Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
respawn-llc Skill Architecture Deletion AuditFind wide code mechanisms with narrow or unproven product value and turn one coherent candidate into a plain-language deletion decision. Proactively use for architecture audits, simplification, redundant IDs or state, retry/recovery machinery, protocol fields, and code that may exist only because other code expects it.
-
rodri-oliveira-dev Skill Dotnet Pr ReviewUse this skill to review a Dapper-FluentMap pull request or diff for correctness, regressions, compatibility, tests, performance, security, packaging, release, and maintainability. Do not use to implement PR changes unless explicitly asked.
Audited -
romiluz13 Bundle Pi Package AuthoringPi packages — npm/git distribution of extensions, skills, prompts, themes via keywords pi-package and package.json pi manifest; pi install paths and security expectations. Use when shipping or consuming pi-package, adding pi.skills entries, or explaining install vs project-local -l. Use for "publish pi skills on npm", "pi install", "pi-package.json", even without naming this skill.
-
ron-myers Skill Candid OptimizeAudit and optimize the context candid loads during reviews — Technical.md efficiency, exclude patterns, decision register, and config tuning
-
saltbo Bundle Bep Verification GatesBuild or audit formal proof inventories, coverage policy, native-report reconciliation, or blocking CI gates. Not for ordinary tests.
-
saltbo Bundle Bep Best Engineering PracticePerform an explicitly requested comprehensive engineering-practice audit across relevant disciplines.
-
swell-agents Skill Python ConventionsApply Python conventions — uv, Ruff strict, mypy strict, pytest, pip-audit.
-
symph0nia Bundle Cyberedge Report FindingsReport and query evidence-backed security findings from authorized CyberEdge Tasks. Use for versioned scanner adapters that classify existing Observations, never for arbitrary command or PoC execution.
-
tamasbege Skill Blindspot FinderAdversarial code review that finds the self-review blind spot by forcing four hostile perspective shifts before rendering a verdict. Use when reviewing a diff or PR before merge, when a review feels like it's about to be a rubber stamp, when Claude just said "looks good" and a second, harsher opinion is wanted, or after a long session where fatigue may be hiding bugs. Covers correctness/robustness, maintainability, security, and production operability (logging, alerting, rollback safety) — the last of which most adversarial reviewers skip.
-
th0rgal Skill Bitwarden SecretsRetrieve and manage secrets using Bitwarden Secrets Manager CLI (bws). Trigger terms: bitwarden, secrets, bws, secret, api key, credentials, password.
-
ucsahinn Bundle Codex Chef OperatorMaintain, audit, and improve Codex Chef setup repositories. Use for README/docs/template/catalog/installer/validation updates, release-readiness work, and safe Codex starter maintenance without weakening security, leaking local state, or changing external systems.
-
udecode Bundle UnslopDraft, audit, or edit prose to remove AI-writing tells without changing facts or flattening voice; use for humanizing text, reviewing AI slop, or scanning prose files and docs.
Audited -
vinilana Bundle Open Fusion Quality GatesVerify Open Fusion changes before completion. Use when Codex is finishing a task, preparing a PR, reviewing readiness, or checking software quality gates such as tests, lint, typecheck, formatting, docs alignment, security redaction, SOLID/DRY risks, and residual implementation risk.
-
greatsumini Bundle Cc Usage Audit한 프로젝트에서 사용자가 Claude Code에 입력한 프롬프트·작업 이력을 분석해 (1) 사용 패턴 정량화, (2) 사용자의 개발 철학 추출(근거 인용), (3) 그 철학을 렌즈로 한 메타 시스템(하니스·게이트·CI·프로세스) audit, (4) 우선순위가 매겨진 개선점 발굴을 수행한다. 트리거 — "내 프롬프트 분석해줘", "claude code 사용 패턴 분석", "내 개발 철학 추출", "메타 시스템 점검/audit", "하니스 개선점 발굴", "내가 입력한 프롬프트 기반으로 개선점 파악" 및 유사 의도.
Audited -
drn Skill Hera ReviewDefault, user-overridable code review methodology — the review CONTRACT (what to analyze, how to tag findings) that a broad finder follows when spawned inside a hera-spawn-review panel, or that runs standalone via /hera-review for a single-pass review outside a panel. Encodes ralph-review's review contract (behavior / delta / plan / regression / security / test-coverage audits, the canonical finding tags) without ralph's loop control, auto-fix execution, or OpenSpec-drift resolution flow — those stay with hera-spawn-review (the panel synthesizer + fix loop) or with the invoking user when this runs standalone. Named in a diligence profile's [panel] as review_skill = "hera-review" (the shipped default); a project overrides it freely with its own review_skill or review_instruction — swapping it never requires touching hera-spawn-review.
-
akitaonrails Skill Post RefactorPost-refactor clean-code check after recent refactors or a few merged PRs. Use when the user says "post-refactor", "after the refactor", "we merged a few PRs", "clean code checks", or wants a focused sweep for regressions, vulnerabilities, duplicated abstractions, magic values, weak documentation, missing coverage, or flaky tests without running a full PR/post-merge audit.
-
akitaonrails Skill Github ResolutionExecute the approved outcomes of a pr-audit and/or iss-audit — fix or adjust everything the audit found necessary before merging, verify no regressions, cover every new behavior with unit tests, keep the code clean with zero slop, and resolve each approved ticket one by one. When more than 3 tickets are resolved in one batch, run pr-post-audit before committing and pushing. Use after an audit when the user says to proceed, fix, resolve, adjust, or implement what the audit recommended.
Audited -
franzos Skill AuditAuditing a Forseti deployment
-
nevenincs Skill Vaultspec AdrRecord a new or changed costly decision after checking accepted decision coverage and sufficient Research, Reference, or Audit evidence.
-
nevenincs Bundle Vaultspec CurateReconcile the ADR architecture corpus against the codebase and the feature lifecycle documents against the single-home-fact boundary. Use to audit ADR status and supersession, find ADR-vs-ADR, ADR-vs-code, and document-vs-document conflicts (restated grounding, displaced decisions, forked facts), and action them. Mechanical .vault/ hygiene is the CLI's job; this skill does the semantic reconciliation the CLI cannot.
-
nevenincs Skill Vaultspec Code ReviewAudit planned work for safety, intent, and quality into a rolling audit record. Use at each point of the review cadence.
-
kbravh Skill Proton Pass SecretsRead secrets (API tokens, passwords, TOTP codes) from Proton Pass using the pass-cli and secret references like pass://vault/item/field. Use whenever the user provides a pass:// reference, mentions a credential/token/API key stored in Proton Pass, asks to run a command or investigate an API using a secret from their vault, or wants secrets injected into environment variables, .env files, or config templates — even if they don't name pass-cli explicitly.
-
keep-starknet-strange Bundle Starknet SkillsRoutes Cairo/Starknet coding and audit tasks to the smallest relevant module for focused, high-quality execution.
-
keep-starknet-strange Bundle Audit LocalRun a local security audit on a Cairo repository
-
kevintsai1202 Skill Web Content AuditUse this skill when you need to verify cross-file data/asset consistency in a content-driven site — not "does it render?" (that's `web-visual-verification`) but "do the data, files, and references all line up?". Triggers on phrases like "盤點內容", "稽核資產", "對照 course-data 跟 markdown", "找缺圖", "task ID 有沒有重複", "quiz 編號 vs 硬編碼總數", "audit", "content audit", "content drift", "asset coverage", "three-way sync check", "cross-file consistency", "find missing illustrations", "資料一致性檢查", "找出該補插圖的地方", or any moment when the user senses divergence between source files and deployed data. Output is a human-readable markdown report, not a pass/fail. Pair with `web-visual-verification` for full pre-release coverage.
-
kevintsai1202 Skill Web Visual VerificationUse this skill whenever you need to verify that a web UI actually works the way it's supposed to — clicking through flows, asserting state, catching console errors, taking screenshots across multiple viewports for visual review. Triggers on phrases like "驗證網頁", "verify the site", "Playwright tests", "visual regression", "RWD verification", "screenshot comparison", "responsive check", "console error check", "看看手機版有沒有壞", "視覺驗證", "Playwright 測試", "截圖比對", "RWD 驗證", "驗 sidebar", "看 console 有沒有錯", or any post-change moment where the user wants to know "did I break anything?". This is the runtime-behaviour verifier — use `web-content-audit` instead if the question is about file/data consistency rather than rendered behaviour.
-
langgenius Bundle Dify Docs Format CheckCheck formatting compliance in changed documentation against writing-guides/formatting-guide.md and tools/translate/formatting-{zh,ja}.md. Routes by path: en/ files get the English linter and rules; zh/ and ja/ files get the CJK linter and rules. Use after finalizing a draft or a translation batch, or when the user says "check formatting", "format check", "format audit", or "check CJK formatting".
Audited -
langgenius Bundle Dify Docs API ReferenceRule pack for the Service API specs ({en,zh,ja}/api-reference/openapi_service.json): spec conventions, app-type scoping, code-verification rules, and the audit machinery. Writing and editing run under dify-docs-write; the standalone audit of an existing spec ("audit the API spec") runs directly from this pack.
-
langgenius Skill Dify Docs Terminology CheckAudit terminology consistency across documentation against the codebase UI labels and the glossary — in prose and in the UI strings shown in screenshots. Covers full files, not just diffs; excludes env var docs. Use after finalizing a draft, or when the user says "check terminology", "check terms", "verify glossary", or "terminology audit".
-
leifermendez Bundle Skill Prevention LayerGit diff security and risk auditor. Evaluates ONLY changed code (staged, commit range, or patch file). Detects security leaks, data-loss dangers, and dependency risks. Outputs structured YAML. Blocks critical/high findings with mandatory fix actions.
Audited -
leifermendez Bundle Skill Prisma Mongo AuditSenior-level review and guidance for Prisma ORM with MongoDB. Enforces 15 production commandments covering connection pools index design query optimization cursor pagination batching aggregation security transactions and advanced indexing. Use for code reviews schema audits performance debugging or production-readiness checks on any Prisma and MongoDB project.
-
leifermendez Bundle Skill Security ChecklistTrigger: security audit, codebase review, technical debt assessment, architecture analysis. Comprehensive audit of any codebase detecting frameworks, languages, architecture patterns, and pain points with pros/cons tables.
Audited -
logicleap-labs Skill Secret GuardSecret Guard
-
45ck Skill Secret Exposure Reviewersecret-exposure-reviewer
-
45ck Skill Owasp Wstg Checklist Runnerowasp-wstg-checklist-runner
-
quarkusio Bundle Deprecation CleanupMaintain @Deprecated code in the Quarkus codebase: remove code that has been deprecated for more than 12 months, and add the @Deprecated annotations that were missed when a related element was deprecated (e.g. a field is deprecated but its getters/setters/constructors are not). Use this skill whenever the user asks to clean up deprecations, remove old/long-deprecated code, purge deprecated APIs, "remove code deprecated for over a year", audit @Deprecated usage, or fix inconsistent/incomplete deprecation annotations — even if they don't name a specific class or module.
Audited
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include unslop, architecture-deletion-audit, dotnet-pr-review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.