate Choruz Markdown documentation (docs/, README, AGENTS.md, the in-app docs pages) using one owner per fact, tier placement, executed-operation fact-checking, current-state prose, and the repository validators. Use for new or revised docs, docs-tree organisation, and documentation-quality audits.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include constatar-verify, reflection, arch-health. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.