Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
fxckcode Bundle Env Secrets ManagementManage .env files, API keys, passwords, and sensitive configuration values — including workarounds for tool output censorship that corrupts secrets in commands and file writes. Use when handling secrets, configuring environment variables, or debugging authentication issues caused by secret censoring.
-
fxckcode Bundle NPM Supply Chain SecurityThree-layer npm supply chain security: consumer basics, PNPM hardening, and publisher best practices (OIDC, Provenance, 2FA). Use when securing npm projects, auditing dependencies, evaluating install risks, or after supply chain attacks.
-
gramiojs Skill Sync TranslationsAudit EN/RU documentation for sync issues — find missing translations, outdated pages, and auto-translate missing Russian pages.
-
hebstr Bundle SweepUser-invocable ONLY via `/audit:sweep`. Does not auto-trigger on mentions of "full review", "audit complet", "review complète", "review this project", "audit this repo", "thorough review", "diagnostic complet", "état des lieux du projet", or any phrasing requesting a multi-angle project assessment. Full project review: detects project type and size, spawns specialist background agents with disjoint scopes (architecture, quality, tests, docs), consolidates findings into one deduplicated report sorted by severity, then offers an interactive walkthrough. Not for: single-file reviews, PR or diff reviews, or non-code document reviews (papers, resumes, CVs).
-
hebstr Bundle Skill AdversaryUser-invocable ONLY via `/audit:skill-adversary`. Does not auto-trigger on mentions of "audit this skill", "review SKILL.md", "find flaws", "adversary review", "attack this skill", "trigger edge cases", "stress-test", or French equivalents ("auditer cette skill", "trouver les failles", "passer ce skill au crible"). Adversarial reviewer for Claude Code skills: reads a skill's full directory (SKILL.md, agents, docs, templates) and reports trigger edge cases (false positives and negatives), instruction ambiguities, contradictions, cross-file coherence issues, and gaps. Not for: general code review (use posit-dev:critical-code-reviewer), reviewing non-skill files, or creating/editing skills (use skill-creator).
-
hebstr Skill Doc StructureAudit and reorganize project documentation layout (CLAUDE.md for Claude rules, README.md for human docs). User-invocable ONLY via `/workflow:doc-structure [<project-path>]`; the path is optional and defaults to the current working directory. For monorepos, invoke once per sub-package path. Does not auto-trigger on mentions of CLAUDE.md, README.md, documentation, or sync. Not for code-level docstring/README drift, splitting one doc file into a `docs/` tree, or reorganizing sections within a single CLAUDE.md or README.md.
-
idimsh Skill UX AuditAudit UX against established UX laws, cognitive principles, and Nielsen's heuristics — with actionable fixes
-
keepit-official Bundle Keepit Account HealthComprehensive Keepit backup account health checker and configuration validator. Use when users ask to check Keepit status, verify backup configuration, review account health, audit connector setup, or get an overview of their Keepit backup environment. Triggers on keywords like "Keepit status", "backup health", "check Keepit", "connector overview", "account configuration", "backup setup review".
Audited -
keepit-official Bundle Keepit Compliance Audit LogComprehensive compliance audit log extractor and formatter for regulatory reporting and security investigations. Use when users ask to extract audit logs, generate compliance reports, create audit trails, investigate security events, document user actions, or prepare for regulatory audits. Supports GDPR, HIPAA, ISO 27001, NIS2, SOC 2, and other frameworks. Triggers on keywords like "audit log", "compliance report", "security investigation", "regulatory audit", "audit trail", "user activity", "GDPR report", "access log".
Audited -
keepit-official Bundle Keepit Retention Policy AuditorRetention policy compliance auditing and validation for Keepit backup environments. Use when users ask about retention policies, data retention compliance, GDPR/NIS2/DORA/HIPAA/SOX retention requirements, retention configuration review, or policy change tracking. Triggers on keywords like "retention policy", "retention audit", "data retention", "compliance check", "GDPR retention", "NIS2", "DORA", "how long is data kept", "retention settings".
-
keepit-official Bundle Keepit Security Incident InvestigatorSecurity incident investigation and threat detection for Keepit backup environments. Use when users ask about security incidents, suspicious activity, unauthorized access, failed login patterns, data exfiltration, or threat investigation. Triggers on keywords like "security incident", "suspicious activity", "unauthorized access", "failed logins", "threat investigation", "data exfiltration", "breach investigation".
Audited -
kochellenk-afk Skill Landing Page Match ScorerScore Google Ads landing page alignment with keywords and ad copy across 7 dimensions, then prescribe specific changes ranked by Quality Score and conversion impact. Use this skill when a user wants a landing page audit, asks why their landing page experience is low, mentions message match, asks how to improve conversion rate from Google Ads, wants to align landing pages with keywords, or shares a landing page URL alongside ad/keyword data. Trigger on phrases like "landing page audit", "landing page experience", "message match", "improve conversions on", "why does my landing page score low", "review my landing page", or any request pairing a landing page with Google Ads keywords or ads.
-
konggithubdev Skill Solve ChallengeSolves CTF challenges by analyzing files, connecting to services, and applying exploitation techniques. Orchestrates category-specific CTF skills for pwn, crypto, web, reverse engineering, forensics, OSINT, malware analysis, remote, and miscellaneous challenges. Use when given a CTF challenge to solve, a challenge file to analyze, or a service endpoint to exploit.
Audited -
konstruktoid Skill Python TestingAdds or updates pytest coverage for a Python change by first discovering the repository's existing test layout and conventions, matching them rather than imposing a new structure, deciding whether the change requires a test at all, and running the suite in a bounded verify loop. Use when a Python change adds behavior, fixes a bug, changes a public interface, or touches security-relevant logic, and when deciding where a new test belongs in an unfamiliar repository.
-
konstruktoid Bundle Bash Secure ScriptingAuthors, reviews, and hardens Bash scripts for the stability and security properties a linter cannot verify on its own, including strict-mode semantics and the cases errexit ignores, cleanup and locking on every exit path, injection-safe handling of untrusted input and filenames, PATH and environment control, temporary files and permissions, and credential handling, verified with shellcheck, bash -n, and the repository's formatter in a bounded loop. Use when creating or editing a shell script, a sourced shell library, or shell embedded in CI steps, container entrypoints, systemd units, cron jobs, or git hooks, and when reviewing quoting, eval, set -euo pipefail, traps, temporary files, privilege or sudo use, or secrets in shell code.
-
konstruktoid Bundle Github Organization GovernanceConfigures, reviews, and hardens GitHub organization and enterprise settings that apply across repositories, covering member privileges and base permissions, two-factor and single sign-on requirements, team-based access and periodic access reviews, GitHub App and personal access token policy, the allowed-actions and self-hosted runner policy, organization rulesets targeted by custom properties, and audit log retention, streaming, and evidence, verified by reading the applied state back and measuring coverage across repositories in a bounded loop. Use when setting organization or enterprise policy, rolling a ruleset out across repositories, designing or populating custom properties, reviewing member, team, app, or token access, restricting which actions and runners repositories may use, or assembling evidence for a compliance framework such as SOC 2, PCI DSS, HIPAA, or FedRAMP.
-
lacerbi Skill AuditAnalyze files for quality and consistency within the codebase
-
miles990 Bundle Audit跨子系統架構一致性審查 - 利用多視角並行分析架構健康度
Audited -
milkywayrules Bundle Verasic SecbotSTRIDE security review on git diff with optional deterministic scanner. Use when the user asks to "security review", "review for security", "STRIDE review", "check my diff for vulnerabilities", or before commit/PR when auth, crypto, webhooks, or untrusted input changed.
Audited -
milkywayrules Bundle Verasic Git Commits AuditPre-push commit history audit against the Verasic commit convention. Use when the user asks to "audit commits", "check commit messages", "clean commit history", or before push/PR to verify branch history.
Audited -
morluto Bundle Verifier EvaluationsDesign, audit, or repair mathematical benchmark verifiers, submission contracts, and scoring.
-
morluto Skill Audit Mathematical VocabularyAudit a bounded mathematical slice for missing or unusable Jacobian capabilities, beyond a single-operation review.
-
morluto Bundle Audit Public Operation ContractsAudit a Jacobian operation’s mathematical contract, boundedness, exact results, and composition.
-
mozilla Bundle Sec ApprovalHelp prepare a Firefox security approval request by analyzing local commits/changes, deciding whether sec-approval is required at all (only parent-process vulnerabilities triggerable from a content process), and drafting answers to the sec-approval questionnaire. Use when setting sec-approval? on a Bugzilla bug.
-
adityaarakeri Bundle Dead Code AuditDead Code Audit
-
adol1111 Bundle Technical DesignDecide and document review-critical technical choices for one explicitly targeted or unambiguously current Feature or child Task when architecture, ownership, data, state, algorithm, concurrency, security, performance, or verification has materially different plausible approaches or a non-obvious invariant. Straightforward work needs no design artifact.
-
agentlyhq Skill Geo Site AuditPre-checks a target site with Jina before running a structured, weighted Generative Engine Optimization audit and returning a scored action plan.
Audited -
aksh-3141 Bundle Merge ChecksAudit code changes across 13 quality dimensions before or after merge
Audited -
albumentations-team Bundle Performance OptimizationSystematic performance audit for AlbumentationsX runtime code. Use whenever implementing, reviewing, profiling, or optimizing transforms, functional kernels, apply methods, random generation, reductions, label maps, dtype conversions, batch paths, allocation-heavy code, backend routing, or code that may belong in Albucore.
-
dotnet Skill Update TpnAudit and update the THIRD-PARTY-NOTICES.TXT file. Use when the user asks to "update TPNs", "audit third-party notices", "check third-party licenses", or after adding/removing a dependency. Scans submodules, vendored code, NuGet packages, and native libraries to ensure the TPN file is complete and accurate.
4k -
elan6666 Bundle Byte ReviewReview a product, implementation, plan, or deliverable for material issues and readiness. Use when the user asks for review, audit, critique, quality assessment, or what should change next.
-
elithrar Bundle Code ReviewerReview a specified code change for actionable defects. Use for uncommitted changes, base-branch diffs, commits, PRs or MRs; review alone is read-only, and requested fixes follow the review. Not a repository-wide security or complexity audit.
-
fastly Bundle FastlyConfigures, manages, and debugs the Fastly CDN platform — covering service and backend setup, caching and VCL, security features like DDoS/WAF/NGWAF/rate limiting/bot management, TLS certificates and cache purging, the Compute platform, and the REST API. Use when working with Fastly services or domains, setting up edge caching or origin shielding, configuring security features, making Fastly API calls, enabling products, or looking up Fastly documentation. Also applies when troubleshooting 503 errors or SSL/TLS certificate mismatches on Fastly, and for configuring logging endpoints, load balancing, ACLs, or edge dictionaries. Read the relevant reference file before writing any Fastly API call or curl command — request field names (e.g. the backend fields override_host, ssl_cert_hostname, ssl_sni_hostname, use_ssl) are easy to misremember, and a wrong name causes a silent 503 instead of an error, so do not rely on training-knowledge field names.
-
fastly Bundle FastlikeRuns Fastly Compute WASM binaries locally and serves as the authoritative reference for Compute platform internals. The fastlike source code is highly readable and covers the host ABI, caching and purging APIs, KV/config/secret store interfaces, rate limiting with counters and penalty boxes, ACL lookups, the full request lifecycle, backend fetch semantics, and a built-in per-request profiler with hostcall spans, backend waterfalls, native CPU samples, and optional deep metrics (body bytes, cache outcomes, header summaries, wasm heap curve). Use when working with Compute runtime internals or host calls, understanding how edge data stores behave at runtime, profiling local Compute apps, or testing WASM binaries locally. Prefer this skill over Viceroy for any non-Rust Compute work — its source code is easier to understand as a Fastly Compute API reference.
-
fastly Bundle Fastly CLIExecutes Fastly CLI commands for managing CDN services, Compute deploys, and edge infrastructure. Use when running `fastly` CLI commands, creating or managing Fastly services from the terminal, deploying Fastly Compute applications, managing backends/domains/VCL snippets via command line, purging cache, configuring log streaming, setting up TLS certificates, managing KV/config/secret stores, checking service stats, authenticating with Fastly SSO, or working with fastly.toml. Also applies when working with Fastly service IDs in CLI context, or with `fastly service`, `fastly compute`, `fastly auth`, or any Fastly CLI subcommand. Covers service CRUD, version management, autocloning, and troubleshooting common CLI errors.
-
fastly Bundle Fastly NgwafPerforms an internal audit of Fastly Next-Gen WAF (NGWAF) workspaces to audit that critical templated protection rules are configured and enabled. Use when auditing NGWAF workspace security posture, checking for missing or disabled login protection rules (LOGINDISCOVERY, LOGINATTEMPT, LOGINSUCCESS, LOGINFAILURE), auditing credit card validation rules (CC-VAL-ATTEMPT, CC-VAL-FAILURE, CC-VAL-SUCCESS), auditing gift card protection rules (GC-VAL-ATTEMPT, GC-VAL-FAILURE, GC-VAL-SUCCESS), identifying potential login endpoints not covered by NGWAF rules, or comparing attack traffic against blocked traffic to confirm enabled rules are actually blocking.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include update-tpn, code-reviewer, env-secrets-management. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.