Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
kong Skill Volcano FunctionsUse for Volcano server-side Functions and privileged or secret-bearing logic, including function invocation, generators such as QR codes or PDFs, outbound third-party APIs, orchestration, scheduled processing, and file or image processing.
-
crawlio-app Skill Extract SecretsUse this skill when the user asks to "find hardcoded secrets", "scan for API keys", or "audit credentials" in a web application they own or are authorized to test. Scans decompiled JavaScript and classifies findings as confirmed, potential, or false positive.
Audited -
eliasali0720 Bundle Hipaa FundamentalsDetermines whether and how HIPAA applies to a product, company, or data flow, and explains the core rules with exact regulatory citations — PHI and the 18 identifiers, covered entities vs business associates, Privacy/Security/Breach Notification Rules, patient rights, and penalties. Use when someone asks "does HIPAA apply to us", "is this PHI", "are we a business associate", "do we need a BAA", or needs any HIPAA scoping, definitions, or regulatory overview.
-
eliasali0720 Bundle Hipaa Risk AnalysisConducts and reviews HIPAA Security Rule risk analyses under 45 CFR 164.308(a)(1)(ii)(A) using the NIST SP 800-66r2 methodology — ePHI asset inventory, data-flow mapping, threat and vulnerability identification, likelihood/impact rating, risk register, and risk management plan. Use when someone asks for a HIPAA risk analysis, risk assessment, security risk assessment (SRA), 164.308 compliance, OCR audit prep, or an asset inventory of ePHI systems.
-
eliasali0720 Bundle Hipaa Compliance ProgramBuilds and matures a HIPAA compliance program — the 12 required policies, Privacy Officer and Security Officer designation, workforce training, 6-year documentation retention, and OCR audit readiness — staged from day-1 startup to enterprise. Use when someone asks how to become HIPAA compliant, needs a HIPAA compliance program, HIPAA policies, a compliance checklist for a startup, privacy officer or security officer duties, HIPAA training requirements, or is preparing for an OCR audit.
-
harishdvs Skill Grizzly AuditSimulate a cold first-time reader and report the reading experience of a chapter. Use when the user asks why a chapter feels boring or flat, whether a chapter works, what a reader would feel, or wants a fresh-eyes read. Reports experience, not errors; for error-finding use grizzly-review.
-
harishdvs Skill Grizzly ReviewComprehensive quality review of one or more chapters. Use when the user asks for a full review, quality check, violation scan, or pre-publication pass. Runs five passes with severity-tiered findings. For "why is this boring" use grizzly-audit instead.
-
jason-hub-star Skill AbsorbExtract only the changes worth porting from an external source (article, release notes, competing harness, thread) by comparing it against the current inventory and classifying each idea as already present, an addition to an existing asset, or genuinely new. Use for “what can we learn from this repo”, “should we adopt this”, “review these release notes”, “흡수”. Unlike a harness audit, this judges what to bring in, not what to remove.
-
jason-hub-star Bundle Harness AuditMeasure whether installed harness assets (skills, commands, templates) are actually invoked, using session logs rather than opinions, then archive dead assets, harvest improvements back to the template, and keep the installed set under the recovery-rate cap. Use for “which skills are unused”, “too many skills”, “harness check”, “why doesn't this skill trigger”, “정비”. Unlike absorb, this removes and consolidates what exists.
Audited -
jason-hub-star Skill Evidence AuditAudit work before it is shared or called complete, choosing a light decision review, a multi-lens defect search, or a deep high-risk review. Use for “audit”, “red team”, “final review”, “감사”, security and resilience checks, or release readiness. Finding issues is read-only unless fixes are explicitly requested.
-
observal Bundle Observal AdminAdministers Observal users, settings, diagnostics, review queues, security events, audit logs, SAML, SCIM, local server services, upgrades, rollback, and database migrations. Use when the user needs privileged governance, submission decisions, identity configuration, security investigation, or server operations.
-
observal Skill Security Auditor<!-- SPDX-FileCopyrightText: 2026 Lokesh Selvam <lokeshselvam7025@gmail.com> -->
-
pr1m4lc0d3 Bundle Kiss Debt GuardUse when a repo needs an enforceable size/debt control rather than advice — installs a light, dependency-free size-budget audit script plus a config, and points to heavier guards (dead-code, duplicate-surface, test-debt, dependency-risk, doc-drift) when a repo warrants them. Use during KISS kickoff, or when files keep drifting over budget despite good intentions.
Audited -
marsmike Bundle Retrieval VerificationAudit vault note descriptions by predicting content from title+description alone and scoring the prediction against the real body. Use for periodic vault maintenance or after a bulk distill/import.
-
paradigmxyz Skill Auth Failure Log TriageInvestigate reported auth, credential, permission, API proxy, 401, 403, 503, OAuth, token, or secret-resolution failures by querying VictoriaLogs first. Use when a user says an integration auth failed, a tool got unauthorized/forbidden/service unavailable, an api-proxy request failed, or asks why credentials/secrets are not working.
-
sujeet-pro Bundle ReviewReview, audit, sanity-check, look-at any review-able target. Triggers on a GitHub PR URL (fetched via the gh CLI), a local path or "." (review the working tree), a markdown/doc file, or a comment-thread URL. Read-only by default; --fix applies accepted findings locally and pushes to the PR branch after confirmation (never force, never merge, never to a protected branch). Produces severity-tiered findings (blocker / critical / should / may / nit) with path:line and <=15-word verbatim evidence quotes. Six dimensions: correctness, tests, security, performance, readability, consistency. For a deep PR review with cross-file code-context retrieval, use /adk:pr-review.
-
shandar Skill Pwp Code ReviewSystematic code review protocol — review code with rigor and specificity. Use this skill whenever the user asks you to review code, check a PR, audit a file, look over changes, or give feedback on implementation quality. Also use when they say 'review this', 'is this code good', 'check my work', 'what do you think of this implementation', or 'any issues with this'. Covers correctness, security, readability, performance, maintainability, and testing.
-
shuymn Bundle Adversarial VerifyAdversarial verification of code changes — probes target files for vulnerabilities through edge cases, error paths, security boundaries, and concurrency attacks. Use when you want to stress-test implementation correctness or validate defensive robustness before shipping.
-
skills-il Bundle Israeli Scam DetectorNot legal advice and not a security guarantee. Check whether a suspicious Israeli SMS, email, link or phone call is a scam, and get the exact next steps, including after the money is already gone. Covers smishing and phishing impersonating Israeli banks, Bituach Leumi, Rashut HaMisim, Israel Post and gov.il, SIM-swap takeover, and the 2026 wave of AI voice-cloning and deepfake fraud. Explains the real deadlines under the Payment Services Law 2019 (the Debit Cards Law it replaced is repealed), the 8-business-day refund clock, and the 24/7 human bank fraud line that owes customers aged 70 or over queue priority, and where Russian-language service is an expectation the regulator voiced rather than a duty. Use when a user asks whether a message or link is real, got a suspicious call, thinks they were scammed, or wants to protect an elderly or Russian-speaking relative. Do NOT use for malware removal, corporate incident response, or to declare a specific message safe.
-
skills-il Bundle Israeli Appsec ScannerSecurity scanning guidance for Israeli web applications covering OWASP Top 10, Israeli Privacy Protection Authority (PPA) compliance, dependency vulnerability scanning, secrets detection, and secure coding patterns for Hebrew/RTL apps. Use when user asks to "scan for vulnerabilities", "check security compliance", "audit Israeli app security", "bodek aviskhut" (Hebrew transliteration), or needs help with PPA compliance, secrets detection, or Hebrew input sanitization. Provides actionable checklists, automated scanning scripts, and Israeli-specific security guidance. Do NOT use for network penetration testing, physical security audits, or non-application-layer security concerns.
Audited -
skills-il Bundle Israeli Privacy ShieldIsraeli Privacy Protection Law compliance guidance including Amendment 13 (effective August 14, 2025), database registration, consent requirements, data security, cross-border transfers, breach notification, privacy protection officer appointment, and AI governance. Use when user asks about Israeli privacy law, "haganat pratiut", "tikun 13", data protection in Israel, GDPR compliance for Israeli companies, privacy policy requirements, or database registration. Covers the Privacy Protection Law 1981, Amendment 13, and 2017 Security Regulations. Do NOT use for EU GDPR-only questions without Israeli context.
Audited -
skills-il Bundle Israeli Cybersecurity OpsCoordinate Israeli-built cybersecurity tools for security operations including threat triage, vulnerability management, compliance checking, and incident response. Use when user mentions security operations, "SOC", vulnerability scanning, threat triage, compliance assessment, or asks to coordinate Wiz, Snyk, Check Point, CyberArk, SentinelOne, Armis, Torq, or Pentera tools. Embeds Israeli security best practices including INCD guidelines and Israeli Privacy Protection Law compliance. Do NOT use for offensive security testing or creating exploits.
Audited -
spencerkit Bundle Code ReviewMulti-language code review skill with security audit and performance optimization suggestions
-
sshtomar Skill Rct Ethics RegistrationHandle ethical requirements, IRB approval, trial registration, and pre-analysis plans for RCTs. Use when user mentions: research ethics, IRB, informed consent, trial registration, pre-analysis plan, PAP, data security, vulnerable populations, research transparency.
-
starkware-libs Skill Fri ProtocolCircle FRI protocol specifics for STWO: commitment phase, query phase, folding operations, security parameter derivation, and multi-step folding. Use when modifying FRI prover or verifier code, changing FRI parameters, or reviewing folding operations.
-
starkware-libs Skill Zk Stark FoundationsSTWO-specific STARK architecture and protocol flow. Provides implementation locations, security parameter configuration, proof flow mapping, and invariants. Use when working on proof system code, reviewing constraint logic, modifying FRI parameters, or auditing soundness.
-
starkware-libs Skill Security Review ChecklistSecurity review checklist for STWO. Separate from soundness review. Covers: side-channel surface, input validation, unsafe code audit, dependency security, API misuse patterns, and proof malleability. Run this for any change affecting the public API, proof format, hash functions, or memory-safety-critical code.
-
starkware-libs Skill Soundness Review ChecklistStructured checklist for reviewing soundness-critical code changes in STWO. Run this checklist before approving ANY modification to: constraint logic, FRI protocol, verifier, field arithmetic, polynomial commitment scheme, Fiat-Shamir channel, proof serialization, or security parameters.
-
sterlingcrispin Skill SelfauditPause and do a first-principles audit of recent work
-
sterlingcrispin Skill AuditcodexSend recent work to OpenAI Codex CLI for an independent audit/review
-
sterlingcrispin Skill AuditcodexdirectSend specific files to OpenAI Codex CLI for an independent audit/review
-
strongeron Bundle Sb AuditPeriodic Storybook audit — naming-drift survey, archived/decision-board review, lifecycle tagging, usage refresh. Use for 'audit my Storybook', 'find drift', 'show pending decisions', or a periodic catalog health check.
Audited -
strongeron Bundle Sb FlowsMap the whole app — routes, navigation edges, and persistent nav chrome, not just a screen list. Use for 'map the app', 'show the flow', 'app map', 'audit navigation', or 'how do screens connect'.
Audited -
reinvestwealth Skill Riw Prepare Financials CaPrepare a Canadian corporation's year-end financial statements from books kept in ReInvestWealth: Income Statement and Balance Sheet mapped to GIFI codes, a CCA schedule, working papers, and a GIFI import file for the T2 preparer, all on a compilation engagement basis with a complete audit trail. As the final step, on its own approval, it posts the year-end adjusting entries (CCA, accruals, reclasses, corrections) back into the books so the ledger carries the filed position forward. Use when someone asks for year-end financials, financial statements, a compilation engagement, GIFI mapping, or a T2 preparation package.
Audited -
reinvestwealth Skill Riw Prepare Financials UsPrepare a US corporation's year-end financial statements from books kept in ReInvestWealth: Income Statement and Balance Sheet on the income tax basis of accounting, a tax depreciation schedule, working papers, and a return mapping file for the Form 1120 or 1120-S preparer, all prepared for CPA review with a complete audit trail. As the final step, on its own approval, it posts the year-end adjusting entries (depreciation, accruals, reclasses, corrections) back into the books so the ledger carries the filed position forward. Use when someone asks for year-end financials, financial statements, tax-basis statements, or an 1120 or 1120-S preparation package for a US corporation.
Audited -
sanexxxx777 Skill System HealthPreventive hygiene audit of your own Claude Code configuration — memory files, project context (CLAUDE.md), rules, permissions, skills — a deterministic scan of sizes / broken links / stale entries / excessive permissions / junk + interpretation + targeted fixes by agreement. Keeps the setup from rotting before it breaks. Triggers — "check the system", "system health", "workflow hygiene", "what to clean up", "audit memory", "optimize the system".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include sb-audit, volcano-functions, extract-secrets. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.