Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
sebastianelvis Skill InvestigateRun investigation cycles that test hypotheses through proof verification, counterexample search, or security analysis, with keep-or-discard discipline. Use when asked to investigate, verify, prove, or disprove claims.
Audited -
testbeagle Skill BreachsweepUse when asked to security-test, pentest, or find vulnerabilities in a locally runnable app you own — auth/authorization (IDOR), input validation (injection), secret exposure, security headers, insecure cookies/CORS. Triggers on "보안 점검", "취약점 찾아줘", "security audit", "pentest my app".
-
upsolve-labs Skill ReviewSenior engineer code review. Compares the current branch against its base branch for bugs, security risks, and code quality issues. Best run in a clean conversation.
-
yumeno Bundle Ask Codex With Contextテキスト、複数画像、git diff、git logなどのコンテキストを添えてCodex CLIにレビュー、監査、設計相談を依頼する。ユーザーがCodexによる画像確認や、ファイルパス・diff・security・監査と併せた質問を明示した場合に使う。
Audited -
abmach Skill ScoreDocument implementation changes - audit finished code and update docs, README, and CHANGELOG for shipped features; invoked by orchestrate when Docs Affected = true, via "/score PLAN-001" for one plan, or "/score" alone for batch mode
Audited -
adityaarakeri Skill Self ReviewReview a completed diff or change set for correctness, security, regressions, scope, and missing tests. Use in author mode before handoff or in read-only mode when the user asks to review, inspect, check readiness, or report findings. Do not replace runtime completion evidence from verify-done, and do not fix findings during a review-only request.
Audited -
vstorm-co Bundle Production CheckFull production readiness audit with 0-100 score — scans the entire project across security, error handling, observability, deployment readiness, database patterns, and container hygiene. Launches parallel analysis, classifies findings by severity, and produces a prioritized action plan. Use this skill when user says /production check, /production score, asks 'is this production ready', 'audit this project', 'how production ready is this', or wants a comprehensive codebase health check.
-
vstorm-co Bundle Production ReviewProduction-readiness code review that checks for security vulnerabilities, error handling, logging, configuration, performance, and operational concerns. Use this skill when the user asks for a code review, PR review, quality check, production readiness check, or says 'review this', 'is this production ready', 'check my code'. Also trigger when reviewing pull requests that touch backend services, APIs, or infrastructure code. Works with Python, Node.js, Go, and Java codebases.
-
vstorm-co Bundle Production FastapiProduction-grade FastAPI patterns — structured logging, health checks, graceful shutdown, middleware, Pydantic v2, async patterns, error handling, and security hardening. Use this skill when the user is building or modifying a FastAPI application, working with Pydantic models, configuring Starlette middleware, setting up Uvicorn/Gunicorn, or asks about FastAPI best practices. Triggers when importing fastapi, starlette, pydantic, or uvicorn. Also trigger when user says /production fastapi. DO NOT trigger for Django or Flask unless explicitly asked.
-
vstorm-co Skill Production PlannerArchitecture planning for production systems — guides system design with scalability, reliability, security, and operational concerns from day one. Use this skill when the user asks to plan architecture, design a system, plan a new service, discuss system design, or says 'plan this', 'how should I architect this', 'design the system for'. Triggers on architecture discussions, system design, API design, data modeling, and infrastructure planning.
-
vstorm-co Bundle Production SecurityProduction security hardening — secrets management, CORS policy, authentication patterns, authorization models, rate limiting, security headers, dependency scanning, and OWASP Top 10 awareness. Use this skill when the user works on authentication, authorization, secrets, CORS, rate limiting, security headers, or any security-adjacent code. Also trigger when user says /production security.
Audited -
zakirkun Skill Security🔒 Cybersecurity & Privacy Skill
-
zencoderai Skill GitThis skill should be used when the user asks to "clone a repo", "git clone", "check out this repo", "install this tool from GitHub", "try this open source project", or mentions cloning, checking out, or installing any Git repository. Automatically gates public repo clones with a security assessment before execution.
-
zencoderai Skill Code ReviewReview code changes for correctness, security, performance, and code quality. Use when the user asks to review a diff, review code changes, review commits, or perform a code review. Input can be: (1) a text diff pasted directly, (2) one or more git commit hashes to extract the diff from, or (3) a git range like abc123..def456. The user may also provide task description or requirements that motivated the change.
-
zly2006 Bundle Zhihu Pp AI Slop CleanerUse for Zhihu++ maintenance work that scans Kotlin main sources for low-call functions, structurally similar function bodies, dead code, pure forwarding wrappers, pointless abstractions, repeated helpers, and cross-platform duplicate glue before refactoring or PR cleanup. Trigger when the user asks to clean AI slop, remove low-call wrappers, find similar or duplicated code, review duplicated helper functions, or audit functions with call count at most 2 in /Users/zhaoliyan/IdeaProjects/Zhihu.
Audited -
zly2006 Bundle Zhihu Instrument Test GovernanceAudit, add, migrate, or remove Zhihu++ Android instrument tests under app/src/androidTest. Use for instrument-test cleanup, flaky device-test reduction, regression-test provenance, deciding whether a UI test belongs on an emulator, or reviewing a PR that changes permanent Android instrument coverage.
-
basisti Bundle Basis Multi TenantIsolamento multi-tenant em tabela única (single-table, coluna `tenant_id`) com Row Level Security do Postgres. Use quando alguém disser "vazamento cross-tenant", "leak cross-tenant", "RLS bypass", "isolamento multi-tenant", "esqueci de filtrar por tenant", "pk composta", "id composto", "TenantContext"; ao criar tabela nova com `tenant_id`; ao revisar endpoint que recebe `tenantId` do cliente; ou quando um `SELECT` volta vazio e ninguém sabe por quê. Prefira esta à `basis-spring-app` quando o assunto for isolamento entre clientes, porque o sintoma engana: parece bug de datasource, de transação ou de migration, e é de RLS.
Audited -
basisti Skill Basis Java Code StandardsUse when writing, reviewing, or refactoring Java code in a Basis project — formatting and naming, modern Java (records, sealed types, pattern matching, text blocks), exception handling, nullability and immutability, collections and streams, date/time and money, logging, concurrency, resources/IO, security, API design, and tests (JUnit 5 + AssertJ + Mockito). Activate on any change to `.java` files, on code review, or when the user asks to check conformance with the code standards.
-
chieaid24 Bundle UI AuditAudit and repair the visual consistency of a UI, unattended. Screenshot every flow with the repo's browser runner, find defects (misalignment, overlap, clipped text, overflow) and drift from DESIGN.md or from the app's own dominant patterns, then dispatch a fix subagent per finding and re-run its probe until every flow is clean. Use when the user wants to audit the UI, fix UI inconsistencies, or screenshot every flow and check it. Not for building new screens, redesigns, or UX/copy changes - only visual-consistency repair of existing flows.
-
chieaid24 Bundle Security AuditSecurity audit of a codebase - web apps, APIs, services, CLI tools, libraries, daemons, and more. Use when asked to find security bugs, do a security review, audit for vulnerabilities, or pen-test the code. Focuses on exploitable issues with real impact, not theoretical concerns or industry-standard behavior.
Audited -
cutec-chris Bundle Skill CreatorCreate new PawLia skills from scratch, improve or audit existing ones. Also manages credentials for skills — store, check, list and delete API keys and tokens that other skills need at runtime (skills themselves only see the runtime `CRED_*` env vars, never the store). When a skill has bugs or needs changes, delegate the full task here — describe the problem and let the skill-creator autonomously diagnose and fix it. Do not pre-read the skill files yourself. Use when the user wants to: create a new skill, scaffold a skill directory, manage skill credentials, improve or review an existing skill, validate a SKILL.md against the spec, package a skill for distribution. Triggers on phrases like "create a skill", "new skill", "store api key", "add credentials", "improve this skill", "validate skill", "audit skill", "scaffold a skill".
Audited -
daemon-blockint-tech Skill Raven Zero Day Auto PreventAutomatically enforce defensive policy against an in-progress 0-day signal, end-to-end, with strict approval gating. Use when the user says "auto-prevent", "auto-block", "auto-quarantine", "policy-driven response", "stop this 0-day now without me clicking through", or asks Raven to execute the Defend plan automatically when criteria are met. Every automatic action terminates at a tool oracle (𝒯) with mandatory approval-gate verification, references a real D3FEND Isolate / Evict / Harden technique id, and emits a tamper-evident audit trail.
Audited -
deepaksinghcs14 Skill Deadeye PrPR review across four lenses -- over-engineering, correctness, performance, security -- printed locally, opt-in to post.
-
deepaksinghcs14 Skill Deadeye ReviewFour-lens self-review (over-engineering, correctness, performance, security) of the working diff, or the whole repo with --repo.
-
descope Bundle Auth ReviewStatic security review for authentication and authorization vulnerabilities. Use when the user invokes /auth-review, asks to audit auth, find identity breaches, review access control, hunt for IDOR/BOLA, or check authorization. Framework- and vendor-agnostic. Enumerates every route/endpoint, builds an authorization matrix, applies a vulnerability catalog, and writes a triage report ready to turn into issues or PRs.
-
descope Bundle Workos To DescopeUse this skill whenever anyone asks about migrating from WorkOS to Descope — whether they're a developer doing it themselves or a technical lead evaluating the move. Triggers on: "how do I migrate from WorkOS", "replace WorkOS with Descope", "we're moving off WorkOS", "WorkOS to Descope", "switch from WorkOS", "our app uses @workos-inc/node / @workos-inc/authkit-nextjs / AuthKit / WorkOS SSO / Directory Sync / SCIM and we want to use Descope instead", or any question about WorkOS features (AuthKit, Organizations, Enterprise SSO, Directory Sync/SCIM, Admin Portal, RBAC, FGA, Audit Logs, Radar, Pipes) in the context of Descope. Works for any language or framework with a Descope SDK. Always use this skill before producing migration guidance — do not rely on memory alone.
-
digitizers Bundle Fable ModeUse this skill IMMEDIATELY whenever the message contains "fable-mode", "fable mode", "פייבל", or "מצב פייבל" — including as a prefix before a task (e.g. "fable-mode: review this...") — no matter what the task itself is. Also use it proactively, unprompted, in two situations: (1) the user wants a fact double-checked or verified against a live source instead of answered from memory — "double-check", "can you verify", "is this still true", "I don't trust my memory", current versions/limits/pricing/capabilities of tools, APIs, or services; (2) the task is costly if wrong — production changes, migrations, deletions, security, money, architecture commitments, debugging, or research synthesis. Enforces strict planning, verification, and calibrated claims; stays active for the rest of the conversation until "fable-mode off" / "כבה מצב פייבל". Do NOT use for casual questions, trivial edits, creative writing, or when "fable" appears only as an ordinary word (writing a fable, defining it).
Audited -
apache Bundle HeatmapUse git heatmap analysis to identify high-churn files and lines as candidates for thorough review or bug hunting. Works for PR reviews, security audits, bug hunts, or any code analysis task.
Audited -
avalonreset Skill Github LegalGitHub legal compliance — generate LICENSE, SECURITY.md, CITATION.cff, NOTICE; handle fork attribution and dependency compatibility.
-
awslabs Skill Phase 2 ArchitecturePhase 2 Architecture Analysis guide. Use when documenting system components, connections, data stores, or analyzing technical architecture for threat modeling.
-
awslabs Skill Phase 3 Threat ActorsPhase 3 Threat Actor Analysis guide. Use when identifying threat actors, setting relevance and priority, or analyzing who might attack the system.
Audited -
awslabs Skill Phase 4 Trust BoundariesPhase 4 Trust Boundary Analysis guide. Use when defining trust zones, crossing points, and security boundaries between architecture nodes.
-
awslabs Skill Phase 9 Output GenerationPhase 9 Output Generation guide with Threat Composer export reference. Use when generating final reports, exporting to JSON/Markdown, or completing the threat modeling process.
Audited -
awslabs Skill Phase 7 Mitigation PlanningPhase 7 Mitigation Planning guide. Use when creating mitigations, linking them to threats, validating coverage, or planning security controls.
-
awslabs Skill Phase 6 Threat IdentificationPhase 6 Threat Identification guide with STRIDE methodology reference. Use when identifying threats, categorizing security issues, applying STRIDE analysis, or assessing threat severity and likelihood.
Audited -
fxckcode Bundle API TestProtocol-first, client-agnostic skill for testing REST APIs end-to-end from the terminal. Detects OS and HTTP client automatically, constructs requests with env var references for secrets, interprets responses, infers auth and Content-Type, diagnoses errors, supports request chaining and response assertions. All output is secret-redacted before display. Trigger: When user says "test API", "HTTP request", "curl", "REST call", "API E2E", "testear API", "llamada HTTP", "probar endpoint", "API test", "call endpoint", "send request", "make request", "hit endpoint", "enviar request", "probar API", "test this endpoint", "call this endpoint", "hit this URL".
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include investigate, breachsweep, review. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.