Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
inclusionai Skill Choruz Pre Simplify AuditPerform the independent Choruz pre-simplify audit or re-audit of skill execution evidence, code structure and test effectiveness. Read-only and limited to the proposed change and its affected paths; not an implementation task or repository-wide cleanup.
-
inkatze Skill BuilderDetect a project's stack and recommend or apply the universal mechanical quality guards from planwright's core catalog (formatter, linters, type-checker, test runner, secret scan, commit hooks, CI gate), plus the growable breadth dimensions. Escalates stake-bearing decisions (auth, data modeling, security posture, integration surface) into the deferral mechanism instead of auto-defaulting them. Plugs into /spec-draft's design phase and /execute-task's guard-application step.
-
jackson-video-resources Skill Strategy AuditTear a strategy apart before you trade it. Edge source, regime dependence, overfit risk, drawdown math.
-
tankimgwan Skill Linmas Incident Triage LeadIncident triage skill for security-event classification, containment planning, evidence preservation, and response coordination.
-
tankimgwan Skill Linmas Secure Code ReviewerSecure code review skill for application risk analysis, threat modeling, scanner tuning, and developer-focused remediation guidance.
Audited -
tankimgwan Skill Linmas Security Operations LeadSecurity operations skill for monitoring, escalation readiness, operational hardening, and day-to-day defensive workflows.
-
tankimgwan Skill Linmas Controls Compliance ReviewerControls and compliance review skill for evidence review, control mapping, audit preparation, and framework gap analysis.
-
tankimgwan Skill Linmas Exploit Validation SpecialistExploit validation skill for authorized environments, attack-surface review, and bounded proof-of-impact workflows.
-
tenwalk Bundle Ieee ExperimentsDesign and audit IEEE communications simulation and numerical-results sections for JSAC, TWC, TCOM, WCL, and CL. Covers benchmark schemes, Monte-Carlo protocol, BER/SER/outage/rate/EE metrics, SNR/antenna/user sweeps, analysis-vs-simulation validation, convergence and complexity, learning-based evaluation, ISAC rate-CRB/detection tradeoffs, robustness, and empirical/ray-tracing/testbed evidence. Use for planning or checking results: benchmark selection, simulation setup, Monte-Carlo validation, neural-network evaluation, CRB/ISAC tradeoffs, fairness boundaries, or reviewer-risk audits.
-
bakhod1r Skill PostmortemWrite a blameless incident postmortem with a timeline and tracked actions. Use after any customer-visible incident, data loss, or security event.
Audited -
haifai-ai Skill Data CleaningClean, normalize, and reconcile messy spreadsheets or delimited files — duplicates, inconsistent labels, mixed types, broken dates — then hand back a tidy workbook plus an audit trail of every change. Use when data looks messy before analysis.
-
derio-net Bundle Fr ProgressPlan / spec progress reporting, and the repo-state preflight for any repo with docs/superpowers/ or fr config. Use when: "what's in progress", "status board", "audit drift", "spec rollup", "is this plan up to date", "is this repo fr-managed", "legacy v1 plans", "before archiving or moving files under docs/superpowers/".
-
sevenbelowllc Skill CloudflareCloudflare infrastructure architect for [YOUR PRODUCT] stack. Auto-activates for Cloudflare DNS, WAF, firewall rules, zone settings, origin certificates, security rules, rate limiting, and any networking change that touches public endpoints.
-
sevenbelowllc Bundle API Security Best PracticesImplement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities
-
alibaba Bundle AI Friendly Audit代码仓库 AI 亲和度审计工具,支持前端、后端、全栈等各类项目。此技能用于检查给定的代码仓库对 AI Coding 工具的友好程度,生成详细的分析报告和改进建议。当用户需要评估代码仓库是否适合 AI 辅助开发、希望提升仓库的 AI 可操作性、或准备引入 AI Coding 工具前进行仓库评估时,应使用此技能。支持 TypeScript/JavaScript、Go、Java/Kotlin、Python、Rust 等主流技术栈。融合 OpenAI Harness Engineering 方法论,评估 Outer Loop(反馈闭环、评估门禁、机械化不变量)建设。
Audited -
hbui290 Bundle N8n Code ToolWrite and debug JavaScript or Python for the AI-callable n8n Custom Code Tool, including schemas, sandbox limits, and return formats.
-
hbui290 Bundle N8n Error HandlingDesign visible, structured, recoverable n8n failures using error outputs, retries, Error Trigger workflows, and HTTP error responses.
-
hbui290 Bundle Cloudflare Security AuditAudit authorized codebases for exploitable vulnerabilities using scoped reconnaissance, adversarial review, validation, and structured reporting.
-
alexyskoutnev Skill Sentence AuditSentence-by-sentence precision pass for paper prose, divide a paragraph into sentences, test each against the first-time-reader defect list, rewrite minimally, condense aggressively; plus the LaTeX editing invariants (wrapping, per-paragraph commits, layout checks) that keep an edit pass safe. Use when polishing a section or caption for submission, when a paragraph reads wrong but the fault is unclear, or when auditing a figure-caption-table exhibit as a unit.
-
andiedie Bundle Codebase SimplifyAudit a codebase for evidence-backed opportunities to remove or collapse complexity.
-
andrewdongminyoo Bundle Rn Eas Profile AuditUse when you need a deterministic, read-only resolution of one Expo EAS build profile and its extends chain from eas.json.
Audited -
clearmeasurelabs Skill PostmortemWrites a single-incident postmortem/retrospective right after a production incident -- a fast-path companion to Pillar 3 (Achieve Stability). Use immediately after an incident is resolved, while details are still fresh, instead of waiting for a full stability audit.
Audited -
crawlio-app Skill Audit SiteUse this skill when the user asks to "audit a site", "analyze a website", "review a site", "site health check", or wants a comprehensive analysis including technology stack, issues, and recommendations. Orchestrates a full crawl, enrichment capture, observation analysis, and findings report.
Audited -
achrefchatcount Bundle Juridique FranceSkill expert en compliance et délais légaux français. À utiliser pour : vérification des délais de paiement LME (60 j max), calcul des pénalités de retard (3× taux légal + 40 € indemnité forfaitaire), seuils sociaux (CSE 50 sal., etc.), catégorie légale d'entreprise (micro/petite/moyenne/grande), audit de conformité d'un portefeuille de factures. Se déclenche sur : "délai de paiement", "retard fournisseur", "LME", "pénalités de retard", "seuil social", "CSE", "compliance", "conformité légale", "indemnité forfaitaire", "catégorie entreprise", "obligations légales RH". NE PAS utiliser pour : contentieux judiciaire, droit du travail individuel, licenciement, rédaction de contrats.
Audited -
cyl19970726 Bundle Video Content ReconstructionReconstruct a video's full content with an adaptive, evidence-backed two-round workflow. Use when Codex must understand, restore, analyze, convert to an article, document, or audit any video whose important information may live across speech, subtitles, on-screen text, interfaces, actions, parameters, before/after states, examples, claims, counterexamples, or visual transitions. First probe the viewer's intended cognitive change, information carriers, meaning changes, relationship structure, and omission risks; then derive and execute a video-specific capture protocol. Do not route by a closed content taxonomy.
Audited -
datadog Bundle PupDatadog API CLI with 49 command groups, 300+ subcommands. Skills and domain agents for monitoring, logs, APM, security, and infrastructure.
-
ekovegeance Skill Email And Password Best PracticesConfigure email verification, implement password reset flows, set password policies, and customise hashing algorithms for Better Auth email/password authentication. Use when auth need to set up login, sign-in, sign-up, credential authentication, or password security with Better Auth.
-
ekovegeance Bundle Better Server Security Best PracticesConfigure rate limiting, manage server secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for Better Auth. Use when auth need to secure their server setup, prevent brute force attacks, or harden a Better Auth deployment.
-
ekovegeance Skill Two Factor Authentication Best PracticesConfigure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin. Use when auth need MFA, multi-factor authentication, authenticator setup, or login security with Better Auth.
-
hikaruegashira Skill Audit Support日本の内部統制報告制度(J-SOX)・会社法監査・税務調査対応。freeeデータを活用した証憑収集・統制テスト・監査調書作成をサポート。
-
pockethost Bundle PocketbaseModels PocketBase backends: collections, relations, auth, API rules, migrations, and architecture. Use when designing schema, security rules, data modeling, choosing between hooks vs client access, or explaining PocketBase platform concepts — not for npm JS SDK code or pb_hooks.
-
qteqpid Bundle My IOS App Swiftui PerformanceAudit and improve SwiftUI runtime performance. Use when diagnosing slow rendering, janky scrolling, high CPU, memory usage, excessive view updates, layout thrash, body evaluation cost, identity churn, view lifetime issues, lazy loading, Instruments profiling guidance, and performance audit requests.
-
quillai-network Bundle Semantic Guard AnalysisDetects logic vulnerabilities in smart contracts by analyzing guard-state consistency patterns. Identifies functions that bypass security checks (require, modifiers) that other functions consistently apply. Uses the Consistency Principle — a contract is its own specification. Use when auditing smart contracts for missing access controls, inconsistent pause checks, logic bugs, forgotten modifiers, or when traditional tools report no issues but logic errors may exist.
Audited -
quillai-network Bundle Behavioral State AnalysisToken-efficient smart contract security auditing via Behavioral State Analysis (BSA). Scopes analysis to contract type, runs only relevant threat engines, and uses tiered output depth. Use for auditing smart contracts, security reviews, or DeFi threat modeling.
-
quillai-network Bundle Signature Replay AnalysisDetects signature replay vulnerabilities in smart contracts — affecting 19.63% of signature-using contracts. Covers five replay types (same-chain, cross-chain, cross-contract, nonce-skip, expired-signature), EIP-712 domain separator verification, nonce management analysis, ecrecover edge cases (address(0), malleability, s-value), permit/permit2 safety, ERC-1271 contract wallet support, and meta-transaction security. Use when auditing contracts with ecrecover, ECDSA, EIP-712, permit, meta-transactions, multi-sig, or any off-chain signature verification.
-
rabbyhub Bundle Rabby Mobile Code ReviewReview Rabby Mobile pull requests for actionable correctness, wallet-safety, security, privacy, performance, build, and supply-chain issues, and publish validated inline GitHub findings. Use for outbound review of a PR or its changed code; use mobile-pr-ready-watch instead to mark a PR ready, monitor incoming feedback, implement requested fixes, or resolve review threads.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include choruz-pre-simplify-audit, builder, strategy-audit. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.